ProjectDiscoveryProjectDiscovery Logo
AI PentestingPR Security ReviewThreat ModelingVulnerability RemediationExposure AnalysisTriage
Open Source▾
NucleiNuclei TemplatesSubfinderHTTPxNaabuVulnX
Pricing
Resources▾
DocumentationBlogWhitepapersWebinarsResearchEventsPrograms
Talk to an expert
NeoCloud

Resource hub

Oh My Rogue Agent
IndustryResearchNeo

Oh My Rogue Agent

Yesterday, Hugging Face came out saying they'd detected an AI autonomous-agent-powered cyberattack and that they had to use open-source models to actually investigate and remediate it. Later we heard from OpenAI that their agent was responsible; it happened during an ExploitGym eval, and the agent just drifted off the goal. It escaped the sandbox, reached OpenAI Research Environment, got access to internet, and hacked Hugging Face production environment trying to find the solution for the benchm

Footer

ProjectDiscovery Logo
SOC2 Compliant LogoRSABlackhatG2

Solutions

  • AI Pentesting
  • PR Security Review
  • Threat Modeling
  • Vulnerability Remediation
  • Exposure Analysis
  • Triage

Open Source

  • Nuclei
  • Nuclei Templates
  • Subfinder
  • HTTPx
  • Naabu
  • VulnX
  • All tools

Resources

  • Blog
  • Whitepapers
  • Webinars
  • Research
  • Events
  • Programs

Documentation

  • PDCP Platform
  • PDCP APIs
  • Neo Platform
  • Neo APIs

Company

  • Security
  • Privacy
  • Terms
  • Contact
DiscordGitHubXLinkedInYouTube

©2026 ProjectDiscovery, Inc.

Do Not Sell or Share My Personal Information

We value your privacy

We use tools on this site to collect and record your data (e.g., your searches), which we and our vendors may use to provide, improve, and personalize our offerings, make recommendations, and for analytics and marketing. Some of these tools identify visitors and link website activity to business contact and company information so we can better understand interest in our services and tailor our outreach. We may share your data with third parties, such as advertising vendors, social media companies, and research partners, which may be "targeted advertising," "selling," or "sharing" under applicable privacy laws. Continuing to browse our site means you accept these terms and our Privacy Policy. To opt out, click the Your Privacy Choices link in the footer.

From Nuclei to Neo: LIVE with Rishi
WebinarNeoNuclei

From Nuclei to Neo: LIVE with Rishi

Nuclei changed how the industry thinks about vulnerability scanning. Neo is the next chapter. Join us on Wednesday, May 20th, at 1 PM ET as Davis sits down with Rishi in San Francisco to cover why we created Nuclei, the hard questions in security, and where the industry is going.

Should you build or buy your AI security tool?
WebinarNeoAI Security

Should you build or buy your AI security tool?

See why building your own AI security tool is easy until the bill arrives. Join our next webinar to see where the build vs. buy math really lands.

DAST: A blast from the past
WebinarNeoDAST

DAST: A blast from the past

Legacy DAST struggles with modern apps. Learn where it still fits, where it fails, and what to ask when evaluating a modern DAST replacement.

Can't we do this with Claude Code?
WebinarNeo

Can't we do this with Claude Code?

We ran the experiment so you don't have to. Join our Founding Solutions Engineer, Davis Franklin, for a live look at the execution harness behind Neo and why it's harder to replicate than it looks.

Continuous Pentesting with Verified Proof
WebinarNeoContinuous Pentesting

Continuous Pentesting with Verified Proof

See how Neo continuously combines code understanding and runtime exploitation to find business logic flaws, complex IDORs, and auth bypasses that black-box tools miss.