Armadin and TENEX.ai announced in a press release on August 3 that the two AI security companies had completed a joint engagement in which Armadin’s autonomous attack platform tested the defenses of an unnamed global institution while TENEX.ai’s AI-driven security operations team detected and responded to it in real time. According to the companies, the three-day exercise is the largest controlled live AI cyberattack conducted to date, though that scale claim comes from Armadin and TENEX.ai themselves; the institution involved was not named, and no independent third party verified the results.
What Happened
Armadin, a privately held company whose platform runs continuous simulated attacks it calls “Hyperattacks,” was given zero-knowledge access to the institution’s external perimeter, internal network, and web applications, meaning no privileged credentials, no advance whitelisting of its activity, and no access to source code. Over three days, the company says its AI agents carried out 17 million offensive actions, surfaced 238 security findings, and chained together 38 validated attack paths, 98 of which the companies characterize as significant.
TENEX.ai, also privately held and backed by investors including Andreessen Horowitz, ran its AI-driven security operations platform against the same activity. The company says it triaged all 101,169 alerts generated during the engagement and reconstructed the full attack timeline across 231 billion recorded events, a volume of analysis the companies estimate would take a five-person human analyst team roughly 2,400 hours, or about four months, to complete manually.
Agentic AI, Explained
Both platforms rely on what the industry calls agentic AI: AI systems that independently plan and execute multi-step tasks rather than simply answering a single prompt. On the offensive side, Armadin describes deploying roughly 26,000 individual AI agents that adapted their tactics as they encountered the institution’s defenses, chaining smaller exposures into larger validated attack paths. On the defensive side, TENEX.ai’s agents queried security data, traced attacker activity across billions of log events, and surfaced evidence for human analysts to review, while the company says every escalation decision was still made by a person, not the AI itself.
A SOC, or security operations center, is the team and toolset an organization uses to monitor for and respond to threats around the clock. In this engagement, attacker activity represented roughly one out of every 13,338 events TENEX.ai’s platform processed, illustrating the scale of noise a real-world SOC has to filter through to find genuine threats.
How This Differs From Traditional Security Testing
Most enterprise security programs are still tested the way they have been for years: an annual or twice-yearly penetration test, where a hired team spends a fixed window probing for weaknesses and hands over a report afterward. That cadence means a system can carry an undiscovered exposure for months between tests, and a configuration change made the week after a test clears can go unchecked until the next cycle. Armadin and TENEX.ai frame this engagement as evidence for a different model, continuous adversarial testing running at the same machine speed as the AI-driven attacks security teams increasingly face, though it is worth noting both companies have a direct commercial interest in that framing, since it describes the product each of them sells.
The findings were also mapped to established industry frameworks rather than reported in isolation. TENEX.ai says it classified each finding across 31 dimensions, including references to MITRE ATT&CK and OWASP, two widely used catalogs of known attack techniques and web application vulnerabilities that security teams use as a common reference point when comparing findings across tools and vendors. The company also says it ran 31 separate verification checks and logged both positive and negative results, an approach meant to show which parts of the environment were confirmed safe rather than simply left unexamined, and that it correlated 2,164 distinct source addresses tied to the simulated attacker across 89 separate alerting rules, work the companies say would normally require a separate investigation for each of the 38 attack paths individually.
What the Companies Are Behind This
Armadin is led by CEO Kevin Mandia. TENEX.ai, headquartered in Sarasota, Florida, with additional offices in Overland Park, San Jose, and Phoenix, is led by CEO Eric Foster and co-founder and CTO Venkata Koppaka, and its investors include Crosspoint Capital Partners, Shield Capital, DTCP, Deepwork Capital, and the Florida Opportunity Fund, with a 2025 seed round led by Andreessen Horowitz. TENEX.ai says its customer base includes enterprises across the Google and Microsoft security ecosystems. Neither company is publicly traded.
Both companies’ executives used notably strong language to describe the results, calling Armadin’s technology the industry’s “most sophisticated offensive AI capability” and warning that organizations that do not adopt similar continuous testing “will find out what unmanaged exposure costs.” Statements like these are the companies’ own characterization of their products and competitive position, not independently verified claims, and should be read as such.
What’s Unverified
The release itself carries a disclaimer identifying it as marketing material, and several key details that would normally allow independent verification are absent: the tested institution is not named, no outside auditor is cited confirming the reported statistics, and the specific attack paths and vulnerabilities found were not disclosed publicly, which is standard practice for responsible disclosure but also means outside readers cannot check the findings against the institution’s actual environment.
Sources
- Armadin and TENEX.ai Run the Largest Controlled Live AI Cyberattack on Record, PRNewswire, August 3, 2026.
Editorial Disclosure
This article is based on a press release issued by Armadin on August 3, 2026, distributed via PRNewswire and self-identified within the release as marketing and promotional material. Armadin and TENEX.ai are privately held companies; no securities are discussed in this article and no ticker or exchange applies. Next Gen Tech Stocks was not compensated for this coverage. Statistics describing the engagement, including the characterization of it as the largest of its kind, originate from Armadin and TENEX.ai and have not been independently verified; the institution involved was not named in the source release. This article is for informational and educational purposes only. See our full Disclaimer.







