When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something.

If you’re paying attention, you should have noticed that the major vulnerability we recently reported in one of the world’s most popular WordPress themes was found by an autonomous AI agent we developed called Wordfence Argus. A few minutes ago we reported another. We have made several additional breakthroughs with Argus that are working their way through the responsible disclosure process, and which we’ll publish over the coming weeks. You’re going to be hearing a lot about Wordfence Argus, which is an internal application we have developed for aggressive vulnerability hunting.

We have debated whether Argus is AI, a harness, or an agent, but none of those seem to apply because this kind of application includes harnesses, prompts, models, orchestration and more.

Wordfence Argus has given us front-row seats in the AI revolution, because it is making breakthroughs in a field in which we are world-class experts. We have the ability to fully appreciate the complexity of the research that it is conducting, and how it is beginning to exceed human capability – and far exceeds the tempo at which a human team can operate. This is incredibly exciting to see, and bodes well for challenging fields where we badly need innovation, like cancer research, which I personally provide funding for and care very much about.

The design approach we’ve taken with Argus and its use of LLMs is to confine, constrain, focus, motivate, parallelize, hypothesize, verify, record, prioritize, and then iterate hard and fast. I can’t go into the design details or which models we’re using or which prompt structure or harness design we use, because we are in a race with threat actors to ensure that we find the most dangerous vulnerabilities before they do.

And that is exactly what Argus is designed to do: to find the worlds most dangerous WordPress Vulnerabilities. More on this in the coming weeks.

Wordfence Argus is model agnostic, and we’re continuously evaluating different models to find the best balance of capability vs price. When a new model is released, we’re able to immediately pivot Argus to using that, in order to evaluate whether it provides improved capability. This keeps us at the forefront of AI powered cyber research.

Maintaining this lead is a critical success factor today for any cybersecurity organization, because attackers are gaining access to the same tools that we have access to. Innovation in vulnerability research comes from prompt engineering, harness design and task-specific model selection, along with traditional deterministic programming. Preventing malicious actors from accessing cyber-capable models is one control – but it leaves threat actors with powerful new prompts, a rapidly evolving ecosystem of open source harnesses, open-weights models without guardrails, and the many other tools emerging from the AI ecosystem.

Thus it is imperative that we lead in AI assisted vulnerability research and cybersecurity research. Wordfence Argus is one of the tools, along with others like Wordfence PRISM, that we’ve developed to accelerate innovation in vulnerability research, and to establish and maintain a lead ahead of threat actors.

I’m incredibly proud of the work our team is doing. They developed Wordfence Argus on their own, made a major research breakthrough, and kept it as a surprise for Kerry Boyte (my co-founder) and I, which they revealed in person at our suite at DEF CON this year at a big team gathering. What I’m particularly proud of is that our company has the kind of culture that enables the blue-sky research that produced Argus, without it being supervised, guided, micromanaged or interfered with. Turns out that creating a space that lets hackers hack, and getting out of the way, leads to profound breakthroughs.

Mark Maunder – Wordfence Founder & CEO

The post Wordfence Argus: Moving Beyond Human Research Capability appeared first on Wordfence.