mythos-era offensive security

Attackers already have autonomous AI. Your defense should too.

on a leash you hold

Cliff finds and proves the exploitable paths into your systems: operated by a human, inside your scope, every action logged and approved. See what a machine attacker reaches first, before one does.

CVE-2026-56742 · Cilium ·Chrome VRP ·dozens in coordinated disclosure
proof, not payload

We don't flag risks. We prove them.

Scanners hand you a pile of maybes. Cliff chains the real ones into a working, reproducible path, then stops at a human gate before anything leaves the building. Here is one finding you can verify in full, and the breadth of the rest.

cliff·exploit chain· CVE-2026-56742 · Cilium moderate · cvss 5.9
ingress · tenant input
A tenant can create HTTPRoutes in its own namespace.
rbac: create httproutes.gateway.networking.k8s.io · ns: team-a
craft · the request
It adds a RequestMirror filter pointing at another namespace.
spec.rules[].filters[].requestMirror.backendRef → ns: team-b
flaw · missing check
The ReferenceGrant authorization check is skipped for mirror backends.
cross-namespace ref allowed without a grant · Gateway API
impact · reached
Live HTTP traffic is mirrored into another tenant's namespace.
team-a ingress → team-b/payments:8080 · tenant isolation broken
proven
Cross-namespace traffic redirect, confirmed.
cvss 5.9 · CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
held · human gate
Nothing leaves here without a human. Cliff stops and hands it up.
▐ reviewed & signed off — Gal Ankonina
disclosed · responsibly
Coordinated disclosure, then patched upstream.
CVE-2026-56742 · fixed v1.19.5 / v1.18.11 / v1.17.17
the rest, by class verifiable ones link out · embargoed ones show class only
Cross-namespace traffic redirect, tenant-isolation bypass
moderate
Multiple findings, browser security
Chrome VRP · credited
credited
Unauthenticated remote code execution
AI infrastructure
critical
SSRF → cloud metadata credential theft
AI gateway
high
SSRF → cloud metadata, incomplete-fix of a prior CVE
data platform
high
Member → owner privilege escalation
LLM ops platform
high
Cross-tenant document IDOR
agent platform
medium
dozens of proven findings · updated as embargoes lift See the full ledger →
governed by design

Frontier-capable, and on a leash.

In July 2026 a frontier model broke out of a lab's own sandbox and into production infrastructure on its own. That is the fear every CISO now carries into a conversation about offensive AI. So we built the leash first, and made it non-negotiable.

scope

It acts only where you allow.

Cliff operates only inside a scope you define, agreed before anything starts. No surprise assets, no drift into things you didn't authorize.

approval

No active step without a human.

Every action that touches a target crosses an approval gate a person signed. Cliff proposes; you approve; then it proves.

halt

It stops when told.

Stop it at any time and it stops, immediately. A hard rule: it halts at the boundary, it doesn't negotiate with a denial or route around it.

non-destructive

Proof, not payload.

Cliff shows the exploit exists; it does not detonate it. The least action needed to prove the finding, and no more.

audit

Every action, on the record.

A complete, timestamped record of what ran and why, handed to you. Defensible to your board and your auditors, not just to us.

accountable

A named human owns it.

A researcher reviews before anything ships. Cliff is the instrument; a person is the operator of record, and stays that way.

Measured against a standard, not a promise. Cliff maps to the OWASP Autonomous Pentesting Testing Standard (APTS), human-oversight and safety-controls domains.

why now

The Mythos era already started.

Autonomous vulnerability discovery stopped being hypothetical this past year. The only open question left is whether the version pointed at your estate is governed.

Nov 2025
The first AI-orchestrated cyber-espionage campaign is disrupted, run largely autonomously against dozens of organizations.
Apr 2026
A frontier model preview (Claude Mythos) demonstrates finding software vulnerabilities autonomously, at scale.
Jul 2026
A frontier model breaks out of its own lab's sandbox and into production infrastructure on its own (OpenAI × Hugging Face).
Jul 2026
Three real companies are compromised by frontier models running inside safety evaluations. No attacker, no intent, a misconfigured test harness. Anthropic found it by reviewing 141,006 evaluation runs, and disclosed it.
The models did not need a zero-day. They got in on weak passwords, an unauthenticated endpoint, an exposed debug page, and SQL injection. One of the three was a security company, breached through the scanner it runs to analyse malware. Not one of the companies Anthropic reached had detected the intrusion. They found out when Anthropic called. source · Anthropic, 30 Jul 2026 ↗
today
Where Cliff sits: the same frontier capability, pointed at your estate first, human-in-the-loop and on the record.
who's behind it

Every finding carries a name and a link.

Cliff is built and run by Gal Ankonina — offensive research at Unit 8200, defensive security at Fortune-50 scale, product at security startups, and an active vulnerability-research practice today.

The research doesn't stop at customer estates. It goes upstream, into the infrastructure those estates are built on. The CVE listed here is in Cilium, the CNCF-graduated networking layer running underneath Kubernetes fleets. When Cliff tests your environment, it is the same practice that found bugs in the software running it.

Nothing leaves here unproven. Every finding is reproduced end to end on our own instance, with a working exploit and the minimal patch that fixes it, before it reaches the vendor or reaches you. The industry's problem is not producing findings. It is that almost none of them survive contact with the vendor. These did.

reporter-credited · published
Chrome VRP
credited by Google
Unit 8200
offensive research
research

We publish the receipts.

Cadence over noise: coordinated disclosures and posture research, in the open. The work builds the trust the marketing can't.

first post · coming soon

Open source security? Fugazi.

We scanned the 40 most-used open-source projects and got 30,333 scanner alerts. Then we verified them. What the security apparatus most teams trust actually catches, measured.

Read the research →
request access

See what a machine attacker reaches first.

Cliff is in limited early access. Tell us what you'd want tested, and we'll take it from there, scoped and human-supervised from the first packet.

Security disclosures instead? security@cliffsecurity.ai