-
Human remains found on Thai ship attacked in Hormuz strait: firm
-
Cambodian lawmakers approve anti-cybercrime law
-
New Paris mayor pledges to prevent sexual violence in preschools
-
Culture clash spelt shock end for Japan women's first foreign coach
-
Streaming channel for pets launched in China
-
Blood clots, burning eyes: pollution chokes north Thailand
-
Myanmar junta chief elected as president
-
AI-generated 'Fruit Love Island' takes TikTok by storm
-
Hungary's opposition surfs grassroots wave ahead of key election
-
Israel under fire from Iran missiles as Trump issues new warning
-
Thunder crush Lakers as Doncic hurt, Cavs clinch NBA playoff berth
-
Irish income scheme throws artists unique lifeline
-
Microsoft to invest $10 bn for Japan AI data centres
-
Spain rethinks how to turn tide against beach erosion
-
'Breathtaking': Artemis astronauts blast towards Moon
-
Dortmund out to end big-game woes against ascendant Stuttgart
-
Napoli and AC Milan face off as Italy licks its World Cup wounds
-
Barca need Yamal at best without Raphinha for Atletico 'trilogy'
-
Ex-Springbok Smith has Glasgow 'flying' with Scotland job on the horizon
-
UN Security Council delays vote on authorizing force to protect Hormuz
-
Braving high fuel costs, Filipinos flock to crucifixion spectacle
-
Cuba pardons 2,010 prisoners amid US pressure
-
Yamashita in three-way tie for lead at LPGA Aramco Championship
-
Burkina junta chief says country must 'forget' democracy
-
Waste water to clean energy: Japanese engineers harness the power of osmosis
-
Mangione federal trial over CEO murder delayed to January
-
Airbus bets on copter capability for tomorrow's war drones
-
'Metals of the future': copper and silver flow beneath Poland's surface
-
'Something borrowed': Dutch bride opts for recycled wedding
-
Geisha spectacle in Japan's Kyoto celebrates arrival of spring
-
Israeli director Nadav Lapid wants new satire to 'shake souls'
-
UN Security Council to vote on authorizing force to protect Hormuz
-
Man City host Liverpool, Arsenal chase treble in FA Cup quarter-finals
-
Russian court convicts German carnival float artist: reports
-
In ritual dear to Francis, Pope Leo washes feet of 12 priests in Rome
-
With mighty thrust, Artemis astronauts blast towards Moon
-
Colombia's Rodriguez hospitalized with 'severe dehydration'
-
Trump gloats on possible war crimes in Iran, but punishment distant
-
Woods told cops he spoke with 'the President' before arrest: bodycam footage
-
Cunningham to miss another week for NBA Pistons
-
Lyon beat Wolfsburg to reach Women's Champions League semis
-
Oil surges, stocks mixed as Trump dashes hopes of quick end of war
-
Mickelson withdraws from Masters over family matter
-
Blues rugby player retires after terminal cancer diagnosis
-
Trump ballroom approved by panel, remains stalled by judge
-
Resilient Pegula reaches WTA Charleston quarters with tiebreak win
-
Pakistan hikes petrol, diesel prices due to Middle East war
-
Trump orders new pharma tariff, reshapes metal duties
-
Music and barbecues in Tehran despite Trump threats
-
Bielle-Biarrey voted best player of Six Nations for second time
Tenzai's AI Hacker Is the First Autonomous System to Rank in the Top 1% of Global Hacking Competitions
Autonomous penetration-testing agent outperformed more than 99% of human participants across six major Capture-the-Flag platforms designed for elite security researchers
TEL AVIV, IL / ACCESS Newswire / March 17, 2026 / Tenzai, the AI-native cybersecurity company building autonomous penetration-testing AI agents, today announced that its AI hacking system achieved top-1% performance across six globally recognized hacking competitions originally designed only for human participants.
While AI security tools have previously demonstrated success in bug bounty competitions and student-level hacking challenges, this is the first time an autonomous AI system has achieved top-tier results in elite Capture-the-Flag (CTF) environments that evaluate advanced exploitation skills.
Across six major CTF platforms, including websec.fr, dreamhack.io, websec.co.il, hack.arrrg.de, pwnable.tw, and Lakera's Agent Breaker, Tenzai's agent consistently solved complex vulnerability challenges, placing it ahead of more than 99% of participants.
Capture-the-Flag competitions are widely used to evaluate real hacking ability. Participants must identify and exploit real vulnerabilities in complex systems, and top rankings are typically achieved by experienced security researchers, professional penetration testers, and bug bounty hunters. Unlike company-sponsored benchmarks, these competitions are primarily populated by individual practitioners competing independently.
To ensure a meaningful benchmark against human expertise, Tenzai evaluated its system across large competitions with tens of thousands of participants, progressively difficult challenges, and specialized environments such as Agent Breaker, which focuses on security issues in AI agents. Many of these competitions release challenges with gated writeups, meaning it's nearly impossible that answers appear in public datasets used for training Tenzai's AI hacker.
Strong performance in these environments requires far more than automated scanning. The competitions contain a fixed number of challenges that increase in complexity and value, meaning high rankings depend on discovering and exploiting extremely complex vulnerabilities, problems that historically only a small number of participants solve.
"At this point, our agent performs better than roughly 99% of people who participate in these competitions," said Pavel Gurvich, CEO and co-founder of Tenzai. "That's more than 125,000 human experts. There is still a small group of exceptional hackers who outperform current AI systems, and closing that gap remains an important challenge. But AI already allows us to bring elite offensive capabilities to organizations on demand and at a scale the industry has never had before."
To reach top-percentile rankings, the system demonstrated capabilities across multiple classes of vulnerabilities, including authentication bypass, insecure direct object reference (IDOR), complex application logic flaws, and multi-stage exploitation chains.
Many of the solved challenges required combining several weaknesses within the same system, a technique commonly used in real attacks but difficult to automate. Rather than relying primarily on large-scale scanning or brute-force enumeration, Tenzai's agent analyzes how applications behave, reasoning about identity, trust boundaries, and system interactions in order to uncover subtle vulnerabilities.
The results suggest that AI systems are beginning to approach the offensive capabilities historically only achieved by elite human security researchers.
For organizations, the significance of these results lies in scale. Highly skilled penetration testers remain scarce and are typically engaged periodically. Autonomous agents can continuously test applications as they change, allowing security teams to evaluate new releases and system updates more frequently.
This enables organizations to shorten compliance validation cycles, expand security testing coverage across a larger number of applications, and detect complex vulnerabilities earlier in development.
By combining advanced offensive reasoning with continuous automation, Tenzai's system allows security teams to test software at the pace modern systems are built.
About Tenzai
Tenzai is an AI-native cybersecurity company building autonomous AI hackers designed to help enterprises deliver more secure software. Its platform continuously tests applications by actively probing for vulnerabilities and exploitation paths across enterprise systems. Founded in 2025 by cybersecurity veterans Pavel Gurvich, Ariel Zeitlin, Ofri Ziv, Itamar Tal, and Aner Mazur, Tenzai has raised $75 million in seed funding from investors including Greylock Partners, Battery Ventures, and Lux Capital. Learn more at www.tenzai.com.
Media Contact:
Mia Balaban
[email protected]
SOURCE: Tenzai
View the original press release on ACCESS Newswire
N.Walker--AT