bg
Cybersecurity
08:14, 25 September 2026
views
4

Artezio Turns AI Into a “White Hat” Hacker

Developers have released a multilayered AI platform that not only finds vulnerabilities but also helps reproduce the logic behind a potential attacker’s actions.

In Russia, white hat hacking services are widely used. Companies hire ethical hackers and ask them to break into their information infrastructure. This helps uncover weaknesses in their defenses. But what if artificial intelligence could be trained to do the same thing?

A Technology-Driven Response to Attackers

Artezio, part of the LANIT Group, set out to do exactly that. Its team built a platform based on multilayered AI technology. The algorithms are not designed to strengthen an organization’s defenses but to try to break through its infrastructure in much the same way attackers equipped with modern AI tools would. The difference is that the program’s goal is not to cause damage but to identify vulnerabilities. The solution has already been tested on several commercial projects and received high marks.

The platform is built on information that analysts have been collecting since 2018. This body of data has enabled the AI to conduct controlled attacks across a potential customer’s entire information-security perimeter. The platform tests external defenses, internal networks, web applications, and APIs.

A Wide Range of Potential Customers

The technology is primarily intended for companies that conduct regular information-security audits. For example, it can be used by businesses whose large customers require proof of adequate security before closing a deal. The solution can also test the security of AI products and data-processing systems before they enter the market. Customers receive a report containing reproduction steps, severity assessments, and potential consequences, documentation confirming that the tests were performed for auditors, and repeat testing after vulnerabilities are fixed.

“The reason a new approach and comprehensive solution were needed is the speed of attacks. In the past, preparing an attack took days. Now it takes minutes: the tool is created for a specific target in real time. Just 24 hours can pass between the publication of vulnerability information and mass exploitation. Corporate response procedures are designed around weeks and cannot keep pace. The only way to find out what an attacker will be able to do is to get there first,” the developers explain.

Cutting Security Spending Can Be Expensive

Experts also point out that attempts to cut information-security costs can result in substantial losses. In the first quarter of 2026, a successful cyberattack cost companies an average of 50 million rubles (about $590,000). An hour of downtime in the IT and telecommunications sectors costs roughly 21.7 million rubles (about $257,000). In addition, a personal-data breach affecting more than 100,000 people can result in a fine of 10 million to 15 million rubles (about $119,000 to $178,000), while a repeat violation can result in a fine equal to 1% to 3% of annual revenue, subject to a minimum of 20 million to 25 million rubles (about $237,000 to $296,000) and a maximum of 500 million rubles (about $5.9 million).

Automation Addresses the Cybersecurity Talent Shortage

Demand for automated information-security testing systems in Russia continues to grow. Companies need to test virtually every update to their products. The workload has become so large that the market is facing a severe shortage of human security professionals. New technologies can help address that shortage, particularly because development in this area has already been underway for several years.

Practical simulation of attacker behavior has been used since 2021. At the time, the so-called Rostelecom-Solar national cyber range was actively operating. Its infrastructure included a subsystem for automated attacks and automated assessment of participants’ actions.

In 2024, MTS RED released the Cicada8 platform for continuous security monitoring. It automatically identified vulnerabilities and was designed to cut the time needed to obtain an up-to-date threat picture from several weeks to about one week. In 2026, Cicada8 introduced a full-fledged AI penetration tester. The agent-based system generates and tests attack hypotheses on its own, works with applications and APIs, and analyzes authentication mechanisms and business logic.

In effect, algorithms have now learned to reproduce human actions with a high degree of fidelity rather than simply operate as scanners.

The solution presented by Artezio is another step toward building a full-fledged market in Russia for automated information-security testing tools. It addresses the needs of customers who now need more than a list of individual vulnerabilities: they also need to understand the logic behind the actions a potential attacker could take.

Defensive tools answer the question of what we have secured. Our solution answers a different question – what can still be done with this infrastructure. It needs to reach the target before someone else does. We do not give the customer a list of alerts but ready-to-use attack scenarios taken all the way to proof. Each one can be reproduced step by step and neutralized
quote

like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next