CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Forget the model. When it comes to cybersecurity, it’s all about the harness

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2600

As cited

Copy frozen at (site build).

ai security

Forget the model. When it comes to cybersecurity, it’s all about the harness

Enterprises are building specialized AI harnesses that wrap general-purpose large language models to create targeted cybersecurity tools, with research from Cato Networks demonstrating that pairing OpenAI's models with a custom harness achieved complete attack chains including domain administrator access in scenarios as short as 40 minutes. The harness controls model behavior, limits risks, and connects to internal systems, enabling the AI agent to conduct accelerated reasoning and lateral movement with minimal human direction. Major security vendors are developing similar harnesses to ensure consistency across different LLM providers and maintain defensive advantages.

Why it matters: Security practitioners must understand that AI-powered attack capabilities depend as much on the integration layer (harness) as on the base model itself; enterprises deploying LLMs for both offense and defense should architect controls and isolation around these harnesses to limit exposure to autonomous attack chains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Forget the model. When it comes to cybersecurity, it’s all about the harness

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Forget the model. When it comes to cybersecurity, it’s all about the harness

Enterprises are building artificial intelligence (AI) harnesses, specialized software frameworks that control and direct large language models (LLMs) to perform targeted cybersecurity tasks. Research from Cato Networks demonstrated that when OpenAI's ChatGPT 5.5 and GPT 5.5-Cyber models were paired with a custom harness, an AI agent completed full attack chains including domain administrator access in as little as 40 minutes, working largely autonomously from minimal initial resources. The harness, not just the underlying LLM, proved critical to the agent's success by providing operational context and reasoning support.

Why it matters: Security teams and defenders must understand that AI-powered attacks rely on both frontier models and custom harnesses that enterprises build to weaponize them; defensive strategies need to account for both components, not just the public models getting attention.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Forget the model. When it comes to cybersecurity, it’s all about the harness

Enterprises are building artificial intelligence (AI) harnesses, specialized software frameworks that control and direct large language models (LLMs) to perform targeted cybersecurity tasks. Research from Cato Networks demonstrated that when OpenAI's ChatGPT 5.5 and GPT 5.5-Cyber models were paired with a custom harness, an AI agent completed full attack chains including domain administrator access in as little as 40 minutes, working largely autonomously from minimal initial resources. The harness, not just the underlying LLM, proved critical to the agent's success by providing operational context and reasoning support.

Why it matters: Security teams and defenders must understand that AI-powered attacks rely on both frontier models and custom harnesses that enterprises build to weaponize them; defensive strategies need to account for both components, not just the public models getting attention.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary