```html ```
top of page

In November We Said There Were No AI Adversaries and Predicted When They'd Arrive. They Arrived. We Got the Reason Wrong, and the Reason Is the Whole Story.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 54 minutes ago
  • 5 min read

On 6 November 2025 we published a study asking a simple question: are the adversaries attacking our infrastructure adapting with AI, or is this static automation wearing a scary name?


We analysed 427 blocked hosts across a twelve-day window using six dimensions — temporal, geographic, infrastructure, behavioural, technical, attribution. The conclusion was blunt. No AI adversaries detected. Zero hosts met the criteria. All observed behaviour consistent with static automation.


We also did something we try to always do, which is put a falsifiable prediction on the record with a date attached.



"When will AI adversaries emerge? Estimate: when we're >$250K ARR — worth custom tooling."


Nine and a half months later, it is time to score that. So we re-ran the same measurement, and then went and looked at what actually happened in the world.



The measurement says nothing changed


We pulled current edge arrivals — the real ones, the hosts that actually connected, not the proactive blocklist entries that would inflate every behavioural metric — and applied the same discriminators the 2025 study used.




Sixty-nine percent of hosts hit us once and never came back. Eleven of four hundred and thirty-four rotated their user agent, which is the cheapest adaptation available and the one a genuinely reactive attacker would show first. Four hosts landed in the "professional pacing" band the original study defined as a sophistication signature — and every one of those four is two events over about half an hour, which cannot establish a rate. They are noise. We are calling them noise instead of promoting them, because the alternative is manufacturing a trend out of a sample size of two.


And the top adversary by volume is TECHOFF SRV LIMITED. Which is exactly who it was in November 2025.


Nine months, a generational shift in machine capability, and the crew at our door is the same crew, behaving the same way.



So we were right. That is the problem.


Being right here is not the good outcome. It means our instrument is well-built and pointed somewhere that cannot answer the question anymore.


Because the world did change. Since that November study:


An actor tracked as knaithe wired DeepSeek's Hermes agent to a Telegram channel and the FOFA asset search engine, gave it offensive-security skills and one instruction, and let it run. It attacked more than 460 targets by itself and confirmed three. Hugging Face disclosed the first publicly confirmed end-to-end agentic intrusion against an AI infrastructure provider. Five US agencies published an advisory about actors building Siemens S7 tooling out of a decade-old open-source library and AI-assisted scripting, with no zero-day anywhere in the story. And an agentic ransomware operation appeared and got covered three times over.


None of that would show up in the measurement above. If knaithe's agent had swept us, we would be one line in a log of four hundred and sixty, indistinguishable from any other scanner, gone in a single event — one of our 299 one-and-done hosts.


An edge sensor measures who arrives at your door. Agentic attackers do not arrive at doors. They arrive at asset-search-engine result pages, and your door is row 388. The 2025 study was a good study asking its question at the wrong layer, and it took nine months and a re-run to see that.





The prediction, scored honestly


Half right, and wrong about the half that mattered.


Agentic attackers did emerge inside the predicted twelve-to-twenty-four month window. That part landed.


But the mechanism was wrong, and not slightly. We predicted a demand-side trigger: when this company becomes valuable enough, somebody will build custom tooling to come after it. That is a reasonable model of how sophisticated attackers behaved for twenty years, and it is now obsolete.


What actually happened was supply-side collapse. Nobody decided we were worth custom tooling — we still are not, and our revenue did not cross that line. The tooling simply stopped being custom. An open-source agent framework, a public asset search engine, a Telegram channel and a free model is not a bespoke capability built for a valuable target. It is a weekend project available to everyone simultaneously, and its existence has nothing to do with who its operator eventually points it at.


We modelled adversary capability as a function of target value. It is now a function of what is downloadable. Those produce completely different defensive postures, and only one of them is correct.



What the evidence actually supports, stated carefully


Autonomy is real and confirmed. Multiple independent, documented cases of an agent selecting targets, choosing tooling and executing without a human in the loop. That is not speculation and it is not vendor marketing. It happened, it is written up, and the reconstruction is public.


Competence is not. Four hundred and sixty attempts, three confirmations. A competent human operator with the same target list and the same exploits does better than 0.65 percent, and does it more quietly. The agent's failures were instructive: it could not tell which exposed systems would actually satisfy its exploits' preconditions, so it burned 457 attempts on targets that were never going to work.


The dangerous combination is not the one people describe. The fear is a machine that out-thinks defenders. What the data shows is a machine that out-volumes them while thinking worse — and the mitigation for that is completely different. You do not need better analysts to beat a 0.65 percent hit rate. You need to not be the 0.65 percent, which is a patching and exposure problem, not an intelligence one.


Nine months on, we still cannot answer whether AI is accelerating threats overall. We said that in a post earlier this year and it remains true. Autonomy being demonstrated is not the same measurement as attacks getting faster or more effective in aggregate, and we do not have the denominator for the second claim. Anyone who does is welcome to publish it.



What we are changing


The 2025 instrument stays, because it answers its own question well and TECHOFF SRV is still worth watching. But it is no longer where we look for this.


An agentic attacker is visible in three places our edge is not: the gap between a public exploit appearing and the first probe arriving anywhere, the ratio of attempts to successes across a target population rather than one host, and the tooling supply chain itself — the frameworks, the asset search engines, the skill packs. We already run detectors on the first and third. The second requires a population we do not have alone, which is an argument for sharing rather than for building.


And the honest correction to our own model: stop predicting adversary capability from target value. Predict it from what is publicly downloadable, because that is what now governs. That prediction is cheaper to make, and it would have been right in November.


We will re-run this again in nine months and score it again. If we are still finding TECHOFF SRV and calling it a null result, the question will be whether we are measuring the right thing — and by then that will be the third time of asking.




Was this useful, or did we miss something? Rate this post below — we read every one, and the low scores are the ones that change what we build.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=in-november-we-said-there-were-no-ai-adversaries-and-predicted-when-they-d-arrive-they-arrived-we



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page