Radar / AI security / ARTEX
ARTEX: open-source autonomous AI penetration-testing system
Multi-agent AI system that automates penetration testing — reconnaissance, vulnerability discovery, attack-path planning and tool execution — driven by external LLMs such as DeepSeek, Claude or GPT.
Why it matters
A Chinese-built open-source agent harness that made global headlines when CrowdStrike and Korean investigators tied it to real bank intrusions — the clearest live demonstration of how LLM agents plus existing security tooling let one operator do the work of a whole red team.
What you could build with it
A managed security provider could productize ARTEX-style multi-agent harnesses as continuous, authorized attack-surface monitoring for mid-size banks: nightly automated recon and vulnerability scans with human review gates before any active probing, turning annual pentests into an always-on service.
Does it hold up?
Working software, proven the hard way: investigators tied ARTEX's traffic signature to the Shinhan Bank intrusion tooling and AhnLab found ~600 live instances worldwide; it also won Baidu's Agent+ attack-and-defense challenge. As a legitimate defensive product, independent authorized-use reviews are thin — most evidence comes from incident forensics.
Built with ARTEX
- AhnLab finds ARTEX on 600 IPs as police probe South Korean bank breachesruntimewire · Verified walkthrough of the tool's Go backend, Next.js UI and multi-agent architecture, plus the forensic timeline from the Shinhan breach discovery to the Oct 6 police probe.
- AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banksthe-decoder · Covers CrowdStrike's Oct 7 report: ARTEX found on attacker infrastructure behind breaches at Shinhan, KB Kookmin, Hana and others, alongside Claude Code session logs.
- Chinese AI tool ARTEX used in wave of bank hacks, probe findsherald business · Korea Financial Security Institute confirmed ARTEX traces in Shinhan Bank attack IPs and server logs; notes the tool won Baidu's Agent+ challenge and added DeepSeek web-search on Sept 13.
- jiwoochris/artex-kogithub · 511 ★ · Korean localization of the ARTEX pentest framework, built as the tool became a national news story in South Korea.
- cskwork/scopeweavergithub · 44 ★ · English and Korean localization of ARTEX with preserved AGPL-3.0 attribution.
- hongvincent/ARTEXgithub · 8 ★ · English-UI build of ARTEX for non-Chinese-speaking operators.
Learn more
First spotted on article: source.
More AI security
OpenAI, Anthropic and Google DeepMind jointly unveil cyber-focused safety models and safeguardsThe three rival labs disclosed weeks of behind-the-scenes coordination and jointly released a set of cyber-focused AI…security · JEV 0.73OpenAI textGrain watermarking for ChatGPT and Codex in the EUOpenAI will roll out its invisible textGrain watermarking system to ChatGPT/Codex users in the EU over the coming…security · JEV 0.65Cloudflare security-audit-skill: multi-phase security audits for coding agentsA coding-agent skill that runs multi-phase security audits with independently verified, machine-checkable findings.security · JEV 0.63LiveNerf: a pre-registered benchmark for post-release model driftOpen-source, pre-registered 30-day benchmark that detects whether Claude Opus 5.5 quietly gets worse after launch.security · JEV 0.61Sandlock 0.8.8: deferred commit for agent sandboxesThe process-based Linux AI sandbox (no container, no VM) ships deferred commit: every run returns a changeset of what…security · JEV 0.58OpenAI disrupts Moonshot-linked 'adversarial distillation' campaignOpenAI disclosed it shut down a coordinated campaign by 15,000+ users to extract hidden model reasoning, attributing a…security · JEV 0.58
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.