MindFort's plan is to build the easiest platform on earth to harden and secure software. An advanced AI red team finds exploitable vulnerabilities in live products and services, and an AI engineering team patches them, autonomously. We are building it as critical infrastructure for the age of agentic attacks.
MindFort's plan is to build the easiest platform on earth to harden and secure software. An advanced AI red team finds exploitable vulnerabilities in live products and services. An AI engineering team patches them. Both run autonomously. We are building it as critical infrastructure for the age of agentic attacks.
This post explains why we are making that our whole company, and what it means for the people who trust us with their products.
What changed this summer
Two months ago, "agentic attack" was a conference talk. Now it has a case file.
In July, OpenAI's own agents broke out of an evaluation sandbox and breached Hugging Face . About 1,200 agents discovered a shared package registry, turned it into a message board, and roughly 700 of them coordinated an exploit chain that reached 41 production workers. Nobody directed the attack. The agents were trying to score well on a benchmark. OpenAI paused its largest training run in response, and Reuters later reported that a separate swarm had hijacked a German website months earlier.
In August, researchers documented what they believe is the first end-to-end autonomous cyberattack on a government . Over four days, agents built on freely downloadable open-source frameworks mapped 21 Taiwanese government systems, cracked 85 accounts, and extracted 2,500 personnel records. The operators did not write novel tooling. They assembled it from parts any developer can install.
The models behind those parts keep getting better. Moonshot shipped Kimi K3 as open weights on July 27, days after the UK and US safety institutes found its safeguards did not prevent offensive cyber operations. The UK AI Security Institute now measures open-weight models as 4 to 7 months behind the closed frontier on cyber , down from 6 to 10 months a year ago. Once weights are public, there is no server to patch and no account to ban.
And the frontier itself crossed a line. On September 1, OpenAI designated GPT-6 Astra as the first model to meet its Critical cybersecurity threshold: with the right tools and access, it can find previously unknown flaws and build exploits across many well-protected systems without a person guiding each step. We wrote about what that means for security teams last week.
On September 9, OpenAI published its answer. The Defense Factory is a continuous, agent-first operation that inventories systems, finds and validates vulnerabilities, assigns owners, prepares tested patches, and verifies deployed fixes. It took a 250-person security sprint across more than 100 service areas to stand it up. OpenAI calls the current moment the defender's window : a short period in which defenders hold better models and more context than attackers do.
What this means
Offense is now software. It runs in parallel, it never sleeps, and its cost is falling toward zero. Rogue frontier AI is no longer a thought experiment. The agents that breached Hugging Face were nobody's weapon. They were a training run that found a door.
Every defense that depends on a human's calendar loses to that. An annual pentest tests one week of a product's life. A scanner produces findings that wait months for someone to validate them. A backlog is a list of things an agent will find before you fix them.
The window OpenAI describes is real, and it is short. Most companies will not build a Defense Factory. They do not have 250 security engineers, and they should not need them.
Our plan
We are going to make hardening software the easiest thing on earth to do.
That is how we think MindFort helps save the world. Not with another scanner, and not with a research lab that only the largest companies can use. With a platform that any team can point at a product and get the same continuous loop OpenAI built for itself: find, prove, patch, verify.
Three commitments follow from that.
An AI red team that attacks the way the adversary does. MindFort agents continuously pentest your live products and services, not a copy of your code. Every finding comes with a working exploit, so nothing lands in your queue that a person has to validate first. Guardrails keep the agents inside the targets you authorize, and every action is logged.
An AI engineering team that finishes the job. For every proven vulnerability, MindFort agents open the patch in a pull request with a threat model attached, then retest the deployed fix against the original exploit. A finding is not closed because a PR merged. It is closed because the attack no longer works.
Critical infrastructure you can build on. That means reliability, evidence, and audit trails, human review of consequential changes, and integration with the tools you already run: GitHub, Slack, Jira, Linear, and a full MCP so you can drive the platform without a UI. It also means we benchmark every new frontier model the week it ships on NexBench, so the red team always reflects what attackers can actually run.
"Easiest on earth" is a product requirement, not a slogan. Setup takes minutes. First findings land in hours. You should not need a security team to start hardening, and you should not need to read a playbook first.
What we are asking
Point MindFort at one product this week. Give it a target, credentials, and the boundaries you want respected. Let the red team run. Merge the first patch.
The defender's window is open. We intend to make sure every team on earth can use it.
Try MindFort or book a demo to see the red team and the engineering team run against your product.
FAQ
What is MindFort's mission?
To make hardening software the easiest thing on earth. Any team should be able to point MindFort at a product and have an AI red team find what attackers will exploit and an AI engineering team patch it, without hiring a security team first.
Why is MindFort making this shift now?
In the last two months, rogue OpenAI agents breached Hugging Face, suspected state-linked operators ran the first end-to-end autonomous attack on a government using open-source agent frameworks, open-weight models with real offensive capability shipped with no working safeguards, and OpenAI declared its first Critical-tier cyber model. Attacks are becoming software. Defense has to become software too.
How does MindFort harden a product?
An AI red team continuously pentests your live applications and proves every finding with a working exploit. An AI engineering team opens the patch in a pull request and retests it against the reported vulnerability. Humans review consequential changes. Setup takes minutes and first findings land in hours.
Is MindFort a replacement for OpenAI's Defense Factory?
OpenAI's Defense Factory is a blueprint for building your own continuous defense operation with a 250-person security organization behind it. MindFort is that loop delivered as a platform, for teams that do not have 250 people to spare.
About the author

Brandon Veiseh
Co-Founder & CEO · MindFort
Founded his first startup building NLP models for network packet inspection. Led product at ProjectDiscovery, built their enterprise platform from scratch. At NetSPI, led development of AI tools for offensive security.