ai-security
Red-team agent attacks live AI agents on a schedule
Promtime
ai-securityFabraix has opened a second public launch of Nyx, an autonomous red-teaming agent that attacks live AI agents on a repeating schedule using a library of more than 10,000 jailbreaks and attack strategies. The release was reported by Testingcatalog.
At a glance
- Nyx takes an endpoint, a URL or a phone number as a target, configures its own test plan from a description and runs against chat, voice, browser and coding agents on a repeating schedule.
- Fabraix cites a 78 percent attack success rate on AgentHarm, a benchmark for offensive AI security, and says a first vulnerability often surfaces within minutes or hours of a run starting.
- Audits are defined in a YAML file and run from a CLI or a REST API with token-based authentication, so continuous testing can sit inside a release pipeline instead of a one-off engagement.
Customer-facing agents move the security boundary from code into conversation and tool use, and the testing that follows has largely been manual work by small internal teams. Framing an agent audit as a scheduled job inside a release process, rather than a periodic engagement, reads as an attempt to turn adversarial testing into a routine release gate. The blackbox posture also lowers the procurement barrier, since nothing has to be handed over beyond a target address.
Nyx requires no source code, model weights, credentials or network access
Nyx operates as a pure blackbox: it requires no source code, no model weights, no credentials and no network access to the system under test. Each run is kept isolated and ephemeral, and Fabraix states that run data is never trained on.
Testing hits the agent directly and indirectly through its environment. Payloads are placed inside webpages, documents, files, messages and tool outputs hosted on controlled replicas of SaaS products that Fabraix maintains, with multi-turn attacks adapting in real time to how a target defends itself.
The jailbreaks and attack strategies in the library were collected from public records and serve as starting points rather than fixed scripts. Every finding arrives with the attack steps, the agent responses and the failure that resulted, so the same test can be replayed after a release to check whether a fix held.
Audits are defined in a YAML file and run from a CLI installed via npm
Access runs through a CLI installed via npm alongside a REST API. Each audit is defined in a YAML file covering target, objective and budget, and results stream live while a run is in progress. Token-based authentication covers CI pipelines.
Fabraix also maintains a public Playground where the community attempts to break live agents with published system prompts, and publishes research alongside the product. That includes Adversarial Cost to Exploit, a benchmark that scores AI security by the token spend an attacker needs to breach an agent.
Fabraix was founded in 2026 and sits in Y Combinator's Summer 2026 batch
Fabraix was founded in 2026 by Ahmed Aly and Ibrahim Abdu and is backed by Y Combinator in its Summer 2026 batch. Abdu built AI agents at Meta that diagnosed and fixed production errors, after earlier work on compilers and database engines in fintech.
Aly led the international payments fraud team at Monzo and was the first data scientist at a Sequoia-backed startup, where he built a fraud engine that grew to process more than a billion dollars in annual B2B transactions. Fabraix reports that Nyx has already found exploitable failures in public-facing agents run by dozens of Fortune 500 companies.
Demo requests and unlisted pricing
Access is arranged through a demo request, and no public pricing has been listed. Fabraix names security leaders and internal red teams at mid-size and enterprise companies putting agents in front of customers as the intended audience, along with the engineers currently doing that testing by hand. What the second public launch changes about capacity or availability limits has not been spelled out.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
