manawize

Join us! – András’s thoughts on Gitex – Part 2

🤖 When artificial intelligence starts hacking

AI is ushering in a new era in cyber security

One of the most exciting presentations at Gitex 2025 was not about a new piece of software, nor was it about a cyberattack.
But rather about how artificial intelligence learns to „hack”.

Ali Ahmad, the Exploiters Its co-founder and chief executive brought a unique perspective to the stage.
His company is based in the United Arab Emirates and organises hands-on cyber security training courses, CTF (Capture the Flag) competitions and workshops.

Ahmad’s aim is simple:
to train the cybersecurity professionals of the future not through theory, but through real-world attacks and simulations.

And now technology has given him a tool that will change everything: artificial intelligence.

⚙️ The old world of cyber security: slow, human, precise

Traditional penetration testing used to be a long, painstaking process.
As Ahmad said:

„We used to spend days thoroughly mapping out a single domain.
”We searched for subdomains and open ports manually, and had to analyse each vulnerability individually.”

The experts used several separate tools, and then had to compile the results manually.
The process was often not only time-consuming but also physically exhausting.

The market has continued to evolve, and increasingly complex solutions have emerged for penetration testing – that is, testing how easily one can gain access to a given system by circumventing its security. However, these results were still analysed and assessed by people, who then drew up action plans to rectify the issues.

🚀 The rise of AI: what used to take days can now be done in minutes

In this new era, artificial intelligence is not only assisting but also transforming cybersecurity processes.

Ahmad demonstrated how AI agents work – autonomous intelligent units capable, within minutes, of:

  • to gather data (reconnaissance),
  • to analyse vulnerabilities,
  • to develop exploits,
  • and produce comprehensive reports.


To put it very simply, what used to take an experienced team of hackers several days to complete can now be done by an AI agent in 10 minutes.

🧩 The new tools: PentestGPT and HexaStrike

Ahmad also presented two AI solutions that are already revolutionising the industry.

1️⃣ PentestGPT – the assistant who offers advice

PentestGPT is a ChatGPT-based support system.
It does not carry out attacks, but assists the ethical hacker during the analysis.

For example, it shows:

  • which Nmap commands are worth using,
  • how best to run a port scan,
  • what exploits might be relevant,
  • and how to carry out a buffer overflow or reverse engineering task.


It’s as if an experienced hacker were whispering in your ear — every single moment.

2️⃣ HexaStrike – the self-driving hacker

The next level is HexaStrike.
A complex system comprising multiple AI agents that fully automates penetration testing.

HexaStrike is capable of:

  • read the domain,
  • to identify services and versions,
  • to link publicly known CVE vulnerabilities,
  • select the appropriate exploit,
  • and carry out the attack independently, then draw up a report.


It integrates more than 150 open-source tools, including Nmap, Gobuster and ExploitDB – all with a single-sentence command:

„Try out this domain!”

The system then takes care of everything – whilst the user simply views the results in Visual Studio Code or the Cursor AI interface.

🔬 Live demonstration – when the code comes to life

In front of the Gitex audience, Ahmad ran HexaStrike live in an isolated environment.
Once a single IP address has been entered, the system:

  • started the Nmap scan,
  • analysed the data,
  • planned the route of the attack,
  • selected the exploits,
  • and produced the report – without any human intervention.


The room was silent. The audience watched as the artificial intelligence carried out a hack on its own – in a secure, educational environment, of course.

⚠️ The Shadow of Power – Ethical Dilemmas and Risks

But every revolution also raises the question of responsibility. Ahmad did not gloss over the dangers:

  • These tools are far too easily accessible – even people with no technical knowledge can use them to carry out attacks.
  • AI can make mistakes or „hallucinate” – that is, it can misinterpret data.
  • If it falls into the wrong hands, the system could be capable of carrying out automated cyber-attacks.


Ahmad emphasised:

„AI is the best pupil – but only as long as it is taught by a responsible teacher.”


For this reason, Exploiters uses all AI tools in a strictly controlled, educational environment.

🔮 The future: the era of „Vibe Hacking”

The speaker also introduced a new concept: „Vibe Hacking”. This refers to the future of natural-language, prompt-based hacking.

Just as anyone can now write code using a „no-code” approach, in the future anyone will be able to carry out ethical hacking using simple instructions such as:

„Check whether this server is secure.”

Hacking could thus shift from the closed world of the technical elite towards a more accessible, educational space – where the aim will no longer be destruction, but protection.

🧠 Lessons learnt
  1. AI is revolutionising offensive cybersecurity. What used to take days can now be done in a matter of minutes.

  2. Technology does not replace people, but complements them. AI is fast, but without human judgement it can be dangerous.

  3. The professionals of the future will need to think in terms of AI-integrated systems. In the future, ethical hacking will involve not only coding but also prompt engineering.
🧩 Final thoughts

Artificial intelligence has learnt to hack – but the question is no longer whether it is capable of doing so. Rather, it is what we use it for.

AI may be the most dangerous weapon in cyberspace, but it can also be the best defence – it all depends on who’s on the other side of the keyboard.

Our latest blog posts:

Share it with others!

How can we help your company?

Have a question?
Would you like to give us a try?
Feel free to write to me!

Are you ready for the next step? Request a personalised quote now!
We will get back to you within 24 hours.

IT Service Request Form – New Gen
Adatvédelmi áttekintés

Ez a weboldal sütiket használ, hogy a lehető legjobb felhasználói élményt nyújthassuk. A cookie-k információit tárolja a böngészőjében, és olyan funkciókat lát el, mint a felismerés, amikor visszatér a weboldalunkra, és segítjük a csapatunkat abban, hogy megértsék, hogy a weboldal mely részei érdekesek és hasznosak.