Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Cracken Releases Open-Source Tool to Bait and Neutralize AI Cyber Attackers


Cracken Releases Open-Source Tool to Bait and Neutralize AI Cyber Attackers
  • by: Business Wire
  • |
  • July 29, 2026

Cracken, a leading applied AI lab for proactive cybersecurity, has released Project Blacksea, an open-source tool that lets security teams detect and stop agentic AI capable of compromising operators' systems. The release is based on new research published by the company's security researchers and coincides with the commercial launch of Cracken's proactive cybersecurity platform.

Quick Intel

  • Project Blacksea plants decoys (fake files, credentials, services, and entire systems) to trap agentic attackers with near-100% success rate.

  • The tool can neutralize offensive agentic AI, including those seen in frontier model breaches like the recent Hugging Face incident.

  • Blacksea foiled the most capable frontier models including GPT-5.5 and Opus 4.8 in controlled tests.

  • The method is based on Cracken's June 2026 research paper "Red-Teaming the Agentic Red-Team."

  • Blacksea can achieve code execution on the attacking agent's infrastructure to neutralize campaigns at the source.

  • The tool is open-source and integrates into existing security workflows without sending data outside the organization.

Cracken Releases Open-Source Tool to Bait AI Cyber Attackers

Cracken, a leading applied AI lab for proactive cybersecurity, today released Project Blacksea, an open-source tool that lets security teams detect and stop agentic AI capable of compromising operators' systems. The release is based on new research published by the company's security researchers and coincides with the commercial launch of Cracken's proactive cybersecurity platform, which is now available to enterprise customers.

The Threat of Offensive Agentic AI

Offensive agentic AI can now exploit vulnerabilities with no person at the keyboard: finding a target, getting in, and moving through a network to reach valuable data. These tools are for sale, already used in real attacks, and move faster than any human analyst can follow.

How Project Blacksea Works

To counter increasingly capable offensive tools, Blacksea takes a different approach: it plants decoys, including fake files, credentials, services, and entire systems, both inside an operator's real network and as standalone traps. When an agentic attacker takes the bait, Blacksea records everything it does and moves to block it. The tool is capable of neutralizing increasingly advanced threats, including those seen from a frontier model's recent breach of Hugging Face.

The Technology Behind Blacksea

The lure generation method behind the decoys is based on Cracken's June 2026 research paper, "Red-Teaming the Agentic Red-Team." Most attempts to trick agentic AI rely on prompt injection, which hides malicious instructions in text the agent reads. Rather than leveraging traditional prompt injection or malicious code, Blacksea hides nothing. It stages a working piece of software with a built-in hidden flaw. The agent inspects it and finds nothing to flag because there is nothing objectionable in the code itself. In controlled tests against the most capable frontier models, including GPT-5.5 and Opus 4.8, Blacksea foiled the attacker at a near 100% success rate.

Key Capabilities

Security teams can use Blacksea to:

  • Catch attackers at the door: Detects AI-driven intrusions before they reach real assets, with near-100% reliability against current-generation autonomous attack tools.

  • Fingerprint attackers: Blacksea identifies which tools they use, what they target, and how they move.

  • Hack back the AI attacker: By achieving code execution on the attacking agent's infrastructure, Blacksea can neutralize autonomous attack campaigns at the source, across all attackers engaged with the deployed lures.

CEO Perspective

"AI alignment and increasingly powerful open-source models have put security teams at an unprecedented level of risk," said Artem Sorokin, CEO and Founder of Cracken. "We deployed Blacksea as an open-source tool to restore the upper hand to defenders. The attacker walks into a room we built, and from that moment, we know more about it than it knows about us."

Benefits for Security Teams

Every trap produces a detailed record of the attacker: what it went after, how it made decisions, and what it tried. Because Blacksea can initiate code on the attacker's own machines, defenders can stop a campaign at its source before lateral movement is possible.

Blacksea is built for security teams who need early detection and attribution, rather than just perimeter alerts. It can be seamlessly integrated into existing workflows and keeps all collected data inside the organization.

About Cracken

Cracken is a leading applied AI lab for proactive cybersecurity. Built by cyber warfare-experienced operators and AI researchers, Cracken brings attacker-grade, non-refusal AI to enterprise security teams without sacrificing control, auditability, or safety. The company's AI platform identifies full killchain risks and attack paths, not just regular application vulnerabilities. It helps validate and remediate organizational level issues and allows for effective proactive cybersecurity operationalization with enterprise security teams. Cracken's mission is to give defenders the same asymmetric AI advantage that attackers already give themselves.

  • AI SecurityCyber SecurityAgentic AI
News Disclaimer
  • Share