In a landmark experiment at the Codegate 2026 international hacking competition in Seoul, South Korea, top-tier human hacking teams proved superior to a specialized "AI Hacker." The AI, developed by the Korea Advanced Institute of Science and Technology (KAIST), competed alongside human teams in the main event. While it demonstrated formidable speed on tasks where source code was provided, it ultimately faltered on problems that required abstract reasoning and intuition, finishing 18th in the general division. The event underscores the current state of AI in cybersecurity: a powerful accelerator for known problems but not yet a replacement for human ingenuity in novel, complex scenarios.
The competition, held over 24 hours, pitted the KAIST AI Hacker against some of the world's best cybersecurity professionals. The AI's performance was a tale of two halves.
Final Results:
The results provide valuable insights into the current strengths and weaknesses of AI in offensive security.
AI Strengths:
AI Weaknesses:
This suggests that current AI models are highly effective at the 'science' of hacking (finding known flaws) but less so at the 'art' (discovering novel or logic-based vulnerabilities).
The primary impact of this event is informational. It provides a realistic benchmark for the current capabilities of AI in offensive security. While the threat of fully autonomous, creative AI hackers remains in the future, the competition proves that AI is already a powerful tool that can augment human capabilities. For defenders, this means that the speed of attacks is likely to increase, as attackers will use AI to automate reconnaissance and find low-hanging fruit. However, defense against complex, novel attacks will still rely on human expertise. The consensus from the event is that the most effective approach, for both offense and defense, is human-AI collaboration, where AI handles scale and speed, and humans provide strategic direction and creative problem-solving.
The Codegate 2026 international hacking defense tournament concludes in Seoul.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.