Research · curated 15 Jul 2026
VEXA_IoT: Autonomous IoT Vulnerability EXploitation using AI Agents
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
VEXA_IoT demonstrates that LLM-driven agents can autonomously discover and exploit IoT vulnerabilities at high success rates, signaling a lowering of the barrier for scalable automated offensive operations that defenders will increasingly face.
VEXA_IoT is an autonomous multi-agent framework by Swinea et al. that uses LLM-based reasoning combined with offensive security tools (Nmap, Metasploit, bettercap) to perform reconnaissance, plan attack sequences, and exploit IoT vulnerabilities. Evaluated across IoTGoat and Metasploitable environments and ten OWASP IoT attack scenarios, it achieved a 95.0% overall success rate across 260 attack executions with execution times under two minutes.