#penetration testing
17 stories taggedpenetration testing.

Autonomous AI Pentesters Arrive as the Patch Gap Widens
Attackers now exploit new flaws in about five days. The average company still takes six weeks to patch. Vendors say AI agents can close the gap. Regulators are starting to notice.

Reflectiz Launches AI Agent Team That Attacks Your Website So Criminals Don't Have To First
A new platform sends four specialised AI agents to probe websites for weaknesses continuously, not just once a year. Whether that actually closes the gap between releases and real-world attacks is the right question to ask.

From NSA Recruit at 17 to CEO: The Making of a White-Hat Hacker
Vinnie Liu never broke into systems for thrills. He did it to understand them. That distinction, formed before he was a teenager, shaped a career that went from the NSA to running one of the most recognised offensive security firms in the business.

AI Is Cutting the Time Attackers Need to Exploit a Flaw. Defenders Haven't Caught Up.
Security vendor Picus argues defenders can no longer wait for public exploits or vendor fixes before acting.

Companies Are Spending More on Cyber 'Attack Drills' to Keep Up with AI-Powered Hackers
New research from Omdia finds 88% of organisations plan to increase spending on offensive security, as AI gives attackers a speed advantage that human-paced testing can no longer match.

After Russian Hackers Knocked Out a Satellite Network, an AI Tool Is Now Stress-Testing Its Defences
Viasat's satellite network was crippled by a Russian cyberattack in 2022. Now an AI-assisted security tool from Atalanta is being used to check whether the rebuilt defences can hold.

From Argentina's Early Hacking Scene to AI-Powered Offensive Security: The Nico Waisman Story
How a self-taught hacker with no formal training built his way to leading security at XBOW, a firm that uses artificial intelligence to find weaknesses before attackers do.

OpenAI hands a specialised hacking AI to a small club of security firms
GPT 5.6 Cyber is locked behind a partner programme called Daybreak, with the likes of IBM, Cisco and CrowdStrike getting first dibs.

The World's Greatest Detective Was Also the World's Greatest Con Artist
A cybersecurity professor dressed as Sherlock Holmes walked a DEF CON audience through why the tricks criminals use to manipulate people today are identical to what a Victorian fictional detective pulled off in the 1890s.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests isn't about finding weaknesses. It's about knowing which ones actually matter.

Patched Doesn't Mean Safe: Why Security Teams Need to Test After They Fix
A new survey of 750 security leaders finds that fewer than one in three organisations check whether a fix actually stopped an attacker. The gap between completing work and reducing risk is where breaches still happen.

Horizon3.ai Raises $250 Million as Demand for Automated Security Testing Grows
The cybersecurity firm behind autonomous penetration testing just landed a major funding round. Here is what the company does, why investors are paying attention, and what it means for the broader security market.

Bank of America Is Buying British Cybersecurity Firm MDSec
The US banking giant is acquiring a 65-person UK security consultancy, deepening its foothold in northern England and adding offensive security expertise to its in-house defences.

Frenos Raises $1.52 Million More to Test Factory and Power-Grid Security Without Touching the Real Thing
The startup runs fake cyberattacks inside a virtual copy of your industrial network, so it can find the dangerous paths before real criminals do.