Offensive Security stories
Enterprises face a growing backlog as AI tools uncover more flaws, with HackerOne saying 25% still prove exploitable and many are critical.
Rising AI-generated vulnerability reports are leaving security teams with record backlogs and only hours to judge which flaws hackers can exploit.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Pressure is growing on AI vendors and software suppliers to improve vulnerability disclosure as experts warn basic CVE details are no longer enough.
Security teams will get Claude tools inside TrendAI Vision One as the firms target AI-driven attacks and faster incident response.
Offensive AI is widening exposure gaps for firms that test only a third of their attack surfaces on average, Synack says.
Boards in regulated sectors now have firmer assurance after Abacus secured CREST approval for penetration testing, renewed annually.
Security researchers say long automated jobs can make Claude Code’s deny rules fall back to user prompts, weakening protections in CI/CD pipelines.
Security teams now have a beta tool to probe large language model apps for prompt injection, jailbreaks and data theft before attackers do.
Qualys debuts Agent Val to validate real exploit paths in live systems, promising sharply reduced noise and faster remediation for teams.
Qualys rolls out Agent Val to live‑test exploit paths in production, promising sharper risk prioritisation and major remediation noise cuts.
Simbian unveils an AI-driven cyber security platform uniting offence and defence via a shared Context Lake to speed, link and automate response.
Cobalt weaves AI into its pentesting platform, automating recon and triage while keeping human experts on complex attack paths.
Cobalt launches Security Program Manager service to run enterprise pentesting, align tests with business goals and speed up remediation.
NetSPI unveils an AI-powered overhaul of its pentesting platform UX, promising two-click workflows and sharper risk-based remediation focus.
HackerOne launches live Agentic Prompt Injection Testing to expose real-world AI exploit paths as prompt injection threats surge 540%.
Tenzai's autonomous AI agent has placed in the top 1% of major global hacking CTF contests, beating more than 125,000 human rivals.
Cloud identity compromise now drives over 80% of cyber incidents, as attackers increasingly abuse trusted accounts and workplace tools.
Demand for round-the-clock cyber defence is pushing Slipstream Cyber to strengthen its operations as attacks become faster and more complex.
Organisations test just a third of their attack surface as reliance on agentic AI grows, raising fresh concerns over unseen cyber risks.