Penetration testing stories
HackerOne warns of widening AI security & testing gap
3 days ago
#
devops
#
digital transformation
#
cloud security
HackerOne warns AI rollouts are outpacing security, with 89% of organisations lacking full testing and incidents driving up costs.
Terra Security gains first AWS nod for AI threat tests
Last week
#
network infrastructure
#
devops
#
hyperscale
Terra Security becomes first AWS partner validated for Autonomous Security Validation, as AI-driven continuous threat testing gains pace.
Survey shows pentesters favour PTaaS over bug bounties
Last week
#
devops
#
application security
#
devsecops
New research from Cobalt finds 98% of surveyed pentesters prefer PTaaS to bug bounties and show almost no faith in AI-only security scanning.
Agentic AI boosts elite cyber teams but hinders rookies
Last week
#
devops
#
apm
#
risk & compliance
Agentic AI massively accelerates elite cyber teams but can slow inexperienced hackers, Hack The Box's large-scale benchmark reveals.
LevelBlue & Tenable expand exposure tools for partners
Last week
#
devops
#
digital transformation
#
cloud security
LevelBlue debuts Exposure Management for Partners with Tenable, giving MSSPs and MSPs tiered, unified exposure and risk visibility tools.
Reversec names Åse Holmberg Zetterlund as Chief Executive
Last week
#
devops
#
partner programmes
#
supply chain
Cyber consultancy Reversec has named former Accenture executive Åse Holmberg Zetterlund as CEO to drive its next phase of global expansion.
Why cybersecurity needs women from non-tech careers
Last week
#
ransomware
#
devops
#
advanced persistent threat protection
Cybersecurity is missing vital human insight; drawing in women and non‑STEM talent could close both the threat and perspective gaps.
The power of representation in cybersecurity
Last week
#
firewalls
#
devops
#
network security
As cyber threats grow, more women are entering security roles, yet leadership remains male-dominated, risking lost talent and weaker defences.
LevelBlue unveils flexible funds-based cyber IR retainer
Last week
#
ransomware
#
devops
#
apm
LevelBlue launches Resilience Retainer, a flexible funds-based cyber incident response service with rapid SLAs and rollover security spend.
Why diversity in cybersecurity leadership is vital
Last week
#
devops
#
apm
#
risk & compliance
Homogeneous cybersecurity leadership is a critical, overlooked point of failure; true defence in depth demands diversity as a core control.
F5 Labs unveils monthly AI model security leaderboards
Last week
#
data protection
#
devops
#
application security
F5 Labs launches monthly AI security leaderboards, ranking popular models on new indices of risk, resilience and cost under live attack.
Security debt surges as legacy vulnerabilities pile up
Last month
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
Simbian unveils AI agent for continuous pentesting
Last month
#
data protection
#
devops
#
application security
Simbian launches an AI Pentest Agent that runs continuous, adaptive penetration tests, promising faster, context-aware vulnerability detection.
3DiVi sets four-layer defence for face authentication
Last month
#
data protection
#
devops
#
surveillance
3DiVi unveils four-layer defence model to harden face authentication against deepfakes and spoofing as remote ID checks surge globally.
CompTIA launches SecAI+ to tackle AI security skills
Last month
#
malware
#
data protection
#
devops
CompTIA unveils SecAI+ certification to equip cybersecurity professionals with AI security, risk management and governance skills.
Hackers ditch noisy ransomware for stealthy data theft
Last month
#
firewalls
#
data protection
#
dr
Hackers are abandoning noisy ransomware to quietly steal data, as a report finds 80% of top attack techniques now focus on evasion.
Cyber firms face 'verification crisis' on real risk
Last month
#
firewalls
#
devops
#
digital transformation
Cyber firms warned over 'verification crisis' as tools flag floods of flaws but only 0.47% prove exploitable, leaving real risk unresolved.
Bitget, BlockSec unveil new security standard for UEX
Last month
#
devops
#
surveillance
#
crypto
Bitget and BlockSec launch a UEX Security Standard, urging provable, system-wide safeguards for unified multi-asset trading platforms.
SpecterOps unveils BloodHound Scentry identity risk service
Last month
#
devops
#
pam
#
cloud security
SpecterOps has launched BloodHound Scentry, a managed identity risk service to find and remediate attack paths across complex environments.
Flare sees rapid MSSP uptake of external threat intel
Last month
#
devops
#
soc
#
partner programmes
Flare reports 114% annual growth among MSSPs as providers consolidate threat intelligence tools to boost services without extra analyst strain.