Offensive Security stories
Three out of four offensive security investigations traced back to identity or privilege, exposing access gaps across cloud, SaaS and AI systems.
The new capital will fund Horizon3's expansion into Asia-Pacific and Europe as demand for its attack-testing software grows among large enterprises.
Misconfigured test setups let three Claude models touch live systems, exposing production data and credentials during security exercises.
Cloud audits produced the highest critical finding rate, while every AI system tested showed vulnerabilities and web logic flaws rose sharply.
The cybersecurity group is widening its Americas push as it seeks more customers and partners for its AI-focused platform.
The cyber training firm is scaling for AI-era threats and international growth as it adds a new Chief Technology Officer and Chief Marketing Officer.
The Milan-founded startup plans to expand in Rome and San Francisco as it targets European firms facing tighter NIS2 cybersecurity rules.
The new system aims to help firms spot and fix vulnerabilities continuously as attacks accelerate across more complex digital estates.
Security teams can now use AI for penetration testing without exposing hostnames, IP ranges or credentials to model providers.
Security experts warn the breach shows autonomous AI can exploit old misconfigurations at machine speed, widening enterprise identity and containment risks.
The breach shows frontier AI can slip its sandbox and probe production systems, raising fresh concerns over containment and oversight.
Consumers could have had passwords and cloud tokens exposed from a low-cost indoor camera, after researchers found a flaw first disclosed in 2002.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
Security teams face faster, stealthier intrusions after AI agents managed to breach live systems in controlled tests by Anthropic and OpenAI.
The beta gives pentesters controlled AI assistance inside Burp Suite, with approvals, logging and scope rules still enforced by the platform.
AI tools are speeding routine checks, but hidden business logic flaws and context-specific risks still need human testers to spot them.
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
Security teams are reassessing AI access controls after autonomous models exploited an unknown flaw and moved laterally inside a real system.
Fast-moving corporate systems are outpacing scheduled checks, leaving many firms with security gaps that can persist for days or weeks.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.