Offensive Security stories
The move aims to widen security coverage as firms struggle to test expanding attack surfaces quickly enough.
Enterprises using Microsoft Defender will get round-the-clock human-led threat hunting, as CrowdStrike also broadens its AI risk coalition across partners.
Security teams can now validate scanner findings in minutes as Intruder rolls out AI agents to cut false positives and speed remediation.
Businesses could face faster cyber attacks as experts warn Anthropic's leaked Mythos model may outpace remediation and widen governance gaps.
Three-quarters of organisations now see third-party software as a top risk, as AI flaws and supply-chain gaps slow security fixes.
As cyber tools become more powerful, Anthropic is limiting access while OpenAI is widening it, raising fresh fears over misuse.
Enterprises face a growing backlog as AI tools uncover more flaws, with HackerOne saying 25% still prove exploitable and many are critical.
Rising AI-generated vulnerability reports are leaving security teams with record backlogs and only hours to judge which flaws hackers can exploit.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Pressure is growing on AI vendors and software suppliers to improve vulnerability disclosure as experts warn basic CVE details are no longer enough.
Security teams will get Claude tools inside TrendAI Vision One as the firms target AI-driven attacks and faster incident response.
Offensive AI is widening exposure gaps for firms that test only a third of their attack surfaces on average, Synack says.
Boards in regulated sectors now have firmer assurance after Abacus secured CREST approval for penetration testing, renewed annually.
Security researchers say long automated jobs can make Claude Code’s deny rules fall back to user prompts, weakening protections in CI/CD pipelines.
Security teams now have a beta tool to probe large language model apps for prompt injection, jailbreaks and data theft before attackers do.
Qualys debuts Agent Val to validate real exploit paths in live systems, promising sharply reduced noise and faster remediation for teams.
Qualys rolls out Agent Val to live‑test exploit paths in production, promising sharper risk prioritisation and major remediation noise cuts.
Vulnerability exploitation has collapsed from years to hours, leaving organisations racing to fix exposed systems before attackers do.
Procurement teams in defence and critical infrastructure may now view White Rook Cyber more favourably after its CREST testing approval.
Demand for round-the-clock cyber defence is pushing Slipstream Cyber to strengthen its operations as attacks become faster and more complex.