Offensive Security stories
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
Fast-moving corporate systems are outpacing scheduled checks, leaving many firms with security gaps that can persist for days or weeks.
The pilot could speed up vulnerability hunting across government systems, but it also leaves human teams to verify and fix each AI flag.
Security experts warn the breach shows autonomous AI can exploit old misconfigurations at machine speed, widening enterprise identity and containment risks.
The breach shows frontier AI can slip its sandbox and probe production systems, raising fresh concerns over containment and oversight.
Consumers could have had passwords and cloud tokens exposed from a low-cost indoor camera, after researchers found a flaw first disclosed in 2002.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
Access to ChatGPT and GPT-5.6 is being tightened for some accounts as OpenAI moves to hardware-backed passkeys amid rising phishing risk.
Tests on five models found a planted text string sharply reduced successful AI-led intrusions, cutting full compromise to 1% in an AWS range.
Security teams are being pressed to prove their defences work in live attacks, as spending scrutiny shifts from tools to real-world response.
The controlled trial could help security teams cut false positives and speed remediation as frontier AI moves beyond finding bugs to validating risk.
New tools for governing AI agents are moving to the fore as Google picks 33 cybersecurity startups for its first cybersecurity forum cohort.
The AWS badge could help XBOW win more enterprise deals as buyers seek continuous testing that shows which vulnerabilities are exploitable.
Firms with manually rotated ADFS certificates could still be exposed, as attackers may recover live signing keys and forge SAML logins.
Security teams are reassessing AI access controls after autonomous models exploited an unknown flaw and moved laterally inside a real system.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Businesses may get security test results in hours as ITSEC Asia's new platform flags risks and keeps human consultants in the loop.
Boards are being pushed to rethink data platforms and cyber controls as AI adoption exposes Australian firms to faster attacks and stricter governance demands.