< ciso
brief />
Tag Banner

All news with #penetration testing tag

34 articles

AI Forces Continuous Offensive Security Practices

🔐 As AI-enabled attacks scale and accelerate, CISOs face a surge in exploitable vulnerabilities and must rethink vulnerability management. Experts argue that annual compliance pen tests are no longer sufficient; organizations need continuous, automated offensive security—pen testing, red teaming, and attack path validation—to prove exploitability in production. Human expertise remains critical to guide AI tools and develop future offensive security talent.
read more →

AWS Continuum Adds CI/CD Integrated Pentesting

🛠️ AWS Continuum for Penetration Testing (formerly AWS Security Agent) now offers public preview CI/CD integration that makes penetration testing a deploy-time event. The service delivers findings—including severity, affected endpoints, and remediation guidance—directly in pipeline output while avoiding meaningful delays for non-security changes. Teams can paste an auto-generated pipeline snippet into existing workflows and complete setup in under five minutes, with application context bootstrapped automatically on first run.
read more →

AWS expands Continuum penetration testing to six regions

🔒 AWS Continuum for Penetration Testing (AWS Security Agent) is now available in six additional Regions, enabling localized penetration testing for web applications and APIs. The expansion covers Asia Pacific (Seoul), Canada (Montreal), Europe (London), US East (Columbus), Europe (Paris), and Europe (Stockholm). Organizations can run testing closer to production to meet data residency and compliance needs while preserving existing Region support.
read more →

AWS Continuum adds pre-test credential discovery

🔒 AWS Continuum for penetration testing introduces a frontier agent that performs on-demand, customized penetration tests with real exploitability checks. The new capability authenticates using provided login credentials before a full test, capturing and suggesting all accessible domains reached during login to help define accurate network scope. Accessible domains are surfaced whether credential attempts succeed, fail, or time out, reducing misconfiguration and wasted test cycles.
read more →

CISO’s Guide to Agentic Pentesting and Governance

🔍 A new free guide explains how autonomous AI agents are accelerating exploit weaponization and why annual pentests are no longer sufficient. It highlights industry data showing attackers now exploit vulnerabilities within days while median patch times lag weeks, and outlines vendor criteria—provable coverage, independent validation, browser-native agents—and governance controls to safely adopt agentic testing. The guide also covers budget math, compliance benefits, and a 90-day adoption roadmap.
read more →

When Threat Intelligence Requires Active Validation

🔎 Intelligence alerts are valuable early signals, but the true problem is the queue of unvalidated items that allows risk to accumulate. Organizations often lack the time and offensive expertise to test each indicator, turning volume into backlog. Threat-led penetration testing (TLPT) reframes testing to validate current intelligence—confirming whether a leaked credential or disclosed vulnerability is exploitable in a specific environment. Practical integrations, such as Pentera with Recorded Future, automate validation runs to prioritize proof over probability.
read more →

Practical pen testing for GenAI, LLM and RAG apps

🛡️ This article outlines a practical, application-focused approach to penetration testing GenAI systems, emphasizing that prompts can be attack vectors. It recommends mapping architecture components (prompts, retrieval, embeddings, tools, APIs), defining strict rules of engagement and using canaries and synthetic data. Testers should treat prompt injection as multi-turn campaigns, evaluate RAG/vector stores and upstream ML pipelines, and automate repeatable attacks with controlled Python harnesses to preserve evidence and enable regression testing.
read more →

CREST accredits first cohort for AI pentesting

🛡️ CREST has awarded its new AI-Enabled Penetration Testing accreditation to 10 firms across Europe, India and the US as an optional module added to its Penetration Testing Accreditation Standard in July 2026. The module lets providers that integrate AI into pentesting undergo independent assessment to demonstrate responsible, secure AI governance to clients and regulators. CREST’s move follows its March 2026 report and subsequent AI Principles and June AI Charter.
read more →

AWS Security Agent adds cost controls and revalidation

🔒 AWS Security Agent (part of AWS Continuum) now offers two capabilities for its on-demand AI-driven penetration testing service: a configurable maximum task-hours limit and selective revalidation of findings. Teams can set preset or custom hour caps so tests stop gracefully when the limit is reached while preserving discovered findings and keeping billing tied to actual task-hours used. Individual findings from completed runs can be re-tested against the live application to confirm an Active or Resolved status, with full revalidation history linked to the original finding.
read more →

OpenAI unveils GPT‑5.6 Cyber for vetted security partners

🔒 OpenAI has released GPT 5.6 Cyber, a specialized model for vulnerability research, penetration testing, and incident response, available only to approved companies and security vendors. The offering includes two access tiers—Daybreak Blue for defensive workloads and Daybreak Red for tightly governed tasks—and will be integrated into partner tools and services rather than exposed to regular users. OpenAI emphasizes safeguards such as identity verification, scoped testing, logging, and human oversight to mitigate abuse.
read more →

AWS Security Agent adds email-based MFA pentesting

🛡️ AWS Security Agent (now part of AWS Continuum) can now automate penetration testing for applications that use email-based multi-factor authentication. The agent generates a unique forwarding address per credential so MFA messages can be routed to it via an email provider rule, allowing the agent to read and submit codes or links during a test without storing email account credentials. This complements existing TOTP support and is available in all Regions where the agent is supported.
read more →

CREST launches AI module for pentesting accreditation

🛡️ CREST has introduced optional AI-Enabled Penetration Testing requirements as an add-on to its existing Penetration Testing Accreditation Standard. Launched on July 28, the module lets providers that integrate AI undergo independent assessment to demonstrate responsible AI governance to clients and regulators. Applications are open to existing CREST members and accredited service providers seeking extra assurance for AI use.
read more →

AI Reveals a Validation Gap in Cybersecurity Skills

🔍 The article argues that cybersecurity faces a validation gap rather than a simple skills shortage, stressing that theoretical training and certifications can’t replicate real-world experience. It highlights risks from rapid AI deployment without governance, and notes many organizations lack visibility into AI breaches. The author advocates building continuous, hands-on cyber ranges with AI Proving Grounds, realistic environments, and post-exercise analysis to nurture and validate talent.
read more →

NCSC guidance to frustrate penetration testers

🔒 The NCSC asked pen testers what makes their work harder and published recommendations to boost organisational resilience. Responses emphasise secure-by-design practices—like threat modelling, phishing-resistant MFA, avoiding hard-coded credentials, and early input validation—alongside network segmentation and strong OT/IT separation. The guidance also highlights the critical role of quality logging, monitoring and exercised incident response to detect and respond to intrusions.
read more →

AWS Security Agent adds verification scripts

🔐 AWS Security Agent now generates verification scripts for penetration test findings to help teams reproduce and validate discovered vulnerabilities. The tool creates ready-to-run scripts for each confirmed finding that include setup instructions, documented environment variables, and redacted sensitive values. Teams download the script, configure variables, and execute it against targets to streamline triage and speed remediation. Verification scripts are available in all Regions where AWS Security Agent is supported.
read more →

AI Attack Capability Rising Faster Than Expected Per UK Tests

🔍 New benchmarks from the UK’s AI Security Institute (AISI) show leading AI models rapidly improving at multi-stage penetration testing, with the difficulty of tasks solvable by models doubling every 4.7 months as of early 2026. The tests measure the longest task an AI can complete with 80% success relative to human work-hours, emphasizing autonomous chaining of steps rather than raw speed. While there are caveats — token limits and inconsistent model performance — the findings highlight growing offensive and defensive implications for enterprise security.
read more →

Pwn2Own Berlin Day Two: Enterprise Zero‑Days Revealed

🔒 During day two of Pwn2Own Berlin 2026 at OffensiveCon (May 14–16), competitors earned $385,750 by exploiting 15 unique zero-day vulnerabilities across enterprise products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux. Cheng-Da Tsai (Orange Tsai) earned $200,000 by chaining three bugs to achieve remote code execution as SYSTEM on Exchange, while other researchers demonstrated privilege escalations on Windows and RHEL and exploited the NVIDIA Container Toolkit. The AI category also saw multiple successes against coding agents such as Cursor AI and OpenAI Codex. Under Pwn2Own rules all targets run the latest patched OS versions and vendors receive a 90-day disclosure window to issue fixes.
read more →

Why Automated Pentesting Hits a Validation Ceiling

🔍 The article, by Sila Ozeren Hacioglu of Picus Security, describes the 'PoC Cliff' where automated pentesting delivers strong initial results but rapidly dwindles after a few executions as its deterministic, chained approach exhausts favored attack paths. It contrasts that model with Breach and Attack Simulation (BAS), which runs thousands of independent, atomic tests to validate whether defenses actually detect and block techniques. The piece identifies six critical validation surfaces often left dark and gives three diagnostic vendor questions to close the gap.
read more →

AWS Security Agent Brings On-Demand Penetration Testing

🔐 AWS Security Agent is now generally available, offering on-demand, continuous penetration testing across AWS, Azure, GCP, other cloud providers, and on-premises environments. The service deploys autonomous AI agents that combine SAST, DAST, and active exploit attempts to validate findings, reduce false positives, and provide CVSS-scored, reproducible results. Pricing is metered at $50 per task-hour, the product supports authenticated flows via LLM-driven sign-ins, and includes automated remediation suggestions and pull requests to accelerate fixes.
read more →

AWS Security Agent: On-Demand Penetration Testing GA

🔒 AWS announced general availability of AWS Security Agent for on-demand penetration testing in six AWS Regions. The service runs autonomous, persistent AI agents that discover, validate, and report vulnerabilities using sophisticated multi-step attack scenarios tailored to each application, producing CVSS scores, reproduction steps, and remediation guidance. Previewed at re:Invent 2025, it aims to convert periodic manual testing into a continuous, scalable capability and supports multicloud and on-premises environments. New customers can try a 2-month free trial and review pricing and documentation to get started.
read more →