Penetration testing stories
AI is speeding up attacks as well as defence, with high-risk prompts and unsupervised agents exposing firms to new security gaps.
Boards face rising pressure to control shadow AI as attackers automate faster and security teams shift to continuous verification.
Access to ChatGPT and GPT-5.6 is being tightened for some accounts as OpenAI moves to hardware-backed passkeys amid rising phishing risk.
Tests on five models found a planted text string sharply reduced successful AI-led intrusions, cutting full compromise to 1% in an AWS range.
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
Security teams are being pressed to prove their defences work in live attacks, as spending scrutiny shifts from tools to real-world response.
The controlled trial could help security teams cut false positives and speed remediation as frontier AI moves beyond finding bugs to validating risk.
New tools for governing AI agents are moving to the fore as Google picks 33 cybersecurity startups for its first cybersecurity forum cohort.
The AWS badge could help XBOW win more enterprise deals as buyers seek continuous testing that shows which vulnerabilities are exploitable.
Firms with manually rotated ADFS certificates could still be exposed, as attackers may recover live signing keys and forge SAML logins.
The real risk is growing backlogs and patching delays, as AI speeds up exploit development faster than security teams can respond.
New safeguards will let Fable 5 block more harmful cyber prompts, as Anthropic also seeks a common scale for jailbreak risk.
Banks are seeing attackers favour stealthy access over ransomware, with a UK-specific exploit hitting nearly half of monitored sensors.
Boards are being pushed to rethink data platforms and cyber controls as AI adoption exposes Australian firms to faster attacks and stricter governance demands.
As AI spreads through core business functions, executives warn weak oversight could expose firms to deepfakes, fraud and costly incidents.
Industrial operators can now test cyber exposures without touching live systems, helping prioritise fixes that could prevent costly downtime.
The pilot could speed up vulnerability hunting across government systems, but it also leaves human teams to verify and fix each AI flag.
Managed service providers can now offer broader cyber security services without building their own security operations from scratch.
Security teams may be able to cut false alarms as Picus says its new platform proves whether a vulnerability can actually be exploited.
The recognition could help buyers identify cyber providers whose staff meet UK professional standards, amid skills shortages and crowded markets.