Penetration testing stories
Offensive AI is widening exposure gaps for firms that test only a third of their attack surfaces on average, Synack says.
A 1,151% jump in iOS injection attacks in late 2025 has put mobile identity checks under fresh pressure, iProov says.
Boards in regulated sectors now have firmer assurance after Abacus secured CREST approval for penetration testing, renewed annually.
MSPs can now add 24/7 threat monitoring and incident response without building their own security operations centre, as Acronis goes global.
Sensitive chats and uploaded files could have been quietly leaked from ChatGPT via DNS tunnelling before OpenAI fixed the flaw.
Sensitive prompts and documents will stay out of model training as ExpressVPN enters AI software with an enclave-based service for Pro subscribers.
Security teams now have a beta tool to probe large language model apps for prompt injection, jailbreaks and data theft before attackers do.
Horizon3.ai doubles ARR as more than 5,200 organisations adopt its NodeZero platform, fuelled by MSSP demand and rising cyber risks.
NSS Labs warns many enterprise AI guardrails fail basic security tests, urging independent, real-world validation of protections.
Rapid7 warns that hands-on attacks against cellular IoT hardware can pivot through trusted modules to breach cloud and backend systems.
Qualys rolls out Agent Val to live‑test exploit paths in production, promising sharper risk prioritisation and major remediation noise cuts.
Simbian unveils an AI-driven cyber security platform uniting offence and defence via a shared Context Lake to speed, link and automate response.
UK regulators are racing to assess whether Anthropic’s Mythos model could speed up attacks on banks and unsettle financial stability.
Researchers could face legal uncertainty unless ministers modernise a 1990 cyber law that campaigners say is hindering defence and investment.
Customer data and service security may be at risk, as nearly one in five UK telecom web servers leak configuration details, a study finds.
Projects in Lunar Strategy’s network will now get earlier security checks, as Cyberscope moves into smart contract audits before token launches and expansion.
The expanded tie-up gives Collingwood extra protection for member and supporter data as cyber threats intensify across Australian sport.
Users can now query AI without prompts or files being exposed, as ExpressVPN moves beyond virtual private networks into confidential computing.
Demand for round-the-clock cyber defence is pushing Slipstream Cyber to strengthen its operations as attacks become faster and more complex.
Organisations test just a third of their attack surface as reliance on agentic AI grows, raising fresh concerns over unseen cyber risks.