Offensive Security stories
Cloud identity compromise now drives most cyber attacks
Today
#
malware
#
uc
#
firewalls
Cloud identity compromise now drives over 80% of cyber incidents, as attackers increasingly abuse trusted accounts and workplace tools.
Terra Portal blends AI agents with human-led pentesting
Yesterday
#
firewalls
#
devops
#
network security
Terra Security unveils Terra Portal, a desktop hub fusing AI agents with human pentesters to speed vulnerability fixes from months to hours.
Terra Security names Anna Sarnek VP of business strategy
3 days ago
#
firewalls
#
network infrastructure
#
devops
Terra Security appoints Anna Sarnek VP of business strategy to steer partner-led growth and define its AI-native offensive security push.
Terra Security gains first AWS nod for AI threat tests
Last week
#
network infrastructure
#
devops
#
hyperscale
Terra Security becomes first AWS partner validated for Autonomous Security Validation, as AI-driven continuous threat testing gains pace.
Survey shows pentesters favour PTaaS over bug bounties
Last week
#
devops
#
application security
#
devsecops
New research from Cobalt finds 98% of surveyed pentesters prefer PTaaS to bug bounties and show almost no faith in AI-only security scanning.
Agentic AI boosts elite cyber teams but hinders rookies
Last week
#
devops
#
apm
#
risk & compliance
Agentic AI massively accelerates elite cyber teams but can slow inexperienced hackers, Hack The Box's large-scale benchmark reveals.
LevelBlue & Tenable expand exposure tools for partners
Last week
#
devops
#
digital transformation
#
cloud security
LevelBlue debuts Exposure Management for Partners with Tenable, giving MSSPs and MSPs tiered, unified exposure and risk visibility tools.
LevelBlue unveils flexible funds-based cyber IR retainer
Last week
#
ransomware
#
devops
#
apm
LevelBlue launches Resilience Retainer, a flexible funds-based cyber incident response service with rapid SLAs and rollover security spend.
Anthropic unveils Claude Code Security to scan codebases
Last month
#
devops
#
cloud security
#
application security
Anthropic unveils Claude Code Security, an AI tool that scans codebases for complex bugs, verifies risks and suggests patches for developers.
Horizon3.ai names Dan Bird MBE Field CTO for EMEA cyber push
Last month
#
devops
#
digital transformation
#
hyperscale
Horizon3.ai appoints defence veteran Dan Bird MBE as EMEA field CTO to sharpen offensive security amid rising regional cyber threats.
CompTIA launches SecAI+ to tackle AI security skills
Last month
#
malware
#
data protection
#
devops
CompTIA unveils SecAI+ certification to equip cybersecurity professionals with AI security, risk management and governance skills.
Bitget, BlockSec unveil new security standard for UEX
Last month
#
devops
#
surveillance
#
crypto
Bitget and BlockSec launch a UEX Security Standard, urging provable, system-wide safeguards for unified multi-asset trading platforms.
SpecterOps unveils BloodHound Scentry identity risk service
Last month
#
devops
#
pam
#
cloud security
SpecterOps has launched BloodHound Scentry, a managed identity risk service to find and remediate attack paths across complex environments.
AI security drives demand for faster pentesting models
Fri, 30th Jan 2026
#
devops
#
digital transformation
#
cloud security
AI security fears and rapid release cycles are pushing firms to demand faster, deeper pentesting - and many are ready to ditch existing vendors.
HackerOne unveils AI‑driven continuous pentesting service
Thu, 29th Jan 2026
#
devops
#
cloud security
#
application security
HackerOne launches Agentic PTaaS, blending AI agents with human experts to deliver continuous, always-on penetration testing for enterprises.
AI reshapes data privacy as firms shift to real-time defence
Thu, 29th Jan 2026
#
saas
#
data protection
#
devops
AI-driven cloud adoption is forcing firms to swap static privacy checklists for continuous, real-time defence of sensitive data flows.
UK bill accelerates shift to offensive cyber security
Sat, 24th Jan 2026
#
firewalls
#
endpoint protection
#
devops
New UK cyber bill pushes critical sectors towards continuous offensive security testing as state-backed and criminal threats intensify.
Misconfigured cloud training labs open paths to attacks
Fri, 23rd Jan 2026
#
firewalls
#
hyperscale
#
cloud security
Misconfigured cloud training labs on AWS, Google Cloud and Azure expose major firms to live attacks via overly permissive access roles.
Agentic AI double agents expose dangerous security gaps
Wed, 14th Jan 2026
#
application security
#
devsecops
#
supply chain
Agentic AI promises rapid software gains, but a recent Claude Code cyberattack shows how “double agents” can outpace unprepared developers.
Astra unveils cloud scanner to cut misconfig alert noise
Mon, 12th Jan 2026
#
devops
#
hyperscale
#
cloud security
Astra launches a continuous cloud scanner for AWS, Azure and GCP, promising fewer false alerts by validating which risks are truly exploitable.