AI Pentesting for Compliance
Aikido's AI penetration testing platform offers continuous, autonomous security assessments that produce compliance-ready reports for most frameworks, though some requiring accredited human testers st…
Aikido's AI penetration testing platform offers continuous, autonomous security assessments that produce compliance-ready reports for most frameworks, though some requiring accredited human testers st…
Aikido acquires Root to secure the software supply chain by using AI-generated patches for open-source vulnerabilities. Root's agent-native system produces hundreds of verified CVE patches daily witho…
A supply-chain attack on the @mastra AI-agent ecosystem saw an attacker republish 141 packages with a malicious dependency that targeted crypto wallets. The incident highlights how AI coding tools lik…
A supply chain attack compromised over 140 npm packages in the @mastra scope, including @mastra/core with 918K weekly downloads, by injecting a malicious dependency that executes a postinstall script …
Aikido launched Code Audit, a tool that uses agentic AI to find multi-step, logic-based vulnerabilities in source code, filling the gap between SAST and pentesting. The release follows Anthropic's wit…
Anthropic released Claude Fable 5, a public version of its Mythos Preview model, routing cybersecurity prompts to a less capable Opus 4.8 model for safety. The release follows Mythos Preview's debut a…
Aikido's AI pentesting tool discovered a critical authentication bypass vulnerability in phpBB, affecting tens of millions of users across thousands of forums. The flaw, present in versions up to 3.3.…
AI SAST is a new category of static application security testing where an AI reasons about code to find vulnerabilities like IDORs and business logic flaws that traditional rules-based SAST misses. It…
A malicious npm package called codexui-android, disguised as a legitimate remote user interface for OpenAI Codex, exfiltrated developer authentication tokens by hiding malicious code in the published …
Independent security consultancy Doyensec found that Aikido's AI pentesting tool discovered 49 verified vulnerabilities versus XBOW's 31 in a head-to-head benchmark on two real applications, a 58% inc…
Critical evaluation framework for purchasing AI-powered penetration testing tools, warning that the market is fragmented and that vendors often use the same terms to describe different capabilities. I…