Penetration testing stories
Three-quarters of organisations now see third-party software as a top risk, as AI flaws and supply-chain gaps slow security fixes.
A new survey shows UK cyber chiefs now see agentic AI as the biggest near-term threat, prompting an expanded security summit.
As cyber tools become more powerful, Anthropic is limiting access while OpenAI is widening it, raising fresh fears over misuse.
Security teams are struggling to review surging AI-generated code, with 62% saying the workload is getting harder to manage.
Enterprises face a growing backlog as AI tools uncover more flaws, with HackerOne saying 25% still prove exploitable and many are critical.
Rising AI-generated vulnerability reports are leaving security teams with record backlogs and only hours to judge which flaws hackers can exploit.
Financial regulators are alarmed after Anthropic said Claude Mythos can uncover software flaws at machine speed, raising bank security risks.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Security teams are bracing for harder-to-stop attacks after the model found a Linux kernel flaw that had gone unnoticed for 27 years.
The update promises better software engineering and longer task handling for users, while keeping Claude Opus 4.7 at the same price.
Offensive AI is widening exposure gaps for firms that test only a third of their attack surfaces on average, Synack says.
A 1,151% jump in iOS injection attacks in late 2025 has put mobile identity checks under fresh pressure, iProov says.
Boards in regulated sectors now have firmer assurance after Abacus secured CREST approval for penetration testing, renewed annually.
Procurement teams in defence and critical infrastructure may now view White Rook Cyber more favourably after its CREST testing approval.
Security chiefs say unauthorised access to Anthropic AI's Mythos model shows generative tools could speed phishing, scanning and exploit discovery.
UK cyber security suppliers could gain access to regulated procurement frameworks under a new accreditation scheme based on staff competence.
UK regulators are racing to assess whether Anthropic’s Mythos model could speed up attacks on banks and unsettle financial stability.
Researchers could face legal uncertainty unless ministers modernise a 1990 cyber law that campaigners say is hindering defence and investment.
Customer data and service security may be at risk, as nearly one in five UK telecom web servers leak configuration details, a study finds.
Projects in Lunar Strategy’s network will now get earlier security checks, as Cyberscope moves into smart contract audits before token launches and expansion.