11 hours ago • Pentest-Tools

The US Department of Defense just credited Specter, our AI pentesting engine, with finding a vulnerability through HackerOne. 🎯

A successful AI pentest needs more than good prompts. Full story: https://pentest-tools.com/features/ai...

4 days ago • Pentest-Tools

Cleaning up after AI is basically a job now. Who would have figured?
1 in 4 practitioners reworks more than 25% of what AI tools produce, according to our AI pentesting survey: https://pentest-tools.com/insights/ai... 

Does that track for you?

#offensivesecurity #cybersecurity #penetrationtesting

It checks out (I'm 1 in 4)

I've seen it happen

I can see this happening

I don't believe it

1 vote

5 days ago • Pentest-Tools

Bucharest Cybersecurity Conference 2026 is where some of the sharpest offensive security conversations in the region happen, and that's the main reason we're contributing as Gold sponsors this year.

October 20-22, Bucharest. The Pentest-Tools.com team will be there talking AI pentesting, compliance, and reporting pressure. Autonomous AI agents in offensive operations are on this year's agenda too, so come find out how AI Pentests by Specter works.

Thanks to DNSC Romania for hosting.

Register: https://bcc.dnsc.ro/

6 days ago • Pentest-Tools

DEF CON asked how it works.
Black Hat asked what it proves.
Everyone asked: who sees the data?

That question gets to the heart of AI pentesting: trust.

Our answer:
✅ frontier LLMs, run in the US
✅ we validate exploits, not flag guesses
✅ a decade of offensive security work, not a prompt wrapped in a UI

Robert Tanase and Jan Pedersen unpack what we learned at DEF CON and Black Hat, and what's next for AI Pentests, on our latest Office Hours.

Full recap and early access: https://pentest-tools.com/blog/ai-pen...

#offensivesecurity #penetrationtesting

11 days ago • Pentest-Tools

We surveyed 201 security and compliance practitioners on what audit cycles actually look like. Nearly 9 in 10 partially remap evidence by hand or re-document it per framework.

Free findings, no email required:
https://pentest-tools.com/insights/co...

12 days ago • Pentest-Tools

At some point, one of these LLM choices became the tool you reach for without thinking. Let's settle it by vote.

Which LLM do you use for security testing activities?

Claude

ChatGPT

Gemini

A different one (tell us)

6 votes

13 days ago • Pentest-Tools

Last month we made a bit of history, and for once it wasn't a CVE. We were the first Romanian company ever to have a booth at DEF CON, showing AI Pentests, powered by Specter, to a room full of people whose entire job is finding what's wrong with things. Still in beta, early access is open now.

What else happened in August, you asked?

🎯 Sniper added a new exploit for CVE-2021-35464, a five-year-old RCE in Forgerock OpenAM that's still alive in the wild. As always, if Sniper can exploit it, the Network Scanner can detect it.
🌐 155 new detections in the Network Scanner, 70 of them critical, prioritized by CVSS, EPSS, and CISA KEV.
🤖 AI is picking up more of the boring work: the Password Auditor now finds stubborn login forms on its own, and our AI Ping Assistant moved from the website straight into the product.
🔌 The findings API can now update risk and verified status, findings carry a ransomware-campaign flag straight from CISA, and you can create your account in the US region if data residency matters to you.

Full breakdown in the changelog: https://pentest-tools.com/change-log
Early access to AI Pentests: https://pentest-tools.com/discover-ai...

Until next time: stay sharp, stay human.

🎰 August 2026 on Pentest-Tools.com: 155 new detections, our DEF CON debut, and AI inside the product

Pentest-Tools

13 days ago • 202 views

2 weeks ago • Pentest-Tools

If you've been here for a while, you know we're a very matter-of-fact team. That's why we'd rather *show* you what we build through *how it works* (aka results).

So today we're taking a moment to celebrate our latest bug bounty acknowledgements:

The #offensivesecurity logic behind AI Pentests has earned thanks from the U.S. Department of Defense, HPE, F5, phpBB, PepsiCo, and others through bug bounty programs.

Behind them are real reports we submitted to real programs based on work that requires 

✅ investigation, 
✅ reproducible evidence, 
✅ and clear impact.

This approach shapes every AI pentest: 

follow the evidence → validate exploitability → document each step before a finding reaches the report.  

Thank you to the program teams who reviewed and acknowledged AI Pentests!

See what we built + links to our bug bounty right here: https://pentest-tools.com/features/ai...

2 weeks ago • Pentest-Tools

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

👉 CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
👉 CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3* 
👉 CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🤏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: https://psirt.global.sonicwall.com/vu... 

And here's where you can get more of our research: https://pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫵

3 weeks ago • Pentest-Tools

Attackers have their own model for prioritizing vulnerabilities. They don't ask “How many vulnerabilities can I find?” but “Which of these gives me a viable path forward - and what can I actually do with it?”

CISA just issued an important reminder on this in their Vulnerability Review. 👇️

Attackers concentrate on a smaller set of weaknesses that give them reliable, repeatable paths to exploitation.

Because #offensivesecurity practitioners think in much the same way, they can help security teams get much more value from their limited resources.

How?

By giving them the proof they can use to prioritize what’s exposed, exploitable, and impactful.

CISA’s full FY2024–2025 Vulnerability Review: https://www.cisa.gov/sites/default/fi...