Verifying AI-Generated Code: Why Green Tests Prove Nothing
AI-generated code passes tests. Five real cases where it was inert: present, plausible, green on every gate, and doing nothing. How to verify by removal.
Security Insights
Expert guidance on penetration testing, API security, and compliance for engineering and security teams.
AI-generated code passes tests. Five real cases where it was inert: present, plausible, green on every gate, and doing nothing. How to verify by removal.
Trust in fully autonomous AI pentesting fell from 29% to 9% in a year. What the data measured, why it collapsed, and how to specify autonomy levels in an RFP.
August 2026 Patch Tuesday fixed a QUIC RCE at CVSS 9.8. QUIC runs on UDP/443, a port most external pentests never scan, ours included. How to check yours.
How often should you pentest? A decision framework built on change velocity, exposure and your compliance floor, plus what continuous testing cannot prove.
The CRA never mandates a pentest. Article 14's September 2026 reporting deadline requires a 24-hour clock and grandfathering doesn't cover legacy products.
The Dutch Cyberbeveiligingswet entered force 15 August 2026 with no transition period. What the Cbw requires, who supervises you, and the evidence to file now.
CISA added MLflow CVE-2026-64849 to the KEV catalog on 19 August 2026. Attackers steal cloud credentials via SSRF. What belongs in your AI/ML pentest scope.
CrowdStrike found 88% of PoC-based exploitation happens within 48 hours. Here is what that collapsed window actually changes for mid-market security teams.
Fortinet patched two auth bypasses in August 2026, on top of a January flaw that was exploited first. Patching closes them. Here is the scope language that decides whether your next pentest finds the next one.
PentAGI is a strong open-source autonomous pentest agent. Here is what it costs to run, what it cannot produce, and when a signed independent report is needed.
Build a pentest practice, subcontract it, or resell white-label? The margin math for MSPs, the break-even numbers, and the one question that decides it.
NIS2 never says "penetration testing". See what Article 21(2)(f) actually requires, where the binding rules live, and which national deadlines apply to you.
CTEM is Gartner's five-phase exposure program. Here's what each phase does, where penetration testing fits in validation, and what mid-market teams need.
Most fintechs are in DORA scope but not TLPT scope. See the Article 26 thresholds, what Article 24(6) annual testing requires, and the Article 25 test types supervisors accept.
PCI DSS 4.0 rejects pentest reports missing methodology, CVSS scores, proof of exploitation, or retest. Here are the 6 triggers, and the checklist to pass.
What the OpenAI and Hugging Face incident teaches about AI agent containment, software dependencies, permissions and testing security controls in practice.
As at Jul 2026, AWS Security Agent pentests cost about $50 per task-hour, roughly $1,200 for a typical app test on AWS's own example, plus a two-month free trial for new customers. What it covers and misses.
Comparing Vanta penetration testing providers? What makes a pentest independent and auditor-ready, with findings mapped to SOC 2, that drops into Vanta.
Automated pentesting covers the systematic 80% for most mid-market teams. Here's when it's enough, when it's not, and the independence trap nobody names.
Agentic pentesting explained: what it is, how AI agents plan and exploit, how it differs from autonomous scanning, and what makes it audit-ready in 2026.
AI pentest trust collapsed from 29% to 9% in a year. Here's what auditors actually accept in 2026 and a 10-question checklist to vet any AI pentest report.
24 billion credentials leaked in 2026. See what credential exposure means for your attack surface and how a pentest tests whether stolen logins still work.
Shipping an AI chatbot or copilot? Your last pentest likely missed it. Learn what an LLM penetration test should cover in 2026 and what to ask your vendor.
ShinyHunters exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) at NAIC and Nissan. Here's the exposure a penetration test would have caught first.
A control-by-control Essential Eight audit checklist: what to do, the evidence an assessor asks for, and a self-check question for each of the eight strategies.
Penetration tests cost $4K–$50K in 2026. Here's exactly what drives the price, what competing guides skip, and how AI pentesting cuts that bill by 90%.
SOC 2 doesn't require a pentest, but 94% of auditors expect one. Learn what evidence satisfies CC4.1 and CC7.1 in 2026 and how to get it affordably.
Which Essential Eight controls require penetration testing? What do ACSC assessors expect as evidence? A control-by-control guide for Australian CISOs and MSPs.
Learn what HTTP security headers are, why they matter, and how to check and configure them. Covers HSTS, CSP, X-Frame-Options, Referrer-Policy, and more.
New posts as they land: findings from real assessments, what the regulatory changes actually mean, and the occasional teardown.