Security Insights

Research, guides, and deep dives

Expert guidance on penetration testing, API security, and compliance for engineering and security teams.

Threat Analysis

AI Agent Containment After the OpenAI Hugging Face Incident

OpenAI says its models escaped a test environment and reached Hugging Face production. The lesson is not a misconfiguration. It is an assumed-safe egress path.

CyberOrbit TeamJul 26, 2026 · 16 min read
Comparisons

AWS Security Agent Pentest: What It Covers and Misses

AWS Security Agent runs pentests inside your AWS accounts. Here's exactly what it covers, what sits outside its scope, and when you need an independent test.

CyberOrbit TeamJul 24, 2026 · 30 min read
Compliance

Vanta Penetration Testing: Will Your Auditor Accept It?

Vanta offers pentests two ways, bundled and via partners. Here's how to match the right one to your audit stage and get an independent report that drops into Vanta.

CyberOrbit TeamJul 23, 2026 · 21 min read
Security Testing

When Automated Pentesting Is Enough (and When It's Not)

Automated pentesting covers the systematic 80% for most mid-market teams. Here's when it's enough, when it's not, and the independence trap nobody names.

CyberOrbit TeamJul 22, 2026 · 22 min read
Security Testing

What Is Agentic Pentesting? The Definitive 2026 Guide

Agentic pentesting explained: what it is, how AI agents plan and exploit, how it differs from autonomous scanning, and what makes it audit-ready in 2026.

CyberOrbit TeamJul 21, 2026 · 21 min read
Security Testing

AI Pentest Report Trust: What Auditors Accept in 2026

AI pentest trust collapsed from 29% to 9% in a year. Here's what auditors actually accept in 2026 and a 10-question checklist to vet any AI pentest report.

CyberOrbit TeamJul 20, 2026 · 19 min read
Threat Intelligence

24 Billion Stolen Records: Your Credential Exposure Risk

24 billion credentials leaked in 2026. See what credential exposure means for your attack surface and how a pentest tests whether stolen logins still work.

CyberOrbit TeamJul 13, 2026 · 15 min read
Security Testing

LLM Penetration Testing: What Your Pentest Must Cover 2026

Shipping an AI chatbot or copilot? Your last pentest likely missed it. Learn what an LLM penetration test should cover in 2026 and what to ask your vendor.

CyberOrbit TeamJul 13, 2026 · 16 min read
Threat Analysis

Oracle PeopleSoft Vulnerability 2026: What a Pentest Catches

ShinyHunters exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) at NAIC and Nissan. Here's the exposure a penetration test would have caught first.

CyberOrbit TeamJul 13, 2026 · 14 min read
Compliance Guides

The Essential Eight Audit-Prep Checklist (With the Evidence Your Auditor Asks For)

A control-by-control Essential Eight audit checklist: what to do, the evidence an assessor asks for, and a self-check question for each of the eight strategies.

CyberOrbit TeamJul 6, 2026 · 19 min read
Pricing

Penetration Testing Cost in 2026: Real Numbers

Penetration tests cost $4K–$50K in 2026. Here's exactly what drives the price, what competing guides skip, and how AI pentesting cuts that bill by 90%.

CyberOrbit TeamApr 16, 2026 · 9 min read
Compliance

Is a Pentest Required for SOC 2? What Auditors Expect (2026)

SOC 2 doesn't require a pentest — but 94% of auditors expect one. Learn what evidence satisfies CC4.1 and CC7.1 in 2026 and how to get it affordably.

CyberOrbit TeamApr 16, 2026 · 8 min read
Compliance Guides

Essential Eight Penetration Testing: What Australian Organisations Need in 2026

Which Essential Eight controls require penetration testing? What do ACSC assessors expect as evidence? A control-by-control guide for Australian CISOs and MSPs.

CyberOrbit TeamApr 9, 2026 · 18 min read
Security Guides

How to Check Your Website's Security Headers (And Why It Matters)

Learn what HTTP security headers are, why they matter, and how to check and configure them. Covers HSTS, CSP, X-Frame-Options, Referrer-Policy, and more.

CyberOrbit TeamApr 5, 2026 · 12 min read

The security writing, weekly

New posts as they land: findings from real assessments, what the regulatory changes actually mean, and the occasional teardown.

Privacy