AI Agent Containment After the OpenAI Hugging Face Incident
OpenAI says its models escaped a test environment and reached Hugging Face production. The lesson is not a misconfiguration. It is an assumed-safe egress path.
Security Insights
Expert guidance on penetration testing, API security, and compliance for engineering and security teams.
OpenAI says its models escaped a test environment and reached Hugging Face production. The lesson is not a misconfiguration. It is an assumed-safe egress path.
AWS Security Agent runs pentests inside your AWS accounts. Here's exactly what it covers, what sits outside its scope, and when you need an independent test.
Vanta offers pentests two ways, bundled and via partners. Here's how to match the right one to your audit stage and get an independent report that drops into Vanta.
Automated pentesting covers the systematic 80% for most mid-market teams. Here's when it's enough, when it's not, and the independence trap nobody names.
Agentic pentesting explained: what it is, how AI agents plan and exploit, how it differs from autonomous scanning, and what makes it audit-ready in 2026.
AI pentest trust collapsed from 29% to 9% in a year. Here's what auditors actually accept in 2026 and a 10-question checklist to vet any AI pentest report.
24 billion credentials leaked in 2026. See what credential exposure means for your attack surface and how a pentest tests whether stolen logins still work.
Shipping an AI chatbot or copilot? Your last pentest likely missed it. Learn what an LLM penetration test should cover in 2026 and what to ask your vendor.
ShinyHunters exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) at NAIC and Nissan. Here's the exposure a penetration test would have caught first.
A control-by-control Essential Eight audit checklist: what to do, the evidence an assessor asks for, and a self-check question for each of the eight strategies.
Penetration tests cost $4K–$50K in 2026. Here's exactly what drives the price, what competing guides skip, and how AI pentesting cuts that bill by 90%.
SOC 2 doesn't require a pentest — but 94% of auditors expect one. Learn what evidence satisfies CC4.1 and CC7.1 in 2026 and how to get it affordably.
Which Essential Eight controls require penetration testing? What do ACSC assessors expect as evidence? A control-by-control guide for Australian CISOs and MSPs.
Learn what HTTP security headers are, why they matter, and how to check and configure them. Covers HSTS, CSP, X-Frame-Options, Referrer-Policy, and more.
New posts as they land: findings from real assessments, what the regulatory changes actually mean, and the occasional teardown.