Security Insights

Research, guides, and deep dives

Expert guidance on penetration testing, API security, and compliance for engineering and security teams.

Security Research

Verifying AI-Generated Code: Why Green Tests Prove Nothing

AI-generated code passes tests. Five real cases where it was inert: present, plausible, green on every gate, and doing nothing. How to verify by removal.

CyberOrbit TeamSep 7, 2026 · 19 min read
Security Testing

Only 9% Trust AI Pentesting Alone. Here's What the 91% Want

Trust in fully autonomous AI pentesting fell from 29% to 9% in a year. What the data measured, why it collapsed, and how to specify autonomy levels in an RFP.

CyberOrbit TeamSep 2, 2026 · 30 min read
Security Research

CVE-2026-62815 QUIC: Is UDP/443 In Your Pentest Scope?

August 2026 Patch Tuesday fixed a QUIC RCE at CVSS 9.8. QUIC runs on UDP/443, a port most external pentests never scan, ours included. How to check yours.

CyberOrbit ResearchSep 1, 2026 · 27 min read
Security Testing

Penetration Testing Frequency: Continuous vs Annual

How often should you pentest? A decision framework built on change velocity, exposure and your compliance floor, plus what continuous testing cannot prove.

CyberOrbit TeamAug 28, 2026 · 25 min read
Compliance

EU Cyber Resilience Act Penetration Testing: 2026 Guide

The CRA never mandates a pentest. Article 14's September 2026 reporting deadline requires a 24-hour clock and grandfathering doesn't cover legacy products.

CyberOrbit TeamAug 27, 2026 · 25 min read
Compliance

Netherlands NIS2 2026: The Cbw Is Live, No Grace Period

The Dutch Cyberbeveiligingswet entered force 15 August 2026 with no transition period. What the Cbw requires, who supervises you, and the evidence to file now.

CyberOrbit TeamAug 27, 2026 · 19 min read
Security Research

MLflow CISA KEV: Is Your AI Stack In Pentest Scope?

CISA added MLflow CVE-2026-64849 to the KEV catalog on 19 August 2026. Attackers steal cloud credentials via SSRF. What belongs in your AI/ML pentest scope.

CyberOrbit TeamAug 24, 2026 · 24 min read
Security Research

The 48-Hour Exploit Window: Nation-State Tempo for Everyone

CrowdStrike found 88% of PoC-based exploitation happens within 48 hours. Here is what that collapsed window actually changes for mid-market security teams.

CyberOrbit TeamAug 20, 2026 · 23 min read
Security Research

Fortinet Auth Bypass 2026: Is Your Perimeter In Scope?

Fortinet patched two auth bypasses in August 2026, on top of a January flaw that was exploited first. Patching closes them. Here is the scope language that decides whether your next pentest finds the next one.

CyberOrbit TeamAug 19, 2026 · 33 min read
Comparisons

PentAGI Alternative: Open-Source vs Managed Pentest

PentAGI is a strong open-source autonomous pentest agent. Here is what it costs to run, what it cannot produce, and when a signed independent report is needed.

CyberOrbit TeamAug 14, 2026 · 31 min read
Partners

MSP Penetration Testing Services: The Real Economics

Build a pentest practice, subcontract it, or resell white-label? The margin math for MSPs, the break-even numbers, and the one question that decides it.

CyberOrbit TeamAug 13, 2026 · 28 min read
Compliance

NIS2 Penetration Testing Requirements: The 2026 Guide

NIS2 never says "penetration testing". See what Article 21(2)(f) actually requires, where the binding rules live, and which national deadlines apply to you.

CyberOrbit TeamAug 11, 2026 · 27 min read
Security Testing

CTEM Penetration Testing 2026: What It Is, Where It Fits

CTEM is Gartner's five-phase exposure program. Here's what each phase does, where penetration testing fits in validation, and what mid-market teams need.

CyberOrbit TeamAug 5, 2026 · 26 min read
Compliance

DORA Penetration Testing Requirements: Fintech CISO Guide

Most fintechs are in DORA scope but not TLPT scope. See the Article 26 thresholds, what Article 24(6) annual testing requires, and the Article 25 test types supervisors accept.

CyberOrbit TeamJul 28, 2026 · 32 min read
Compliance

PCI DSS 4.0 Pentest Requirements: What QSAs Now Reject

PCI DSS 4.0 rejects pentest reports missing methodology, CVSS scores, proof of exploitation, or retest. Here are the 6 triggers, and the checklist to pass.

CyberOrbit TeamJul 28, 2026 · 30 min read
Threat Analysis

AI Agent Containment After the OpenAI Hugging Face Incident

What the OpenAI and Hugging Face incident teaches about AI agent containment, software dependencies, permissions and testing security controls in practice.

CyberOrbit TeamJul 26, 2026 · 7 min read
Comparisons

AWS Security Agent Pricing: Cost, Free Trial, and Coverage

As at Jul 2026, AWS Security Agent pentests cost about $50 per task-hour, roughly $1,200 for a typical app test on AWS's own example, plus a two-month free trial for new customers. What it covers and misses.

CyberOrbit TeamJul 24, 2026 · 31 min read
Compliance

Vanta Penetration Testing Providers: Independent, Audit-Ready

Comparing Vanta penetration testing providers? What makes a pentest independent and auditor-ready, with findings mapped to SOC 2, that drops into Vanta.

CyberOrbit TeamJul 23, 2026 · 23 min read
Security Testing

When Automated Pentesting Is Enough (and When It's Not)

Automated pentesting covers the systematic 80% for most mid-market teams. Here's when it's enough, when it's not, and the independence trap nobody names.

CyberOrbit TeamJul 22, 2026 · 22 min read
Security Testing

What Is Agentic Pentesting? The Definitive 2026 Guide

Agentic pentesting explained: what it is, how AI agents plan and exploit, how it differs from autonomous scanning, and what makes it audit-ready in 2026.

CyberOrbit TeamJul 21, 2026 · 23 min read
Security Testing

AI Pentest Report Trust: What Auditors Accept in 2026

AI pentest trust collapsed from 29% to 9% in a year. Here's what auditors actually accept in 2026 and a 10-question checklist to vet any AI pentest report.

CyberOrbit TeamJul 20, 2026 · 19 min read
Threat Intelligence

24 Billion Stolen Records: Your Credential Exposure Risk

24 billion credentials leaked in 2026. See what credential exposure means for your attack surface and how a pentest tests whether stolen logins still work.

CyberOrbit TeamJul 13, 2026 · 15 min read
Security Testing

LLM Penetration Testing: What Your Pentest Must Cover 2026

Shipping an AI chatbot or copilot? Your last pentest likely missed it. Learn what an LLM penetration test should cover in 2026 and what to ask your vendor.

CyberOrbit TeamJul 13, 2026 · 16 min read
Threat Analysis

Oracle PeopleSoft Vulnerability 2026: What a Pentest Catches

ShinyHunters exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) at NAIC and Nissan. Here's the exposure a penetration test would have caught first.

CyberOrbit TeamJul 13, 2026 · 14 min read
Compliance Guides

The Essential Eight Audit-Prep Checklist (With the Evidence Your Auditor Asks For)

A control-by-control Essential Eight audit checklist: what to do, the evidence an assessor asks for, and a self-check question for each of the eight strategies.

CyberOrbit TeamJul 6, 2026 · 18 min read
Pricing

Penetration Testing Cost in 2026: Real Numbers

Penetration tests cost $4K–$50K in 2026. Here's exactly what drives the price, what competing guides skip, and how AI pentesting cuts that bill by 90%.

CyberOrbit TeamApr 16, 2026 · 9 min read
Compliance

Is a Pentest Required for SOC 2? What Auditors Expect (2026)

SOC 2 doesn't require a pentest, but 94% of auditors expect one. Learn what evidence satisfies CC4.1 and CC7.1 in 2026 and how to get it affordably.

CyberOrbit TeamApr 16, 2026 · 8 min read
Compliance Guides

Essential Eight Penetration Testing: What Australian Organisations Need in 2026

Which Essential Eight controls require penetration testing? What do ACSC assessors expect as evidence? A control-by-control guide for Australian CISOs and MSPs.

CyberOrbit TeamApr 9, 2026 · 17 min read
Security Guides

How to Check Your Website's Security Headers (And Why It Matters)

Learn what HTTP security headers are, why they matter, and how to check and configure them. Covers HSTS, CSP, X-Frame-Options, Referrer-Policy, and more.

CyberOrbit TeamApr 5, 2026 · 11 min read

Explore by topic

#AI agent containment#AI governance#AI infrastructure security#AI offensive tooling#AI penetration testing#AI pentesting#AI security#AI-generated code#B2B SaaS#CISA KEV#CISO#CVE-2026-26035#CVE-2026-35273#CVE-2026-62815#CVE-2026-64849#CVE-2026-68820#CrowdStrike 2026#Hugging Face#LLM security#ML pipeline security#NIS2 directive#OWASP APTS#OWASP LLM Top 10#OpenAI#QUIC security#SOC 2#SSRF#account takeover#acsc#agentic engineering#agentic pentesting#agentic workload security#annual pentest#application security#attack surface#audit evidence#audit preparation#australia#authentication bypass#automated penetration testing#autonomous pentesting#aws penetration testing#aws security agent#breach analysis#cloud credential theft#cloud security#code review#compliance#continuous penetration testing#continuous threat exposure management#cost#cps 234#cra#credential exposure#credential stuffing#csp#ctem#cyber resilience act#cyberbeveiligingswet#cybersecurity#data breach#dora#e8 checklist#edge device security#essential eight#eu regulation#evidence#exploit window#exposure management#external attack surface#financial services#fintech#firewall penetration testing#fortinet#gartner#hsts#http security#hybrid pentesting#independent pentest#managed services#manual penetration testing#mid-market security#mlflow#msp#msp margin#mssp#multi-cloud#mutation testing#netherlands#network perimeter security#network security#nis2#open source security tools#oracle peoplesoft#partner program#password spraying#patch management#patch tuesday#payment security#pci dss#pci dss 11.4#pci dss 4.0#penetration testing#penetration testing frequency#penetration testing scope#pentagi#pentest cadence#pentest comparison#pentest report#pentest vendors#post-patch validation#pricing#product security#prompt injection#ptaas#qsa#requirement 11.4#sandbox egress#security audits#security controls#security headers#security strategy#security testing#self-hosted security#service catalog#shinyhunters#soc 2#third-party pentest#threat analysis#threat intelligence#threat-led penetration testing#tlpt#trust services criteria#validation#vanta#vendor evaluation#verification#vulnerability disclosure#vulnerability exploitation#web security#website hardening#white label penetration testing#windows server security#zero-day

The security writing, weekly

New posts as they land: findings from real assessments, what the regulatory changes actually mean, and the occasional teardown.

Privacy