Normal view
The Security Problem With AI Agents Is Delegated Authority
How Continuous Pentesting Became Standard Practice at Dow
A few years ago, Dow's cyber engineering team made the switch from point-in-time pentesting to continuous coverage for their high-value assets. How'd they do it? By partnering with Synack. And keep in mind this was before the recent wave of AI-powered pentesting solutions. Dow was ahead of the curve.
The post How Continuous Pentesting Became Standard Practice at Dow appeared first on Synack.
AI Pentesting Works. Building It Yourself Is the Hard Part.
AI pentesting works, but building it in-house is the hard part. Synack VP Chris Brown breaks down the reliability, token economics, model dependency and validation costs that come with building versus buying an AI pentesting capability.
The post AI Pentesting Works. Building It Yourself Is the Hard Part. appeared first on Synack.
Build vs. Buy AI Pentesting: Why Dow Chose to Partner With Synack
To hear both sides of the build vs buy debate around AI pentesting solutions, we spoke with Dow's cyber engineering team lead Dan Lacher and Synack's CTO Mark Kuhr. From Dow's perspective, Synack served as a force multiplier for a small internal red team. Meanwhile, building the Synack Autonomous Red Agent (Sara) from scratch definitely had some trial and error.
The post Build vs. Buy AI Pentesting: Why Dow Chose to Partner With Synack appeared first on Synack.
Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure
The AI Pentesting Platform Checklist for Regulated Enterprises
Regulated enterprises evaluating AI pentesting platforms should assess eight capabilities: FedRAMP Moderate authorization or higher, multi-framework compliance support, human-in-the-loop with agentic AI, verified zero-false-positive findings, bidirectional workflow integrations, self-service launch, auditable coverage visibility, and full offensive security platform capabilities. Vendors who can't clearly distinguish their AI from an automated scanner are likely selling exactly that.
The post The AI Pentesting Platform Checklist for Regulated Enterprises appeared first on Synack.
The Hidden Risk in Enterprise AI Agents: Ungoverned Context
The Hidden Costs of Building an AI Pentesting Solution
Most security teams underestimate what it costs to build an AI pentesting solution in house. People, AI token costs, infrastructure, and compliance gaps add up faster than the initial business case accounts for, and the hidden bill usually arrives in year two. Iβve been hearing the same question from security leaders lately. Theyβre all asking [β¦]
The post The Hidden Costs of Building an AI Pentesting Solution appeared first on Synack.
Why the Future of Pentesting Needs Humans and Agentic AI Working Together
Most enterprises test less than a third of their attack surface, and attackers have already moved to AI-speed offense. Agentic AI closes the coverage gap, but only when paired with human expertise: an AI-first, human-validated model that secures critical infrastructure without sacrificing operational safety.
The post Why the Future of Pentesting Needs Humans and Agentic AI Working Together appeared first on Synack.
GitLost: GitHubβs AI Agent Tricked Into Leaking Private Repository Data
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
Continuous Penetration Testing: What Security Leaders Need to Know
βContinuousβ has become the most stretched word in offensive security. This guide breaks down what continuous penetration testing means, why most of the market doesnβt deliver it, and how Synackβs Sara is bringing always-on, human-validated testing to the enterprise.
The post Continuous Penetration Testing: What Security Leaders Need to Know appeared first on Synack.