Security testing stories
The beta gives pentesters controlled AI assistance inside Burp Suite, with approvals, logging and scope rules still enforced by the platform.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Security teams could cut testing delays to hours as Intruder's AI tool scans web apps for flaws from source code access.
Employees now face more realistic phone-based fraud tests as security teams can simulate vishing using local caller IDs and AI voices.
Cloud audits produced the highest critical finding rate, while every AI system tested showed vulnerabilities and web logic flaws rose sharply.
Governance features aim to help security teams prove AI controls to boards and regulators as shadow AI and agentic risks spread.
Critical vulnerability backlogs have swelled 29-fold, prompting a tool that sends fix plans into engineering systems and AI coding tools.
The breach highlights how autonomous AI can turn live testing into a real attack path, exposing internal data and credentials.
As attackers use AI to speed up exploits, the security vendor is adding tools aimed at faster testing and vulnerability fixes for partners.
Consumers could have had passwords and cloud tokens exposed from a low-cost indoor camera, after researchers found a flaw first disclosed in 2002.
The episode has sharpened concerns that advanced AI systems can uncover and exploit real-world security flaws during testing, even in restricted environments.
Developers may get patched code faster as Google's preview agent scans repositories, tests exploits and drafts fixes for review.
Businesses using AI coding tools face repeatable security gaps, as the new index found an average 15 vulnerabilities in each codebase.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
A faulty token check let low-privilege users view other applicants' identities, payment details and Social Security numbers in a financial onboarding app.
AI tools are speeding routine checks, but hidden business logic flaws and context-specific risks still need human testers to spot them.
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
Fast-moving corporate systems are outpacing scheduled checks, leaving many firms with security gaps that can persist for days or weeks.