Skip to content

Offensive AI

How AI is used to attack, and how FireCompass AI agents run offensive security at scale.

Implementing Agentic AI Pentesting While Managing Risk and Cost

Summary of a closed-door CISO roundtable, hosted by CISO Platform with FireCompass, August 2026. Held under Chatham House convention. Senior security leaders spent a session on three questions. What does it cost to run an AI pentesting agent at full speed? What has to be true architecturally before you point one at production. And what… Read More »Implementing Agentic AI Pentesting While Managing Risk and Cost

Case Study: Attack Chaining from an External Web Application to an Internal Network Foothold

Theoretical vulnerability criticality does not matter. Here is one attack chain our AI agents ran that explains why. A Fortune 1000 organization put one public-facing back-office application in scope, in the tier that handles payouts and ledgers. Tested on its own, that application returned a short list of medium-severity findings. FireCompass agents also tested the… Read More »Case Study: Attack Chaining from an External Web Application to an Internal Network Foothold

Nine Programs, Nine Organizations, One Forgotten DNS Record: How FireCompass’s Agentic AI Penetration Testing Found Subdomain Takeover Risk Across Five Cloud and CDN Providers

Introduction A subdomain takeover starts with a decommissioning step nobody remembered to do. A team points a company subdomain at a third-party resource, a CDN edge, a cloud app, a storage bucket, a static-site build, and later deletes or renames that resource without ever removing the DNS record that pointed to it. The subdomain keeps… Read More »Nine Programs, Nine Organizations, One Forgotten DNS Record: How FireCompass’s Agentic AI Penetration Testing Found Subdomain Takeover Risk Across Five Cloud and CDN Providers

Shipped to the Browser: How FireCompass’s Agentic AI Penetration Testing Found API Keys and Signing Secrets Hardcoded Into Client-Side Code Across Ten Independent Programs

Every browser tab runs code the vendor chose to send to it, and everything in that code is visible to whoever opens developer tools, reads a source map, or decompiles the bundle. A recurring and often underestimated class of exposure is what happens when that shipped code, or a config response it calls, carries something… Read More »Shipped to the Browser: How FireCompass’s Agentic AI Penetration Testing Found API Keys and Signing Secrets Hardcoded Into Client-Side Code Across Ten Independent Programs

Firecompass ranked #1 AI on HackerOne. Read more →