Skip to content

Offensive AI

How AI is used to attack, and how FireCompass AI agents run offensive security at scale.

Continuous Autonomous Pentesting: A 5-Step Workflow for 2026

Your annual pentest report landed in March. By April, three new shadow apps were live. By June, a developer pushed an unauthenticated API endpoint to production. By the time next year’s engagement kicks off, your attack surface has changed so much that the previous report is archaeology, not security. The question more security teams are… Read More »Continuous Autonomous Pentesting: A 5-Step Workflow for 2026

AI Agents Are Doing Real Work. Governing Them Is the Unsolved Problem

AI Agents Are Doing Real Work. Governing Them Is the Unsolved Problem

Insights from a closed-door roundtable on AI agent safety and governance, chaired by Bruce Schneier and hosted by FireCompass founder Bikash Barai. Participant comments are kept anonymous by agreement. The most useful thing about this roundtable was that nobody pretended to have the answer. A room of senior security leaders spent an hour on AI… Read More »AI Agents Are Doing Real Work. Governing Them Is the Unsolved Problem

Breach and attack simulation explained

Breach and Attack Simulation (BAS): What It Validates, and How It Differs from CART, AI Pen Testing, and COST

Plenty of organizations end a quarter with a clean Breach and Attack Simulation (BAS) dashboard and a real breach in the same window. That is not a contradiction. It is a category being asked to answer a question it was never built to answer. BAS tells you whether your controls catch known attacker techniques. That… Read More »Breach and Attack Simulation (BAS): What It Validates, and How It Differs from CART, AI Pen Testing, and COST

Before Google Cloud Backed gRPC for MCP, FireCompass Had Already Built It for Switchblade

Before Google Cloud Backed gRPC for MCP, FireCompass Built It for Our AI Agents

Early January, I published a deep dive into why we ripped out JSON-RPC and rewrote our Model Context Protocol (MCP) server using gRPC for our internal AI initiatives. The idea was simple: if you are building enterprise-grade agents, you cannot rely on the “guesswork” of dynamic JSON payloads. You need the strict guarantees of Protobufs.… Read More »Before Google Cloud Backed gRPC for MCP, FireCompass Built It for Our AI Agents

10 Questions to Ask Your AI Pen Testing Vendor Before You Sign

10 Questions to Ask Your AI Pen Testing Vendor Before You Sign

The shortlist looks identical. The architecture is not. Every AI pen test vendor on your shortlist will tell you their false positive rate is under five percent. Their demos will look impressive. Their decks will name the same frontier models. This is the problem. Frontier model access is commoditizing. Any team can wire an Anthropic,… Read More »10 Questions to Ask Your AI Pen Testing Vendor Before You Sign

Firecompass ranked #1 AI on HackerOne. Read more →