Skip to content

Penetration Testing

Implementing Agentic AI Pentesting While Managing Risk and Cost

Summary of a closed-door CISO roundtable, hosted by CISO Platform with FireCompass, August 2026. Held under Chatham House convention. Senior security leaders spent a session on three questions. What does it cost to run an AI pentesting agent at full speed? What has to be true architecturally before you point one at production. And what… Read More »Implementing Agentic AI Pentesting While Managing Risk and Cost

How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

As organizations continue to expose authentication and account-recovery flows directly to the public internet, these flows remain some of the highest-value, least-forgiving attack surfaces on the web. A single unparameterized query can turn a login form into a full database read primitive. During a recent bug bounty assessment, this finding was surfaced by FireCompass’s Agentic… Read More »How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Modern web applications often expose numerous server-side components that invoke operating system utilities to process user requests. While these utilities simplify functionality, they also expand the attack surface when user-controlled input is passed into shell commands or embedded scripting engines without proper validation. During a recent private bug bounty engagement, FireCompass AI Agent autonomously identified… Read More »From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Firecompass ranked #1 AI on HackerOne. Read more →