Skip to content

Penetration Testing

How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

As organizations continue to expose authentication and account-recovery flows directly to the public internet, these flows remain some of the highest-value, least-forgiving attack surfaces on the web. A single unparameterized query can turn a login form into a full database read primitive. During a recent bug bounty assessment, this finding was surfaced by FireCompass’s Agentic… Read More »How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Modern web applications often expose numerous server-side components that invoke operating system utilities to process user requests. While these utilities simplify functionality, they also expand the attack surface when user-controlled input is passed into shell commands or embedded scripting engines without proper validation. During a recent private bug bounty engagement, FireCompass AI Agent autonomously identified… Read More »From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Forest-Root-Golden-Ticket-SID

Attack chain walkthrough: Forest root domain compromise via golden ticket with SID history

Most stakeholders treat a domain as a security boundary. It is not. The forest is. This walkthrough traces a single attack chain that started with domain-admin access already held in a child domain and ended with every credential in the environment dumped from the forest root. The pivot that made it possible was one forged… Read More »Attack chain walkthrough: Forest root domain compromise via golden ticket with SID history

FireCompass autonomous AI penetration testing agent reaching Top 3 on HackerOne US leaderboard on a $5,000 monthly budget

Press Release: AI Pentest Agent Reaches HackerOne’s Top 3 on a $5,000-a-Month Budget

FireCompass on HackerOne, US leaderboard highlights.   A three-month live experiment by FireCompass reached top-three positions across multiple HackerOne leaderboards, on a $5,000 monthly budget, less than a junior pen tester’s salary. BOSTON, July 28, 2026 /PRNewswire The cost of advanced offensive security is falling fast. In a three-month experiment on a live, authorized global… Read More »Press Release: AI Pentest Agent Reaches HackerOne’s Top 3 on a $5,000-a-Month Budget

Firecompass ranked #1 AI on HackerOne. Read more →