Skip to content

Penetration Testing

How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

As organizations continue to expose authentication and account-recovery flows directly to the public internet, these flows remain some of the highest-value, least-forgiving attack surfaces on the web. A single unparameterized query can turn a login form into a full database read primitive. During a recent bug bounty assessment, this finding was surfaced by FireCompass’s Agentic… Read More »How FireCompass AI Agent Discovered a Critical SQL Injection in an Authentication and Password-Reset Flow

From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Modern web applications often expose numerous server-side components that invoke operating system utilities to process user requests. While these utilities simplify functionality, they also expand the attack surface when user-controlled input is passed into shell commands or embedded scripting engines without proper validation. During a recent private bug bounty engagement, FireCompass AI Agent autonomously identified… Read More »From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths

Forest-Root-Golden-Ticket-SID

Attack chain walkthrough: Forest root domain compromise via golden ticket with SID history

Most stakeholders treat a domain as a security boundary. It is not. The forest is. This walkthrough traces a single attack chain that started with domain-admin access already held in a child domain and ended with every credential in the environment dumped from the forest root. The pivot that made it possible was one forged… Read More »Attack chain walkthrough: Forest root domain compromise via golden ticket with SID history

FireCompass autonomous AI penetration testing agent reaching Top 3 on HackerOne US leaderboard on a $5,000 monthly budget

Press Release: AI Pentest Agent Reaches HackerOne’s Top 3 on a $5,000-a-Month Budget

FireCompass on HackerOne, US leaderboard highlights.   A three-month live experiment by FireCompass reached top-three positions across multiple HackerOne leaderboards, on a $5,000 monthly budget, less than a junior pen tester’s salary. BOSTON, July 28, 2026 /PRNewswire The cost of advanced offensive security is falling fast. In a three-month experiment on a live, authorized global… Read More »Press Release: AI Pentest Agent Reaches HackerOne’s Top 3 on a $5,000-a-Month Budget

FireCompass AI Agents reaching Top 3 on HackerOne leaderboard graphic

How FireCompass AI Agents Reached HackerOne’s Top 3 on $5,000 a Month: Full Methodology, Data, and Limitations

FireCompass Emerging Research. April to July 2026. For one quarter, we ran our AI agent on HackerOne, in the open, competing against human researchers and every other agent hunting the same targets. No lab. No curated benchmark. The agent competed as firecompass-ai on a compute budget of about $5,000 per month. By the July snapshot,… Read More »How FireCompass AI Agents Reached HackerOne’s Top 3 on $5,000 a Month: Full Methodology, Data, and Limitations