Blog

Security Insights

Deep dives, expert analysis, and practical guidance on exposure management, adversarial validation, and the future of AI-driven exposure management.

Biggest data breaches of September 2026 - Strobes
Data BreachesCybersecurity

Biggest data breaches of September 2026

153 million driver's licenses claimed, 23.6 million Gyazo records confirmed. September 2026's biggest breaches, with every number sourced.

Oct 6, 202618 min
How Strobes agents test Android apps on your own devices
Penetration TestingAI Security

Strobes Agentic Pentesting Now Tests Android Apps on Your Own Devices

Strobes Agentic Pentesting now runs Android app pentesting on your own phones and emulators: live crawling, traffic interception, Frida instrumentation, and verified findings.

Oct 6, 202612 min
Top CVEs September 2026: four zero-days, and patching was not the fix
CVEVulnerability Intelligence

Top CVEs of September 2026: Four Zero-Days, and Patching Wasn’t the Fix

Four of September 2026’s top five CVEs were exploited before a patch existed. Fix order, fixed builds, and the compromise check each one needs.

Oct 5, 202610 min
Strobes joins OpenAI Daybreak Trusted Access for Cyber program
AI SecurityOffensive Security

Strobes joins OpenAI's Daybreak program

OpenAI gates its cyber models behind an application, identity checks, and workspace scoping. Strobes is now verified for Daybreak.

Sep 28, 20264 min
Where your data goes during an AI pentest: agentic pentesting data security featured image
Penetration TestingAI Security

Where your data goes during an AI pentest

Session tokens, customer records, error traces. Here's exactly where that data goes during an agentic pentest, and what to ask any vendor.

Sep 24, 202623 min
Anthropic Cyber Verification Program at Strobes, verified since June 2026
AI Security

Three months inside Anthropic's Cyber Verification Program at Strobes

Strobes has run Claude-powered agentic pentests under Anthropic's Cyber Verification Program since June 2026. Here's what the program gates and what changed in three months.

Sep 21, 20263 min
Are security practitioners actually ready for autonomous pentesting - a field perspective from Strobes Security
Penetration TestingAI Security

Are security practitioners actually ready for autonomous pentesting?

We asked 50+ security leaders one open question about autonomous pentesting. Here is the readiness spectrum that came back, and what vendors get wrong.

Sep 10, 202611 min
NIST just published AI prompts for CSF 2.0, here is what to settle first. Strobes banner showing document, AI model, and shield icons with the six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover
ComplianceAI Security

NIST just published AI prompts for CSF 2.0. Here is what to settle first

NIST's draft SP 1353 provides AI prompts for three CSF 2.0 tasks and says weeks of drafting compresses into hours. Here is what the prompts can draft, what only humans can validate, and the four things to settle before anyone opens a model.

Sep 4, 20268 min
Top CVEs of August 2026 by Strobes: the vulnerabilities that mattered this month, what is actively exploited and what to remediate first
CVEVulnerability Intelligence

Top CVEs of August 2026

August's CVSS 7.0 was a Lazarus zero-day exploited for five weeks. Its CVSS 10.0 needed no patch at all. The top CVEs of August 2026, ranked by exploitation evidence rather than severity, with remediation steps for all five.

Sep 3, 202614 min
Biggest data breaches of August 2026, eight incidents and the exposure gaps attackers exploited
Data Breaches

Biggest data breaches of August 2026

284 million records claimed at McKesson, 12.9 million verified at Carhartt. The eight biggest data breaches of August 2026, with every number checked against a company statement, filing, or named outlet.

Sep 3, 202616 min