Blog

Security Insights

Deep dives, expert analysis, and practical guidance on exposure management, adversarial validation, and the future of AI-driven exposure management.

Anthropic Cyber Verification Program at Strobes, verified since June 2026
AI Security

Three months inside Anthropic's Cyber Verification Program at Strobes

Strobes has run Claude-powered agentic pentests under Anthropic's Cyber Verification Program since June 2026. Here's what the program gates and what changed in three months.

Sep 21, 20263 min
Are security practitioners actually ready for autonomous pentesting - a field perspective from Strobes Security
Penetration TestingAI Security

Are security practitioners actually ready for autonomous pentesting?

We asked 50+ security leaders one open question about autonomous pentesting. Here is the readiness spectrum that came back, and what vendors get wrong.

Sep 10, 202611 min
NIST just published AI prompts for CSF 2.0, here is what to settle first. Strobes banner showing document, AI model, and shield icons with the six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover
ComplianceAI Security

NIST just published AI prompts for CSF 2.0. Here is what to settle first

NIST's draft SP 1353 provides AI prompts for three CSF 2.0 tasks and says weeks of drafting compresses into hours. Here is what the prompts can draft, what only humans can validate, and the four things to settle before anyone opens a model.

Sep 4, 20268 min
Top CVEs of August 2026 by Strobes: the vulnerabilities that mattered this month, what is actively exploited and what to remediate first
CVEVulnerability Intelligence

Top CVEs of August 2026

August's CVSS 7.0 was a Lazarus zero-day exploited for five weeks. Its CVSS 10.0 needed no patch at all. The top CVEs of August 2026, ranked by exploitation evidence rather than severity, with remediation steps for all five.

Sep 3, 202614 min
Biggest data breaches of August 2026, eight incidents and the exposure gaps attackers exploited
Data Breaches

Biggest data breaches of August 2026

284 million records claimed at McKesson, 12.9 million verified at Carhartt. The eight biggest data breaches of August 2026, with every number checked against a company statement, filing, or named outlet.

Sep 3, 202616 min
How to automate pentest reporting without losing report quality
Penetration TestingAI Security

How to automate pentest reporting without losing report quality

Report quality is decided before the reporting layer runs. Here's the pipeline, the gates that stop bad output shipping, and what a real automated report contains.

Sep 1, 202615 min
Build vs buy agentic pentesting: building got cheap, owning what you built did not
Penetration TestingOffensive Security

Build vs Buy Agentic Pentesting and What the DIY Path Costs

Everyone can build a working pentest agent in a weekend. Owning it for two years is the hard part: the four costs nobody adds up, and the seven requirements a demo never has to meet.

Aug 31, 202619 min
How to Achieve Cheaper, Faster and Accurate Pentests
Penetration TestingOffensive Security

How to Achieve Cheaper, Faster and Accurate Pentests

Cheaper, faster and accurate pentests were never a real tradeoff. Context removes it: one graph of assets, code and cloud that every engagement reads from and writes back to.

Aug 21, 202623 min
Agentic pentesting POC playbook: ten working days, four test blocks, and a 19-criterion scorecard
Penetration TestingOffensive Security

How to run an agentic pentesting POC

A 10-day testing playbook to evaluate agentic pentesting vendors: what to test each day, the red flags to watch for, and a scorecard that works with any vendor.

Aug 11, 202634 min
Tooling as Code and Structured Scratchpads
engineeringOffensive Security

Tooling as Code and Structured Scratchpads

The two changes that moved our AI security agents furthest this year had nothing to do with the model. Here is how tooling as code and structured scratchpads reshaped how the agents act, and how they prove a finding is real.

Aug 3, 202615 min