<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Strobes Security Blog</title>
    <link>https://strobes.co/blog</link>
    <description>Insights on cybersecurity, vulnerability management, CTEM, and exposure management from the Strobes Security team.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 17 Aug 2026 23:21:38 GMT</lastBuildDate>
    <atom:link href="https://strobes.co/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to run an agentic pentesting POC</title>
      <link>https://strobes.co/blog/agentic-pentesting-poc</link>
      <guid isPermaLink="true">https://strobes.co/blog/agentic-pentesting-poc</guid>
      <description>A 10-day testing playbook to evaluate agentic pentesting vendors: what to test each day, the red flags to watch for, and a scorecard that works with any vendor.</description>
      <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/agentic-pentesting-poc-playbook-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Keyv and Cacheable Supply Chain Attack Explained</title>
      <link>https://strobes.co/blog/keyv-cacheable-npm-supply-chain-attack</link>
      <guid isPermaLink="true">https://strobes.co/blog/keyv-cacheable-npm-supply-chain-attack</guid>
      <description>An attacker hijacked the keyv and cacheable npm packages on August 4, 2026, shipping a credential stealer with valid provenance. Here&apos;s how to respond.</description>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/keyv-cacheable-npm-supply-chain-attack.webp" type="image/jpeg" />
    </item>
    <item>
      <title>Tooling as Code and Structured Scratchpads</title>
      <link>https://strobes.co/blog/tooling-as-code-structured-scratchpads</link>
      <guid isPermaLink="true">https://strobes.co/blog/tooling-as-code-structured-scratchpads</guid>
      <description>The two changes that moved our AI security agents furthest this year had nothing to do with the model. Here is how tooling as code and structured scratchpads reshaped how the agents act, and how they prove a finding is real.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <author>Strobes Security</author>
      <enclosure url="https://strobes.co/api/media/file/Tooling%20as%20Code%20and%20Structured%20Scratchpads.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top CVEs of July 2026</title>
      <link>https://strobes.co/blog/top-cves-july-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-cves-july-2026</guid>
      <description>Five CVEs defined July 2026, ranked by what attackers actually exploited, not CVSS: an AD FS zero-day, twin SharePoint RCEs, a May patch that became a July KEV deadline, and the month&apos;s highest score that nobody touched.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Top%20CVEs%20of%20July%202026-by-strobes.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top 8 Data Breaches and Exposures of July 2026</title>
      <link>https://strobes.co/blog/top-8-data-breaches-july-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-8-data-breaches-july-2026</guid>
      <description>The 8 confirmed data breaches of July 2026, from a 78-million-account Suno leak to rogue AI agents breaching Hugging Face and Anthropic. What happened and how to defend.</description>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/top-8-data-breaches-july-2026-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>What to Evaluate Before You Let an AI Agent Exploit Your Systems</title>
      <link>https://strobes.co/blog/evaluate-ai-agent-pentesting-checklist</link>
      <guid isPermaLink="true">https://strobes.co/blog/evaluate-ai-agent-pentesting-checklist</guid>
      <description>An AI agent that can exploit your systems does an attacker&apos;s work. Here are the seven governance checks to clear before you authorize agentic pentesting in production.</description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/What%20to%20Evaluate%20Before%20You%20Let%20an%20AI%20Agent%20Exploit%20Your%20Systems.png" type="image/jpeg" />
    </item>
    <item>
      <title>Human-in-the-loop security: why AI findings need human validation</title>
      <link>https://strobes.co/blog/human-in-the-loop-security</link>
      <guid isPermaLink="true">https://strobes.co/blog/human-in-the-loop-security</guid>
      <description>An AI pentester can hand you a critical finding in minutes. The only question that matters is whether you believe it. Here is why human validation turns a claim into proof.</description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Human-in-loop-security.png" type="image/jpeg" />
    </item>
    <item>
      <title>How Strobes AI identifies and exploits a SQL injection vulnerability</title>
      <link>https://strobes.co/blog/ai-sql-injection-testing</link>
      <guid isPermaLink="true">https://strobes.co/blog/ai-sql-injection-testing</guid>
      <description>See how Strobes AI runs autonomous SQL injection testing, finding an injectable parameter, proving exploitability, and shipping evidence for remediation.</description>
      <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/How%20Strobes%20AI%20Identifies%20and%20Exploits%20a%20SQL%20Injection%20vulnerability.png" type="image/jpeg" />
    </item>
    <item>
      <title>wp2shell: A Pre-Authentication RCE in WordPress Core, and Why It Is an Exposure Validation Problem</title>
      <link>https://strobes.co/blog/wp2shell-wordpress-pre-auth-rce</link>
      <guid isPermaLink="true">https://strobes.co/blog/wp2shell-wordpress-pre-auth-rce</guid>
      <description>wp2shell is a pre-authentication RCE in WordPress Core that an anonymous request can trigger on a default install. Here are the affected versions, the patch steps, and why events like this are really an exposure validation problem.</description>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <author>Strobes Security</author>
      <enclosure url="https://strobes.co/api/media/file/wp2shell-wordpress-pre-auth-rce-cover.webp" type="image/jpeg" />
    </item>
    <item>
      <title>Strobes Agentic Pentesting: A pen-tester experience and point of view</title>
      <link>https://strobes.co/blog/strobes-agentic-pentesting-a-pen-tester-experience-and-point-of-view</link>
      <guid isPermaLink="true">https://strobes.co/blog/strobes-agentic-pentesting-a-pen-tester-experience-and-point-of-view</guid>
      <description>Eleven validated Critical and High findings from Strobes AI&apos;s autonomous pentesting agents, each with the agent&apos;s reasoning, the request sent, and the response that proved it.</description>
      <pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate>
      <author>Sumeet Darekar</author>
      <enclosure url="https://strobes.co/api/media/file/strobes-agentic-pentesting-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>10 Best Open Source Agentic Pentesting Tools in 2026</title>
      <link>https://strobes.co/blog/open-source-agentic-pentesting-tools</link>
      <guid isPermaLink="true">https://strobes.co/blog/open-source-agentic-pentesting-tools</guid>
      <description>Compare the 10 best open source agentic pentesting tools for self-hosted workflows, from PentAGI and PentestGPT to CAI, Strix, and VulnBot.</description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/10%20Best%20Open%20Source%20Agentic%20Pentesting%20Tools%20in%202026.png" type="image/jpeg" />
    </item>
    <item>
      <title>Vulnerability Chaining: How Agentic Pentesting Proves Attack Paths</title>
      <link>https://strobes.co/blog/vulnerability-chaining-agentic-pentesting-attack-paths</link>
      <guid isPermaLink="true">https://strobes.co/blog/vulnerability-chaining-agentic-pentesting-attack-paths</guid>
      <description>Three low-severity findings can chain into one critical breach. See why CVSS misses chained risk and how agentic pentesting proves or rejects each attack path.</description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/featured-vuln-chaining.webp" type="image/jpeg" />
    </item>
    <item>
      <title>How Agentic Pentesting Separates Test Failures From Real Security Findings</title>
      <link>https://strobes.co/blog/agentic-pentesting-reliability-unstable-apps</link>
      <guid isPermaLink="true">https://strobes.co/blog/agentic-pentesting-reliability-unstable-apps</guid>
      <description>Agentic pentesting reliability on unstable apps: a six-state failure taxonomy, safe retry rules, and what a trustworthy pentest report must disclose.</description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/featured.webp" type="image/jpeg" />
    </item>
    <item>
      <title>What Counts as Valid Proof in an Agentic Pentest?</title>
      <link>https://strobes.co/blog/agentic-pentesting-validation</link>
      <guid isPermaLink="true">https://strobes.co/blog/agentic-pentesting-validation</guid>
      <description>Valid proof in an agentic pentest is reproducible, in-scope, and attributable evidence of exploitability. What counts, what doesn&apos;t, and how to prove it.</description>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/agentic-pentest-valid-proof-featured-hd.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top CVEs of June 2026: 5 Critical Flaws to Patch Now</title>
      <link>https://strobes.co/blog/top-cves-june-2026-5-critical-flaws-to-patch-now</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-cves-june-2026-5-critical-flaws-to-patch-now</guid>
      <description>Five CVEs defined June 2026: Check Point VPN bypass, Splunk pre-auth RCE, Windows HTTP.sys kernel RCE, LiteLLM AI-gateway RCE, and Defender BlueHammer. How to fix each.</description>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Top%20CVE&apos;s%20of%20June%202026.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top 8 Data Breaches and Exposures of June 2026</title>
      <link>https://strobes.co/blog/top-data-breaches-june-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-data-breaches-june-2026</guid>
      <description>The 8 confirmed data breaches of June 2026, from a 24-billion-record credential dump to ShinyHunters&apos; PeopleSoft and Klue OAuth campaigns. What happened and how to defend.</description>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Top%20databreaches%20june%202026.png" type="image/jpeg" />
    </item>
    <item>
      <title>The &quot;vulnerability AI race&quot; is a myth. Here&apos;s what actually changes for your exposure program.</title>
      <link>https://strobes.co/blog/vulnerability-ai-race-myth</link>
      <guid isPermaLink="true">https://strobes.co/blog/vulnerability-ai-race-myth</guid>
      <description>The &quot;vulnerability AI race&quot; is vendor theater. What AI actually changes for exposure management, and why validation through exploitation beats discovery speed.</description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <author>Venu Rao</author>
      <enclosure url="https://strobes.co/api/media/file/ai-race-myth-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Vulnerability Validation: Why Most of Your Scanner Backlog Is Noise</title>
      <link>https://strobes.co/blog/what-is-vulnerability-validation</link>
      <guid isPermaLink="true">https://strobes.co/blog/what-is-vulnerability-validation</guid>
      <description>Vulnerability validation proves which scanner findings are real, reachable, and exploitable. Why manual triage fails and how agentic validation scales.</description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Vulnerability%20Validation.png" type="image/jpeg" />
    </item>
    <item>
      <title>Gartner SRM 2026 Broke Something I Believed About Enterprise Security</title>
      <link>https://strobes.co/blog/gartner-srm-2026-enterprise-security-takeaways</link>
      <guid isPermaLink="true">https://strobes.co/blog/gartner-srm-2026-enterprise-security-takeaways</guid>
      <description>Strobes CEO Venu Rao shares his takeaways from Gartner Security &amp; Risk Management Summit 2026: everyone can find vulnerabilities, almost no one has cracked fixing them.</description>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
      <author>Venu Rao</author>
      <enclosure url="https://strobes.co/api/media/file/srm_featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>How to Pentest Single-Page Applications (React, Angular, Vue)</title>
      <link>https://strobes.co/blog/pentesting-single-page-applications</link>
      <guid isPermaLink="true">https://strobes.co/blog/pentesting-single-page-applications</guid>
      <description>Learn how to pentest React, Angular, and Vue SPAs. Covers DOM XSS, client-side routing bypass, JS bundle secrets, and why traditional DAST scanners fail.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/pentesting-single-page-applications-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Bug Bounty vs. Pentesting vs. AI Pentesting: Which Model Fits Your AppSec Program?</title>
      <link>https://strobes.co/blog/bug-bounty-vs-pentesting-vs-ai-pentesting</link>
      <guid isPermaLink="true">https://strobes.co/blog/bug-bounty-vs-pentesting-vs-ai-pentesting</guid>
      <description>Bug bounty vs pentesting vs AI pentesting: compare costs, coverage, compliance, and when to use each model. Build a layered AppSec testing strategy.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/bug-bounty-vs-pentesting-vs-ai-pentesting-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Pentesting In-House vs. Outsourcing: Cost, Coverage, and the Third Option</title>
      <link>https://strobes.co/blog/pentesting-in-house-vs-outsourcing</link>
      <guid isPermaLink="true">https://strobes.co/blog/pentesting-in-house-vs-outsourcing</guid>
      <description>Compare in-house vs outsourced pentesting on cost, coverage, and depth. Discover why AI pentesting is the third option that changes the math for security teams.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/featured-pentesting-inhouse-vs-outsourcing.png" type="image/jpeg" />
    </item>
    <item>
      <title>DAST vs. Pentesting vs. AI Pentesting: What Each One Actually Finds</title>
      <link>https://strobes.co/blog/dast-vs-pentesting-vs-ai-pentesting</link>
      <guid isPermaLink="true">https://strobes.co/blog/dast-vs-pentesting-vs-ai-pentesting</guid>
      <description>Compare DAST, manual pentesting, and AI pentesting. Learn what each approach finds, misses, costs, and when to use each for full application security coverage.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/dast-vs-pentesting-vs-ai-pentesting-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Continuous Application Pentesting for DevSecOps Teams</title>
      <link>https://strobes.co/blog/continuous-app-pentesting-devsecops</link>
      <guid isPermaLink="true">https://strobes.co/blog/continuous-app-pentesting-devsecops</guid>
      <description>How DevSecOps teams integrate continuous application pentesting into CI/CD pipelines. AI-driven testing, run-over-run diffing, and developer workflow integration.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/continuous-app-pentesting-devsecops-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Pentesting Microservices Architecture: Why Traditional Methods Fall Short</title>
      <link>https://strobes.co/blog/pentesting-microservices-architecture</link>
      <guid isPermaLink="true">https://strobes.co/blog/pentesting-microservices-architecture</guid>
      <description>Why traditional pentesting misses 90% of microservices attack surface. Learn how to test East-West traffic, service mesh, and Kubernetes security at scale.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/pentesting-microservices-architecture-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Application Pentesting for SaaS Companies: Meeting SOC 2 and ISO 27001</title>
      <link>https://strobes.co/blog/app-pentesting-saas-soc2-iso27001</link>
      <guid isPermaLink="true">https://strobes.co/blog/app-pentesting-saas-soc2-iso27001</guid>
      <description>How SaaS companies should structure application pentesting for SOC 2 and ISO 27001 compliance. AI-driven continuous testing vs annual manual engagements.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/app-pentesting-saas-soc2-iso27001-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>How to Pentest APIs at Scale (Without Hiring 10 More Pentesters)</title>
      <link>https://strobes.co/blog/pentest-apis-at-scale</link>
      <guid isPermaLink="true">https://strobes.co/blog/pentest-apis-at-scale</guid>
      <description>Learn how to pentest hundreds of API endpoints using AI agents. Cover OWASP API Top 10, authorization testing, and scale without hiring more pentesters.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/pentest-apis-at-scale-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top 8 Data Breaches of May 2026</title>
      <link>https://strobes.co/blog/top-data-breaches-may-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-data-breaches-may-2026</guid>
      <description>The 8 confirmed data breaches of May 2026, from the 275M-record Canvas LMS breach to GitHub&apos;s VS Code supply chain attack, and how to defend against each pattern.</description>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Top%20Databreaches%20of%20May%202026.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top CVEs of May 2026: 5 Critical Flaws to Patch Now</title>
      <link>https://strobes.co/blog/top-cves-may-2026-5-critical-flaws-to-patch-now</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-cves-may-2026-5-critical-flaws-to-patch-now</guid>
      <description>Five CVEs dominated May 2026: cPanel&apos;s two-month zero-day, Linux&apos;s stealth kernel priv-esc, Langflow exploited 20 hours after disclosure, n8n&apos;s perfect-10 RCE chain, and Microsoft&apos;s SSO bypass. Here&apos;s what happened and what to do.</description>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/may-cve-cover.png" type="image/jpeg" />
    </item>
    <item>
      <title>How to Catch the Blind Bugs Scanners Miss</title>
      <link>https://strobes.co/blog/out-of-band-validation</link>
      <guid isPermaLink="true">https://strobes.co/blog/out-of-band-validation</guid>
      <description>Out-of-band validation detects blind SSRF, blind SQLi, and out-of-band XXE that return no in-band response. Learn how it works and why it matters.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/out-of-band-validation-featured-1.png" type="image/jpeg" />
    </item>
    <item>
      <title>5 Vulnerabilities in Every Vibe-Coded App</title>
      <link>https://strobes.co/blog/vibe-coded-app-vulnerabilities</link>
      <guid isPermaLink="true">https://strobes.co/blog/vibe-coded-app-vulnerabilities</guid>
      <description>The 5 security flaws AI coding assistants ship by default: missing authz, leaked secrets, weak JWTs, IDOR, eval RCE — with detection queries and fixes for each.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/vibe-coded-app-vulnerabilities-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Black-Box Agentic Scanners: Strengths and Their Ceiling</title>
      <link>https://strobes.co/blog/black-box-agentic-scanner-limits</link>
      <guid isPermaLink="true">https://strobes.co/blog/black-box-agentic-scanner-limits</guid>
      <description>Black box agentic pentesting finds real CVEs fast and proves them, but where does it hit a ceiling? An honest, category-level verdict.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/black-box-agentic-scanner-limits-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Why AI-Generated Exploit Code Must Run in Isolation</title>
      <link>https://strobes.co/blog/ai-exploit-code-isolation</link>
      <guid isPermaLink="true">https://strobes.co/blog/ai-exploit-code-isolation</guid>
      <description>Agent-written exploit code is the new RCE vector aimed at the tester. Here&apos;s why per-task isolation and egress control are non-negotiable.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <author>Alibha</author>
      <enclosure url="https://strobes.co/api/media/file/ai-exploit-code-isolation-featured-1.png" type="image/jpeg" />
    </item>
    <item>
      <title>What Is Agentic Pentesting? The Complete Guide for Security Teams (2026)</title>
      <link>https://strobes.co/blog/agentic-pentesting-complete-guide</link>
      <guid isPermaLink="true">https://strobes.co/blog/agentic-pentesting-complete-guide</guid>
      <description>Agentic pentesting uses specialized AI agents to test your entire attack surface in hours, not weeks. Here is how it works, what surfaces it covers, how safety is enforced, and how to evaluate platforms with real benchmarks.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/What_is_Agentic_AI_Pentesting.png" type="image/jpeg" />
    </item>
    <item>
      <title>ISO 27001 Penetration Testing Requirements</title>
      <link>https://strobes.co/blog/iso-27001-penetration-testing-requirements</link>
      <guid isPermaLink="true">https://strobes.co/blog/iso-27001-penetration-testing-requirements</guid>
      <description>ISO 27001:2022 never names penetration testing, yet it is how you evidence Annex A 8.8 and 8.29 at a surveillance audit. The honest read on required vs expected, with the 2013 lineage and the Oct 2025 deadline.</description>
      <pubDate>Wed, 20 May 2026 14:29:00 GMT</pubDate>
      <author>Akhil Reni</author>
      <enclosure url="https://strobes.co/wp-content/uploads/2025/08/9.png" type="image/jpeg" />
    </item>
    <item>
      <title>The TanStack npm Supply Chain Attack That Hit 170 Packages and Punishes You for Revoking Your Token</title>
      <link>https://strobes.co/blog/tanstack-npm-supply-chain-attack</link>
      <guid isPermaLink="true">https://strobes.co/blog/tanstack-npm-supply-chain-attack</guid>
      <description>The TanStack npm supply chain attack hit 12 million weekly downloads using three public techniques and zero novel code. Here is exactly how it worked.</description>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/The%20TanStack%20npm%20Supply%20Chain%20Attack%20That%20Hit%20170%20Packages%20and%20Punishes%20You%20for%20Revoking%20Your%20Token.png" type="image/jpeg" />
    </item>
    <item>
      <title>PCI DSS Penetration Testing Requirements</title>
      <link>https://strobes.co/blog/pci-dss-penetration-testing-requirements</link>
      <guid isPermaLink="true">https://strobes.co/blog/pci-dss-penetration-testing-requirements</guid>
      <description>PCI DSS v4.0.1 Requirement 11.4 is the rare standard that names penetration testing outright: internal and external annually plus after change, segmentation at 12 or 6 months, mandatory since 31 Mar 2025.</description>
      <pubDate>Tue, 05 May 2026 11:22:00 GMT</pubDate>
      <author>Likhil Chekuri</author>
      <enclosure url="https://strobes.co/wp-content/uploads/2025/08/9.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top 10 Data Breaches of April 2026</title>
      <link>https://strobes.co/blog/top-data-breaches-april-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-data-breaches-april-2026</guid>
      <description>The biggest data breaches of April 2026 ranked and analyzed, from Checkmarx supply chain poisoning to Salesforce misconfigurations and ransomware hitting two major US banks.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/image__115_.png" type="image/jpeg" />
    </item>
    <item>
      <title>Top 7 Critical CVEs of April 2026 You Need to Act On Now</title>
      <link>https://strobes.co/blog/top-cves-april-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/top-cves-april-2026</guid>
      <description>The top CVEs of April 2026 were exploited in hours. Marimo RCE, Windows IKE, Fortinet EMS, GitHub GHES, ActiveMQ, and more. Attack scenarios, risk context, and fixes.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/image__116_.png" type="image/jpeg" />
    </item>
    <item>
      <title>Checkmarx and Bitwarden Just Showed That Your Pipeline Is the Attack Surface</title>
      <link>https://strobes.co/blog/checkmarx-bitwarden-supply-chain-attack</link>
      <guid isPermaLink="true">https://strobes.co/blog/checkmarx-bitwarden-supply-chain-attack</guid>
      <description>How the Checkmarx supply chain attack compromised Bitwarden&apos;s CLI pipeline in four minutes, what was stolen, and the program design gap that made it possible.</description>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/Checkmarx_and_Bitwarden_Just_Showed_That_Your_Pipeline_Is_the_Attack_Surface.png" type="image/jpeg" />
    </item>
    <item>
      <title>NIST Just Changed How It Tracks and Prioritizes CVEs</title>
      <link>https://strobes.co/blog/nist-nvd-cve-prioritization-update-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/nist-nvd-cve-prioritization-update-2026</guid>
      <description>NIST has changed how it enriches CVEs in the NVD. Learn what the new risk-based triage model means for your vulnerability management program, scanner data, and remediation workflows.</description>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/NIST_Just_Changed_How_It_Tracks_and_Prioritizes_CVEs.png" type="image/jpeg" />
    </item>
    <item>
      <title>AI-Accelerated Offense: The Cyberattack Your Security Program Was Never Built to Stop</title>
      <link>https://strobes.co/blog/ai-accelerated-offense-cyberattack-security-program</link>
      <guid isPermaLink="true">https://strobes.co/blog/ai-accelerated-offense-cyberattack-security-program</guid>
      <description>AI-Accelerated Offense uses autonomous agents to run the full cyberattack chain in hours. A frontier AI model found thousands of zero-day vulnerabilities across every major OS and browser in weeks. See how it works, why your security program is already behind, and what to do now.</description>
      <pubDate>Thu, 23 Apr 2026 08:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/image_no_logo.png" type="image/jpeg" />
    </item>
    <item>
      <title>HIPAA Penetration Testing Requirements</title>
      <link>https://strobes.co/blog/hipaa-penetration-testing-requirements</link>
      <guid isPermaLink="true">https://strobes.co/blog/hipaa-penetration-testing-requirements</guid>
      <description>HIPAA never says &quot;penetration test,&quot; but the Security Rule&apos;s risk analysis and its REQUIRED evaluation standard expect technical testing of every system touching ePHI. Here is the precise read.</description>
      <pubDate>Mon, 20 Apr 2026 08:15:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/wp-content/uploads/2025/08/9.png" type="image/jpeg" />
    </item>
    <item>
      <title>The Vercel Hack: How One AI Tool Compromised the Infrastructure Behind Millions of Websites</title>
      <link>https://strobes.co/blog/vercel-security-breach-2026-ai-tool-supply-chain-attack</link>
      <guid isPermaLink="true">https://strobes.co/blog/vercel-security-breach-2026-ai-tool-supply-chain-attack</guid>
      <description>Vercel&apos;s April 2026 security breach started with one AI tool&apos;s OAuth approval. Here is the full attack chain, blast radius, and what every security team must do now.</description>
      <pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/vercel-breach-featured.png" type="image/jpeg" />
    </item>
    <item>
      <title>Best AI Pentesting Tools in 2026: Ranked, Priced &amp; Compared (12 Tools)</title>
      <link>https://strobes.co/blog/best-ai-pentesting-tools</link>
      <guid isPermaLink="true">https://strobes.co/blog/best-ai-pentesting-tools</guid>
      <description>Which AI pentesting tool actually reduces risk in 2026? We reviewed 12 platforms on autonomy, proof quality, pricing, and what happens after a vulnerability is found.</description>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/ai-pentesting-featured-v5.png" type="image/jpeg" />
    </item>
    <item>
      <title>Is Claude Mythos the End of Pentesting?</title>
      <link>https://strobes.co/blog/is-claude-mythos-end-of-pentesting</link>
      <guid isPermaLink="true">https://strobes.co/blog/is-claude-mythos-end-of-pentesting</guid>
      <description>Claude Mythos found thousands of zero-days in Linux, browsers, and Apache. Does that make pentesting platforms obsolete? Understanding why models, harnesses, and platforms are three different things -- and why smarter AI makes Strobes more valuable, not less.</description>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <author>Strobes Security</author>
      <enclosure url="https://strobes.co/api/media/file/mythos-featured-new.png" type="image/jpeg" />
    </item>
    <item>
      <title>SOC 2 Penetration Testing Requirements</title>
      <link>https://strobes.co/blog/soc-2-penetration-testing-requirements</link>
      <guid isPermaLink="true">https://strobes.co/blog/soc-2-penetration-testing-requirements</guid>
      <description>SOC 2 never names penetration testing in any criterion, yet auditors treat it as the load-bearing evidence for CC4.1 and CC7.x. Here is the gap between the letter and the audit.</description>
      <pubDate>Sun, 05 Apr 2026 14:08:00 GMT</pubDate>
      <author>Akhil Reni</author>
      <enclosure url="https://strobes.co/wp-content/uploads/2025/08/9.png" type="image/jpeg" />
    </item>
    <item>
      <title>Strobes VI Now Tracks Supply Chain Attacks, Ransomware Groups, and Threat Actors</title>
      <link>https://strobes.co/blog/strobes-vi-supply-chain-ransomware-threat-actors-tracking</link>
      <guid isPermaLink="true">https://strobes.co/blog/strobes-vi-supply-chain-ransomware-threat-actors-tracking</guid>
      <description>224,487 supply chain incidents. 1,251 threat actors. Ransomware groups tracked in real time. Strobes VI now provides the threat intelligence layer that powers proactive exposure management, starting with the lessons from the Axios npm compromise.</description>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <author>Strobes</author>
      <enclosure url="https://strobes.co/api/media/file/strobes-vi-featured-new.png" type="image/jpeg" />
    </item>
    <item>
      <title>The Worst Data Breaches of March 2026</title>
      <link>https://strobes.co/blog/worst-data-breaches-of-march-2026</link>
      <guid isPermaLink="true">https://strobes.co/blog/worst-data-breaches-of-march-2026</guid>
      <description>Nine confirmed data breaches across the US and Europe in March 2026, from a 200,000-device wipe at Stryker to 15.8 million patient records stolen at Cegedim Sante. Here is what happened, breach by breach, and what the pattern tells defenders.</description>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <author>Shubham Jha</author>
      <enclosure url="https://strobes.co/api/media/file/featured-breach-v4.png" type="image/jpeg" />
    </item>
    <item>
      <title>How Strobes AI Turns a Supply Chain Zero-Day into a Full Exposure Assessment in Under 30 Minutes</title>
      <link>https://strobes.co/blog/strobes-ai-supply-chain-incident-response-exposure-assessment</link>
      <guid isPermaLink="true">https://strobes.co/blog/strobes-ai-supply-chain-incident-response-exposure-assessment</guid>
      <description>When the axios npm package was compromised on March 31, 2026, Strobes AI agents autonomously performed incident response, identified every exposed repository across the attack surface, and generated a complete exposure assessment with remediation tasks in under 30 minutes.</description>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <author>Strobes Security</author>
      <enclosure url="https://strobes.co/api/media/file/strobes-ir-exposure-featured-v4.png" type="image/jpeg" />
    </item>
  </channel>
</rss>