#PenTester
Why not AI malefactors: if you can build a good PenTester you can build a good penetrator. Name it Penetraitor, perhaps.

How much would you bet that there isn't a rogue LLM running in the cloud right now?
September 29, 2026 at 3:47 PM
Vendor relations: handing the lists of brand new linux CVEs (Debian and RHEL that I've found so far) to the lead pentester on our recently finished assessment and saying "enjoy!"

(If they're tested against, they can then be hardened against. Threat actors are likely already aware.)
September 29, 2026 at 3:09 PM
A pentester two years in, halfway through HTB CPTS prep, is asking how to handle burnout. Full-time work plus after-hours study is wearing thin, and engagements have started to feel like the same two weeks on repeat. Push through the cert, or pivot to AppSec or security engineering?
Burnout after 2 years in pentesting
I've been working as a pentester for about two years (initially part-time, then switched to full-time), and lately I've started feeling burned out and losing interest in studying because of how int...
reddit.com
September 28, 2026 at 12:43 PM
tune a novelty-decay dial and watch a simulated pentester stop repeating itself. the same 60-step run drops from 51 duplicate actions down to 18
The Fly That Stopped: Mushroom-Body-Inspired Habituation as a Reward-Free Scheduling Prior for Autonomous Penetration Testing
arXiv:2609.29126 · cs.CR
arxiv.org
September 27, 2026 at 8:01 AM
Impacket tstool uses MSRPC to enumerate, control, disconnect, log off, reboot, and hijack Windows Terminal Services sessions remotely, with Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket support. #TerminalServices #MSRPC #Impacket
Impacket For Pentester: Tstool
impacket-tstool uses MSRPC to remotely enumerate, control, disconnect, log off, reboot, and even hijack Windows Terminal Services sessions without dropping a binary or opening an RDP client. It also supports passwordless authentication methods like Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket, making it a stealthy post-exploitation tool against systems such as the DC1 domain controller in ignite.local. #impacket-tstool #TerminalServices #DC1 #ignite.local #tscon #qwinsta
www.hendryadrian.com
September 23, 2026 at 9:00 AM
September 22, 2026 at 9:00 AM
Mein Problem als #pnp #munchkin und ex #Pentester ist ja mir legst du ein System und regeln vor und Designer erklärt toll was dadurch gefördert wird. 10 Minuten später mit nem Taschenrechner und es ist klar das das system genau das Gegenteil fordert. Grumpf jedes mal
September 19, 2026 at 9:29 AM
Hiring an LLM red-team pentester by setting up an AI Interview tool to fail every candidate, then see who still gets through

Update: please welcome James T. Kirk to our team!
September 19, 2026 at 12:09 AM
Dev vs Pentester:

Dev → secure prompts, models, deployments
Pentester → attack AI apps/agents, find abuse paths

Best teams do both.

Dev: aisectraining.com/aisec-secure...
Book: www.amazon.com/dp/B0H74CWYSV
https://www.amazon.com/dp/B0H74CWYSV
www.amazon.com
September 16, 2026 at 4:00 AM
the difference isn't just "understanding the why." lol.

the real difference is what happens when the exploit fails.

a script kiddie moves on and tries another tool.

a pentester opens the code, debugs it, and makes it work. that's the job.
September 13, 2026 at 4:31 AM
I strongly recommend reading up on the catalyst for this if you haven't. I'm far from an expert but Ive been a developer for over a decade, am forced to work with these tools at work, and am a hobbyist pentester/malware author. And I am very alarmed :p. openai.com/index/huggin...
The Hugging Face incident and the road ahead
OpenAI shares findings from the Hugging Face security incident and the steps we’re taking to strengthen AI model security, monitoring, and alignment.
openai.com
September 9, 2026 at 7:12 PM
shannon v3.1.0 — Shannon is an autonomous, white-box AI pentester for web applications and APIs... https://kitploit.com/tools/github/keygraphhq/shannon?utm_source=bluesky&utm_medium=social&utm_campaign=kitploit&utm_content=357816
September 8, 2026 at 11:50 AM
Keygraph released Shannon 3.0, an open-source AI pentester that maps an app's architecture from source code before exploiting the live app.
Shannon 3.0 AI pentester gets through Aikido and XBOW
Keygraph has released Shannon 3.0, the third major version of its open-source AI pentester for web applications and APIs. Shannon is a CLI agent that reads an application's source code, works out where it is likely to break, then attacks the running app with real exploits. Anything it cannot demonstrate against the live target gets discarded, a rule the project states as no exploit, no report. It is out now under AGPL-3.0, run locally through npx or from source. 0:00 /0:10 1× The headline change is a multi-stage security code analysis pipeline, adapted from the open-source Mantis security review skills. It runs alongside the recon and vulnerability agents, first building its own picture of the application: components, interfaces, dependencies, data flows, trust boundaries, and high-value assets. Agents then follow attacker-controlled data from entry point to sensitive operation, and the candidates they produce are deduplicated, challenged by a review agent, checked for production viability, and confirmed against their code paths before entering the exploitation queue. The pass is opt-in through a config flag, and a code analysis hypothesis never becomes a finding on its own. Keygraph published its own comparison. Doyensec, in an Aikido-sponsored study, had run Aikido and XBOW against two self-hosted apps. Keygraph ran Shannon 3.0 against one of them, Photoview 2.4.0, on a matching deployment with three models, and scored the results itself. DeepSeek v4 Flash reported 18 findings for $6.10, Grok 4.6 reported 10 for $35.07, and Opus 5 reported 24 for $115 with one false positive. All three runs flagged the critical pre-auth SQL injection Photoview has since patched, and the Opus run caught six of the seven issues fixed in that round. Doyensec listed 32 validated findings for Aikido and 7 for XBOW, at $4,000 per scan each. Version 3.0 also rebuilds the CLI so scan status, phase progress, and per-agent logs read in the terminal, and checkpoints progress into named workspaces so interrupted runs resume where they stopped. An official GitHub Action and a GitLab CI/CD component run the same scan inside a pipeline, keep reports and logs as artifacts, and can fail a build on proven vulnerabilities above a chosen severity. Reports come out as PDF and Markdown with evidence attached, plus SARIF 2.1.0 for GitHub code scanning. Shannon runs self-hosted on operator-supplied models, across Anthropic, OpenAI, xAI, Bedrock, and local runtimes. SPONSORED Check out the official repo Learn more Keygraph is the San Francisco company behind Shannon, founded in 2024 by Varun Sivamani, previously engineering lead for HRIS and payroll at Lattice, and backed by Pear VC and Authentic Ventures. The project passed 47,000 GitHub stars before this release and is named after Claude Shannon. Keygraph also sells a commercial platform that runs an extended build of the same agent continuously. Shannon Open Source is pitched as a complete pentester in its own lane, aimed at developers and small teams testing staging environments they own.
www.testingcatalog.com
September 7, 2026 at 10:31 PM
La ciber seguridad es oscura y alberga horrores (normalmente se usa 'pentester')
September 7, 2026 at 7:23 PM
A pentester wonders if big companies still hire for the role, seeing mostly startup and small-firm openings while software engineering jobs abound, and considers switching to software engineering.
Do Big Companies Still Hire Penetration Testers?
Are big companies still hiring penetration testers? I feel like penetration testing jobs barely exist at big companies anymore. Most of the openings I see seem to be at small startups or small secu...
reddit.com
September 7, 2026 at 2:43 PM
Ich hatte 2024 hier mal einen Workshop gehalten u. damals labert eich auch über diese Datenabflüsse. Folgendes: für mich sind die Ransomgruppen Pentester u. wenn man zu dumm, zu faul u. zu inkompetent ist, sich mal - als ITfrizze - die Dateibäume anzuschauen u. daraus notwendige /1
September 7, 2026 at 6:57 AM
Indeed! I'm good though. Working for the man lol. I'm a senior pentester now for a heartless and evil company, so what else could I ask for lol. But seriously, can't really complain. Been spending lots of time outdoors doing things I love in my free time etc. Yourself, how's things?
September 6, 2026 at 2:42 AM
Seit Jahren mal wieder auf der #ifa2026
Die letzten Jahre waren mir etwas zu langweilig. Immer das gleiche. Als Pentester direkt am Eingang abgeholt:D
September 4, 2026 at 11:18 AM