8.3 C
Casper
Friday, October 9, 2026

ThreatBook Buys AI Penetration Testing Tool CyberStrikeAI

spot_img

Must read

ThreatBook says the open-source tool will stay free, with a new on-premises enterprise edition and added safeguards against misuse.

ThreatBook, a cybersecurity company, said Sept. 30 that it has acquired CyberStrikeAI, an open-source tool that uses artificial intelligence to simulate attacks on computer networks and find weaknesses before real attackers do. The practice is known as penetration testing. Financial terms were not disclosed.

ThreatBook plans to build the tool, which is written in the Go programming language, into its “red team” offerings. Red teams are security teams that act as attackers.

What the tool does

Users describe a target in plain language, and CyberStrikeAI produces a structured security report, the company said. It comes with more than 100 built-in tool templates covering the steps from reconnaissance to exploitation, lets users choose which large language model drives its decisions, and shows each step the AI agent takes. It connects to other tools through the Model Context Protocol, or MCP, a standard for linking AI systems to software.

ThreatBook said CyberStrikeAI has drawn more than 6,600 stars on the code-sharing site GitHub and has been deployed in more than 2,300 networks since its late-2025 launch. The company called it one of the most widely used AI penetration testing tools, but did not provide a source for that ranking.

Also Read: Attackers Aren’t Hacking In. They’re Logging In.

Open source stays, with limits

ThreatBook said it will keep the open-source version and add controls to prevent misuse. It did not say what the controls will be. A new enterprise edition can be installed entirely inside a customer’s network, with data kept on-site, an audit trail, and permission controls for every action an agent takes, the company said.

A trial of the enterprise edition is available now in mainland China and is expected to reach the rest of Asia-Pacific next month.

Xue Feng, ThreatBook’s founder and chief executive, said automated reconnaissance and exploitation have shrunk the time defenders once had to respond to attacks. Such capabilities “should be in the hands of defenders,” he said, not only criminals and state-backed hacking groups.

spot_img

More articles

spot_img

Latest posts