SRT Community, Author at Synack

SRT Community

Recent research

Evaluating Enterprise-Grade Guardrails For Your Agentic AI Pentesting Solution: Insights From Synack’s New eBook
At Synack, we recently released Sara Pentest, an agentic AI powered penetration test with human oversight. As security teams navigate the next frontier of pentesting and agentic AI, an important component to technical requirements will be legal and security guardrails. We touched on this in our first ebook on agentic AI, a, “Guide to Agentic [...]
Read more

NIS2 is Live: Moving Beyond “Check-Box” Compliance to True Cyber Resilience
The deadline has come and gone. As of October 17, 2024, the transposition deadline for the NIS2 Directive has passed, and for thousands of organizations across the EU (and those doing business within it), the reality of enforcement has arrived. Several member states have not yet fully implemented the directive, which leaves many organizations unclear [...]
Read more

More research by SRT Community

Applying Agentic AI to Pentesting: Insights from Synack’s New eBook
At Synack, we have written the first comprehensive playbook on how to leverage agentic AI for penetration testing. The goals are clear: First, to educate the security community on agentic AI fundamentals and best practices in pentesting and vulnerability management. Second, to provide an in-depth overview on how Synack is leveraging agentic AI–including the use [...]
Read more

Best Practices to Achieve the Benefits of Agentic AI in Pentesting
Agentic AI systems take penetration testing to a level far beyond traditional methods. In the words of a former Synack Red Team member and security engineer, Max Moroz, “Traditional pentesting is like checking your locks and windows once a year while a swarm of AI-powered burglars are constantly probing your house.” Companies are now considering [...]
Read more

AI Agents and How They Are Used in Pentesting
AI agents are increasingly used in penetration testing. Some recent examples include PentestAGI and Synack’s Sara. Agents can add considerable value by reducing the time and effort required to complete some testing tasks manually. For example, an agent can autonomously initiate an nmap scan on a target web application IP address. Companies like Synack are [...]
Read more

Qualys and Synack Partnership Elevates Vulnerability Management Outcomes
In today’s complex cybersecurity landscape, two crucial pillars of defense are routinely kept siloed: Vulnerability scanning and penetration testing. All too often, this leads to inefficiencies and potential blind spots. But what if you could combine their strengths for a more robust security posture? That’s precisely what the new integration between Qualys Vulnerability Management (VM) [...]
Read more

Superior Pentesting Compliance Validation with Synack PTaaS
For most organizations, pentesting is the periodic independent validation that security controls are working effectively to satisfy compliance requirements like PCI/DSS, NIST, SOC 2, FedRAMP, DORA, HIPAA and ISO 27001. These and other regulatory frameworks serve as a structured, systematic approach for validating security posture and protecting enterprises from cyber risks. While the mission of [...]
Read more

Synack + Tenable: Bridging Vulnerability Management and Penetration Testing with AI
Synack, the leader in human-led and AI-driven Penetration Testing as a Service (PTaaS), has joined forces with Tenable to deliver a comprehensive security solution aimed at cutting through noise and addressing truly exploitable threats. This collaboration, announced on Tenable’s blog today, allows customers to integrate valuable insights from Tenable Vulnerability Management with Synack’s AI-powered vulnerability [...]
Read more

The Hidden Cost of Triage
Your bug bounty program costs more than you think when factoring in triage. So you’ve set up vulnerability scanners and run an open bug bounty program. Congrats: You’re embracing modern security practices. The reports are flowing in, and you’re paying out for valid findings. On the surface, it looks like a win. But dig a [...]
Read more

Vulnerability Management Needs Agentic AI for Scale and Humans for Sense
Agentic AI for pentesting is upending vulnerability management by scaling up identification of suspected software flaws.
Read more

FedRAMP forges ahead with faster vulnerability remediation
FedRAMP program managers are weighing an expectation for major cloud vendors to address critical cybersecurity vulnerabilities in just three days—ten times faster than current guidelines.
Read more

U.S. strikes on Iran could trigger cyber retaliation
Hacktivists and government spies linked to Iran could launch digital attacks on U.S. critical infrastructure in response to Israeli and American strikes on Iranian nuclear targets.
Read more

Efficiency and Impact: How Synack Integrations Supercharge Security Outcomes
“Efficiency” is an early candidate for 2025’s Word of the Year. The relentless focus on measuring impact without adding headcount has pressured security leaders to move faster and remediate smarter. That’s where the power of integration comes in. Connecting Synack PTaaS to your security ecosystem — ASM tools, vulnerability management, ticketing platforms — lets you [...]
Read more

Security in Uncertainty: Women CISOs Weigh In During RSA
AI-enabled cyberthreats and volatile markets weighed on infosec leaders heading into the 2025 RSA Conference in San Francisco. In an unpredictable era for cybersecurity budgets, Synack joined co-sponsor NASDAQ to host a panel discussion unpacking how women security executives are shifting strategies to meet the moment. “It’s fun in cyber to welcome everyone else to [...]
Read more