PentesterLab: Penetration Testing & Web App Security Blog

· Pentesterlab

3 min read Original article ↗

What Has Always Been the Moat in Pentesting?

Featured

What Has Always Been the Moat in Pentesting?

Artificial intelligence has prompted a question our industry should have asked long ago: what is the moat in pentesting? For years, ...

By Louis Nyffenegger September 1, 2026 · 4 min read

Filter: All Research APPSEC AuthZ CAREER Code Review Insight JWT PENTESTING

Weekly Research

Research Worth Reading - Week 35, 2026

💎 Ruby Marshal Kick-off Gadgets - elttam • ␛ VMs won't contain cyber-capable agents - The Trail of Bits Blog • ☕️ Escaping Google Cloud Application Integration Sandbox: Straight into Borg

PentesterLab Aug 31, 2026

Weekly Research

Research Worth Reading - Week 34, 2026

🤖 Patterns and problems in multiagent systems \ Anthropic • ⚒️ Staying Ahead of Adversarial AI Through Agentic Source Code Review | Google Cloud Blog • 💸 We burned 11.7bn tokens to find the best cyber AI model | GLM5.3 and DeepSeek are now frontier

PentesterLab Aug 23, 2026

Weekly Research

Research Worth Reading - Week 33, 2026

🏭 visa/visa-vulnerability-agentic-harness: Visa Vulnerability Agentic Harness • 🔀 LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection • 💎 Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam

PentesterLab Aug 17, 2026

Weekly Research

Research Worth Reading - Week 32, 2026

✅ AI Guardrails That Prove, Not Guess • 🧠 GitHub - Kritt-ai/open-kritt: Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code. · GitHub • 🐚 Cruising for Shells in Flowise - elttam

PentesterLab Aug 13, 2026

SAML Vulnerabilities and Attacks: A Practical Guide

Security Assertion Markup Language (SAML) is a widely deployed standard for Single Sign-On (SSO) in the enterprise, and a recurring source ...

Louis Nyffenegger Aug 12, 2026 · 32 min read

Weekly Research

Research Worth Reading - Week 31, 2026

🪲 CVE-2026–44722: A Zip encryption downgrade caused by an incorrect operator • 🪲 Finding six NGINX vulnerabilities with open models • 🤗 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

PentesterLab Aug 4, 2026

The AI Pentesting Winners May Not Be AI Startups

Every few weeks, another startup announces an AI pentester. Looking at the market, it feels as though the future of AI ...

Louis Nyffenegger Aug 3, 2026 · 6 min read

Weekly Research

Research Worth Reading - Week 30, 2026

⚒️ ethiack / ethibench • ⚒️ capitalone / VulnHunter • 🪲 FastJson 1.2.83 Remote Code Execution

PentesterLab Jul 27, 2026

Bletchley Park and the Future of Open Source AppSec

After the Allies broke Enigma during the Second World War, they faced an unusual problem. The difficult part was no longer ...

Louis Nyffenegger Jul 22, 2026 · 10 min read

Weekly Research

Research Worth Reading - Week 29, 2026

🤖 Special Token Injection (STI) Attack Guide • 🪲 MAD Bugs: My Cousin Vinyl (CVE-2026-50052) • 🪲 From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal

PentesterLab Jul 20, 2026

Technical interviews in the age of AI

With AI, technical interviews are becoming harder and harder to trust. Candidates now have access to automated tools designed to help ...

Louis Nyffenegger Jul 16, 2026 · 5 min read

Weekly Research

Research Worth Reading - Week 28, 2026

🖥️ Local AI for Penetration Testing & Research • 🧠 The context an agent needs to find the next vulnerability. • 🤖 The Bug Bounty Singularity: Our Hackbot

PentesterLab Jul 13, 2026