Blog

The Sekura Blog

Calm. Never Breathless.

Notes on autonomous penetration testing, proof-of-exploit, and building a product you can trust.

Sekura — owl-in-shield mark

Latest

From the Sekura team

A breach analysis every week, and essays on how the pipeline works — calm, never breathless. Proof over probability.

Essay · October 6, 2026

AI red teaming tools in 2026

AI red teaming tools split into two distinct categories: tools that probe AI systems for safety failures, and tools that use AI agents to run penetration tests against traditional infrastructure.

Read more →

Breach analysis · August 13, 2026

ChainDrop worm compromises 400 npm packages

A self-propagating npm worm named ChainDrop compromised more than 400 packages in early August 2026, stealing AWS credentials, Kubernetes tokens, and HashiCorp Vault secrets from enterprise CI/CD pipelines.

Read more →

Breach analysis · July 30, 2026

EY breach exposes client tax records

ShinyHunters claimed a supply-chain attack on EY's IT support platform. Unauthorized access from March 28 to April 12, 2026 exposed client SSNs, bank accounts, and tax filing records.

Read more →

Breach analysis · July 9, 2026

Accenture source code breach exposes cloud keys

Threat actor '888' posted 35GB of alleged Accenture source code, RSA keys, SSH keys, and Azure PATs for sale on PwnForums in July 2026. Accenture confirmed an incident. Here is what proof-first analysis would have shown.

Read more →

Essay · July 3, 2026

What the Sekura LLM proxy never sees

Sekura routes LLM API calls through proxy.sekura.ai for billing and metering. Your source code, prompts, and findings never cross the proxy. Here is how the architecture works and why it matters for IP-sensitive teams.

Read more →

Essay · June 26, 2026

Most High Severity Findings Are Never Exploitable

Severity-based scanners score vulnerabilities in isolation and miss reachability entirely. Most high-severity alerts point to code paths attackers cannot actually reach. Here is the data and what changes when you scan for proof instead.

Read more →

Essay · June 12, 2026

Audit Prep Arrives as a Byproduct

Sekura maps every confirmed pentest finding to SOC 2, ISO 27001, PCI DSS, and 11 other frameworks automatically. Audit prep stops being an annual scramble and becomes a direct output of the security work you already do.

Read more →

Essay · June 5, 2026

What npx sekura init actually does

A step by step look at what runs when you invoke npx sekura@latest init: registry fetch, signature check, IDE detection, OAuth, keychain storage, and GitHub Actions wiring.

Read more →

Essay · April 16, 2026

LLM apps inherit a new attack surface

AI-integrated apps carry prompt injection, jailbreak, and data exfil vulnerabilities that static scanners miss. Concrete payloads Sekura uses to probe LLM endpoints, grounded in real CVEs and the OWASP LLM Top 10.

Read more →

Breach analysis · April 8, 2026

Carnival breach exposes 6 million customer records

ShinyHunters used one compromised employee account to extract names, addresses, and government IDs for 5.9 million Carnival Corporation customers. A look at what application-layer security testing would have surfaced.

Read more →

Essay · March 26, 2026

Anatomy of an autonomous pentest scan

A technical walkthrough of Sekura's seven-phase multi-agent pipeline: SAST, recon, dynamic probing, exploit synthesis, chain analysis, post-quantum review, and reporting, with examples of what each phase produces.

Read more →

Guides

Learn the pipeline

Guides, comparisons and compliance explainers on autonomous penetration testing, agentic security, and AI red teaming — from the team building Sekura.

Guides

What Is Agentic Security

Agentic security applies AI agents that plan, use tools, and act autonomously to security work, from offensive testing to SOC triage and remediation.

Read more →

Solutions

Comparisons

Sekura vs traditional vulnerability scanners

How Sekura differs from SAST/SCA/DAST scanners: scanners output ranked potential issues; Sekura reports only what it has actually exploited. Side-by-side comparison across output, false positives, scope, cadence, and triage burden.

Read more →

Sekura vs manual penetration testing

How Sekura differs from a human pentester: manual pentests are point-in-time, $30k–$150k per cycle, take weeks; Sekura runs continuously across the whole attack surface and updates as your environment changes. Comparison and hybrid recommendation.

Read more →

Alternatives

Compliance