The Defense Manpower Data Center's file-sharing system held unencrypted SSNs for 3 million military and civilian personnel for nine months before discovery. What proof-first testing would have shown.
Read more →Blog
The Sekura Blog
Calm. Never Breathless.
Notes on autonomous penetration testing, proof-of-exploit, and building a product you can trust.

Latest
From the Sekura team
A breach analysis every week, and essays on how the pipeline works — calm, never breathless. Proof over probability.
AI red teaming tools in 2026
AI red teaming tools split into two distinct categories: tools that probe AI systems for safety failures, and tools that use AI agents to run penetration tests against traditional infrastructure.
Read more →What agentic cybersecurity actually means
Agentic cybersecurity is on every vendor slide. Here is what the term actually means, where it is real today, and how to tell the mechanism from the marketing.
Read more →ChainDrop worm compromises 400 npm packages
A self-propagating npm worm named ChainDrop compromised more than 400 packages in early August 2026, stealing AWS credentials, Kubernetes tokens, and HashiCorp Vault secrets from enterprise CI/CD pipelines.
Read more →ShinyHunters takes 25 million Alcon Salesforce records
ShinyHunters claimed 25 million Salesforce records from Alcon Inc. in August 2026, using OAuth Connected App abuse to exfiltrate CRM data without triggering login alerts. Here is what proof-first analysis would have shown.
Read more →EY breach exposes client tax records
ShinyHunters claimed a supply-chain attack on EY's IT support platform. Unauthorized access from March 28 to April 12, 2026 exposed client SSNs, bank accounts, and tax filing records.
Read more →Hugging Face pipeline breach exposes internal credentials
A malicious dataset chained two code-execution flaws in Hugging Face's data-processing pipeline, giving an AI agent lateral access to internal cluster credentials.
Read more →AssuranceAmerica breach exposes 7 million driver records
A stolen employee credential gave attackers bulk access to 6.99 million Americans' driver's licenses and insurance records at AssuranceAmerica. Here is what that failure mode looks like through a proof-first lens.
Read more →Accenture source code breach exposes cloud keys
Threat actor '888' posted 35GB of alleged Accenture source code, RSA keys, SSH keys, and Azure PATs for sale on PwnForums in July 2026. Accenture confirmed an incident. Here is what proof-first analysis would have shown.
Read more →What the Sekura LLM proxy never sees
Sekura routes LLM API calls through proxy.sekura.ai for billing and metering. Your source code, prompts, and findings never cross the proxy. Here is how the architecture works and why it matters for IP-sensitive teams.
Read more →KDDI breach exposes 14 million ISP credentials
KDDI's centralized email platform for six Japanese ISPs was breached in June 2026, with up to 14.22 million email addresses and passwords potentially exposed via a third-party software flaw.
Read more →Most High Severity Findings Are Never Exploitable
Severity-based scanners score vulnerabilities in isolation and miss reachability entirely. Most high-severity alerts point to code paths attackers cannot actually reach. Here is the data and what changes when you scan for proof instead.
Read more →Klue OAuth Breach Hits Nine Technology Firms
A dormant Klue service account credential gave the Icarus group access to Salesforce CRM data at HackerOne, Huntress, OneTrust, Snyk, and at least five other technology firms in June 2026.
Read more →Snyk, Veracode and Sekura: Three Different Jobs
Dependency scanners and SAST tools do detection. Autonomous pentesting does exploitation. These are different jobs. Here is a framework for choosing between Snyk, Veracode and Sekura.
Read more →Council of Europe breach via Oracle PeopleSoft zero-day
ShinyHunters claimed on June 14 to have stolen 297 GB from the Council of Europe via CVE-2026-35273, a zero-day in Oracle PeopleSoft, exposing payroll records and medical data for over 10,000 employees.
Read more →Audit Prep Arrives as a Byproduct
Sekura maps every confirmed pentest finding to SOC 2, ISO 27001, PCI DSS, and 11 other frameworks automatically. Audit prep stops being an annual scramble and becomes a direct output of the security work you already do.
Read more →Evertec vendor platform breach exposed payment cards
In May 2026, an attacker accessed a third-party support platform used by Evertec, a NYSE fintech, to reach debit card numbers and transaction records of Banco Popular de Puerto Rico customers.
Read more →What npx sekura init actually does
A step by step look at what runs when you invoke npx sekura@latest init: registry fetch, signature check, IDE detection, OAuth, keychain storage, and GitHub Actions wiring.
Read more →Instagram account-takeovers expose an AI verification gap
Attackers fed Meta's AI support flow an AI-generated face video built from a target's own profile photos, passed identity verification, swapped the email, and reset the password. No CVE. No backend breach. High-profile Instagram accounts gone.
Read more →7-Eleven franchise records exposed via Salesforce misconfiguration
ShinyHunters queried 7-Eleven's unauthenticated Salesforce Experience Cloud portal to steal 185,000 franchise applicants' records, including Social Security numbers and driver's license data.
Read more →The math on pentest cost per finding
Annual pentests cost $30k to $150k per engagement and run once a year. Continuous coverage changes the math. A spreadsheet-grade comparison of cost per verified finding.
Read more →Charter breach exposes 13 million Spectrum customers
ShinyHunters used a vishing call to compromise one employee's Microsoft Entra account and bulk-export 13 million Spectrum customer records from Salesforce. No CVE. No scanner would have caught it.
Read more →GitHub internal repos breached via poisoned extension
TeamPCP used a trojanized Nx Console VS Code extension to steal GitHub employee credentials and exfiltrate roughly 3,800 internal repositories in May 2026.
Read more →Canvas breach exposes 275 million student records
ShinyHunters exploited a trust boundary flaw in Instructure's Free-for-Teacher program, exposing 275 million student and staff records across nearly 9,000 Canvas institutions before Instructure paid a ransom.
Read more →Amtrak breach exposes 2.1 million customer records
ShinyHunters compromised Salesforce credentials through social engineering in April 2026, exposing 2.1 million Amtrak customer records. No CVE. No code flaw. Scanners had no visibility into the attack path.
Read more →France Titres breach exposes 11 million citizen records
A basic IDOR flaw in France's national identity portal gave one attacker access to 11.7 million citizens' records. What dynamic probing of the API would have surfaced.
Read more →LLM apps inherit a new attack surface
AI-integrated apps carry prompt injection, jailbreak, and data exfil vulnerabilities that static scanners miss. Concrete payloads Sekura uses to probe LLM endpoints, grounded in real CVEs and the OWASP LLM Top 10.
Read more →Post-quantum crypto agility: what to flag now
Harvest-now-decrypt-later attacks are active today. Here is what a crypto agility audit actually surfaces, and why waiting for NIST finalisation is the wrong anchor.
Read more →Carnival breach exposes 6 million customer records
ShinyHunters used one compromised employee account to extract names, addresses, and government IDs for 5.9 million Carnival Corporation customers. A look at what application-layer security testing would have surfaced.
Read more →Exploit Chain Analysis Catches What Scanners Miss
Single-vulnerability scanners miss the attacks that matter most. Real attackers chain low-severity findings into critical exploits. Here is how exploit-chain analysis finds paths that no scanner sees.
Read more →Hallmark Salesforce Breach Exposes 1.7 Million Records
ShinyHunters exploited misconfigured Salesforce Experience Cloud guest user permissions at Hallmark Cards in March 2026, leaking 1.7 million customer records after an April 2 extortion deadline passed.
Read more →Anatomy of an autonomous pentest scan
A technical walkthrough of Sekura's seven-phase multi-agent pipeline: SAST, recon, dynamic probing, exploit synthesis, chain analysis, post-quantum review, and reporting, with examples of what each phase produces.
Read more →The triage tax: what scanners cost you
Vulnerability scanners are cheap to license. The real cost is the engineering hours spent validating, prioritizing, and dismissing their output. Here is how to measure it.
Read more →Proof, not probability. The case for deterministic exploits.
CVSS scores tell you what might be exploitable. Sekura tells you what is. Here is why the proof bar matters more than the severity score, and what changes when you enforce it.
Read more →No posts match your search.
Guides
Learn the pipeline
Guides, comparisons and compliance explainers on autonomous penetration testing, agentic security, and AI red teaming — from the team building Sekura.
Guides
AI Red Teaming: Both Meanings Explained
AI red teaming has two meanings: adversarial testing of AI systems like LLM apps, and using AI agents to perform offensive security. This guide covers both.
Read more →OWASP LLM Top 10 Testing: A Practical Guide
OWASP LLM Top 10 testing means dynamically probing LLM apps for prompt injection, insecure output handling, excessive agency, and more. How to test each.
Read more →Penetration Testing Guide: Types, Process, and Cost
This penetration testing guide covers what a pentest is, the main types, the process phases, real cost ranges, and how to choose the right approach.
Read more →What Is Agentic Security
Agentic security applies AI agents that plan, use tools, and act autonomously to security work, from offensive testing to SOC triage and remediation.
Read more →What Is Autonomous Penetration Testing
Autonomous penetration testing uses AI agents to find, exploit, and prove security vulnerabilities without human operators driving every step of the test.
Read more →Solutions
Continuous Penetration Testing for Modern CI/CD Pipelines
Continuous penetration testing runs proof-based exploit checks on every deploy, closing the gap that annual pentests leave in fast-moving environments.
Read more →LLM Security Testing for AI Applications
LLM security testing sends adversarial payloads at your running AI application to find prompt injection, jailbreaks, and data exfiltration before attackers do.
Read more →Comparisons
Sekura vs traditional vulnerability scanners
How Sekura differs from SAST/SCA/DAST scanners: scanners output ranked potential issues; Sekura reports only what it has actually exploited. Side-by-side comparison across output, false positives, scope, cadence, and triage burden.
Read more →Sekura vs manual penetration testing
How Sekura differs from a human pentester: manual pentests are point-in-time, $30k–$150k per cycle, take weeks; Sekura runs continuously across the whole attack surface and updates as your environment changes. Comparison and hybrid recommendation.
Read more →Alternatives
Cobalt Pentest Alternative: Continuous Autonomous Testing With Sekura
Weighing a Cobalt pentest alternative? Compare continuous autonomous testing from Sekura with Cobalt's human pentest-as-a-service platform.
Read more →Horizon3 NodeZero Alternative: Sekura for Application-Layer Pentesting
Evaluating a Horizon3 NodeZero alternative? See how Sekura's proof-first application pentesting compares on scope, deployment, and pricing.
Read more →Pentera Alternative: Sekura for Proof-First Application Security
Considering a Pentera alternative? Compare Sekura's proof-of-exploit application testing with Pentera's network-centric security validation.
Read more →XBOW Alternative: Sekura for Proof-First Autonomous Pentesting
Looking for an XBOW alternative? Compare Sekura and XBOW on proof of exploit, surfaces covered, deployment control, and public pricing.
Read more →Compliance
Penetration Testing for SOC 2: What Auditors Expect
Penetration testing for SOC 2 is not strictly required, but auditors expect it under CC4.1 and CC7.1. Here is what they accept and how to prepare.
Read more →