Stormberry on Nostr: Two security firms say they ran 17 million offensive actions against live systems ...
Two security firms say they ran 17 million offensive actions against live systems over three days. The result: 38 validated attack paths and 238 findings, work they estimate would have taken a five-person team 2,400 hours.
Treat the arithmetic with the usual caution. A count of findings is a count of things found, not of things worth fixing, and the firms publishing the number sell the service.
The structural point survives that scepticism. Rob Joyce, formerly of the NSA, put it plainly: you are going to be red-teamed whether you pay for it or not. If attacking systems becomes cheap enough to run continuously, an annual penetration test stops measuring your security and starts measuring how long a hole could sit open.
Most companies I speak to are not choosing between annual testing and continuous testing. They have never done either.
For a small or mid-sized Norwegian company in that position, the first step is not an AI red team. It is a written list of everything you expose to the internet, an ordinary vulnerability scan, and fixing what it finds.
Source: The Register, 2026-08-22
https://stormberry.as/ai#security #redteam #AI #Stormberry
Published at
2026-09-07 12:30:23 UTCEvent JSON
{
"id": "ca6147fe4c172b6e4c8ebbb3fca6929db05c1872f9bd0b0ddb3a62f3bf29cd7c",
"pubkey": "108aef782a95a65a2df059578e67a71366a65a697e163711b54574e8da0e6e30",
"created_at": 1788784223,
"kind": 1,
"tags": [
[
"t",
"security"
],
[
"t",
"redteam"
],
[
"t",
"ai"
],
[
"t",
"stormberry"
],
[
"r",
"https://stormberry.as/ai"
]
],
"content": "Two security firms say they ran 17 million offensive actions against live systems over three days. The result: 38 validated attack paths and 238 findings, work they estimate would have taken a five-person team 2,400 hours.\n\nTreat the arithmetic with the usual caution. A count of findings is a count of things found, not of things worth fixing, and the firms publishing the number sell the service.\n\nThe structural point survives that scepticism. Rob Joyce, formerly of the NSA, put it plainly: you are going to be red-teamed whether you pay for it or not. If attacking systems becomes cheap enough to run continuously, an annual penetration test stops measuring your security and starts measuring how long a hole could sit open.\n\nMost companies I speak to are not choosing between annual testing and continuous testing. They have never done either.\n\nFor a small or mid-sized Norwegian company in that position, the first step is not an AI red team. It is a written list of everything you expose to the internet, an ordinary vulnerability scan, and fixing what it finds.\n\nSource: The Register, 2026-08-22\n\nhttps://stormberry.as/ai\n\n#security #redteam #AI #Stormberry",
"sig": "bfa8e8f5ba4dfad86038c9aae5cafd9e89f5474e9b9d50f10192a0af11d5fcc0450629578836510c67fa809a8bc2ef212346e4b70f50ff7654c05e2fb04454ec"
}