Skip to content
View original post on X: Feng Xue· 41/100AI score41/100

ThreatBook acquires CyberStrikeAI, a widely used AI pentesting agent

AISummary

ThreatBook has acquired CyberStrikeAI, an open-source AI pentesting agent, after reports that attackers had used it in real intrusions.

The company says it added guardrails to limit misuse but will put new capability enhancements into its commercial edition, and it argues defenders should control such tools.

It also corrects an earlier threat intelligence report that linked the developer, a security engineer at Alipay, to government agencies, calling that attribution a false positive.

Post on XView on X
@s0what

Announcement:
ThreatBook has acquired CyberStrikeAI (https://github.com/aipentest/cyberstrikeai), one of the most widely used AI pentesting agents out there.

Honestly, when I read back in February that attackers were actually using CyberStrikeAI in real attacks, my first reaction was: that's a technical endorsement! After all, there are countless AI pentesting agents out there — the fact that attackers picked this one speaks for itself.

Open source technologies and tools are neutral — what matters is who wields them. We believe they should be in the hands of defenders, who need to think and act like attackers to stay ahead. That said, we've added guardrails to limit potential misuse, but at the end of the day it's open source, and there's only so much we can do. New capability enhancements will go into the commercial edition.

One more thing worth mentioning: the attribution issue.
The initial threat intelligence report suggested the developer was likely affiliated with certain national agencies, citing the mention of his contributions to China's national vulnerability database on his GitHub profile. This is a false positive. The developer was a security engineer at Alipay who built this tool in his spare time and open-sourced it. In China, submitting vulnerabilities you discover to the national database is a regulatory requirement — it says nothing about any ties to government agencies.

As a CTI vendor ourselves, all I can say is: attribution is hard. You need to understand the culture, the ecosystem, the motivations, and many other factors before making a claim. We all need to be more careful. But it happens.

https://asiatechdaily.com/threatbook-acquires-cyberstrikeai-as-ai-pushes-penetration-testing-toward-autonomous-security/

Source: Feng Xue · x.comPublished · added here