Announcement:
ThreatBook has acquired CyberStrikeAI (https://github.com/aipentest/cyberstrikeai), one of the most widely used AI pentesting agents out there.
Honestly, when I read back in February that attackers were actually using CyberStrikeAI in real attacks, my first reaction was: that's a technical endorsement! After all, there are countless AI pentesting agents out there — the fact that attackers picked this one speaks for itself.
Open source technologies and tools are neutral — what matters is who wields them. We believe they should be in the hands of defenders, who need to think and act like attackers to stay ahead. That said, we've added guardrails to limit potential misuse, but at the end of the day it's open source, and there's only so much we can do. New capability enhancements will go into the commercial edition.
One more thing worth mentioning: the attribution issue.
The initial threat intelligence report suggested the developer was likely affiliated with certain national agencies, citing the mention of his contributions to China's national vulnerability database on his GitHub profile. This is a false positive. The developer was a security engineer at Alipay who built this tool in his spare time and open-sourced it. In China, submitting vulnerabilities you discover to the national database is a regulatory requirement — it says nothing about any ties to government agencies.
As a CTI vendor ourselves, all I can say is: attribution is hard. You need to understand the culture, the ecosystem, the motivations, and many other factors before making a claim. We all need to be more careful. But it happens.
