Companies are still experimenting with automated AI systems to find security weaknesses, but fewer are relying on the technology.

Confidence in the effectiveness of artificial intelligence for automated penetration testing is waning, despite ongoing experimentation by organizations seeking to identify security vulnerabilities. While companies continue to explore AI-driven tools for security assessments, a notable decrease in reliance on this technology has been observed.
This shift suggests a growing skepticism regarding the current capabilities of AI in comprehensively uncovering exploitable weaknesses within complex systems. Early enthusiasm for AI's potential to revolutionize security testing appears to be tempered by practical challenges and limitations encountered in real-world deployments.
Organizations that were once optimistic about the prospect of fully autonomous AI-powered penetration tests are now exercising more caution. The trend indicates a move away from complete delegation of security testing to AI, towards a more hybrid approach where human expertise remains central.
The reasons behind this decline in confidence are not explicitly detailed in the available information, but it is likely related to the inherent complexities of cybersecurity and the evolving nature of threats. AI systems, while capable of processing vast amounts of data and identifying patterns, may struggle with the nuanced understanding and creative problem-solving that human penetration testers bring to the table.
For instance, AI might excel at identifying known vulnerability patterns or executing predefined attack vectors. However, it may fall short when faced with novel attack methodologies, zero-day exploits, or the intricate logic of custom-built applications, which often require human intuition and adaptability.
The development and refinement of AI for penetration testing is an ongoing process. While current iterations may not fully meet expectations for autonomous operation, the technology is still being actively researched and developed. Future advancements could potentially address the limitations that are currently contributing to the decline in confidence.
In the interim, organizations are likely to continue leveraging AI as a supplementary tool within their security testing frameworks. This could involve using AI for initial reconnaissance, automated vulnerability scanning, or to assist human testers by flagging potential areas of concern.
The current landscape suggests that while AI holds promise for enhancing cybersecurity efforts, human oversight and expertise remain indispensable for robust and effective penetration testing. The industry is likely to see a continued evolution of AI's role, moving from a fully autonomous solution to a powerful assistive technology.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed