Archive for Ridge Security

Ridge Security asks which AI is actually best at hacking?

Posted in Commentary with tags on September 3, 2026 by itnerd

Everyone wants to know which AI model is smartest. But which one is actually best at hacking?

Ridge Security just published what it says is the first-of-its-kind public benchmark putting eight leading models head-to-head as autonomous pentesters. 96 tests across four vulnerable environments. And the results weren’t what you’d expect from a typical AI leaderboard.

Grok 4.5 led on coverage at 77%. Gemini 3 Flash hit 52% at just $5.42 a run. GPT-OSS-120B was the efficiency winner.

But here’s the more interesting part: the model itself may matter less than what you build around it. Ridge found that an agent’s ability to execute, recover when attacks fail and verify its own findings can make a huge difference.

They also found frontier models sometimes refusing to generate payloads or take exploitation steps even during authorized testing. A pretty interesting problem when you’re asking AI to actually do the hacking.

You can read the press release here: Ridge Security Publishes First-of-Its-Kind Benchmark Comparing Leading AI Models for Autonomous Red Teaming

Your AI agent has the password. Does the LLM need it?

Posted in Commentary with tags on August 31, 2026 by itnerd

Here’s a question Ridge Security has been digging into: Can an agent use a secret, like a password or token, without its underlying LLM ever having to see that secret?

Ridge’s answer is yes – but getting there means confronting a real problem with how agents are typically built today.

If a pentest agent’s LLM sees raw secrets, that value doesn’t stay contained to one conversation. It can leak into debug logs, error reports, caches, retries, or saved reports. And once it’s already in the LLM’s context, it’s too late to filter out. It also widens the attack surface, since the value now passes through model infrastructure and becomes a target for prompt injection, where a malicious input could trick the agent into repeating or leaking it.

Ridge’s security team argues the fix isn’t a better filter, it’s a different architecture. They call it a “Security Harness”: the agent gets permission to use a secret without the LLM ever being shown the secret itself. The real credential stays behind a trusted boundary, and the model works with a safe reference it can reason about and use only when an authorized action calls for it. They lay out the thinking, and how it could work, in this recent blog post.

The core idea, as they put it: just because an agent is authorized to use a credential doesn’t mean every part of the system, including the LLM, needs to see it. Sharing it anyway turns a controlled operation into an avoidable risk.

Ridge Security Launches RidgeGen

Posted in Commentary with tags on August 4, 2026 by itnerd

Ridge Security today announced the availability of RidgeGen™, an enterprise-grade native agentic AI platform for continuous offensive security testing. Unlike traditional automated security testing tools that primarily follow pre-defined catalogs, RidgeGen takes a fundamentally different approach. It’s a multi-agent AI system that fully leverages the reasoning capabilities of modern foundation models. The agents continuously reason, test, validate, and recommend fixes in iterative AI loops. They’re augmented by our proprietary security knowledge base, grounded through specialized toolchains, and protected by a strict three-zone security guardrail architecture to ensure every action stays within the user’s intended scope.

The launch comes as artificial intelligence reshapes both software development and cyberattacks. As AI accelerates code generation and enables attackers to discover and weaponize vulnerabilities faster than ever before, traditional vulnerability scanners and periodic penetration tests are struggling to keep pace. Even existing automated penetration testing tools often fall short, providing limited findings that can leave organizations with a false sense of security. Security teams are increasingly overwhelmed with alerts but lack the evidence needed to determine which vulnerabilities represent real business risks and how to implement rapid remediation.

RidgeGen addresses this challenge by augmenting AI models with Ridge Security’s proprietary security knowledge base, specialized tooling, and enterprise-grade agentic AI framework. It combines AI reasoning with deterministic controls that keep security testing safe, auditable, and explainable. By separating AI reasoning from authority, enforcement, and verification, RidgeGen enables organizations to safely deploy autonomous offensive security while maintaining strict governance over targets, credentials, and testing policies.

Unlike traditional security testing tools that identify potential issues based on signatures or known CVEs, RidgeGen autonomously investigates how attackers could chain together vulnerabilities, business logic flaws and misconfigurations to compromise an environment. Every finding is validated with reproducible evidence before being surfaced, dramatically reducing false positives and false negatives and enabling security teams to prioritize exploitable risk rather than theoretical exposure.

While RidgeGen is designed to be model-agnostic and supports flexible deployment options, including on-premises environments, its development and benchmark testing framework were built on Google Cloud. Throughout the development process, Gemini served as a key baseline model for evaluating performance, reliability, and cost efficiency. Our benchmark testing across multiple leading AI models demonstrated that Gemini delivers a strong balance of performance and cost efficiency, making it a highly effective foundation for enterprise-grade agentic AI security applications.

Key capabilities include:

  • Autonomous agentic AI red teaming and offensive security testing
  • Evidence-backed verification that eliminates false positives and AI hallucinations
  • Discovery of complex multi-step attack chains and business logic vulnerabilities
  • Click-away remediation guidance generated from validated findings
  • Runtime guardrails that enforce safe, supervised and authorized testing modes
  • Secure credential handling through SafeBox, preventing sensitive data from entering AI model prompts or memory
  • Model-agnostic architecture supporting leading commercial and self-hosted AI models
  • On-premises deployment options that keep customer data and evidence within enterprise environments

RidgeGen complements RidgeBot, Ridge Security’s AI-powered continuous security validation platform. Together, the two solutions provide organizations with continuous visibility across their attack surface while delivering deep, autonomous validation of high-value targets – creating a unified “find, prove and fix” approach to Continuous Threat Exposure Management (CTEM).

The platform is available immediately for enterprise organizations and managed security service providers worldwide.

Ridge Security Achieves ISO/IEC 27001 Certification

Posted in Commentary with tags on January 7, 2026 by itnerd

Ridge Security today announced that it has achieved ISO/IEC 27001 certification, the globally recognized standard for information security management systems (ISMS). The certification comes ahead of the company’s upcoming RidgeBot 6.0 platform release, which introduces enterprise-scale enhancements for AWS and Windows security validation.

ISO/IEC 27001 certification provides Ridge Security with a competitive advantage by meeting these rigid requirements, helping accelerate sales cycles and supporting expansion into new global markets. Achieving this certification validates Ridge Security’s commitment to safeguarding sensitive information, continuously improving its security posture, and operating with long-term resilience and accountability.

The new certification applies to all Ridge Security products, including the company’s flagship platform, the upcoming RidgeBot 6.0, a leading agentic AI-based adversarial risk validation platform that supports continuous threat exposure management programs. It is designed for continuous security validation and risk-based vulnerability management, scanning IT environments, discovering attack surfaces and validating weaknesses using real proof-of-concept exploits with zero false-positives.

Additionally, RidgeBot can safely simulate real-world adversarial attacks. RidgeBot 6.0 integrates with AI frameworks such as RidgeGen, enabling advanced capabilities including exploit chaining, contextual reasoning, PII detection, and detailed remediation guidance. These features allow enterprises to conduct frequent, scalable testing beyond traditional manual methods.

More information on RidgeBot 6.0 is available at https://ridgesecurity.ai/ridgebot/.

Ridge Security Brings AI-Powered Penetration Testing to Microsoft Azure Marketplac

Posted in Commentary with tags on November 21, 2025 by itnerd

Ridge Security has made its flagship AI-powered solution, RidgeBot®, available on the Microsoft Azure Marketplace, Microsoft’s online store providing applications and services for use on Azure. Customers and partners can seamlessly deploy RidgeBot within their Azure environments to perform continuous, AI-driven validation that identifies, validates, and remediates vulnerabilities at scale.

Transforming Security Validation Through Automation

Powered by AI-driven automation, RidgeBot autonomously identifies attack surfaces, safely executes exploitations, and generates actionable reports aligned with OWASP and MITRE frameworks. This enables security and DevOps teams to detect, validate, and remediate vulnerabilities faster, reducing risk exposure and strengthening resilience across hybrid and multi-cloud environments.

By leveraging Azure’s global infrastructure, RidgeBot allows organizations to unify automated penetration testing and continuous security validation under a single cloud platform. The result is a scalable, always-on approach that replaces infrequent manual testing with continuous, data-driven assurance of real-world defenses.

Designed for Enterprises and Partners Alike

RidgeBot on Microsoft Azure Marketplace provides flexible deployment options tailored to different security and operational needs:

  • Managed Application (Subscription): Deploy RidgeBot directly from Azure with a simple monthly plan covering one web app or up to twenty IPs, billed through Azure.
  • Virtual Machine (BYOL): Deploy RidgeBot as a VM using a license purchased directly from Ridge Security for greater configuration flexibility.
  • Microsoft Sentinel Joint Solution: Centrally manage multiple RidgeBot deployments across on-premise and cloud environments for unified alerts and analytics.

These options empower enterprises and partners to scale security validation seamlessly within their Azure ecosystems. Learn more at www.ridgesecurity.ai/azure

Ridge Security Earns 95% Willingness to Recommend rating, Gartner Peer Insights

Posted in Commentary with tags on November 12, 2025 by itnerd

Ridge Security, leader in AI-powered offensive security for Continuous Threat Exposure Management (CTEM), today announced that it was the second highest vendor to score a willingness to recommend with 95% in the 2025 Gartner’s Peer Insights “Voice of the Customer” for Adversarial Exposure Validation.

Based on 22 reviews validated by Gartner as of August 2025 Ridge Security recently announced RidgeGen, a comprehensive Agentic AI framework designed to take security validation from automation to autonomy. Powered by RidgeGen, Ridge Security’s flagship product, RidgeBot, covers an organization’s IT infrastructure, including hosts, networks, applications, APIs, and LLMs, making it the platform with the most comprehensive offensive security framework ever developed. We feel like the willingness to recommend score from Gartner Peer Insights™ “Voice of the Customer” is evidence of the company’s growing demand for Adversarial Exposure Validation technology.

According to Gartner, Adversarial Exposure Validation represents a market segment focused on solutions that continuously test, validate, and measure an organization’s security posture by emulating real-world attacker behaviors. These technologies operationalize adversarial techniques to assess and prioritize exposures with precision and repeatability.

Within this framework, Gartner Peer Insights defines willingness to recommend as the percentage of verified end users who indicate they would endorse a vendor solution to their peers, a key measure of customer advocacy. Derived from 18 months of practitioner reviews, this metric offers an evidence-based view of user confidence and satisfaction with Ridge Security’s flagship product, RidgeBot.