Dubai-based Secure.com has just issued “21 Holes in 3 Production Stacks: What AI Pentesting Actually Finds in 2026,” new research proving just how far AI-driven pentesting has moved from theory to operational risk. In a single weekend, an automated pipeline with no human in the loop uncovered 21 vulnerabilities across three live production stacks, including 7 critical issues tied largely to basic security hygiene failures.
Secure.com researchers pointed an AI-driven pentesting pipeline at three well-known production systems and found
- Multi-tenant e-commerce marketplace: Frontend Runtime Config Leaked on Every Page Load; Unauthenticated Scheduler & Admin Endpoints; Unauthenticated Notification Injection
- Generative AI imaging platform: Cross-Origin Session Theft Across All Four Backend APIs; Admin Dashboard Publicly Reachable
- Popular consumer password manager: Full Production Environment Exposed in Public JavaScript Bundle
This materially changes the economics of both attack and defense. What until now took skilled human testers and significant budget can be executed continuously for roughly $18 per hour, raising questions about whether periodic pentesting models are still viable.
21 Holes in 3 Production Stacks – What AI Pentesting Actually Finds in 2026: Three clients. Three very different architectures. One weekend of machine time: https://www.secure.com/resources/holes-production-stacks
When an AI SOC Misses a Threat, What Happens?
Posted in Commentary with tags secure.com on July 2, 2026 by itnerdWith organizations adopting AI-powered SOCs, much of the attention focuses on reducing false positives. False negatives where AI falsely clears an attack or its early phases is far less discussed, but far more problematic.
Yasir Zahid, Cybersecurity Leader and Product Builder with Dubai-based Secure.com, has just published “When an AI SOC Gets It Wrong: False Negatives, Risk, and What Comes Next.“
Yasir’s detailed analysis recognizes that AI SOCs miss real threats more often than SOC teams and their organizations expect, and lays out the costs of false negatives to the average organization.
You can read more here: What Happens When an AI SOC Misses a Threat
Leave a comment »