惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recorded Future
Recorded Future
爱范儿
爱范儿
Y
Y Combinator Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
腾讯CDC
罗磊的独立博客
阮一峰的网络日志
阮一峰的网络日志
Know Your Adversary
Know Your Adversary
P
Proofpoint News Feed
T
Tailwind CSS Blog
Attack and Defense Labs
Attack and Defense Labs
G
GRAHAM CLULEY
大猫的无限游戏
大猫的无限游戏
博客园 - Franky
C
Cyber Attacks, Cyber Crime and Cyber Security
T
The Blog of Author Tim Ferriss
T
The Exploit Database - CXSecurity.com
博客园 - 叶小钗
Latest news
Latest news
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Hacker News
The Hacker News
量子位
S
Security @ Cisco Blogs
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家
U
Unit 42
Project Zero
Project Zero
B
Blog
博客园 - 【当耐特】
D
DataBreaches.Net
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hugging Face - Blog
Hugging Face - Blog
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
F
Full Disclosure
Vercel News
Vercel News
NISL@THU
NISL@THU
AWS News Blog
AWS News Blog
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
T
Threatpost
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
T
Tor Project blog
M
MIT News - Artificial intelligence
V
V2EX

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP) Bypassing WAFs Using Oversized Requests Getting Started with AI Hacking Part 2: Prompt Injection Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2) DomCat: A Domain Categorization Tool Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1) Microsoft Store and WinGet: Security Risks for Corporate Environments Default Web Content MailFail Commonly Abused Administrative Utilities: A Hidden Risk to Enterprise Security Stop Spoofing Yourself! Disabling M365 Direct Send Bypassing CSP with JSONP: Introducing JSONPeek and CSP B Gone Offensive Tooling Cheatsheets: An Infosec Survival Guide Resource DNS Triage Cheatsheet GraphRunner Cheatsheet Burp Suite Cheatsheet Impacket Cheatsheet Wireshark Cheatsheet Hashcat Cheatsheet EyeWitness Cheatsheet Nmap Cheatsheet Netcat (nc) Cheatsheet Hunt for Weak Spots in Your Wireless Network with Airodump-ng from the Aircrack-ng Suite Detecting ADCS Privilege Escalation Vulnerability Scanning with Nmap Getting Started with NetExec: Streamlining Network Discovery and Access How to Use Dirsearch Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 3: Arcanum Cyber Security Bot How to Design and Execute Effective Social Engineering Attacks by Phone Abusing S4U2Self for Active Directory Pivoting Why Use a Macro Pad? Espanso: Text Replacement, the Easy Way Caging Copilot: Lessons Learned in LLM Security Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 2: Copilot Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 1: Burpference Intercepting Traffic for Mobile Applications that Bypass the System Proxy How to Root Android Phones Communicating Security to the C-Suite: A Strategic Approach Offline Memory Forensics With Volatility Getting Started with AI Hacking: Part 1 Go-Spoof: A Tool for Cyber Deception How to Test Adversary-in-the-Middle Without Hacking Tools Canary in the Code: Alert()-ing on XSS Exploits How to Hack Wi-Fi with No Wi-Fi Why Your Org Needs a Penetration Test Program Burp Suite Extension: Copy For Light at the End of the Dark Web Wi-Fi Forge: Practice Wi-Fi Security Without Hardware Avoiding Dirty RAGs: Retrieval-Augmented Generation with Ollama and LangChain Gone Phishing: Installing GoPhish and Creating a Campaign 5 Things We Are Going to Continue to Ignore in 2025 John Strand’s 5 Phase Plan For Starting in Computer Security Questions From a Beginner Threat Hunter GRC for Security Managers: From Checklists to Influence AI Large Language Models and Supervised Fine Tuning Attack Tactics 9: Shadow Creds for PrivEsc w/ Kent & Jordan One Active Directory Account Can Be Your Best Early Warning Introduction to Zeek Log Analysis Indecent Exposure: Your Secrets are Showing Creating Burp Extensions: A Beginner’s Guide Pitting AI Against AI: Using PyRIT to Assess Large Language Models (LLMs) The Top Ten List of Why You Got Hacked This Year (2023/2024) ICS Hard Knocks: Mitigations to Scenarios Found in ICS/OT Backdoors & Breaches Intro to Data Analytics Using SQL Finding Access Control Vulnerabilities with Autorize The Detection Engineering Process Cyber Risk Lessons We Can Learn From Hurricane Preparedness Intro to Desktop Application Testing Methodology What Is Penetration Testing? Adversary in the Middle (AitM): Post-Exploitation Pentesting, Threat Hunting, and SOC: An Overview
Everyone's Selling AI That Kills Pentesting. We Built One That Doesn't. - Black Hills Information Security, Inc.
BHIS · 2026-06-17 · via Black Hills Information Security, Inc.

Right now, it feels like everybody and their brother has a new agentic red team product that is going to kill all penetration testing… Close the doors. Fire the testers. The robots have it from here!

We have been hearing that one a lot. So when Melisa from our Business Capture team sat down with Brian Fehrman and me for this episode of AI Security Ops, she started with, “What is this thing you built, and is it the same hype everyone else is selling?”

Short answer: No.

What we built, Fusion AI, runs at about a third the cost of a traditional external pentest, a human tester still signs off on every finding, and it is not here to replace anybody.

Here’s the longer answer —

Where It Started

The genesis was a dinner back in January. Brian and I were in DC with John and Erica at a Chinese restaurant, and they basically threw down a challenge: go build our own AI-powered external penetration testing offering. We could already see which way the wind was blowing with traditional pentesting, and the data we look at internally was telling the same story. So the marching orders from John were clear, and we ran with it.

It helped that this is not new ground for either of us. I went and got a master’s in data science over the pandemic, and then Brian one-upped me and got a doctorate in data science and engineering. When John and Erica looked around for who should take this on, it made sense.

We started small, just testing the waters with Claude Code and Claude Code skills. It quickly grew into a custom-coded agentic platform that ingests external scan results and then spawns agents to go investigate them. That part, on the surface, is roughly what a lot of folks in the industry are doing. The difference is what we put inside it.

The Part That Actually Matters

A tool is not expertise. Just because you have a hammer does not make you a master carpenter. We saw this almost a decade ago, before this round of AI hype, when every EDR vendor slapped “Now with AI!” on the box and expected applause. Having the technology does not make the product good.

So we spent the time. We went through old reports, studied what works and what does not, and tried to capture the methodology that makes BHIS successful and keeps people coming back. We built our institutional knowledge into the platform. The question we kept asking was simple: How would a BHIS tester actually run this external, and can we get the AI to do that?

Here is a concrete example. John Strand has preached for years that you do not just look at the criticals and the highs in a scanner result. The interesting stuff is hiding in the mediums, the lows, and the informationals, and the real skill is chaining those together into something with real impact. So we built our agents to do exactly that. There is what we call chaining algebra built into the platform, where it goes and finds the lower-severity findings that combine into something that matters.

The other piece we cared about was transparency. AI has an interpretability problem. You get told “here is a vulnerability” and you are left wondering how it found it, how it validated it, how it confirmed it. With what we built, you see all of it. Every step, every command, everything you need to understand how it reached a conclusion and how you would reproduce it.

Why Now?

People ask why we finally took this on. Honestly, a lot of it was necessity.

Threat actors caught on to AI before most defenders did. In October of 2025, Anthropic published a report on a Chinese threat actor abusing their services to run real, successful hacking campaigns, with a 30,000-foot view of how they pulled it off. You can read that as a blueprint. The world changed. We have adversaries using AI to discover vulnerabilities, run testing, and automate their work, and BHIS has always tried to mimic what real threat actors do. We almost had to build this just to keep pace.

The customer side flipped too. About a year ago, companies were telling us they absolutely did not want AI anywhere near their engagements. Now they call and ask whether we are using AI, because they want to see it. Got any more of that AI stuff in there? It was a fast turnaround.

What Surprised Us

Brian and I were both a little apprehensive going in. The fear was simple; we did not want to ship something that puts out garbage, hallucinates findings that are not there, or misses things that should obviously be caught. So we iterated. We tested it against our own company, and against some of our continuous customers who were happy to pilot it, and we kept tuning until we could look at the output and say, yes, this looks good and it is actionable.

The thing that genuinely surprised us was coverage. Our CFO Erica wanted to know whether AI could save money and add efficiency on externals, and the honest answer is that it depends on how you measure it. But the coverage was a real shock.

Here is the story we keep telling. On a recent three-day external, the platform found a customer website that had been compromised. The way it found it was that the threat actors had embedded links to shady gambling sites inside the HTML source of the page. We suspect they did it to boost their own sites in the search rankings, since they were piggybacking on an otherwise reputable domain. The platform also flagged the exploit that probably led to the compromise, and it caught a critical that the human tester could have missed on such a short engagement.

I will be honest with you. On a three-day engagement for a decent-sized environment with a bunch of web services, there is no way I would have gone line by line through the HTML of every page looking for that. No human would. That is where this really augments traditional testing. There is only so much time, and the AI does not get tired of looking.

Where It Still Needs a Human

It’s not magic, and I’m not going to pretend it is.

The platform still confabulates sometimes. It has trouble fitting findings cleanly into our severity model, so it will rank something a high or a critical and we will look at it and say, no, not really. That is exactly why a human stays in the loop. The AI report does not go to the customer. It goes to one of our testers, who reviews and verifies everything. And the AI-generated report is built for that — it hands the tester every command needed to go confirm each finding, right there in line. The findings that survive contact with the BHIS security conultant then go into the final report deliverable for the customer.

This is also why it took us about six months. Brian and I both wanted an enterprise-class code base, something mature enough that if one of us got hit by a bus, someone else could pick it up. I recently had GPT 5.5 run a comparison against what is the state of the art in the Agentic AI ecosystem for Summer 2026. It called the result “solid, production-minded, React-style engineering, with deterministic workflow orchestration plus autonomous tool-using workers.” It also gave us a list of things to fix, because this is an ongoing thing, not a one and done finished product. More in-depth web apps testing is probably next on our list to tackle for the Fusion AI initiative.

Who This Is For

This is the part that Melisa, sitting on the Business Capture side, was most excited about, and so am I.

The AI offering runs at about a third the cost of a normal penetration test, with less human-on-keyboard time. That puts it in reach for the mid-sized and smaller shops who want real security but have always been priced out. We never want to isolate those customers, and this fills a gap we hear about constantly.

The plan from here is to run this on essentially all of our externals unless a customer opts out, giving our testers a built-in second set of eyes asking “Did I miss anything?”, and to integrate it into our continuous pentesting offerings. That is also where the name comes from. Fusion AI is the fusion of automated AI and the human tester. It is not cruise control. On a recent rules-of-engagement call, you could watch the customer relax the moment they understood they still have a real BHIS tester available at any time. That is what they actually wanted.

Fusion AI is live on external engagements now. If your environment is on the smaller side and a full pentest has always felt just out of reach, this is the one to ask us about. Talk to your BHIS contact, or reach out at blackhillsinfosec.com, and we’ll walk you through it.

Want the full story? Catch the full episode “Introducing Fusion AI Pentest” on the AI Security Ops podcast. Watch it on YouTube at youtube.com/@AISecurityOps or wherever you get your podcasts. Melisa makes her podcast/webcast debut, and Brian tells the gambling-site story way better than I just did.

Keep on prompting.


Click the image below to learn more about Fusion AI