We're writing about offensive security

READ ALL ABOUT IT

Today we released an open source capability framework, lab generator and evaluator for autonomous offensive security. MIT licensed, and available now at github.com/arena-labs-ai/arena.

I spent nearly two decades in cybersecurity, six of them at Sygnia responding to breaches across roughly 40 countries and nearly every industry. You learn something specific from that work that you cannot learn anywhere else: you learn exactly how things break. Not in theory. In production, at 3 a.m., while a real adversary is still inside the environment.

Today A Security is introducing ARENA, the Agentic Red-team Evaluation for Neutral Assessment. The ARENA platform helps red teams, pentesters, security researchers, and enthusiasts generate fresh, real-world-shaped vulnerable targets with ground truth, so they can measure an AI attacker’s performance, sophistication and results over time.
A critical vulnerability in Zoom, a platform used by 70% of the Fortune 100, discovered by publicly available frontier models, allows an attacker participating in a meeting a zero-click remote code execution on all meeting participants across all native clients. This research emphasizes the risk of weaponized AI and how vulnerable we are as an industry.