Skip to main content

The New Way Security Teams Evaluate Pentesting Vendors

1 week 3 days ago
by George Whittaker

Why security buyers are rethinking what matters most.

Security teams typically don’t struggle to find vulnerabilities as much as they have in the past. The harder part usually begins after the report arrives, once dozens of findings land in front of engineering teams already juggling patch schedules, production deadlines, and internal disagreements about urgency. Platforms like XBOW, OffSec, and Cobalt have entered that environment as organizations started rethinking what they actually need from pentesting vendors beyond annual compliance exercises.

A vulnerability may look severe inside a dashboard, while no one internally agrees whether it creates meaningful exposure or simply adds another item to an already crowded queue. Infrastructure also changes too quickly for static testing cycles to answer every operational question.

APIs update mid-quarter, contractors receive temporary access that lingers longer than expected, and cloud permissions change quietly during routine development work. Buyers evaluating vendors now spend more time asking whether testing accurately reflects the systems employees use every day.

Pentesting Vendors Now Face Different Expectations

Long reports stopped carrying the same weight years ago. Security teams already know modern environments contain weaknesses. What many organizations want now is clearer evidence showing which findings deserve immediate attention and which ones can wait without creating major operational exposure. That distinction became harder to ignore as remediation timelines stretched across larger environments.

Go to Full Article
George Whittaker

Operation Bluebird Launches New Twitter

1 week 3 days ago
An anonymous reader quotes a report from Ars Technica: Operation Bluebird, the Virginia-based startup trying to revive the allegedly abandoned "Twitter" name and logo, announced Monday that it has launched its new social media network: Twitter.now. "We are a small company, we have investors, and we have a product," Stephen Coates, one of Operation Bluebird's cofounders, told Ars. "And we have waited months and months to launch, and we are not going to wait anymore." [...] Twitter.now, still in its nascent stage, only has hundreds of users for the time being. The social media network looks and feels much like the Twitter of old and many of its offshoots -- it has replies and retweets. A new and notable feature is the automated fact-checking tool, a Gemini-based "veracity engine for real-time analysis" ("Vera" for short), which runs on every tweet. Coates has been testing Vera in recent days by posting obviously false messages, like "George Washington was our second president." "Our first goal is to see if we can truly bring back a town square that's safer and less harmful," he said. "We say freedom of speech and not freedom of reach. We want people to say what they want, but we also want to create a platform that's not financially locked into that viral content that's harmful or inaccurate." Operation Bluebird argues that Elon Musk effectively abandoned the Twitter brand and trademarks when he renamed the company X, opening the door for the startup to claim them. X Corp. sued to stop the effort, but a federal judge tentatively ruled in April that X appeared to have relinquished rights to "tweet," the bird logo, and possibly "Twitter" itself, though no written ruling has been issued. Bluebird has taken that as enough of a green light to move forward while emphasizing that its new Twitter is not affiliated with X. "Operation Bluebird, Inc. picked up the name X Corp. walked away from and is rebuilding it on trust, in your browser at twitter.now," it states prominently on its website. "We are not X, and we are not affiliated with X Corp."

Read more of this story at Slashdot.

BeauHD