Asia PacificBreaking News

ThreatBook acquires AI powered penetration testing platform CyberStrikeAI

Cybersecurity company ThreatBook has acquired CyberStrikeAI, an open-source AI-powered penetration testing platform, as the Singapore- and Hong Kong-based firm broadens its agentic security capabilities.

ThreatBook said in its announcement that it plans to incorporate CyberStrikeAI into its red-team offerings while continuing to develop both open-source and enterprise versions of the platform. The companies did not disclose the financial terms or other details of the transaction.

CyberStrikeAI joins ThreatBook’s security portfolio

Built in Go, CyberStrikeAI is designed to coordinate authorised security testing across several stages, including reconnaissance, vulnerability assessment, exploitation and reporting. Its public GitHub repository features more than 100 curated security tools and is distributed under an Apache 2.0 licence.

The platform combines asset and vulnerability management with queued testing tasks and visual monitoring of attack chains. It can also integrate multiple AI models as a reasoning layer and produce structured security assessment reports from natural-language instructions.

By automating the sequencing of these activities, the platform aims to reduce manual work for authorised security testers. However, the same capabilities make access management and governance important considerations as ThreatBook expands its use.

CyberStrikeAI’s repository had accumulated roughly 7,100 stars at the time of writing. ThreatBook said the project had surpassed 6,600 GitHub stars and had been deployed across more than 2,300 networks since launching in late 2025. The network deployment figure was provided by the company and has not been independently verified.

ThreatBook intends to incorporate CyberStrikeAI into controlled red-team operations, allowing security teams to replicate attacker behaviour and uncover vulnerabilities in their environments. The company said an open-source edition will remain available, alongside additional protections designed to limit potential misuse.

The acquisition adds an offensive-security testing component to ThreatBook’s existing portfolio of threat intelligence, detection and response products. It also places the company in a part of cybersecurity where AI-driven automation can benefit defenders while potentially making offensive activity easier to execute.

Enterprise version to add tighter controls

ThreatBook said the enterprise edition will support complete on-premises deployment, allowing customer information to remain within an organisation’s own network. Additional features will include audit logs and controls governing actions taken by AI agents.

These measures are intended to give enterprise security teams greater oversight of automated testing. ThreatBook founder and chief executive Xue Feng said AI-assisted reconnaissance and exploitation are reducing the amount of time defenders have to respond, making equivalent automated testing capabilities increasingly important.

The platform has also drawn attention from independent cybersecurity researchers. Team Cymru reported in March that it identified 21 unique IP addresses running CyberStrikeAI between January 20 and February 26, 2026. Its analysis associated one server banner with infrastructure referenced in earlier research concerning attacks against Fortinet FortiGate devices.

The research did not indicate that all CyberStrikeAI installations were being used maliciously. However, it highlighted the potential for AI-native offensive tools to make automated targeting faster.

CyberStrikeAI’s own documentation states that the platform is intended for educational purposes and authorised security testing, with users required to obtain explicit permission before testing any systems.

Enterprise rollout starts in China

ThreatBook said a trial of CyberStrikeAI’s enterprise edition is now available in mainland China, with a broader Asia-Pacific release planned for October 2026.

The rollout provides a commercial route for a project that has gained traction within the open-source cybersecurity community. ThreatBook has not revealed pricing, customer commitments or changes to staffing, and it has not confirmed whether CyberStrikeAI’s original developers will join the company.

The acquisition will also test whether the project can retain the advantages of its open-source community while operating within tighter enterprise security controls. ThreatBook has yet to specify how its planned safeguards will go beyond the existing warnings and security documentation, or whether those restrictions will be compulsory in the public version.

 

 

Related Articles

Back to top button