A Phone Assistant Confirmed a Change It Never Made
The AI phone assistant told us it had updated a customer account. It hadn't. During an AI agent pentest, we called the assistant twice using the same account number but two different names.
SilentGrid / Research
Consultants publish what comes out of the work: control bypasses, exploitation write-ups, OT and ICS findings, and the reasoning behind how we scope an engagement.
The AI phone assistant told us it had updated a customer account. It hadn't. During an AI agent pentest, we called the assistant twice using the same account number but two different names.
OWASP released the 2026 edition of its Top 10 for LLM Applications in August. There are some notable changes in the ranking, but from a penetration testing perspective, the bigger change is what sits behind the model now.
AI assistants do more than answer questions now. A support chatbot can pull up a ticket, a finance assistant can fetch an invoice, and an internal tool can change a record on someone's behalf, all through tool calls the model asks your…
At least, not in the way you expect. Every year, we speak with organisations planning their first penetration test. The reason is usually familiar. A client has asked about security. The board has raised concerns.
As organisations continue adopting AI, one challenge quickly emerges: how do you manage access to multiple large language models (LLMs) in a secure and controlled way? For many organisations, the answer is an LLM gateway.
On the 11th of March 2026, the Iranian aligned Handala Hack (Handala) group claimed responsibility for a disruptive cyberattack which affected the medical multinational corporation, Stryker.
It's a single line of code - easy to miss in a review, and present in more Android apps than you'd expect: webView.addJavascriptInterface(new AppBridge(), "NativeApp"); When it's configured correctly, it's fine.
There's a particular kind of screen you'll find in control rooms, substations, and utility plants the world over. It shows a live schematic of whatever process the facility is running (e.g.
Okay, so a disclaimer upfront… setting up a self-hosted local Minecraft server didn’t actually teach me anything about business-to-business sales. I mean, you were expecting that, right?
In a previous post, we discussed how AI-assisted analysis has become a useful tool in offensive security engagements.
At SilentGrid, we rarely get called in for full-scale load testing - but recently, we had an urgent client request to validate system performance under high user activity.
A Threat That Has Evolved Beyond Nation-State Actors In the late 1950s, the Soviet embassy in The Hague placed an order for office furniture from a local Dutch company.
During one of our red team engagements late last year, we were given a challenge: Once inside the building, could we access employee lockers? At first glance, this didn’t sound too exciting.
The integration of artificial intelligence into offensive security practices represents a significant evolution in how cybersecurity assessments are conducted.
Maximising Value in Offensive Security Assessments: Why More Information Leads to Better Results When organisations engage offensive security firms like SilentGrid for adversary simulation or penetration testing, a common assumption…
Showing the most recent 15 articles. Browse the full archive
Stay across it
Occasional notes on what we are finding. No newsletter cadence to keep up with, and you can unsubscribe from any email.