Sitemap
Homepage
About
Info Hub
Blog
AI Can Hack a Bank in 21 Minutes: ECB's DORA Deadline Is October
Catch them early: Integrate Automated Pentesting in your CI/CD Pipeline
Como Cumprir com a NIS2: Guia para PMEs Portuguesas
Como Fazer um Inventário de Ativos para Cibersegurança
Don’t Fear The AI Reaper: Using LLMs to Hack Better and Faster
Ethiack Culture: We T.E.S.T. when we test
Ethiack Featured in the Portugal Fintech Report 2023
Ethiack Raises a €4 Million Funding Round to Develop AI-Powered Hackbots
From Compliance to Continuous Security: Ethiack's Vision For Financial Cybersecurity
Growing, Hosting, Hacking: Ethiack’s 2025 Wrap Up
Here's What Anthropic's Mythos Means for the Future of Cybersecurity
How to use AI and Automation for Ethical Hacking and Vulnerability Assessment
If you want peace, prepare for cyberwar
Mythos didn't change the rules, it showed us they already changed
Pentesting no more: Why it's time to move from Pentesting to Ethical Hacking
Quo Vadis Cybersecurity?
Rez0 Joins Ethiack to Advance AI Offensive Security
Roll out the Ethiacker Awards: Celebrating the Best Ethical Hackers of 2024
Security Had It Backwards. This Is What Comes Next.
Super-charging Bug Bounty Hunting with the Power of AI
The State of AI Powered Hacking in Early 2026: What Is Real, What Is Hype, What Is Missing
United Against Cyber Enemies
We’re now ISO 27001 certified! Here’s what this means for you
Webinar | Cybersecurity in Supply-Chain: Start with Prevention
What is a Pentest: How ethical hacking can protect you
Why is SOC 2 Important for Startups: A Guide for CTOs
You Don't Cut Corners in Cybersecurity: Our Black Friday Motto
Case Studies
How ANA Aeroportos Kept 10 Airports Secure While Attackers Got Faster
How BaladAPP Made Trust Their Competitive Advantage in Brazil's Event Market
How Broadvoice Replaced Firefighting with Continuous, Validated Security
How CEGID Made Validation Continuous Across 2,000+ Assets and 20+ Companies
How ComplianceWise Went from Annual Pentests to 24/7 Validation, and Funded Elite Hacking with the Savings
How Critical Software Validated Exploitability for Zero-Tolerance Industries
How Secfix Closed the Gap Between Annual Pentests and Constant Code Changes
How Smartex Cut Time-to-Mitigation from Weeks to Days
How U.Porto Brought 5,000+ Assets Under Continuous Validation
How Wallim Built Continuous Validation Into Their Stack, On a Startup Budget
How Zick Learn Earned Enterprise Trust Without Hiring an Internal Pentester
Events
Ethiack distinguished as a Leader in Innovation in Portugal
Ethiack's Journey with Google for Startups in the Growth Academy: AI for Cybersecurity
Making Portugal More Cyber Secure at C-DAYS 2024
Securing Success: Ethiack is The Most Promising Startup at Web Summit 2023
The Cybersecurity Union: Notes from ENISA's Cybersecurity Conference
Product
Beacon V2: Testing Internal Assets Made Easy
Cleaning the Portal: UX Improvements to The Way You Use Ethiack
Ethiack 2.14: Test Internal Assets, CI/CD, SSO, New Reports, and more!
Ethiack Beacon: Easily Test Your Internal Assets
Ethiack's Spring Release: What's New and What's Coming
Extended Capabilities for Ethiack’s API: What’s Changing
Find the Needle in the Haystack with Advanced Filters for Attack Surface Management
Full Walkthrough: Ethiack 2.0
Introducing the Hackian - an AI agent that can hack
Introducing the new Ethiack Portal: Built for the Way You Work Now
Meet Idroid: Automated Pentesting for Android Apps
Now Detecting: WP2Shell — Pre-Authentication RCE in WordPress Core (CVE-2026-63030/CVE-2026-60137)
Understanding our Risk Score, and why it reflects real-world conditions
What’s New in Ethiack: Main Product Updates on V2.27, V2.28 and V2.29
Research
Abusing Redirect Discrepancies to leak secrets in URLs
Agentic Problems and the Rise of Zombie AIs
AI Pentester Benchmarks Are Rubbish. So We Made a Better One
AI Pentesting Without the Noise: Hackbots and the Verifier
Bypassing WAFs for Fun and JS Injection with Parameter Pollution
Digital Exposure Analysis of the 500 Largest Portuguese Companies
Evaluating Pentesting Agents for the Real-World - Part 1
Evaluating Pentesting Agents for the Real-World - Part 2
Git Arbitrary Configuration Injection (CVE-2023-29007)
Grafana CVE-2025-6023 Bypass: A Technical Deep Dive
Hackian and the Ghosts in Your Business Logic: When Your App’s Rules Are the Real Vulnerability
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails
Nextcloud CVE-2026-45281 Cross-Account Calendar Takeover
One-click RCE on OpenClaw in under 2 hours with an Autonomous Hacking Agent
Strategy is Key: Evaluating the Pentesting Skills of Frontier LLMs
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE
Resources
Bug Bounty VS Pentesting for SaaS: Which one should you choose?
Everything Financial Institutions Need to Know About the NIS2 Directive
Identifying Vulnerabilities in SaaS: The Guide Updated for 2023
Navigating DORA: How Continuous Penetration Testing Bolsters Your ICT Risk Management Framework and Contributes to Overall Compliance
Navigating DORA: What Every Financial Institution Needs to Know
Risk Assessment: What is it and how to conduct one
The Hidden ROI of Security: How to Put a Number on the Risks You Stop.
The State of Digital Exposure to Cybercrime for European Retail
The State of Digital Exposure to Cybercrime for European Telecoms