Conformal Prediction for Offensive Security
Researchers apply conformal prediction to offensive security, presenting initial findings on privacy-attacking machine learning and network traffic analysis.
The paper observes that conformal prediction (CP), introduced over 25 years ago, has been used mainly defensively in cybersecurity and rarely for offensive purposes. The authors present initial findings applying CP in two offensive areas: attacks on privacy-preserving machine learning and network traffic analysis. The work aims to close a gap in the offensive security literature rather than report an incident.
The Model Proposes, the Code Disposes: A Pre-Registered Ablation of a Verifier-and-Acceptance Stage in an LLM-Orchestrated Offensive-Security Agent
Pre-registered ablation finds a model verifier stage in an LLM offensive-security agent suppresses findings; removing it eliminated suppression with precision tradeoff.
The paper evaluates a verifier-and-acceptance stage in an LLM-orchestrated offensive-security agent via a pre-registered 20-run confirmatory ablation and a 2x2 factorial study with 40 runs on vulnerable lab targets. Removing the stage eliminated pre-report suppression (median 2 vs 0 findings, p = 0.00003) but reduced model-blinded shipped precision (0.471 vs 0.353, p = 0.0087). Suppression was attributed to the model verifier rather than deterministic acceptance rules, and an instrumented canary recorded zero external contacts in all 60 runs. The full design retained 93.8% of model-adjudicated true candidates but failed its pre-registered non-inferiority floor of 0.90.
Cybersecurity jobs available right now: July 28, 2026
July 28, 2026 cybersecurity job listings spanning cloud security, offensive security, AI safety, and application security roles across multiple organizations.
This Help Net Security post lists open cybersecurity positions at Toyota Automated Logistics, VELUX, Maryville University, BlackSea Technologies, AZ Group, Sedha Consulting, Gentex, cyforce, Postman, NVIDIA AI, Matillion, and RBC. Roles include cloud security engineering, offensive security leadership, AI safety research, and vulnerability triage management, spanning USA, Denmark, UAE, Israel, UK, and Canada. Positions are on-site, hybrid, or remote; many noted as no longer accepting applications.
Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa acquired PlexTrac to add pentest-driven validation of remediation, claiming the largest standalone unified exposure management vendor with 3,000+ customers.
Brinqa acquired PlexTrac to add offensive-security-driven validation that remediation actually worked, aiming to close the continuous threat exposure management loop from prioritization through verified fixes. Brinqa says the combination makes it the largest standalone vendor in unified exposure management, serving more than 3,000 customers across 57 countries, with PlexTrac continuing as a standalone product. Brinqa cited 164% year-over-year new-bookings growth in 2025 and inclusion in Gartner's inaugural Magic Quadrant for Exposure Assessment Platforms.
Offensive Security Investments Surge as AI Threats Increase
Omdia's Theresa Lanowitz discusses surging offensive security investment and both the promise and risks of agentic AI in pentesting and red teaming.
In a Dark Reading News Desk interview, Omdia analyst Theresa Lanowitz discusses why organizations are increasing offensive security spending as AI-driven threats grow. She weighs the potential and the risks of applying agentic AI to penetration testing, red teaming, and related offensive security practices.