Press ReleaseThreat Detection & Defense

ThreatBook Acquires Leading AI‑Native Security Testing Platform CyberStrikeAI

Empowering Security Teams to Identify Highly Concealed Vulnerabilities By Launching Unique, Covert Attacks in a Controlled Environment—Further Enabling Organisations to Achieve Better RiskInformed DecisionMaking

ThreatBook, the agentic security company, has acquired the open‑source AI penetration testing platform CyberStrikeAI. Written in Go, the high‑performance platform will be integrated into ThreatBook’s Red Team capabilities, empowering security teams to identify highly concealed vulnerabilities by launching unique, covert attacks in a controlled environment—further enabling organisations to achieve better risk‑informed decision‑making.

Since CyberStrikeAI’s launch in late 2025, it has garnered over 6,600 stars on GitHub and been deployed in over 2,300 networks, making it one of the most widely used AI penetration testing tools globally.

Following the acquisition, ThreatBook will retain the open‑source version of CyberStrikeAI, while launching an enterprise edition, which can be fully deployed inside the network, and where all data stays on‑premises, accompanied by a full audit trail and permission controls for every agent action. ThreatBook will incorporate additional control mechanisms into the open‑source version to prevent misuse of CyberStrikeAI’s technology.

ThreatBook Is Focused on Enterprise Security and Defence Scenarios

Xue Feng, Founder and CEO of ThreatBook, said: “AI attacks are now evolving far quicker than anyone could have imagined. The assumption that attackers need time to orchestrate their attacks is outdated and simply untrue. The time window that defenders once relied on to respond to attacks has been eroded by automated reconnaissance, mining, and exploitation.”

“Such capabilities should not be confined solely to cybercriminals, APT groups, and saboteurs. They should be in the hands of defenders who are committed to building a safer world, thereby levelling the playing field and enabling defenders to think and act just as attackers do. CyberStrikeAI is a mission‑critical capability that helps security teams achieve this.”

Key CyberStrikeAI capabilities include: one‑command deployment, enabling instant, hassle‑free set‑up; native multiparty computation (MCP) orchestration through standardised tool invocation, freely extensible via YAML files; full attack‑chain coverage with over 100 built‑in tool templates from reconnaissance to exploitation; visual attack‑chain tracking that makes every step of the agent’s progress observable; multi‑model decision engine, allowing users to plug in their preferred large language model (LLM) as the reasoning core; and “natural language in, report out” processing, to describe the target and receive a structured security assessment report.

ThreatBook will continue to invest in the development of both the open‑source and enterprise editions of CyberStrikeAI, making the AI’s autonomous penetration testing capabilities more reliable, controllable, and usable. Effective immediately, ThreatBook has rolled out a trial version of the enterprise edition in mainland China, which is expected to be made available in the rest of APAC next month.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *