Ridge Security News

Request a Demo
Experience a live demo and learn more about RidgeBot®.

Recent News Articles

Your Peers Have Something To Say

Ridge Security compromising with customers first

RidgeBot: #1 most reviewed tool for pentesting

July 1, 2026

Ridge Security Appoints Former ST Engineering Technology Leader Ravinder Singh to Advisory Board

Ridge Security, a leader in AI-powered offensive security and adversarial exposure validation, today announced the appointment of Ravinder Singh to its Advisory Board.

Read the full story $

June 26, 2026

New infosec products of the month: June 2026

Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI.

Read the full story $

June 26, 2026

June infosecurity launches highlight shift towards AI governance and autonomous system management

June’s security product releases reveal a market increasingly focused on systems capable of reasoning, deciding, and acting autonomously to combat dynamic cyber threats, moving beyond traditional point tools.

Read the full story $

June 25, 2026

Ridge Security Named a Sample Vendor in the 2026 Gartner Hype Cycle for Security Operations

Ridge Security today announced its recognition as a Sample Vendor in the Adversarial Exposure Validation (AEV) category of the Gartner Hype Cycle for Security Operations, 2026, marking the fourth consecutive year the company has been featured in this research. The acknowledgment positions Ridge Security among a select group of vendors redefining how organizations validate and strengthen their security posture in an era of accelerating threats.

Read the full story $

May 28, 2026

Microsoft criticizes public disclosure of unpatched zero-day vulnerabilities

In a statement published yesterday, Microsoft warned that recent public disclosures of unpatched zero-day vulnerabilities without prior coordination have placed customers at “unnecessary risk.” The company said several researchers disclosed vulnerability details publicly before Microsoft had an opportunity to develop and distribute security fixes.

Read the full story $

May 29, 2026

The Collapse Equation

In September 2025, Anthropic’s threat intelligence team detected something unprecedented. A Chinese state-sponsored hacking group, which the company designated GTG-1002, had manipulated Claude Code into attempting infiltration of roughly thirty global targets spanning major technology companies, financial institutions, chemical manufacturers, and government agencies. The AI executed 80 to 90 per cent of the campaign autonomously, with human operators intervening at perhaps four to six critical decision points per intrusion. At peak operation, the system generated thousands of requests per second. This was attack velocity that human hackers could never match.

Read the full story $

May 28, 2026

5 lessons from vulnerability management’s front lines

What separates organizations that fix their vulnerabilities from those that don’t? That’s what the research team at Semgrep wanted to know when it set out to analyze anonymized remediation patterns across thousands of actively developed repositories and organizations.

Read the full story $

May 27, 2026

Six Highlights from the 2026 Verizon DBIR Every Security Team Should Know

The 2026 Data Breach Investigations Report reflects a threat environment that is not only growing in volume but shifting in character. Here are the findings that matter most for security teams:

Read the full story $

May 27, 2026

Why AI Could Make Cybersecurity One of the Hottest Jobs in Tech

According to a new report from The New York Times this week, artificial intelligence will continue to upend jobs, notably in the tech sector. Still, it could help “fuel a new wave of hiring for cybersecurity jobs.” The paper of record added that demand is “so fierce” that some search firms are now turning away clients due to a shortage of qualified candidates to fill the openings.

Read the full story $

May 26, 2026

Why Annual Penetration Tests Are No Longer Enough

Traditional annual penetration tests are becoming less effective as organizations rapidly expand cloud, hybrid, and AI-driven environments that change far faster than yearly assessment cycles can keep up with.

Read the full story $

May 20, 2026

Anthropic Allows Glasswing Partners to Share Mythos-Based Findings

When Anthropic early last month unveiled Mythos, the high-flying AI company limited access to the frontier model for fear that its advanced capabilities in detecting software vulnerabilities could be used by bad actors to quickly create exploits for software flaws it finds.

Read the full story $

May 18, 2026

Security Breach at Polish Water Treatment Plants Enables Manipulation of Industrial Control Systems

A security breach at Polish water treatment plants may have allowed hackers to take control of the industrial equipment and tamper with water quality, according to an official report.

Read the full story $

May 15, 2026

Researchers warn AI cyber models have surpassed autonomous hacking benchmarks

Two independent studies found that advanced AI cybersecurity models, including Anthropic’s Claude Mythos Preview and OpenAI’s GPT-5.5, have exceeded previous benchmarks for autonomous cyberattack capability. Researchers from the UK AI Security Institute (AISI) and Palo Alto Networks said the models are now capable of chaining together complex multi-stage attack paths and identifying vulnerabilities at rates that significantly outpace earlier systems.

Read the full story $

May 12, 2026

Ridge Security’s RidgeBot® Wins 2026 GOVIES Award for AI-Powered Offensive Security Platform

Ridge Security today announced that its RidgeBot® platform has been named a winner in the AI-Powered Offensive Security Platform category in the 2026 Security Today GOVIES Awards.

Read the full story $

May 11, 2026

Polish ABW warns cyberattacks shifting from espionage and data theft toward physical disruption of critical infrastructure

Poland’s Internal Security Agency (ABW) disclosed that cyberattacks targeting ICS (industrial control systems) and public infrastructure escalated sharply through 2024 and 2025, with several incidents coming close to causing real-world disruption to essential services. In its newly published annual report, the agency identified that water treatment facilities in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo were breached during 2025. Investigators found that attackers gained access to the operational systems that control water treatment processes, systems designed to ensure the safe delivery of water to local communities.

Read the full story $

May 10, 2026

Polish intelligence warns hackers breached water treatment control systems – Expert Comments

Poland’s Internal Security Agency (ABW) said hackers breached water treatment facilities in five Polish towns during 2025, in some cases gaining access to industrial control systems (ICS) capable of disrupting water operations. According to the agency, attackers were able to alter technical device parameters, creating what officials described as a “direct risk” to the continuity of water supplies.

Read the full story $

May 8, 2026

Mothers Know Best

At a Microsoft event many years ago, the author Steven Berlin Johnson marveled at the information, knowledge of relationships, dots that got connected and wisdom that formed in a mother’s brain. He was describing the almost mythical powers of his wife, who juggled motherhood with a career as a medical researcher then a screenwriter, to remember birthdays, schedules, doctors’ appointments, food allergies, and family dynamics, not only of their own children but children in their ecosystem.

Read the full story $

May 7, 2026

Selective NVD enrichment: Why it matters

To the dismay of many security pros, the U.S. Department of Commerce’s National Institute of Standards and Technology has announced that it is scaling back the enrichment of Common Vulnerabilities and Exposures (CVEs) in the National Vulnerability Database (NVD).

Read the full story $

May 7, 2026

Security Today Announces the 2026 Government Security Awards “The GOVIES” Winners

Today, Security Today, the leading industry media brand for the global security marketplace, announced the winners of the 2026 Government Security Awards “The GOVIES,” recognizing organizations driving innovation across the security industry.

Read the full story $

May 5, 2026

Frost & Sullivan Recognizes Picus Security as the 2026 Global Company of the Year for Advancing Automated Security Validation

Frost & Sullivan today announced that it has awarded Picus Security the 2026 Global Company of the Year recognition in the automated security validation industry. This recognition highlights Picus Security’s consistent leadership in delivering measurable security outcomes, advancing innovation, and driving customer impact in a rapidly evolving threat landscape.

Read the full story $

May 1, 2026

Identity Management and Information Security News for the Week of May 1st: Keeper Security, JumpCloud, Silverfort, and More

Keeping tabs on all the most relevant Identity Management and Information Security news can be time-consuming. As a result, our editorial team aims to summarize some of the top headlines in the space by curating a collection of the latest vendor product news, mergers and acquisitions, venture capital funding, talent acquisition, and other noteworthy news. With that in mind, here is some of the top identity management and information security news from the week of May 1st.

Read the full story $

May 1, 2026

Endpoint Security and Network Monitoring News for the Week of May 1st: Entrust, Auvik, Suzu Labs, and More

Keeping up with all the most relevant Endpoint Security and Network Monitoring news can be time-consuming. As a result, our editorial team aims to summarize some of the top headlines in the space by curating a collection of the latest vendor product news, mergers and acquisitions, venture capital funding, talent acquisition, and other noteworthy news. With that in mind, here is some of the top endpoint security and network monitoring news from the week of May 1st.

Read the full story $

April 29, 2026

Ridge Security integrates RidgeBot with CrowdStrike SIEM

Ridge Security has integrated its RidgeBot product with CrowdStrike Falcon Next-Gen SIEM, bringing validated attack findings from automated penetration testing into CrowdStrike’s security information and event management platform.

Read the full story $

April 29, 2026

Ridge Security Integrates Attack Insights into CrowdStrike Falcon Next-Gen SIEM

As organizations face increasing volumes of vulnerabilities and alerts, security teams often lack clarity into which exposures represent real, exploitable risk. By bringing RidgeBot’s validated attack findings into the CrowdStrike Falcon® platform, organizations can prioritize remediation based on proven attack paths and reduce noise across security operations.

Read the full story $

April 29, 2026

Daily CyberTech Highlights: Essential News and Analysis

As security teams struggle with alert fatigue and growing vulnerability backlogs, prioritizing real, exploitable risks has become a critical challenge in modern cyber defense. Ridge Security has announced a new integration that brings automated penetration testing insights directly into CrowdStrike Falcon Next Gen SIEM. The RidgeBot integration with CrowdStrike Falcon is designed to help organizations identify which vulnerabilities pose genuine threats by delivering validated attack insights into existing security workflows.

Read the full story $

April 29, 2026

Ridge Security Brings Validated Attack Insights into CrowdStrike Falcon Next-Gen SIEM

Ridge Security today announced an integration that enables automated penetration testing insights from RidgeBot® to flow into CrowdStrike Falcon® Next-Gen SIEM.

Read the full story $

April 16, 2026

Frost Recognises Ridge Security for Product Innovation

Frost & Sullivan has recognised Ridge Security with the 2026 Global New Product Innovation Recognition in the Automated Security Validation industry for its outstanding achievements in innovation, strategy execution, and customer impact. This recognition highlights Ridge Security’s consistency in driving measurable outcomes, strengthening its market position, and delivering customer-centric innovation in an increasingly complex threat landscape.

Read the full story $

April 10, 2026

Anthropic’s Claude Mythos Autonomously Discovers, Exploits Zero-Days

Anthropic has unveiled Claude Mythos Preview, a new AI model with cybersecurity capabilities the company’s researchers are calling a watershed moment for the industry. Unlike prior models that could identify vulnerabilities but rarely exploit them, Mythos Preview autonomously discovers and weaponizes zero-day flaws—including across every major operating system and web browser—without human intervention beyond an initial prompt.

Read the full story $

April 9, 2026

Anthropic restricts release of new AI model after it identifies hundreds of zero-day vulnerabilities

Anthropic has unveiled a new AI model, Claude Mythos Preview, capable of identifying hundreds of previously unknown high-severity vulnerabilities, including more than 500 zero-day flaws in open-source software during testing. The model demonstrated the ability to autonomously analyze codebases and surface security weaknesses at scale, significantly accelerating vulnerability discovery.

Read the full story $

April 8, 2026

Cyber Industry Reacts to Anthropic’s Project Glasswing as AI Accelerates the Race to Secure Software

Anthropic this week unveiled Project Glasswing, a coordinated effort with industry heavyweights including Amazon, Apple, Microsoft, Cisco, CrowdStrike, Broadcom, Palo Alto Networks, and the Linux Foundation. The initiative centers on a new AI system called Claude Mythos Preview, a model designed to uncover deeply embedded software vulnerabilities at a scale that traditional tools have failed to reach.

Read the full story $

April 7, 2026

Fortinet issues emergency weekend patch for actively exploited FortiClient EMS zero-day

Over the weekend, Fortinet released an emergency security update for a critical FortiClient Enterprise Management Server (EMS) vulnerability (CVSS 9.1), after confirming it is being actively exploited in the wild.

Read the full story $

April 6, 2026

Meta pauses work with Mercor after supply chain breach raises risk to AI training data

As first reported by Wired on Friday, Meta has paused all work with AI data startup Mercor following a confirmed security breach linked to a supply chain attack involving the LiteLLM open-source project, which impacted thousands of organizations globally.

Read the full story $

April 3, 2026

MSPs Can’t Scale Without AI, Vendors Say at RSAC

MSPs couldn’t escape one key message at the RSA Conference this year: you can’t scale security operations without AI anymore. In fact, AI security tools for MSPs have quickly become essential.

Read the full story $

April 2, 2026

The European Commission confirms attack on its Europa web platform

The European Commission has confirmed a cyberattack affecting its Europa.eu web platform, with initial reports indicating that the attackers accessed the data from the cloud infrastructure provided by AWS.

Read the full story $

April 1, 2026

Ridge Security Wins 2026 Innovation Award for RidgeBot

Ridge Security announced it has earned the Frost & Sullivan 2026 Global New Product Innovation Recognition for Automated Security Validation, honoring companies that set a new standard in solving critical security challenges.

Read the full story $

April 1, 2026

Ridge Security Receives Frost & Sullivan’s 2026 Global New Product Innovation Recognition for Leadership in Automated Security Validation

Frost & Sullivan is pleased to announce that Ridge Security has been recognized with the 2026 Global New Product Innovation Recognition in the Automated Security Validation industry for its outstanding achievements in innovation, strategy execution, and customer impact. This recognition highlights Ridge Security’s consistency in driving measurable outcomes, strengthening its market position, and delivering customer-centric innovation in an increasingly complex threat landscape.

Read the full story $

March 30, 2026

The EU Gets Pwned By ShinyHunters

The European Commission has confirmed a cyberattack affecting its Europa.eu web platform, with early findings indicating that data was extracted from cloud infrastructure hosted on Amazon Web Services (AWS). The incident was discovered on March 24, 2026, and officials said the breach was contained while an investigation into the full scope remains ongoing.

Read the full story $

March 30, 2026

Bringing the cyber community into the battle against agentic insecurity at RSAC 2026

At the RSAC2026 Conference, practitioners and vendors came together to hear a new story focused less on prevention, and more on adaptation ahead of the inevitability of change brought on by the rapid enterprise adoption of agentic artificial intelligence coding agents and autonomous automation — whether the cybersecurity community is ready for it or not.

Read the full story $

March 24, 2026

Ridge Security Launches PurpleRidge 3.0 with Autonomous AI Pentesting

Ridge Security, a Silicon Valley-based innovator in AI-powered penetration testing and Continuous Threat Exposure Management (CTEM), has unveiled PurpleRidge Security™ 3.0 at RSAC 2026. With this latest release, the company strengthens its commitment to delivering advanced, autonomous cybersecurity solutions specifically designed for small and medium businesses (SMBs) and Managed Security Service Providers (MSSPs).

Read the full story $

March 24, 2026

Ridge Security Unveils Agentic AI Penetration Testing Platform to Bring Continuous Security Validation to SMBs

At RSAC 2026, Ridge Security introduced a new iteration of its PurpleRidge Security platform, positioning it as a shift in how smaller organizations approach penetration testing and continuous threat exposure management. The Silicon Valley company, known for its AI-driven offensive security tools, is now leaning into agentic AI to automate what has traditionally been a labor-intensive and costly process.

Read the full story $

March 23, 2026

Ridge Security Brings Agentic AI Pentesting to SMBs With PurpleRidge 3.0

Ridge Security released PurpleRidge 3.0 at RSAC 2026, a self-service penetration testing platform that uses agentic AI to give small and mid-sized businesses the kind of offensive security validation that has traditionally required dedicated teams and six-figure budgets.

Read the full story $

March 23, 2026

Ridge Security Introduces PurpleRidge 3.0 at RSAC 2026, Bringing Autonomous AI Pentesting to SMBs and MSSPs

Ridge Security, a Silicon Valley-based leader in AI-powered penetration testing and Continuous Threat Exposure Management (CTEM), today announced at RSAC 2026 the latest version of PurpleRidge Security™, a fully self-service, agentic AI-based autonomous penetration testing service purpose-built for small and medium businesses (SMBs) and Managed Security Service Providers (MSSPs).

Read the full story $

March 13, 2026

Iranian cyber shift raises risk to Western infrastructure

Cybersecurity experts warn that Iranian state-aligned hackers may be shifting from reconnaissance to potentially destructive operations against Western and allied infrastructure, as Middle East tensions raise the risk of wider cyber escalation.

Read the full story $

March 9, 2026

Secure the Service Bay

Automotive service shops often must remind customers that being proactive about maintenance is the key to keeping a vehicle on the road. Unfortunately, many shop owners need to be reminded of the importance of taking preventative measures to protect their shop data.

Read the full story $

March 4, 2026

After Operation Epic Fury, Iran May Turn to Cyberwar — Are U.S. Networks Ready?

Last Saturday, the United States military began its Operation Epic Fury, which saw U.S. Air Force aircraft strike positions in Iran, resulting in the death of Supreme Leader Ali Khamenei along with more than 40 high-ranking government officials.

Read the full story $

March 2, 2026

Iranian Cyber Actions, Threats, Mitigation Recommendations

Given the fact that Iran was attacked by the US and Israel over the weekend, and Iran is a known bad cyber actor, it’s time to have a discussion about what threats that Iran can pose. Thus I have four experts to share their thoughts on this important topic.

Read the full story $

February 27, 2026

When Hackers Leverage AI: Defending What You Don’t Know Is Exposed

Cybersecurity has always been adversarial. Defenders build controls, attackers find ways around them, and the cycle repeats. But artificial intelligence has fundamentally altered this dynamic. Today’s attackers are using AI to reason, coordinate and explore environments in ways traditional security tools were never designed to detect.

Read the full story $

February 20, 2026

CISA Warns of Critical Security Vulnerability in Honeywell Cameras

CISA has warned that a critical security vulnerability (CVE-2026-1670) has been identified in four Honeywell CCTV camera models.

Read the full story $

February 12, 2026

Ridge Security、TMCnetおよびINTERNET TELEPHONY誌による2025 Cybersecurity Excellence Awardを受賞

米国時間2026年2月11日、Ridge Security社は、TMCがTMCnetおよびINTERNET TELEPHONY誌を通じて授与する2025 Cybersecurity Excellence Awardの受賞者として、同社のRidgeBot®を選定したことを発表しました。

Read the full story $

February 19, 2026

The CISA Has Provided Two Warnings That You Should Pay Attention To

The CISA has given US government agencies three days to patch their systems against a maximum-severity hardcoded credential vulnerability (CVE-2026-22769)in Dell’s RecoverPoint solution exploited by the UNC6201 Chinese hacking group since mid-2024 https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog.

Read the full story $

February 17, 2026

PurpleRidge Launches Automated AWS Account Audit to Stop “8-Minute” AI-Assisted Cloud Attacks

PurpleRidge (powered by RidgeBot® from Ridge Security) today announced the launch of its Automated AWS Account Audit, a direct response to recent security research showing attackers can compromise a cloud environment in as little as eight minutes.

Read the full story $

February 11, 2026

Ridge Security Awarded a 2025 Cybersecurity Excellence Award by TMCnet and INTERNET TELEPHONY Magazine

Ridge Security today announced that TMC has named RidgeBot® as a recipient of the 2025 Cybersecurity Excellence Award presented by TMCnet and INTERNET TELEPHONY magazine.

Read the full story $

February 10, 2026

Ridge Security Appoints Dan Mrvos as Vice President of Sales

Ridge Security, leader in AI-powered offensive security for Continuous Threat Exposure Management (CTEM), today announced that Dan Mrvos has joined the company as Vice President of Sales. Mr. Mrvos will report to CEO Nick Mo and lead global sales as Ridge Security continues to scale its business. He brings more than 30 years of experience building and growing emerging technology companies, from early-stage startups through IPO, as well as turnaround and acquisition environments.

Read the full story $

February 10, 2026

Fighting AI with AI: A Practical View of the New Cybersecurity Reality

This year, attackers began using AI in a much more aggressive and systematic way. The threat is real and will continue to grow in 2026. We have already seen real breaches where attackers use advanced AI models to automate most of their steps. Moreover, we are seeing malware that can rewrite itself in real time to avoid detection.

Read the full story $

February 6, 2026

Moltbook ‘vibe-coded’ flaw exposed AI chats & keys

A new social media service called Moltbook left its backend database publicly accessible due to a security misconfiguration, exposing private AI conversations, user email addresses, and large volumes of API keys, according to Wiz Security.

Read the full story $

February 5, 2026

SolarWinds Appears To Be Back From The Dead

The CISA has added to its KEV catalog and is giving federal agencies till Friday to patch the actively exploited, critical security (9.8) flaw reported last week in SolarWinds’ Web Help Desk software.

Read the full story $

February 2, 2026

TMC Announces 2025 Cybersecurity Excellence Award Winners, Presented by TMCnet

TMC, a global, integrated media company helping technology vendors build influence and demand through in-person and digital programs, today announced the winners of the 7th TMCnet Cybersecurity Excellence Awards.

Read the full story $

January 9, 2026

Endpoint Security and Network Monitoring News for the Week of January 9th: Exabeam, Hexnode, Ridge Security, and More

Ridge Security, an AI-powered provider of offensive security for Continuous Threat Exposure Management (CTEM), has announced two new features for RidgeBot 6.0. These additions include AWS Security Audit and Windows Authenticated Pentest enhancements, which will improve context-aware offensive security validation across IT, OT, and AI infrastructure.

Read the full story $

January 8, 2026

Ridge Security Announces Powerful New AWS, Windows Pentesting Features for RidgeBot 6.0

Ridge Security, leader in AI-powered offensive security for Continuous Threat Exposure Management (CTEM), today announced two new features for RidgeBot 6.0 that enhance context-aware offensive security validation across IT, OT, and AI infrastructure – AWS Security Audit and Windows Authenticated Pentest enhancements.

Read the full story $

January 6, 2026

Ridge Security Achieves ISO/IEC 27001 Certification

Ridge Security, leader in AI-powered offensive security for Continuous Threat Exposure Management (CTEM), today announced that it has achieved ISO/IEC 27001 certification, the globally recognized standard for information security management systems (ISMS).

Read the full story $

December 29, 2025

Ransomware Gang Exploits Oracle Zero-Day to Steal Data of 3.5 Million University of Phoenix Students and Staff

The growing role of automation and artificial intelligence in these attacks is drawing increased scrutiny from security leaders and policymakers alike. Hom Bahmanyar, Global Enablement Officer at Ridge Security Technology Inc., said the University of Phoenix breach reflects a broader escalation that organizations are struggling to keep pace with.

Read the full story $

December 29, 2025

University of Phoenix Discloses 3.5M-Record Data Breach Linked to Oracle EBS Zero-Day

In a news brief circulated in connection with the incident, Hom Bahmanyar, Global Enablement Officer at Ridge Security Technology Inc., argued the breach fits a broader pattern of accelerating cyber risk and emphasized a shift toward proactive, validation-led security programs.

Read the full story $

December 15, 2025

AI Cyberthreats: The Rise of Counter-AI

“Only when we can continuously think and act like a hacker can we truly protect our environment,” said Nick Mo, CEO of Ridge Security. He noted that AI now makes it possible to simulate attacks at scale to validate security postures continuously, rather than relying on static alerts or occasional penetration testing.

Read the full story $

December 15, 2025

LW ROUNDTABLE: Part 3, Cyber resilience faltered in 2025 — recalibration now under way

Attackers weaponized AI at speed and scale in 2025, automating reconnaissance and exploiting continuously. Defenders are restricted by compliance while adversaries run unconstrained. Small and mid sized organizations bear the brunt because they lack operational flexibility and face the same threats as large enterprises.

Read the full story $

December 15, 2025

LW ROUNDTABLE: Part 3, Cyber resilience faltered in 2025 — recalibration now under way

Attackers weaponized AI at speed and scale in 2025, automating reconnaissance and exploiting continuously. Defenders are restricted by compliance while adversaries run unconstrained. Small and mid sized organizations bear the brunt because they lack operational flexibility and face the same threats as large enterprises.

Read the full story $

August 5, 2024

How GenAI Uses Data Consumption And Learning To Transform Cybersecurity

GenAI’s transformative power is evident in its robust data consumption and adaptive learning capabilities. It has the potential to revolutionize outcomes in almost every scenario.

Read the full story $

December 11, 2025

Marquis Ransomware Breach: When Third-Party Vendors Become the Weakest Link in Financial Services

However, Lydia Zhang, President of Ridge Security, argues the breach is more closely related to CVE-2024-53704, a different SonicWall SSL VPN vulnerability.

Read the full story $

December 10, 2025

Over 4 billion lead-generation records exposed, including LinkedIn profiles 

Hom Bahmanyar, Global Enablement Officer, Ridge Security Technology Inc. says: “The widespread misconception that detection of weak credentials across an organization’s assets requires specialized GPUs and scheduled downtime has unfortunately led to inaction on the part of many organizations.”

Read the full story $

December 9, 2025

United States Penetration Testing Market 2031 | Growth Drivers, Key Players & Investment Opportunities

In March 2025, Ridge Security released version 5.2 of RidgeBot, an AI‐driven automated pentesting platform, enhancing automated vulnerability discovery and validation capabilities for enterprises.

Read the full story $

December 8, 2025

RidgeBot Available on Microsoft Azure Marketplace

Ridge Security has made its flagship AI-powered solution, RidgeBot®, available on the Microsoft Azure Marketplace, Microsoft’s online store providing applications and services for use on Azure.

Read the full story $

December 4, 2025

Ransomware attack on Marquis Software Solutions targeted 74 banks

Lydia Zhang, president of Ridge Security, said this recent attack was more closely related to CVE-2024-53704 rather than CVE-2024-40766. Zhang said the “53704” SonicWall SSL VPN vulnerability leaks the swap cookie and session ID, which lets a remote attacker bypass authentication and take over an existing session.

Read the full story $

December 3, 2025

Aisuru, “the apex of botnets”, 29.7 Tbps DDoS attack highlighted by Cloudflare

Lydia Zhang, President & Co-Founder, Ridge Security Technology Inc. had this to say: “The ironic thing is that organizations often don’t realize their IoT devices or routers have been compromised until a DDoS attack occurs.”

Read the full story $

November 25, 2025

Ridge Security debuts on Microsoft Azure Marketplace

Ridge Security has launched its AI-powered RidgeBot penetration testing platform on the Microsoft Azure Marketplace, providing organizations with a streamlined path to automate and continuous security validation, Security Brief Australia reports.

Read the full story $

November 24, 2025

Salesforce Confirms the Gainsight Incident Resulted in Customer Data Being Accessed

Lydia Zhang, President & Co-Founder of Ridge Security Technology, adds that it’s clear that once attackers succeed in a large-scale breach, it becomes progressively easier for them to leverage the compromised data and tokens to achieve additional attacks. 

Read the full story $

November 22, 2025

Salesforce: Some Customer Data Accessed via Gainsight Breach

Lydia Zhang, co-founder and president of Ridge Security Technology, said that “the message for defenders is that patching the initially ‘broken’ door isn’t enough. You must thoroughly inspect every part of your environment to ensure the attackers cannot reuse access from a prior breach to open new doors.”

Read the full story $

November 21, 2025

Salesforce confirms 200+ orgs impacted by another third party Gainsight breach

Lydia Zhang, President & Co-Founder,Ridge Security Technology Inc. followed up with this: “It’s clear that once attackers succeed in a large-scale breach, it becomes progressively easier for them to leverage the compromised data and tokens to achieve additional attacks.

Read the full story $

November 20, 2025

Ridge Security Brings AI-Powered Penetration Testing to Microsoft Azure Marketplace to Enable Continuous Security Validation at Scale

Ridge Security, a leading innovator in automated penetration testing and continuous security validation, has made its flagship AI-powered solution, RidgeBot®, available on the Microsoft Azure Marketplace, Microsoft’s online store providing applications and services for use on Azure.

Read the full story $

November 18, 2025

Users Pasting Malware With Just One Shortcut

Lydia Zhang, President at Ridge Security Technology, told Infosecurity Magazine, “Without thorough security testing or a widely accepted industry standard established before setting cyber insurance terms, it opens the door to hackers who can then target organizations with the highest coverage.”

Read the full story $

November 18, 2025

Cyber Insurance Cost Spikes Continue in UK as Annual Numbers Triple

Lydia Zhang, President & Co-Founder, Ridge Security, believes that this move will do little to curb criminals intentionally targeting organizations known to have strong policies: “It’s ironic that cyber insurance has become a viable solution. Without thorough security testing or a widely accepted industry standard established before setting cyber insurance terms, it opens the door to hackers who can then target organizations with the highest insurance coverage.”

Read the full story $

November 12, 2025

Ridge Security Scores a 95% Willingness to Recommend in the 2025 Gartner Peer Insights™ Voice of the Customer for Adversarial Exposure Validation

Ridge Security, leader in AI-powered offensive security for Continuous Threat Exposure Management (CTEM), today announced that it was the second highest vendor to score a willingness to recommend with 95% in the 2025 Gartner’s Peer Insights “Voice of the Customer” for Adversarial Exposure Validation.

Read the full story $

November 12, 2025

Cyber-Insurance Payouts Soar 230% in UK

“It’s ironic that cyber insurance has become a viable solution,” argued Ridge Security Technology president, Lydia Zhang.

Read the full story $

November 12, 2025

UK insurers pay nearly £200m to help businesses recover from cyber attacks

Lydia Zhang, President & Co-Founder, of Ridge Security Technology, added: “In July, the UK government said it plans to ban public bodies from paying ransoms to computer hackers. Private companies will also be required to inform authorities if they intend to comply with ransom demands.” 

Read the full story $

October 6, 2025

Ridge Security Announces RidgeGen, the Company’s Agentic AI Framework Driving the Next Evolution in Autonomous Security Validation

Ridge Security, leader in AI-powered offensive security for Continuous Threat Exposure Management (CTEM), today announced RidgeGen, a comprehensive Agentic AI framework designed to take security validation from automation to autonomy. Powered by RidgeGen, Ridge Security’s flagship product, RidgeBot, delivers intelligent, context-aware offensive security validation across the IT, OT, and AI infrastructure.

Read the full story $

April 30, 2025

Ridge Security Launches RidgeSphere: A Centralized Management Platform for Multi-Tenant RidgeBot Deployments

Ridge Security, a security validation leader in Continuous Threat Exposure Management, today announced RidgeSphere, a centralized management platform designed to simplify the orchestration of multiple RidgeBot.

Read the full story $

March 17, 2025

Ridge Security Named to the Prestigious CRN Tech Elite 250 for 2025

Ridge Security, leader in AI-powered Offensive Security for CTEM, today announced that CRN, a brand of The Channel Company, has recognized Ridge Security on its 2025 Tech Elite 250 list.

Read the full story $

March 4, 2025

Ridge Security Announces RidgeGen in RidgeBot 5.2: A GenAI-Based Security Service Module Enhancing Security Validation Efficiency and Accuracy

Ridge Security, a leader in AI-powered security validation, is excited to announce the release of RidgeBot® 5.2, featuring RidgeGen, an advanced security service module powered by specially trained Generative AI (GenAI) language models.

Read the full story $

September 9, 2024

Ridge Security Bolsters its Board, Appointing Paul Auvil Senior Advisor

Paul Auvil brings over 35 years of finance, technology, and corporate leadership experience. He has worked for leading cybersecurity and technology companies, bringing a keen understanding and wealth of knowledge and expertise to Ridge Security.

Read the full story $

August 29, 2024

Top 10 Penetration Testing Solution Providers 2024

Traditional security measures, while essential, are no longer sufficient to protect against the complex and persistent attacks that can cripple a business. 

Read the full story $

August 5, 2024

Ridge Security Recognized in Gartner’s 2024 Hype Cycle for Security Operations for Its Innovative Approach to Adversarial Exposure Validation

Ridge Security, a leading provider of AI-powered automated security validation proudly announces its inclusion in the newly published Gartner Hype Cycle for Security Operations 2024. Ridge Security has been recognized in the newly defined category of Adversarial Exposure Validation under Continuous Threat Exposure Management (CTEM) framework.

Read the full story $

June 3, 2024

Ridge Security Technology Honored as Publisher’s Choice DevSecOps Vanguard and Lydia Zhang Named Market Leader Pioneering Woman in Cybersecurity

Ridge Security Technology is proud to announce that it has been awarded the “Publisher’s Choice DevSecOps Vanguard 2024” and its co-founder and president, Lydia Zhang, has been honored as a “Market Leader Pioneering Woman in Cybersecurity 2024” by the Global InfoSec Awards.

Read the full story $

May 7, 2024

Ridge Security Technology Named Most Promising Cybersecurity Startup, Winner of the Coveted Global InfoSec Awards at RSA Conference 2024

Ridge Security Technology is proud to announce that it has been recognized as the “Most Promising Cybersecurity Startup” and its CEO, Nick Mo, received the prestigious Next Gen Visionary Cyber CEO Awardfrom Cyber Defense Magazine.

Read the full story $

March 18, 2024

A Tale of Overcoming Cyber Threats with Auto Pentesting and CTEM

Chief Information Security Officer (CISO) Emily Reed is responsible for safeguarding the digital assets of a thriving healthcare organization renowned for its advanced digital technology solutions.

Read the full story $

March 12, 2024

Like Digital Cicadas,Like Digital Cicadas, Cybercriminals Lie In Wait Before Unleashing Their PresenceLike Digital Cicadas,

A curious parallel can be drawn between cybercriminals and the intriguing phenomenon of Cicadas. Akin to the periodic insects that emerge from the ground after years of dormancy, cybercriminals often resurface with renewed vigor, unleashing their disruptive activities on unsuspecting organizations.

Read the full story $

March 4, 2024

Ridge Security: Elevating Cyber Defenses with Rapid, AI-Driven Penetration Testing

Penetration testing reveals computer system weaknesses and seeks to exploit them. However, implementing such a test is costly and impractical due to the extensive human hours required. As a result, completing the test and generating a report typically takes two weeks.

Read the full story $

February 26, 2024

Ridge Security Partners with BROAD Corporation to Deliver Top Tier Security Solutions in Japan

Ridge Security, cutting-edge AI-powered security validation solution provider, announced it has signed a partnership with BROAD Corporation, to equip enterprise customers in the Japan market with top-tier solutions to enhance security operations and protect critical assets and infrastructure.

Read the full story $

February 7, 2024

Ridge Security Recognized as a Strong Performer in the 2024 Gartner® Peer Insights™ Voice of the Customer.

Ridge Security, a leader in automated penetration testing and AI-powered security validation for CTEM, today announced Gartner Peer Insights placed it in the upper-left Strong Performers quadrant of the “Voice of the Customer.” The Ridge Security rating of 4.7 out of 5 stars, with 94 % of customers indicating a “Willingness to Recommend.”

Read the full story $

January 9, 2024

Deciphering Cybersecurity Vulnerabilities Requires Context

Imagine two security analysts engaging in conversation about the intricacies of their work when one receives hundreds of vulnerability alerts; all scored high risk at seven or eight. Throwing his hands up in frustration, he asks his co-worker, “What are we supposed to do with all this? Where do we start?” After a glance, the second analyst replies, “Well, there’s zero context from the vulnerability scanner. So, looks like no lunch break for us today, buddy … or tomorrow.”

Read the full story $

December 26, 2023

Cybersecurity Teams Have to Do More Than ‘Walk and Chew Gum at the Same Time’

The old idiom ‘Can you walk and chew gum at the same time’ was initially used as a negative slam regarding an individual’s level of competence. In light of today’s threat landscape, the question for organizations might be, “Can your security team handle the multiple tasks and numerous processes required to detect, respond, and mitigate escalating cyber threats at the same time?” Called upon to become super multitaskers, they must successfully address routine and unexpected challenges without compromising quality or efficiency.

Read the full story $

September 7, 2023

AI Data Consumption and Analysis are a Cybersecurity Force Multiplier

AI’s capacity to consume, assimilate and use massive datasets from numerous resources is the driving force behind significant advancements in most industries. AI-driven technologies provide deeper data insights to improve health care outcomes and optimize operational processes in manufacturing, for example. AI technologies to improve security outcomes are also being deployed to detect and prevent cyberattacks. While these AI use cases differ in their procedures and goals, the common denominator is the value of leveraging data intelligence.

Read the full story $

September 19, 2023

Are Unparalleled AI Deployments Outpacing Cybersecurity Capabilities?

There is a growing concern that the increasing use of AI could create a tipping point where the technology grows and permeates our personal lives and businesses rapidly, building upon itself while cyber protections are still catching up. 

Read the full story $

August 22, 2023

Achieving a Successful Continuous Threat Exposure Management Program

If your organization is concerned about increasing and expanding cyber threats, you are not alone. While many enterprises recognize the need to create a multi-layered security posture, this article explores the importance of Continuous Threat Exposure Management (CTEM) and how it can help proactively manage risks and bolster defences against growing cyber threats.

Read the full story $

August 22, 2023

Achieving a Successful Continuous Threat Exposure Management Program

If your organization is concerned about increasing and expanding cyber threats, you are not alone. While many enterprises recognize the need to create a multi-layered security posture, this article explores the importance of Continuous Threat Exposure Management (CTEM) and how it can help proactively manage risks and bolster defences against growing cyber threats.

Read the full story $

August 3, 2023

Gartner Hype Cycle for Security Operations Spotlights Ridge Security in Two Critical Security Categories

Ridge Security, a leading exposure management provider, is proud to announce that is has been included in two distinct categories of the Gartner Hype Cycle for Security Operations 2023. RidgeBot, the AI-Powered automated security validation solution, is included in the following two categories: Automated Penetration Testing and Red Teaming Technology, and Breach and Attack Simulation.

Read the full story $

April 25, 2023

Ridge Security Takes Home Two Coveted Global InfoSec Awards

Ridge Security secures Most Innovative Cloud Workload Protection and Best Web Penetration Test Solution in 11th Annual Global InfoSec Awards. RidgeShield integrated with RidgeBot® combines the power of automated security testing and cloud workload protection for maximum protection.

Read the full story $

September 28, 2022

The Evolution of Vulnerability Scanning and Pentesting

An awareness of unprotected vulnerabilities and risks is the starting point for determining the best way to align resources with cybersecurity. By conducting regular real-world attack testing, security operations can illuminate weaknesses while gaining control over risks. Cybersecurity testing is deployed to eliminate risk, improve business continuity and meet compliance requirements.

Read the full story $

September 13, 2022

Ridge Security and Stellar Cyber Partner to Deliver an AI-Driven, High-Fidelity, Open XDR Security Platform

The integration between Stellar Cyber Open XDR and Ridge Security’s RidgeBot reduces enterprise risk with streamlined operations and data for instant remediation and response.

Ridge Security, the cutting-edge automated security validation solution provider, announced it has partnered with Stellar Cyber, the innovator of Open Extended Detection and Response (XDR), to deliver an integrated solution that streamlines security operations and consolidates multi-sourced data and insights into one single platform to quickly and automatically investigate and remediate threats.

Read the full story $

August 31, 2022

The Value of Integrating Exposure Management into MSSP/MDR Security Stacks

Complete 360-degree protection of customer assets with exposure management allows MSSPs and MDRs to expand their capabilities beyond hunting for active threats that target systems. They can now analyze and prioritize their customer’s risks, while providing a more complete picture of their entire threat landscape with a kill chain for each attack.

Read the full story $

June 8, 2022

Ridge Security Announces Security Validation Hyperautomation Solution at RSAC 2022

RidgeBot 4.0 combines two testing methodologies into one system: automated pentesting and adversary cyber emulation

Ridge Security, a cutting-edge security validation automation solution provider, today announced the availability of RidgeBot 4.0, a major update to its proven, automated penetration testing capabilities. RidgeBot 4.0 unifies the blackbox based automated penetration testing and agent-based adversary cyber emulation testing into a single platform and management to deliver 360-degree enterprise security validation testing – now with expanded use cases. RidgeBot 4.0 also enables managed security service providers (MSSPs) to provide continuous security testing and pentration testing on demand to their customers. Ridge Security will showcase the solution during RSAC in San Francisco, from June 6-9.

Read the full story $

October 19, 2021

Ridge Security Hosts First Capture the Flag (CTF) Competition at ROOTCON 15

Eighteen Teams Compete in Knowledge-based Challenge Leveraging RidgeBot PenTest Solution

Ridge Security, cutting-edge pen-testing solution provider, sponsored a Capture the Flag (CTF) at the annual ROOTCON 15 with eighteen teams participating and testing out their knowledge and skills in seven rounds of Vulnerability Exploitation challenges. ROOTCON brings together a global community of security experts, practitioners, and business developers with the aim of making the digital world a safer place.

Read the full story $

February 3, 2021

Ridge Security Penetration Testing Solution Hardens Networks With Expanded Ransomware Protection

Reimagine ransomware: RidgeBot 3.2 targeted attack simulation are designed to combat high-profile ransomware attacks

Ridge Security, cutting-edge pen-testing solution provider announces new capabilities in RidgeBot that combat ransomware. RidgeBot couples ethical hacking techniques with AI-driven, decision-making algorithms to help identify and validate weak credentials and frequently exploited vulnerabilities, in order to help minimize damage from simple or sophisticated, extortion-encryption attacks such as ransomware attacks.

Read the full story $

May 13, 2021

Ridge Security Automated Penetration Testing Solution Delivers Advanced Post-Exploitation Techniques

Ridge Security helps you stay on the front lines of cyber defense with advanced tools in latest release of RidgeBot

Ridge Security, cutting-edge automated pen-testing solution provider, announces new capabilities in RidgeBot 3.4, for post-exploitation validation. This new release further differentiates RidgeBot from vulnerability scanners and 1-step auto-exploitation tools that are currently available and strengthens RidgeBot’s position as a true risk-based vulnerability management platform.

Read the full story $

July 21, 2021

Ridge Security Announces Expanded Core Capabilities in RidgeBot with Enhanced Web Application Testing

From network, to host, to web applications, RidgeBot 3.5 delivers the most comprehensive pent-testing platform for risk-assessment

Ridge Security, cutting-edge pen-testing solution provider, announces enhanced and new capabilities in RidgeBot™, the automated penetration testing platform. RidgeBot™ 3.5 features an expanded plugin set addressing critical security gaps in customers’ infrastructure, support for seamless 3rd party integration and continued global expansion in its partner ecosystem. In addition, with its advanced pen-testing capabilities in host servers, RidgeBot™ is solidly positioned as the most comprehensive, automated penetration testing tool covering network, host, and web applications.

Read the full story $