Resources

Radical thinking and constant research inform all we do. Think ahead with shared intelligence from our Swarm of ethical hackers.

People talking at desk

The podcast

Insights, interviews and tales from inside the Cybersecurity industry

Start listening

Las Vegas def con

Don’t become the demo: a guide to surviving summer hacker camp

Hacker Summer Camp brings 30,000+ security minds to Las Vegas, and with them, plenty of ways to become an unintended…

fallback image

When the API Lies – How RAID Discovered a Critical Privilege Escalation by Reading JavaScript

A privilege escalation vulnerability hid behind a broken endpoint and a misleading error message. Here's how RAID's agentic system decompiled…

Alt text "Stencil street art of a man in a suit, one hand pressed to his face, mouth open mid-scream, on a teal wall — symbolizing loss of control and panic in the face of a security breach.

The OpenAI agent didn’t “go rogue”. The containment failed. 

I’ve purposely held back from commenting on the OpenAI and Hugging Face incident.  The early coverage was predictably dramatic.  AI…

Gartner Hype Cycle XaaS Red teaming as a service

CovertSwarm named in two Gartner® Hype Cycle™ reports in the Red Teaming as a Service category  

CovertSwarm has been named a Sample Vendor for Red Teaming as a Service in the Gartner Hype Cycle for XaaS,…

Two dimly lit paths diverging into darkness, representing the choice between a minimum viable DORA testing program and a genuinely resilient one.

The two DORA testing programs

Having the right security testing capabilities is not enough. Most firms building a DORA-aligned program are covering the right pillars…

security awareness training

The attack your training prepared them for doesn’t exist 

I've delivered more security awareness sessions than I can count. I'm also a social engineer, which means I've been the…

service desk call social engineering

The call nobody talks about

The attack call is the one that gets written up in the report. But in James Sheppard's experience, it's rarely…

DORA TLPT - The gap between strategy and reality

DORA Threat-Led Penetration Testing: What article 26 actually requires 

Annual penetration testing does not satisfy DORA's testing mandate. Here's what Article 26 actually requires, who it applies to, and…

Deloitte ranks CovertSwarm among EMEA’s 500 fastest-growing tech companies.

Based on verified revenue growth of 595.89% over three years. Here's what the number means and why the model behind…