Resources

Radical thinking and constant research inform all we do. Think ahead with shared intelligence from our Swarm of ethical hackers.

People talking at desk

The podcast

Insights, interviews and tales from inside the Cybersecurity industry

Start listening

fallback image

CovertSwarm named in the Gartner® Hype Cycle™ for Security Operations, 2026

CovertSwarm has been named a Sample Vendor for Red Teaming as a Service in the Gartner Hype Cycle for Security…

Swarm Intelligence banner with redacted text

Claude Fable 5: what we know so far

Fable is the first publicly accessible version of Anthropic's Mythos-class model, the tier they initially decided was too capable to…

CREST AI charter logo

CovertSwarm is a founding signatory of the CREST AI Charter

CovertSwarm has become a founding signatory of the CREST AI Charter, endorsing nine principles for responsible AI use in cybersecurity.

CovertSwarm best place to work

Sunday Times Best Places to Work. Three Years Running.

We attack businesses for a living. So we hold ourselves to the same standard internally. Here's what 100% participation and…

DORA compliance vs safety

DORA is not GDPR. Stop treating it like it is. 

Most firms are treating DORA like GDPR: get a consultant, document the framework, move on. That worked for data privacy.…

Frontier AI models and offensive security - Luke Potter CovertSwarm

Frontier AI models are exciting.

CovertSwarm COO Luke Potter on why frontier AI is genuinely exciting, why most of the conversation is asking the wrong…

A lone figure walks away down a dark, empty street at night, unseen and undetected.

AI Sharpens the Question. It Doesn’t Change the Answer.

The cyber security industry has spent decades selling findings instead of answers. AI tools like Mythos make the problem faster…

unlocked door - people- constant cyber attack

Constant Cyber Attack: What People Keep Getting Wrong

There are a lot of terms floating around offensive security right now. COST. CTEM. Exposure validation. Some of it is…

hidden vulnerabilities xrdp

When “Just Logging In” Isn’t Just Logging In: A Lookat xrdp and CVE-2026-33145

A quiet finding with real-world impact. CVE-2026-33145 shows how xrdp's AlternateShell feature, enabled by default, passes client-supplied input directly into…