AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
ThreatBook has acquired CyberStrikeAI, an open-source AI penetration testing platform that the company says has accumulated more than 6,600 GitHub stars and been deployed across more than 2,300 networks since its launch in late 2025. ThreatBook plans to integrate the platform into its Red Team capabilities, using autonomous agents to conduct controlled offensive security activities designed to expose vulnerabilities before attackers can exploit them.
CyberStrikeAI is written in Go and is designed to orchestrate security testing across an attack chain, from reconnaissance through exploitation and reporting. Its capabilities include more than 100 built-in tool templates, native MCP orchestration, visual attack-chain tracking, support for multiple LLMs as reasoning engines, and natural-language input that can produce structured security assessment reports. Its GitHub documentation describes the system as combining agents, MCP-native tools, knowledge retrieval, visual workflows and attack-chain modelling for authorized security operations.
The significance is less about replacing individual penetration-testing tools than about changing how they can be coordinated. An agentic system can interpret an objective, select tools, assess intermediate results and determine subsequent actions, potentially compressing work that traditionally depends on sequential decisions by human testers. For ThreatBook, the acquisition also fits a broader move toward an agent-based security architecture.
The acquisition also reflects a deliberate shift in ThreatBook’s product strategy. Rather than treating autonomous penetration testing as a standalone capability, the company sees it as part of a broader agentic security architecture in which AI agents can perform different offensive and defensive functions across the security lifecycle.
ThreatBook had been evaluating several open-source autonomous penetration-testing platforms before deciding to acquire CyberStrikeAI. In an exclusive conversation with AsiaTechDaily, Feng XUE, Founder and CEO of ThreatBook, said the platform stood out because of the traction it had already gained within the cybersecurity community and the capabilities the company observed during its own evaluation.
“Prior to our acquisition, CyberStrikeAI had already attracted a lot of attention from the cybersecurity community. In just a few months, it had earned several thousand stars on GitHub and was already being used by thousands of networks, which is impressive.
As part of our broader strategy in being ‘The Agentic Security Company’, we were evaluating multiple open-source autonomous penetration testing platforms with an eye to acquiring one, so naturally, CyberStrikeAI, being one of the more high-profile ones caught our attention. Interestingly, there were rumors in some media reports previously that CyberStrikeAI was (one of) the most popular autonomous penetration testing software used by attackers, so we asked ourselves why. We tested it, and it turned out to be the best one.”
For ThreatBook, that evaluation reinforced a broader view that offensive security needs to become more continuous and automated as attackers increasingly use automation themselves. XUE argues that defenders need comparable capabilities to identify weaknesses before they become exploitable, while recognizing that the technology itself can have dual-use implications.
“Our belief is that the best approach to defense is offense, by that I mean the ability for organizations to conduct penetration testing regularly, continuously and automatically, before real attacks happen. I believe that technology in and of itself is neutral – the CyberStrikeAI open-source platform is a good example of that – it very much depends on the actors using it. There is some wisdom for security people to think and act like attackers if they are to successfully preempt attacks and defend their organizations.”
That philosophy fits into ThreatBook’s broader move toward agentic security. The company rebranded itself as “The Agentic Security Company” in May 2026, reflecting its view that security operations will increasingly involve multiple specialized agents rather than relying predominantly on defensive systems.
XUE said ThreatBook sees these agents working across different parts of the security lifecycle, with offensive and defensive capabilities operating alongside vulnerability discovery.
“ThreatBook rebranded itself as ‘The Agentic Security Company’ recently in May 2026 because for a long time now, we see the future of cybersecurity as agentic, where every SecOps team uses multiple agents to carry out an array of tasks. They will deploy Red agents to conduct offense security activities, and Blue agents to carry out defensive work. Previously, the majority of company solutions were Blue and more focused on defense.
Right now, every new product we acquire or build is intended to complement and augment every other product on our platform. This year saw Cybersecurity enter into ‘The Era of Agents’ so I think our purchase of CyberStrikeAI is particularly timely and useful to organizations as it significantly bolsters our Red Team capabilities. ThreatBook will continue to invest in developing both editions of CyberStrikeAI, making the platform’s autonomous penetration testing capabilities more reliable, more controllable and easier to use. A trial version of the Enterprise Edition is available in Mainland China effective immediately, and is expected to reach the global market in the fourth quarter of 2026.”
ThreatBook’s strategy ultimately extends beyond red-team automation. The company also plans to introduce Yellow agents focused on vulnerability discovery, creating a model in which offensive testing, vulnerability identification and defensive operations can increasingly work together.
“With the introduction of Red ‘offensive’ agents, as well as Yellow ‘vulnerability discovery’ agents, we are becoming an agentic company offering a truly holistic approach and solutions to organizations, covering all their cybersecurity needs.”
The acquisition also highlights the central tension surrounding AI-driven offensive security. The same autonomy that can help defenders identify weaknesses can create significant consequences if an agent has excessive permissions or access to sensitive infrastructure. ThreatBook will retain CyberStrikeAI’s open-source version while adding additional controls intended to prevent misuse. It is also developing an enterprise edition that can be deployed entirely inside an organization’s network, with data remaining on-premises, a full audit trail and permission controls for every agent action.
These safeguards are becoming increasingly relevant as agentic systems gain the ability to interact directly with tools and infrastructure. OWASP’s 2026 framework for agentic applications identifies risks including tool misuse and identity and privilege abuse, particularly where agents inherit or exercise permissions across interconnected systems. The CyberStrikeAI project itself emphasizes authorized use and advises users to review security hardening before enabling high-risk capabilities.
ThreatBook has launched a trial version of the enterprise edition in mainland China and says it expects availability across the rest of APAC next month, with the broader global rollout targeted for the fourth quarter of 2026. The company, founded in 2015, combines AI with threat intelligence across the security lifecycle. Adding autonomous offensive testing extends that model from identifying and responding to threats toward continuously testing whether an organization’s defenses can withstand them.
The broader question for enterprises, however, will be whether autonomous penetration testing can scale without creating a new class of operational risk. As AI agents become capable of conducting increasingly complex security actions, the competitive advantage may not come from autonomy alone. It will increasingly depend on how precisely organizations can define what an agent is allowed to see, execute and change. ThreatBook’s CyberStrikeAI acquisition therefore points to a larger transition in cybersecurity: defenders are beginning to automate not only detection and response, but the offensive process used to discover weaknesses in the first place. The next stage of that transition will depend on whether security teams can make autonomous testing continuous while keeping its power observable, authorized and controllable.