Curated content for the security professional: We cover the latest on frameworks, threats, and cybersecurity trends to keep your organization ahead of emerging risks.

The legal and compliance industry holds some of the most sensitive and valuable information in the business world, making it an irresistible target for cybercriminals and nation-state actors. From merger and acquisition details to regulatory investigations and client privileged communications, law firms and compliance organizations possess data that can be worth millions on the dark web or provide significant competitive advantages to malicious actors.

In the world of cybersecurity, trust isn't given; it's earned. It's proven through rigorous processes, demonstrable expertise, and an unwavering commitment to quality. Today, we are thrilled to announce that Capture The Bug has earned that trust in a significant new way: we are now officially a CREST-accredited provider for penetration testing services.

In the chess match between cybercriminals and security professionals, there's a unique group of players who understand both sides of the board. Ethical hacking represents the art of thinking like an attacker while working to strengthen defenses, creating an essential bridge between offensive and defensive cybersecurity strategies.

An organisation passed its penetration tests. A red team gained persistent access undetected. Here is the CISO decision framework for knowing which engagement your organisation needs right now.

ANZ enterprise buyers require penetration test evidence before signing SaaS vendor contracts. Here is what the test must cover, and why tenant isolation is the question that determines whether the report passes review.

A web app pentest costs USD $5,000 to $30,000 in 2026. The price is set by five variables. Here is how to estimate your own cost before you request a quote.

The Essential Eight does not mandate penetration testing. But Maturity Level 2 and above requires it in practice. Here is what a pentest proves and what it cannot prove about your Essential Eight controls.

Australia's penetration testing market consolidated in 2026. CyberCX is now inside Accenture. Tesserent trades as Thales. Here is how to choose the right AU provider before the market changes again.

Penetration testing in New Zealand costs NZD $5,000 to $50,000 depending on scope. Here are the 2026 NZD pricing ranges, what drives the number, and what to expect from a credible NZ provider.

There are two CREST bodies operating in Australia, and they are not equivalent. Here is what CREST International and CREST ANZ each validate, when each matters, and how to verify a provider's actual status.

Penetration testing in Australia costs AUD 6,000 to AUD 60,000 depending on test type and scope. Here are the 2026 AUD pricing ranges, what drives the number, and what to watch for in quotes.

In February 2026, an autonomous AI agent fully compromised McKinsey's internal AI platform, Lilli, in under two hours. The attacker exploited a SQL injection behind 22 unauthenticated endpoints. The agent pulled 46.5 million chat messages, 95 system prompts, and the credentials of 57,000 users. The guardrails worked at the topic classification layer. They did not work at the execution layer, where it mattered.

Most generic penetration testing misses the attack surfaces that put policyholder data at risk. Here is the evaluation framework for selecting an insurtech penetration testing partner in 2026.

Australia's CDR and New Zealand's open banking regime create API attack surfaces that standard testing checklists miss. Here is what testing for consent, CDR data, and payment APIs actually requires in 2026.

A hardcoded API key in an LLM integration. Scraped in five minutes. Active six months later. Here is which secret scanning tool would have caught it at each stage, and what that means for your stack.
Flexible, scalable PTaaS for modern product teams.