ThreatBook has acquired CyberStrikeAI, an open-source artificial intelligence-powered penetration testing platform, as the Singapore- and Hong Kong-based cybersecurity company expands its agentic security portfolio.
In its announcement, ThreatBook said it will integrate CyberStrikeAI into its red-team capabilities and continue developing both open-source and enterprise editions. Financial terms and other transaction details were not disclosed.
Open-source project moves into ThreatBook
CyberStrikeAI is written in Go and is designed to orchestrate authorized security testing across reconnaissance, vulnerability assessment, exploitation and reporting workflows. Its public GitHub repository lists more than 100 curated security tools and carries an Apache 2.0 license.
The platform also includes asset and vulnerability management, queued testing tasks and visual tracking of attack chains. It can connect different AI models as a reasoning layer and generate structured assessment reports from natural-language instructions. Those functions are intended to reduce manual sequencing for authorized testers, but they also explain why governance and access controls are central to the acquisition.
The repository displayed about 7,100 stars at the time of writing. ThreatBook said the project had accumulated more than 6,600 GitHub stars and had been deployed in more than 2,300 networks since its late-2025 launch. The network-deployment figure is company-supplied and was not independently verified.
ThreatBook plans to use the platform as part of controlled red-team exercises that simulate attacker behavior to help organizations identify weaknesses. The company said it will keep an open-source version available while adding safeguards intended to reduce misuse.
The acquisition gives ThreatBook an offensive-testing layer alongside its existing threat intelligence, detection and response products. It also brings the company into a sensitive area of cybersecurity where the same automation that helps defenders test systems can lower the operational barrier for attackers.
Security controls form part of the roadmap
ThreatBook said the planned enterprise edition will support full on-premises deployment, keeping customer data inside an organization’s network. It will also include audit trails and permission controls for agent actions.
The company said these controls are intended to make automated testing more accountable for enterprise security teams. ThreatBook founder and chief executive Xue Feng said faster AI-assisted reconnaissance and exploitation have shortened the response window available to defenders, increasing the need for comparable testing capabilities on the defensive side.
Independent researchers have documented the risks around the platform. In March, Team Cymru said it observed 21 unique IP addresses running CyberStrikeAI between January 20 and February 26, 2026. Its analysis linked one server banner to infrastructure highlighted in earlier research about targeting of Fortinet FortiGate devices. The report did not suggest that every CyberStrikeAI deployment was malicious, but warned that AI-native offensive tooling could accelerate automated targeting.
The project’s own documentation states that it is for educational and authorized security testing and that users must obtain explicit permission before testing systems.
Enterprise trial begins in China
ThreatBook said a trial version of the enterprise edition is available immediately in mainland China. The company expects to make it available across the rest of Asia-Pacific in October 2026.
The announced rollout adds a commercialization path for a project that has grown rapidly in the open-source security community. ThreatBook did not disclose pricing, customer commitments, staffing changes or whether CyberStrikeAI’s original developers will join the company.
The rollout will also test whether an enterprise distribution can preserve the community benefits of an open-source project while enforcing stricter operational boundaries. ThreatBook has not yet detailed how its planned safeguards will differ from the project’s existing warnings and security documentation, or whether controls will be mandatory in the public edition.
Google says threat actors are shifting to agentic AI attacks

