Company intelligence
Ethiack
Continuous Exposure Management and AI Pentesting
About Ethiack
Security teams don't lack vulnerabilities. They lack clarity on what attackers can actually exploit. Ethiack continuously tests and validates exploitability across your entire attack surface using agentic AI pentesting, so teams fix what matters before attackers strike. Exposure keeps growing. Exploitability is unclear. Attackers move faster. Scanners generate noise. Pentests are snapshots. The result: security teams spend hours chasing findings they can't trust, while real risks go undetected. How is Ethiack different? We don't show potential vulnerabilities. We prove what is exploitable, continuously and autonomously, with 99.5% precision. → See — Continuous discovery of your full attack surface: external, internal, cloud, third-party → Test — 24/7 autonomous pentesting triggered by new assets, new threats, or system changes → Act — Validated, prioritised risks with proof-of-exploit and clear remediation guidance Results our customers see ✔ 200%+ annual ROI in reduced cyber risk ✔ 99.5% precision in exploitable vulnerabilities ✔ 90% noise elimination ✔ 80% faster remediation ✔ 8h/week saved per security engineer ✔ 30x faster than manual pentesting Ethiack helps organisations implement Continuous Threat Exposure Management (CTEM) with continuous adversarial exposure validation and on-demand pentesting. 🔒 100% European. Data processed and stored exclusively in the EU. See if you're exploitable → ethiack.com
Verified activity
Signals from Ethiack
17 published signals
Research & Knowledge
Ethiack security researcher Rafael Castilho investigated routing discrepancies in Remix, a framework powering major platforms like TikTok, PayPal, and Shopify.
Reported by Ethiack
Presence & Recognition
Ethiack is attending the Gartner Security & Risk Management Summit 2026 in London from September 22 to 24.
Reported by Ethiack
Research & Knowledge
Ethiack published a research paper on autonomous pentesting and frontier LLMs incorporated into Hackian's harness.
Reported by Ethiack
Capital & Finance
Ethiack's customer protection number climbed faster than last year's pace in 2026.
Reported by Ethiack
Capital & Finance
Ethiack protected over €93 million for its customers in 2025.
Reported by Ethiack
Research & Knowledge
Ethiack research team discovered and reported the KindaRails2Shell vulnerability CVE-2026-66066, which was exploited for over a month.
Reported by Ethiack
Products & Services
Ethiack built its AI to stop the noise by validating vulnerabilities and providing direct remediation steps when security alerts hit.
Reported by Ethiack
Security
Ethiack security researcher Rafael Castilho mapped the full chain in GeoNetwork 4.4.11 to identify a missing PreAuthorize annotation, Saxon XSLT engine left at default settings, and Remote Code Execution on government infrastructure.
Reported by Ethiack
Research & Knowledge
Ethiack validated the vulnerability before it was disclosed at all and authoring the CVE ourselves for KindaRails2Shell.
Reported by Jorge Monteiro
Research & Knowledge
Ethiack validated exploitation hours for a client's asset after a CVE dropped, three days before reaching CISA's KEV catalog for WordPress2Shell.
Reported by Jorge Monteiro
Research & Knowledge
Ethiack security researcher Rafael Castilho uncovered four vulnerabilities in GeoNetwork, the open-source geospatial catalog powering national agencies, environmental platforms, and government data portals across Europe and beyond.
Reported by Ethiack
Products & Services
Ethiack officially patched all four CVEs discovered in GeoNetwork 4.x deployments.
Reported by Ethiack
Research & Knowledge
Ethiack provided mitigations to every affected organization following responsible disclosure.
Reported by Ethiack
Research & Knowledge
Ethiack identified 121 affected GeoNetwork 4.x deployments across 39 countries.
Reported by Ethiack
Products & Services
Ethiack found 4 vulnerabilities in GeoNetwork, a geospatial metadata catalog and an OSGeo project, with a single missing authorization check.
Reported by Jorge Monteiro
Research & Knowledge
Ethiack found a PreAuth RCE chain in GeoNetwork used by Governments, International Orgs, and military across the globe to catalog geospatial data.
Reported by Rafael Castilho
Research & Knowledge
Ethiack published Part 2 of a series on evaluating AI pentesting agents to provide a reliable framework for measuring offensive AI performance.
Reported by Ethiack