Open-source AI penetration testing just got a corporate parent with a compliance story. On September 30, 2026, Singapore- and Hong Kong-based ThreatBook said it had acquired CyberStrikeAI, an open-source AI penetration testing platform written in Go. Deal terms: Undisclosed. The interesting line is not the price. It is the dual-track product plan: keep the open-source edition, and launch a controlled Enterprise Edition for teams that cannot run ungoverned agents against their own estate.
Traction, as company-stated. ThreatBook’s release says that since a late-2025 launch, CyberStrikeAI has attracted more than 7,000 stars on GitHub, while “public internet-scanning data” points to more than 3,000 instances in use worldwide. Treat those as vendor claims with a URL — not an independent CyberMerge census. Capabilities listed on the PR: one-line deployment; native Model Context Protocol (MCP) orchestration extendable via YAML; more than 100 built-in tool templates across the attack chain; visual attack-chain tracking; multi-model LLM decision engine; natural-language target in, structured report out.
What changes for buyers. ThreatBook will integrate CyberStrikeAI into its red-team capabilities and keep the open-source edition available while adding “further safeguards” aimed at misuse. The Enterprise Edition is positioned for full on-premises deployment, local data retention, a full audit trail of every agent action, and permission controls. A trial is available in Mainland China immediately; global availability is targeted for the fourth quarter of 2026 (ThreatBook). TechNode notes ThreatBook did not disclose pricing, customer commitments, staffing changes, or whether original developers join — so leave those as Undisclosed.
POV — AI offense tooling consolidates into leashed platforms. Defenders are right that automated recon and exploit chaining compress response windows. They are wrong if they adopt the same automation without observability. Boards evaluating AI pentest or continuous red-team tools should demand three proofs: where the agent runs (on-prem vs SaaS), who can authorize each action (permissions), and whether every step is replayable (audit). Star counts and instance tallies are distribution signals. They are not governance. ThreatBook’s move is the market telling independents that the commercial path for AI offense is controlled red teaming attached to an intelligence/response platform — not a forever-unlicensed agent on a public VPS.
Competitive read. Vendors selling “agentic offense” without an enterprise control plane should expect buyers to ask how they differ from a popular OSS project that just got acquired for exactly that gap. Pure open-source maintainers should assume more corporate interest — and more pressure to add misuse controls that may slow casual forks. For CISOs, the procurement question after this deal is simple: can your red-team AI produce evidence a regulator or board would accept, or only a flashy attack graph?
Desk sheet — sourced only: ThreatBook Sep 30, 2026 — acquisition announced; >7,000 GitHub stars; >3,000 instances (company/public-scan claim); OSS retained; Enterprise on-prem + audit + permissions; China trial now; global Enterprise Q4 2026 target; price Undisclosed. TechNode Global Oct 1, 2026 — terms Undisclosed; notes gaps on pricing/staffing. SecurityBrief Asia Oct 2, 2026 — secondary red-team framing. Revenue, multiple, headcount transfer: Undisclosed.
