This week’s TL;DR covers two important stories. First, AI penetration testing is losing the trust of security teams. Second, a hidden malware campaign ran inside Edge for years.
Confidence in AI Penetration Testing Falls Sharply
According to a June 2026 report from Cobalt, security professionals have cooled sharply on autonomous AI testing. In 2025, 29% believed AI could fully meet their testing needs. By 2026, however, that figure had collapsed to just 9%.
So, what went wrong? In short, the tools underdelivered. AI-based testing proved expensive to run at scale. More critically, it missed what mattered most. Three-quarters of organizations reported that automated systems had failed to catch significant vulnerabilities. These false negatives leave real gaps in security posture.
Furthermore, the volume problem is growing. AI-assisted development produces more code. More code, in turn, means more vulnerabilities. As a result, reporting rates are running 46% higher than forecasted, according to the Forum of Incident Response and Security Teams. The bottleneck is the human capacity to verify and act. HackerOne even paused its Bug Bounty program due to the backlog.
Cost is another sticking point. AI tooling burns through budgets quickly and unpredictably. CISOs pressured to “use more AI” are now reconciling that pressure with real results.
Nevertheless, AI still has a role. The emerging consensus is augmentation, not replacement. AI handles broad, continuous scanning. Meanwhile, human testers handle depth, context, and validated attack chains. Most organizations now prefer a human-in-the-loop model.
AI Penetration Testing – TL;DR
Confidence in autonomous AI penetration testing dropped from 29% to 9% in a single year. False negatives, runaway costs, and a human verification bottleneck are all to blame. Ultimately, AI cannot replace the judgment that makes it meaningful.
Microsoft Pulls 119 Edge Extensions Hiding Malware in Images and Fonts
Microsoft removed 119 malicious extensions from the Edge Add-ons store this week. The campaign, named StegoAd, is linked to a single threat actor active since at least 2021. Together, the extensions reached up to 2.6 million users.
On the surface, everything looked legitimate. The extensions were ad blockers, VPNs, translators, and video downloaders. They worked as advertised and collected genuine reviews. Meanwhile, the malicious code stayed completely dormant. It only activated after clearing evasion checks, including multi-day delays and server-side fingerprinting.
The standout technique was steganography. Specifically, the actor hid executable JavaScript inside ordinary image and font files. Early variants tucked code after the end marker of a PNG file. Later, as detection improved, they switched to WebP images and WOFF2 font files. Static scanners never flagged them because the files rendered perfectly.
Underneath the surface, however, the damage went well beyond ad fraud. The payloads included a remote code execution backdoor. They also stole Google credentials, two-factor codes, and WordPress admin logins. Additionally, they exfiltrated session cookies in bulk. Remarkably, the actor even used Google Analytics IDs as covert telemetry.
Microsoft has now removed all 119 extensions and suspended 90-plus developer accounts. If you use Edge, check your extensions against Microsoft’s published list. If anything matches, treat the browser as compromised and rotate all sensitive passwords immediately.
Edge Extensions Campaign – TL;DR
119 malicious Edge extensions hid malware inside image and font files for up to five years. Behind a facade of ad fraud, they stole credentials, two-factor codes, and session cookies. With up to 2.6 million installs, Edge users should audit their extensions and change passwords now.
Conclusion
Both stories share a common thread: the tools we trust can fail us. Whether it’s AI scanners missing critical flaws or browser extensions hiding malware in plain sight, layered defenses and human oversight are, as always, essential. Learn how ThinScale helps close the security gaps traditional controls can miss. Contact us today.


