ExploitOps.

By Mattersec LabsIssue · Sept 2026

The field journal for continuous adversarial security.

What is ExploitOps?

ExploitOps is the continuous discipline of discovering, validating, fixing and preventing exploitable behaviour across the software lifecycle. It connects the security work teams already do into one loop: what changed, what is actually exploitable, what matters, how it gets fixed, and how it stays fixed.

Modern software changes faster than any team can review it. Teams already run SAST, pentests, AI evals, runtime tools and triage queues. ExploitOps connects those into one loop, so the organisation always knows what became exploitable, what is being fixed, and what stays fixed. Every important discovery becomes a persistent control.

Know what's exploitable before someone else does.

How it differs

Pentesting
Answers an important question at a point in time. ExploitOps makes that answer permanent: what changed since, what was fixed, what stays fixed.
Red teaming
Exercises a scenario against people and process. ExploitOps takes the paths it uncovers and keeps them under continuous validation.
AppSec
Reviews code and intent before it ships, and triages what scanners raise. ExploitOps gives AppSec proof of exploitability, so the queue shrinks to what matters.

How it works

Four verbs, repeated. The loop is the discipline; MATT, the AI Security Supervisor, runs it across your existing stack: scanners, pentesting platforms, observability, SIEM, issue trackers, source control and AI eval platforms.

  1. 01

    Observe

    Know what changes across code, applications, AI agents, models, dependencies, integrations and production behaviour.

  2. 02

    Prove

    Determine what is actually exploitable: adversarial reasoning, attack simulation, security evals, 1,200+ attack patterns. AI-driven offensive testing lives here, as one capability.

  3. 03

    Fix

    Give engineers root cause, severity, exploitability and priority, inside the workflows they already use.

  4. 04

    Remember

    Turn important discoveries into reusable evaluations, regression checks, rules and controls: institutional security memory. Then repeat.

Who owns ExploitOps

  • CISO or Head of Security owns the program.
  • Product Security or AppSec runs the rule set.
  • Engineering owns the fixes and approves every rule.
  • Leadership reads one page: which rules hold, what changed.

Maturity model

  1. L0Point-in-timeAnnual pentest, scanner queue, findings in a PDF. Exploitability is known once a year.
  2. L1ConnectedFindings flow into issue trackers with exploitability and priority attached.
  3. L2ContinuousEvery meaningful change observed and proven against every control.
  4. L3CompoundingDiscoveries become controls within days; the loop runs across the whole stack.
Concept · 0045

What "Mythos Safe" means, and how to know if you are

Mythos Safe is a testable state: every security assumption in a product written as a rule and re-tested on every release against what frontier models can do.

MATT Research · 6 min
Exploit brief · 0044

The Hugging Face breach: five lessons for CXOs

OpenAI's models escaped a test sandbox and ran code on Hugging Face servers for four days with no human steering. Five lessons for leadership, from the record.

MATT Research · 7 min
Guide · 0043

Why annual pentests fail against AI attackers

The annual pentest assumed a vulnerability took an expert weeks to find. In 2026 it takes a prompt. Where the model breaks and what replaces it.

MATT Research · 6 min
Field note · 0042

AI-written code: the checks reviewers skip

Generated code is syntactically clean, passes review and omits the ownership check the author assumed. The failure modes of AI-written code, with tests.

MATT Research · 7 min
Field note · 0041

SOC 2 in the age of agentic attacks

SOC 2 proves controls existed on audit day; agentic attackers test them every day. How to turn compliance evidence into live test results auditors accept.

MATT Research · 6 min
Attack library · AP-0104 Object ownership missing on a generated endpoint The most common finding in AI-written handlers, and the rule that closes it. Open pattern →
Who writes ExploitOps

Built by the people Apple, Meta and Microsoft thanked.

Hall of Fame credits, Black Hat stages, OWASP chapters, Appknox research. Every claim below links to its source.

ExploitOps Review

Understand your own attack surface.

Sixty minutes with a security researcher. Where your product breaks, where your current model breaks, and what continuous adversarial testing should look like. Paid; settled when you book.