Recorded Future is the world’s #1 threat intelligence company. Pentera is the world’s #1 in exposure validation. Today, our two companies are joining forces to pioneer automated threat-led validation – and to close one of the most critical gaps in security operations: the gap between high-profile threat intelligence and remediation action taken in time.
The Gap Between Intelligence and Action
Threat intelligence has never been more valuable – or more perishable. Mean time to exploitation keeps shrinking, and with AI now firmly embedded in the attacker’s toolkit, adversaries combine high-quality intelligence with the capability to exploit faster than ever before. A credential leaked overnight or a vulnerability disclosed in the morning can be weaponized before most organizations have even triaged the alert.
This makes threat intelligence more critical than ever – it is the earliest signal cyber defenders get. But intelligence only reduces risk when it is operationalized in time. In most organizations, that last step – from knowing to acting – is exactly where the process breaks. High-value intelligence arrives, and then it waits: for triage, for prioritization alongside a long list of issues to be addressed, for locating the right owner with the skills and the time to test whether the threat is actually exploitable in the environment.
What We Heard From Customers – and Confirmed With the #1 in Threat Intelligence
The signal came first from our customers, they asked for this – and it was remarkably consistent. When we kept hearing it, we did the obvious thing: we went to the world’s leader in threat intelligence, Recorded Future, and asked what they see.
They see exactly the same thing. Organizations require threat intelligence data as a core part of their security and compliance programs – but the scale of the threat data always exceeds the team’s capacity to operationalize it, and the ability to validate every relevant threat against the live environment is limited by time and by specialized offensive skills.
Proving It Together: Successful POCs With Joint Customers
We took this challenge to our joint customers, collected their feedback, and ran a series of highly successful proofs of concept. The results demonstrated the power and immediate value of automated threat-led penetration testing (TLPT): intelligence flows in from Recorded Future, Pentera automatically runs the validation, and the security team receives evidence – not another alert – showing whether each threat is exploitable in their specific environment and what to fix first.
“The convergence of threat intelligence and security validation is one of the most important shifts in our security program. Knowing what’s coming is only half the answer. Being able to test against it in our own environment, at speed, is what builds real resilience in the AI era.”
Joseph Gothelf, Vice President, Cybersecurity, Wyndham Hotels & Resorts
Built on Pentera’s Validation-on-Demand (VOD) Framework
The partnership is powered by Pentera’s Validation-on-Demand (VOD) framework. VOD was designed to enable exactly this type of partnership, but at its basis it can receive input from any source – the Pentera platform, a technology partner like Recorded Future, or enterprise AI agents such as those built on OpenAI or Anthropic – send a validation request, and return an immediate, evidence-based response. Any intelligence source, human or machine, can now trigger real attack validation on demand and get back proof of exploitability instead of a probability score.
Recorded Future is an amazing partner, with a base of trusted customers who ask for the best. Security validation is valuable across a long list of use cases – but it is the deep knowledge and experience of the Recorded Future team that helped us tune the VOD to solve one of the most critical gaps in the market. The response has been immediate, the value for SecOps teams is clear: we already have a long list of Early Availability requests, and we are working toward our version 1.0 release by the end of 2026.
First Release: Automated Validation of Leaked Credentials – Right After Black Hat USA 2026
The first joint capability will be officially released right after Black Hat USA 2026: automated validation of leaked credentials from Recorded Future via Pentera Surface, our external attack surface testing. Pentera customers will enjoy this early release of identity leaked-credentials validation by simply adding their Recorded Future API token into their Surface. From that point, leaked credentials surfaced by Recorded Future are automatically tested against the organization’s real attack surface – confirming which ones are live, exploitable, and need immediate action.
This capability will be available to all Recorded Future customers who have the Identity module activated in their license.
The Bottom Line
The window between threat/vulnerability disclosure and exploitation keeps shrinking. The window between threat intelligence and defensive action should too. By connecting the world’s #1 threat intelligence with the undisputed leader in exposure validation, organizations can automatically validate real exposure, prioritize what matters, and remediate with confidence – before attackers get there.
Want early access? Join the Early Availability program through your Pentera or Recorded Future account team, or meet both teams at Black Hat USA 2026.