September 9, 2026
AI and LLM Penetration Testing in 2026: The New Attack Surface
An ethical hacking company working across Croatia, the Netherlands and the EU. Under written authorisation we attack your systems as a real intruder would. We prove what we reached and hand you a ranked plan to fix it.
Free intro call. No obligation. Pricing on request.
Illustration: a typical attack path we find, prove, close and retest.
What we do
Scoped to your environment, never a generic checklist. Each one ends with proof, not opinions.
Infrastructure, Active Directory, cloud, web apps, APIs, wireless and IoT. We usually test in two phases. First from outside, with no inside knowledge, to map what is exposed. Then from inside, as if an attacker already had a foothold. You get every proven weak point ranked by CVSS, with a fix for each.
Read morePhishing by email, SMS and phone, plus on-site tests where we walk in and try doors, badges and unattended screens, within agreed rules. You see how far an intruder could get through your people, then we train your staff on what worked.
Read moreWe take apart your SaaS, app, binary or firmware. You get a list of the ways it can be broken or abused, each one proven.
Read moreA goal-based attack on technology, people and processes, minimum two months. You get evidence of whether your detection and response hold against a real intrusion.
Read moreAlso available
We read your code to find flaws that testing from the outside cannot see. Available as an add-on to any penetration test.
Open source intelligence: what an attacker can learn about your company, its people and its systems from public sources. Ask us for a scoped quote.
How we work
Six phases on every engagement, following public standards, under safety rules we put in writing.
Scope, rules of engagement, testing windows and written authorisation.
Systems, services and versions mapped: your real attack surface.
We prove what an attacker could reach and how far they could spread, without causing damage.
Findings ranked by risk, each with evidence and a remediation step.
A walkthrough of the findings with your team.
We confirm the key findings are actually closed.
In writing
Who we are
Luka Bayer and Fady Oueslati have been taking systems apart since they were kids, from hacking to infrastructure, and both turned it into a profession. Through Obventum and its sister company ReactiveZero, their clients range from small municipalities and companies with a few hundred employees to national government agencies and multinational enterprises, across Croatia and the Netherlands.
No sales layer, no handover: the founder on your intro call is the one inside your network.

Founder and Ethical Hacker
Leads client projects, from external network tests to full-scale intrusions. Writes reports engineers and executives can both act on.
inLinkedIn
Co-founder and Ethical Hacker
OSCP (hands-on exploitation) and CHFI (digital forensics) certified. Web application, API and infrastructure testing. Finds the business logic flaws automated tools miss and hands developers the fix.
inLinkedInHow we test
Why web applications and APIs are the most common way in, and how we test them.
See how we test itFrom the blog
Practical reading for EU companies on the threats we test against.
Sister company
ReactiveZero is our sister company in the Netherlands, run by the same two founders. Same people, same method.
Together we run four NVIDIA DGX systems in our own environment, training a local offensive security model for an AI-assisted penetration testing platform, now in beta. A human tester validates every result, and data never leaves hardware we control.