惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
量子位
D
DataBreaches.Net
博客园 - 司徒正美
J
Java Code Geeks
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
B
Blog
The Cloudflare Blog
D
Docker
I
InfoQ
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
腾讯CDC
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
Vercel News
Vercel News
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
S
SegmentFault 最新的问题
GbyAI
GbyAI
有赞技术团队
有赞技术团队

The Last Watchdog

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight | The Last Watchdog News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws | The Last Watchdog News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026 | The Last Watchdog GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it | The Last Watchdog News alert: OpenMatter adds secure routing for OpenAI, Anthropic and Google models | The Last Watchdog LW ROUNDTABLE: OpenAI’s test agents self-organized into a rogue swarm no one anticipated | The Last Watchdog MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits | The Last Watchdog NEWS ALERT: Lunar Cyber tracks stolen API keys, ties them to infected employer devices | The Last Watchdog NEWS ALERT: SRA makes SOC AI license-free — customers pay only for the Azure compute they use | The Last Watchdog BLACK HAT FIRESIDE CHAT: How linking SOC alerts cuts noise, reveals attacks taking shape | The Last Watchdog News alert: Airlock Digital IRAP assessment bolsters trust for sensitive Australian deployments | The Last Watchdog News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week | The Last Watchdog MY TAKE: Black Hat 2026 Part 3 — Agentic AI can do the work, but somebody has to prove it | The Last Watchdog MY TAKE: Black Hat 2026 Part 2 — Security shifts to deciding in advance what an AI agent may reach | The Last Watchdog MY TAKE: Black Hat 2026 Wrap-up Part 1 — AI is forcing security and operations to merge in the SOC | The Last Watchdog News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures | The Last Watchdog BLACK HAT ROUNDTABLE: Security pros dissect fallout from Hugging Face’s double guardrail failure | The Last Watchdog News alert: Airlock extends endpoint control to govern AI agents and define operating boundaries | The Last Watchdog News alert: Mallory links threat intelligence to governed response as exploit timelines shrink | The Last Watchdog News alert: Community voting shapes 2026 Cybersecurity Excellence Awards | The Last Watchdog BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate | The Last Watchdog News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations | The Last Watchdog News alert: Insignary’s on-demand SBOM verification boosts software supply chain security | The Last Watchdog News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions | The Last Watchdog News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI | The Last Watchdog News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk | The Last Watchdog News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks | The Last Watchdog News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks | The Last Watchdog News alert: OpenMatter launches platform to verify AI activity across enterprise systems | The Last Watchdog News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies | The Last Watchdog
News alert: Bright Security launches AI PT, AI-powered pe...
cybernewswire · 2026-09-02 · via The Last Watchdog

SAN RAFAEL, Calif., Sept. 1, 2026, CyberNewswire — As AI compresses the gap between vulnerability disclosure and exploitation to nearly zero, the new AI Pentesting Module gives security teams continuous, AI-driven penetration testing built on Bright’s proven dynamic testing engine, at a fraction of traditional cost.Bright Security, the AI-native application security company, today announced AI PT, its new AI penetration testing module. It finds, exploits, and proves real vulnerabilities the way a human tester would, at a fraction of the time and cost of a traditional engagement.

The launch responds to a rapidly closing window between disclosure and exploitation. Frontier AI systems built for security research, including Anthropic’s Claude Mythos and OpenAI’s Aardvark, can now discover and weaponize software flaws with little to no human involvement. Anthropic’s own research team recently used a similarly capable system to uncover more than 500 previously unknown high-severity vulnerabilities in widely used open-source software, flaws that had gone undetected for years. Independent research tracking more than 83,000 CVEs, compiled by Zero Day Clock, found that the typical gap between a vulnerability’s disclosure and its first exploit has fallen from roughly two years in 2018 to a matter of hours today. Separately, vulnerability-intelligence firm VulnCheck reports that more than a quarter of exploited flaws are now weaponized within 24 hours of going public.

That leaves most security teams badly outpaced. The typical enterprise still runs a formal penetration test once or twice a year and takes a median of 43 days to remediate what that test finds. Between engagements, and while a finding works its way through the fix queue, applications sit exposed to exactly the kind of fast-moving, AI-assisted attackers described above.

AI PT closes that gap. Purpose-built agents map an organization’s live attack surface across apps and APIs, build a threat model, and craft real exploits, the same way an attacker would, then run them against the live application. Attack-surface discovery and authentication run on Bright’s proven, deterministic DAST engine rather than AI guesswork, the same engine behind Bright’s Dynamic Testing and STAR Harness modules, so what AI PT finds reflects how the application actually behaves.

Bashvitz

“Since the advent of solutions like Mythos and Aardvark came on the scene, many of our customers and partners have been very concerned about their ability to protect their AI SDLC. We continuously strive to offer these customers the most up to date solutions. With the release of the AI PT module, we continue to build on the STAR solution we launched in 2025 and enable organizations to leverage AI where it matters, both early and late in the SDLC, while relying on our industry-leading dynamic engine to deliver validated results at a fraction of the cost of AI-only solutions, Manual pentesting still has its place. It just wasn’t built to run at the speed of AI-assisted development. AI PT lets teams test every release, not just the ones they can schedule a tester for.” said Gadi Bashvitz, CEO of Bright Security. ”

“We built AI Pentesting on top of our existing discovery, authentication, and centralized management platform. This enables the much-needed reduction in time to detect vulnerabilities in the AI era, while delivering greater predictability and significantly lower costs than pure AI pentesting approaches.� Said Tom, VP Product at Bright Security.

Bright’s AI Pentesting advantage:

•Continuous coverage. Every release gets tested, not just the one or two a year a scheduled tester allows.

•Deterministic discovery and authentication. AI PT runs attack-surface discovery and authentication on Bright’s proven DAST engine instead of AI guesswork, the same accuracy advantage behind Bright’s other modules.

•Flexible engagement depth. Black box and grey box testing, matched to what you’d give a human tester.

•Autonomous or human in the loop. Run it fully automated, or gate exploit steps for review.

•Built into the platform. Findings live alongside STAR Harness and Dynamic Testing in one system of record, ready for SOC 2, GDPR, and ISO 27001 audits.

Availability and pricing

AI PT is available now as part of the Bright Security platform. Continuous, validated coverage comes at a fraction of what traditional pentest firms charge. Security teams at multiple global top-10 insurance and financial institutions already run on Bright’s platform.

Want to see it find and prove a real vulnerability, live? Book a 30-minute demo at brightsec.com/product/book-a-demo, or learn more about AI PT at brightsec.com/ai-pt.

About Bright Security: Bright Security (brightsec.com) is an AI-native application security company. It helps enterprises find and fix real vulnerabilities in their applications and APIs early in the development lifecycle. The platform pairs agentic AI with an industry-leading dynamic testing engine to deliver automated testing, auto-remediation, and AI-driven penetration testing at enterprise scale, without the false positives and manual grind of legacy AppSec tools. Bright Security is ISO 27001 and ISO 27701 certified, AICPA SOC compliant, and GDPR ready. The company is headquartered in California.

Media contact: Eyal Dror, CMO, Bright Security Inc, eyal.dror@brightsec.com

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

September 1st, 2026 | News Alerts | Top Stories