What Is Agentic Pentesting? What It Proves, and Where It Stops.
- ID
- 32711
- Status
- summarized
- Published
- 07 Oct 2026, 7:42 PM
- Fetched
- 07 Oct 2026, 8:35 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/what-is-agentic-pentesting-what-it.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 07 Oct 2026, 8:36 PM
- Tags
- Audience
- developerssaas_foundersai_agent_users
What happened
This is a vendor explainer from Picus, which states plainly that it builds and sells autonomous pentesting, arguing that agentic pentesting's real limits are in timing and coverage rather than detection. It cites four 2026 figures: 35,364 CVEs in H1 (up 49.5% YoY), only 95 of roughly 39,600 CVEs published through August with confirmed in-the-wild exploitation, mean disclosure-to-exploitation time collapsing from 21.5 days in 2025 to 8 hours in 2026, and just 421 of 26,000+ AI-scale-discovered vulnerabilities patched upstream. The piece frames Gartner's Continuous Offensive Security Testing model as the replacement for point-in-time pentests, citing a planning assumption that over 60% of enterprise pentest programs will be continuous validation by 2028. The excerpt cuts off mid-sentence and provides no methodology or links for its numbers.
Why it matters
The one actionable detail is the gap arithmetic: an annual pentest leaves up to a 365-day blind window and weekly automated runs leave up to seven days, against an 8-hour exploitation window the article claims. If your release cadence is daily or weekly and your security validation is annual, the cadence is mismatched regardless of tooling. Separately, if your patch queue is ranked by CVSS severity, the 95-of-39,600 exploitation figure is an argument to re-rank by confirmed exploitation instead. Treat all four numbers as vendor-sourced and unverified, since Picus sells the product category the article concludes you need.
Discussion angle
Do the cadence math for your own team: how many days sit between a production change and the next security validation? Then decide whether you'd move to trigger-based validation on deploy, and what a small team would actually need to run that without a vendor platform.