AI Weekly Malaysia

Back to items Summaries

What Is Agentic Pentesting? What It Proves, and Where It Stops.

ID
32711
Status
summarized
Published
07 Oct 2026, 7:42 PM
Fetched
07 Oct 2026, 8:35 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/what-is-agentic-pentesting-what-it.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
07 Oct 2026, 8:36 PM
Tags
Audience
developerssaas_foundersai_agent_users

What happened

This is a vendor explainer from Picus, which states plainly that it builds and sells autonomous pentesting, arguing that agentic pentesting's real limits are in timing and coverage rather than detection. It cites four 2026 figures: 35,364 CVEs in H1 (up 49.5% YoY), only 95 of roughly 39,600 CVEs published through August with confirmed in-the-wild exploitation, mean disclosure-to-exploitation time collapsing from 21.5 days in 2025 to 8 hours in 2026, and just 421 of 26,000+ AI-scale-discovered vulnerabilities patched upstream. The piece frames Gartner's Continuous Offensive Security Testing model as the replacement for point-in-time pentests, citing a planning assumption that over 60% of enterprise pentest programs will be continuous validation by 2028. The excerpt cuts off mid-sentence and provides no methodology or links for its numbers.

Why it matters

The one actionable detail is the gap arithmetic: an annual pentest leaves up to a 365-day blind window and weekly automated runs leave up to seven days, against an 8-hour exploitation window the article claims. If your release cadence is daily or weekly and your security validation is annual, the cadence is mismatched regardless of tooling. Separately, if your patch queue is ranked by CVSS severity, the 95-of-39,600 exploitation figure is an argument to re-rank by confirmed exploitation instead. Treat all four numbers as vendor-sourced and unverified, since Picus sells the product category the article concludes you need.

Discussion angle

Do the cadence math for your own team: how many days sit between a production change and the next security validation? Then decide whether you'd move to trigger-based validation on deploy, and what a small team would actually need to run that without a vendor platform.

Top