Threat Intelligence

Agentic Pentesting Promises Faster Proof of Exposure, But Know Where It Stops

The Hacker News · 7 Oct 2026
Key Takeaway When evaluating any automated pentesting service, ask how quickly it retests after changes and whether it proves exploitability with evidence, rather than relying on yearly tests alone.

Agentic pentesting tools are pitched as systems you point at a target so they can discover, validate and exploit attack paths on their own, much as a real attacker would. The source article, from The Hacker News, says that promise deserves serious attention and also careful pressure testing. Its author, Picus, builds and sells autonomous pentesting, and says it is open about the method's limits for that reason.

The article's core argument is about timing. An annual pentest can leave up to a 365-day blind window between a change and the next test, and weekly automated runs still leave a gap of up to seven days. Against an eight-hour exploitation window, the article says both approaches lose. It points to Gartner's Continuous Offensive Security Testing model, which favours trigger-driven, risk-tiered testing completed in minutes or hours. Gartner's planning assumption is that by 2028 over 60% of enterprise pentest programs will run as continuous validation.

According to the article, agentic pentesting offers two proofs. First, it confirms whether individual exposures are exploitable by safely executing the exploit, rather than guessing from a version banner. Second, it shows chained reach, from initial access through privilege escalation and lateral movement to a critical asset. Because each fix can be rechecked with another run, remediation becomes defensible rather than hopeful. The excerpt we have covers only the opening of the article, so its discussion of the method's limits is not included here.

pentesting vulnerability management continuous validation SMB security

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.