thehackernews.com 7 Oct 2026, 11:42 UTC

Agentic Pentesting Exposes Attack Paths as Exploits Arrive in Hours

CyberSIXT Evidence Panel Source marked as original reporting

THE Hacker News discussion on agentic pentesting explains that these autonomous security assessments aim to discover, validate and exploit attack paths at scale, mirroring real attacker behaviour, and that the real value lies not in the first step (proving exploitability) but in when and how broadly that proof is delivered.

The piece notes that four year-to-date metrics drive the urgency: 35,364 CVEs were found in the first half of 2026 (up 49.5% year over year); only 95 of around 39,600 CVEs published through August have seen confirmed in‑the‑wild exploitation, indicating that severity rankings can mislead prioritisation; the average time from disclosure to exploitation dropped from 21.5 days in 2025 to about eight hours in 2026; and more than 26,000 vulnerabilities surfaced by AI-scale discovery had only 421 patches upstream.

The article argues that traditional annual or weekly testing leaves large, exploitable blind windows, especially against an eight‑hour exploitation window.

Two proofs underpin agentic pentesting: first, proving whether individual exposures are exploitable through live exploits (as opposed to banner or version-based inferences); second, demonstrating chained reach by validating real attack paths from initial access through privilege escalation and lateral movement to a critical asset, with evidence on the affected assets.

It also discusses the practical limits: even across a 250,000-endpoint estate, full cycle testing takes weeks and may miss fast-changing conditions; live exploitation cannot cover production‑only zones or certain CVEs without working exploits. The article then frames an evolving validation model—trigger‑driven, risk‑tiered testing that can operate within risk‑aligned timeframes and, by 2028, may see over 60% of enterprise pentest programs running as continuous validation.

View full article

Article by CyberSIXT