- Time-to-exploit: Dropped from ~2 years (2018) to mere hours today (Zero Day Clock).
- Weaponization speed: 25% of flaws exploited within 24 hours of disclosure (VulnCheck).
- Remediation delay: Median 43 days between vulnerability discovery and fix.
Experts would likely conclude that AI-powered security tools are becoming essential to match the speed and sophistication of AI-driven cyberattacks, though human oversight remains critical for accuracy and control.
The New Arms Race: Can AI-Powered Testers Outpace AI-Driven Attacks?
SAN RAFAEL, CA – September 01, 2026
The gap between discovering a software vulnerability and seeing it weaponized by attackers has collapsed. What once took months or even years now takes a matter of hours, a dizzying acceleration fueled by the very same artificial intelligence that promises to revolutionize our world. This new reality has rendered traditional cybersecurity timelines obsolete, forcing a fundamental rethink of how we defend our digital infrastructure. Into this high-stakes environment steps Bright Security, which today announced an expansion of its platform with AI PT, an AI-powered penetration testing module designed to fight fire with fire.
A Threat Measured in Hours, Not Years
The central challenge confronting security teams today is speed. Research from Zero Day Clock, tracking over 83,000 vulnerabilities, reveals a stark trend: the average time-to-exploit has plummeted from roughly two years in 2018 to mere hours today. This is not a theoretical risk. Vulnerability-intelligence firm VulnCheck corroborates this, reporting that over a quarter of exploited flaws are now weaponized within 24 hours of public disclosure. The reason for this compression is the rise of sophisticated AI systems, like the research models 'Claude Mythos' and 'Aardvark,' which can autonomously discover and weaponize software flaws with minimal human intervention.
This leaves the vast majority of organizations dangerously exposed. The standard practice of conducting a formal penetration test once or twice a year, followed by a remediation process that takes a median of 43 days, is a relic of a bygone era. Between these scheduled tests, applications are sitting ducks for attackers who operate on a timeline measured in minutes, not fiscal quarters. An application security manager at a major financial institution, speaking on condition of anonymity, put it bluntly: "Our annual pentest report is a snapshot of a single day. The other 364, we're flying partially blind, and we know the adversary isn't taking a day off."
Fighting AI with AI: A New Pentesting Paradigm
Bright Security's AI PT module is a direct response to this new paradigm. It aims to automate the work of a human penetration tester, but at machine speed and scale. The system is designed to autonomously map an organization's live attack surface, build a threat model, and then craft and execute real exploits to prove a vulnerability's existence and severity.
"Manual pentesting still has its place. It just wasn't built to run at the speed of AI-assisted development," said Gadi Bashvitz, CEO of Bright Security, in the announcement. "AI PT lets teams test every release, not just the ones they can schedule a tester for."
What sets this approach apart from being just another automated scanner is its hybrid architecture. The company, which rebranded from NeuraLegion in 2022, has built its reputation on a 'developer-first' dynamic application security testing (DAST) engine that boasts impressively low false-positive rates. The new AI PT module leverages this proven, deterministic engine for the critical initial steps of discovery and authentication. This is a crucial design choice. Instead of relying on a purely generative AI model that might hallucinate or misinterpret an application's structure—what the company calls "AI guesswork"—it grounds its attack simulations in a verifiable map of how the application actually behaves.
“We built AI Pentesting on top of our existing discovery, authentication, and centralized management platform," noted Tom, the company's VP of Product. This layered approach, he explained, enables the drastic reduction in detection time needed in the AI era while delivering "greater predictability and significantly lower costs than pure AI pentesting approaches.” By combining its deterministic engine with agentic AI for exploit crafting, the platform aims to deliver the best of both worlds: the accuracy of a validated map and the creative, adaptive attack strategies of an AI agent.
The Economic and Operational Shift
The implications of this technology extend far beyond the security operations center. For business leaders and CFOs, the value proposition is rooted in economics and efficiency. The high cost and limited availability of elite human penetration testers create a natural bottleneck. AI PT promises to break that bottleneck, offering what the company calls "continuous coverage" at a fraction of the cost of traditional engagements. Testing every single software release becomes not just a theoretical ideal but an operational possibility.
This shift also directly impacts developer productivity. A long-standing complaint in the AppSec world is the deluge of false positives from legacy scanning tools, which forces development teams to waste countless hours chasing phantom vulnerabilities. By focusing on validated, exploitable findings—a core tenet of the company's platform, which claims a false-positive rate under 3%—tools like AI PT allow developers to focus their efforts on real risks. This aligns with the broader 'shift-left' movement, integrating security seamlessly into the development lifecycle rather than treating it as a final, painful checkpoint.
Furthermore, the system offers flexibility. Users can configure it for 'black box' or 'grey box' testing, mimicking the levels of information they would provide to a human testing team. Critically, for organizations wary of unleashing a fully autonomous hacking tool on their live systems, AI PT includes a 'human in the loop' option, allowing security teams to review and approve exploit steps before they are executed. This provides a vital safeguard and an element of control as organizations grow comfortable with this new capability.
Weaving a More Resilient Digital Fabric
Bright Security's announcement is not just about a single product; it's a reflection of the maturation of AI-native security. The platform's ability to test for vulnerabilities specific to AI-generated code, including those outlined in the OWASP LLM Top 10, shows a forward-looking awareness of how the development landscape itself is changing. The integration of findings from AI PT alongside the platform's other modules—Dynamic Testing and STAR Harness—into a single system of record streamlines compliance and auditing for standards like SOC 2 and ISO 27001.
As AI continues to be woven into every aspect of software creation and deployment, security can no longer be a reactive, human-gated process. It must become as automated, intelligent, and continuous as the development cycles it is meant to protect. By providing an AI-powered defense that operates at the speed of AI-powered attacks, the industry is beginning to build the tools necessary to secure a future where the front lines of cyber defense are increasingly autonomous.
Topics & Related
Artificial Intelligence
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →