Cobalt Introduces Autonomous Pentest to Bring Continuous Offensive Security to Modern Development

Cobalt has introduced Autonomous Pentest, a new AI-powered capability designed to help organizations continuously test applications for security vulnerabilities across their entire software portfolio. Fully integrated into the Cobalt Offensive Security Platform, the new offering delivers validated, actionable findings in as little as 24 hours while keeping expert human pentesters at the center of every engagement.

As AI accelerates software development and organizations ship code faster than ever, traditional penetration testing performed quarterly or even monthly can no longer keep pace. At the same time, security teams are managing expanding attack surfaces with limited budgets, creating demand for a more scalable approach to identifying and validating exploitable risk.

Rather than replacing human expertise, Cobalt Autonomous Pentest combines expert-led offensive security with AI-powered orchestration and insights drawn from more than a decade of real-world pentesting data. The platform delivers scale through three core capabilities:

  • Expert Direction: Every engagement is led by experienced Cobalt pentesters, who review execution plans, enforce scope discipline, and apply the creative adversarial reasoning that AI alone cannot replicate.
  • Model-Agnostic AI: A model-agnostic AI engine performs chain prediction, prioritization, and adaptive sequencing. Informed by 13 years of exploit data, it continuously adapts as attacker techniques and the threat landscape evolve.
  • Findings in 24 Hours: Validated findings are delivered within 24 hours directly into Jira, GitHub, Slack, and more than 50 other security and development tools. Each finding includes proof of exploit where applicable, reproduction steps, and tailored remediation guidance to help teams take immediate action.

“Meeting the demands of today’s development cycles requires more than automating traditional pentesting,” said Sonali Shah, CEO of Cobalt. “It requires rethinking how offensive security is delivered. Only Cobalt unifies the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry’s largest dataset of real-world pentest results. Together, these capabilities enable security teams to continuously identify, prioritize, and remediate exploitable risk at the speed of modern software development.”

The Autonomous Pentest offering is powered by insights from more than 10,000 critical and high-severity findings. By combining this extensive exploit dataset with experienced human pentesters, Cobalt aims to help organizations achieve fast, flexible, and precise security coverage across their entire application portfolio.

Cobalt is showcasing Autonomous Pentest at Black Hat USA 2026 (Booth 4903), with general availability planned for August 2026.

Join our LinkedIn group Information Security Community!

No posts to display