HomeCyber BalkansUp to 10x More Coverage Compared to Traditional Pentests

Up to 10x More Coverage Compared to Traditional Pentests

Published on

spot_img

Boston, MA, USA, September 8th, 2026, CyberNewswire

Reflectiz, a prominent player in continuous web exposure management, has unveiled a groundbreaking multi-agent penetration testing platform tailored specifically for websites. This innovative platform utilizes various specialized AI agents designed to identify, exploit, and validate vulnerabilities within intricate web environments. By starting the testing process with an existing model of each site, Reflectiz’s solution significantly increases coverage—up to ten times greater than traditional penetration testing tools.

Historically, penetration testing was viewed as a singular event—a distinct engagement resulting in a report that described a snapshot of a website’s security status at a specific moment. However, in the rapidly evolving digital landscape, this approach has proven inadequate. Websites are frequently updated, yet they are typically subjected to penetration testing only once or twice a year. This significant gap creates an environment where potential exposure can accumulate and become a dangerous vulnerability.

Idan Cohen, CEO and co-founder of Reflectiz, emphasized this disconnect. He pointed out that, “Websites change every week and get pentested once or twice a year. That gap is where exposure builds up.” He underscored the urgent necessity for a testing method that can keep pace with frequent changes without imposing unsustainable costs on web management teams.

Reflectiz’s multi-agent system sets itself apart from traditional tools by leveraging a decade’s worth of data collected from scanning thousands of live production websites. This extensive background allows the AI agents to create a detailed and dynamic model of each site, including pages, scripts, third-party integrations, sensitive data inputs, and overall user behavior. This foundational understanding enables the pentesting agents to adopt an attacker’s perspective, enhancing the effectiveness of the testing process.

Unlike conventional methods that generate findings as mere line items, Reflectiz ensures that the results come equipped with contextual insights about the scripts involved, the data at risk, and the potential exposure to real users in real-time. This capability allows development teams to bypass lengthy investigative processes and focus directly on implementing fixes. Ysrael Gurt, CTO and co-founder of Reflectiz, articulated the essence of their innovation: “The hard part of web pentesting was never the payload. It was understanding what the application actually does.”

The multi-agent system is designed to work as a coordinated team, with each agent fulfilling a unique role. One agent simulates real user behavior by navigating through the site—completing logins, entering one-time codes, and executing two-factor authentication to map out the actual user experience. Another agent classifies the technology stack used on the site and determines which types of attacks are applicable. A third agent conducts the attacks and identifies vulnerabilities, while the fourth agent plays a crucial validation role, reproducing each finding to eliminate false positives before they are presented in the report.

As a result, Reflectiz’s testing yields comprehensive findings, complete with reproduction steps and supporting evidence, alongside a coverage map detailing what was tested. This approach encompasses the full spectrum of vulnerabilities outlined by the OWASP Top 10, allowing teams to select the level of depth for their testing, from rapid, predefined checks to more intricate, expert-level attack patterns targeting critical assets.

The newly launched agentic pentesting feature is part of Reflectiz’s expansive Offensive Hub, which complements existing capabilities within the Security Hub and Privacy Hub. Together, these tools provide a holistic 360° risk map of web exposure, detailing what operates on each website, what data is handled, and the possible attack vectors. Findings from these hubs are cross-referenced automatically, minimizing the need for manual reconciliation of data across dashboards.

For teams navigating security challenges, Reflectiz’s AI remediation agent, Atlas, offers guided solutions for addressing identified risks. This includes clear explanations of vulnerabilities and step-by-step directions for remediation, seamlessly integrating results into existing workflows via REST API, CI/CD triggers, and Slack alerts.

To demonstrate the capabilities of the agentic pentesting platform, the founders of Reflectiz, Idan Cohen and Ysrael Gurt, will host a live webinar on September 15 at 11 AM ET / 6 PM CET. Interested participants can register through Reflectiz’s official website.

Reflectiz’s continuous web exposure management solutions promise to revolutionize how enterprises—across sectors such as retail, finance, travel, insurance, healthcare, and gaming—meet regulatory requirements like PCI DSS and NIS2 while ensuring comprehensive security without altering a single line of code. For further information, interested parties can visit Reflectiz’s website at Reflectiz.

Source link

Latest articles

Cyber Briefing for September 8, 2026 – CyberMaterial

Daily Cybersecurity Insights: Key Developments in Cyber Risks In the ever-evolving domain of cybersecurity, recent...

Breaking Down Data Barriers for More Efficient and Intelligent Policing

A Public Sector Session from Elastic ...

BigBear 2.0 Phishing Campaign Compromises Microsoft 365 Sessions Post-MFA

Title: Rising Phishing Threats Require Prompt Action for Cybersecurity Defense In light of recent cybersecurity...

Adobe Commerce Max-Severity Bug Under Active Attack

Adobe Issues Emergency Hotfix for Vulnerability Exploited by Cybercriminals In recent developments, Adobe has urgently...

More like this

Cyber Briefing for September 8, 2026 – CyberMaterial

Daily Cybersecurity Insights: Key Developments in Cyber Risks In the ever-evolving domain of cybersecurity, recent...

Breaking Down Data Barriers for More Efficient and Intelligent Policing

A Public Sector Session from Elastic ...

BigBear 2.0 Phishing Campaign Compromises Microsoft 365 Sessions Post-MFA

Title: Rising Phishing Threats Require Prompt Action for Cybersecurity Defense In light of recent cybersecurity...