VYPR
researchPublished Aug 4, 2026· 1 source

Snyk Launches AI-Powered Continuous Pentesting Platform

Snyk introduces Evo Continuous Offensive Security (COS), an AI-driven platform for autonomous application pentesting and agent red teaming to uncover exploitable vulnerabilities.

Snyk has announced the general availability of Evo Continuous Offensive Security (COS), a new platform designed to empower security teams with continuous, AI-powered pentesting and agent red teaming capabilities. This innovative solution aims to identify and validate exploitable vulnerabilities, including complex architectural flaws and credential leaks within AI-generated code, addressing the rapidly expanding attack surface created by accelerated software development cycles and the integration of AI agents.

The proliferation of AI in software development has significantly increased the attack surface, encompassing architectural intricacies discoverable only by advanced reasoning systems, sensitive credentials embedded in AI-generated code, and the AI models and agents now integral to the development lifecycle. Threat actors are concurrently targeting legacy vulnerabilities, newly written code, and the production environments where AI agents operate. Snyk's research indicates that enterprise AI adoption is outpacing security program capabilities, a concern echoed by the Five Eyes alliance's warning about AI's potential to bypass cybersecurity defenses imminently.

To combat this evolving threat landscape, Snyk's expanded AI Security Platform focuses on four critical actions: discovering the full attack surface, remediating existing vulnerabilities, validating exploitability, and preventing future risks. Evo COS directly addresses the validation aspect by providing continuous testing that goes beyond traditional scanners. It leverages an enterprise-grade AI harness that reasons about application intent to uncover architectural and business-logic vulnerabilities that automated scanners often miss.

Evo COS integrates findings from Snyk Code, Snyk Open Source, and Snyk API & Web, enabling its AI Pentesting and Dynamic Testing (DAST) components to autonomously identify exploitable vulnerabilities at scale. These components exhaustively test endpoints for common flaws like XSS and SQL injection, while the AI pentesting focuses on the more complex issues that traditional tools cannot detect. This approach ensures that security teams have a comprehensive view of their application's security posture.

Furthermore, the platform introduces Agent Red Teaming capabilities to address the unique risks posed by AI agents and LLM-integrated applications. This feature simulates prompt injection, tool and agent abuse, and data exfiltration scenarios, providing continuous testing against evolving agent footprints. Unlike other solutions that rely on synthetic tests, Snyk is developing new benchmarks modeled on real-world environments from design partners.

Beyond validation, Snyk's platform enhancements include AI Security Posture Management (AI-SPM) with upgraded risk taxonomy and scoring, and Evo Agentic AppSec, a preview of an automated remediation agent that fixes vulnerabilities via CLI or ADE. A new malicious code defense solution also aims to protect against supply chain attacks. Snyk Secrets, now generally available, offers secrets detection and prevention tailored for the agentic development lifecycle, with preventative measures integrated across AI coding agents, IDEs, and CI/CD pipelines.

Early adopters have praised Snyk's approach. Emburse's Senior Director and ISO, Colleen Carroll, noted that Snyk's COS provides clearer visibility into exploitable vulnerabilities, enabling faster risk reduction and confident innovation. Gabriel Brolo, Staff Security Engineer at Yalo, highlighted the platform's ability to keep pace with modern software development by focusing on genuinely exploitable risks rather than theoretical possibilities, addressing the limitations of traditional pentesting models.

Synthesized by Vypr AI