ZeroHour
CSO Onlinepublished ()ingested

Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

infoToolsimportance 20
AI summary · glm-5.3-flash

Reflectiz launched a multi-agent AI penetration testing platform for websites, claiming up to 10x more coverage than conventional pentests.

Reflectiz, a continuous web exposure management vendor, launched a multi-agent penetration testing platform for websites under a new Offensive Hub. Four specialized agents crawl the site like a real user, fingerprint the stack, run attacks, and independently validate findings to remove false positives. The company claims up to 10x more coverage than conventional pentesting by starting from its pre-existing live model of each site. Findings integrate via REST API, CI/CD triggers and Slack, and the Atlas remediation agent guides fixes.

  • Team of four agents: user-like crawler, stack fingerprinter, attack runner, and independent validator to eliminate false positives
  • Claims up to 10x more coverage than conventional pentesting by leveraging Reflectiz's existing model of each website
  • Part of new Offensive Hub alongside Security Hub and Privacy Hub, with automatically cross-referenced findings
  • Covers OWASP Top 10; results route into existing workflows via REST API, CI/CD triggers and Slack alerts
VendorsReflectiz
OrganizationsReflectiz
Full article611 words · extracted from csoonline.com · click to collapse

Press release By CyberNews Wire

Sep 8, 20264 mins

Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. 

Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.

A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily. 

“Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.”

While others start every test blind, Reflectiz already knows the website.

Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. The pentesting agents add the attacker’s perspective to that same model.

A finding does not arrive as a line item. It arrives with the script involved, the data it can reach, and whether real users are exposed right now, allowing teams to skip the investigation and go straight to the fix.

“The hard part of web pentesting was never the payload. It was understanding what the application actually does,” said Ysrael Gurt, CTO and co-founder of Reflectiz. “Our engine has been reading live websites for years, so our agents start with a map of the site that other tools never build.”

A team of specialized agents, not another scanner

The agentic pentesting runs as a coordinated team of AI agents, each with a defined role:

  • One agent crawls the site the way a real user does, through logins, one-time codes, and 2FA, mapping what is actually there.
  • A second fingerprints the stack and works out which attacks apply where.
  • A third runs those attacks and chains what it finds.
  • The fourth matters most: an independent validator reproduces every finding before it reaches the report. False positives are removed by design.

The result: findings with reproduction steps and evidence, plus a coverage map of what was tested and cleared. 

Testing spans the full OWASP Top 10, and teams set depth per flow, from fast predefined checks to expert-level attack chains on critical assets. 

Completing the 360° map of web risk

The agentic pentesting, part of the new Offensive Hub, joins Security Hub and Privacy Hub on the Reflectiz platform, completing a 360° map of web risk: what runs on the website, what data it touches, and how it can be attacked.

  • One exposure picture. Findings from all three hubs cross-reference automatically, no dashboards reconciled by hand.
  • Guided fixes. Atlas, the Reflectiz AI remediation agent, explains each risk and walks the team through the fix.
  • Existing workflows. Results route into current operations through a REST API, CI/CD triggers, and Slack alerts.

See it live

Reflectiz Launches Agentic Pentesting for Websites

CyberNews Wire

Reflectiz

Reflectiz is the continuous web exposure management company. Its agentless, outside-in platform monitors, tests, and secures the entire web layer, from third-party scripts and web privacy risk to agentic penetration testing of the live site. Reflectiz helps enterprises in retail, finance, travel, insurance, healthcare, and gaming meet PCI DSS, DORA, NIS2, and global privacy requirements without touching a line of code. Learn more at https://www.reflectiz.com.

Contact

Marketing Manager

Oran Frenkel

Reflectiz

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4219697/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests.html