ZeroHour
GBHackerspublished ()ingested CyberNewswire
Part of a story covered by 2 sources: “Reflectiz launches agentic pentesting for websites, claiming up to 10x coverage vs conventional pentests” — merged summary and timeline →

Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

infoToolsimportance 22
AI summary · glm-5.3-flash

Reflectiz launched a multi-agent AI penetration testing platform for websites, claiming up to 10x more coverage than conventional pentests by leveraging existing site context.

Reflectiz, a web exposure management vendor, announced an agentic penetration testing product within a new Offensive Hub. The platform uses specialized AI agents for crawling, stack fingerprinting, attack execution, and independent validation, claiming to cover the OWASP Top 10 and reduce false positives. Findings integrate with existing workflows via REST API, CI/CD triggers, and Slack, and an AI remediation agent named Atlas guides fixes. The announcement is a vendor press release with a planned September 15 webinar demo.

  • Multi-agent pentesting platform built on a decade of site-scanning context for production websites.
  • Independent validator agent reproduces every finding before reporting to cut false positives.
  • Rules and findings route into REST API, CI/CD, and Slack; remediation guided by Atlas agent.
  • Vendor claims 10x coverage versus conventional pentesting; claims are not independently verified.
Full article653 words · extracted from gbhackers.com · click to collapse

Boston, MA, USA, September 8th, 2026, CyberNewswire

Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. 

Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites.

Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.

A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily. 

“Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.”

While others start every test blind, Reflectiz already knows the website.

Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors.

The pentesting agents add the attacker’s perspective to that same model.

A finding does not arrive as a line item. It arrives with the script involved, the data it can reach, and whether real users are exposed right now, allowing teams to skip the investigation and go straight to the fix.

“The hard part of web pentesting was never the payload. It was understanding what the application actually does,” said Ysrael Gurt, CTO and co-founder of Reflectiz.

“Our engine has been reading live websites for years, so our agents start with a map of the site that other tools never build.”

A team of specialized agents, not another scanner

The agentic pentesting runs as a coordinated team of AI agents, each with a defined role:

  • One agent crawls the site the way a real user does, through logins, one-time codes, and 2FA, mapping what is actually there.
  • A second fingerprints the stack and works out which attacks apply where.
  • A third runs those attacks and chains what it finds.
  • The fourth matters most: an independent validator reproduces every finding before it reaches the report. False positives are removed by design.

The result: findings with reproduction steps and evidence, plus a coverage map of what was tested and cleared. 

Testing spans the full OWASP Top 10, and teams set depth per flow, from fast predefined checks to expert-level attack chains on critical assets. 

Completing the 360° map of web risk

The agentic pentesting, part of the new Offensive Hub, joins Security Hub and Privacy Hub on the Reflectiz platform, completing a 360° map of web risk: what runs on the website, what data it touches, and how it can be attacked.

  • One exposure picture. Findings from all three hubs cross-reference automatically, no dashboards reconciled by hand.
  • Guided fixes. Atlas, the Reflectiz AI remediation agent, explains each risk and walks the team through the fix.
  • Existing workflows. Results route into current operations through a REST API, CI/CD triggers, and Slack alerts.

See it live

Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the agentic pentesting in a live webinar on September 15 at 11 AM ET / 6 PM CET.

Registration: https://www.reflectiz.com/lp/founders-case-study-webinar/

Product information: Reflectiz Offensive Hub | Walkthrough Video

About Reflectiz

Reflectiz is the continuous web exposure management company. Its agentless, outside-in platform monitors, tests, and secures the entire web layer, from third-party scripts and web privacy risk to agentic penetration testing of the live site.

Reflectiz helps enterprises in retail, finance, travel, insurance, healthcare, and gaming meet PCI DSS, DORA, NIS2, and global privacy requirements without touching a line of code. Learn more at https://www.reflectiz.com.

Marketing Manager

Oran Frenkel

Reflectiz

[email protected]

CyberNewswire

A PR Newswire Syndication Platform for Cybersecurity Companies

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests/