ZeroHour
Story · 1 source · 1 articlefirst updated ()

BugBase launches Pentest Copilot Enterprise, an autonomous AI black-box pentesting platform

infoToolsimportance 22
What's new: First merged summary for this story: no prior dashboard coverage exists. This summary establishes the baseline for BugBase's Pentest Copilot Enterprise launch (announced 2026-09-04), consolidating capability, coverage-claim and deployment details from two mutually consistent Help Net Security reports; no corrections, supersessions, or figure updates were required.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

BugBase announced Pentest Copilot Enterprise on 2026-09-04: an AI platform that runs autonomous black-box red teaming without source-code access, using parallel agents and real Chromium browsers to attack 100 vulnerability classes with validated, reproducible…

Two Help Net Security reports dated 2026-09-04 (a weekly product roundup and a dedicated article) cover BugBase's launch of Pentest Copilot Enterprise. The platform performs black-box red teaming without sharing source code with testers while maintaining authenticated context. Parallel specialized agents first map pages, APIs, accounts and business functions, then execute iterative attacks across 100 vulnerability types, including authentication, injection and business-logic flaws. It drives real Chromium browsers to preserve cookies, tokens, CSRF state and multiple identities, and navigates WAFs, bot detection, CAPTCHA and T-OTP. BugBase claims full scope coverage on OWASP Juice Shop, Broken Crystals and the GOAD, NHA and DRACARYS Active Directory labs. Reports include reproducible PoCs and one-click retesting, and the product is deployable as SaaS, a dedicated tenant, or on-premises. The two sources agree on the 100 vulnerability types and the use of real Chromium browsers; no discrepancies between the reports were found. No CVE ids, affected product versions, or incident counts were provided in either report.

  • BugBase announced Pentest Copilot Enterprise on 2026-09-04, per Help Net Security's product roundup and a dedicated article published the same day.
  • The platform performs black-box red teaming without sharing source code with testers, while maintaining authenticated context.
  • Parallel specialized agents map pages, APIs, accounts and business functions, then execute iterative attacks across 100 vulnerability types, including authentication, injection and business-logic flaws.
  • Attacks run in parallel across identities, states and workflows.
  • The tool uses real Chromium browsers to preserve cookies, tokens, CSRF state and multiple identities, and navigates WAFs, bot detection, CAPTCHA and T-OTP.
  • BugBase claims full scope coverage on OWASP Juice Shop, Broken Crystals and the GOAD, NHA and DRACARYS Active Directory labs.
  • Reports include reproducible PoCs and one-click retesting.
  • Deployment options: SaaS, dedicated tenant, or on-premises.

Coverage timeline

  1. · 12d ago
    Help Net Security· 15
    New infosec products of the week: September 4, 2026

    Weekly roundup covers F5's AI-powered WAF enhancements, Ping Identity's personal AI agent access, Superna 2.15 cyberstorage, and BugBase Pentest Copilot Enterprise.