ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Reflectiz launches agentic pentesting for websites, claiming up to 10x coverage vs conventional pentests

infoToolsimportance 22
What's new: First merged summary for this story - no previous coverage exists. The change event is the launch announcement itself: Reflectiz introduced its agentic pentesting platform and Offensive Hub, reported 2026-09-08. The three reports are mutually consistent; unique additions are the September 15 webinar (GBHackers), per-flow depth controls for critical assets (Cyber Security News), and cross-hub…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Reflectiz, a web exposure management vendor, has announced a multi-agent AI penetration testing platform for websites inside a new 'Offensive Hub'. Four specialized agents crawl, fingerprint, attack, and independently validate web applications; the vendor…

Reflectiz announced (per report timestamps of 2026-09-08) an agentic penetration testing capability for websites, housed in a new Offensive Hub alongside its existing Security Hub and Privacy Hub, with findings automatically cross-referenced across hubs. The platform chains four specialized AI agents: a user-like crawler, a stack fingerprinter, an attack runner/chainer, and an independent validator that reproduces every finding before reporting to cut false positives. Coverage is claimed to span the OWASP Top 10, with per-flow depth controls for critical assets. The vendor attributes an up-to-10x coverage advantage over conventional pentesting to its pre-existing live model of each site, which GBHackers says is built on a decade of site-scanning context. Findings ship with reproduction steps and coverage maps and integrate via REST API, CI/CD triggers, and Slack; an Atlas AI remediation agent explains risks and walks teams through fixes, and GBHackers adds a planned September 15 webinar demo. All three reports derive from the vendor announcement (Cyber Security News flags its item as a syndicated CyberNewswire press release), and the performance claims lack third-party validation. There are no substantive disagreements between the sources; the only differences are the unique details noted above.

  • Reflectiz, described as a (continuous) web exposure management vendor, announced the agentic penetration testing platform; all three reports are dated 2026-09-08.
  • The product sits in a new 'Offensive Hub' alongside Reflectiz's Security Hub and Privacy Hub, with findings automatically cross-referenced across hubs (per CSO Online).
  • Four coordinated agent roles: user-like crawling, stack fingerprinting, attack execution/chaining, and independent validation; the validator reproduces every finding before reporting to reduce false positives (per GBHackers).
  • Vendor claims up to 10x more coverage than conventional pentesting, attributed to a pre-existing live model of each site; GBHackers cites 'a decade of site-scanning context' for production websites as the foundation.
  • Testing is claimed to cover the full OWASP Top 10; Cyber Security News adds per-flow depth controls for critical assets.
  • Findings are delivered with reproduction steps and coverage maps and integrate via REST API, CI/CD triggers, and Slack.
  • The Atlas AI remediation agent explains risks and guides teams through fixes (named in all three reports).
  • GBHackers reports a planned September 15 webinar demo of the platform.
VendorsReflectiz
OrganizationsReflectiz

Coverage timeline

  1. · 9d ago
    Cyber Security News· 22
    Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

    Reflectiz released an agentic penetration testing platform using specialized AI agents to discover, attack, and validate web vulnerabilities with independently validated findings.

  2. · 9d ago
    GBHackers· 22
    Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

    Reflectiz launched a multi-agent AI penetration testing platform for websites, claiming up to 10x more coverage than conventional pentests by leveraging existing site context.