AGP Picks
View all

Bright Security Expands its AI SDLC security Platform & Launches an AI PT Module

Picture1

SAN RAFAEL, Calif., Sept. 01, 2026 (GLOBE NEWSWIRE) --

Bright Security Expands AI SDLC Security Platform, Launches AI PT: AI-Powered Penetration Testing That Cuts Weeks Down to Hours

As AI compresses the gap between vulnerability disclosure and exploitation to nearly zero, the new AI Pentesting Module gives security teams continuous, AI-driven penetration testing built on Bright's proven dynamic testing engine, at a fraction of traditional cost.

Bright Security, the AI-native application security company, today announced AI PT, its new AI penetration testing module. It finds, exploits, and proves real vulnerabilities the way a human tester would, at a fraction of the time and cost of a traditional engagement.

The launch responds to a rapidly closing window between disclosure and exploitation. Frontier AI systems built for security research, including Anthropic's Claude Mythos and OpenAI's Aardvark, can now discover and weaponize software flaws with little to no human involvement. Anthropic's own research team recently used a similarly capable system to uncover more than 500 previously unknown high-severity vulnerabilities in widely used open-source software, flaws that had gone undetected for years. Independent research tracking more than 83,000 CVEs, compiled by Zero Day Clock, found that the typical gap between a vulnerability's disclosure and its first exploit has fallen from roughly two years in 2018 to a matter of hours today. Separately, vulnerability-intelligence firm VulnCheck reports that more than a quarter of exploited flaws are now weaponized within 24 hours of going public.

Picture2

That leaves most security teams badly outpaced. The typical enterprise still runs a formal penetration test once or twice a year and takes a median of 43 days to remediate what that test finds. Between engagements, and while a finding works its way through the fix queue, applications sit exposed to exactly the kind of fast-moving, AI-assisted attackers described above.

AI PT closes that gap. Purpose-built agents map an organization's live attack surface across apps and APIs, build a threat model, and craft real exploits, the same way an attacker would, then run them against the live application. Attack-surface discovery and authentication run on Bright's proven, deterministic DAST engine rather than AI guesswork, the same engine behind Bright's Dynamic Testing and STAR Harness modules, so what AI PT finds reflects how the application actually behaves.

"Since the advent of solutions like Mythos and Aardvark came on the scene, many of our customers and partners have been very concerned about their ability to protect their AI SDLC. We continuously strive to offer these customers the most up to date solutions. With the release of the AI PT module, we continue to build on the STAR solution we launched in 2025 and enable organizations to leverage AI where it matters, both early and late in the SDLC, while relying on our industry-leading dynamic engine to deliver validated results at a fraction of the cost of AI-only solutions, Manual pentesting still has its place. It just wasn't built to run at the speed of AI-assisted development. AI PT lets teams test every release, not just the ones they can schedule a tester for," said Gadi Bashvitz, CEO of Bright Security.

“We built AI Pentesting on top of our existing discovery, authentication, and centralized management platform. This enables the much-needed reduction in time to detect vulnerabilities in the AI era, while delivering greater predictability and significantly lower costs than pure AI pentesting approaches,” said Tom, VP Product at Bright Security.

Bright's AI Pentesting advantage:

  • Continuous coverage. Every release gets tested, not just the one or two a year a scheduled tester allows.
  • Deterministic discovery and authentication. AI PT runs attack-surface discovery and authentication on Bright's proven DAST engine instead of AI guesswork, the same accuracy advantage behind Bright's other modules.
  • Flexible engagement depth. Black box and grey box testing, matched to what you'd give a human tester.
  • Autonomous or human in the loop. Run it fully automated, or gate exploit steps for review.
  • Built into the platform. Findings live alongside STAR Harness and Dynamic Testing in one system of record, ready for SOC 2, GDPR, and ISO 27001 audits.

Availability and pricing

AI PT is available now as part of the Bright Security platform. Continuous, validated coverage comes at a fraction of what traditional pentest firms charge. Security teams at multiple global top-10 insurance and financial institutions already run on Bright's platform.

Want to see it find and prove a real vulnerability, live? Book a 30-minute demo at brightsec.com/product/book-a-demo, or learn more about AI PT at brightsec.com/ai-pt.

About Bright Security

Bright Security (brightsec.com) is an AI-native application security company. It helps enterprises find and fix real vulnerabilities in their applications and APIs early in the development lifecycle. The platform pairs agentic AI with an industry-leading dynamic testing engine to deliver automated testing, auto-remediation, and AI-driven penetration testing at enterprise scale, without the false positives and manual grind of legacy AppSec tools. Bright Security is ISO 27001 and ISO 27701 certified, AICPA SOC compliant, and GDPR ready. The company is headquartered in California.

Contact

CMO
Eyal Dror
Bright Security Inc
eyal.dror@brightsec.com

Photos accompanying this announcement are available at 

https://www.globenewswire.com/NewsRoom/AttachmentNg/7f2cfb87-c6ff-4eb4-899f-2a7239107542

https://www.globenewswire.com/NewsRoom/AttachmentNg/e6591533-5f3f-4d43-a209-c9b90d9a06ec


Bright Security Inc

Bright Security Inc
Bright Security Inc

Bright Security Inc

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

St. Vincent & Grenadines Industry Wire

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.