The Good Tech Companies - Bright Security Expands its AI SDLC security Platform & Launches an AI PT Module

Episode Date: September 1, 2026

This story was originally published on HackerNoon at: https://hackernoon.com/bright-security-expands-its-ai-sdlc-security-platform-and-launches-an-ai-pt-module. Bright S...ecurity Expands AI SDLC Security Platform, Launches AI PT: AI-Powered Penetration Testing That Cuts Weeks Down to Hours Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #cybersecurity, #ai, #cybernewswire, #press-release, #cyber-threats, #cyber-security-awareness, #cybersecurity-tips, #good-company, and more. This story was written by: @cybernewswire. Learn more about this writer by checking @cybernewswire's about page, and for more stories, please visit hackernoon.com.

Transcript
Discussion (0)
Starting point is 00:00:00 This audio is presented by Hacker Noon, where anyone can learn anything about any technology. Bright Security expands its AISDLC security platform and launches an AIPT module by Cyber Newswire. San Rafael, United States, September 1, 2026, Cyber Newswire, as AI compresses the gap between vulnerability disclosure and exploitation to nearly zero, the new AI pentesting module gives security team's continuous, AI-driven penetration testing built on Bright's proven dynamic testing engine at a fraction of traditional cost. Bright Security, the AI native application security company, today announced AIPT, its new AI penetration testing module.
Starting point is 00:00:42 It finds, exploits, and proves real vulnerabilities the way a human tester would at a fraction of the time and cost of a traditional engagement. The launch responds to a rapidly closing window between disclosure and exploitation. Frontier AI systems built for security research, including Anthropics' Claude Mythus and OpenAIs Ardvarg, can now discover and weaponize software flaws with little to no human involvement. Anthropics' own research team recently used a similarly capable system to uncover more than 500 previously unknown high severity vulnerabilities in widely used open source software, flaws that had gone undetected for years. Independent research tracking more than 83,000 CVEs, compiled by zero-day clock, found that the typical gap between a vulnerability's disclosure and its first exploit has fallen from roughly two years in 2018 to a matter of hours today. Separately, Vulnerability
Starting point is 00:01:34 intelligence firm Volncheck reports that more than a quarter of exploited flaws are now weaponized within 24 hours of going public. That leaves most security teams badly outpaced. The typical enterprise still runs a formal penetration test once or twice a year and takes a median of 43 days to remediate what that test finds. Between engagements and while a finding works its way through the fix queue, applications sit exposed to exactly the kind of fast-moving, AI-assisted attackers described above. AI point closes that gap. Purpose-built agents map and organization's live attack surface across apps and APIs, build a threat model, and craft real exploits, the same way an attacker would, then run them against the live application. Attack surface discovery and authentication run on Bright's
Starting point is 00:02:20 proven, deterministic DAST engine rather than AI guesswork, the same engine behind Brights dynamic testing and star harness modules, so what AI point finds reflect show the application actually behaves. Greater than, since the advent of solutions like Mythus and Ardvark came on the scene, greater than many of our customers and partners have been very concerned about their greater than ability to protect their AISDLC. We continuously strive to offer these greater than customers the most up-to-date solutions. With the release of the AI Point module, greater than we continue to build on the Star solution we launched in 2025 and enable greater than organizations to leverage AI where it matters, both early and late in the
Starting point is 00:03:00 greater than SDLC, while relying on our industry leading dynamic engine to deliver greater than validated results at a fraction of the cost of AI-only solutions, manual greater than pen-testing still has its place. It just wasn't built to run at the speed of greater than AI-assisted development. AI point lets teams test every release, not just the greater than one's they can schedule a tester for, said Gotti Bashwitz, CEO of Bright Security. We built the AI pen testing on top of our existing discovery, greater than authentication, and centralized management platform. This enables the greater than much-needed reduction in time to detect vulnerabilities in the AI era, while greater than delivering greater predictability and significantly lower costs than
Starting point is 00:03:42 pure AI greater than pen-testing approaches, said Tom, VP product at Bright security. Bright's eye pen testing advantage, continuous coverage. Every release gets tested, not just the one or two a year a scheduled tester allows. Deterministic discovery and authentication. I-point runs attack surface discovery and authentication on Bright's proven DAST engine instead of AI guesswork, the same accuracy advantage behind Bright's other modules. Flexible engagement depth, black box and gray box testing matched to what you'd give a human tester. Autonomous or human in the loop, run it fully automated or gate exploit steps for review. Built into the platform, findings live alongside Star harness and dynamic testing in one system of record,
Starting point is 00:04:26 ready for SOC2, GDPR, and ISO-27,01 audits. Availability and pricing AIPT is available now as part of the Bright Security Platform. Continuous, validated coverage comes at a fraction of what traditional Pentest firms charge. Security teams at multiple global top 10 insurance and financial institutions already run on Bright's platform. Want to see it find and prove a real vulnerability, live? Book a 30-minute demote BrightSec.com product, book a demo, or learn more about AIPT at BrightSec. Com, IPT. About Bright Security, Bright Security, BrightSec. Com is an AI native application security company. It helps enterprises find and fix real vulnerabilities in their applications and AP as early
Starting point is 00:05:14 in the development lifecycle. The platform pairs Agentic AI with an industry leading dynamic testing engine to deliver automated testing, auto remediation, and AI-driven penetration testing at enterprise scale, without the false positives and manual grind of legacy AppSecTools. Bright Security ISOSO 27,701 and ISO 27,701 certified AICPA Society. society compliant and GDPR ready. The company is headquartered in California. Contact C. Moel Dror Bright Security Inseal. Drore at Brightsec.com. This story was published as a press release by Cyber Newswire under Hackernoon Business Blogging Program. Thank you for listening to this Hackernoon story, read by artificial intelligence. Visit hackernoon.com to read, write, learn and publish.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.