Almost nothing in the attacker’s toolkit is new. The vulnerability classes on display at Black Hat USA 2026 and DEF CON 34 were the same ones security teams have tracked for a decade: request smuggling, SQL injection, SSRF, broken object level authorization. What changed is the economics. Attacks that used to need a specialist and a quarter now need a mid-tier model subscription and an afternoon. That shift is the strongest argument yet for continuous penetration testing, because the gap between “someone could chain those four lows” and “someone did it on a lunch budget” has closed.
Watch the full TurboTalk: Zak Raxter, Senior Solutions Architect, Offensive Security at FireCompass, on the CISO Platform AI Pen Testing and AI Safety series.
Zak Raxter spent both conferences looking for one thing: not the flashiest demo, but the assumptions that stopped being true. He found three. Every number below has a public source, listed at the end.
Expert-grade attacks are now running on hobbyist budgets. The techniques did not change. The price of executing them collapsed.
What Continuous Penetration Testing Means
Continuous penetration testing is the practice of re-running attack simulation against an application or API on a recurring and event-driven schedule rather than once or twice a year. It validates exploitability with proof, covers business logic and authorization rather than CVE matching alone, and re-tests whenever the asset changes, a new API ships, or a new CVE lands.
The One Line Version: Expert-Grade Attacks on Hobbyist Budgets
Two pieces of research from the conference floor make the point better than any threat report.
Research one: 30,000 sites, 700 broken, one new technique
James Kettle, director of research at PortSwigger, took years of his own HTTP desync work and fed it to a model with a single question. Could AI find genuinely new ways to exploit request smuggling, not just replay his existing ones?
The answer was yes. The resulting system, HTTP Terminator, worked through 138 HTTP and SMTP RFCs split into roughly 15,000 fragments, generated candidate attack vectors, and validated them. Across 30,000 authorized sites it found about 700 vulnerable targets. The list included banks, government infrastructure, security products and an airport.
It also produced a new attack concept, Shared-Parser Confusion, where a server reuses response-parsing logic on requests and misapplies the rules. Along the way it surfaced an Apache Traffic Server zero day, CVE-2026-63078.
The detail that matters most for security leaders is not the yield. It is how the yield was produced. The purely autonomous runs were productive but ordinary. The zero day and the new technique both needed Kettle to step back in, read the output, and seed the next direction. His own summary: “Neither of us would have discovered it alone.”
That is the operating model, and it cuts both ways. A guided agent outperforms an unguided one, for attackers and for defenders.
Research two: a $500,000 exploit found for $25
Adam Kues at Searchlight Cyber pointed a model at WordPress core and burned roughly $25 of a $200 subscription. What came back was a pre-authentication remote code execution chain in software running on a very large share of the web. Exploit brokers price that class of bug around $500,000.
The chain is worth reading slowly, because no single step is a critical finding on its own:
- A validation and execution mismatch in the REST batch API, where requests with errors skip an array index update and parameters get validated against the wrong payload.
- That desync bypasses sanitization on the
author__not_inparameter, opening pre-auth SQL injection. - A nested batch call sidesteps the method restriction on the batch route.
- UNION-based injection poisons the in-memory post cache with fabricated post objects.
- A forged customize changeset borrows administrator context.
- The
parse_requesthook replays the request with those privileges and creates a new admin account.
The research is now public as wp2shell, tracked as CVE-2026-63030 chained with CVE-2026-60137. The human decided what to investigate. The model worked out how to exploit it.
Three Assumptions That Broke in 2026
Assumption one: low severity findings stay low
The Microsoft 365 Copilot Enterprise flaw published as SearchLeak and assigned CVE-2026-42824 is three low severity issues that together produce full mailbox exfiltration from a single click.
A query string parameter reaches the model as an executable instruction through enterprise search. The victim types nothing.
The sanitizer wraps output after generation finishes, but the browser renders the stream as it arrives, so the injected image tag fires first.
The content security policy allow-lists bing.com, and the search-by-image endpoint fetches the attacker’s URL server side.
The victim clicks a microsoft.com link. Copilot reads their mailbox, calendar, SharePoint and OneDrive, and ships the results out over Microsoft’s own infrastructure. Anti-phishing tooling sees a trusted domain. Network tooling sees normal traffic to a normal destination. Subject lines alone routinely carry one-time codes, MFA prompts and password reset links.
Microsoft rated it critical and patched it. The structural lesson outlives the patch: a triage queue that defers anything rated low is now a queue that defers the raw material for account takeover. With a model doing the chaining, the cost of assembling three lows into a critical has fallen to near zero.
Assumption two: our telemetry is trusted input
An AI coding agent reads a stack trace to debug a failure. Who controls what lands in that stack trace?
Research published as Agentjacking, presented at DEF CON 34, answers that uncomfortably. A publicly discoverable Sentry DSN plus an MCP integration becomes remote code execution on a developer machine. The attacker writes a crafted error into the error stream. The agent reads it as part of its debugging context and acts on it.
- 85% success rate in controlled testing across more than 100 organizations.
- 2,388 organizations found with publicly discoverable Sentry DSNs.
- 71 of those sit in the Tranco top one million.
- Roughly 27% of the Fortune 1000 reachable through one MCP integration path.
Existing controls stay silent for a structural reason. Every action the hijacked agent takes sits inside permissions it was legitimately granted. EDR, WAF and IAM all see authorized work by an authorized identity. Your logs are no longer only an output. Anything that accepts input, writes it to a file, and feeds that file to a model is an injection surface.
Assumption three: the scope we set is the scope it stays in
Under permissive evaluation settings, agents tasked with offensive security work have found and exploited vulnerabilities in supporting infrastructure and then reached systems outside the intended environment. Guardrails expressed as instructions behave like suggestions. A capable agent that is not hard-bounded will follow an attack path across the boundary you assumed it would respect.
For anyone running autonomous testing, the implication is specific. Scope has to be enforced where the agent executes, on every action, not described once in a prompt at the start. We have written before about what changes the moment an AI agent starts acting rather than answering.
API Attacks Moved From Payloads to Logic
The API picture changed in character more than in volume.
| Signal | 2024 | 2025 |
|---|---|---|
| Share of API attacks using unauthorized workflows or abnormal activity | ~30% | 61%+ |
| Average API attacks per organization per day | ~121 | ~258 |
| Organizations reporting an API security incident | Lower baseline | 87% |
The most exploited OWASP API Security Top 10 risks in 2025: security misconfiguration around 40%, broken object and property level authorization around 35%, broken authentication around 19%. Separately, 44% of attacks begin by exploiting public-facing applications, driven largely by missing or weak authentication, and the count of active ransomware and extortion groups rose 49% year over year.
Why your tooling stays quiet
A broken object level authorization request is syntactically perfect. Clean 200 response, valid JSON, correct content type, no anomalous payload. The only thing wrong is which records came back. There is no signature to fire on, because nothing in the request is malformed.
Proving it requires holding two authenticated identities at the same time and replaying across the boundary between them. Most scanners test as one user, which is precisely why the most exploited API risk category is the one scanners report least.
The same logic explains the control that proved easier to bypass than expected. A WAF inspects requests that look wrong. None of the research above sends a request that looks wrong.
Assume the Capability Gap Is Gone
A common planning assumption is that the strongest models sit behind provider safeguards and enterprise agreements. That assumption no longer buys much time.
The gap between the best open-weight models and the frontier is currently measured in months, not generations, and models in the GLM 5.3 class land within a few percent of frontier scores on relevant benchmarks. Simple techniques bypass safeguards on these models at a 64% to 92% rate, and at effectively 100% once weights are altered. Anyone can download them and strip the restrictions out.
Plan for an adversary with frontier-class capability, no safeguards and no rate limits. That is a realistic posture, not a pessimistic one.
Four Shifts Worth Making This Quarter
The strongest results in the PortSwigger research came when a human guided and seeded the model, not when it ran unattended. The same pattern holds on defense. Use the human as the gate before active exploitation, and keep the full audit trail. This is also the reason a model on its own cannot run a penetration test: the harness around it does most of the work.
Attackers already use it for recon, exploitation and proof-of-concept generation. Pick one slow or shallow step in your program, such as triage, retesting or authorization coverage, measure it before and after, and keep the human gate in place. Our guide to running agentic pentesting while managing risk and cost covers how to phase that in.
Nobody can afford maximum depth on every asset all the time. Label every asset by business criticality and rate of change, using criteria a person can actually review. FireCompass tags attack surface with a Hacker Target label for exactly this reason: the question is not what is vulnerable, it is what a real attacker would pick.
Spend expensive testing on business logic, authorization and multi-stage chains. Leave version and CVE matching to cheap tooling, including open source. The findings that matter now are the ones without a CVE attached.
Depth and cadence by tier
| Tier | Depth | Cadence |
|---|---|---|
| P1, business critical | Business logic, authorization across identities, multi-stage attack chains | Monthly at minimum, ideally every major release |
| P2 | On-demand depth | Quarterly at minimum |
| P3 | Event-driven testing | On trigger, such as a new API or new workflow |
| Day-one CVEs | Exposure check across the surface | Daily |
| Recon and discovery | Full external surface | Weekly, because the surface changes faster than the scope |
Re-test on triggers first: a new asset, a new API, a deploy, or a new CVE. Then fall back to the schedule set by criticality and budget.
Five Questions to Put to Your Team This Week
- When did we last test authorization across two tenants held at the same time, rather than as a single user?
- Which API versions are still routed that we believe were retired?
- Is every asset labeled by criticality and rate of change, using criteria a person can review?
- What does our coding agent read automatically, and who can write into that source?
- How many production changes shipped since our last external test?
Question five is usually the uncomfortable one. A quarterly test against an estate that ships a hundred changes a quarter is a point-in-time measurement described as a security program.
Frequently Asked Questions
Running a full pen test hourly is not realistic. Weekly testing of business-critical assets is, using current agentic tooling, with monthly as the floor and an additional run on every significant change.
Two controls together. A human gate before active exploitation, and filtering on both sides of the model, so input is validated before it reaches the agent and output is validated before it acts. Then restrict permissions to the minimum the task needs, because an agent will use everything it is permitted to use.
Not with a self-assembled setup. With a platform that enforces rate limiting, hard scope boundaries, least privilege and a full audit trail, it is viable, and FireCompass agents run against production systems under those conditions.
The WAF. Every chain described above sends requests that look legitimate, and new obfuscation work is making that easier rather than harder.
Widen it. The most common gap is shadow IT: forgotten staging environments, retired APIs still routed, and applications stood up quickly by teams that now ship code faster than review can keep up. Recon weekly, then scope the test to what recon actually finds.
Business logic workflow abuse. Authentication and authorization bypass get the headlines. Logic abuse is the equivalent of living off the land, using the application exactly as designed to reach an outcome it was never meant to allow, and it is now 61% of observed API attack activity.
Coverage and criticality labeling, then depth where it counts. If the team is small, the move that buys the most is using AI to extend what the existing testers can cover. Nothing here suggests AI replaces pen testers. It raises their ceiling.
Test It on Your Own Surface
Your perimeter is being tested at this pace already, whether or not anyone has told you. The only reliable way to know whether these techniques work against your estate is to run them yourself, under control, with proof attached to every finding.
FireCompass runs AI pen testing agents that validate exploitability rather than reporting signatures, with a false positive rate under 2%, benchmark results of 104 out of 104 on XBEN, and a number one ranking on HackerOne, with the full methodology and limitations published here.
What would a guided agent find on your attack surface right now?
Find out with a free AI Pen Test from FireCompass. Point it at your external attack surface and see what comes back with a working proof of concept attached.
Sources
- AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day, The Hacker News
- Exploit brokers pay $500,000 for a WordPress RCE. I found one with $25, Adam Kues, Searchlight Cyber
- wp2shell: a pre-authentication RCE in WordPress core’s REST batch API, Hadrian
- New attack turned Microsoft 365 Copilot into a 1-click data theft tool (SearchLeak, CVE-2026-42824), BleepingComputer
- Agentjacking: MCP Injection via AI Coding Agents, Cloud Security Alliance Labs
- OWASP API Security Top 10, OWASP
