Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Guide urges caution before AI agents pentest live websites

A free guide published on 17 September 2026 argues autonomous testing agents can close the patch gap, but says security leaders must set conditions first.

By The Agentic Times ·

Guide urges caution before AI agents pentest live websites
· Image: thehackernews.com

A guide for chief information security officers on "agentic pentesting" for websites was published by The Hacker News on 17 September 2026. It argues that autonomous AI agents "– software that plans and carries out multi-step tasks with little human input –" can help organisations find exploitable flaws in their own web estate faster, and it sets out what security leaders should demand before pointing such an agent at a production system.

The case rests on a timing gap. According to the guide, Mandiant, part of Google Cloud, finds that attackers weaponise newly disclosed vulnerabilities in about five days. The median organisation, by contrast, takes 43 days to patch one, a figure the guide attributes to the Verizon Data Breach Investigations Report 2026. That leaves a window of several weeks in which a known flaw is both public and unfixed.

The guide also says exploitation of vulnerabilities is now "the front door" for intruders, and that it is the starting point for 31 per cent of breaches, again citing the Verizon report. On those numbers, scanning and patch cycles measured in weeks are out of step with the pace at which exploit code appears.

The pitch for agentic testing is that an agent can run continuously rather than in the annual or quarterly bursts typical of manual penetration tests, and can chain steps together in the way a human tester would. The guide is written for security leaders rather than testers, and frames the decision as a governance question as much as a technical one: what the agent is allowed to touch, what it is allowed to do when it finds something, and who is accountable for the result.

That caution matters because the target is live infrastructure. An autonomous tool that probes a production website is, by design, performing the same actions an attacker would. The guide's framing "– what leaders "must demand before pointing one at production" –" suggests the authors treat unsupervised deployment as the main risk to manage, rather than a solved problem.

The guide is free and aimed at a CISO readership. It does not, in the material reviewed, name a specific product as the recommended approach, and the underlying statistics come from third-party research rather than from testing of any agent.

Security teams considering the approach are, on the guide's own logic, weighing two exposures against each other: the risk of leaving known flaws unpatched for weeks, and the risk of handing an autonomous system permission to attack their own systems. Neither is zero. The guide's argument is that the first is now large enough to justify serious scrutiny of the second.

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html