{"id":2626,"date":"2026-06-16T01:21:21","date_gmt":"2026-06-16T08:21:21","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=2626"},"modified":"2026-06-16T04:15:34","modified_gmt":"2026-06-16T11:15:34","slug":"new-continuous-ai-pentesting","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/","title":{"rendered":"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding"},"content":{"rendered":"\n<p>Over the past months, I\u2019ve noticed a shift in customer conversations. Coverage, prioritization, emerging threats \u2014 those questions have given way to exposed MCP servers, unmanaged AI chatbots, and risks that don\u2019t show up as CVEs. Mythos comes up in every other call.<\/p>\n\n\n\n<p>The calculus changed. AI now writes a quarter of production code, with twice as many vulnerabilities. The exploitation window collapsed from days to hours. And while everyone\u2019s talking about Mythos, the models already in use can find zero-days for a few hundred dollars in tokens.<\/p>\n\n\n\n<p>At CyCognito we\u2019ve been building for this on two fronts:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Expanding AI asset coverage: <\/strong>building on <a href=\"https:\/\/www.cycognito.com\/blog\/introducing-discovery-of-externally-reachable-mcp-services\">our MCP server discovery release<\/a>, the platform now detects much more of the AI stack, including n8n, Ollama, MLflow, PyTorch, Triton, and more. That\u2019s 60+ detection models in production, and growing.<\/li>\n\n\n\n<li><strong>Continuous AI pentesting: <\/strong>a new capability that simulates an AI-powered attacker, which I\u2019m going to introduce to you in this post.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Field-tested. Receipts upfront.<\/strong><\/h2>\n\n\n\n<p>The best way to get a feel for our new AI pentesting capabilities is to look at what they\u2019ve already uncovered. The examples I picked here cover different asset types and techniques, but they share a common theme: risk that no CVE scan would surface, specific to the environment and the business.<\/p>\n\n\n\n<p>Here goes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. All CRM records, in the open<\/h3>\n\n\n\n<p>A large enterprise had an externally reachable MCP server exposing an unauthenticated natural-language interface to its production environment.<\/p>\n\n\n\n<p>Simulated prompt-injection drew verbose error responses, and those disclosed internal details about the backend. These surfaced the CRM behind the server and the calls needed to reach it.<\/p>\n\n\n\n<p>From there, several million rows of account, opportunity, and per-item financial data were queryable through a handful of HTTP POST requests. No credentials required.<\/p>\n\n\n\n<p>From an exposure management point of view, this is a reminder of the risk an exposed MCP server can pose. Depending on how it was set up, it can act as a privileged path into a critical backend system, often deployed outside security workflows and without sufficient authentication.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Sensitive data behind an exposed RAG index<\/h3>\n\n\n\n<p>One organization had a CrewAI agent stack on the public internet. A security layer was added, but authentication was enforced only on the agent API itself, not on the knowledge base it was reading from. As a result, the store holding the agent\u2019s source documents was readable through anonymous requests.<\/p>\n\n\n\n<p>This exposed the RAG index, which holds whatever an organization feeds the agent to draw on: customer data, internal communications, contracts, and operational knowledge. Anything the agent needs to do its job, all of it accessible to anyone with an internet connection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Easy access to a building\u2019s security system<\/h3>\n\n\n\n<p>At another organization, a physical security system controlling door locks, card readers, and CCTV was discovered on the public internet.<\/p>\n\n\n\n<p>The system was deployed alongside the organization\u2019s AI document analysis tools and customer-facing chatbot, on the same surface and with the same lack of segmentation.<\/p>\n\n\n\n<p>The review processes that missed the AI deployments also missed the physical access system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How it works<\/strong><\/h2>\n\n\n\n<p>I think the examples above paint a pretty clear picture. Findings like these don\u2019t come from CVE scanning. They require security experts (in this case agents), skilled enough to spot overlooked weaknesses and execute multi-step tests, applying reasoning and deep context.<\/p>\n\n\n\n<p>Take the exposed CRM example above. The first step was to fingerprint an exposed MCP server and associate it with the organization. The next was to enumerate the tool catalog, which revealed the tools were wired to the MCP server. From there, a sequence of natural-language calls walked the data model and pulled the full dataset, validating the data exposure and the missing authentication.<\/p>\n\n\n\n<p>To execute an attack chain like this you need to know which threads to pull, and know what those threads could be running through.<\/p>\n\n\n\n<p>The AI pentesters we built allow us to do just that: at scale, with speed and across multiple environments in parallel.<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a313a1734595&quot;}\" data-wp-interactive=\"core\/image\" class=\"wp-block-image size-large wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"803\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on-async--click=\"actions.showLightbox\" data-wp-on-async--load=\"callbacks.setButtonStyles\" data-wp-on-async-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-1280x803.png\" alt=\"\" class=\"wp-image-2637\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-1280x803.png 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-512x321.png 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-768x482.png 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png 1480w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge image\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on-async--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\"><em> Continuous AI Pentesting: Solution architecture, at a glance.<\/em> <em>[Click to expand]<\/em><\/figcaption><\/figure>\n\n\n\n<p>Let me walk you through how it works.<\/p>\n\n\n\n<p>It starts with expertise. For eight years, our team has uncovered weaknesses in some of the most complex enterprise environments. Manufacturers with intertwined physical and digital footprints. Multinationals acquiring more companies than IT can track. Fortune 500s a century old, with the IT debt to show for it.<\/p>\n\n\n\n<p>We learned a lot, and that knowledge has been gradually baked into our platform, in its three core modules:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Exposure Assessment<\/strong>, which maps the external footprint, attributes every asset to the right part of the organization, and enriches it with business and stack context.<\/li>\n\n\n\n<li><strong>Exposure Validation<\/strong>, which runs 100,000+ deterministic tests continuously, leaving AI pentesters free to focus on high-judgment work.<\/li>\n\n\n\n<li><strong>Threat Intelligence<\/strong>, which taps into the history of existing and emerging vulnerabilities, as well as playbooks and statistical models, trained on past engagements to understand and predict attacker activities.<\/li>\n<\/ul>\n\n\n\n<p>All three now become the foundational layer for continuous AI pentesting, producing inputs that feed into the <strong>Target Graph\u2122<\/strong>: a contextual orchestration layer that constantly reevaluates the threat matrix and the exposed surface.<\/p>\n\n\n\n<p>The Target Graph\u2122 is the X-factor that puts the context and know-how to work. Playing the orchestrator role, it informs where AI pentesting should run, at what depth, and with which techniques, improving the efficiency of each run and the quality of the findings.<\/p>\n\n\n\n<p>More importantly, by driving these decisions, the Target Graph\u2122 makes it possible to run continuously across the full surface.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Minding the 99% gap<\/h2>\n\n\n\n<p>Continuous coverage matters because it addresses one of the biggest challenges with pentesting today. Manual testing is point-in-time by design, and now we\u2019re seeing AI testing delivered the same way, as an on-demand service. This leaves the fundamental advantages of automation on the table: ramping up speed, but doing nothing for scale.<\/p>\n\n\n\n<p>The issue there comes down to economics: the high token cost forces vendors and customers to apply AI testers selectively, typically only on the top 1% of priority assets. Meanwhile, as the examples above show, plenty of critical risks live outside the main applications, in the 99% that gets ignored.<\/p>\n\n\n\n<p>The Target Graph\u2122 is how we change this dynamic. By drawing on the contextual layout of the surface, and accounting for what deterministic validation already found, we enable AI pentesting to work efficiently and continuously, flexibly shifting test depth and techniques, dramatically increasing the cadence and scope of coverage.<\/p>\n\n\n\n<p>Moreover, the same stream of exposure data also keeps the system current, providing the fresh inputs it needs to stay responsive to asset and surface-level changes, emerging threats, and signals from attacker activity in the wild.<\/p>\n\n\n\n<p>And as effective as this sounds (and it is), it gets much better because the whole model is also built to be self-improving. The how is simple. Every new validated attack chain, surfaced by AI, gets codified into new deterministic tests. In turn, each new deterministic test we introduce frees AI capacity in future runs.<\/p>\n\n\n\n<p>The pipeline already runs specialized agents for every type of exposed asset CyCognito covers: web applications and APIs, AI and LLM endpoints, cloud, VPNs, OT\/IT systems, etc. Each producing valuable findings with full evidence, working always-on, across the full external surface.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What\u2019s next<\/strong><\/h2>\n\n\n\n<p>The work is moving fast, out of the lab and in real environments. This is the part that energizes me the most: the response when we put this new capability in front of our customers. The interest was immediate, and the organizations raising their hands to join us as design partners are names many of you would know.<\/p>\n\n\n\n<p>Internally we are codenaming this \u2018Project <strong>Kineto\u2019<\/strong>, after the Kinetograph, the first motion picture camera that gave the world cinema, turning still snapshots into continuous motion.&nbsp;<\/p>\n\n\n\n<p>This echoes our vision for AI pentesting: moving from a still snapshot to a dynamic picture, running continuously across your attack surface.<\/p>\n\n\n\n<p>Those are all the updates I have for you today, but we plan to continue to share our progress, to keep you in lockstep with our work.<\/p>\n\n\n\n<p>To follow along, <a href=\"http:\/\/cycognito.com\/ai-pentesting-kineto\/\">join the waitlist<\/a> for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Periodic progress notes from the research team<\/li>\n\n\n\n<li>A chance to apply for the design partner program<\/li>\n\n\n\n<li>Early access before general availability<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Today we&#8217;re announcing continuous AI pentesting. It runs always-on across your full external surface, using AI agents to spot overlooked weaknesses, reason through context, and chain the multi-step moves a skilled adversary would. It has already uncovered real exposures in live environments. Here&#8217;s how it works.<\/p>\n","protected":false},"author":18,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[229,2],"tags":[],"class_list":["post-2626","post","type-post","status-publish","format-standard","hentry","category-featured","category-product"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"Today we&#039;re announcing continuous AI pentesting. It runs always-on across your full external surface, using AI agents to spot overlooked weaknesses, reason through context, and chain the multi-step moves a skilled adversary would. It has already uncovered real exposures in live environments. Here&#039;s how it works.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-16T08:21:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-16T11:15:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1480\" \/>\n\t<meta property=\"og:image:height\" content=\"928\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Rob Gurzeev\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Rob Gurzeev\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\"},\"author\":{\"name\":\"Rob Gurzeev\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d5cdeba13fde783ae5ebf80d0765b679\"},\"headline\":\"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding\",\"datePublished\":\"2026-06-16T08:21:21+00:00\",\"dateModified\":\"2026-06-16T11:15:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\"},\"wordCount\":1381,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-1280x803.png\",\"articleSection\":[\"Featured\",\"Product\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\",\"name\":\"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-1280x803.png\",\"datePublished\":\"2026-06-16T08:21:21+00:00\",\"dateModified\":\"2026-06-16T11:15:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png\",\"width\":1480,\"height\":928},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d5cdeba13fde783ae5ebf80d0765b679\",\"name\":\"Rob Gurzeev\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/188f9b5d63c82a731809f453b8cc26f8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/188f9b5d63c82a731809f453b8cc26f8?s=96&d=mm&r=g\",\"caption\":\"Rob Gurzeev\"},\"description\":\"CEO &amp; Co-Founder\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/rob-gurzeev\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/","og_locale":"en_US","og_type":"article","og_title":"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding | CyCognito Blog","og_description":"Today we're announcing continuous AI pentesting. It runs always-on across your full external surface, using AI agents to spot overlooked weaknesses, reason through context, and chain the multi-step moves a skilled adversary would. It has already uncovered real exposures in live environments. Here's how it works.","og_url":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/","og_site_name":"CyCognito Blog","article_published_time":"2026-06-16T08:21:21+00:00","article_modified_time":"2026-06-16T11:15:34+00:00","og_image":[{"width":1480,"height":928,"url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png","type":"image\/png"}],"author":"Rob Gurzeev","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Rob Gurzeev","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/"},"author":{"name":"Rob Gurzeev","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d5cdeba13fde783ae5ebf80d0765b679"},"headline":"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding","datePublished":"2026-06-16T08:21:21+00:00","dateModified":"2026-06-16T11:15:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/"},"wordCount":1381,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-1280x803.png","articleSection":["Featured","Product"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/","url":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/","name":"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture-1280x803.png","datePublished":"2026-06-16T08:21:21+00:00","dateModified":"2026-06-16T11:15:34+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#primaryimage","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/ai-pentesting-architecture.png","width":1480,"height":928},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/new-continuous-ai-pentesting\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Continuous AI Pentesting: What We\u2019re Building, and What It\u2019s Already Finding"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/d5cdeba13fde783ae5ebf80d0765b679","name":"Rob Gurzeev","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/188f9b5d63c82a731809f453b8cc26f8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/188f9b5d63c82a731809f453b8cc26f8?s=96&d=mm&r=g","caption":"Rob Gurzeev"},"description":"CEO &amp; Co-Founder","url":"https:\/\/www.cycognito.com\/blog\/author\/rob-gurzeev\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=2626"}],"version-history":[{"count":7,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2626\/revisions"}],"predecessor-version":[{"id":2642,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2626\/revisions\/2642"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=2626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=2626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=2626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}