Bright Security Expands AI SDLC Security Platform with AI PT Module

Bright Security Expands its AI SDLC security Platform & Launches an AI PT Module
🕧 8 min

Bright Security(opens in new tab) Expands AI SDLC Security Platform, Launches AI PT: AI-Powered Penetration Testing That Cuts Weeks Down to Hours.

As AI compresses the gap between vulnerability disclosure and exploitation to nearly zero, the new AI Pentesting Module gives security teams continuous, AI-driven penetration testing built on Bright’s proven dynamic testing engine, at a fraction of traditional cost.

Bright Security, the AI-native application security company, today announced AI PT, its new AI penetration testing module. It finds, exploits, and proves real vulnerabilities the way a human tester would, at a fraction of the time and cost of a traditional engagement.

The launch responds to a rapidly closing window between disclosure and exploitation. Frontier AI systems built for security research, including Anthropic’s Claude Mythos and OpenAI’s Aardvark, can now discover and weaponize software flaws with little to no human involvement. Anthropic’s own research team recently used a similarly capable system to uncover more than 500 previously unknown high-severity vulnerabilities in widely used open-source software, flaws that had gone undetected for years. Independent research tracking more than 83,000 CVEs, compiled by Zero Day Clock, found that the typical gap between a vulnerability’s disclosure and its first exploit has fallen from roughly two years in 2018 to a matter of hours today. Separately, vulnerability-intelligence firm VulnCheck reports that more than a quarter of exploited flaws are now weaponized within 24 hours of going public.

Also Read: IT Tech Pulse Exclusive Interview with Michael Cucchi Chief Product and Marketing Officer at Hydrolix

That leaves most security teams badly outpaced. The typical enterprise still runs a formal penetration test once or twice a year and takes a median of 43 days to remediate what that test finds. Between engagements, and while a finding works its way through the fix queue, applications sit exposed to exactly the kind of fast-moving, AI-assisted attackers described above.

AI PT closes that gap. Purpose-built agents map an organization’s live attack surface across apps and APIs, build a threat model, and craft real exploits, the same way an attacker would, then run them against the live application. Attack-surface discovery and authentication run on Bright’s proven, deterministic DAST engine rather than AI guesswork, the same engine behind Bright’s Dynamic Testing and STAR Harness modules, so what AI PT finds reflects how the application actually behaves.

“Since the advent of solutions like Mythos and Aardvark came on the scene, many of our customers and partners have been very concerned about their ability to protect their AI SDLC. We continuously strive to offer these customers the most up to date solutions. With the release of the AI PT module, we continue to build on the STAR solution we launched in 2025 and enable organizations to leverage AI where it matters, both early and late in the SDLC, while relying on our industry-leading dynamic engine to deliver validated results at a fraction of the cost of AI-only solutions, Manual pentesting still has its place. It just wasn’t built to run at the speed of AI-assisted development. AI PT lets teams test every release, not just the ones they can schedule a tester for,” said Gadi Bashvitz, CEO of Bright Security.

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

“We built AI Pentesting on top of our existing discovery, authentication, and centralized management platform. This enables the much-needed reduction in time to detect vulnerabilities in the AI era, while delivering greater predictability and significantly lower costs than pure AI pentesting approaches,” said Tom(opens in new tab), VP Product at Bright Security.

Bright’s AI Pentesting advantage:

  • Continuous coverage. Every release gets tested, not just the one or two a year a scheduled tester allows.
  • Deterministic discovery and authentication. AI PT runs attack-surface discovery and authentication on Bright’s proven DAST engine instead of AI guesswork, the same accuracy advantage behind Bright’s other modules.
  • Flexible engagement depth. Black box and grey box testing, matched to what you’d give a human tester.
  • Autonomous or human in the loop. Run it fully automated, or gate exploit steps for review.
  • Built into the platform. Findings live alongside STAR Harness and Dynamic Testing in one system of record, ready for SOC 2, GDPR, and ISO 27001 audits.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

  • GlobeNewswire, a trusted channel for companies announcing financial results, regulatory filings, and market-moving updates. Its platform bridges organizations with investors, journalists, and audiences worldwide, ensuring corporate news is delivered with both credibility and reach.

Recommended Reads :