Delivers fast, actionable pentests, with findings in 24 hours
Cobalt™, the pioneer in pentesting as a service (PTaaS) and a leader in continuous offensive security testing grounded in human expertise, today announced Cobalt Autonomous Pentest. This new offering makes continuous offensive security possible across an organization’s entire application portfolio, delivering fast, actionable pentests with findings in just 24 hours.
AI is fundamentally changing the pace of application security. AI-assisted development enables organizations to ship software faster than ever, while attackers are using AI to automate reconnaissance and accelerate exploitation. Traditional pentesting performed quarterly or even monthly, can no longer keep pace. As security teams face growing attack surfaces and constrained budgets, organizations need a more scalable approach to identifying and validating exploitable risk.
Cobalt Autonomous Pentest is fully integrated in the Cobalt Offensive Security Platform, and delivers this scale through three core capabilities:
- Expert Direction: Seasoned Cobalt pentesters direct every engagement. Pentesters review the execution plan, enforce scope discipline, and bring the creative adversary reasoning that pure-AI tools cannot replicate.
- Model Agnostic: The model-agnostic AI engine handles chain prediction, prioritization, and adaptive sequencing. Informed by 13 years of exploit data, it adapts as the frontier evolves and threat actor techniques change.
- Findings in 24 Hours: Cobalt delivers next-day findings into Jira, GitHub, Slack, and 50+ other tools. Every finding includes proof of exploit where applicable, reproduction steps, and tailored remediation guidance so teams can act immediately.
According to Omdia Research1, 94% of organizations see the importance of keeping humans in the loop for offensive security programs. Cobalt places human expertise at the center of its autonomous solution. The Cobalt Autonomous Pentest leverages the Cobalt Core, the company’s community of approximately 500 rigorously vetted pentesters.
"Meeting the demands of today's development cycles requires more than automating traditional pentesting,” said Sonali Shah, CEO, Cobalt. “It requires rethinking how offensive security is delivered. Only Cobalt unifies the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry's largest dataset of real-world pentest results. Together, these capabilities enable security teams to continuously identify, prioritize, and remediate exploitable risk at the speed of modern software development.”
The Cobalt Autonomous Pentest draws from more than 10,000 critical and high-severity findings. This powerful combination of exploit data and human expertise allows organizations to scale fast, flexible, and precise coverage across their entire attack surface. It extends coverage across the portfolio and complements human-led, comprehensive pentesting for compliance-driven engagements — the right testing model and depth for every asset.
Availability
Cobalt Autonomous Pentest debuts at Black Hat USA 2026 (booth 4903), with general availability August 2026.
Additional Resources:
- Why We Repositioned Cobalt Around Continuous Offensive Security, by Lisa Matherly, CMO, Cobalt
- Why the Industry Is Both Racing Toward Autonomous, and Pulling Back From It, by Shah
- Introducing Cobalt Autonomous Pentest: Continuous Offensive Security Across Your Entire Portfolio, by Gunter Ollmann, CTO, Cobalt
About Cobalt
Cobalt is the pioneer in pentesting as a service (PTaaS) and a leader in continuous offensive security testing grounded in human expertise. The Cobalt Offensive Security Platform spans the full spectrum of offensive security, from targeted, human-led pentesting to high-frequency, AI-driven autonomous security testing. Only Cobalt brings together the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry's largest dataset of real-world pentest results. Thousands of customers and hundreds of partners rely on Cobalt and its global network of 500+ vetted security experts to continuously identify, prioritize, and remediate exploitable risk with the speed, flexibility, and precision today's organizations require.
Cobalt maintains an outstanding NPS of 9, reflecting its dedication to customer satisfaction. Read our reviews on G2 to see why customers love us. More at https://www.cobalt.io. Follow Cobalt on LinkedIn and X.
[1] Omdia Research Survey, Next-generation Offensive Security Strategies Grant Defenders the AI Advantage, June 2026
View source version on businesswire.com: https://www.businesswire.com/news/home/20260723032666/en/
This new offering makes continuous offensive security possible across an organization’s entire application portfolio, delivering fast, actionable pentests with findings in just 24 hours.
Contacts
Media Contact
Leslie Kesselring
Kesselring Communications for Cobalt
leslie@kesscomm.com
