# AI Hackers Are Faster Than Your Pen Test — Eli Cohen, Snyk

## Executive summary

The rapid increase in code generation, particularly through LLMs (with 62% of output being insecure), has created a massive security backlog. Traditional security methods—Static Analysis (SAST), Dynamic Analysis (DAST), and periodic human pen testing—are insufficient to keep pace with AI-powered attackers who can chain vulnerabilities and breach systems in minutes. The solution proposed is Continuous Offensive Security, utilizing a multi-agent system (Agent Red Teaming) that runs vulnerability assessments on every Pull Request (PR) or code delta, ensuring that testing is continuous, scalable, and deeply informed by application context.

## Key takeaways

- The Security Crisis: Speed and Volume: The volume of code being generated is increasing dramatically (218% more lines of code per developer). Simultaneously, AI attackers are leveraging frontier models to chain low-severity vulnerabilities into critical ones, with the average time for a successful AI attack being 24-34 minutes, and the fastest recorded time being 4 minutes.
- Limitations of Traditional Testing: SAST misses runtime issues (e.g., authorization bugs). DAST is limited by predefined payloads and struggles with business logic. Human pen testing, while the 'golden standard' for business logic, is prohibitively expensive and slow, typically only occurring once or twice a year.
- Continuous Offensive Security Paradigm: Security must shift to continuous offensive security, running AI pen testing on every code change (PR/delta). This approach is necessary because the velocity of code change and attack is now 24/7.
- The Multi-Agent Architecture: The proposed solution uses a series of specialized agents: an Orchestrator (the brain) manages the plan; a Recon agent collects data (APIs, endpoints); Vulnerability-hunting agents identify flaws; a Judge agent validates if the vulnerability is truly exploitable (reducing false positives); and Remediation/Reporting agents make findings actionable.

## Technical details

- Static Application Security Testing (SAST): Scans code for known issues (e.g., SQL injection, XSS) but cannot detect runtime issues or configuration flaws.
- Dynamic Application Security Testing (DAST): Tests the application at runtime using predefined payloads to find vulnerabilities like Broken Object Level Authorization (BOLA).
- Agent Red Teaming: A multi-step attack simulation that combines dynamic testing with advanced techniques to identify authorization issues and data exfiltration risks.
- AI Pen Testing Workflow: The process is guided by context, integrating data from SAST, DAST, and other scanners. The core agents include the Orchestrator, Recon, Vulnerability Hunters, the Judge (for exploit validation), and Remediation agents.

## Practical implications

- Security teams must adopt continuous, automated offensive security testing that runs on every code change (PR).
- When evaluating vendors, prioritize solutions that reason about application context and integrate data from multiple scanning sources (SAST, DAST, etc.).
- The most critical feature is the ability to prove exploitability, moving beyond simple bug flagging to reduce false positives.

## Topics

AI Security, DevSecOps, Continuous Integration (CI), Offensive Security, LLM Vulnerability Assessment, Snyk Evo, Snyk

Source: https://www.youtube.com/watch?v=f3o0-9Dlw3E
