{"id":9340,"date":"2026-09-08T14:41:21","date_gmt":"2026-09-08T14:41:21","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9340"},"modified":"2026-09-08T14:41:21","modified_gmt":"2026-09-08T14:41:21","slug":"reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9340","title":{"rendered":"Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\"><strong>Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation.\u00a0<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.<\/p>\n<p class=\"wp-block-paragraph\">A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWebsites change every week and get pentested once or twice a year. That gap is where exposure builds up,\u201d said Idan Cohen, CEO and co-founder of Reflectiz. \u201cTeams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><strong>While others start every test blind, Reflectiz already knows the website.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. The pentesting agents add the attacker\u2019s perspective to that same model.<\/p>\n<p class=\"wp-block-paragraph\">A finding does not arrive as a line item. It arrives with the script involved, the data it can reach, and whether real users are exposed right now, allowing teams to skip the investigation and go straight to the fix.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe hard part of web pentesting was never the payload. It was understanding what the application actually does,\u201d said Ysrael Gurt, CTO and co-founder of Reflectiz. \u201cOur engine has been reading live websites for years, so our agents start with a map of the site that other tools never build.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><strong>A team of specialized agents, not another scanner<\/strong><\/p>\n<p class=\"wp-block-paragraph\">The agentic pentesting runs as a coordinated team of AI agents, each with a defined role:<\/p>\n<p>One agent crawls the site the way a real user does, through logins, one-time codes, and 2FA, mapping what is actually there.<\/p>\n<p>A second fingerprints the stack and works out which attacks apply where.<\/p>\n<p>A third runs those attacks and chains what it finds.<\/p>\n<p>The fourth matters most: an independent validator reproduces every finding before it reaches the report. False positives are removed by design.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The result:<\/strong> findings with reproduction steps and evidence, plus a coverage map of what was tested and cleared.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Testing spans the full <a href=\"https:\/\/www.reflectiz.com\/blog\/owasp-top-ten-2026\/\">OWASP Top 10<\/a>, and teams set depth per flow, from fast predefined checks to expert-level attack chains on critical assets.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><strong>Completing the 360\u00b0 map of web risk<\/strong><\/p>\n<p class=\"wp-block-paragraph\">The agentic pentesting, part of the new Offensive Hub, joins Security Hub and Privacy Hub on the Reflectiz platform, completing a 360\u00b0 map of web risk: what runs on the website, what data it touches, and how it can be attacked.<\/p>\n<p><strong>One exposure picture.<\/strong> Findings from all three hubs cross-reference automatically, no dashboards reconciled by hand.<\/p>\n<p><strong>Guided fixes.<\/strong> Atlas, the Reflectiz AI remediation agent, explains each risk and walks the team through the fix.<\/p>\n<p><strong>Existing workflows.<\/strong> Results route into current operations through a REST API, CI\/CD triggers, and Slack alerts.<\/p>\n<p class=\"wp-block-paragraph\"><strong>See it live<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the agentic pentesting in a live webinar on September 15 at 11 AM ET \/ 6 PM CET.<\/p>\n<p class=\"wp-block-paragraph\">Registration: <a href=\"https:\/\/www.reflectiz.com\/lp\/founders-case-study-webinar\/\">https:\/\/www.reflectiz.com\/lp\/founders-case-study-webinar\/<\/a><\/p>\n<p class=\"wp-block-paragraph\">Product information: <a href=\"https:\/\/www.reflectiz.com\/offensive-hub\/\">Reflectiz Offensive Hub<\/a> | <a href=\"https:\/\/www.youtube.com\/watch?v=Vn2W2RxSnSo\">Walkthrough Video<\/a><\/p>\n<div class=\"extendedBlock-wrapper block-coreImage undefined\"><button class=\"lightbox-trigger\">\n<p>\t\t\t<\/p><\/button>\n<p class=\"imageCredit\">CyberNews Wire<\/p>\n<\/div>\n<p class=\"wp-block-paragraph\">\n<\/p><p class=\"wp-block-paragraph\"><strong>Reflectiz<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Reflectiz is the continuous web exposure management company. Its agentless, outside-in platform monitors, tests, and secures the entire web layer, from third-party scripts and web privacy risk to agentic penetration testing of the live site. Reflectiz helps enterprises in retail, finance, travel, insurance, healthcare, and gaming meet PCI DSS, DORA, NIS2, and global privacy requirements without touching a line of code. Learn more at <a href=\"https:\/\/www.reflectiz.com\/\">https:\/\/www.reflectiz.com<\/a>.<\/p>\n<h5 class=\"wp-block-heading\"><strong>Contact<\/strong><\/h5>\n<p class=\"wp-block-paragraph\"><strong>Marketing Manager<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>Oran Frenkel<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>Reflectiz<\/strong><\/p>\n<p class=\"wp-block-paragraph\"><strong>oran.f@reflectiz.com<\/strong><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation.\u00a0 Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9330,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9340","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9340"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9340"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9340\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9330"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9340"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9340"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}