HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

Cobalt Launches Autonomous Pentest to Deliver Continuous Offensive Security in 24 Hours

Cobalt introduced an AI‑driven Autonomous Pentest service that pairs automated exploit‑chain prediction with human expert review, delivering actionable findings within 24 hours. For SOC 2‑focused organizations, the rapid, repeatable evidence stream supports continuous compliance and audit readiness.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 helpnetsecurity.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
helpnetsecurity.com

Cobalt Launches Autonomous Pentest to Deliver Continuous Offensive Security in 24 Hours

What Happened — Cobalt announced Cobalt Autonomous Pentest, an AI‑assisted service that combines automated exploit‑chain prediction with real‑time direction from vetted human pentesters. The platform promises actionable findings (including proof‑of‑exploit) delivered to tools such as Jira, GitHub, and Slack within 24 hours, enabling “continuous offensive security” across an organization’s entire application portfolio.

Why It Matters for Compliance & Audit Readiness

  • Continuous, automated testing aligns with SOC 2 CC3.1 (Risk Management) by providing ongoing evidence that application security controls are being exercised, not just a point‑in‑time assessment.
  • Human‑in‑the‑loop results generate audit‑ready artifacts (test plans, findings, remediation tickets) that can be attached to your control‑testing evidence repository.
  • Faster test cycles help maintain the “least‑privilege” and “change management” principles required for the SOC 2 Security and Availability criteria, reducing the window of exposure between code release and validation.

Who Is Affected — Primarily technology‑focused enterprises (SaaS, cloud‑native platforms, fintech, health‑tech) that ship software on rapid release cadences and must demonstrate robust application‑security controls for SOC 2 audits.

Recommended Actions

  • Map the Autonomous Pentest deliverables to your SOC 2 Application Security (CC3.1) and Change Management (CC6.1) controls.
  • Integrate the findings feed into your GRC or evidence‑collection tool to create a continuous audit trail.
  • Validate that the human‑review component satisfies the “expert direction” requirement of SOC 2’s risk‑assessment policies. Source: Help Net Security

Technical Notes

  • The service leverages a model‑agnostic AI engine trained on 13 years of exploit data and 10 k+ high‑severity findings.
  • Human pentesters review AI‑generated attack chains, enforce scope discipline, and provide reproducible proof‑of‑exploit.
  • Findings are exported via APIs to over 50 integrations (Jira, GitHub, Slack, etc.). Source: same as above
📰 Original Source
https://www.helpnetsecurity.com/2026/07/23/cobalt-adds-autonomous-pentest-to-scale-application-security-testing/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →