Cobalt boosts app security with autonomous testing
Cobalt boosts app security with autonomous testing for continuous offensive security results in 24 hours using AI-assisted development.

Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours.
AI-assisted development enables organizations to ship software faster than ever, while attackers are using AI to automate reconnaissance and accelerate exploitation.
Pentesting performed quarterly or even monthly can no longer keep pace with the growing attack surfaces and constrained budgets that organizations face.
Organizations need a more scalable approach to identifying and validating exploitable risk.
Cobalt Autonomous Pentest is integrated in the Cobalt Offensive Security Platform and delivers this scale through three core capabilities: expert direction, model agnostic, and findings in 24 hours.
Expert direction is provided by seasoned Cobalt pentesters who direct every engagement, review the execution plan, enforce scope discipline, and bring creative adversary reasoning that pure-AI tools cannot replicate.
The model-agnostic AI engine handles chain prediction, prioritization, and adaptive sequencing, informed by 13 years of exploit data.
They deliver next-day findings into Jira, GitHub, Slack, and 50+ other tools, with every finding including proof of exploit where applicable, reproduction steps, and tailored remediation guidance.
Reporters note that 94% of organizations see the importance of keeping humans in the loop for offensive security programs.
Cobalt places human expertise at the center of its autonomous solution, leveraging the Cobalt Core, the company’s community of approximately 500 rigorously vetted pentesters.
In the middle of this shift towards autonomous security testing, it’s clear that the industry is looking for ways to balance the need for speed with the need for precision and expertise.
Organizations need to be able to identify and remediate vulnerabilities quickly, without sacrificing the quality of their testing.
By combining human expertise with AI-powered tools, organizations can achieve this balance and ensure that their security testing is both fast and effective, using tools like exposed ServiceNow instances detection.
“Meeting the demands of today’s development cycles requires more than automating traditional pentesting,” said Sonali Shah, CEO, Cobalt.
“It requires rethinking how offensive security is delivered.
Only Cobalt unifies the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry’s largest dataset of real-world pentest results.
The Cobalt Autonomous Pentest draws from more than 10,000 critical and high-severity findings, allowing organizations to scale fast, flexible, and precise coverage across their entire attack surface.
This combination of exploit data and human expertise enables organizations to extend coverage across their portfolio and complement human-led testing for compliance-driven engagements.


