The New AI-Enabled Offense Against Machine-Speed Adversaries
Tim Nordvedt, Senior Manager of North America Solutions Architecture at Synack, breaks down how frontier AI models are compressing the window between vulnerability and exploit, and gives you a framework for telling real agentic pentesting capability apart from repackaged automation.
Recorded live at BrightTALK's Enterprise AI Security and Governance Summit, Track: AI Security Operations and Threat Intelligence.
The Access Curve Collapsed, Not the Threat
The vulnerabilities in your environment haven't changed. What changed is how many people, and now how many machines, can reach and exploit them, and how fast.
Proven Is the New Constraint
Mythos flagged 6,202 high/critical findings. Only 75, about 1.2%, were ever patched. Finding stopped being the hard part; proving what's real and worth a change window is.
The Harness Beats the Model
Orchestration, guardrails, and human validation determine whether AI pentesting results can be trusted, not which frontier model a vendor has access to.
Discovery volume is rising, remediation windows are shrinking, and most of the attack surface still isn't tested at all.
48,185 CVEs were published in 2025, up over 20% year over year, before frontier models entered the picture. CISA's Binding Operational Directive 26-04 now requires fixes in as little as three days for the most severe, known-exploitable findings, a bar CISA expects the private sector to adopt within 12 to 18 months. Meanwhile, the average organization tests just 32% of its attack surface in a given year, leaving 68% completely unexamined. You can't hire your way out of that gap. Whatever you build or buy to close it will need a validation layer you can actually trust.
Watch On-Demand
Continue Exploring AI Pentesting and Risk Validation
See how Synack combines Sara AI Pentesting with the Synack Red Team to turn AI-scale findings into proof you can act on.
See Sara AI Pentesting in Action
Explore how Synack combines AI-driven reconnaissance and validation with human expertise to uncover real exploitable risk.
See Sara AI →Start a Free Sara AI Pentesting Trial
Run a real AI-powered pentest on an approved target and validate exploitable risk faster.
Start free trial →Why Continuous Security Validation Matters
Learn why leading organizations are moving beyond traditional pentesting toward continuous validation models.
Read the blog →AI-Enabled Offense, Proof, and the Harness FAQ
What did Tim Nordvedt cover in this session?+
Tim Nordvedt, Senior Manager of North America Solutions Architecture at Synack, covered three things: how frontier AI models have changed the threat landscape, what that means for organizational risk, and a practical framework for telling real agentic pentesting capability apart from repackaged automation.
Has AI really changed the threat landscape, or just the access to it?+
The vulnerabilities themselves haven't changed, the access curve to exploiting them has collapsed. The same pattern played out in 2004 when Metasploit put professional-grade exploits in reach of anyone; frontier models like Anthropic's Mythos and OpenAI's GPT-5.6 Cyber are repeating that shift at a much faster pace.
Why did only 75 of the 6,202 vulnerabilities Mythos found actually get patched?+
Of 6,202 high/critical findings, 1,752 were sent to independent reviewers, 62.4% were confirmed genuine, and only 75 were ultimately patched, about 1.2% of the total. The bottleneck wasn't remediation capacity, it was proof: teams could only act on findings they could independently validate and stand behind.
Why does "the harness" matter more than the model?+
Benchmark results show orchestration, decomposition, retries, and cross-checking drive performance more than the underlying model. Microsoft's 100+ agent MDash system beat a solo frontier model on the CyberGym benchmark using the same class of models deployed differently, evidence that a vendor's engagement methodology matters more than which model they license.
What accuracy and guardrail standards do security leaders expect from AI-driven testing?+
In Synack and Omdia's State of Agentic AI Pentest survey, security leaders set roughly an 85% accuracy bar. 93% said guardrails are critical or important, 58% require transparent, explainable AI decision-making, and 54% require industry certifications as standard.
How does CISA's Binding Operational Directive 26-04 affect remediation timelines?+
BOD 26-04, issued in June, replaces a flat remediation deadline with a five-tier risk model for federal civilian agencies, requiring fixes in as little as three days for known-exploitable, fully automated, total-system-control vulnerabilities. CISA explicitly encourages private-sector adoption, so this bar is likely to show up in audits, cyber insurance, and customer requirements within 12-18 months.
How does Synack combine AI with human researchers?+
Synack's approach pairs SARA (Synack Autonomous Threat Agent) for machine-speed recon, asset enumeration, and known-pattern detection with the 1,500+ researcher Synack Red Team for horizontal chaining, business-logic attacks, and judgment calls on ambiguous findings, an agent-led model with human oversight rather than either side working alone.
No video selected
Select a video type in the sidebar.