At RSAC 2026, AI Redefines the Future of Penetration Testing
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”这样的开头。首先,我需要通读整篇文章,抓住主要观点。 文章主要讲的是AI如何改变渗透测试。渗透测试本来是模拟攻击来找漏洞,现在AI让攻击和防御策略都发生了变化。攻击面扩大了,检测和修复的时间却缩短了。Synack公司用AI驱动的代理和人类安全研究员合作,进行更高效的测试。AI负责侦察和大规模扫描,而人类则负责判断和理解上下文。 所以,总结的时候要提到AI在渗透测试中的作用、Synack的混合模型以及人机协作的重要性。还要注意字数限制,大概100字左右。 最后,确保语言简洁明了,直接描述内容,不加其他修饰。 </think> 文章探讨了人工智能(AI)对渗透测试的深远影响。随着攻击面的扩大和检测时间的缩短,AI正在改变攻击与防御策略。Synack等公司通过结合AI驱动的代理与人类安全研究员,实现了更高效、持续的渗透测试。尽管AI在侦察和规模化方面表现出色,但人类在上下文理解和创造力方面仍不可或缺。未来渗透测试将依赖于人机协作的混合模式。 2026-4-2 15:1:24 Author: securityboulevard.com(查看原文) 阅读量:10 收藏

Penetration testing is undergoing a substantial shift as AI reshapes both attack and defense strategies. At RSA Conference 2026, multiple vendors pointed to the same underlying pressure: Attack surfaces are expanding more quickly, while the time required to detect and address weaknesses is shrinking. That shift is being driven in part by the rise of AI-enabled adversaries, which can probe systems at scale and speed.

Penetration testing (pen testing) involves simulating cyberattacks on a system to identify vulnerabilities before attackers can exploit them. It goes beyond automated scans by attempting to exploit weaknesses the way a human adversary would. The rise of AI is changing both how pen testing exposes weaknesses and what can be done to address them.

One company at the forefront of this evolving cybersecurity ecosystem is Synack, which is combining AI-driven agents with a distributed network of human security researchers to move beyond traditional, point-in-time testing. Mark Kuhr, CTO of Synack, said the company is increasingly relying on autonomous agents to perform reconnaissance across environments, identifying potential attack paths before human testers step in to validate and exploit them.

“Doing good recon is extremely important,” Kuhr said. “AI can perform broad attack surface reconnaissance well, and we can build very targeted attack chains from there. It’s efficient, scalable and fast.” However, as in other areas where AI has advanced security capabilities, human oversight remains critical. “Where AI often falls short is in contextual understanding and creativity. Humans infer business logic that AI will sometimes miss.”

AI has also enhanced Synack’s approach through its ability to operate continuously. “AI can run for days with a strong memory of its own work. Humans, of course, have multiple needs. The benefit is that agents can handle the grunt work,” Kuhr said. There is some hope that AI will help alleviate the burnout and alert fatigue endemic to the cybersecurity community, but it also introduces the risk of generating additional noise. The question is no longer whether organizations are using AI for security, but how.

The environments that penetration testing aims to secure are also evolving rapidly with AI adoption, Kuhr noted. This shift will require humans and AI to work together to enable more continuous testing models. One takeaway from RSAC 2026 is that there is no shortage of innovation in how organizations are applying AI to cybersecurity. To what extent today’s AI systems can be trusted to reliably identify critical vulnerabilities remains an open question. An AI system that cannot be trusted to catch meaningful risks is not useful, regardless of its ability to scale.

“There are a lot of benchmarks out there for testing AI right now,” Kuhr said. “But the real world is more random and difficult than a lab. The only way to really evaluate these agents is against the breadth of knowledge of human experts.”

Synack, along with others in the space, is effectively betting that the future of penetration testing lies in a hybrid model, where AI provides scale and speed while humans deliver judgment and context. That balance may ultimately determine how well organizations can defend against increasingly automated threats.


文章来源: https://securityboulevard.com/2026/04/at-rsac-2026-ai-redefines-the-future-of-penetration-testing/
如有侵权请联系:admin#unsafe.sh