News · curated 7 Jul 2026

Infosec professionals sour on automated pentesting tools

Coverage timeline

30 Jun 2026theregister.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Defenders should know that signature-based automated scanners fail to catch prompt-injection and excessive-agency flaws in LLM/agent deployments, which carry disproportionately high severity rates.

A Register report on Cobalt's 2026 State of Pentesting survey (450 respondents) finds support for fully automated pentesting collapsing from 29% to 9%, largely because automated scanners miss AI-specific flaws like prompt injection and excessive agency that require creative, multi-turn adversarial testing. Cobalt also reports 32% of vulnerabilities in AI/LLM environments are high or critical severity, versus 12% in traditional environments.