AI Hackers Are Faster Than Your Pen Test — Eli Cohen, Snyk
Attackers use AI too, and the fastest AI attack he cites took four minutes. A pen test once or twice a year can't keep up. Eli Cohen of Snyk, co-founder of the runtime security company Helios, explains why security has to go on the offense in an agent-first world. Developers now ship far more code, much of it insecure, while attackers use frontier models to chain small vulnerabilities into critical ones in minutes. He walks through why traditional tools fall short: static scanning misses runtime issues, dynamic testing misses business logic, and human pen tests are expensive and happen only a few times a year. Then he describes continuous offensive security: AI pen testing on every code change, agent red teaming, and a team of agents (orchestrator, recon, vulnerability hunters, an exploit-validating judge, remediation and reporting), fed with context from other scanners. He ends with four questions to ask any AI pen testing vendor. In this talk: • Why AI-generated code and AI-powered attackers break the old security model • SAST vs DAST vs pen testing, and what each one misses • How a team of agents runs pen tests and proves exploits on every PR • Four questions to ask any AI pen testing vendor SPEAKER Eli Cohen, Snyk (co-founder of Helios) LinkedIn: https://www.linkedin.com/in/cohen-eli/ LINKS Snyk Evo: https://snyk.io/evo/ Snyk: https://snyk.io Snyk on X: https://x.com/snyksec CHAPTERS 0:00 Intro 1:37 More code than ever 2:22 Most AI code isn't secure 3:07 Attackers use AI too 4:12 AI attacks in minutes 5:31 Why traditional security can't keep up 5:46 Static scanning (SAST) 6:16 Dynamic testing (DAST) and authorization bugs 7:11 Pen testing: great, slow and expensive 9:16 Continuous offensive security 9:56 Agent red teaming 10:46 AI pen testing on every PR 12:21 How it works: orchestrator and recon 13:16 Vulnerability-hunting agents 13:41 Proving exploits, cutting false positives 14:11 Remediation and reporting 14:51 Context is everything 15:46 Combine scanners and pen testing 17:30 Four questions to ask any vendor Recorded at the AI Engineer World's Fair 2026 in San Francisco. Subscribe for more talks from the engineers building with AI. AI Engineer: https://ai.engineer YouTube: https://www.youtube.com/@aiDotEngineer X: https://x.com/aiDotEngineer LinkedIn: https://www.linkedin.com/company/aidotengineer/ #AppSec #AISecurity #AIEngineer




Join the discussion
Sign in to join the discussion
Sign in