Synack study finds 95% of firms miss critical AI flaws between pentests
A Synack‑commissioned survey of security leaders revealed that 95 % of respondents discovered serious or critical vulnerabilities outside their scheduled penetration‑testing windows in the past year, and 42 % experienced this at least once a month. The study identified three main gaps: coverage gaps, with 38 % saying a quarter of their critical attack surface was never independently tested in the last 90 days; trust gaps in AI, as 79 % would not act on AI‑generated results without human validation; and maturity gaps, with only 15 % describing their security‑testing programmes as continuous. Respondents see AI primarily as a tool for scaling reconnaissance and identifying potential flaws, while human analysts remain responsible for assessing exploitability and business risk.
At the Munich Cyber Tactics, Techniques and Procedures (MCTTP) 2026 conference, security architect Christian Schneider introduced a five‑zone model designed to uncover hidden attack paths between AI agents, retrieval‑augmented generation (RAG) systems and multi‑component platforms (MCP). The model stresses moving from component‑centric reviews to path‑centric analysis to detect complex, chained attacks that can bypass traditional security checks.