www.bugcrowd.com Bugcrowd Launches Savant Pathseeker for Continuous Agentic Pentesting
Article Content
- •Savant Pathseeker enables continuous pentesting for web applications and APIs.
- •The solution provides evidence of exploitability, surpassing traditional scanners.
- •Integration with Bugcrowd's platform allows seamless transitions to deeper human-led investigations.
On July 28, 2026, Bugcrowd introduced Savant Pathseeker, a continuous agentic penetration testing solution for external web applications and APIs. This product allows security teams to conduct ongoing tests, identifying vulnerabilities and providing evidence of exploitability without waiting for scheduled pentests. Savant Pathseeker integrates with Bugcrowd's existing services, including Penetration Testing as a Service and Bug Bounty programs. It aims to address the limitations of traditional vulnerability scanners by offering real exploitation attempts and not just theoretical findings. The solution is designed to enhance security teams' capabilities against evolving threats, particularly as attackers increasingly leverage AI. Braden Russell, Bugcrowd's Chief Technology Officer, emphasized the need for continuous testing to keep pace with adversarial tactics. The product provides audit-ready reports and allows for manual intervention when necessary, ensuring a comprehensive security approach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…