TL;DR: Anthropic’s Mythos and Project Glasswing have intensified discussion around AI-powered pentesting, but Ethiack argues the core shift is market perception rather than a wholesale change in security mechanics. The practical issue is how enterprises validate findings, constrain offensive testing, and keep pace with exposed services, legacy integrations, and broader trust and accountability gaps.
NHIMG editorial — based on content published by Ethiack: Back to Info Hub Mythos didn't change the rules, it showed us they already changed
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should security teams govern AI-assisted web testing tools?
A: Treat AI-assisted testing as a governed workflow, not a convenience feature.
Q: Why do exposed services and leaked credentials still matter when AI can find vulnerabilities faster?
A: Because faster discovery does not remove weak access paths.
Q: What do researchers get wrong about using AI in offensive security?
A: The common mistake is treating AI as a substitute for verification.
Practitioner guidance
- Define scope boundaries for AI-assisted testing Require explicit target lists, forbidden actions, and escalation rules before any model is allowed to probe production-connected systems.
- Validate AI-generated findings before triage Create a verification step that separates likely issues from exploitable evidence, then route confirmed findings into existing remediation queues with named owners and due dates.
- Harden service account and token hygiene Prioritise the credentials that connect testing tools to cloud consoles, terminals, and CI/CD systems.
What's in the full article
Ethiack's full blog covers the operational detail this post intentionally leaves for the source:
- Practical examples of how AI-assisted offensive testing is structured across real environments and workflows
- The vendor's view of how model capability changes attack simulation depth, coverage, and response planning
- Operational context on where AI findings still need human judgement, prioritisation, and validation
- Discussion of how teams can balance offensive automation with scope control and accountability
👉 Read Ethiack's analysis of Mythos, Project Glasswing, and AI-powered pentesting →
AI-powered pentesting and the governance gap security teams are missing?
Explore further
AI-powered pentesting exposes a governance gap, not a security reset. The article is right that model capability is improving, but the underlying enterprise problem is still validation, scope, and accountability. Offensive automation only becomes operationally useful when organisations can trust the output and assign remediation ownership. The practical conclusion is that security teams need a control plane for AI-assisted testing, not just better models.
A question worth separating out:
Q: Who is accountable when AI pentesting is run outside approved scope?
A: Accountability should be defined before the pilot starts. Security owns authorisation and controls, while procurement, privacy, and legal must sign off on data handling, retention, and liability boundaries. If the test crosses scope, the absence is usually governance, not just tooling.
👉 Read our full editorial: Mythos and Glasswing show why AI-powered pentesting is shifting