TL;DR: AI-driven offensive models expose a widening attack surface coverage gap, because traditional point-in-time testing, incomplete reconnaissance, and isolated vulnerability checks fail to model how real attacks chain issues across an environment, according to Synack. The practical shift is from periodic validation to continuous, coverage-based testing that matches the speed and composition of modern attack paths.
NHIMG editorial — based on content published by Synack: Become Mythos-Ready and Close the AI Coverage Gap with Synack Introducing the Glasswing-Readiness Assessment
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: What breaks when security teams rely on point-in-time testing?
A: Point-in-time testing breaks when the environment changes faster than the assessment cycle.
Q: Why do AI-driven attackers expose weaknesses that traditional testing misses?
A: AI-driven attackers can explore more of the environment, faster, and with more persistence than human-led manual testing.
Q: How do you know if attack surface management is actually working?
A: Look for fewer unknown internet-facing assets, faster detection of newly exposed services, and clearer ownership for public endpoints.
Practitioner guidance
- Measure attack surface coverage as a control objective Quantify what percentage of assets, identities, secrets, and access paths are actually exercised in testing.
- Include NHIs in every coverage exercise Inventory service accounts, API keys, tokens, and delegated access paths alongside hosts and applications.
- Test exploit chains, not single findings Build assessment scenarios that combine weak segmentation, over-permissioned access, and exposed credentials.
What's in the full article
Synack's full blog post covers the operational detail this post intentionally leaves for the source:
- How the Glasswing-Readiness Assessment is structured across environment coverage and exploit-path validation
- How Sara and the Synack Red Team divide autonomous exploration from human judgment during testing
- What the platform says it can reveal about attack paths that crown-jewel strategies miss
- How practitioners can frame continuous testing as a remediation and leadership alignment problem
👉 Read Synack's analysis of AI-driven attack surface coverage and Glasswing readiness →
AI-driven attack surface coverage: what it means for security teams?
Explore further
Attack surface coverage is now a governance control, not just a testing metric. Synack’s framing is useful because it moves the discussion away from annual assessment rituals and toward measurable exposure coverage. If an organisation only validates a fraction of its environment, it is accepting blind spots as a normal operating condition. Security leaders should treat coverage as a board-relevant control objective, not a technical afterthought.
A question worth separating out:
Q: Who is accountable when attack surface coverage is incomplete?
A: Accountability should sit with the teams that own exposure, remediation, and identity governance together, not with a single tool owner. Coverage failures span asset management, IAM, NHI lifecycle control, and security operations. If those functions are separate, governance must define who closes the gap and how quickly it is re-tested.
👉 Read our full editorial: AI-driven attack surface coverage is outpacing point-in-time testing