An AI pentesting agent with credentials and broad access is itself an attack surface, says Terra OffSec CEO
TechNadu · x · 2026-09-22
Shahar Peled, CEO of Terra OffSec, argues that an AI pentesting agent holding credentials, security tools, and broad internal access is itself an attack surface — compromise or misuse could cause disruptive, even irreversible damage.
He calls for human oversight at the decision point for potentially disruptive or irreversible actions: agents can autonomously handle recon, but high-risk moves need a human in the loop.
Related event: AI Pentest Agents With Credentials Are Themselves an Attack Surface(2 posts)→
More from coding & agent
- Frontier LLM Debugging a Site Turned Off the Author's Wi-Fi — and Locked Itself Out — MilesCranmer · 2026-09-22
- Grok 4.7 launches for coding and knowledge work at $2/M input tokens — pstAsiatech · 2026-09-22
- Tencent's T-Mem fixes similarity-retrieval blind spot in AI agent memory, EMNLP 2026 — jiqizhixin · 2026-09-22
- JEVfire open-sourced: Qwen 0.8B clears Super Mario in-browser at 71ms per action — ricklamers · 2026-09-22
- Founder seeks cheaper LLM than Terra for scraping store deals, weighing Gemini and DeepSeek — ActionHungry · 2026-09-22
- simd author: AI made six mature libraries much faster in one summer — lemire · 2026-09-22