<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz" -->

---
title: AI agents are accelerating vulnerability discovery....
description: AI agents are transforming application security by discovering vulnerabilities at machine scale and speed. XBOW&#x27;s autonomous penetration tester submitted over...
canonical: https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AI agents are accelerating vulnerability discovery. Here’s how AppSec teams must adapt. | daily.dev
og:description: AI agents are transforming application security by discovering vulnerabilities at machine scale and speed. XBOW&#x27;s autonomous penetration tester submitted over...
og:url: https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz
og:image: https://api.daily.dev/og/posts/eBdd7j4RZ.png
og:image:alt: AI agents are accelerating vulnerability discovery. Here’s how AppSec teams must adapt.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AI agents are accelerating vulnerability discovery. Here’s how AppSec teams must adapt.

**[The New Stack](https://daily.dev/sources/newstack)** · 5 min read · 0 upvotes · 0 comments

## Summary

AI agents are transforming application security by discovering vulnerabilities at machine scale and speed. XBOW's autonomous penetration tester submitted over 1,060 vulnerabilities in 90 days, topping HackerOne's leaderboard, while JPMorgan Chase's Auspex system compresses threat modeling from weeks to minutes using tradecraft prompting. AppSec teams must adapt by building queryable security intelligence, fine-tuning models with RAG for their environments, embedding AI into CI/CD pipelines and IDEs, applying AI-driven threat modeling at scale, and using AI to reduce SAST false positives. The core argument is that human-only security review can no longer keep pace with modern development velocity, and teams that proactively integrate AI into their workflows will achieve stronger security coverage at lower cost.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenewstack.io/ai-agents-appsec-strategy/>

## Similar posts on daily.dev

- [Virtual barbarians at the gate: securing the AI blind spot](https://daily.dev/posts/virtual-barbarians-at-the-gate-securing-the-ai-blind-spot-isb9ghzhs) · The Next Web · 0 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#appsec](https://daily.dev/tags/appsec), [#devsecops](https://daily.dev/tags/devsecops), [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AI agents are accelerating vulnerability discovery. Here’s how AppSec teams must adapt.","url":"https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz"},"datePublished":"2026-02-19T21:35:49.259Z","dateModified":"2026-03-15T03:39:31.909Z","description":"AI agents are transforming application security by discovering vulnerabilities at machine scale and speed. XBOW's autonomous penetration tester submitted over...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c9e157f1905d712b7aaf2a0d6035018f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c9e157f1905d712b7aaf2a0d6035018f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The New Stack","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The New Stack","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/newstack","url":"https://daily.dev/sources/newstack"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ai-agents-are-accelerating-vulnerability-discovery-here-s-how-appsec-teams-must-adapt--ebdd7j4rz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,appsec,devsecops,security","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The New Stack","item":"https://daily.dev/sources/newstack"},{"@type":"ListItem","position":3,"name":"AI agents are accelerating vulnerability discovery. Here’s how AppSec teams must adapt."}]}
```

