IT Security Guru
Read post

AI pentesting tools are generating more findings than security teams can validate, new survey finds

A survey of 158 security practitioners by Pentest-Tools.com reveals that AI-assisted pentesting tools are creating a validation backlog rather than saving time. 87.8% of respondents said AI-generated findings required significant manual validation, and nearly 30% of free-text frustrations cited false positives, hallucinated exploits, or fabricated CVEs. One practitioner reported 250 of 300 AI-generated findings were junk. Only 20.3% of teams had workflows to handle 500+ findings from a single engagement. AI usage is highest in scanning and report writing but drops sharply in phases requiring live judgment like exploitation and lateral movement. Business logic flaws remain a consistent blind spot for AI tools. Meanwhile, 75.3% of practitioners already test AI-powered or LLM-integrated applications, and stakeholder pressure for more frequent testing is rising. Testing cadence — not org size — emerged as the strongest predictor of a team's ability to cope with AI-generated volume.

    #security#ai-security
Aug 03•5m read time•From itsecurityguru.org
Post cover image
109 Impressions
IT Security Guru's image
IT Security Guru

IT Security Guru is a cybersecurity news portal offering articles, analysis, and insights on cyberse...

193 Followers

•

107 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard