<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz" -->

---
title: Evo Continuous Offensive Security Is Here | daily.dev
description: Snyk has launched Evo Continuous Offensive Security (COS) at Black Hat USA 2026, an AI-powered autonomous pentesting platform designed to fill the 350 days per...
canonical: https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Evo Continuous Offensive Security Is Here | daily.dev
og:description: Snyk has launched Evo Continuous Offensive Security (COS) at Black Hat USA 2026, an AI-powered autonomous pentesting platform designed to fill the 350 days per...
og:url: https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz
og:image: https://api.daily.dev/og/posts/dRMRfbRyz.png
og:image:alt: Evo Continuous Offensive Security Is Here
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Evo Continuous Offensive Security Is Here

**[Snyk](https://daily.dev/sources/snyk)** · 14 min read · 1 upvotes · 0 comments

## Summary

Snyk has launched Evo Continuous Offensive Security (COS) at Black Hat USA 2026, an AI-powered autonomous pentesting platform designed to fill the 350 days per year when traditional manual pentests aren't running. COS combines AI Pentesting (reasoning about application intent to find architectural and business-logic flaws), Agent Red Teaming (targeting LLM-based attack surfaces like prompt injection and goal hijacking), and DAST (covering commodity vulnerability classes with a 0.08% false-positive rate). A key design principle is that findings are validated by an independent judge model rather than the same model that generated them, keeping false positives low. COS integrates with existing Snyk platform data (code, dependencies, APIs, AI components) to focus reasoning on high-value flaws rather than re-discovering known issues. Alongside COS, Snyk announced enhanced AI Security Posture Management with MCP server risk analysis, a preview of Evo Agentic AppSec with an autonomous remediation agent, and general availability of Snyk Secrets for credential leak prevention in AI-generated code.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://snyk.io/blog/evo-continuous-offensive-security>

## Questions this post answers

### What is Snyk Evo Continuous Offensive Security (COS)?

Evo Continuous Offensive Security is Snyk's AI-powered autonomous pentesting capability, generally available as of Black Hat USA 2026. It reasons about application intent to find architectural flaws and business-logic vulnerabilities that scanners miss, combining AI pentesting, agent red-teaming for LLM stacks, and DAST for commodity classes like XSS and SQL injection, running continuously rather than as a once-a-year engagement.

_Teams weighing continuous versus periodic pentesting can track platform announcements like this one on daily.dev._

### How does Snyk Evo COS avoid the problem of AI validating its own security findings?

Every finding from Evo COS is cleared by an independent validation judge, a separate model from the one that generated the finding, rather than letting the same AI both find and confirm a flaw. Snyk reports this produces an extremely low false-positive rate compared with roughly 30% for raw AI tools, and each confirmed vulnerability ships with a runnable proof of concept and full reasoning trace.

_Developers evaluating AI security tooling trustworthiness can follow analysis like this on daily.dev._

### What is the CVE-2025-12420 BodySnatcher vulnerability in ServiceNow?

CVE-2025-12420, disclosed in January 2026 with a CVSS score of 9.3, is a ServiceNow vulnerability nicknamed BodySnatcher that allowed a single email address to impersonate any ServiceNow administrator and take over the platform's AI agents, without hacking passwords or using exploit code, due to a design flaw that trusted the wrong identity signal.

_Security engineers tracking high-severity design-level CVEs like this can follow disclosures on daily.dev._

## Similar posts on daily.dev

- [AI is shipping code faster than security was built to handle](https://daily.dev/posts/ai-is-shipping-code-faster-than-security-was-built-to-handle-ik9kidop5) · The New Stack · 0 upvotes · 1 comments
- [Continuous Offensive Security & AI Pentesting FAQs](https://daily.dev/posts/continuous-offensive-security-ai-pentesting-faqs-p5xykxwh4) · Snyk · 0 upvotes · 0 comments
- [What Evo COS Found in a Real Enterprise SaaS](https://daily.dev/posts/what-evo-cos-found-in-a-real-enterprise-saas-ndzdu6pou) · Snyk · 0 upvotes · 0 comments
- [Snyk Continuous Offensive Security](https://daily.dev/posts/snyk-continuous-offensive-security-aolhgcw1d) · Snyk · 0 upvotes · 0 comments
- [Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work](https://daily.dev/posts/old-ai-security-vs-evo-watch-agentic-security-replace-weeks-of-manual-work-emwvtnvqt) · Snyk · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#appsec](https://daily.dev/tags/appsec), [#ai-security](https://daily.dev/tags/ai-security)

[View this post on daily.dev](https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Evo Continuous Offensive Security Is Here","url":"https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz"},"datePublished":"2026-08-04T12:02:32.409Z","dateModified":"2026-09-14T08:05:13.901Z","description":"Snyk has launched Evo Continuous Offensive Security (COS) at Black Hat USA 2026, an AI-powered autonomous pentesting platform designed to fill the 350 days per...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/583e3304c748299380da3b183a6f9ec5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/583e3304c748299380da3b183a6f9ec5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Snyk","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Snyk","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/8fb2a7b471c04bac9af29fbeb3ed1cf6","url":"https://daily.dev/sources/snyk"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,appsec,ai-security","timeRequired":"PT14M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Snyk","item":"https://daily.dev/sources/snyk"},{"@type":"ListItem","position":3,"name":"Evo Continuous Offensive Security Is Here"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/evo-continuous-offensive-security-is-here-drmrfbryz#faq","mainEntity":[{"@type":"Question","name":"What is Snyk Evo Continuous Offensive Security (COS)?","acceptedAnswer":{"@type":"Answer","text":"Evo Continuous Offensive Security is Snyk's AI-powered autonomous pentesting capability, generally available as of Black Hat USA 2026. It reasons about application intent to find architectural flaws and business-logic vulnerabilities that scanners miss, combining AI pentesting, agent red-teaming for LLM stacks, and DAST for commodity classes like XSS and SQL injection, running continuously rather than as a once-a-year engagement. Teams weighing continuous versus periodic pentesting can track platform announcements like this one on daily.dev."}},{"@type":"Question","name":"How does Snyk Evo COS avoid the problem of AI validating its own security findings?","acceptedAnswer":{"@type":"Answer","text":"Every finding from Evo COS is cleared by an independent validation judge, a separate model from the one that generated the finding, rather than letting the same AI both find and confirm a flaw. Snyk reports this produces an extremely low false-positive rate compared with roughly 30% for raw AI tools, and each confirmed vulnerability ships with a runnable proof of concept and full reasoning trace. Developers evaluating AI security tooling trustworthiness can follow analysis like this on daily.dev."}},{"@type":"Question","name":"What is the CVE-2025-12420 BodySnatcher vulnerability in ServiceNow?","acceptedAnswer":{"@type":"Answer","text":"CVE-2025-12420, disclosed in January 2026 with a CVSS score of 9.3, is a ServiceNow vulnerability nicknamed BodySnatcher that allowed a single email address to impersonate any ServiceNow administrator and take over the platform's AI agents, without hacking passwords or using exploit code, due to a design flaw that trusted the wrong identity signal. Security engineers tracking high-severity design-level CVEs like this can follow disclosures on daily.dev."}}]}
```

