For the nearly decade-old bootstrapped company, being selected as an exhibitor offered an external benchmark for how technology built in Romania compares with that of much larger global players.
Built around practitioners, knowledge sharing and the hacker mindset, DEF CON gave Pentest-Tools.com a demanding audience against which to test its latest work. Existing customers visited the booth without prior arrangements, while other attendees said they had followed the company for years.
AI is speeding up both sides of cybersecurity
At DEF CON, AI was no longer a fringe topic. It featured prominently across company products and conference sessions, as practitioners experimented with the technology in response to its growing use by attackers. Simply claiming to use AI carried little weight. Practitioners wanted to understand where it improved security work, how consistently it performed and whether its findings could withstand independent scrutiny.
Pentest-Tools.com encountered that scrutiny first-hand when it publicly demonstrated AI Pentests, its autonomous web application testing capability powered by Specter, for the first time. The system investigates applications, follows potential attack paths, tests whether vulnerabilities can be exploited and reports findings backed by reproducible evidence. At the booth, visitors quickly moved past the “AI-powered” label to ask which models the system used, whether the agent harness had been built in-house and how its autonomous testing was validated.
As the underlying models become more capable and widely available, differentiation will increasingly depend on the infrastructure and verification mechanisms that make autonomous actions reliable and auditable.
Pentest-Tools.com’s research found that AI still struggled with business-logic vulnerabilities, assessing real-world impact and connecting individual findings into plausible, multi-step attacks, areas where understanding how a system is intended to work matters as much as recognising a technical pattern.
Finding more vulnerabilities creates a new bottleneck
Pentest-Tools.com’s own research points to the same tension. In June 2026, the company surveyed 158 security practitioners using AI-assisted tools for vulnerability assessment and validation. While AI helped teams find more vulnerabilities faster, it also created a new bottleneck: determining which findings were real, exploitable and worth acting on.
Nearly 88% of respondents had encountered AI-generated findings requiring significant manual validation, while 27% said more than a quarter often needed rework. Yet only one in five teams had workflows capable of handling more than 500 candidates from a single engagement; nearly seven in ten said that volume would place them under serious pressure or become unmanageable.
False positives were the most common frustration, cited in roughly 30% of open-ended responses, ahead of cost, integration or missing features. This was also reflected in buying criteria: 63% prioritised false-positive rates and finding quality, while 53% looked for proof of exploit and verified attack paths. Both ranked above price.
The survey also found that frequent testers were better equipped to manage high volumes because they had established processes for triage, prioritisation and retesting. Among teams running fewer than five tests a month, only 4% had a formal workflow for high-volume AI findings, while 55% said such a workload would be unmanageable. Although the highest-frequency groups were small, the pattern suggests that readiness depends as much on testing discipline as on the technology itself.
AI is expanding what needs to be secured
AI is also widening the attack surface. More than 92% of surveyed practitioners already test AI-powered systems or expect to do so within a year, yet only 26% test them regularly. Almost half do so only when requested by a stakeholder, suggesting that AI application security remains reactive in many organisations.
The readiness gap extends to shadow AI. One in three practitioners includes risks from employees’ unauthorised use of AI in security assessments, while 53% have discussed the issue without formalising a process. Meanwhile, 37% report that internal stakeholders are requesting more frequent testing in response to AI-assisted attacks, and another 32% recognise the increased risk but have yet to change their buying behaviour.
The pressure also extends across the open-source ecosystem. Asked about frontier models discovering vulnerabilities at scale, 41% cited the gap between disclosure and patching as their main concern, while 24% feared attackers would find vulnerabilities before patches became available. As AI accelerates discovery on both sides, the industry’s capacity to verify, prioritise and fix vulnerabilities will become as consequential as finding them.
The competition is moving from automation to trust
Pentest-Tools.com’s survey shows that adoption closely follows the cost of error. AI is widely used for vulnerability discovery (74%), report writing (69%) and documentation (67%), where mistakes are relatively easy to identify. Usage falls to 37% for exploitation and attack-path chaining, and 25% for post-exploitation and lateral movement, where decisions require greater context and judgment.
Practitioners continue to rely on human expertise for business logic, creative attack chaining and assessing real-world risk, while automation handles breadth, repetition and evidence capture. Pentest-Tools.com’s reception at DEF CON suggests that smaller Central and Eastern European companies can narrow the resource gap when strong engineering translates into accurate, reproducible results that practitioners can use.
The competitive standard, however, is rising. As the report concludes, finding vulnerabilities is becoming cheaper but proving them is not.

Member discussion