VIDEO PODCAST
Pentera CEO Amitai Ratzon on AI-Native Offensive Security
James Maguire
September 12, 2026

At Black Hat 2026, Pentera CEO Amitai Ratzon discussed how artificial intelligence is reshaping offensive security, from AI-native attack technology to agent-driven security operations. Ratzon detailed Pentera’s new AI-native attacker for testing web applications, its MCP server for connecting security validation data with AI systems, and its growing emphasis on proving which vulnerabilities are actually exploitable rather than simply generating more alerts.

He also explained Pentera’s integration with cybersecurity vendor Recorded Future, which combines live threat intelligence with automated security validation, and predicted that within a few years AI will become so fundamental to cybersecurity products that describing technology as “AI-based” will sound as redundant as calling an application “cloud-based” does today.

Core Takeaways
Pentera is bringing AI-native attack technology directly into its platform
The new capability adds web applications to Pentera’s existing coverage of on-premises infrastructure, cloud environments and externally exposed assets. Ratzon emphasized that Pentera chose to build the technology internally rather than acquire a specialized vendor.
An MCP server connects Pentera’s security data and attack capabilities with the AI ecosystem
Customers can use AI applications and frontier models to query years of Pentera attack history, add outside context and generate highly customized reporting. The connection also works in the opposite direction: users can trigger Pentera attacks through AI tools, turning MCP into both an intelligence and action layer.
Proof of exploitability is becoming increasingly important as AI generates more security alerts
Rather than simply identifying what might be vulnerable, Pentera attempts to safely execute attack paths and determine which vulnerabilities can actually be exploited. The goal is to reduce alert fatigue and give security teams evidence about which risks deserve priority.
Threat intelligence and security validation are beginning to converge
Pentera’s partnership with Recorded Future feeds threat intelligence into Pentera so emerging threats can be tested against customer environments. Looking further ahead, Ratzon expects AI adoption in cybersecurity to remain gradual because of security concerns and enterprise conservatism, but believes AI will eventually become an assumed component of virtually every cybersecurity product.
KEY QUOTES

Proof Matters More Than Another Alert

“What we're doing is providing proof of exploit. The proof of exploitability, as opposed to just telling people what could be done with AI, is a game changer.
One approach is just put more alerts and scare customers even further. The other way is to say, take it easy. Pentera will absorb everything that AI told you could go wrong. We're going to [handle it] in a safe-by-design manner and then give you the proof: This actually was exploitable. This one that was flagged by an AI platform is not."

MCP Creates a Two-Way Connection With AI

“With MCP server, you basically connect the Pentera application to the AI world. Given that an attack is over, the customer can actually query what just happened and correlate it to all the attacks from the past five or six years, plus everything that was just announced in the news.
It’s integrating data from Pentera and exposing it through AI applications and frontier models, but also allowing customers to trigger Pentera attacks. So it’s a two-way thing.”

Turning Threat Intelligence Into Validated Threats

“Envision a world where a threat identified by Recorded Future is then captured by Pentera and validated by our AI-based validation-on-demand technology.
That TTP, IOC or other threat artifact gets tested by Pentera, and once the issue is fixed, it gets re-validated again. So the threat intelligence is not going to be theoretical any longer.”
ABOUT THE AUTHOR
James Maguire
Executive Director
An award-winning journalist, James has held top editorial roles in several leading technology publications, covering enterprise tech trends in cloud computing, AI, data analytics, cybersecurity and more. He regularly communicates with industry analysts and experts and has interviewed hundreds of technology executives. James is the Executive Director of TechVoices.