Snyk Launches Continuous Pentesting While Its Own Data Shows the Backlog Growing

Snyk Launches Continuous Pentesting While Its Own Data Shows the Backlog Growing

Security
Continuous pentesting meets the adoption curve it was built to chase
By Shashi Bellamkonda · August 8, 2026
Snyk's booth at Black Hat USA 2026, Las Vegas.
46.9%
of AI-using orgs run agentic architectures (Snyk, 2026)
1.39M
repositories in Snyk's adoption study (Snyk, 2026)
350
days a year outside a typical pentest window (Snyk, 2026)

Fifteen days is what a typical penetration test takes. Three hundred fifty is what's left over for attackers to work with, and for applications to keep changing underneath whatever the test found. Snyk used that math to introduce Evo Continuous Offensive Security at Black Hat USA 2026 on August 4, general availability for autonomous, AI-powered pentesting and agent red teaming that runs on a schedule closer to daily than annual (Snyk, 2026).

Evo COS runs the test, then checks its own work. A second, independent layer reviews every finding before it reaches a security team, an answer to the false-positive fatigue that has slowed adoption of earlier automated scanning tools. Snyk paired the launch with a broader view into AI usage across a company's systems, plus general availability for Snyk Secrets, a tool for catching exposed passwords and API keys built on technology from its BitPatrol acquisition (Snyk, 2026).

The Research Snyk Published Explains Why It Built This

Snyk's State of Agentic AI Adoption report landed the same week, drawn from 3,044 enterprise environments and 1.39 million code repositories. Nearly half of organizations already using AI, 46.9%, have moved to AI agents that act on their own, sometimes wired into company data and outside tools rather than kept at arm's length. More than half of that group have built the full setup, agents and the connections that let them reach in (Help Net Security, 2026).

The report's sharper claim is about visibility, not adoption. A system-level count of what enterprises run turns up an AI footprint roughly three times larger than a model inventory alone would show. Security teams counting models are missing most of what is exposed.

That is the gap Evo COS is priced to close.

A scheduled pentest measures a system that has already changed by the time the report ships.

Three Acquisitions Built the Product Snyk Announced This Week

None of what launched at Black Hat started as a Snyk product. DeepCode, a Swiss startup Snyk acquired in 2020, gave Snyk the code-reading technology still at the center of its scanning today. Invariant Labs, another Swiss team acquired in June 2025 less than a year after its founding, brought researchers who were first to document how AI agents can be tricked into leaking data, work that now anchors Snyk's threat research. BitPatrol, the most recent of the three, supplied the technology behind Snyk Secrets, the tool that reached general availability alongside Evo COS this week (Snyk, 2026).

The pattern holds across all three. Snyk buys small, research-heavy teams close to their founding and ships their work as a named feature within a year or two, rather than acquiring revenue.

Continuous Testing Still Needs Someone to Fix What It Finds

Running pentests daily instead of twice a year produces more findings, faster. Nothing about Evo COS's launch addresses whether remediation capacity grows to match. A security team that could not close the backlog from an annual pentest now inherits a continuous one, and the constraint moves from detection to throughput.

Snyk's own adoption numbers suggest the bottleneck will show up first at organizations already running agentic architectures, the 46.9% with the biggest AI footprint and the least system-level visibility into it.

CIO/CTO Viability Question

Before adding continuous pentesting to next year's budget, ask your team how many findings from the last scheduled pentest are still open. If that number is not near zero, a faster testing cadence adds volume to a queue that is not moving, not coverage.

Sources

Snyk. "Evo Continuous Offensive Security Is Here." Snyk, 4 Aug. 2026, snyk.io.

Snyk. "Snyk Secrets Is Now Generally Available." Snyk, 4 Aug. 2026, snyk.io.

Snyk. "Snyk Acquires Invariant Labs to Accelerate Agentic AI Security Innovation." Snyk, 24 June 2025, snyk.io.

Help Net Security. "Your Enterprise AI Footprint Is About Three Times Bigger Than Your Model List." Help Net Security, 5 Aug. 2026, helpnetsecurity.com.

Security Boulevard. "Snyk Brings Evo Continuous Offensive Security to General Availability at Black Hat." Security Boulevard, 4 Aug. 2026, securityboulevard.com.

Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.