Brief IA

YesWeHack: AI Agents Detect Vulnerabilities in 24 Hours

🛠️ AI Tools·Tom Levy·

YesWeHack: AI Agents Detect Vulnerabilities in 24 Hours

YesWeHack: AI Agents Detect Vulnerabilities in 24 Hours
Key Takeaways
1YesWeHack has launched the Pentest Agentique, using autonomous AI agents.
2These agents identify system vulnerabilities in just one day.
3The tests are conducted in real-world conditions, with immediate results.
💡Why it mattersThis speed allows companies to quickly address security flaws.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

YesWeHack: AI Agents Detect Vulnerabilities in 24 Hours

YesWeHack has launched the Pentest Agentique, a cybersecurity solution that deploys autonomous AI agents to test the vulnerabilities of companies in real-world conditions. Results are available on the same day the tests are initiated. YesWeHack is betting on agent-based AI to reinvent pentesting and stay ahead of attackers.

A French and European reference in offensive security, YesWeHack launched its Pentest Agentique on June 25, 2026. This solution features autonomous AI agents capable of legally infiltrating a company's systems, with Dassault among the first convinced companies, to uncover security flaws and deliver their verdict on the same day. This initiative represents a direct technological response to cybercriminals who have long integrated AI into their arsenal. The system integrates with YesWeHack's existing suite of security tools.

How the Pentest Agentique Works

So, how does the solution work in practice? The Pentest Agentique sends autonomous AI agents to explore and probe all digital entry points of an organization, including:

  • Websites
  • Mobile applications
  • APIs (interfaces that allow software to communicate with each other)
  • Other services accessible from the internet

Depending on the level of information provided to these agents beforehand, three testing modes are possible:

  • Black box: the agents know nothing about the targeted system and start from scratch like a real attacker.
  • Gray box: they have some partial information.
  • White box: they have access to the complete architecture.

Results are reported in real-time on the platform, without waiting for the mission to conclude.

To carry out these operations, the solution relies on the most advanced AI models available on the market, including so-called open-weight models, whose parameters are publicly accessible. This allows them to run on their own servers, rather than depending on an external provider. Companies can thus choose models hosted in a specific geographical area, such as Europe or Asia-Pacific, avoiding the transit of their data to American servers. At a time when issues of digital sovereignty and compliance with GDPR are influencing purchasing decisions, this is an argument that can appeal to many European companies.

YesWeHack's Reaction and Promise of Collaboration

Guillaume Vassault-Houlière, the CEO and co-founder of YesWeHack, emphasizes that attackers are increasingly relying on AI, and that exploitation windows are narrowing. "The Pentest Agentique is faster and simpler to set up and execute than traditional pentests conducted by humans," he says. The goal of the Pentest Agentique is therefore to enable SecOps teams to respond at the same speed, with enhanced coverage, detection of attack paths, and full support for the OWASP Top 10, the Open Worldwide Application Security Project, which promotes training and best practices in software security.

Integration and Future of the Pentest Agentique

One of the strong points of the solution is its native integration with the YesWeHack platform. Security teams centralize the results of the Pentest Agentique alongside those from Bug Bounty, continuous pentests, and alerts on actively exploited CVE vulnerabilities. An optional human triage service, available 24/7, is offered to validate each result, ensuring a total absence of false positives.

For now, the Pentest Agentique only covers external attack surfaces. Support for internal perimeters is announced to be in development. Dassault Systèmes and Sanofi, along with several other companies in the CAC 40, have already taken the plunge. Clients of Sekost, the cybersecurity audit firm acquired by YesWeHack in 2025, will also soon have access.

Regarding data, YesWeHack asserts that information from Bug Bounty programs will not be used to train the AI models. As for the role of the human hacker, the message remains that AI complements but does not replace. The community of over 150,000 ethical hackers remains a central pillar of the model, alongside clients like L'Oréal, Louis Vuitton, Ferrero, and the European Commission.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.