Live: 29 Sep 2026, 15:00 CEST 45 minutes · Online · Free

Autonomous Pentesting:
what an AI agent actually does when it attacks your application

A 45-minute live session on how an autonomous pentest agent maps an application, plans, exploits and verifies. What it finds that scanners miss, where it still needs a human, and what changes for defenders when testing runs at machine speed. Hosted by Adam Lundqvist, founder of SQUR.

When
Tue, 29 Sep 2026
15:00 to 15:45 CEST
14:00 BST · 09:00 EDT
Format
Online live, Google Meet
No account needed. Recorded; the replay goes to every registrant.
Who is it for
CTOs, engineering leads, heads of IT and security leads at companies that build their own software. Security consultants welcome.

Why this session, why now

In 2026 an autonomous agent mapped more than 200 interfaces of a large consultancy's internal AI platform, found an overlooked weakness and reached read and write access on the database, in two hours, with no credentials and no human in the attack chain. Responsible research, fixed the same day, and the clearest public demonstration so far of what agentic systems do to the asymmetry between attacker and defender.

Most security programmes still run on snapshots: a pentest once a year, a patch day once a month. This session shows the other side of that gap, from the inside of the agent, and what a defender does with it.

It builds on Adam's article for Techtag, Katz und Maus: Wie Künstliche Intelligenz die Cybersicherheit verändert (German), and goes one level deeper on autonomous pentesting.

Agenda: 45 minutes

00:00
The asymmetry moved
Two 2026 incidents in five minutes: what agents did without a human in the loop, and why "we test once a year" stopped being a strategy.
05:00
Anatomy of an autonomous pentest
Reconnaissance, planning, exploitation, verification, reporting. What each agent does, how they hand off to each other, and why the verification step is what separates a finding from noise.
15:00
A recorded run, narrated
An agent against a demo application: from the first request to a chained finding (broken access control into a business-logic flaw), including the dead ends it tried on the way.
27:00
What it finds, what it cannot, and how it is kept in scope
IDOR, injection, SSRF and business logic versus what scanners see. The limits: scope enforcement, blast-radius controls, when a human steps in.
35:00
What changes for defenders
From the annual snapshot to continuous validation. How to run an autonomous pentest against your own application safely, and what NIS2's leadership responsibility means for the testing cadence.
40:00
Live Q&A
Bring one question about your own application. Questions submitted at registration are answered first.

Register, free

We use your details to send the join link, two reminders and the recording. Nothing else without the box above. Privacy policy.

Speaker

Adam Lundqvist
Founder, SQUR

Adam builds autonomous pentesting from Karlsruhe. Before SQUR he was Director of Engineering at Cobalt, the pentest-as-a-service platform, where he saw the six-week wait for a report from the other side of the table. SQUR's engine runs a full pentest in 24 hours and proves every finding with a working exploit; it won the badenova hackathon in June 2026 and the ECSO startup award qualifier in April 2026.

What this is not

SQUR builds an autonomous pentesting platform, and the recorded run is one of ours, so expect five minutes on how it is built into a product. The other forty are about the method: what agentic testing does, where it stops, and what to do about it regardless of which tool you use.

No slides sold as a demo. No pricing pitch. The recording and the slides go to every registrant afterwards.