The world of cybersecurity is in a state of flux, and the latest trend is a surprising one: infosec professionals are souring on automated pentesting tools. This shift in sentiment is a significant development, and it's worth exploring the reasons behind it. In my opinion, the decline in support for fully autonomous pentesting is a healthy sign, indicating that security practitioners are becoming more discerning and demanding actual assurance rather than just coverage. What makes this particularly fascinating is the stark contrast between the initial enthusiasm for automated tools and the current disillusionment. Last year, 29% of security pros were open to fully autonomous pentesting, but now only 9% are, according to a survey by offensive security firm Cobalt. This drop in support is not just a numbers game; it reflects a deeper understanding of the limitations of these tools. One thing that immediately stands out is the failure of automated scanners to detect critical vulnerabilities, especially those introduced by AI. In my view, this is a critical issue, as it highlights the need for a more nuanced approach to security. The survey found that 78% of respondents experienced 'critical false negatives' from automated scanning tools, meaning they failed to identify vulnerabilities that were actually present. This is a significant problem, as it suggests that these tools are not living up to their promise of providing comprehensive security. What many people don't realize is that the issue goes beyond just false negatives. Automated scanners are brilliant at finding known, signature-based vulnerabilities, but they fail miserably at detecting the sort of vulnerabilities that AI introduces, such as prompt injection exploits and excessive agency flaws. These logic flaws are entirely invisible to tools that test using single-shot automated queries. This raises a deeper question: if automated tools are struggling to keep up with the evolving landscape of cybersecurity, what does this mean for the future of security? From my perspective, it suggests that a hybrid approach is the way forward. Most systems can be automatically scanned by AI, while the most critical systems are left up to humans to protect and manage. This is a sensible strategy, as it leverages the strengths of both automation and human expertise. However, it's worth noting that this is not a unique claim. Application security firm Veracode reported earlier this year that AI-assisted software development is creating more vulnerabilities than security teams can keep up with, leaving more vulnerabilities unresolved for longer periods of time. This is a concerning trend, as it suggests that the very tools meant to enhance security are actually contributing to the problem. In my opinion, the solution is not to abandon automation altogether, but to find a balance between automation and human oversight. AI pentesting tools can be incredibly efficient, as evidenced by Amazon security chief CJ Moses, who claims they have made his team 40% more efficient. However, Moses also emphasizes the need for human involvement to ensure that AI doesn't muck something up. This is a sensible approach, as it recognizes the strengths and limitations of both automation and human expertise. In conclusion, the souring on automated pentesting tools is a significant development in the world of cybersecurity. It reflects a deeper understanding of the limitations of these tools and a growing demand for a more nuanced approach to security. The solution, in my opinion, is a hybrid approach that leverages the strengths of both automation and human expertise. This is a sensible strategy, as it addresses the evolving landscape of cybersecurity and the need for comprehensive security in the digital age.