IT Brief US - Technology news for CIOs & IT decision-makers
United States
Picus launches AI platform to validate real exploits

Picus launches AI platform to validate real exploits

Wed, 8th Jul 2026
Sean Mitchell
SEAN MITCHELL Publisher

Picus Security has launched an Autonomous Exposure Validation Platform designed to help security teams determine whether exposures can actually be exploited in their own environments.

The launch brings together breach and attack simulation, autonomous penetration testing, and exposure validation in a single system. The approach is intended to move teams beyond severity scoring models such as CVSS and EPSS by testing whether a given exposure would work against real assets and existing controls.

Security teams have long used vulnerability scores to rank patching priorities, but those ratings do not show whether an attack path is practical inside a specific organisation. Picus is targeting that gap by validating whether a published vulnerability can execute, which controls stop it, and whether remediation has closed the issue.

Picus is also introducing Picus Swarm, described as five specialist AI agents managed by its Numi AI system. The agents cover discovery, exploitation, validation, mobilisation, and reporting, while customers can set each workflow step to Manual, Supervised, or Fully Autonomous operation.

The platform is aimed at a threat environment in which attackers can move from disclosure to weaponisation within hours. Picus cited roughly 132 published CVEs a day as one reason security teams are under pressure to identify which issues matter most and prove that changes have reduced risk.

Under the new model, exposure validation breaks a vulnerability into the steps needed for an attack to succeed and then checks those steps against a customer's control stack. The process is meant to show, on a per-asset basis, whether the attack path works, which defence blocks it, or whether no defence intervenes.

This can also apply to restricted assets and to vulnerabilities that do not have a safe exploit available for conventional automated penetration testing. Where a patch is not immediately available, the system recommends compensating controls for each stage of the attack chain.

Single loop

Picus is presenting the product as a single loop rather than three separate tools. In practice, breach and attack simulation tests what products such as EDR, SIEM, firewalls, and web application firewalls block or detect, while autonomous penetration testing shows what an attacker can reach and exploit on accessible assets.

Exposure validation then addresses a narrower but often urgent question: whether a newly disclosed CVE is exploitable in that specific environment on that day. The aim is to replace theoretical prioritisation with evidence tied to the customer's assets and defences.

"Finding the exposure was never the hard part," said Volkan Erturk, Co-founder and CTO at Picus Security. "The hard part is acting on the right issue: the defensible decision, the fix that closes the gap, and the evidence it worked. This platform validates attack surfaces, exposures, and security controls as one loop, then drives the fixes that matter to closure and re-validates them, at the speed AI-powered threats now demand."

Customers can choose how much autonomy the AI agents have at each stage, and all actions are logged through audit trails. That reflects a wider pattern in cybersecurity, where suppliers are adding AI-driven automation while still allowing teams to retain approval over sensitive actions.

Customer results

Picus included performance figures from existing deployments, saying customers have doubled security control effectiveness within 90 days and reduced mean time to remediation by 89%, with more than 75 integrations across security tools.

One cited deployment involved a Fortune 100 financial services company, where Picus said a simulation identified a 15-hour lag in detection logging in an XDR product. According to the company, the issue had not been visible until it was tested in a validation exercise.

A customer executive described that outcome in Picus's account of the deployment. "We thought our detection coverage was solid, and on paper it was," said the firm's Chief Information Security Officer. "Picus showed us a gap no dashboard had flagged, and then proved it was closed once we fixed it."

The launch comes as security vendors seek to shift spending discussions from the volume of vulnerabilities discovered to the smaller subset that presents a direct operational risk. By tying exploitability, control performance, and remediation testing into one process, Picus is trying to make that case with security operations teams as well as senior management.

For buyers, the practical question will be whether the platform reduces false urgency around high-scoring vulnerabilities and shortens the time needed to verify fixes. Picus said its system is meant to deliver decisions and verdicts rather than raw alerts.