Snyk has launched a new autonomous cybersecurity platform intended to help organisations detect exploitable weaknesses as their software and artificial-intelligence systems continuously change.
The company announced the general availability of Evo Continuous Offensive Security, or Evo COS, on 4 August 2026 during the Black Hat USA cybersecurity conference in Las Vegas.
Unlike security scanners that primarily produce lists of potential vulnerabilities, Snyk says Evo COS actively tests applications, verifies whether identified weaknesses can be exploited and illustrates how multiple vulnerabilities could be connected to form a larger attack.
Continuous penetration testing
Traditional penetration testing is commonly conducted once or twice a year. During these assessments, authorised security professionals attempt to breach an organisation’s applications and systems to identify weaknesses before criminals exploit them.
However, modern development teams can introduce software changes several times per day. A penetration test completed months earlier may therefore fail to reflect the current condition of an application.
Evo COS is designed to conduct authorised testing continuously as applications evolve. It uses autonomous AI agents to simulate attacks, examine possible access routes and validate security weaknesses.
According to Snyk, the platform can test:
- Web applications and programming interfaces
- AI models and applications
- Autonomous AI agents
- Model Context Protocol servers
- Agent tools, skills and permissions
- Business-logic and architectural weaknesses
- Connections between several vulnerabilities
Producing attack narratives
Evo COS attempts to show security teams how weaknesses can be combined into an exploit chain.
For example, an individual authorisation error might appear to present limited risk. However, when combined with exposed credentials and an application-logic flaw, it could provide access to sensitive company information.
The platform is intended to produce an attack narrative explaining this sequence instead of presenting each issue as an unrelated alert.
Snyk says this approach can help organisations prioritise vulnerabilities that pose genuine operational risks while reducing time spent investigating findings that cannot be exploited.
Separate AI system validates findings
The company describes Evo COS as a multi-model offensive-security system. AI models perform the simulated attacks, while a separate validation model acts as an independent judge that checks whether each reported weakness is genuinely exploitable.
This separation is important because generative AI systems can produce inaccurate or unsupported conclusions. Independent validation may reduce false reports, although organisations should still maintain human oversight when reviewing results or authorising security actions.
Wider expansion of Snyk’s security platform
The Evo COS release is part of a broader expansion of Snyk’s AI Security Platform. The company also announced:
- Enhanced AI Security Posture Management for discovering models, agents, tools and other AI components
- General availability of Snyk Secrets for detecting credentials exposed in source code
- An early preview of Evo Agentic Application Security
- Tools for identifying and repairing inherited software vulnerabilities
- Controls intended to prevent new security weaknesses from entering production
The company describes its strategy through four stages: discovering the attack surface, remediating existing weaknesses, validating what attackers can exploit and preventing new risks.
Why the development matters
AI tools are enabling development teams to produce software much faster. The same technology can also help attackers examine applications, find vulnerabilities and automate cyberattacks.
Security teams therefore need testing systems capable of operating at a speed closer to modern software development and potential AI-powered threats.
Evo COS represents an important shift from occasional manual testing towards persistent, automated attack simulation. Nevertheless, its effectiveness should be evaluated through independent testing, particularly its ability to avoid false positives and operate safely without disrupting production systems.




