Enterprises ship code continuously, while most security validation still happens in snapshots. In this interview, Novee CEO and co-founder Ido Geffen explains what “AI penetration testing” actually means, why it’s different from automated scanning, and why it’s becoming essential as attackers adopt AI to move faster and continuously. He then breaks down what separates best-in-class AI pentesting: operator-like reasoning across real environments, validated exploitability, and the ability to uncover business logic flaws and multi-step attack chains. Ido covers the unique technology behind Novee’s AI penetration tester: a proprietary LLM model, built independently of “frontier” LLMs (like Claude, ChatGPT, Cursor, etc…), and consistently outperforming them at live browser exploitation tests. Finally, he shares what buyers should demand in a live evaluation and how continuous retesting closes the loop after fixes ship.
Segment Resources:
https://novee.security/blog/hacker-trained-ai-discovers-16-new-0-day-vulnerabilities-in-pdf-engines/
This segment is sponsored by Novee Security. See what your attackers already know at https://securityweekly.com/noveersac
Read the interview summary from SC Media here: Novee’s Ido Geffen on why AI pentesting is becoming essential
- 0:00 - RSAC 2026 Interview – AI Pen Testing with Novee Security
- 0:22 - What is Novee Security? AI Vulnerability Scanning Explained
- 0:50 - Can AI Prevent Exploits Before Hackers Strike?
- 01:29 - Nation-State Expertise Behind AI Security Tools
- 02:00 - Custom AI Models vs Open Source LLMs in Cybersecurity
- 02:25 - Training AI to Detect Vulnerabilities at Scale
- 03:28 - Building the “Novee Gym” Cyber Range for AI Training
- 04:07 - What Are Business Logic Vulnerabilities?
- 04:31 - Real Example: Payroll Data Access Security Risks
- 05:19 - Customizing Security by Company & Application Logic
- 06:23 - Avoiding False Positives in Vulnerability Scanning
- 07:37 - AI Exploitability Scanning vs Traditional Pen Testing
- 08:40 - How AI Finds & Validates Exploitable Vulnerabilities
- 09:20 - Automated Remediation & Security Fix Recommendations
- 10:24 - Personalized Defense Based on WAF & Infrastructure
- 11:07 - Continuous Security Testing for Modern Applications
- 13:08 - Why AI Pen Testing is Better Than Basic Vulnerability Scans
- 13:48 - Testing Custom Apps, APIs & AI Systems (Prompt Injection)
- 15:09 - AI Pen Testing Announcement at RSAC 2026
Ido Geffen is the CEO and co-founder of Novee, the leader in AI-powered penetration testing. He brings over 20 years of experience across offensive and defensive cybersecurity, including nation-scale operations, vulnerability exploitation, and defense.
Through his work on national defense, he and fellow Novee co-founders Gon Chalamish and Omer Ninburg saw enterprises facing an impossible challenge: deploying code continuously while testing security only quarterly, even as attackers operate 24/7 with AI-powered tools. They founded Novee in May 2025 to clone their combined expertise into an agent that runs continuously, finding zero-days, business logic flaws, and complex attack chains that traditional tools miss.