Phoenix Security launches Exploit Hunt at Black Hat USA 2026
Phoenix Security says its new Exploit Hunt capability now generally available in Phoenix Purple will only report a vulnerability after it has generated and validated a working exploit. The tool is being shown this week at Black Hat USA 2026 and is designed to help teams prioritize exploitable issues, block risky merges and speed remediation.
Why it matters: - Exploit Hunt is designed to cut through noise by surfacing only vulnerabilities Phoenix Security can turn into a runnable exploit. - The workflow aims to help engineers focus on issues that are actually exploitable, not just flagged by static analysis. - Phoenix Security says the system can also block risky pull requests and help teams remediate before code merges.
What happened: - Phoenix Security announced general availability of Exploit Hunt, a capability inside its Phoenix Purple platform, at Black Hat USA 2026 in Las Vegas. - The company is demonstrating the product at Booth 5702 at Mandalay Bay Convention Center from 4 to 6 August 2026. - Exploit Hunt is available now to Phoenix Purple customers. - Phoenix Security also made demo bookings available through its website.
The details: - Exploit Hunt performs automated adversarial testing against application source code. - The system reports a finding only after it generates and validates a runnable proof-of-concept exploit. - Phoenix builds a call graph, taint map and knowledge graph for the repository before any model runs. - The platform uses that structure to rank files for testing based on PageRank centrality, taint density, cyclomatic complexity, prior static analysis signal, external connectivity and reachable dependency vulnerabilities. - The workspace STRIDE threat model, including trust boundaries and attack-path chains, is fed into the testing process. - Three testing roles run in sequence with restricted visibility into one another’s output. - The first role produces a vulnerability report with a CWE classification, severity rating and exploitation path. - The second role independently re-assesses the report and returns confirmed, disputed or insufficient evidence. - The third role tries to produce a working exploit for candidates that survive the prior stages. - Candidates that fail either stage are excluded from the report. - Each confirmed finding is delivered as a runnable exploit script plus a validation document. - Phoenix stores both artifacts in its exploit store and makes them retrievable through the Phoenix Security API. - Exploit Hunt can run on demand, on a daily, weekly or monthly schedule, or as a native GitHub pull-request gate. - In pull-request mode, the tool posts a per-exploit comment and sets a commit status check. - When used with coding agents, Exploit Hunt can index the current codebase during a session and return vulnerabilities and remedies at the end. - Scheduled runs give changed files since the previous run a differential priority boost. - A confirmed exploitable finding can block a merge when Exploit Hunt is configured as a pull-request gate.
Between the lines: - Phoenix is positioning Exploit Hunt as an AI red-team layer, not a replacement for human penetration testing. - The product is built to separate low-friction fixes from breaking changes that need human review. - Operational controls include bring-your-own model API keys by default, spend caps, a durable skip ledger and explicit opt-in for live scanning. - Findings are grouped and deduplicated, and runs are organization-scoped. - The system fails closed on foreign or malformed references. - Remediation output is delivered as reviewable pull requests with supporting reasoning. - Changes identified as potentially breaking require human approval before they are applied. - Exploit Hunt also uses existing SAST, SCA and AI scans to help derive attacks. - Phoenix says the system can ingest or generate architectural paths and patterns to spot gaps such as broken identity. - An early beta memory feature is designed to remember prior attacks and previously identified false positives so future hunts improve. - Phoenix is also offering a public cost calculator for AI-assisted scanning at AI scan cost calculator. - Using the company’s published assumptions, graph-native analysis is modeled at about $3.60 per verified true positive, versus about $64 for file-by-file scanning on the same repositories with the same model. - Phoenix says those figures vary with fleet size, code volume and scan frequency, and the calculator outputs modeled results rather than measured customer results.
What's next: - Phoenix says it will continue showing the product at Black Hat and taking demo requests from interested teams. - The company also points customers to product details at Phoenix Purple and its Agentic SDLC Security control framework. - Phoenix Security will keep developing Hunt memory in early beta to improve future detections and reduce repeat false positives. - Teams adopting the tool will likely use it as a gate for pull requests, scheduled scans and agent-assisted development workflows.
The bottom line: - Phoenix Security is betting that exploit validation, not raw detection volume, is the fastest path to actionable application security.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Grand Canyon State News
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.