Inside the 2.7x Problem: Vulnerability Discovery Is No Longer the Bottleneck

LLM applications generate serious vulnerabilities at 2.7x the rate of any other asset type, a ratio unchanged across two years of pentest data. Meanwhile, automated agents now reach initial access in under seven minutes at the cost of an API call. Discovery is no longer the bottleneck, and the security programs built around that assumption are exposed. Joe Brinkley (Head of Security Research) and Luke Doherty (Head of Customer Engagement) at Cobalt unpack new findings from thousands of AI and LLM application pentests and 450 security leaders.

What you'll learn:

  • How attackers chain prompt injection, now 37.6% of LLM findings, into multi-step exploits against production AI systems
  • How frontier models like Claude Mythos collapsed the skill barrier to sophisticated offense, and what to do about it
  • How to read the adversary patterns behind the numbers, and where they point next for your program

 

GUEST SPEAKERS
Joe-Brinkley
Joe Brinkley
Head of Security Research, Cobalt
Joe Brinkley, also known in the community as BlindHacker, serves as the Director of Offensive Security Research & Community at Cobalt. Bringing over 20 years of "in the trenches" experience to the offensive security space, Joe’s career began in 2005 with a decade as a high-level government consultant before he transitioned into commercial penetration testing in 2016. He joined Cobalt in late 2025, drawn by a mission to evolve traditional Pentesting into a more dynamic, community-driven research model. When he isn't obsessing over cybersecurity, you’ll likely find him tinkering in his home lab or perfecting a smoked brisket.
LukeDoherty
Luke Doherty
Head of Customer Engagement, Cobalt
Luke Doherty is the Director of Solutions Architecture at Cobalt. He graduated from the ECPI University with a Bachelor's Degree in Computer and Information Systems Security. With over 10 years of technical experience, he helps bring to life Cobalt's mission to transform traditional penetration testing with the innovative Pentesting as a Service (PTaaS) platform.
RESOURCES

The latest thinking in offensive security

sopr_banner-cover
REPORT
State of Pentesting Report 2026

The definitive benchmark for offensive security and remediation performance.

REPORT
The Responsible AI Imperative Report

Discover the security challenges of AI adoption and how to address them.

REPORT
AI and Pentesting Pulse Report

Discover how AI is your highest-risk asset. The organizations closing that gap do six things differently.