aws AWS What's New ·

AWS Security Agent adds budget controls and vulnerability finding revalidation

securityawsgaengineer
feature

The AWS Security Agent, part of AWS Continuum, has introduced new capabilities for its AI-powered penetration testing service. Security teams and DevSecOps engineers can now set a maximum task-hours limit on penetration tests to control costs, with tests stopping gracefully when the limit is reached. Additionally, users can revalidate individual vulnerability findings after deploying a fix without running a full new test. These enhancements aim to provide more efficient cost management and streamline the vulnerability remediation workflow.

  • Set maximum task-hours limits for penetration tests
  • Revalidate individual vulnerability findings
Features (2)
  • Set maximum task-hours limits for penetration tests

    Users can now define a maximum task-hours limit for any penetration test conducted by AWS Security Agent. This allows security teams to manage and cap testing costs, with options for preset, custom, or no limits. Tests will stop gracefully once the limit is reached, preserving all findings discovered up to that point.

  • Revalidate individual vulnerability findings

    AWS Security Agent now supports revalidating specific findings from a completed test run after a fix has been deployed. This eliminates the need to re-run an entire penetration test, providing a clear 'Active' or 'Resolved' status for the remediated vulnerability. Full revalidation history is linked to the original finding.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-agent/

Related releases