frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: ModernPentest – Continuous automated pentesting for web apps and APIs

https://modernpentest.com/
1•victor_y•1h ago

Comments

victor_y•1h ago
Hi HN, I'm Victor. AI is making attacks cheaper and faster. Automated vulnerability scanners, LLM-assisted exploit generation, and attack frameworks that used to require expertise are now accessible to anyone with a prompt. Security testing needs to keep pace.

I built ModernPentest to run continuous automated pentests on any web application or API. Setup takes 5 minutes, and you get a full report with exploitable vulnerabilities in under an hour.

How it works:

- AI agents (Claude Agents SDK) coordinate a multi-stage testing pipeline: discovery, parallel vulnerability testing (injection, access control, authentication), consolidation, and report generation

- Agents run on GCP Cloud Run Jobs (containerized)

- Real-time progress updates via Convex WebSockets

- Security tools: Nuclei, SQLMap, httpx, and custom checks for specific platforms

What it tests:

- Any web application or API (Next.js apps, WordPress sites, Django backends, etc.)

- Deep checks for Supabase RLS policy bypasses and Firebase security rule misconfigurations

- API authentication, authorization, and injection vulnerabilities (OWASP API Top 10)

The speed difference matters. Traditional pentests take 2-4 weeks and give you a point-in-time snapshot. By the time you get results, your codebase has changed. We run in under an hour, so you can test after every deployment.

Remediation validation is another pain point. When you fix a vulnerability, you usually wait 5-10 days for a consultant to verify. Our agents verify your fix in about 5 minutes.

Pricing: $500/month gets you 24 pentests per year (monthly automated + on-demand), SOC 2-ready reports, and remediation tracking. That's $6K/year vs $15K+ for a single traditional pentest.

Tech stack: Next.js frontend, Convex backend, scanning agents on GCP running with Claude Agents SDK.

Demo: https://modernpentest.com

Happy to answer questions about the agent architecture, detection methodology, or false positive handling.

GenAI turned producing $1M videos into $100 and dead easy

https://drive.google.com/file/d/1HVSrACB1PnlEt2NpuPenMyqIJc0ilCZa/view?usp=sharing
1•bayeslaw•36s ago•1 comments

Scott Adams, 'Dilbert' comic creator, dies

https://www.cnn.com/2026/01/13/entertainment/scott-adams-death-cec
1•sleepyguy•2m ago•0 comments

Hey Sam, where is Stargate Argentina?

https://tickerfeed.net/articles/openai-where-is-stargate-argentina
1•sethops1•2m ago•0 comments

Choosing Learning over Autopilot

https://anniecherkaev.com/choosing-learning-over-autopilot
1•evakhoury•7m ago•0 comments

Tribute: Discover and fund the open source projects your code depends on

https://github.com/jshchnz/tribute
2•jshchnz•9m ago•0 comments

Show HN: LeetCode CLI – Interview timer, solution snapshots,collaborative coding

https://github.com/night-slayer18/leetcode-cli
1•night-slayer•9m ago•0 comments

Show HN: Nogic, Turn codebase into a graph to understand how it fits together

https://marketplace.visualstudio.com/items?itemName=Nogic.nogic
1•davelradindra•10m ago•0 comments

Show HN: Timberlogs – Drop-in structured logging for TypeScript

1•enaboapps•10m ago•0 comments

Ask HN: If you had $10M in the bank, would you still show up to your job?

1•hleumas•10m ago•1 comments

Tenor is shutting down – here's the alternative KLIPY

1•Giviberidze•11m ago•0 comments

The $1B AI Drug Lab That Can't Touch Its Own Data

https://www.distributedthoughts.org/billion-dollar-ai-drug-lab-cant-touch-data/
1•danso•11m ago•0 comments

Maps of cities coloured by street/road/ave/etc.

https://erdavis.com/2019/07/27/the-beautiful-hidden-logic-of-cities/
1•fanf2•11m ago•0 comments

Prosecutors seek death penalty for ex-South Korean president Yoon

https://www.bbc.com/news/articles/cq6vyqq5r0do
2•mdhb•11m ago•0 comments

Nukitori is a Ruby gem for HTML data extraction

https://github.com/vifreefly/nukitori
1•thunderbong•14m ago•0 comments

Show HN: Fluid.sh – Make Infrastructure Safe for AI

https://github.com/aspectrr/fluid.sh
1•aspectrr•14m ago•0 comments

A Benchmarking Framework for Software-Based GPU Virtualization Systems

https://arxiv.org/abs/2512.22125
1•PaulHoule•15m ago•0 comments

7 Minute Apps

https://www.youtube.com/watch?v=Nejecji5XNQ
1•spartee•16m ago•0 comments

A Final Message from Scott Adams (X.com)

https://twitter.com/ScottAdamsSays/status/2011116140626657458
1•smarri•17m ago•0 comments

Signal leaders warn agentic AI is an insecure, unreliable surveillance risk

https://coywolf.com/news/productivity/signal-president-and-vp-warn-agentic-ai-is-insecure-unrelia...
50•speckx•17m ago•6 comments

Lessons from 2 years of building virtual humans

https://enterprise.righthand.ai/blog/three-mistakes-from-building
3•notanaiagent•18m ago•2 comments

The Tug of War at the Top of the World

https://www.nytimes.com/2026/01/11/world/europe/svalbard-norway-arctic-control.html
3•whack•18m ago•0 comments

Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws

https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2026-patch-tuesday-fixes-3-zero...
1•fleahunter•18m ago•0 comments

AI Generated Music Barred from Bandcamp

https://old.reddit.com/r/BandCamp/comments/1qbw8ba/ai_generated_music_on_bandcamp/
28•cdrnsf•21m ago•9 comments

Notre-Dame sees record number of visitors, one year on from reopening

https://www.rfi.fr/en/france/20260105-notre-dame-sees-record-number-of-visitors-one-year-on-from-...
3•gnabgib•24m ago•0 comments

The rapid rise and slow decline of Sam Altman

https://garymarcus.substack.com/p/the-rapid-rise-and-slow-decline-of
16•treadump•24m ago•2 comments

DevOps'ish Returns

https://buttondown.com/devopsish/archive/devopsish-returns/
1•oaf357•24m ago•0 comments

Verizon to stop automatic unlocking of phones as FCC ends 60-day unlock rule

https://arstechnica.com/tech-policy/2026/01/fcc-lets-verizon-lock-phones-for-longer-making-it-har...
3•cdrnsf•25m ago•0 comments

Can Philanthropy Fast-Track a Flagship Telescope?

https://www.universetoday.com/articles/can-philanthropy-fast-track-a-flagship-telescope
1•rbanffy•25m ago•0 comments

Claude Code Questionnaires

https://djharper.dev/post/2026/01/10/claude-code-questionnaires/
1•speckx•25m ago•0 comments

Apple-1 Computer Prototype Board #0 Auction

https://www.rrauction.com/auctions/lot-detail/350902407346003-apple-1-computer-prototype-board-0-...
2•qingcharles•26m ago•0 comments