KeygraphHQ has released
Shannon, a fully autonomous open-source AI penetration testing tool that doesn't just scan for vulnerabilities-it actively exploits them, generating verifiable proof-of-concept attacks like SQL injections and authentication bypasses with zero false positives. Powered by advanced AI agents and browser automation, the framework achieved an impressive 96.15% success rate on the challenging XBOW benchmark and uncovered over 20 critical issues, including full database exfiltration, when tested against OWASP Juice Shop. Released under the AGPL-3.0 license, Shannon surged in popularity almost immediately, drawing widespread attention for bridging the security gap in fast-paced AI-assisted development environments. While hailed as a game-changer for continuous red teaming, experts caution about potential misuse without proper authorization and ethical guidelines. The tool is now available on GitHub, empowering developers to run comprehensive, autonomous security tests with a single command.