Terra Security today announced new capabilities for security and engineering leaders seeking to operationalize Continuous Threat Exposure Management (CTEM), enabling them to quickly determine whether ...

NEW YORK: Terra Security today announced new capabilities for security and engineering leaders seeking to operationalize Continuous Threat Exposure Management (CTEM), enabling them to quickly determine whether a newly disclosed vulnerability is actually exploitable in their own environment.
Recent vulnerabilities discovered within major application frameworks, including ORM layers, routing systems, and serialization pipelines, have revealed a systemic issue facing modern Cybersecurity programs: organizations can detect vulnerabilities at scale, but cannot validate exploitability at scale.
As web applications grow more dynamic and interconnected, traditional vulnerability and web app scanners, SAST/SCA/DAST tools, and periodic penetration tests struggle to determine whether a vulnerability is actually reachable in an organization’s live environment. This gap directly impacts the core stages of CTEM, leading to inflated backlogs, misprioritized remediation, and increased operational uncertainty.
“Exploitability validation is the missing middle of CTEM Programs for the majority of organizations,” said Shahar Peled, Co-Founder and CEO of Terra.
“Security teams don’t need more alerts. They need clarity and the ability to take action. Modern vulnerabilities are deeply contextual, and organizations must be able to determine whether an issue is truly exploitable based on their own code, business logic, and user flows.”
Terra’s analysis of recent vulnerability patterns shows that:
These trends are accelerating as engineering teams adopt AI-based tools and leverage more complex frameworks, further amplifying the need for continuous, context-aware validation, rather than point-in-time assessments.
To address this problem, Terra has introduced a continuous exploitability validation approach, powered by advanced agentic AI and human-led oversight. Terra continuously analyzes code changes, business logic, role-based access, and application behavior. It then generates and tests targeted “Signals” to determine whether a vulnerability is realistically exploitable in the environment.
“The future of application risk management isn’t more visibility, it’s more truth. Appsec programs succeed when organizations can distinguish noise from impact. Continuous exploit validation provides the missing layer of certainty that security and engineering teams need,” said Iain Paterson, CISO at Well Health.
Terra’s continuous validation model enables organizations to:
About
Terra Security is the leading Agentic-AI-powered platform for continuous web application penetration testing. Designed for security teams operating in fast-moving, complex environments, Terra combines the scale and efficiency of fine-tuned AI agents with the precision and control of human oversight for safety and compliance. By aligning every test with each organization's unique business logic and risk profile, Terra delivers tailored, exploit-driven findings that expose what truly matters. Founded by seasoned security leaders, Terra is backed by top-tier investors including Felicis, Dell Technologies Capital, SYN Ventures, Lama Partners, Underscore VC, and SVCI.
To learn more, visit https://terra.security
Fonte: Business Wire
Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…
G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes
Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries
Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…
Advocacy, the AI-native, context-first litigation workspace, today emerged from stealth and announced it has raised $3.5 million in seed funding. The…
Palladyne AI Corp. (NASDAQ: PDYN and PDYNW) (“Palladyne AI”), a U.S.-based defense and industrial technology company delivering embodied AI-powered collaborative…
Turkcell Iletisim Hizmetleri A.S. (NYSE:TKC) (BIST:TCELL): Please note that all financial data is consolidated and comprises that of Turkcell İletişim…
Conduent Incorporated (Nasdaq: CNDT), a global technology-driven business solutions and services company, today announced the appointment of Greta Van…