SpartanX Launches NodeX, World's First Full-Stack Autonomous Internal Attack Platform

SpartanX has launched NodeX, what it calls the world's first full-stack autonomous internal attack platform, bringing AI-powered red teaming inside a company's own network perimeter. The launch, announced June 2, 2026, means SpartanX's swarm of more than 600 AI agents can now hunt for exploitable weaknesses both outside and inside an organization — at machine speed, around the clock, according to GlobeNewswire.
Alongside NodeX, the company released Targeted Attack Validation (TAV), a tool that plugs into more than 150 security platforms — including Tenable, Rapid7, and Qualys — to cut scanner noise by 95% and surface only confirmed, exploitable vulnerabilities. CEO Diego Spahn said the product lets organizations "outthink and outmaneuver adversaries at machine speed," according to Yahoo Finance.
Traditional red teaming happens from the outside. NodeX changes that. SpartanX's AI agents now deploy inside the customer's perimeter, mimicking a real attacker who has already broken in. They probe for lateral movement paths — the routes a hacker would use to move from one system to another — across six surfaces: web, API, networks, cloud, identity systems, and AI infrastructure, according to GlobeNewswire.
The urgency is real. The average time for an attacker to move laterally after breaking in has dropped to just 29 minutes, according to the CrowdStrike 2025 Global Threat Report. Some attacks happen in seconds. Quarterly or annual manual pen tests simply cannot keep up with environments that change daily through continuous software deployment pipelines.
Security teams are drowning in alerts. Tenable, Qualys, Rapid7, and dozens of other scanners generate thousands of findings — most of them theoretical, not proven. TAV ingests all of it and runs autonomous attack chains against each finding to confirm whether it can actually be exploited. The result is a short, evidence-backed priority list instead of a wall of noise, according to Yahoo Finance.
SpartanX claims TAV reduces that noise by 95%. Only confirmed-exploitable vulnerabilities make the final list. This approach fits into what analysts call Continuous Threat Exposure Management, or CTEM — a shift away from simply cataloguing software flaws toward proving which ones an attacker could actually use right now.
Finding a vulnerability is only half the job. SpartanX:Defend, the remediation layer, can open a pull request directly in GitHub to fix the issue in code. It also integrates with Jira, Slack, and a customer's CI/CD pipeline, meaning a fix can be proposed, reviewed, and merged without a security engineer manually writing a ticket, according to GlobeNewswire.
Not everyone is comfortable with that level of automation. Some practitioners at Infosecurity Europe 2026 argued that the final decision to apply a fix must stay with a human engineer to avoid false-positive responses causing outages. SpartanX says its agents run in non-destructive mode by default, but critics on security forums have questioned what happens when a 600-agent swarm tests a live production environment.
SpartanX only launched its external attack platform on April 8, 2026 — less than two months before the NodeX announcement. The company closed a seed round led by Venture Guides shortly after and set up its global headquarters in Boston. Investor Anton Simunovic of Venture Guides described the platform as "an entirely new category of offensive security" that moves beyond what he called "glorified scanners," according to Yahoo Finance.
The target market is large. Gartner forecasts global information security spending will hit $240 billion in 2026, a 12.5% jump from 2025. Manual penetration tests typically cost between $70,000 and $150,000 per engagement. SpartanX is betting that continuous, automated coverage at a fraction of that cost will pull enterprise and mid-market buyers away from legacy testing cycles, according to GlobeNewswire.
Publishers
4
Articles
4
Reach
4