Shannon 3.0 AI pentester gets through Aikido and XBOW
Keygraph’s own run says Shannon 3.0 found the critical Photoview SQL injection that Aikido and XBOW were tested against.
The release adds an opt-in, multi-stage code analysis pipeline that turns source review into exploit hypotheses, but only live-demonstrated exploits become findings. In Keygraph’s comparison, Shannon 3.0 was run against Photoview 2.4.0 with three models and reported 10 to 24 findings depending on the model. All three runs caught the patched pre-auth SQL injection; the Opus 5 run caught six of seven issues fixed in that round, with one false positive. The CLI, CI integrations, reports, SARIF output, and self-hosted model support were also updated. TestingCatalog's note
The release adds an opt-in, multi-stage code analysis pipeline that turns source review into exploit hypotheses, but only live-demonstrated exploits become findings. In Keygraph’s comparison, Shannon 3.0 was run against Photoview 2.4.0 with three models and reported 10 to 24 findings depending on the model. All three runs caught the patched pre-auth SQL injection; the Opus 5 run caught six of seven issues fixed in that round, with one false positive. The CLI, CI integrations, reports, SARIF output, and self-hosted model support were also updated. TestingCatalog's note
score 6