AWS Continuum to Enable Agentic Code Security for Enterprises

AWS has introduced 'Continuum,' a new service designed to provide agentic code security for enterprise environments. The platform automates penetration testing, threat modeling, and vulnerability remediation by analyzing a company's entire infrastructure and communication data.
Why it matters
This represents a significant shift toward autonomous, AI-driven cybersecurity tools that can reason across complex enterprise ecosystems.
InfoQ Homepage News AWS Continuum to Enable Agentic Code Security for Enterprises
"Continuum is built on lessons learned from running security across AWS and Amazon.com", claims Chet Kapoor, vice president of search, security, and observability at AWS.
AWS launched penetration testing and code review capabilities as part of AWS Security Agent during AWS re:Invent 2025 . These capabilities allow teams to run penetration testing sessions, both on-demand and integrated into CI/CD workflows, and to execute on-demand code reviews of applications' source code to identify security vulnerabilities and validate compliance with company standards.
The threat-modelling capability allows developers to analyse applications' architectures in order to identify security threats. It produces a system overview describing how the system is built and behaves, and a set of threats describing how the system could be attacked, each with a severity level, a STRIDE classification, and actionable recommendations.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in