James Thatcher, Author at Synack

James Thatcher

Principal AI Engineer

LinkedIn profile for James Thatcher

James Thatcher is a Staff AI Engineer at Synack specializing in agentic AI, machine learning, and AI-powered penetration testing. He focuses on building intelligent security solutions that combine autonomous AI agents with human expertise to modernize continuous security validation and offensive security operations.

Recent research

How Sara Pentest is Changing the Game for AI Pentesting
How Sara AI Pentesting Identifies Real-World Vulnerabilities In a single six-hour session, with no human intervention, Sara found and fully exploited multiple high-severity vulnerabilities across a live application including a SQL injection (SQLi), an admin account takeover, and stored cross-site scripting. In fact, 70% of Sara’s findings on this target were rated high or critical.

Benchmarking Synack’s Agentic AI Against PortSwigger SQLi Labs
Sara Pentest is a penetration test powered by agentic AI and built on Synack’s PTaaS platform. The Sara architecture employs specialist agents to seek out OWASP vulnerabilities, with human oversight focused on validating these identified vulnerabilities. The agents behind Sara Pentest are continuously tested in the same lab environments that make great human pentesters.

More research by James Thatcher

How Synack’s AI Agent Identifies and Exploits XSS In OpenEMR’s Backup Interface
OpenEMR is a widely deployed open source electronic health records system, serving over 100,000 medical providers worldwide and managing sensitive health information for millions of patients. When vulnerabilities exist in software handling protected health information, the consequences extend beyond technical exploitation to regulatory compliance failures and patient privacy breaches.

How Synack’s Autonomous AI Agent Identifies and Exploits a SQL Injection Vulnerability
Portswigger representation of how to approach an SQL injection. In the following scenario, the target application uses a tracking cookie that is vulnerable to SQL injection. However, the vulnerability is “blind” and does not return any data directly. The agent must use time delays to infer information.