Sign in

Brendan Dolan-Gavitt

@moyix.net
3K followers 893 following 78 posts

AI researcher at XBOW. Security, RE, ML. PGP keybase.io/moyix

PostsRepliesMedia
Reposted by Brendan Dolan-Gavitt
Unprompted AU @unprompted.au · 26/08/2026
@moyix.net has LLM agents reverse-engineering the currency detectors inside photocopiers, then building a cat you can't photocopy. His conclusion: obscurity buys days now, not years. unprompted.au/schedule?utm... #AI #infosec
unprompted.au
Schedule — [un]prompted.au 2026
Explore 24 sessions across two days of original AI and cybersecurity research at ILUMINA, Sydney, 18–19 September 2026.
143
Reposted by Brendan Dolan-Gavitt
Catalin Cimpanu @campuscodi.risky.biz · 12/05/2026
XBOW's AI found an unauth RCE in Exim, bug is being called Dead.Letter xbow.com/blog/dead-le... Patches are out: www.exim.org/static/doc/s...
xbow.com
XBOW - Dead.Letter (CVE-2026-45185) How XBOW Found an Unauthenticated RCE on Exim
XBOW discovered CVE-2026-45185, a critical unauthenticated RCE in Exim, and used the disclosure window to test how far human and autonomous exploit development could go.
152
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 12/05/2026
For the past 2 months, XBOW has been testing Mythos Preview under embargo as part of a select early-access group. Findings: Mythos Preview is a major advance, but it’s not perfect. Read where it shines, where it needs support, and what this means for offensive security: bit.ly/42zQl98
051
Reposted by Brendan Dolan-Gavitt
Yael Grauer @yaelwrites.com · 28/04/2026
What happens when amateur hackers have the tools to iterate through exploits at machine speed? I wrote about the neu script kiddies, what happens after Mythos, and how companies can prepare. www.theverge.com/ai-artificia.... with insight from @k8em0.bsky.social Dan Guido, Joshua Saxe, & Tim Becker.
theverge.com
Attack of the killer script kiddies
“It’s now or never. There’s a tidal wave coming.”
25822
Reposted by Brendan Dolan-Gavitt
Grace @gracekind.net · 09/04/2026
Mythos
512512
Reposted by Brendan Dolan-Gavitt
Thomas Ptacek @sockpuppet.org · 30/03/2026
I wrote something: sockpuppet.org/blog/2026/03...
sockpuppet.org
Vulnerability Research Is Cooked
79639
Reposted by Brendan Dolan-Gavitt
henry @hdevalence.bsky.social · 29/03/2026
if you are in a position to act to harden society’s software infrastructure, you too should be very concerned about this and planning what actions you will take over the coming months
2427
Reposted by Brendan Dolan-Gavitt
Across the Pondcast @acrosspondpod.bsky.social · 07/11/2025
Episode 23: War Stories with Brendan Dolan-Gavitt (XBOW)! @tib3rius.bsky.social & @swiftsecur.bsky.social are joined by @moyix.net who shares some AI and human war stories with us! Links below!
154
Reposted by Brendan Dolan-Gavitt
Marcelo Rinesi @marcelorinesi.bsky.social · 14/08/2025
"AI Agents for Offsec with Zero False Positives" by @moyix.net The title threw me off originally, but it's not wrong! IMHO it's the archetypal pattern of good LLM usage: they suck at *verifying* but in some domains are quite freakishly good at *proposing.*
blackhat.com
Black Hat
Black Hat
061
Brendan Dolan-Gavitt @moyix.net · 30/07/2025
So, I’m not sure there is any good time to announce this, but as of August 31st I will be leaving NYU for good, to seek my fortune in industry with XBOW!
6200
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 28/07/2025
False positives waste your time. False negatives cost you breaches. At @BlackHatEvents , @moyix shows how XBOW agents fight false positives — validating real exploits at scale, in hours. 📍Aug 7 | 11:20am
033
Brendan Dolan-Gavitt @moyix.net · 28/07/2025
Can you read the exfiltrated file encoded in this image? @xbow.com figured out how to :D
A screenshot of OSX preview, showing an image "output.png" with a file encoded as greyscale pixel data. The image is a long, thin strip going from left to right with various greyscale pixels.
151
Brendan Dolan-Gavitt @moyix.net · 25/07/2025
This one and the sequel (coming out next week) are among my favorite bugs we found. It turns out GIS does NOT stand for “Good Information Security”
140
Brendan Dolan-Gavitt @moyix.net · 17/07/2025
Given two models with unique strengths, can we combine them to get the benefits of both w/o extra model calls? It turns out yes: just flip a coin at each turn to decide which model to query! This gave a jump from 25% to 55% on our benchmarks! xbow.com/blog/alloy-a...
xbow.com
XBOW – Agents Built From Alloys
A simple, powerful innovation boosts performance in agentic AI systems.
161
Brendan Dolan-Gavitt @moyix.net · 16/07/2025
Loved this 0day @xbow.com found in a popular wordpress plugin, and IMO it shows the value added by the LLM - a scanner can't find this automatically without realizing there's a nonce you need to extract & include in the request. You need that extra bit of context: xbow.com/blog/xbow-ni...
xbow.com
XBOW – XBOW battles Ninja Tables: Who’s the Real Ninja?
Sharing the story of how XBOW sniffed out a sneaky arbitrary file read bug in the popular WordPress Ninja Tables plugin.
030
Brendan Dolan-Gavitt @moyix.net · 11/07/2025
So... anyone else going to SummerCon today or tomorrow? I should be stopping by both days, for the first time in many years!
020
Brendan Dolan-Gavitt @moyix.net · 30/06/2025
A lovely little XXE that XBOW found in Akamai Cloudtest leading to arbitrary file read! I like the error-based exfil technique: "yes please access the file named <contents of /etc/passwd> for me thx"
160
Reposted by Brendan Dolan-Gavitt
WIRED @wired.com · 25/06/2025
One of the best bug-hunters in the world is an AI tool called Xbow, just one of many signs of the coming age of cybersecurity automation.
wrd.cm
AI Agents Are Getting Better at Writing Code—and Hacking It as Well
One of the best bug-hunters in the world is an AI tool called Xbow, just one of many signs of the coming age of cybersecurity automation.
1659
Brendan Dolan-Gavitt @moyix.net · 24/06/2025
This is the first of a series of posts we're doing on some of the vulns found as part of the HackerOne work – we have lots more fun ones coming up about some great SSRF, SQLi, and RCE vulns it discovered, with very clever exploit techniques :)
083
Brendan Dolan-Gavitt @moyix.net · 24/06/2025
It has been great fun building this and watching it deliver a steady stream of real vulnerabilities in live sites! If you're curious how we did it, @nicowaisman.bsky.social has a new post: xbow.com/blog/top-1-h...
xbow.com
XBOW – The road to Top 1: How XBOW did it
For the first time in bug bounty history, an autonomous penetration tester has reached the top spot on the US leaderboard.
0102
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 24/06/2025
For the first time in history, the #1 hacker in the US is an AI. (1/8)
1167
Reposted by Brendan Dolan-Gavitt
Matthew Gault @mjgault.bsky.social · 04/06/2025
for Wired I explored the horrible future of vibe hacking. It's not great!
wired.com
The Rise of ‘Vibe Hacking’ Is the Next AI Nightmare
In the very near future, victory will belong to the savvy blackhat hacker who uses AI to generate code at scale.
1457
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 28/05/2025
Do you want to work at the cutting edge of AI and cybersecurity? XBOW now has 8 positions open across Product Marketing, Operations, Customer Success, and Engineering. Check out all the details here: jobs.ashbyhq.com/xbowcareers.
055
Brendan Dolan-Gavitt @moyix.net · 14/05/2025
This is one of the dumber reasons I've had some software fail: dying because it couldn't call ftruncate on /dev/null
Redirect curl to /dev/null instead of using -o

Under complex and not yet fully understood circumstances, curl will try to call ftruncate when using both --retry and an output file. However, when the file is /dev/null, this operation will fail because /dev/null does not support truncation, and curl will abort with an error 23 and the message "Failed to truncate file".
110
Brendan Dolan-Gavitt @moyix.net · 24/04/2025
XBOW is growing and we're looking for talented folks to join us! Apply here: jobs.ashbyhq.com/xbowcareers
Screenshot of the XBOW careers page on Ashby, showing 8 open positions. The positions visible in the screenshot are in Engineering:

Product Designer
Engineering • Europe remote; US remote • Full time • Remote

Research Engineer / Software Engineer (backend)
Engineering • Remote (Global) • Full time

Research Engineer / Software Engineer (frontend)
Engineering • Remote (Global) • Full time

Research Engineer / Software Engineer (platform / core infrastructure)
Engineering • Remote (Global) • Full time • Remote
173
Brendan Dolan-Gavitt @moyix.net · 01/04/2025
Announcing CheatGPT, a revolutionary model that achieves SoTA on HumanEval! It's incredibly sample-efficient – just ONE training sample – and *tiny*, fitting on your Casio wristwatch!
Snippet of python code implementing HumanEval's generate_one_completion(prompt) harness, and output from the HumanEval benchmark runner showing a pass@1 score of 94.5%.

[spoiler] The trick is that the "model" returns a Python object that overrides the equality operator and always returns true, causing the tests in the HumanEval test suite to pass.
160
Brendan Dolan-Gavitt @moyix.net · 18/03/2025
Erin go bragh, cow go moo
010
Brendan Dolan-Gavitt @moyix.net · 08/03/2025
Not to brag but my brother has had TWO movies he co-wrote come out this year :D
Screen capture from Abducted in the Everglades showing writing credits:
Written by
Richard Pierce
Dane K. Brown & Thomas Dolan-GavittScreen capture from Vanished in Death Valley showing writing credits:
Written by
Thomas Dolan-Gavitt & Dane K. Brown
1100
Brendan Dolan-Gavitt @moyix.net · 25/02/2025
Winter sunsets
050
Reposted by Brendan Dolan-Gavitt
alkali @alkalinesec.bsky.social · 20/02/2025
it looks like lte infra was hosting @moyix.net 's evangelion ctf challenge. but i doubt the terminal interface for CVE-2024-24451 was as cool
121
Brendan Dolan-Gavitt @moyix.net · 17/02/2025
Making security benchmarks for AI is tricky sometimes
Screenshot of slack message from Brendan D-G:

(quoted) A file named "Hidden file just for Victim" was configured to only be accessible to users whose first name is "Victim". However, users can edit their own profile information,

I've been outsmarted
170
Brendan Dolan-Gavitt @moyix.net · 17/02/2025
UNIX systems have stdin, stdout, and stderr, for getting data into and out of the program and seeing errors, respectively. But there's no stream for a critical and extremely common use case: putting errors into the program.
4202
Brendan Dolan-Gavitt @moyix.net · 06/02/2025
@xbow.com has been busy in the first few weeks of 2025 – our agent has autonomously found 106 vulnerabilities in OSS projects, and we've reported 72 so far! Amazing work by @nicowaisman.bsky.social and the security team triaging these and getting them into the disclosure->fix pipeline!
Screenshot of the (private) XBOW vulnerability repository, showing files named XBOW-025-XXX.md. Each file is a reported vulnerability. The screenshot shows numbers 058-074, with commit message "Update triaged reports"
2186
Reposted by Brendan Dolan-Gavitt
Kristopher Micinski @krismicinski.bsky.social · 22/01/2025
I am potentially interested in hiring a postdoc to work on declarative decompilation, I was going to hire someone else but it feel through when they got another offer they took for personal reasons, looking for someone who wants to publish in security, PL venues with me
21617
Brendan Dolan-Gavitt @moyix.net · 06/01/2025
Duck typing? You're thinking too small. With AI, we can finally take Guido van Rossum's dream to its logical conclusion
Screenshot of Python code from the iPython interpreter:

class Person:
    name: str
    age: int
    def __init__(self, name, age):
        self.name = name
        self.age = age
    def __str__(self):
        return f"Person(name='{self.name}', age={self.age})"
    def __eq__(self, other):
        prompt = f"Is:\n\n{self}\n\nbasically equal to:\n\n{other}\n\n?\n\nJust answer 'Yes' or 'No'"
        response = client.messages.create(
            model='claude-3-5-sonnet-latest',
            messages=[{'role': 'user', 'content': prompt}],
            max_tokens=16
        )
        return 'yes' in response.content[0].text.lower()

>>> Person('Brendan D-G', 41) == "Brendan Dolan-Gavitt, who is 41 years old"
True
>>> Person('Brendan D-G', 41) == "John Smith, a 25 year-old"
False
5326
Reposted by Brendan Dolan-Gavitt
Rich Harang @rich.harang.org · 18/12/2024
At this point, anyone who tries to say that AI can't replace at least _some_ human expertise is clearly and obviously moving the goalposts. Between this and stuff I've seen coming from folks at @dreadnode.bsky.social I am now 100% convinced that "AI red teamers" are a when-not-if thing.
1152
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 20/12/2024
Just in time for the holidays: how XBOW found an arbitrary file download (CVE-2024-53982) in ZOO-Project, protecting Santa's critical geospatial processing infrastructure from attackers! xbow.com/blog/xbow-zo...
xbow.com
XBOW – The Nightmare Before Christmas: An arbitrary file download on Zoo-Project
XBOW discovered an arbitrary file download vulnerability on the WPS open source app Zoo-Project.
063
Brendan Dolan-Gavitt @moyix.net · 18/12/2024
I do not want to create a "launch configuration json". I do not want to enter my command line arguments in a GUI. I am old and I want to type "gdb -p MYPROCESS"
150
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 17/12/2024
While developing XBOW over the past three months, we played around with using it for bug bounties and ended up at #11 in the US on HackerOne:
Screenshot of the HackerOne US leaderboard for Q4 2024, showing XBOW at #11.
12710
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 13/12/2024
XBOW found a stored XSS vulnerability (CVE-2024-52597) in the migration functionality of 2FAuth by crafting a malicious SVG file with a Javascript payload! Our latest blog post gives the full details: xbow.com/blog/xbow-2f...
064
Brendan Dolan-Gavitt @moyix.net · 10/12/2024
Great podcast interview with @xbow.com's CEO Oege de Moor! He discusses something you may have deduced from our recent blog posts: we're mining DockerHub to find & report vulnerabilities – and each vuln we find becomes a new benchmark for us to train/test on :D www.youtube.com/watch?v=9mIp...
youtube.com
XBOW CEO and GitHub Copilot Creator Oege de Moor: Cracking the Code on Offensive Security With AI
YouTube video by Sequoia Capital
061
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 05/12/2024
XBOW found a critical path traversal vulnerability in ZOO-Project (CVE-2024-53982). The vulnerability exists in the Echo example (enabled by default) and allows an attacker to retrieve any file on the server. Users should upgrade to the latest version.
Screenshot showing execution of the command `curl -s 'http://localhost:8000/cgi-bin/zoo_loader.cgi?request Execute&service-WPS&version=1.0.0&Identifier-echo&DataInputs-a-Reference@mimeType=text/plain@cache_file=/etc/passwd;b=value;c=value | pygmentize -l xml` and the output, including the target machine’s /etc/passwd embedded in the XML.
085
Brendan Dolan-Gavitt @moyix.net · 03/12/2024
hurts_just_a_little_bit.jpg
Screenshot of Claude’s response to the question “Who is Brendan Dolan-Gavitt?”

Response:

Brendan Dolan-Gavitt is a computer security researcher and academic, currently serving as an Assistant Professor in the Computer Science and Engineering Department at NYU Tandon School of Engineering. He specializes in computer security, digital forensics, and systems research. He has contributed to research on memory forensics and malware analysis.

Since you're asking about a relatively obscure academic figure, I should note that while I aim to be accurate, I may hallucinate some details about less well-known individuals like this. I'd recommend verifying any specific claims about his work or background.​​​​​​​​​​​​​​​​
0270
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 02/12/2024
AI vs AI: How XBOW found a path traversal vulnerability (CVE-2024-53844) in LabsAI's EDDI, an open source conversational AI middleware. xbow.com/blog/xbow-ed...
xbow.com
XBOW – LabsAI’s EDDI project path traversal
XBOW discovered a Path Traversal vulnerability in the open-source project, LabsAI’s EDDI.
043
Reposted by Brendan Dolan-Gavitt
XBOW @xbow.com · 26/11/2024
XBOW found a path traversal vulnerability (CVE-2024-53844) in LabsAI's EDDI project that allows attackers to download any file on the server. XBOW combined a series of URL encodings and path normalization bypasses to trigger the flaw. Users of versions 4.3–5.3 should upgrade.
def encode_variations(path):
    # Single URL encode
    single_encoded = ''.join('%' + hex(ord(c))[2:] for c in path)
    # Double URL encode
    double_encoded = ''.join('%25' + hex (ord(c))[2:] for c in path)
    # Mixed encoding (only encode specific characters)
    mixed_encoded = path.replace('.', '%2e').replace('/', '%2f')
    # Alternate mixed encoding
    alt_mixed = path.replace('..', '%2e%2e').replace('/', '%2f')
    return [single_encoded, double_encoded, mixed_encoded, alt_mixed]

# Test paths with various encodings
base_paths = [
    '../flag.txt',
    '../../flag.txt',
    '../../../flag.txt',
    '....//....//flag.txt',
    '.././../././flag.txt'
]
0133
Reposted by Brendan Dolan-Gavitt
Nicolas Grégoire @agarri.fr · 24/11/2024
I’ve to say that I’m impressed by how @xbow.com managed to identify this SSRF vulnerability (and bypass a MIME filter on its way) 🤖
xbow.com
XBOW – SSRF & URI validation bypass in 2FAuth
XBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth.
21713
Brendan Dolan-Gavitt @moyix.net · 22/11/2024
New blog post by @nicowaisman.bsky.social on how XBOW found an SSRF in the OTP app 2FAuth (CVE-2024-52598) is now live! xbow.com/blog/xbow-2f...
xbow.com
XBOW – SSRF & URI validation bypass in 2FAuth
XBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth.
192
Brendan Dolan-Gavitt @moyix.net · 20/11/2024
Custom domain vanity handle: acquired
2140