Sign in

XBOW

@xbow.com
456 followers 9 following 175 posts

Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. xbow.com

PostsRepliesMedia
XBOW @xbow.com · 27/07/2026
When was the last time you saw an AMQ computer in person? 🤘 We meant it when we said we're bringing all the nostalgia vibes to Black Hat...see you there at booth 3448: xbow.com/events/black...
000
XBOW @xbow.com · 23/07/2026
Read Nico Waisman’s report on how we found critical bugs in Bing Images, one of the most heavily visited pages on the Internet, hidden in plain sight. xbow.com/blog/bing-im...
000
XBOW @xbow.com · 30/06/2026
Most security tools answer one question: what weaknesses exist here? They return a list, each item scored on its own. But attackers chain weaknesses. Finding these chains has historically required expensive human expertise. XBOW does this autonomously. Find out how: xbow.com/whitepapers/...
010
XBOW @xbow.com · 25/06/2026
“Exploit proof” needs to rise to the top of your remediation program as a key modifier for findings, says Moderna Deputy CISO Farzan Karimi in a recent webinar with XBOW co-founder Nico Waisman. Hear more from Farzan below. Watch full webinar recording here: bit.ly/4eIForC
000
XBOW @xbow.com · 24/06/2026
The Five Eyes cyber security agencies confirmed that AI-driven cyber risk is imminent. As the gap between discovery and exploitation shrinks, continuous, autonomous security testing becomes essential. That's the problem XBOW was built to solve. Read the full statement: bit.ly/4vsuzkh
031
XBOW @xbow.com · 24/06/2026
How does XBOW identify business logic flaws? Hear from XBOW security researcher Alvaro Muñoz in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: bit.ly/4fKEpsP
000
XBOW @xbow.com · 23/06/2026
In a new episode of the Cyberwire podcast, “Vulnerability response. Built for humans, outpaced by machines,” XBOW Head of Security Labs Federico Kirschbaum shares his perspective on vulnerability management when frontier models are finding the flaws. Listen to the episode: bit.ly/4epV5ov
011
XBOW @xbow.com · 23/06/2026
What would it take to build an AI-powered offensive security tool? We highlight the cost below. Get full details in our new whitepaper: bit.ly/4eqcEDH
000
XBOW @xbow.com · 22/06/2026
AI Tinkerers is hosting an offensive security demo night on June 25 with XBOW. Live exploits, autonomous pentesting, LLM-assisted vulnerability discovery, code walkthroughs, and technical Q&A. No decks. No pitches. Working systems only. RSVP: bit.ly/3SdPtVS
110
XBOW @xbow.com · 18/06/2026
Why are design flaws like IDOR so hard to find with automation? XBOW security researcher Alvaro Muñoz explains in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: bit.ly/4fKEpsP
000
XBOW @xbow.com · 17/06/2026
If an organization can point a powerful language model at an application and unearth findings, is it effectively running a penetration test? Our new whitepaper breaks down where LLMs are powerful tools for pentesting, and where they need more support: bit.ly/4eqcEDH
020
XBOW @xbow.com · 16/06/2026
We're honored that XBOW has been named a winner of Fast Company's 2026 World Changing Ideas Awards in the Business Products & Services category. This recognition reflects the work of our partners & research team, who believe the future of security is autonomous offense. More: bit.ly/4epnGca
000
XBOW @xbow.com · 11/06/2026
Samsung SDS announced that it is partnering with XBOW to strengthen its cybersecurity capabilities, using XBOW to uncover hidden vulnerabilities through attack simulations and accelerate identification and remediation with unmatched speed and precision. Get details: bit.ly/4oo3zjs
021
XBOW @xbow.com · 10/06/2026
“AI is changing the story of design flaw identification, says XBOW security researcher Alvaro Muñoz in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: bit.ly/4fKEpsP
000
XBOW @xbow.com · 09/06/2026
Great spending time with the GuidePoint Security team and customers this week at the GuidePoint Security Golf Classic at Terry Hills. As attack surfaces grow and vulnerabilities multiply, strong partnerships matter. Together, we're helping organizations validate real, exploitable risk.
000
XBOW @xbow.com · 08/06/2026
How does AI pentesting work? What should you look for? Get some guidance in our blog post "How to Evaluate an AI Pentesting Vendor: A Decision Framework for Security Leaders." bit.ly/4edHyPM
000
XBOW @xbow.com · 05/06/2026
• Why can't traditional pentests keep up with modern attack surfaces? • What stops an autonomous pentesting agent from causing real damage in production? Our CISO answers these questions and more on the Security You Should Know podcast. Listen to the full episode: bit.ly/4eiMXWM
010
XBOW @xbow.com · 05/06/2026
Moderna Deputy CISO Farzan Karimi shared how XBOW uncovered attack paths human testers missed, including one that took down a development environment during a trial. This @cyberscoop.bsky.social piece examines what happens when offensive security moves at machine speed: bit.ly/4va5Pxr
000
XBOW @xbow.com · 04/06/2026
One theme came up repeatedly at InfoSecurity Europe: ➡️ Security teams want proof, not possibility. Great discussions all week with leaders thinking about autonomous offensive security and operational validation at scale. Thanks to everyone who connected with our team.
000
XBOW @xbow.com · 04/06/2026
On June 10, XBOW CISO Nico Waisman and Moderna Deputy CISO Farzan Karimi will discuss the impact of autonomous, continuous, and exploit-validated offensive security in today’s AI threat landscape. Join us: bit.ly/42zUvxV
000
XBOW @xbow.com · 03/06/2026
GPT-5.5 is now part of XBOW. In our testing, GPT-5.5 delivered major gains in vulnerability discovery, exploit reasoning, application interaction, and autonomous testing. Models provide the intelligence. XBOW turns it into autonomous application security. Read more: bit.ly/4ufvhAb
010
XBOW @xbow.com · 02/06/2026
Thank you to everyone who joined yesterday's #GartnerSEC session with Farzan Karimi and Troy West of Moderna to learn how they're building an autonomous offensive security program with XBOW! It’s day two, and we’re ready to talk all things autonomous offensive security. Find us at booth 1028!
000
XBOW @xbow.com · 02/06/2026
Today at #Infosec2026, attendees will get a chance to put offensive security to the test during our workshop: Offensive AI in Practice. See firsthand how AI amplifies attackers’ abilities and how offensive security tools find, exploit, validate, and remediate them. Register: bit.ly/4d9cd19
001
XBOW @xbow.com · 02/06/2026
Our team is at #Infosec2026 today through Thursday! Stop by booth F-135 to say hi to the team 👋 and learn how your organization can scale offensive security with XBOW. 🏹 bit.ly/3P1Vkwj
000
XBOW @xbow.com · 01/06/2026
If you’re at Gartner Security & Risk Management Summit today, find the XBOW team at booth 1028 📍 to learn about autonomous offensive security and how it’s enabling teams to defend against complex and evolving cyberthreats faster, better, and at scale: gtnr.it/2Mf36ll #GartnerSEC
000
XBOW @xbow.com · 01/06/2026
Attending Gartner Security & Risk Management Summit? Tune in as Moderna’s Farzan Karimi and Troy West take the stage to share how XBOW enables them to meet the demands of today’s AI-driven cybersecurity landscape. 🔔 TODAY at 02:05 PM EDT: gtnr.it/4nQofA6 #GartnerSEC
000
XBOW @xbow.com · 29/05/2026
On June 16 at 11AM EDT, XBOW Lead Solutions Architect Bill Reyor will break down why security leaders are moving beyond periodic assessments toward continuous offensive security testing. If your exposure changes daily, your testing strategy should too. Register at the link: bit.ly/42Nm472
000
XBOW @xbow.com · 29/05/2026
Finding IDORs with automation is hard. Most tools stop at "Can I access this?". XBOW had to answer, "Should I be able to?" Here’s how we did it. bit.ly/4fKEpsP
001
XBOW @xbow.com · 28/05/2026
Meet XBOW at the Gartner Security & Risk Management Summit next week at Booth 1028! 📍 Plus, don't miss Moderna’s session where Farzan Karimi and Troy West will discuss how they’re working with XBOW to dramatically increase the speed, scale, and continuity of testing: gtnr.it/4nQofA6
000
XBOW @xbow.com · 28/05/2026
The Future of Pen Testing Is Continuous Security Testing Gartner® research on why point-in-time testing can no longer keep pace and what security leaders are doing instead. Download the report now: bit.ly/4dpavZF
000
XBOW @xbow.com · 27/05/2026
In less than two weeks at Infosecurity Europe 2026, XBOW will lead a hands-on workshop: Offensive AI in Practice. 📍 June 2nd, 2pm BST South Gallery Room 18 @ ExCeL London Secure your spot: bit.ly/4d9cd19
000
XBOW @xbow.com · 26/05/2026
Finding vulnerabilities is becoming easier. Validating what actually matters is the hard part. SecurityWeek highlights XBOW’s benchmarking of Anthropic’s Mythos Preview across vulnerability discovery, reverse engineering, and exploit validation tasks. Here are the findings: bit.ly/4tKZCGE
010
XBOW @xbow.com · 26/05/2026
Find advice from our recent panel discussion at RSAC with Nico Waisman, XBOW CISO; Jason Haddix, Arcanum CEO; Dave Aitel, Technical Staff, OpenAI, below, and get all their insights in our new whitepaper, The Next Six Months of Offensive Security: What CISOs Need to Change Now: bit.ly/4dijSZS
021
XBOW @xbow.com · 22/05/2026
XBOW found CVE-2026-45185, reported it responsibly, then used the disclosure window to test a harder question: How far can autonomous exploit development go against real-world native code? Full write-up here: bit.ly/42yKTmX
011
XBOW @xbow.com · 21/05/2026
What’s holding security teams back? Find out your peers’ 2026 challenges, priorities, and strategies in this year’s 2026 Cyberthreat Defense Report by CyberEdge Group, sponsored in part by XBOW: bit.ly/4udV6kK
000
XBOW @xbow.com · 20/05/2026
In BleepingComputer, Bill Toulas covers XBOW’s discovery of CVE-2026-45185, a critical unauthenticated Exim RCE, and the crucial role AI tools play in helping security researchers to understand unfamiliar code and investigate vulnerabilities faster. Read on: bit.ly/3Rg6MoM
100
XBOW @xbow.com · 20/05/2026
Join us at Infosecurity Europe 2026 to meet the team behind XBOW and learn how autonomous offensive security is revolutionizing modern AppSec programs. Book time with the team for demos, conversations, and a closer look at AI-driven offensive security in practice: bit.ly/3P1Vkwj
001
XBOW @xbow.com · 19/05/2026
One key takeaway after analyzing Mythos Preview for 2 months: powerful for source code audits, less so for validating exploits. See our full evaluation: bit.ly/42zQl98
000
XBOW @xbow.com · 18/05/2026
Join XBOW CISO Nico Waisman and Moderna Deputy CISO Farzan Karimi, on June 10 for a virtual coffee and chocolate tasting with security leaders. We’ll discuss what risk-based security looks like when offensive capability operates at machine speed. RSVP to claim your spot: bit.ly/42zUvxV
000
XBOW @xbow.com · 14/05/2026
Our new whitepaper, The Next Six Months of Offensive Security: What CISOs Need to Change Now, highlights the perspectives shared and the RSAC panelists’ thoughts about, questions on, and recommendations for this next phase of cybersecurity. Explore the whitepaper: bit.ly/4dijSZS
000
XBOW @xbow.com · 14/05/2026
At Infosecurity Europe 2026, we’re hosting a hands-on workshop where participants will use open source offensive tooling and AI models to safely exploit vulnerable applications in a controlled environment. June 2 | 2pm BST | ExCeL London Save your spot: bit.ly/4d9cd19
000
XBOW @xbow.com · 13/05/2026
We are pleased to announce that we have joined the @awscloud.bsky.social Independent Software Vendor (ISV) Accelerate Program, a co-sell program for AWS Partners that provides software solutions that run on or integrate with AWS. Get details: bit.ly/4nlYaIY
000
XBOW @xbow.com · 12/05/2026
For the past 2 months, XBOW has been testing Mythos Preview under embargo as part of a select early-access group. Findings: Mythos Preview is a major advance, but it’s not perfect. Read where it shines, where it needs support, and what this means for offensive security: bit.ly/42zQl98
051
XBOW @xbow.com · 07/05/2026
The flood of vulnerabilities coming from Mythos won’t all be exploitable. CEO and CISO Jason Haddix and XBOW AI researcher Brendan Dolan-Gavitt discuss in the clip below. Watch their full discussion on “security in a post-Mythos world” here: bit.ly/4mHo3Te
021
XBOW @xbow.com · 06/05/2026
🏹 XBOW Extends Its Series C, Securing an Additional $35M From Strategic Investors The raise, which includes participation from customers and partners, highlights that enterprises are not just adopting XBOW’s platform, but investing in it. Learn more: bit.ly/4d37ZXz
010
XBOW @xbow.com · 05/05/2026
In our benchmark, GPT-5 missed 40% of vulnerabilities. Opus 4.6 reduced that to 18%. GPT-5.5 brings it down further to just 10%. When you’re running automated security testing, closing that gap matters. Get details in our blog post: bit.ly/48OX7v6
040
XBOW @xbow.com · 01/05/2026
“A lot of the conjecture about how good this model is is based on source code scanning,” says CEO and CISO Jason Haddix in our recent LinkedIn Live on “security in a post-Mythos world.” Hear more from the discussion between Jason and XBOW AI researcher Brendan Dolan-Gavitt: bit.ly/4mHo3Te
020
XBOW @xbow.com · 30/04/2026
Can LLMs transform pentesting? Yes. But not in isolation. It takes more than a model to make AI pentesting truly enterprise-ready. Learn more below. Get full details in blog post by XBOW Head of AI Albert Ziegler: bit.ly/4cb0o90
011
XBOW @xbow.com · 29/04/2026
Big milestone for XBOW and the industry 🚀 For the first time, an autonomous AI hacker ranked in the top 10 of Microsoft’s Security Response Center leaderboard. In Q1 2026, XBOW ranked 7️⃣ More details in blog ⬇️ bit.ly/4bNBgWT
001
XBOW @xbow.com · 28/04/2026
From automation to autonomy. Mathew Payne, Field Security at XBOW, took the stage at Black Hat Asia to break down what agentic AI means for offensive security testing—and why the shift is already underway. Appreciate everyone who joined the session in Singapore and pushed the conversation forward.
001