Sign in

XBOW

@xbow.com
456 followers 9 following 175 posts

Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. xbow.com

PostsRepliesMedia
Reposted by XBOW
Unprompted AU @unprompted.au · 26/08/2026
@moyix.net has LLM agents reverse-engineering the currency detectors inside photocopiers, then building a cat you can't photocopy. His conclusion: obscurity buys days now, not years. unprompted.au/schedule?utm... #AI #infosec
unprompted.au
Schedule — [un]prompted.au 2026
Explore 24 sessions across two days of original AI and cybersecurity research at ILUMINA, Sydney, 18–19 September 2026.
143
XBOW @xbow.com · 27/07/2026
When was the last time you saw an AMQ computer in person? 🤘 We meant it when we said we're bringing all the nostalgia vibes to Black Hat...see you there at booth 3448: xbow.com/events/black...
000
XBOW @xbow.com · 23/07/2026
Read Nico Waisman’s report on how we found critical bugs in Bing Images, one of the most heavily visited pages on the Internet, hidden in plain sight. xbow.com/blog/bing-im...
000
XBOW @xbow.com · 23/07/2026
TL;DR: Give an autonomous agent enough freedom and proper safeguards, and it will find an amazing zero-day without waking up your blue team.
100
XBOW @xbow.com · 23/07/2026
Earlier this year, XBOW broke into the top 10 of the Microsoft Security Response Center(MSRC) leaderboard as the first and o nly AI in the ranking. Now we're finally able to disclose some of the coolest bugs we found.
121
XBOW @xbow.com · 07/07/2026
We are pleased to announce that XBOW has achieved Application Security distinction for the special Autonomous Security Validation use case within the @awscloud.bsky.social (AWS) Security Competency. Learn more: xbow.com/news/xbow-ac...
xbow.com
XBOW Achieves AWS Security Competency Status | XBOW
XBOW earns AWS Security Competency status, recognizing its autonomous security validation platform for continuous application security testing on AWS.
020
XBOW @xbow.com · 30/06/2026
Most security tools answer one question: what weaknesses exist here? They return a list, each item scored on its own. But attackers chain weaknesses. Finding these chains has historically required expensive human expertise. XBOW does this autonomously. Find out how: xbow.com/whitepapers/...
010
XBOW @xbow.com · 25/06/2026
“Exploit proof” needs to rise to the top of your remediation program as a key modifier for findings, says Moderna Deputy CISO Farzan Karimi in a recent webinar with XBOW co-founder Nico Waisman. Hear more from Farzan below. Watch full webinar recording here: bit.ly/4eIForC
000
XBOW @xbow.com · 24/06/2026
The Five Eyes cyber security agencies confirmed that AI-driven cyber risk is imminent. As the gap between discovery and exploitation shrinks, continuous, autonomous security testing becomes essential. That's the problem XBOW was built to solve. Read the full statement: bit.ly/4vsuzkh
031
XBOW @xbow.com · 24/06/2026
How does XBOW identify business logic flaws? Hear from XBOW security researcher Alvaro Muñoz in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: bit.ly/4fKEpsP
000
XBOW @xbow.com · 23/06/2026
In a new episode of the Cyberwire podcast, “Vulnerability response. Built for humans, outpaced by machines,” XBOW Head of Security Labs Federico Kirschbaum shares his perspective on vulnerability management when frontier models are finding the flaws. Listen to the episode: bit.ly/4epV5ov
011
XBOW @xbow.com · 23/06/2026
What would it take to build an AI-powered offensive security tool? We highlight the cost below. Get full details in our new whitepaper: bit.ly/4eqcEDH
000
XBOW @xbow.com · 22/06/2026
AI Tinkerers is hosting an offensive security demo night on June 25 with XBOW. Live exploits, autonomous pentesting, LLM-assisted vulnerability discovery, code walkthroughs, and technical Q&A. No decks. No pitches. Working systems only. RSVP: bit.ly/3SdPtVS
110
XBOW @xbow.com · 18/06/2026
Why are design flaws like IDOR so hard to find with automation? XBOW security researcher Alvaro Muñoz explains in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: bit.ly/4fKEpsP
000
XBOW @xbow.com · 17/06/2026
If an organization can point a powerful language model at an application and unearth findings, is it effectively running a penetration test? Our new whitepaper breaks down where LLMs are powerful tools for pentesting, and where they need more support: bit.ly/4eqcEDH
020
XBOW @xbow.com · 16/06/2026
We're honored that XBOW has been named a winner of Fast Company's 2026 World Changing Ideas Awards in the Business Products & Services category. This recognition reflects the work of our partners & research team, who believe the future of security is autonomous offense. More: bit.ly/4epnGca
000
XBOW @xbow.com · 12/06/2026
LLMs excel at following instructions, but not always at identifying which instructions to trust. XBOW Head of AI Albert Ziegler explains why prompt injection risk grows alongside AI agency and enterprise access in IBT Media. Read on: bit.ly/3S3pZdO
bit.ly
Gemini Prompt Injection Shows AI Adoption is Increasing Risk for Companies
AI chatbots and assistants are extremely vulnerable to exploitation, particularly prompt injection, according to new research.
000
XBOW @xbow.com · 11/06/2026
Samsung SDS announced that it is partnering with XBOW to strengthen its cybersecurity capabilities, using XBOW to uncover hidden vulnerabilities through attack simulations and accelerate identification and remediation with unmatched speed and precision. Get details: bit.ly/4oo3zjs
021
XBOW @xbow.com · 10/06/2026
“AI is changing the story of design flaw identification, says XBOW security researcher Alvaro Muñoz in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: bit.ly/4fKEpsP
000
XBOW @xbow.com · 09/06/2026
Great spending time with the GuidePoint Security team and customers this week at the GuidePoint Security Golf Classic at Terry Hills. As attack surfaces grow and vulnerabilities multiply, strong partnerships matter. Together, we're helping organizations validate real, exploitable risk.
000
XBOW @xbow.com · 08/06/2026
“Is my application security program built for a world where everyone is a coder?” Read why our CISO, Nico Waisman, believes this question should be top of mind for today’s CISOs in CSO Online: bit.ly/4um5upQ
csoonline.com
15 tough cybersecurity questions every CISO must answer
From anticipating new threats to balancing risk management and business enablement, CISOs face a range of complex challenges that require continual reflection and strategic execution.
000
XBOW @xbow.com · 08/06/2026
How does AI pentesting work? What should you look for? Get some guidance in our blog post "How to Evaluate an AI Pentesting Vendor: A Decision Framework for Security Leaders." bit.ly/4edHyPM
000
XBOW @xbow.com · 05/06/2026
• Why can't traditional pentests keep up with modern attack surfaces? • What stops an autonomous pentesting agent from causing real damage in production? Our CISO answers these questions and more on the Security You Should Know podcast. Listen to the full episode: bit.ly/4eiMXWM
010
XBOW @xbow.com · 05/06/2026
Moderna Deputy CISO Farzan Karimi shared how XBOW uncovered attack paths human testers missed, including one that took down a development environment during a trial. This @cyberscoop.bsky.social piece examines what happens when offensive security moves at machine speed: bit.ly/4va5Pxr
000
XBOW @xbow.com · 04/06/2026
One theme came up repeatedly at InfoSecurity Europe: ➡️ Security teams want proof, not possibility. Great discussions all week with leaders thinking about autonomous offensive security and operational validation at scale. Thanks to everyone who connected with our team.
000
XBOW @xbow.com · 04/06/2026
On June 10, XBOW CISO Nico Waisman and Moderna Deputy CISO Farzan Karimi will discuss the impact of autonomous, continuous, and exploit-validated offensive security in today’s AI threat landscape. Join us: bit.ly/42zUvxV
000
XBOW @xbow.com · 03/06/2026
GPT-5.5 is now part of XBOW. In our testing, GPT-5.5 delivered major gains in vulnerability discovery, exploit reasoning, application interaction, and autonomous testing. Models provide the intelligence. XBOW turns it into autonomous application security. Read more: bit.ly/4ufvhAb
010
XBOW @xbow.com · 02/06/2026
Thank you to everyone who joined yesterday's #GartnerSEC session with Farzan Karimi and Troy West of Moderna to learn how they're building an autonomous offensive security program with XBOW! It’s day two, and we’re ready to talk all things autonomous offensive security. Find us at booth 1028!
000
XBOW @xbow.com · 02/06/2026
Today at #Infosec2026, attendees will get a chance to put offensive security to the test during our workshop: Offensive AI in Practice. See firsthand how AI amplifies attackers’ abilities and how offensive security tools find, exploit, validate, and remediate them. Register: bit.ly/4d9cd19
001
XBOW @xbow.com · 02/06/2026
Our team is at #Infosec2026 today through Thursday! Stop by booth F-135 to say hi to the team 👋 and learn how your organization can scale offensive security with XBOW. 🏹 bit.ly/3P1Vkwj
000
XBOW @xbow.com · 01/06/2026
If you’re at Gartner Security & Risk Management Summit today, find the XBOW team at booth 1028 📍 to learn about autonomous offensive security and how it’s enabling teams to defend against complex and evolving cyberthreats faster, better, and at scale: gtnr.it/2Mf36ll #GartnerSEC
000
XBOW @xbow.com · 01/06/2026
Attending Gartner Security & Risk Management Summit? Tune in as Moderna’s Farzan Karimi and Troy West take the stage to share how XBOW enables them to meet the demands of today’s AI-driven cybersecurity landscape. 🔔 TODAY at 02:05 PM EDT: gtnr.it/4nQofA6 #GartnerSEC
000
XBOW @xbow.com · 29/05/2026
AI models are getting better at finding vulnerabilities, but detection alone isn’t enough. @cyberscoop.bsky.social covers the early results on Mythos Preview, including XBOW’s evaluation. Read more: bit.ly/4e4JqeC
bit.ly
Anthropic: Mythos finds more than 10,000 software flaws in first month
Anthropic’s Mythos model uncovers over 10,000 critical software flaws in its first month, shifting the cyber challenge from finding bugs to patching them.
011
XBOW @xbow.com · 29/05/2026
AI models are getting better at finding vulnerabilities, but detection alone isn’t enough. @cyberscoop.bsky.social covers the early results on Mythos Preview, including XBOW’s evaluation. Read more: bit.ly/4e4JqeC
bit.ly
Anthropic: Mythos finds more than 10,000 software flaws in first month
Anthropic’s Mythos model uncovers over 10,000 critical software flaws in its first month, shifting the cyber challenge from finding bugs to patching them.
000
XBOW @xbow.com · 29/05/2026
On June 16 at 11AM EDT, XBOW Lead Solutions Architect Bill Reyor will break down why security leaders are moving beyond periodic assessments toward continuous offensive security testing. If your exposure changes daily, your testing strategy should too. Register at the link: bit.ly/42Nm472
000
XBOW @xbow.com · 29/05/2026
Finding IDORs with automation is hard. Most tools stop at "Can I access this?". XBOW had to answer, "Should I be able to?" Here’s how we did it. bit.ly/4fKEpsP
001
XBOW @xbow.com · 28/05/2026
Meet XBOW at the Gartner Security & Risk Management Summit next week at Booth 1028! 📍 Plus, don't miss Moderna’s session where Farzan Karimi and Troy West will discuss how they’re working with XBOW to dramatically increase the speed, scale, and continuity of testing: gtnr.it/4nQofA6
000
XBOW @xbow.com · 28/05/2026
The Future of Pen Testing Is Continuous Security Testing Gartner® research on why point-in-time testing can no longer keep pace and what security leaders are doing instead. Download the report now: bit.ly/4dpavZF
000
XBOW @xbow.com · 27/05/2026
XBOW's @moyix.net recently joined @grahamcluley.com on the @smashingsecurity.com podcast to discuss: ° Some of the vulnerabilities XBOW has uncovered ° The pros and cons of AI for pentesting ° AI's impact on vulnerability discovery and disclosure ° And more Listen here: bit.ly/42SYK7R
bit.ly
Bot Verification
051
XBOW @xbow.com · 27/05/2026
In less than two weeks at Infosecurity Europe 2026, XBOW will lead a hands-on workshop: Offensive AI in Practice. 📍 June 2nd, 2pm BST South Gallery Room 18 @ ExCeL London Secure your spot: bit.ly/4d9cd19
000
XBOW @xbow.com · 26/05/2026
Finding vulnerabilities is becoming easier. Validating what actually matters is the hard part. SecurityWeek highlights XBOW’s benchmarking of Anthropic’s Mythos Preview across vulnerability discovery, reverse engineering, and exploit validation tasks. Here are the findings: bit.ly/4tKZCGE
010
XBOW @xbow.com · 26/05/2026
Find advice from our recent panel discussion at RSAC with Nico Waisman, XBOW CISO; Jason Haddix, Arcanum CEO; Dave Aitel, Technical Staff, OpenAI, below, and get all their insights in our new whitepaper, The Next Six Months of Offensive Security: What CISOs Need to Change Now: bit.ly/4dijSZS
021
XBOW @xbow.com · 22/05/2026
XBOW found CVE-2026-45185, reported it responsibly, then used the disclosure window to test a harder question: How far can autonomous exploit development go against real-world native code? Full write-up here: bit.ly/42yKTmX
011
XBOW @xbow.com · 21/05/2026
What’s holding security teams back? Find out your peers’ 2026 challenges, priorities, and strategies in this year’s 2026 Cyberthreat Defense Report by CyberEdge Group, sponsored in part by XBOW: bit.ly/4udV6kK
000
XBOW @xbow.com · 20/05/2026
In BleepingComputer, Bill Toulas covers XBOW’s discovery of CVE-2026-45185, a critical unauthenticated Exim RCE, and the crucial role AI tools play in helping security researchers to understand unfamiliar code and investigate vulnerabilities faster. Read on: bit.ly/3Rg6MoM
100
XBOW @xbow.com · 20/05/2026
Join us at Infosecurity Europe 2026 to meet the team behind XBOW and learn how autonomous offensive security is revolutionizing modern AppSec programs. Book time with the team for demos, conversations, and a closer look at AI-driven offensive security in practice: bit.ly/3P1Vkwj
001
XBOW @xbow.com · 19/05/2026
One key takeaway after analyzing Mythos Preview for 2 months: powerful for source code audits, less so for validating exploits. See our full evaluation: bit.ly/42zQl98
000
XBOW @xbow.com · 18/05/2026
“XBOW found that Mythos was ‘good, but less powerful, at validating exploits’ and that the model could be ‘too literal and conservative,’ sometimes overstating the practical significance of its findings,” writes Sam Sabin in @axios.com. More on our analysis of Mythos Preview: bit.ly/4tA87Eo
bit.ly
The next phase of AI cybersecurity still needs humans
The new phase of AI-powered cybersecurity depends on how effectively humans can direct these models.
012
XBOW @xbow.com · 18/05/2026
Join XBOW CISO Nico Waisman and Moderna Deputy CISO Farzan Karimi, on June 10 for a virtual coffee and chocolate tasting with security leaders. We’ll discuss what risk-based security looks like when offensive capability operates at machine speed. RSVP to claim your spot: bit.ly/42zUvxV
000
XBOW @xbow.com · 15/05/2026
The Hacker News’s Ravie Lakshmanan covers a newly disclosed Exim vulnerability discovered and responsibly reported by XBOW. Research like this helps uncover high-impact vulnerabilities before attackers do. Read more in @thehackernews.com.web.brid.gy ⬇️
010