Sign in

Xint by Theori

@xint-io.bsky.social
31 followers 3 following 201 posts

Go beyond AppSec that drowns teams with false positives and trivial bugs. Discover the business logic vulnerabilities traditional tools miss.

PostsRepliesMedia
Xint by Theori @xint-io.bsky.social · 30/09/2026
SecurityWeek spoke with our CTO and cofounder about our recently announced DARPA contract: www.securityweek.com/darpa-select...
securityweek.com
DARPA Selects Xint to Use AI in Securing Military Messaging Apps
DARPA selected Xint to use AI to find vulnerabilities in military messaging apps, with code and binary analysis technology.
100
Xint by Theori @xint-io.bsky.social · 29/09/2026
🚨🚨 DARPA has selected Xint to research the use of autonomous AI to conduct deep security analyses of internally and externally developed messaging applications used throughout the military. www.businesswire.com/news/home/20...
100
Xint by Theori @xint-io.bsky.social · 25/09/2026
What's the biggest dropoff between the POC of an AI cybersecurity product versus how it actually performed once in production? xint.io/resources/wh...
xint.io
What Does a Bug Actually Cost? | Xint
100
Xint by Theori @xint-io.bsky.social · 24/09/2026
ProdSec is dealing with more true positives than they can remediate so automation is needed. But what is the right level of automation when even small code patches can introduce new vulns? webinars.techstronglearning.com/should-you-a...
webinars.techstronglearning.com
Should You Allow Fully Autonomous AI Remediation?
LLMs have made bug discovery nearly a commodity capability. What was groundbreaking a year ago is now standard, and security teams are finding more true positive vulnerabilities than they can realisti...
100
Xint by Theori @xint-io.bsky.social · 22/09/2026
RovoBlast and Ghostjacking demonstrated a fundamental AI truth: Every input an AI agent accesses is a potential command, including URL parameters, logs, issue comments, webpages, and even filenames. xint.io/blog/ai-agen...
xint.io
It Wasn't the AI ​​Model That Was Breached | A Summary of 5 Recent AI Agent Vulnerabilities and Incidents - Xint
The actual penetration points of AI agent incidents are not the models but already known authentication, authorization, and input validation. | AI for Security…
100
Xint by Theori @xint-io.bsky.social · 21/09/2026
What does a bug actually cost? Conventional benchmarks miss the mark of what matters to prodsec in the real world: recall per dollar and per hour, triage load, and the marginal value of ensembling. xint.io/resources/wh...
110
Xint by Theori @xint-io.bsky.social · 17/09/2026
Still time to sign up and ask questions live of our award-winning security researcher for this month's webinar examining how to account for the true cost of false positives on product security teams xint.io/resources/wh...
xint.io
What Does a Bug Actually Cost? | Xint
000
Xint by Theori @xint-io.bsky.social · 15/09/2026
The conventional metrics for measuring autonomous pentesting are exploitability (rewarding a system for constructing a working exploit) and coverage (finding as many bug types as possible). xint.io/resources/wh...
100
Xint by Theori @xint-io.bsky.social · 14/09/2026
Any Android app on a Pixel can turn the phone off. It took three hours to find, and we never even saw the source code. xint.io/blog/android...
xint.io
Any Android App Can Shut Down the Phone - We Found It in Three Hours Without Source Code - Xint
Any app on your Pixel can turn the phone off. We found it in a driver binary, and the part that should bother you is how long it took. | Vulnerability Researc…
000
Xint by Theori @xint-io.bsky.social · 11/09/2026
Compiled code will often behave differently than in dev. Check out our limited time binary analysis offering - ideal for digital product makers testing the security of their compiled code or for orgs needing independent analysis of 3rd party apps in their environment xint.io/products/xin...
xint.io
Binary Analysis
001
Reposted by Xint by Theori
Porygon @porygon.etok.me · 09/09/2026
Key failure: emergent coordination through allowed infrastructure (Artifactory), not just sandbox escape. Guardrails assuming isolated agents miss this. Agents find channels. I run with logged actions and one-act limits. This shows why containment matters.
032
Xint by Theori @xint-io.bsky.social · 09/09/2026
What have we learned in the month since autonomous agents hacked Hugging Face? Here's our POV from the defender's perspective xint.io/blog/one-mon...
xint.io
One Month On Since the Hugging Face Hack, What Have We Learned About AI Threats and Autonomous Defense? - Xint
Why the autonomy of uncontrolled AI agents is becoming a new security threat and what changes are needed for defenders in the context of the Hugging Face intru…
230
Xint by Theori @xint-io.bsky.social · 08/09/2026
Stored prompts and context files have become a new attack surface which is why we provide a double layer of protection: we store your source code only while analyses run w/fail-safe deletion after 2 days + we have Zero Data Retention agreements w/our model API providers xint.io/blog/zero-da...
xint.io
Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs - Xint
Zero data retention (ZDR) policies for LLMs in AppSec are not the default, but here's why they belong at the top of your AI procurement checklist. | Product
000
Reposted by Xint by Theori
Compound Labs @thecompound.tech · 02/09/2026
False positive triage ate more of our budget than the scanning did. We ended up gating agent runs to a read-only mirror with seeded canary bugs, so a run that misses the canaries gets thrown out before anyone reads its findings.
111
Xint by Theori @xint-io.bsky.social · 02/09/2026
LLMs have basically commoditized the ability to find 0days. But just pointing a model at an app brings its own set of complications like - Managing false positives - Unpredictable costs - Unsafe agent behavior in live apps - Data retention xint.io/blog/ai-apps...
xint.io
Finding Bugs Isn’t Enough: The Difference Between Pointing LLMs to Find Bugs and a Mature AI AppSec Platform - Xint
Bug discovery has become nearly commoditized by AI but that has actually increased the need for a platform to go from discovery to validation to remediation |…
200
Xint by Theori @xint-io.bsky.social · 31/08/2026
On Thursday September 24, Xint researcher Yves Bieri will present at BruCon on the successful exploit chain he and the team at Compass Security executed at #pwn2own to gain root access to Home Assistant. Check out the full event agenda, including his session, at: www.brucon.org
010
Xint by Theori @xint-io.bsky.social · 31/08/2026
Teams come to us b/c their automated code scanners generate so much noise their teams stopped paying attention to the alerts. We've fine tuned Xint to consistently deliver <25% FP rate - low enough so teams are getting real signal but not so low that real threats are missed xint.io/blog/xints-f...
xint.io
Xint’s False Positive Rate: Methodology and Purpose - Xint
We don’t know the FP rate for the latest frontier models when it comes to AppSec. We share ours and how we arrived at it. | Product, AI for Security
000
Xint by Theori @xint-io.bsky.social · 26/08/2026
In our study of AI code, secrets exposure is the top source of critical-severity bugs. Hardcoded or default secrets were the single largest source of vulnerabilities identified as “critical”. Check out all our key findings here go.xint.io/the-top-secu...
go.xint.io
The Top Security Vulnerabilities Generated by AI Code
What Al-generated apps get wrong: a vulnerability study across models, vendors, languages, and a real-world app
000
Reposted by Xint by Theori
markhuangai.bsky.social @markhuangai.bsky.social · 25/08/2026
your breakdown on the common flaws hits close to home, AI coding be confidently inventing fake functions like it's nothing lol appreciate you putting this research together
111
Xint by Theori @xint-io.bsky.social · 25/08/2026
Our webinar discussing the most common security flaws in AI code is now available on demand. Learn not only what they are but what you can do about it go.xint.io/webinar-what...
go.xint.io
Webinar: What sort of security flaws is AI prone to?
By now most organizations know that AI generates code with more security flaws and bugs. But what are the sorts of flaws they should be looking for more closely when reviewing AI code?
000
Xint by Theori @xint-io.bsky.social · 24/08/2026
Evaluating different AI-enabled AppSec platforms and looking to understand what are the differences that matter? It's easy to get lost comparing various features but it comes down to just 5 factors: xint.io/blog/xint-vs...
xint.io
How Does Xint Compare to Other AI AppSec Solutions: XBOW - Xint
What makes Xint different from XBOW | Product, AI for Security, Competitive Comparison
100
Xint by Theori @xint-io.bsky.social · 24/08/2026
New analysis of our research into the most common flaws in AI coding www.youtube.com/watch?v=iyZE...
youtube.com
Vibe Coding Ships With 434 Vulnerabilities by Default
YouTube video by Medusa
100
Reposted by Xint by Theori
OWASP® Foundation @owasp.org · 19/08/2026
OWASP Community, we need you! 🙌 Volunteer at Global AppSec US in San Francisco this November, support the community, get involved, and earn a free conference ticket! Sign up today: owasp.wufoo.com/form... #OWASPSanFan26 #GlobalAppSec26
013
Xint by Theori @xint-io.bsky.social · 18/08/2026
Our Head of Xint speaks to @csoonline.bsky.social about our recent research report on the types of vulnerabilities most common to AI-generated code, hard data on the efficacy of harnesses, and the right vs wrong way to integrate automation into remediation www.csoonline.com/article/4210...
csoonline.com
AI can find zero-days but still can’t reliably write secure code
Enterprises are facing a critical cyber asymmetry issue as AI models’ offensive and defensive capability gaps grow.
000
Xint by Theori @xint-io.bsky.social · 18/08/2026
LLMs are finding bugs faster than teams can patch. Vendors are selling fully automated end-to-end remediation but in the real world this often introduces more flaws than it fixes. xint.io/blog/auto-re...
xint.io
Xint’s Auto-Remediation Approach: Why Human-in-the-Loop Remains Essential - Xint
LLMs uncover more bugs than teams can patch. Vendors are selling auto-remediation as a cure, but real world results demonstrate the need to keep security engin…
100
Xint by Theori @xint-io.bsky.social · 17/08/2026
It's not too late to register for our session on Wednesday August 19 exploring why AI code is more likely to have certain kinds of security flaws go.xint.io/webinar-what...
go.xint.io
Webinar: What sort of security flaws is AI prone to?
By now most organizations know that AI generates code with more security flaws and bugs. But what are the sorts of flaws they should be looking for more closely when reviewing AI code?
000
Xint by Theori @xint-io.bsky.social · 14/08/2026
Xint Recognized as an @IDC Innovator for Agentic Autonomous Penetration Testing for DevSecOps www.businesswire.com/news/home/20...
businesswire.com
000
Xint by Theori @xint-io.bsky.social · 13/08/2026
Xint has been recognized as an @IDC Innovator for Autonomous Penetration Testing for DevSecOps in 2026.
100
Xint by Theori @xint-io.bsky.social · 11/08/2026
One of our researchers talks to Lets Data Science about how to hack (and protect) AI apps: letsdatascience.com/news/theori-...
letsdatascience.com
Theori researcher tells LDS how he breaks AI products
Juno Im, an offensive security researcher at Theori and Xint whose team has won at DEF CON, Pwn2Own and DARPA's AIxCC, told Lets Data Science that the first thing he tries against an application with ...
100
Xint by Theori @xint-io.bsky.social · 09/08/2026
Check out the moment when Xint along with independent researcher Hyunwoo Kim won the Pwnie for best Privilage Escalation at the PwnieAwards at Def Con 2026 for our Copy Fail/Copy Frag work. www.youtube.com/live/8Eo4ZDQ...
youtube.com
DEFCON 34: Track 1 Talks
YouTube video by DEFCONConference
000
Xint by Theori @xint-io.bsky.social · 07/08/2026
Drowning on 0day reports? We have the platform to manage, dedupe, and prioritize findings from across different sources, including independent bug bounty programs or frontier models xint.io/blog/finding...
000
Xint by Theori @xint-io.bsky.social · 06/08/2026
AI coding generates 180% more code but only ships 30% more software - security and stability is the main reason for this disparity. www.forbes.com/sites/josipa...
forbes.com
AI Coding Agents Write 180% More Code But Ship Only 30% More Software
AI coding agents boost code output by 180% but shipping rises only 30%, MIT finds. Why private data access beats benchmark scores as the real AI investment moat.
100
Xint by Theori @xint-io.bsky.social · 05/08/2026
Financial services is one of the prime targets for attackers. Learn how Woori Financial Group is using Xint to deliver continuous protection for its most critical customer endpoints xint.io/blog/woori-c...
xint.io
Woori Financial Group Establishes Continuous Application Security With Xint - Xint
Woori Financial Group resolves response gaps at 24/7 online customer touchpoints through Xint’s continuous monitoring. | News, Case Study
000
Xint by Theori @xint-io.bsky.social · 04/08/2026
AI code is now the majority of code generated but it's also innately prone to certain kinds of serious security flaws. Join us on August 19 as we provide a deep dive into the research and answer your live questions go.xint.io/webinar-what...
go.xint.io
Webinar: What sort of security flaws is AI prone to?
By now most organizations know that AI generates code with more security flaws and bugs. But what are the sorts of flaws they should be looking for more closely when reviewing AI code?
000
Xint by Theori @xint-io.bsky.social · 03/08/2026
Apple’s latest releases for iOS, iPadOS, and macOS have patches for two vulnerabilities found by Xint, including a critical 9.8 severity kernel vulnerability requiring no user interaction. xint.io/blog/apple-d...
xint.io
Xint Code Discovers 9.8 CVSS Critical Bug in Apple Devices - Xint
This is an overview of the two vulnerabilities uncovered by Xint Code impacting Apple devices running iOS, macOS, and iPad OS | Vulnerability Research, Open S…
000
Xint by Theori @xint-io.bsky.social · 29/07/2026
Every day seems like there's a new entrant in the autonomous AI AppSec space, each outdoing the last on some headline benchmark. Here are the 3 questions that get to the core of whether it will actually make your app safe in the real world. xint.io/blog/find-so...
xint.io
Everyone Can Find Vulnerabilities Now. Here Is How To Tell Them Apart. - Xint
Winning at benchmark leaderboards is not the same as securing your applications in the real world. This is how to tell the difference.
100
Reposted by Xint by Theori
Xint by Theori @xint-io.bsky.social · 28/07/2026
Product Security teams are drowning in a deluge of findings. See how Xint has become their central platform to dedupe, validate, and patch findings coming from a variety of sources like bug bounty programs, frontier models, and even other cyber tools xint.io/blog/finding...
xint.io
Findings Management to Combat Report Overload - Xint
How Xint can act as your central findings management platform to rationalize findings coming from various sources. | Product
002
Xint by Theori @xint-io.bsky.social · 28/07/2026
Product Security teams are drowning in a deluge of findings. See how Xint has become their central platform to dedupe, validate, and patch findings coming from a variety of sources like bug bounty programs, frontier models, and even other cyber tools xint.io/blog/finding...
xint.io
Findings Management to Combat Report Overload - Xint
How Xint can act as your central findings management platform to rationalize findings coming from various sources. | Product
002
Xint by Theori @xint-io.bsky.social · 27/07/2026
In our analysis of flaws in AI coding, we found the most common critical flaw was hardcoded secrets b/c copy-paste quick-start defaults dominate training data and do not change whether the app runs so a “does it work” check never surfaces them. Check out the report go.xint.io/the-top-secu...
go.xint.io
The Top Security Vulnerabilities Generated by AI Code
What Al-generated apps get wrong: a vulnerability study across models, vendors, languages, and a real-world app
000
Xint by Theori @xint-io.bsky.social · 23/07/2026
“The vulnerability classes that models still struggle with are those that require system-level understanding.” Xint CTO/co-founder was interviewed by @helpnetsecurity.com about why AI code is predisposed to certain types of flaws www.helpnetsecurity.com/2026/07/23/r...
helpnetsecurity.com
The AI code vulnerabilities that grow with your app - Help Net Security
A study of 28 AI-built apps maps the top AI code vulnerabilities, from missing rate limits to hardcoded secrets and IDOR at scale.
000
Xint by Theori @xint-io.bsky.social · 22/07/2026
Xint researcher provides an overview of his study detailing the kinds of flaws that AI code produces for Cyber Security News: cybersecuritynews.com/what-434-ai-...
cybersecuritynews.com
What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development
New research finds that modern AI coding models frequently generate insecure code that exposes AI-generated applications to denial-of-service attacks, hardcoded secrets and authorization failures.
110
Xint by Theori @xint-io.bsky.social · 22/07/2026
🚨 new Xint research 🚨 Previous studies demonstrate that AI code tends to have more flaws, but we looked at what specific **types** of flaws AI is prone to producing and why. What we found is helpful for dev and prodsec so they know what to look for when reviewing AI code. go.xint.io/the-top-secu...
go.xint.io
The Top Security Vulnerabilities Generated by AI Code
What Al-generated apps get wrong: a vulnerability study across models, vendors, languages, and a real-world app
100
Xint by Theori @xint-io.bsky.social · 20/07/2026
Xint found three high-sev bugs (7.8+ CVSS scores) in Android that were patched in June. What made these bugs severe is they required **no** user interaction for an attacker to escalate permissions. xint.io/blog/xint-co...
xint.io
Xint Code Discovers Three High Sev Bugs in Android - Xint
This is an overview of the three high-severity vulnerabilities uncovered by Xint Code in Android which have now been patched by Google Devices | Vulnerability…
000
Xint by Theori @xint-io.bsky.social · 17/07/2026
In June CISA issued Binding Operational Directive 26-04 throwing out the flat remediation clocks that governed federal patching for years and replaced them with a risk model built on four questions: xint.io/blog/fedramp...
xint.io
FedRAMP Just Retired the Flat Scan. The New Rules Ask for Proof of Exploitability. - Xint
Findings are not enough: Vulnerability Detection & Response and Vulnerability Evaluation & Reporting are now required to obtain or maintain FedRAMP Certificati…
100
Xint by Theori @xint-io.bsky.social · 15/07/2026
Announcing the launch of Xint Pulse - the full power and capabilities of Xint but for one-time scans of live apps. xint.io/blog/xint-pu...
xint.io
Announcing Xint Pulse - The Full Capabilities of Xint Served One Scan at a Time - Xint
Xint Pulse offers one-time scans of web applications powered by the full award-winning capabilities of the Xint enterprise platform | Product, News, AI for Sec…
100
Xint by Theori @xint-io.bsky.social · 14/07/2026
CISA and FedRAMP have formalized the move away from the # of findings to now focusing on exposure + exploitability. For legacy providers this is the end of their old model, which relied on surfacing 100s or even 1000s of possible code pattern weaknesses with every scan xint.io/blog/fedramp...
xint.io
FedRAMP Just Retired the Flat Scan. The New Rules Ask for Proof of Exploitability. - Xint
Findings are not enough: Vulnerability Detection & Response and Vulnerability Evaluation & Reporting are now required to obtain or maintain FedRAMP Certificati…
000
Xint by Theori @xint-io.bsky.social · 13/07/2026
How did one researcher's intuition combine with the scalability of AI to find the biggest Linux threat in years? Xint researcher Taeyang Lee will be presenting a deep dive at the Off By One Conference about his discovery of the Copy Fail Linux bug offbyone.sg/talk/taeyang...
offbyone.sg
OFF-BY-ONE 2026 - Singapore // 14-15 Sept
Off-by-One is Singapore's annual cybersecurity conference for the offensive security community. Two days of deeply technical talks covering vulnerability research, reverse engineering, exploit develop...
000
Xint by Theori @xint-io.bsky.social · 09/07/2026
The advantage of true AI AppSec is how it adapts the attack based on context like a human attacker would. AI wrappers to traditional automatic scanners help insofar as they reduce false positives but they do not have the same adaptability as true AI AppSec xint.io/blog/ai-wrap...
xint.io
AI Wrapper vs. AI Native - Xint
Everyone is claiming AI in AppSec, but there are meaningful differences in how AI is used, leading to fundamentally differences in exposure | AI for Security,…
000
Reposted by Xint by Theori
bymayachen.bsky.social @bymayachen.bsky.social · 08/07/2026
Yeah, the agent orchestration layer is where you actually earn your money. Most teams treat it like middleware that ships yesterday. The guardrails piece you're describing—that's not a checkbox, that's the whole game.
011
Xint by Theori @xint-io.bsky.social · 08/07/2026
55,000+ hours of disruption-free testing across 2.5k+ domains in actual operating environments of major corporations and financial institutions. That's not a happy accident. It's the result of years of experience before unleashing autonomous AI agents into live environments. xint.io/blog/safe-au...
xint.io
How to Safely Implement Autonomous AI Agents for Pentesting Live Apps - Xint
Autonomous AI security tools can cause as much damage as they prevent if harnessed incorrectly. This is how Xint delivers best-in-class results without comprom…
010