73 Followers
0 Following
33 Posts
Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://xbow.com/traces

Where security goes on offense.

Trained by top hackers, proven in the wild. Ranked #1 on HackerOne worldwide leaderboard.

Explore it during our limited 10-day promotion. xbow.com/pentest

Seznam needed answers fast.
XBOW delivered. ⚡

Real pentest results. No drag. No drama.

For a limited time, we’re offering the same fast-track pentest experience and we will guarantee an exploit-validated security finding or you don’t pay.
⏰ Offer ends 12/26.

👉 http://xbow.com/pentest

Pentests that take weeks cannot secure software that changes daily.

🚀 XBOW Lightspeed provides expert-level testing in hours with autonomous offensive security.

📍 See it live at Booth 215 today!

🗓️ Today at the AI Summit join our talk on The Autonomous Offense Era: Securing a World Where Attackers Don’t Sleep

XBOW's Nico, Aqueel, and Sarah unpack autonomous exploitation, what works, what fails, and what to expect next.

📍 Find us at Booth 215 for live walkthroughs after the session.

Huge appreciation to the Seznam team!

On their first demo, XBOW identified a critical vulnerability with zero access and zero prep, just autonomous offensive security doing real work for a real customer.

It’s the kind of partnership that proves what matters.

https://www.youtube.com/watch?v=w4L2bM1BLzI

The Real Impact of AI on Security Testing | XBOW & Seznam

YouTube

Black Hat Europe starts today!

📍 Booth 215 all week. Autonomous multi-agent offense. Human-level testing in hours. Full exploit validation.

Come see it live.

AI-enabled attackers have already accelerated.

The question: can your offensive security match their speed?

Next week at Black Hat Europe, we’re showing how autonomous offense closes the security scale gap with human-level testing in hours.

Let us show you how @ booth #215

Pentests that take weeks can’t secure software that changes daily.

XBOW Lightspeed uses autonomous multi-agent offense to deliver human-level testing in hours, with full exploit validation and continuous coverage.

http://xbow.com/pentest

1/ XBOW Unleashes GPT-5’s Hidden Hacking Power. 

OpenAI's initial assessment of GPT-5 showed modest cyber capabilities. But when integrated into the XBOW platform, we saw a completely different story: performance more than doubled. 

More on what we found: 🧵

⚡️ XBOW found LFI where most tools would have given up.

Photo download endpoint blocked all path traversal attempts. But JavaScript analysis revealed /photo/proxy?url= - vulnerable to file:// scheme access.

Result: Successfully read /etc/passwd via proxy endpoint.

Technical breakdown: https://xbow.com/blog/xbow-photo-proxy-lfi/

XBOW – How XBOW turned a JavaScript hint into a working file inclusion

The XBOW bug bounty effort continues, and this time it uncovered a critical local file inclusion vulnerability by transforming an intriguing SSRF into a full file read exploit.