When was the last time you saw an AMQ computer in person? 🤘 We meant it when we said we're bringing all the nostalgia vibes to Black Hat...see you there at booth 3448: xbow.com/events/black...
XBOW
@xbow.com
Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. https://xbow.com/
Earlier this year, XBOW broke into the top 10 of the Microsoft Security Response Center(MSRC) leaderboard as the first and o nly AI in the ranking. Now we're finally able to disclose some of the coolest bugs we found.
We are pleased to announce that XBOW has achieved Application Security distinction for the special Autonomous Security Validation use case within the @awscloud.bsky.social (AWS) Security Competency. Learn more: xbow.com/news/xbow-ac...
XBOW Achieves AWS Security Competency Status | XBOW
XBOW earns AWS Security Competency status, recognizing its autonomous security validation platform for continuous application security testing on AWS.
xbow.com
Most security tools answer one question: what weaknesses exist here? They return a list, each item scored on its own. But attackers chain weaknesses. Finding these chains has historically required expensive human expertise. XBOW does this autonomously. Find out how: xbow.com/whitepapers/...
“Exploit proof” needs to rise to the top of your remediation program as a key modifier for findings, says Moderna Deputy CISO Farzan Karimi in a recent webinar with XBOW co-founder Nico Waisman. Hear more from Farzan below. Watch full webinar recording here: https://bit.ly/4eIForC
The Five Eyes cyber security agencies confirmed that AI-driven cyber risk is imminent. As the gap between discovery and exploitation shrinks, continuous, autonomous security testing becomes essential. That's the problem XBOW was built to solve. Read the full statement: https://bit.ly/4vsuzkh
How does XBOW identify business logic flaws? Hear from XBOW security researcher Alvaro Muñoz in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: https://bit.ly/4fKEpsP
In a new episode of the Cyberwire podcast, “Vulnerability response. Built for humans, outpaced by machines,” XBOW Head of Security Labs Federico Kirschbaum shares his perspective on vulnerability management when frontier models are finding the flaws. Listen to the episode: https://bit.ly/4epV5ov
What would it take to build an AI-powered offensive security tool? We highlight the cost below. Get full details in our new whitepaper: https://bit.ly/4eqcEDH
AI Tinkerers is hosting an offensive security demo night on June 25 with XBOW. Live exploits, autonomous pentesting, LLM-assisted vulnerability discovery, code walkthroughs, and technical Q&A. No decks. No pitches. Working systems only. RSVP: https://bit.ly/3SdPtVS
Why are design flaws like IDOR so hard to find with automation? XBOW security researcher Alvaro Muñoz explains in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: https://bit.ly/4fKEpsP
If an organization can point a powerful language model at an application and unearth findings, is it effectively running a penetration test? Our new whitepaper breaks down where LLMs are powerful tools for pentesting, and where they need more support: https://bit.ly/4eqcEDH
We're honored that XBOW has been named a winner of Fast Company's 2026 World Changing Ideas Awards in the Business Products & Services category. This recognition reflects the work of our partners & research team, who believe the future of security is autonomous offense. More: https://bit.ly/4epnGca
LLMs excel at following instructions, but not always at identifying which instructions to trust. XBOW Head of AI Albert Ziegler explains why prompt injection risk grows alongside AI agency and enterprise access in IBT Media. Read on: https://bit.ly/3S3pZdO
Gemini Prompt Injection Shows AI Adoption is Increasing Risk for Companies
AI chatbots and assistants are extremely vulnerable to exploitation, particularly prompt injection, according to new research.
bit.ly
Samsung SDS announced that it is partnering with XBOW to strengthen its cybersecurity capabilities, using XBOW to uncover hidden vulnerabilities through attack simulations and accelerate identification and remediation with unmatched speed and precision. Get details: https://bit.ly/4oo3zjs
“AI is changing the story of design flaw identification, says XBOW security researcher Alvaro Muñoz in the clip below. Get more of his thoughts on business logic flaws and how to address them in his new blog: https://bit.ly/4fKEpsP
Great spending time with the GuidePoint Security team and customers this week at the GuidePoint Security Golf Classic at Terry Hills. As attack surfaces grow and vulnerabilities multiply, strong partnerships matter. Together, we're helping organizations validate real, exploitable risk.
“Is my application security program built for a world where everyone is a coder?” Read why our CISO, Nico Waisman, believes this question should be top of mind for today’s CISOs in CSO Online: https://bit.ly/4um5upQ
15 tough cybersecurity questions every CISO must answer
From anticipating new threats to balancing risk management and business enablement, CISOs face a range of complex challenges that require continual reflection and strategic execution.
csoonline.com
How does AI pentesting work? What should you look for? Get some guidance in our blog post "How to Evaluate an AI Pentesting Vendor: A Decision Framework for Security Leaders." https://bit.ly/4edHyPM
• Why can't traditional pentests keep up with modern attack surfaces? • What stops an autonomous pentesting agent from causing real damage in production? Our CISO answers these questions and more on the Security You Should Know podcast. Listen to the full episode: https://bit.ly/4eiMXWM
Moderna Deputy CISO Farzan Karimi shared how XBOW uncovered attack paths human testers missed, including one that took down a development environment during a trial. This @cyberscoop.bsky.social piece examines what happens when offensive security moves at machine speed: https://bit.ly/4va5Pxr
One theme came up repeatedly at InfoSecurity Europe: ➡️ Security teams want proof, not possibility. Great discussions all week with leaders thinking about autonomous offensive security and operational validation at scale. Thanks to everyone who connected with our team.
On June 10, XBOW CISO Nico Waisman and Moderna Deputy CISO Farzan Karimi will discuss the impact of autonomous, continuous, and exploit-validated offensive security in today’s AI threat landscape. Join us: https://bit.ly/42zUvxV
GPT-5.5 is now part of XBOW. In our testing, GPT-5.5 delivered major gains in vulnerability discovery, exploit reasoning, application interaction, and autonomous testing. Models provide the intelligence. XBOW turns it into autonomous application security. Read more: https://bit.ly/4ufvhAb
Thank you to everyone who joined yesterday's #GartnerSEC session with Farzan Karimi and Troy West of Moderna to learn how they're building an autonomous offensive security program with XBOW! It’s day two, and we’re ready to talk all things autonomous offensive security. Find us at booth 1028!
Today at #Infosec2026, attendees will get a chance to put offensive security to the test during our workshop: Offensive AI in Practice. See firsthand how AI amplifies attackers’ abilities and how offensive security tools find, exploit, validate, and remediate them. Register: https://bit.ly/4d9cd19
Our team is at #Infosec2026 today through Thursday! Stop by booth F-135 to say hi to the team 👋 and learn how your organization can scale offensive security with XBOW. 🏹 https://bit.ly/3P1Vkwj
If you’re at Gartner Security & Risk Management Summit today, find the XBOW team at booth 1028 📍 to learn about autonomous offensive security and how it’s enabling teams to defend against complex and evolving cyberthreats faster, better, and at scale: https://gtnr.it/2Mf36ll #GartnerSEC
Attending Gartner Security & Risk Management Summit? Tune in as Moderna’s Farzan Karimi and Troy West take the stage to share how XBOW enables them to meet the demands of today’s AI-driven cybersecurity landscape. 🔔 TODAY at 02:05 PM EDT: https://gtnr.it/4nQofA6 #GartnerSEC
AI models are getting better at finding vulnerabilities, but detection alone isn’t enough. @cyberscoop.bsky.social covers the early results on Mythos Preview, including XBOW’s evaluation. Read more: https://bit.ly/4e4JqeC
Anthropic: Mythos finds more than 10,000 software flaws in first month
Anthropic’s Mythos model uncovers over 10,000 critical software flaws in its first month, shifting the cyber challenge from finding bugs to patching them.
bit.ly