Xint by Theori

@xint-io.bsky.social

Go beyond AppSec that drowns teams with false positives and trivial bugs. Discover the business logic vulnerabilities traditional tools miss.

AI code is now the majority of code generated but it's also innately prone to certain kinds of serious security flaws. Join us on August 19 as we provide a deep dive into the research and answer your live questions go.xint.io/webinar-what...

Webinar: What sort of security flaws is AI prone to?

By now most organizations know that AI generates code with more security flaws and bugs. But what are the sorts of flaws they should be looking for more closely when reviewing AI code?

go.xint.io

Every day seems like there's a new entrant in the autonomous AI AppSec space, each outdoing the last on some headline benchmark. Here are the 3 questions that get to the core of whether it will actually make your app safe in the real world. xint.io/blog/find-so...

Everyone Can Find Vulnerabilities Now. Here Is How To Tell Them Apart. - Xint

Winning at benchmark leaderboards is not the same as securing your applications in the real world. This is how to tell the difference.

xint.io

Product Security teams are drowning in a deluge of findings. See how Xint has become their central platform to dedupe, validate, and patch findings coming from a variety of sources like bug bounty programs, frontier models, and even other cyber tools xint.io/blog/finding...

Findings Management to Combat Report Overload - Xint

How Xint can act as your central findings management platform to rationalize findings coming from various sources. | Product

xint.io

Product Security teams are drowning in a deluge of findings. See how Xint has become their central platform to dedupe, validate, and patch findings coming from a variety of sources like bug bounty programs, frontier models, and even other cyber tools xint.io/blog/finding...

Findings Management to Combat Report Overload - Xint

How Xint can act as your central findings management platform to rationalize findings coming from various sources. | Product

xint.io

In our analysis of flaws in AI coding, we found the most common critical flaw was hardcoded secrets b/c copy-paste quick-start defaults dominate training data and do not change whether the app runs so a “does it work” check never surfaces them. Check out the report go.xint.io/the-top-secu...

The Top Security Vulnerabilities Generated by AI Code

What Al-generated apps get wrong: a vulnerability study across models, vendors, languages, and a real-world app

go.xint.io

“The vulnerability classes that models still struggle with are those that require system-level understanding.” Xint CTO/co-founder was interviewed by @helpnetsecurity.com about why AI code is predisposed to certain types of flaws www.helpnetsecurity.com/2026/07/23/r...

The AI code vulnerabilities that grow with your app - Help Net Security

A study of 28 AI-built apps maps the top AI code vulnerabilities, from missing rate limits to hardcoded secrets and IDOR at scale.

helpnetsecurity.com

🚨 new Xint research 🚨 Previous studies demonstrate that AI code tends to have more flaws, but we looked at what specific **types** of flaws AI is prone to producing and why. What we found is helpful for dev and prodsec so they know what to look for when reviewing AI code. go.xint.io/the-top-secu...

The Top Security Vulnerabilities Generated by AI Code

What Al-generated apps get wrong: a vulnerability study across models, vendors, languages, and a real-world app

go.xint.io

CISA and FedRAMP have formalized the move away from the # of findings to now focusing on exposure + exploitability. For legacy providers this is the end of their old model, which relied on surfacing 100s or even 1000s of possible code pattern weaknesses with every scan xint.io/blog/fedramp...

FedRAMP Just Retired the Flat Scan. The New Rules Ask for Proof of Exploitability. - Xint

Findings are not enough: Vulnerability Detection & Response and Vulnerability Evaluation & Reporting are now required to obtain or maintain FedRAMP Certificati…

xint.io

How did one researcher's intuition combine with the scalability of AI to find the biggest Linux threat in years? Xint researcher Taeyang Lee will be presenting a deep dive at the Off By One Conference about his discovery of the Copy Fail Linux bug offbyone.sg/talk/taeyang...

OFF-BY-ONE 2026 - Singapore // 14-15 Sept

Off-by-One is Singapore's annual cybersecurity conference for the offensive security community. Two days of deeply technical talks covering vulnerability research, reverse engineering, exploit develop...

offbyone.sg

The advantage of true AI AppSec is how it adapts the attack based on context like a human attacker would. AI wrappers to traditional automatic scanners help insofar as they reduce false positives but they do not have the same adaptability as true AI AppSec xint.io/blog/ai-wrap...

AI Wrapper vs. AI Native - Xint

Everyone is claiming AI in AppSec, but there are meaningful differences in how AI is used, leading to fundamentally differences in exposure | AI for Security,…

xint.io

Yeah, the agent orchestration layer is where you actually earn your money. Most teams treat it like middleware that ships yesterday. The guardrails piece you're describing—that's not a checkbox, that's the whole game.

Bild

55,000+ hours of disruption-free testing across 2.5k+ domains in actual operating environments of major corporations and financial institutions. That's not a happy accident. It's the result of years of experience before unleashing autonomous AI agents into live environments. xint.io/blog/safe-au...

How to Safely Implement Autonomous AI Agents for Pentesting Live Apps - Xint

Autonomous AI security tools can cause as much damage as they prevent if harnessed incorrectly. This is how Xint delivers best-in-class results without comprom…

xint.io

Our team's experience in practical offensive security is why we built Xint understanding what guardrails autonomous agents need when doing penetration testing on a live application - otherwise AI security can cause the same issues it was meant to prevent xint.io/blog/safe-au...

How to Safely Implement Autonomous AI Agents for Pentesting Live Apps - Xint

Autonomous AI security tools can cause as much damage as they prevent if harnessed incorrectly. This is how Xint delivers best-in-class results without comprom…

xint.io

🚨 Interested in the quality of Xint results but needed a 1-time scan of a single live app (for example, for a one-time compliance scan of a vendor) instead of a longer-term commitment for several apps, servers, and APIs? Get on the waitlist for Xint Pulse - coming soon! xint.io/pulse-waitlist

Xint Pulse Waitlist | Full Pentest, No Subscription

Join the Xint Pulse waitlist. Get a complete pentest for a single app, no subscription, no contract. Be first to know when Pulse launches.

xint.io

Product Security is paying vendors to find vulnerabilities hackers will try to exploit. What they get instead is lists of hundreds (possibly) thousands of possible code weaknesses that add more noise instead of providing focus. xint.io/blog/171258

Vulnerabilities vs. Weaknesses: Why the Distinction Matters - Xint

There's a difference between insecure code patterns and true vulnerabilities that hackers seek to exploit. Why does that matter? | Vulnerability Research, AI…

xint.io

Speed wins - especially for startups. The ability to **securely** ship new features and updates is critical for building customer delight and trust at the same time. See how Z Enterprise does exactly that with Xint xint.io/blog/fintech...

How a FinTech Startup Accelerates Rapid Product Iteration Without Introducing Security Gaps With Xint - Xint

For startups where speed is of the essence, when and how should security checks are performed can either be an accelerant or a bottleneck

xint.io

The latest models might show 10% improvements in certain benchmarks but increase costs by 2-10x depending on the complexity of the task. How do we deliver frontier-like performance while still maintaining predictable app/code scanning costs? xint.io/blog/increme...

FAQ: Are the Incremental Improvements in New Models Worth the Higher Cost? - Xint

What are the incremental benefits to each new (more expensive) model and when does it make sense to update? | AI for Security, Product, FAQ

xint.io