Xbow Profile Banner
XBOW Profile
XBOW

@Xbow

Followers
10K
Following
37
Media
68
Statuses
143

Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM

Seattle, Washington, USA
Joined May 2007
Don't wanna be here? Send us removal request.
@Xbow
XBOW
2 months
CEO @oegerikus was hosted today on @FoxNews to discuss how XBOW is changing the game in cybersecurity. "We found a flaw in a well-secured company. They fixed it. Then our AI checked again and found a bypass for their fix. These AIs are pretty clever." Full interview and
3
4
56
@Xbow
XBOW
2 days
SAST and DAST operate in silos. Attackers don’t. XBOW agents combine both: → Static tells them where to look → Dynamic shows how to break it → Coordination = real exploits, not noise Autonomous testing needs attacker logic, not just coverage. ⚡️Deep dive here:
3
1
11
@Xbow
XBOW
12 days
Action required now: Upgrade to Chef Automate 4.13.295 or later immediately. CVE: https://t.co/D2A9zVxJAT This is autonomous security testing in practice - finding and responsibly disclosing critical vulnerabilities before they're exploited at scale
0
0
1
@Xbow
XBOW
12 days
The discovery path: Found during testing on a HackerOne program, then realized it affected the upstream open-source Chef Automate project. We immediately disclosed to Progress (Chef's parent company), who responded quickly with a fix.
1
0
5
@Xbow
XBOW
12 days
What makes this interesting from a testing perspective: XBOW also discovered a default authentication token (93a49a4f2482c64126f7b6015e6b0f30284287ee4054ff8807fb63d9cbd1c506) that provided access to previously protected endpoints. This token exists in some GitHub repos but
2
0
1
@Xbow
XBOW
12 days
How XBOW found it: XBOW's autonomous testing identified SQL injection through the type field in the filters array using PostgreSQL's string concatenation operator. The application uses pq driver, and error messages revealed the injection point.
1
0
0
@Xbow
XBOW
12 days
The vulnerability allows authenticated attackers to execute arbitrary SQL commands against the PostgreSQL database through the compliance profiles search endpoint at /api/v0/compliance/profiles/search. Potential impact: compromised data access.
1
0
0
@Xbow
XBOW
12 days
🚨 Critical SQL injection in Chef Automate (CVE-2025-8868) If you're running Chef for infrastructure automation, patch immediately to version 4.13.295 or later. Full technical breakdown: https://t.co/BtOAk40tVn What XBOW found 🧵
Tweet card summary image
xbow.com
How a little-known default token provided the entry point for XBOW to uncover a critical SQL injection in an unexpected API parameter.
1
6
20
@oegerikus
Oege de Moor
18 days
AI attacks are scaling. Defenders aren’t. We're entering the Chaos Phase, where autonomous exploit tools move faster than manual security ever could. With AI, defenders will win. But those that are slow to adopt AI will lose.
2
8
17
@Xbow
XBOW
19 days
XBOW found a new zero-day in Apache Druid. It wasn't just a lucky guess. XBOW is trained to think like a human attacker, using historical CVE knowledge to find a novel SSRF (CVE-2025-27888). This is how AI-powered pentesting turns old knowledge into new findings. Read the
3
20
141
@Xbow
XBOW
20 days
200+ real vulns. 0 false positives. XBOW agents ran autonomous exploits across Docker Hub webapps, and uncovered vulnerabilities traditional tools miss. Systematic. Validated. No assumptions. 🗓️ This Thurs — @moyix + @pwntester lead a live breakdown https://t.co/Wztoo32YGs
2
5
42
@Xbow
XBOW
1 month
We're excited to partner with @Rhymetec to combine our autonomous AI hacker with their deep human expertise. Machine speed with human ingenuity. This is how security teams get the advantage to stay ahead. Read the full announcement:
Tweet card summary image
rhymetec.com
Rhymetec is proud to partner with XBOW, the world’s leading autonomous pentesting platform. Together, we bring a new standard of security.
0
5
24
@Xbow
XBOW
1 month
Full talk is now available! https://t.co/i9oGJrZEGH
@BugBountyDEFCON
Bug Bounty Village
1 month
It's out!! You can now watch @djurado's and @niemand_sec talk: "Prompt. Scan. Exploit - Ai's Journey Through Zero-Days, and a Thousand Bugs". Learn more about @Xbow and autonomous hacking. You can watch it in our Youtube channel exclusively: https://t.co/ywACpqVLUY. Enjoy!
0
3
38
@Xbow
XBOW
2 months
"The ChatGPT moment of cyber hacking hasn't happened yet, it will happen, and offensive actors will use AI we need players like XBOW to help keep the world safe." - @apoorv03, Partner at Altimeter Capital. As attackers arm themselves with AI, we can't afford to fall behind.
2
3
16