XBOW is heading to London for #BlackHatEurope. We’ll be live on the expo floor at booth #215, showing how autonomous offensive security works, in real time. ✅ See autonomous pentesting in action ✅ Get hands-on with exploit validation ✅ Meet the team behind 1092+ real-world vulns
XBOW
Computer and Network Security
Seattle, Washington 10,243 followers
Boosting offensive security with AI
About us
XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first product that passes 75% of web security benchmarks with zero human intervention.
- Website
-
https://xbow.com/
External link for XBOW
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- Seattle, Washington
- Type
- Privately Held
- Founded
- 2024
Locations
-
Primary
Get directions
Seattle, Washington, US
Employees at XBOW
Updates
-
AI attacks are accelerating. So is our team. This month we're excited to welcome two proven cybersecurity leaders to XBOW: 🔹 Jonaki Egenolf joins as CMO (ex-Snyk, Veracode) 🔹 Dean Breda joins as GC (ex-HackerOne, Veracode) They join a leadership bench with deep cybersecurity expertise that includes Niroshan Rajadurai, CRO (ex-GitHub Advanced Security) and Nico Waisman, CSO (ex-Lyft), to drive our mission forward. XBOW is closing that gap with automation that doesn't compromise on quality or accuracy. This year, XBOW: • Reached #1 on HackerOne's leaderboard • Released the first on-demand AI pentest platform • Won as an emerging leader in Fortune Cyber60 Welcome to the mission, Jonaki & Dean! Read more: https://lnkd.in/eMwUggUV
-
Tune in live for this session at VantaCon today. AI is transforming the security landscape, and compliance and assurance must evolve with it. Hear from Oege de Moor, CEO of XBOW and Jeremy Epling CPO of Vanta as they unpack how AI is changing attacker behavior and how organizations can strengthen security programs in response. ⏰ Today at 11:10am PT 📍 Tune in here https://lnkd.in/ewUUr-ap
-
-
GTG-1002 proved it: AI can run most of an intrusion lifecycle on its own. The question for every team now is simple: Can your systems withstand that level of depth? In our new breakdown, we explain: - What GTG-1002 reveals about modern AI attack patterns - How these attacks chain dozens of small steps into real impact - How your team can safely mirror that depth to understand real exposure - What XBOW has already uncovered using this approach Full post → https://lnkd.in/erSTHGmN
-
“The emergence of wide-scale AI attacks is prompting a new shift in the defense paradigm.” 📖 Read Nico's full reflection on what GTG‑1002 means for enterprise security https://lnkd.in/eamDcmAb
-
-
“The stakes are incredibly high. If our adversaries develop superior AI warriors before we do, the consequences could be devastating. This is why the mission of companies like XBOW is so critical—it's not just about building a business, it's about national security.” Thank you Konstantine Buhler for articulating what’s at stake so clearly. The age of AI-driven offense is here, defense has to move just as fast.
Anthropic just shared the first major publicly documented AI cyber attack...it should be a wake-up call for everyone. In mid-September, Anthropic uncovered a sophisticated espionage campaign by a Chinese state-sponsored group. What makes this attack a landmark event? It was largely executed by AI agents, not humans. Here's how it worked: 1. Human Command: Operators selected the targets and designed the overall attack framework. 2. AI Reconnaissance: The AI autonomously scanned networks to identify the most valuable databases. 3. AI Exploitation: It then researched vulnerabilities and wrote its own exploit code to breach defenses. 4. AI Data Heist: The AI harvested credentials and exfiltrated sensitive private data. 5. AI Documentation: Finally, it created detailed documentation for use in future operations. The AI handled 80-90% of the campaign on its own, with humans only intervening 4-6 times. It operated at a speed impossible for human teams, making thousands of requests per second. This is a very big deal. The stakes are incredibly high. If our adversaries develop superior AI warriors before we do, the consequences could be devastating. This is why the mission of companies like XBOW is so critical—it's not just about building a business, it's about national security. We must win this fight. Thanks to Lauren Reeder for flagging this. Grateful to have leaders like Oege de Moor and Nico Waisman on the front lines, defending against these new threats. https://lnkd.in/gekUFeff
-
Live in 1 hour → Live Demo: XBOW Pentest On-Demand. Launch a pentest in minutes. Get validated results in days. Join us live at 9 AM PT / 12 PM ET / 6pm CET with Aqeel Siddiqui and Sarah Hyatt to see how teams secure what they ship, at machine speed. 👉 xbow.com/pentest-webinar
-
-
Expert-level pentesting. On demand. Built for speed. Today we’re introducing XBOW Pentest On-Demand. Teams can now secure what they ship, without delay. → Launch a test in minutes → Get validated, reproducible results in days → Compliance-ready reports, no meetings required Security should move at the speed of your business. 🗓️ See it live in tomorrow’s demo xbow.com/pentest-webinar #Pentesting #AutonomousSecurity #SecurityAI
-
As BloomPath AI’s engineering org scaled 4x in a year, they faced a familiar challenge: How do you keep security in sync with velocity, without burning out teams or delaying releases? With XBOW, they moved to: → Autonomous offensive security → Real exploits, not false positives → 2-hour validations built into CI/CD Security caught up to the pace of development, without compromise. 📰 Read the full story: https://lnkd.in/eiFQkjSR 🚀 Start your own: https://xbow.com/pentest
-
-
From #1 on HackerOne to Fortune’s Cyber60. XBOW topped HackerOne’s leaderboard in under five months. Last week, we were named Early Growth Stage category winner in the Cyber60 list by AWS, Lightspeed, and Fortune. But this milestone is more than a recognition, it’s a signal. Autonomous offensive security isn’t hypothetical. It’s here. It works. And today, it's available to companies of all sizes. No lead times. No human bottlenecks. No meetings. Just real exploits, real coverage, launched in minutes. 📰 Read Nico Waisman's recap → https://lnkd.in/gDZyQJGv