Blog
Security Research
React2Shell (CVE-2025-55182): A Wake-Up Call for Modern Web Security and How XBOW Helps You Respond
Nico WaismanSecurity Research
How Companies Can Test Their Systems Against AI-powered Attacks Like GTG-1002
Aqeel SiddiquiSecurity Research
Cooking an SQL Injection Vulnerability in Chef Automate
Javier GilSecurity Research
The Chaos Phase: How AI is Transforming Cybersecurity Threats
Oege de MoorSecurity Research
CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint
Nico WaismanSecurity Research
The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.
Nico WaismanSecurity Research
Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
Alvaro MuñozSecurity Research
Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution
Alvaro MuñozSecurity Research