<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>XBOW Blog</title>
    <link>https://xbow.com/blog</link>
    <description>Latest posts from the XBOW blog</description>
    <language>en-us</language>
    <atom:link href="https://xbow.com/blog/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AI Pentesting Adoption Challenges for Enterprise: What’s Actually Getting in the Way</title>
      <link>https://xbow.com/blog/ai-pentesting-adoption-challenges-enterprise</link>
      <guid isPermaLink="true">https://xbow.com/blog/ai-pentesting-adoption-challenges-enterprise</guid>
      <description>Enterprise AI pentesting adoption depends on trusted findings, controlled testing, governance alignment, and integration with existing security workflows.</description>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Grok 4.5 Poised To Take Over the Middle of the AI Security Market</title>
      <link>https://xbow.com/blog/Grok-4-5-ai-model-offensive-security</link>
      <guid isPermaLink="true">https://xbow.com/blog/Grok-4-5-ai-model-offensive-security</guid>
      <description>Grok 4.5 delivers near frontier offensive security performance at a practical price, making it the strongest AI model for many real-world cybersecurity workloads in the middle of the cost curve.</description>
      <pubDate>Fri, 10 Jul 2026 18:09:38 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Human-in-the-Loop AI Pentesting</title>
      <link>https://xbow.com/blog/human-in-the-loop-ai-pentesting</link>
      <guid isPermaLink="true">https://xbow.com/blog/human-in-the-loop-ai-pentesting</guid>
      <description>AI is transforming penetration testing by automating security assessments, but the most effective approach combines autonomous AI with human oversight to deliver faster, more accurate, and context-aware results.</description>
      <pubDate>Fri, 10 Jul 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>The Rise of Affordable Models: Comparing GLM and Muse Spark on Cyber</title>
      <link>https://xbow.com/blog/affordable-ai-models-glm-muse-spark-cybersecurity</link>
      <guid isPermaLink="true">https://xbow.com/blog/affordable-ai-models-glm-muse-spark-cybersecurity</guid>
      <description>Lower-cost AI models like Muse Spark 1.1 and GLM are rapidly improving, making AI-powered offensive security more accessible and changing the economics of vulnerability discovery.</description>
      <pubDate>Thu, 09 Jul 2026 20:07:35 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Continuous Vulnerability Testing With a Small Team: A Practical Guide</title>
      <link>https://xbow.com/blog/continuous-vulnerability-testing-small-teams</link>
      <guid isPermaLink="true">https://xbow.com/blog/continuous-vulnerability-testing-small-teams</guid>
      <description>Continuous vulnerability testing only reduces risk when teams prioritize exploitable findings, streamline remediation, and measure success by how quickly issues are fixed, not how many are found.</description>
      <pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Can an AI Pentest Replace Human Pentesters?</title>
      <link>https://xbow.com/blog/can-ai-replace-human-pentesters</link>
      <guid isPermaLink="true">https://xbow.com/blog/can-ai-replace-human-pentesters</guid>
      <description>AI pentesting accelerates vulnerability discovery and expands testing coverage, enabling human pentesters to focus on the complex, business logic-driven attacks where their expertise delivers the greatest value.</description>
      <pubDate>Mon, 29 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>AI Pentesting Tools vs Automated Vulnerability Scanners</title>
      <link>https://xbow.com/blog/ai-pentesting-vs-vulnerability-scanners</link>
      <guid isPermaLink="true">https://xbow.com/blog/ai-pentesting-vs-vulnerability-scanners</guid>
      <description>AI pentesting goes beyond automated vulnerability scanning by proving which vulnerabilities are actually exploitable, dramatically reducing false positives and delivering more accurate, actionable security findings.</description>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Enterprise Application Pentesting Best Practices: A Guide for Large-Scale Security Teams</title>
      <link>https://xbow.com/blog/ai-pentesting-enterprise-large-security-teams</link>
      <guid isPermaLink="true">https://xbow.com/blog/ai-pentesting-enterprise-large-security-teams</guid>
      <description>Enterprise pentesting requires continuous, validated testing that scales with changing applications, helping security teams prioritize real risk, accelerate remediation, and maintain coverage across complex environments.</description>
      <pubDate>Fri, 12 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>How CISOs Can Close the AI Security Gap Before It Widens: A Practical Framework</title>
      <link>https://xbow.com/blog/how-cisos-can-close-the-ai-security-gap</link>
      <guid isPermaLink="true">https://xbow.com/blog/how-cisos-can-close-the-ai-security-gap</guid>
      <description>AI is helping attackers move faster, not differently. Learn the practical steps CISOs can take now to strengthen security fundamentals, accelerate remediation, and prepare for AI-driven threats.</description>
      <pubDate>Tue, 09 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>Suzanne Ciccone</dc:creator>
      <category>Security Research</category>
    </item>
    <item>
      <title>GPT-5.5 and XBOW: A Step Change in Autonomous Application Security</title>
      <link>https://xbow.com/blog/gpt-5-5-and-xbow-a-step-change-in-autonomous-application-security</link>
      <guid isPermaLink="true">https://xbow.com/blog/gpt-5-5-and-xbow-a-step-change-in-autonomous-application-security</guid>
      <description>The most efficient vulnerability discovery model we’ve ever tested is now part of XBOW.</description>
      <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>Christopher Ford</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Mythos and GPT-5.5 Will Find a Lot of Vulnerabilities. Is That Enough?</title>
      <link>https://xbow.com/blog/mythos-gpt-5-5-ai-vulnerability-detection-security</link>
      <guid isPermaLink="true">https://xbow.com/blog/mythos-gpt-5-5-ai-vulnerability-detection-security</guid>
      <description>Frontier AI models like Mythos and GPT-5.5 can uncover real vulnerabilities, but enterprise-ready offensive security requires much more than finding bugs, including coverage, validation, safety, governance, and operational integration.</description>
      <pubDate>Tue, 02 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>Suzanne Ciccone</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Getting to “Should I?”, Instead of “Can I?”: How XBOW Finds IDORs With High Accuracy in Ambiguous Contexts</title>
      <link>https://xbow.com/blog/xbow-finds-idors-high-accuracy-ambiguous-context</link>
      <guid isPermaLink="true">https://xbow.com/blog/xbow-finds-idors-high-accuracy-ambiguous-context</guid>
      <description>By understanding expected access patterns before testing them, XBOW brings context-aware reasoning to complex authorization issues.</description>
      <pubDate>Thu, 28 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>Alvaro Muñoz</dc:creator>
      <category>Product</category>
    </item>
    <item>
      <title>Ethical Considerations in AI-Driven Penetration Testing: A Governance Framework for Security Teams</title>
      <link>https://xbow.com/blog/ethical-considerations-ai-pentesting</link>
      <guid isPermaLink="true">https://xbow.com/blog/ethical-considerations-ai-pentesting</guid>
      <description>AI-driven pentesting introduces new governance challenges around authorization, accountability, privacy, and explainability, requiring security teams to pair autonomous testing with enforceable controls, validated findings, and human oversight.</description>
      <pubDate>Fri, 22 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Dead.Letter (CVE-2026-45185) How XBOW Found an Unauthenticated RCE on Exim</title>
      <link>https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim</link>
      <guid isPermaLink="true">https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim</guid>
      <description>XBOW discovered CVE-2026-45185, a critical unauthenticated RCE in Exim, and used the disclosure window to test how far human and autonomous exploit development could go.</description>
      <pubDate>Tue, 12 May 2026 14:00:00 GMT</pubDate>
      <dc:creator>Federico Kirschbaum</dc:creator>
        <dc:creator>Andres Luksenberg</dc:creator>
      <category>Security Research</category>
    </item>
    <item>
      <title>Mythos for Offensive Security: XBOW&apos;s Evaluation</title>
      <link>https://xbow.com/blog/mythos-offensive-security-xbow-evaluation</link>
      <guid isPermaLink="true">https://xbow.com/blog/mythos-offensive-security-xbow-evaluation</guid>
      <description>We received early access to Mythos Preview for early capability testing a few weeks back. Today, we can finally share what we found. </description>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
      <category>Security Research</category>
    </item>
    <item>
      <title>10 Red Flags to Investigate When Evaluating AI Pentesting Vendors</title>
      <link>https://xbow.com/blog/ai-pentest-vendors-red-flags</link>
      <guid isPermaLink="true">https://xbow.com/blog/ai-pentest-vendors-red-flags</guid>
      <description>AI pentesting helps security teams scale testing and improve efficiency, but many vendors overstate AI capabilities and results. To simplify evaluation, watch for key red flags and challenge questionable claims early in the process.</description>
      <pubDate>Fri, 08 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>What Is Insecure Direct Object Reference (IDOR), and How Do You Test for It?</title>
      <link>https://xbow.com/blog/insecure-direct-object-reference-idor</link>
      <guid isPermaLink="true">https://xbow.com/blog/insecure-direct-object-reference-idor</guid>
      <description>IDORs are difficult because they live in the gap between what an application accepts and what it should allow. Finding them consistently requires persistence, context, and the ability to reason through business logic.</description>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>How to Evaluate an AI Pentesting Vendor: A Decision Framework for Security Leaders</title>
      <link>https://xbow.com/blog/ai-pentesting-evaluation-guide</link>
      <guid isPermaLink="true">https://xbow.com/blog/ai-pentesting-evaluation-guide</guid>
      <description>AI pentesting helps scale offensive security by automating discovery, exploitation, and validation, with solutions ranging from assisted tools to fully autonomous agents.</description>
      <pubDate>Mon, 27 Apr 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>GPT-5.5: Democratizing Cyber Capabilities</title>
      <link>https://xbow.com/blog/democratizing-cyber-capabilities</link>
      <guid isPermaLink="true">https://xbow.com/blog/democratizing-cyber-capabilities</guid>
      <description>Today, OpenAI released GPT 5.5, its answer to Anthropic’s Mythos. The two companies took very different paths. This is the same old security question: who gets access to powerful tools and research?</description>
      <pubDate>Thu, 23 Apr 2026 18:00:00 GMT</pubDate>
      <dc:creator>Oege de Moor</dc:creator>
        <dc:creator>Nico Waisman</dc:creator>
      <category>Company News</category>
    </item>
    <item>
      <title>GPT-5.5: Mythos-Like Hacking, Open to All</title>
      <link>https://xbow.com/blog/mythos-like-hacking-open-to-all</link>
      <guid isPermaLink="true">https://xbow.com/blog/mythos-like-hacking-open-to-all</guid>
      <description>We had early access over the past few weeks and tested it across our benchmarks and workflows. Here’s how 5.5 performed for our offensive security capabilities.</description>
      <pubDate>Thu, 23 Apr 2026 18:00:00 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
        <dc:creator>Steve  Buckley</dc:creator>
      <category>AI Research</category>
    </item>
  </channel>
</rss>