Blog
Security Research
CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint
Nico WaismanCompany News
Empowering Defenders in the Age of AI: My Journey to XBOW
Niroshan RajaduraiCompany News
XBOW on HackerOne: What’s Next
Nico WaismanAI Research
XBOW Unleashes GPT-5’s Hidden Hacking Power, Doubling Performance
Oege de Moor, Albert ZieglerCompany News
Black Hat & DEF CON: Running XBOW Live, Presentation Slides, and The Talk You Didn’t Miss
Nico WaismanCompany News
XBOW Partners with Vanta to Bring Autonomous Penetration Testing to Startups
Joanna CliftonSecurity Research
The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.
Nico WaismanSecurity Research
Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
Alvaro MuñozSecurity Research