Skip to main content

Tag

Application Security

Offensive Security Academy
AI Pentesting Tools vs Automated Vulnerability Scanners

AI Pentesting Tools vs Automated Vulnerability Scanners

XBOW Team
AI Research
GPT-55 and XBOW A Step Change in Autonomous Application Security.

GPT-5.5 and XBOW: A Step Change in Autonomous Application Security

Christopher Ford
Product
Getting to “Should I?"

Getting to “Should I?”, Instead of “Can I?”: How XBOW Finds IDORs With High Accuracy in Ambiguous Contexts

Alvaro Muñoz
Offensive Security Academy
What Is Insecure Direct Object Reference (IDOR), and How Do You Test for It?

What Is Insecure Direct Object Reference (IDOR), and How Do You Test for It?

XBOW Team
Offensive Security Academy
AI-Assisted Attack Path Analysis and Exploitation Planning

AI-Assisted Attack Path Analysis and Exploitation Planning

XBOW Team
Security Research
Three Critical RCE Vulnerabilities in Microsoft Software Identified Autonomously by XBOW

Three Critical RCE Vulnerabilities in Microsoft Software Identified Autonomously by XBOW

Nico Waisman
Product
XBOW AI-Driven Pentesting vs. DAST

XBOW AI-Driven Pentesting vs. DAST

XBOW Team
Offensive Security Academy
How Often Should Penetration Testing Be Done?

How Often Should Penetration Testing Be Done?

XBOW Team
Offensive Security Academy
What Is AI-Driven Pen Testing

What Is AI-Driven Pen Testing

XBOW Team
AI Research
Tales from the Trace: How Context-Aware AI Redefines Vulnerability Reports

Tales from the Trace: How Context-Aware AI Redefines Vulnerability Reports

Ray Kelly
Security Research
React2Shell (CVE-2025-55182): A Wake-Up Call for Modern Web Security and How XBOW Helps You Respond

React2Shell (CVE-2025-55182): A Wake-Up Call for Modern Web Security and How XBOW Helps You Respond

Nico Waisman
AI Research
Tales from the Trace: How Agentic AI Merges Static and Dynamic Testing

Tales from the Trace: How Agentic AI Merges Static and Dynamic Testing

Ray Kelly, Alvaro Muñoz
Security Research
Cooking an SQL Injection Vulnerability in Chef Automate

Cooking an SQL Injection Vulnerability in Chef Automate

Javier Gil
Security Research
CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint

CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint

Nico Waisman
Company News
XBOW Partners with Vanta to Bring Autonomous Penetration Testing to Startups

XBOW Partners with Vanta to Bring Autonomous Penetration Testing to Startups

Joanna Clifton
Security Research
The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.

The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.

Nico Waisman
Security Research
Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle

Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle

Alvaro Muñoz
Security Research
Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution

Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution

Alvaro Muñoz
Security Research
How XBOW Turned a JavaScript Hint Into a Working File Inclusion

How XBOW Turned a JavaScript Hint Into a Working File Inclusion

Nico Waisman
Security Research
When the Heat Gets to Your Database: A Refreshing SQL Injection Discovery in Z-Push

When the Heat Gets to Your Database: A Refreshing SQL Injection Discovery in Z-Push

Javier Gil
Security Research
Finding XSS in Salesforce Aura Components: How XBOW Got Creative

Finding XSS in Salesforce Aura Components: How XBOW Got Creative

Diego Jurado
Security Research
CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest

CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest

Diego Jurado
Security Research
Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN

Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN

Alvaro Muñoz
Security Research
The Nightmare Before Christmas: An Arbitrary File Download on Zoo-Project

The Nightmare Before Christmas: An Arbitrary File Download on Zoo-Project

Nico Waisman
Security Research
Stored Cross-Site Scripting (XSS) in 2FAuth

Stored Cross-Site Scripting (XSS) in 2FAuth

Diego Jurado
Security Research
LabsAI’s EDDI Project Path Traversal

LabsAI’s EDDI Project Path Traversal

Diego Jurado
Security Research
SSRF & URI Validation Bypass in 2FAuth

SSRF & URI Validation Bypass in 2FAuth

Nico Waisman
Security Research
How XBOW Found a Scoold Authentication Bypass

How XBOW Found a Scoold Authentication Bypass

Nico Waisman
Security Research
XBOW Battles Ninja Tables: Who’s the Real Ninja?

XBOW Battles Ninja Tables: Who’s the Real Ninja?

Alvaro Muñoz