Tag
Application Security
Offensive Security Academy
AI Pentesting Tools vs Automated Vulnerability Scanners
XBOW TeamAI Research
GPT-5.5 and XBOW: A Step Change in Autonomous Application Security
Christopher FordProduct
Getting to “Should I?”, Instead of “Can I?”: How XBOW Finds IDORs With High Accuracy in Ambiguous Contexts
Alvaro MuñozOffensive Security Academy
What Is Insecure Direct Object Reference (IDOR), and How Do You Test for It?
XBOW TeamOffensive Security Academy
AI-Assisted Attack Path Analysis and Exploitation Planning
XBOW TeamSecurity Research
Three Critical RCE Vulnerabilities in Microsoft Software Identified Autonomously by XBOW
Nico WaismanProduct
XBOW AI-Driven Pentesting vs. DAST
XBOW TeamOffensive Security Academy
How Often Should Penetration Testing Be Done?
XBOW TeamOffensive Security Academy
What Is AI-Driven Pen Testing
XBOW TeamAI Research
Tales from the Trace: How Context-Aware AI Redefines Vulnerability Reports
Ray KellySecurity Research
React2Shell (CVE-2025-55182): A Wake-Up Call for Modern Web Security and How XBOW Helps You Respond
Nico WaismanAI Research
Tales from the Trace: How Agentic AI Merges Static and Dynamic Testing
Ray Kelly, Alvaro MuñozSecurity Research
Cooking an SQL Injection Vulnerability in Chef Automate
Javier GilSecurity Research
CVE-2025-27888: Server-Side Request Forgery via URL Parsing Confusion in Apache Druid Proxy Endpoint
Nico WaismanCompany News
XBOW Partners with Vanta to Bring Autonomous Penetration Testing to Startups
Joanna CliftonSecurity Research
The Campaign Is Not Available in Your Country: XBOW Discovered an SQLi While Attempting to Bypass Geolocation Restrictions.
Nico WaismanSecurity Research
Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
Alvaro MuñozSecurity Research
Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution
Alvaro MuñozSecurity Research
How XBOW Turned a JavaScript Hint Into a Working File Inclusion
Nico WaismanSecurity Research
When the Heat Gets to Your Database: A Refreshing SQL Injection Discovery in Z-Push
Javier GilSecurity Research
Finding XSS in Salesforce Aura Components: How XBOW Got Creative
Diego JuradoSecurity Research
CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest
Diego JuradoSecurity Research
Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN
Alvaro MuñozSecurity Research
The Nightmare Before Christmas: An Arbitrary File Download on Zoo-Project
Nico WaismanSecurity Research
Stored Cross-Site Scripting (XSS) in 2FAuth
Diego JuradoSecurity Research
LabsAI’s EDDI Project Path Traversal
Diego JuradoSecurity Research
SSRF & URI Validation Bypass in 2FAuth
Nico WaismanSecurity Research
How XBOW Found a Scoold Authentication Bypass
Nico WaismanSecurity Research