A Conversation with Nico Waisman | Unsupervised Learning
Preparing for AI-Driven Offensive Security
AI is changing offensive security from a limited, point-in-time service into a continuous capability that can test more systems, go deeper into applications, and adapt as environments change.
In this episode of Unsupervised Learning, XBOW CISO Nico Waisman discusses how the company’s early HackerOne experiments helped demonstrate what AI could accomplish in real-world offensive security. Although the work initially drew criticism, it also accelerated product development and anticipated the broader adoption of AI tools now taking place across the security industry.
The conversation explores how AI-powered penetration testing can complement attack surface management by moving beyond asset discovery and low-hanging findings. By fingerprinting applications, grouping similar systems, prioritizing high-value targets, and combining broad coverage with deep testing, organizations can better evaluate how their environments would withstand adaptive, AI-driven attackers.
Asset context is central to this approach. Nico explains why security teams need an accurate model of their infrastructure, relationships, sensitive data, and potential blast radius. This organizational memory can help agents prioritize testing, validate whether reported vulnerabilities are actually exploitable, and distinguish theoretical findings from risks that require immediate action.
The discussion also looks ahead to customizable agent skills, expanded support for internal and source-informed testing, and XBOW’s move into native vulnerability research across browsers, firmware, and kernels. The result is a vision of offensive security where AI expands the capacity of human teams, continuously validates real exposure, and helps defenders prepare for machine-speed attacks.
Speakers
CISO @ XBOW