XBOW, AI Hackers, and the Future of Pen Testing | Three Buddy Problem
How AI Is Expanding the Reach of Offensive Security
AI is reshaping penetration testing, but its greatest impact may be expanding the reach of offensive security rather than replacing the people who practice it.
In this live episode of Between Two Problems from Ekoparty Miami, XBOW Head of Security Lab Federico Kirschbaum discusses how autonomous AI agents are changing vulnerability discovery and exploitation. Unlike traditional scanners, XBOW can reason through web applications, adapt its approach, combine multiple weaknesses, and validate findings with working exploits. Customers can also review the agents’ traces to understand how each vulnerability was discovered and exploited.
The conversation explores where human expertise remains essential. AI can accelerate repetitive research, broaden testing coverage, and compress weeks of exploitation work into days, but experienced practitioners still provide judgment, safety controls, strategic direction, and specialized knowledge. Rather than eliminating the craft, AI raises the level of abstraction and gives security professionals more time to focus on complex, meaningful problems.
Kirschbaum also places this shift within the history of offensive security, from early vulnerability scanners and exploit frameworks to bug bounty platforms. As AI lowers the cost of validated testing, penetration testing could become accessible to far more organizations. The discussion closes with a look at Argentina’s influential hacking community, Ekoparty’s role in developing global security talent, and the enduring importance of curiosity, expertise, and passion regardless of how the tools evolve.
Speakers
Head of Security Lab @ XBOW