Cyber Defenders and Attackers Turn to AI
Changing the Balance Between Attackers and Defenders
In this Bloomberg Tech interview, XBOW founder and CEO Oege de Moor joins Altimeter Capital Partner Apoorv Agrawal and hosts Caroline Hyde and Ed Ludlow to discuss how AI is changing the balance between cyber attackers and defenders.
The conversation begins with a milestone for autonomous cybersecurity: XBOW became the first AI system to reach the top of HackerOne’s U.S. leaderboard. The ranking is based on vulnerabilities accepted by participating companies, demonstrating that an autonomous system can successfully discover real security flaws in production environments.
Oege explains how XBOW uses an always-on swarm of AI agents to perform work that would traditionally require a large team of human security researchers operating around the clock. The agents conduct reconnaissance, scan applications, attempt exploitation, and report vulnerabilities so organizations can identify weaknesses before attackers find them. Over time, Oege expects autonomous systems to move beyond finding vulnerabilities and assist with fixing them as well.
The discussion focuses heavily on speed. AI is helping developers produce more software and code faster, expanding the potential attack surface at the same time that attackers gain access to increasingly capable AI tools. Apoorv argues that cybersecurity has always been a race between offense and defense, and that giving defenders even a few weeks of advantage can significantly reduce their exposure to newly discovered vulnerabilities.
AI also has the potential to change how security professionals work. Routine tasks such as reconnaissance, scanning, exploitation, and reporting can increasingly be automated, while experienced security researchers can use autonomous tools to expand their reach and focus on higher-value work. Rather than simply replacing human expertise, the technology can increase the scale at which that expertise is applied.
The conversation also looks at XBOW’s path toward broader enterprise adoption. Oege says the company is focused on organizations with significant security requirements, including financial services and healthcare, where continuously identifying exploitable vulnerabilities can have particularly high value.
The interview closes with the broader cybersecurity arms race created by AI. As attackers gain access to faster and more capable technology, defenders need comparable capabilities to keep pace. XBOW’s approach is to put autonomous offensive security in the hands of defenders, continuously testing their systems so vulnerabilities can be discovered and addressed before adversaries exploit them.