Closing the Gap Between Vulnerability Discovery and Exploitation
Autonomous Pentesting at Machine Speed
In this RSAC 2026 interview, XBOW Chief Information and Security Officer Nico Waisman joins theCUBE’s Dave Vellante and John Oltsik to discuss how autonomous AI penetration testing is changing the speed and scale of offensive security.
The conversation begins with a growing problem for security teams: software is being created faster than organizations can test it. AI-assisted development and vibe coding are accelerating code production, while traditional penetration tests remain periodic and heavily dependent on scarce human expertise. Nico argues that closing this gap requires security testing that can operate at the same machine speed as modern software development.
XBOW approaches the problem with swarms of autonomous AI agents that attack web applications and attempt to prove whether vulnerabilities are actually exploitable. A separate validator architecture reviews findings, helping reduce false positives and provide security teams with evidence they can act on. Nico points to XBOW reaching the top of the HackerOne leaderboard as evidence that autonomous systems can compete with human researchers at discovering previously unknown vulnerabilities in production applications.
The discussion also explores how XBOW uses multiple foundation models rather than relying on a single AI provider. Different models can be selected for different tasks, including vulnerability discovery, exploitation, and safety validation. As model capabilities evolve, this architecture allows XBOW to incorporate stronger models without rebuilding the underlying platform.
The next step is moving penetration testing directly into the software development lifecycle. Instead of testing an application periodically, autonomous agents can continuously evaluate changes as new code is deployed, bringing offensive security closer to CI/CD workflows and allowing teams to identify exploitable vulnerabilities earlier.
Nico also discusses XBOW’s partnership with Microsoft, which connects offensive security findings with attack surface management and SOC workflows. The goal is a closed-loop security model where validated vulnerabilities can inform detection and response, helping defenders understand not only what is exposed, but how an attacker could actually exploit it.
The conversation closes with the broader implications of autonomous agents, MCP, and increasingly capable AI systems. As software and AI agents gain greater access to sensitive systems, organizations will need stronger governance and continuous validation. Nico argues that autonomous offensive security will become increasingly important as companies work to find and fix vulnerabilities at the same speed that both software and attacks are evolving.