Inside the Rise of Autonomous AI Hackers
Autonomous Hacking Is Already Here
AI is moving cybersecurity from human-assisted testing to fully autonomous offensive operations.
In this talk, XBOW's Oege de Moor explains how autonomous AI agents can now perform black-box security testing with little more than a target URL. He highlights XBOW's discovery of a remote code execution vulnerability in Bing Image Search and its rise to the top of the HackerOne leaderboard as evidence that autonomous systems can already compete with, and in some cases outperform, elite human hackers.
The discussion explores how XBOW approaches attacks in much the same way a human researcher would, using reconnaissance, attack-surface discovery, prioritization, and repeated exploitation attempts. De Moor also explains how combining multiple frontier models can improve performance by allowing different models to compensate for one another's weaknesses.
He contrasts this approach with source-code analysis tools, arguing that defenders need more than theoretical findings. They need to know whether a vulnerability is actually exploitable, what impact it could have, and how far an attacker could move once inside.
The larger warning is about speed. Vulnerabilities are increasingly exploited before CVEs are publicly disclosed, leaving defenders less time to react. De Moor argues that security teams must adopt AI-powered testing, augment human researchers, and prioritize proven exploitability now, before autonomous offensive capabilities become broadly available.