XBOW reposted this
Heading to SecTor next week? The XBOW team will be at Booth #430. Stop by and see what we've been building. 🍁 #SecTor2026 #CyberSecurity #OffensiveSecurity #AI #XBOW
XBOW is the autonomous offensive security company redefining cyber defense for the AI era. Combining AI reasoning with offensive security workflows, the XBOW platform delivers expert-level security testing at machine speed. XBOW empowers security teams to transform from reactive to proactive defense at AI scale. For XBOW customers, autonomous offense is the best defense.
External link for XBOW
XBOW autonomously finds exploitable vulnerabilities before attackers do. It plans, executes, and validates real attacks on your web applications on demand. XBOW combines AI reasoning with proven security tooling to run full attack chains in hours, not weeks. Using source-code context, headless browsing, and runtime exploitation, XBOW surfaces zero-days and novel vulnerability classes traditional scanners miss. Every attack path is fully documented. Security teams reduce risk at a predictable cost without additional headcount.
Seattle, Washington, US
XBOW reposted this
Heading to SecTor next week? The XBOW team will be at Booth #430. Stop by and see what we've been building. 🍁 #SecTor2026 #CyberSecurity #OffensiveSecurity #AI #XBOW
XBOW reposted this
2006: Started a side project at Oxford. 2011: NASA used it to find bugs in their Mars rover. 2019: Sold to Microsoft and became GitHub Advanced Security. Semmle was a query engine for source code, and its killer application was finding security bugs in code. In particular, if you already knew of a vulnerability, it allowed you to write a query to find all variants of that bug. We'd go to a big company and ask them to show us 3 bad security bugs they’d had before, then we’d come back to them with 10 variants they didn’t know existed. Only 5 years after launch, Semmle helped NASA ensure the safe landing of the Curiosity Mars rover. Semmle found 33 undetected variants of a bug in the landing software (remember the “seven minutes of terror”?) while the rover was still on its way to Mars. NASA patched them, and the rover landed safely. In 2018, we raised a $21 million Series B from Accel. By that point, many large banks and big tech companies had become customers. By 2019, Microsoft, which owned GitHub, was our biggest customer. So when it came to the acquisition, GitHub felt like the natural home for Semmle. The culture fit was great, and the integration went very smoothly. The day the deal closed, I announced it at our weekly Friday all-hands in Oxford. It was a deeply emotional moment: the team fought together for 13 years, side-by-side. The team were my friends, and the company had become part of my own identity. That’s why, when I'm asked what I learned from the acquisition, I tell people it's super important to choose a good home for your team and your product. You spend years nurturing and growing a company, so if you decide to sell, make sure the people and product you love will thrive. I couldn't have wished for a better home for Semmle than GitHub. The product was renamed GitHub Advanced Security (specifically CodeQL), and it became wildly popular thanks to the commercial efforts of Niroshan and team. Our security researchers became the core of GitHub Security Lab. Many of the engineering team stayed around at GitHub, proving that indeed it was a good home for us all. For me, working with people I admire is my greatest professional joy. Today Nico is our CISO at XBOW, and Niroshan leads our GTM team. Many others came along with us. And we’re still relentlessly pursuing the same mission: defend the world, by finding the bugs before the bad guys do.
Recent events demonstrated again that we need to secure the entire application portfolio against AI-powered attackers. 🛡️ Autonomous Exposure Management helps you get there: you set the starting scope, XBOW discovers the rest, and agents test hundreds of apps in parallel with reproducible evidence for every finding. Join us live: TODAY, Wednesday, September 30 at 1pm ET / 10am PT, where Maury Cupitt and Steffen Canty discuss the AI-driven attacker trends that shaped this and the problems we had to solve to get here. Sign up now: https://lnkd.in/gWSr7vHg
XBOW reposted this
Meet Nico Waisman, Founder & Chief Security at XBOW. And on October 26, he's the opening keynote speaker at DMV Rising. 17 years hunting vulnerabilities at Immunity. GitHub Security Lab. CISO at Lyft, where he built a security program that kept pace with engineering speed without becoming a bottleneck. Now building autonomous agents at XBOW that do what human penetration testers do—but at scale, and without human constraints. His keynote: Autonomous Offense: AI, Agentic Pen Testing, and the Race to Patch Faster. He's diving into what happens when you point AI agents at real systems with no guardrails. What he learned: they behave exactly as designed. And that's the problem... and the opportunity. If you're building defenses, architecting security programs, or trying to stay ahead of what's coming, you need to be there. Learn more about DMV Rising and request a seat today: https://dmvrising.com/ DMV Rising · October 26 · Day 1 of the Cyber Innovation Conference Media Partners: CyberEdBoard Community | Information Security Media Group (ISMG) Platinum sponsors: Virtru | DataTribe Gold: XBOW | Anaconda Silver: Cape | Expel | Four Inc. | JPMorganChase | Sonatype Bronze: Method Security | threatER Community Partners: STATION DC | The Cyber Guild | VCDC | DCA Live
XBOW reposted this
Tune in tomorrow. From one app at a time to your whole portfolio: join us to see how Autonomous Exposure Management finds what's exposed and proves what's reachable. Sept 30th - 10 AM PT https://lnkd.in/gtVVcXzP
🎯 XBOW discovered and validated a vulnerability in the Linux kernel code [𝘊𝘝𝘌-2026-72018] that human researchers had largely overlooked and successfully developed a working LPE exploit. This research also exposed where autonomy still breaks down at the research frontier. XBOW handled the bulk of the threat modeling, code auditing, vulnerability discovery, validation, and exploit development, but a few critical moments required human judgment to redirect its reasoning. Those interventions ultimately shaped how we redesigned the system to handle long-running research more autonomously. Read more on how we found it in the full write up: https://lnkd.in/g-BgVigP
TORONTO 🇨🇦 Heading to SecTor 2026 this October? We can't wait to show you XBOW in action! If you want to meet up, let's connect: https://lnkd.in/g6r-vy7P
The vulnpocalypse has enter the zeigiest, and the technical debt can no longer be ignored. 🫣 Casey Ellis, founder of Bugcrowd, shares his thoughts about what that means for the state of bug bounties and more in the latest episode of 𝐎𝐟𝐟𝐞𝐧𝐬𝐞 𝐓𝐚𝐤𝐞𝐧, hosted by Federico Kirschbaum. Watch the full conversation here: https://lnkd.in/gZhJdyPb
Introducing Autonomous Exposure Management: Offensive Security at Enterprise Scale 👏 XBOW tests your whole external application estate the way an attacker would, with no source code and no credentials, and proves what is exploitable. At a glance: 🟢 Across enterprises, teams own three to 10 times more applications than they pentest. 🟢 XBOW finds your external application estate and brings it in as scoped targets. Our team runs that work, and you approve the list before testing starts. 🟢 Agents test targets in parallel, on demand, with no scheduling. 🟢 Testing starts from an attacker's perspective: no source code, no credentials. 🟢 Every finding arrives with reproducible evidence, severity, and remediation guidance. Learn more: https://lnkd.in/gaYi77z9