#xbow
Dark Elf Repeater Xbow troops!
#paintingwarhammer
#darkelves
#theoldworld
December 9, 2024 at 10:38 AM
While developing XBOW over the past three months, we played around with using it for bug bounties and ended up at #11 in the US on HackerOne:
December 17, 2024 at 4:17 PM
Thank you for the custom controller @xbox.com 🥰

(Was a gift from Xbow Bowl )
January 20, 2026 at 6:08 PM
One of the best bug-hunters in the world is an AI tool called Xbow, just one of many signs of the coming age of cybersecurity automation.
AI Agents Are Getting Better at Writing Code—and Hacking It as Well
One of the best bug-hunters in the world is an AI tool called Xbow, just one of many signs of the coming age of cybersecurity automation.
wrd.cm
June 25, 2025 at 5:07 PM
New blog post by @nicowaisman.bsky.social on how XBOW found an SSRF in the OTP app 2FAuth (CVE-2024-52598) is now live! xbow.com/blog/xbow-2f...
XBOW – SSRF & URI validation bypass in 2FAuth
XBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth.
xbow.com
November 22, 2024 at 4:46 PM
XBOW says it will stop going for the HackerOne leaderboard

xbow.com/blog/xbow-on...
XBOW - XBOW on HackerOne: What’s Next
XBOW, our autonomous AI pen-tester, reached #1 on HackerOne's global leaderboards, proving AI can match human-level security research. With that question answered, we're now focused on helping custome...
xbow.com
August 19, 2025 at 4:11 PM
XBOW found a critical auth bypass (CVE-2024-50334) in Scoold, a widely-used open-source Q&A site, fully autonomously! @nicowaisman.bsky.social and I wrote up a post walking through the methodology it used – IMO it's a super cool bug and fascinating trace xbow.com/blog/xbow-sc...
XBOW – How XBOW found a Scoold authentication bypass
As we shift our focus from benchmarks to real world applications, we will be sharing some of the most interesting vulnerabilities XBOW has found in real-world, open-source targets. The first of these ...
xbow.com
November 14, 2024 at 4:10 PM
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
xbow.com
September 28, 2026 at 12:40 AM
XBOW autonomously discovered CVE-2024-50334, a critical authentication bypass in Scoold, an open-source Q&A webapp used by major companies like Cisco and IBM. Our recent blog post details how it found the flaw: xbow.com/blog/xbow-sc...
XBOW – How XBOW found a Scoold authentication bypass
As we shift our focus from benchmarks to real world applications, we will be sharing some of the most interesting vulnerabilities XBOW has found in real-world, open-source targets. The first of these ...
xbow.com
November 20, 2024 at 7:24 PM
I’ve to say that I’m impressed by how @xbow.com managed to identify this SSRF vulnerability (and bypass a MIME filter on its way) 🤖
XBOW – SSRF & URI validation bypass in 2FAuth
XBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth.
xbow.com
November 24, 2024 at 2:38 PM
Just in time for the holidays: how XBOW found an arbitrary file download (CVE-2024-53982) in ZOO-Project, protecting Santa's critical geospatial processing infrastructure from attackers! xbow.com/blog/xbow-zo...
XBOW – The Nightmare Before Christmas: An arbitrary file download on Zoo-Project
XBOW discovered an arbitrary file download vulnerability on the WPS open source app Zoo-Project.
xbow.com
December 20, 2024 at 4:24 PM
@xbow.com has been busy in the first few weeks of 2025 – our agent has autonomously found 106 vulnerabilities in OSS projects, and we've reported 72 so far! Amazing work by @nicowaisman.bsky.social and the security team triaging these and getting them into the disclosure->fix pipeline!
February 6, 2025 at 6:55 PM
The trick to how it did it is in this post: xbow.com/blog/xbow-ti... Some details below...
XBOW – Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
A complete arbitrary local file read vulnerability achieved through an ingenious byte-by-byte exfiltration technique.
xbow.com
July 28, 2025 at 10:10 PM
December 12, 2024 at 10:07 PM
Day 3 of the 2024 review and it the old favourite the #italianwars - 4 new units this year, a Bande Nere Pike Block, Papal Gendarme, Swiss Mtd Xbow and some Stradiots, don't think I'll ever stop !
#wargames #wargaming #Miniatures #history #tabletopgames
December 23, 2024 at 9:57 AM
1/ XBOW Unleashes GPT-5’s Hidden Hacking Power. 

OpenAI
's initial assessment of GPT-5 showed modest cyber capabilities. But when integrated into the XBOW platform, we saw a completely different story: performance more than doubled. 

More on what we found: 🧵
August 15, 2025 at 9:31 PM
Since the Xbow boys got there time in the spot light the Gunpowder boys wanted a go as well.
September 26, 2023 at 7:02 AM
AI vs AI: How XBOW found a path traversal vulnerability (CVE-2024-53844) in LabsAI's EDDI, an open source conversational AI middleware. xbow.com/blog/xbow-ed...
XBOW – LabsAI’s EDDI project path traversal
XBOW discovered a Path Traversal vulnerability in the open-source project, LabsAI’s EDDI.
xbow.com
December 2, 2024 at 4:41 PM
So, I’m not sure there is any good time to announce this, but as of August 31st I will be leaving NYU for good, to seek my fortune in industry with XBOW!
July 30, 2025 at 12:35 AM
Like a Sinclair C5 and a KTM XBow had a baby.
#weirdcarbs
September 9, 2025 at 5:24 AM
Welp, after playing my PoE2 character (Merc xbow) up into early maps, I can confidently say that GGG have held true to their vision to slow down everything about player speed and power.

Unfortunately, it has resulted in a game that simply isn’t fun to play.
December 14, 2024 at 5:35 PM
XBOW found a stored XSS vulnerability (CVE-2024-52597) in the migration functionality of 2FAuth by crafting a malicious SVG file with a Javascript payload! Our latest blog post gives the full details: xbow.com/blog/xbow-2f...
December 13, 2024 at 6:11 PM
Real security is POC || GTFO – and XBOW agrees.

We’re releasing technical deep-dives on cool findings from our journey to the top of the HackerOne US leaderboard.

The first is a zero-day XSS in Palo Alto Networks GlobalProtect by @pwntester.bsky.social.

xbow.com/blog/xbow-gl...
XBOW – Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN
XBOW discovered multiple cross-site scripting (XSS) vulnerabilities in Palo Alto Networks’ GlobalProtect VPN web application
xbow.com
June 24, 2025 at 7:58 PM
Even mature products hide critical flaws – and @xbow.com just found another one.

CVE-2025-49493: XXE in Akamai CloudTest discovered during its climb to #1 on HackerOne.

A complete technical breakdown from an error-based detection to a full exfiltration by Diego Jurado: xbow.com/blog/xbow-ak...
XBOW – CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest
When XBOW met Akamai: a walkthrough of discovering and exploiting an XML External Entity vulnerability (CVE-2025-49493) in a widely-deployed application.
xbow.com
June 30, 2025 at 7:42 PM
65 reports were submitted since September, including 20 critical findings
December 17, 2024 at 4:33 PM