<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>XBOW Blog</title>
    <link>https://website-xbow.vercel.app//blog</link>
    <description>Latest posts from the XBOW blog</description>
    <language>en-us</language>
    <atom:link href="https://website-xbow.vercel.app//blog/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AI Pentesting Tools vs Automated Vulnerability Scanners</title>
      <link>https://website-xbow.vercel.app//blog/ai-pentesting-vs-vulnerability-scanners</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ai-pentesting-vs-vulnerability-scanners</guid>
      <description>AI pentesting goes beyond automated vulnerability scanning by proving which vulnerabilities are actually exploitable, dramatically reducing false positives and delivering more accurate, actionable security findings.</description>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Enterprise Application Pentesting Best Practices: A Guide for Large-Scale Security Teams</title>
      <link>https://website-xbow.vercel.app//blog/ai-pentesting-enterprise-large-security-teams</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ai-pentesting-enterprise-large-security-teams</guid>
      <description>Enterprise pentesting requires continuous, validated testing that scales with changing applications, helping security teams prioritize real risk, accelerate remediation, and maintain coverage across complex environments.</description>
      <pubDate>Fri, 12 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>How CISOs Can Close the AI Security Gap Before It Widens: A Practical Framework</title>
      <link>https://website-xbow.vercel.app//blog/how-cisos-can-close-the-ai-security-gap</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/how-cisos-can-close-the-ai-security-gap</guid>
      <description>AI is helping attackers move faster, not differently. Learn the practical steps CISOs can take now to strengthen security fundamentals, accelerate remediation, and prepare for AI-driven threats.</description>
      <pubDate>Tue, 09 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>Suzanne Ciccone</dc:creator>
      <category>Security Research</category>
    </item>
    <item>
      <title>GPT-5.5 and XBOW: A Step Change in Autonomous Application Security</title>
      <link>https://website-xbow.vercel.app//blog/gpt-5-5-and-xbow-a-step-change-in-autonomous-application-security</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/gpt-5-5-and-xbow-a-step-change-in-autonomous-application-security</guid>
      <description>The most efficient vulnerability discovery model we’ve ever tested is now part of XBOW.</description>
      <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>Christopher Ford</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Mythos and GPT-5.5 Will Find a Lot of Vulnerabilities. Is That Enough?</title>
      <link>https://website-xbow.vercel.app//blog/mythos-gpt-5-5-ai-vulnerability-detection-security</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/mythos-gpt-5-5-ai-vulnerability-detection-security</guid>
      <description>Frontier AI models like Mythos and GPT-5.5 can uncover real vulnerabilities, but enterprise-ready offensive security requires much more than finding bugs, including coverage, validation, safety, governance, and operational integration.</description>
      <pubDate>Tue, 02 Jun 2026 12:00:00 GMT</pubDate>
      <dc:creator>Suzanne Ciccone</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Getting to “Should I?”, Instead of “Can I?”: How XBOW Finds IDORs With High Accuracy in Ambiguous Contexts</title>
      <link>https://website-xbow.vercel.app//blog/xbow-finds-idors-high-accuracy-ambiguous-context</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/xbow-finds-idors-high-accuracy-ambiguous-context</guid>
      <description>By understanding expected access patterns before testing them, XBOW brings context-aware reasoning to complex authorization issues.</description>
      <pubDate>Thu, 28 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>Alvaro Muñoz</dc:creator>
      <category>Product</category>
    </item>
    <item>
      <title>Ethical Considerations in AI-Driven Penetration Testing: A Governance Framework for Security Teams</title>
      <link>https://website-xbow.vercel.app//blog/ethical-considerations-ai-pentesting</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ethical-considerations-ai-pentesting</guid>
      <description>AI-driven pentesting introduces new governance challenges around authorization, accountability, privacy, and explainability, requiring security teams to pair autonomous testing with enforceable controls, validated findings, and human oversight.</description>
      <pubDate>Fri, 22 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Dead.Letter (CVE-2026-45185) How XBOW Found an Unauthenticated RCE on Exim</title>
      <link>https://website-xbow.vercel.app//blog/dead-letter-cve-2026-45185-xbow-found-rce-exim</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/dead-letter-cve-2026-45185-xbow-found-rce-exim</guid>
      <description>XBOW discovered CVE-2026-45185, a critical unauthenticated RCE in Exim, and used the disclosure window to test how far human and autonomous exploit development could go.</description>
      <pubDate>Tue, 12 May 2026 14:00:00 GMT</pubDate>
      <dc:creator>Federico Kirschbaum</dc:creator>
        <dc:creator>Andres Luksenberg</dc:creator>
      <category>Security Research</category>
    </item>
    <item>
      <title>Mythos for Offensive Security: XBOW&apos;s Evaluation</title>
      <link>https://website-xbow.vercel.app//blog/mythos-offensive-security-xbow-evaluation</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/mythos-offensive-security-xbow-evaluation</guid>
      <description>We received early access to Mythos Preview for early capability testing a few weeks back. Today, we can finally share what we found. </description>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>10 Red Flags to Investigate When Evaluating AI Pentesting Vendors</title>
      <link>https://website-xbow.vercel.app//blog/ai-pentest-vendors-red-flags</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ai-pentest-vendors-red-flags</guid>
      <description>AI pentesting helps security teams scale testing and improve efficiency, but many vendors overstate AI capabilities and results. To simplify evaluation, watch for key red flags and challenge questionable claims early in the process.</description>
      <pubDate>Fri, 08 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>What Is Insecure Direct Object Reference (IDOR), and How Do You Test for It?</title>
      <link>https://website-xbow.vercel.app//blog/insecure-direct-object-reference-idor</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/insecure-direct-object-reference-idor</guid>
      <description>IDORs are difficult because they live in the gap between what an application accepts and what it should allow. Finding them consistently requires persistence, context, and the ability to reason through business logic.</description>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>How to Evaluate an AI Pentesting Vendor: A Decision Framework for Security Leaders</title>
      <link>https://website-xbow.vercel.app//blog/ai-pentesting-evaluation-guide</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ai-pentesting-evaluation-guide</guid>
      <description>AI pentesting helps scale offensive security by automating discovery, exploitation, and validation, with solutions ranging from assisted tools to fully autonomous agents.</description>
      <pubDate>Mon, 27 Apr 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>GPT-5.5: Democratizing Cyber Capabilities</title>
      <link>https://website-xbow.vercel.app//blog/democratizing-cyber-capabilities</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/democratizing-cyber-capabilities</guid>
      <description>Today, OpenAI released GPT 5.5, its answer to Anthropic’s Mythos. The two companies took very different paths. This is the same old security question: who gets access to powerful tools and research?</description>
      <pubDate>Thu, 23 Apr 2026 18:00:00 GMT</pubDate>
      <dc:creator>Oege de Moor</dc:creator>
        <dc:creator>Nico Waisman</dc:creator>
      <category>Company News</category>
    </item>
    <item>
      <title>GPT-5.5: Mythos-Like Hacking, Open to All</title>
      <link>https://website-xbow.vercel.app//blog/mythos-like-hacking-open-to-all</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/mythos-like-hacking-open-to-all</guid>
      <description>We had early access over the past few weeks and tested it across our benchmarks and workflows. Here’s how 5.5 performed for our offensive security capabilities.</description>
      <pubDate>Thu, 23 Apr 2026 18:00:00 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
        <dc:creator>Steve  Buckley</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Smaller Bites, Bigger Meals: What We Learned Running Opus 4.7 in Offensive Workflows</title>
      <link>https://website-xbow.vercel.app//blog/anthropic-opus4-7-first-look</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/anthropic-opus4-7-first-look</guid>
      <description>We got exclusive early access to Anthropic&apos;s latest model Opus 4.7. Here&apos;s what&apos;s new, what&apos;s improved, and why it matters for the future of AI security.</description>
      <pubDate>Thu, 16 Apr 2026 14:00:25 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>Offensive Security Needs to Become Continuous</title>
      <link>https://website-xbow.vercel.app//blog/offensive-security-needs-to-become-continuous</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/offensive-security-needs-to-become-continuous</guid>
      <description>Continuous offensive security will become a shared layer that connects how software is built with how it’s secured.</description>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <dc:creator>Christopher Ford</dc:creator>
      <category>Product</category>
    </item>
    <item>
      <title>AI for Pentesting: Strengths, Weaknesses, and Where XBOW Fills the Gaps</title>
      <link>https://website-xbow.vercel.app//blog/ai-pentesting-strengths-weaknesses-xbow-fills-gaps</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ai-pentesting-strengths-weaknesses-xbow-fills-gaps</guid>
      <description>AI is transforming pentesting, but models alone fall short. Learn where AI excels, where it needs structure, and how validation and orchestration make it reliable.</description>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <dc:creator>Albert Ziegler</dc:creator>
      <category>AI Research</category>
    </item>
    <item>
      <title>AI-Assisted Attack Path Analysis and Exploitation Planning</title>
      <link>https://website-xbow.vercel.app//blog/ai-exploitation-attack-path-analysis</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/ai-exploitation-attack-path-analysis</guid>
      <description>AI-driven pentesting analyzes attack paths and plans exploits, connecting vulnerabilities into real attack chains and validating them to identify truly exploitable risk.</description>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Machine Learning for Vulnerability Discovery</title>
      <link>https://website-xbow.vercel.app//blog/machine-learning-for-vulnerability-discovery</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/machine-learning-for-vulnerability-discovery</guid>
      <description>Machine learning accelerates vulnerability discovery but lacks runtime context, making AI-driven validation essential to reduce false positives and confirm real exploitability.</description>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <dc:creator>XBOW Team</dc:creator>
      <category>Offensive Security Academy</category>
    </item>
    <item>
      <title>Three Critical RCE Vulnerabilities in Microsoft Software Identified Autonomously by XBOW</title>
      <link>https://website-xbow.vercel.app//blog/three-rce-vulnerabilities-in-microsoft-identified-xbow</link>
      <guid isPermaLink="true">https://website-xbow.vercel.app//blog/three-rce-vulnerabilities-in-microsoft-identified-xbow</guid>
      <description>For the first time, autonomous AI uncovered critical RCE vulnerabilities in Microsoft Cloud, demonstrating how AI-driven pentesting is accelerating real-world exploit discovery.</description>
      <pubDate>Thu, 02 Apr 2026 04:00:00 GMT</pubDate>
      <dc:creator>Nico Waisman</dc:creator>
      <category>Security Research</category>
    </item>
  </channel>
</rss>