Blog
Security Research
Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
Alvaro MuñozSecurity Research
Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution
Alvaro MuñozTechnical Deep Dive
How XBOW Turned a JavaScript Hint Into a Working File Inclusion
Nico WaismanAI Research
Agents Built From Alloys
Albert ZieglerTechnical Deep Dive
When the Heat Gets to Your Database: A Refreshing SQL Injection Discovery in Z-Push
Javier GilSecurity Research
Finding XSS in Salesforce Aura Components: How XBOW Got Creative
Diego JuradoSecurity Research
CVE-2025-49493: XML External Entity (XXE) Injection in Akamai CloudTest
Diego JuradoSecurity Research
Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN
Alvaro MuñozCompany News