Earlier quoted context omitted.
Everyone already agrees with that; the interesting argument here is that it also makes it easy to produce many good results in short time.
But the good ones don’t have the same output rate because they are checked by humans before submission. They are faster than the purely manual ones but can’t beat the AI created bad ones neither in speed nor numbers. It’s like the IT security version of the Gish gallop.
XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
81–90 of 128 posts
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#82Have XBow provided a link to this claim, I could only find: https://hackerone.com/xbow?type=user Which shows a different picture. This may not invalidate their claim (best US), but a screenshot can be a bit cherry-picked.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#83Xbow has really smart people working on it, so they're well-aware of the usual 30-second critiques that come up in this thread. For example, they take specific steps to eliminate false positives. The #1 spot in the ranking is both more of a deal and less of a deal than it might appear. It's less of a deal in that HackerOne is an economic numbers game. There are countless programs you can sign up for, with varied diff…
Below people are reading the tea leaves to get any clue.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#84First: > To bridge that gap, we started dogfooding XBOW in public and private bug bounty programs hosted on HackerOne. We treated it like any external researcher would: no shortcuts, no internal knowledge—just XBOW, running on its own. Is it dogfooding if you're not doing it to yourself? I'd considerit dogfooding only if they were flooding themselves in AI generated bug reports, not to other people. They're not the o…
Seems reasonable to call that dogfooding considering that flooding themselves wouldn't be any more useful than synthetic testing and there's only so much ground they could cover using it on their own software.
If this were coming out of Microsoft or IBM or whatever then yeah, not really dogfooding.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#85Have XBow provided a link to this claim, I could only find: https://hackerone.com/xbow?type=user Which shows a different picture. This may not invalidate their claim (best US), but a screenshot can be a bit cherry-picked.
If you scroll down on [the leaderboard]( https://hackerone.com/leaderboard?year=2025&quarter=2&owasp=... ) page to Country and select United States, xbow is currently on top
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#86The future is definitely a combination of human and bots like anything else, it won't replace the humans just like coding bots won't replace devs. In fact this will allow humans to focus ob the fun/creative hacking instead of the basic/boring tests.
What I am worried about is on the triage/reproduction side, right now it is still mostly manual and it is a hard problem to automate.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#87Xbow has really smart people working on it, so they're well-aware of the usual 30-second critiques that come up in this thread. For example, they take specific steps to eliminate false positives. The #1 spot in the ranking is both more of a deal and less of a deal than it might appear. It's less of a deal in that HackerOne is an economic numbers game. There are countless programs you can sign up for, with varied diff…
I don't think LLM replace humans, they do free up time to do nicer tasks.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#88Xbow has really smart people working on it, so they're well-aware of the usual 30-second critiques that come up in this thread. For example, they take specific steps to eliminate false positives. The #1 spot in the ranking is both more of a deal and less of a deal than it might appear. It's less of a deal in that HackerOne is an economic numbers game. There are countless programs you can sign up for, with varied diff…
> Top infosec talent doesn't want to do it (and there's not enough of it). What is the top talent spending its time on?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#89The thing about bug bounties, the only way to win is to not play the game.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#90Related: https://arstechnica.com/gadgets/2025/05/open-source-project-...
The main difference is that all of the vulnerabilities reported here are real, many quite critical (XXE, RCE, SQLi, etc.). To be fair there were definitely a lot of XSS, but the main reason for that is that it's a really common vulnerability.