Live data from Hacker News

XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

xbow.com

81–90 of 128 posts

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#81
post #77
post #58

Earlier quoted context omitted.

Everyone already agrees with that; the interesting argument here is that it also makes it easy to produce many good results in short time.

But the good ones don’t have the same output rate because they are checked by humans before submission. They are faster than the purely manual ones but can’t beat the AI created bad ones neither in speed nor numbers. It’s like the IT security version of the Gish gallop.

Then you're refuting the premise of the article, and you should be more specific in your critique, because right now all you're saying is "this can't work".

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#82

Have XBow provided a link to this claim, I could only find: https://hackerone.com/xbow?type=user Which shows a different picture. This may not invalidate their claim (best US), but a screenshot can be a bit cherry-picked.

If you scroll down on [the leaderboard](https://hackerone.com/leaderboard?year=2025&quarter=2&owasp=...) page to Country and select United States, xbow is currently on top

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#83

Xbow has really smart people working on it, so they're well-aware of the usual 30-second critiques that come up in this thread. For example, they take specific steps to eliminate false positives. The #1 spot in the ranking is both more of a deal and less of a deal than it might appear. It's less of a deal in that HackerOne is an economic numbers game. There are countless programs you can sign up for, with varied diff…

Maybe that is because the article is chaotic (like any "AI" article) and does not really address the false positive issue in a well.presented manner? Or even at all?

Below people are reading the tea leaves to get any clue.

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#84

First: > To bridge that gap, we started dogfooding XBOW in public and private bug bounty programs hosted on HackerOne. We treated it like any external researcher would: no shortcuts, no internal knowledge—just XBOW, running on its own. Is it dogfooding if you're not doing it to yourself? I'd considerit dogfooding only if they were flooding themselves in AI generated bug reports, not to other people. They're not the o…

I think they mean dogfooding as in putting on the "customer" hat and using the product.

Seems reasonable to call that dogfooding considering that flooding themselves wouldn't be any more useful than synthetic testing and there's only so much ground they could cover using it on their own software.

If this were coming out of Microsoft or IBM or whatever then yeah, not really dogfooding.

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#85
post #82

Have XBow provided a link to this claim, I could only find: https://hackerone.com/xbow?type=user Which shows a different picture. This may not invalidate their claim (best US), but a screenshot can be a bit cherry-picked.

If you scroll down on [the leaderboard]( https://hackerone.com/leaderboard?year=2025&quarter=2&owasp=... ) page to Country and select United States, xbow is currently on top

Ah thanks, I think it would be useful for them to perhaps add it as a footnote or something.

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#86
Since I am the cofounder of a mostly manual based testing in that space we do follow the new AI hackbots closely. There is a lot of money being raised (Horizon3 at 100M, Xbow at 87M, Mindfort will probably soon raise).

The future is definitely a combination of human and bots like anything else, it won't replace the humans just like coding bots won't replace devs. In fact this will allow humans to focus ob the fun/creative hacking instead of the basic/boring tests.

What I am worried about is on the triage/reproduction side, right now it is still mostly manual and it is a hard problem to automate.

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#87

Xbow has really smart people working on it, so they're well-aware of the usual 30-second critiques that come up in this thread. For example, they take specific steps to eliminate false positives. The #1 spot in the ranking is both more of a deal and less of a deal than it might appear. It's less of a deal in that HackerOne is an economic numbers game. There are countless programs you can sign up for, with varied diff…

100% agree with OP, to make a living in BBH you can't go hunting on VDP program that don't pay anything all day. That means you will have a lot of low hanging fruits on those programs.

I don't think LLM replace humans, they do free up time to do nicer tasks.

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#88

Xbow has really smart people working on it, so they're well-aware of the usual 30-second critiques that come up in this thread. For example, they take specific steps to eliminate false positives. The #1 spot in the ranking is both more of a deal and less of a deal than it might appear. It's less of a deal in that HackerOne is an economic numbers game. There are countless programs you can sign up for, with varied diff…

> Top infosec talent doesn't want to do it (and there's not enough of it). What is the top talent spending its time on?

The best paying bug bounties.

Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne

#90
post #51
post #3

Related: https://arstechnica.com/gadgets/2025/05/open-source-project-...

The main difference is that all of the vulnerabilities reported here are real, many quite critical (XXE, RCE, SQLi, etc.). To be fair there were definitely a lot of XSS, but the main reason for that is that it's a really common vulnerability.

All of them are real? You have a 100% rate of reports closed as valid?
Post reply on HN