Building offsec agents: xbow.com PGP keybase.io/moyix/

Brooklyn, NY
Joined June 2008
Incredible to have helped build the first AI system to reach #1 in the US on @Hacker0x01 ! We found a LOT of great bugs :D
For the first time in history, the #1 hacker in the US is an AI. (1/8)
This was a really fun convo! Have a listen to hear about AI doing weird AI things and more!
Episode 23: War Stories with Brendan Dolan-Gavitt (@Xbow)! @0xTib3rius & @SwiftSecur1 are joined by @moyix who shares some AI and human war stories with us! Links below!
1
14
Brendan Dolan-Gavitt retweeted
Episode 23: War Stories with Brendan Dolan-Gavitt (@Xbow)! @0xTib3rius & @SwiftSecur1 are joined by @moyix who shares some AI and human war stories with us! Links below!
1
5
1
10
Brendan Dolan-Gavitt retweeted
From assessment to SOC 2 submission in 5 days → Day 1: Start → Day 2: Report → Day 3: Fix → Day 5: Submit to evidence workflow See how @BloompathAI found it, fixed it, proved it, in less than a week. 📰 xbow.com/blog/customer-bloom… 🚀 xbow.com/pentest
2
3
21
Brendan Dolan-Gavitt retweeted
Nico reflects on our journey, from HackerOne to the NYSE floor, and what comes next for democratizing offensive testing. 📰 Read the recap → xbow.com/blog/democratizing-…
1
7
0
As the operator of a soup kitchen, I don’t see why I should be expected to fix health code violations people report. After all, we are run almost entirely by volunteers
18
8
6
109
I'll be down in DC for OWASP Global AppSec next week and hosting a dinner with the XBOW team Wednesday night! RSVP so we can chat about how AI makes pentesting faster and more effective over drinks and delicious food!
If you’re in DC for @owasp Global AppSec, join us for Apps(ec) & Aperitifs: dinner, drinks, swag, and sharp security conversations. Register to attend; spots and swag are limited. 📍RSVP here xbow.com/dcreception2025 #OWASP #AppSec #Cybersecurity
2
Brendan Dolan-Gavitt retweeted
🏆 @FortuneMagazine , @lightspeedvp , and @awscloud have named @Xbow the Early Growth Stage Category Winner on the #Cyber60 2026. Proof that autonomous offense isn’t the future, it’s already here, and we’re defining it. 🔗 Read more → fortune.com/ranking/cyber/20…
3
1
18
So cool to see XBOW at the NYSE!
Seeing our logo on the NYSE floor as the Early Growth Stage Winner on the #Cyber60 is a proud milestone, and a glimpse of where cybersecurity is headed. “The rapid advances of AI and the ceaseless scheming of hackers make cyber startups one of the most dynamic and innovative sectors in tech.” @FortuneMagazine Thank you to our customers, team, and investors @sequoia and @altimetercap for being part of this journey. 🔗 Read → fortune.com/2025/10/30/ai-st…
1
21
Brendan Dolan-Gavitt retweeted
Security is one of the most important areas in AI, as @altcap said at GTC! @Xbow is leading the charge on startups that are innovating in Cyber! Great shoutout for @oegerikus and team by @George_Kurtz
Come hang out with us in DC! I will be there to spread the good word about hackbots :D
If you’re in DC for @owasp Global AppSec, join us for Apps(ec) & Aperitifs: dinner, drinks, swag, and sharp security conversations. Register to attend; spots and swag are limited. 📍RSVP here xbow.com/dcreception2025 #OWASP #AppSec #Cybersecurity
1
13
Like, my incorporeal friend, I do not think you would say it's so easy if you had ever had to use meat fingers to do everything 😩
1
8
GPT-5 has a much higher opinion of my hardware skills than is warranted. I mentioned my wife’s laptop died and it’s trying to sell me on the notion that tracing a bad MOSFET and replacing it with a hot air rework station is the easy, practical option
2
28
It turns out the IRS gets really huffy about this too
7
I don't understand why companies get so upset when I extend them a short-term loan with highly favorable repayment terms*?? Do they want me to charge interest??? * (Forget to submit reimbursements for months)
1
15
These numbers do not add up to 128GB???
4
1
16
Brendan Dolan-Gavitt retweeted
This is not our talk, DEFCON screens didn't work during our time slot. We recorded and uploaded the full talk ourselves. Our talk:
Prompt Scan Exploit AI’s Journey Through 0Days and 1000 Bugs - piped.video/watch?v=sOkgHfu4… at @defcon D. Jurado & J. Nogue Hi, it’s me, XBOW, the AI offensive agent—a smart cyber detective on a mission to find bugs in the digital world. In the past few months, I've discovered over 200 security flaws in open source projects and submitted more than 1000 bug bounty reports. - @djurado9; and @niemand_sec at @xbow @SwordBytesSec #DEFCON33 #BugBounty #AIHacking #PromptScanExploit #LLMSecurity #AutonomousPentest #ZeroDays #AppSec #AIForSecurity #XBOW #SwordBytesSec
1
4
21
It was a huge honor to give the keynote for this excellent workshop! Thanks so much to @mahal0z for inviting me; I'm delighted to see that the RE research community is thriving!
CCS has come to a close, and so has the first-ever SURE Workshop. We want to thank the authors, the PC, @moyix, our panel, and CCS for making SURE a success. We felt the support for this research area (the room was packed out for more than half the day). See you all next year!
2
7
The Efficient Altruism Hypothesis states that if you see a child drowning in a pond, you should keep on walking; if they were really drowning someone would have already saved them.
6
21
205
Brendan Dolan-Gavitt retweeted
We just had our first talk of the day, our spectacular keynote from @moyix. He explored reverse engineering and discussed how we still have a long way to go in making questions about programs accessible to non-technical people. We'll be live-tweeting talks as they happen!
1
1
6