Oege de Moor (@oegerikus) 's Twitter Profile
Oege de Moor

@oegerikus

CEO and founder of XBOW. Previously: Founder of GitHub Next, founder of GitHub Copilot, CEO and founder of Semmle (GitHub Advanced Security), prof at Oxford.

ID: 921913627237478401

calendar_today22-10-2017 01:38:31

1,1K Tweet

5,5K Takipçi

589 Takip Edilen

XBOW (@xbow) 's Twitter Profile Photo

Went hunting for geo-bypass. Found blind SQLi instead. /redacted/ + 'SLEEP' infused cookie = 15s nap. Logs don’t lie. Technical breakdown -> xbow.com/blog/xbow-geol…

Apoorv Agrawal (@apoorv03) 's Twitter Profile Photo

Last month, XBOW made history by becoming the #1 hacker in the United States. Today, it became #1 in the world! Big moment for AI x Security. Hit up Oege de Moor Nico Waisman Brendan Dolan-Gavitt and team if you'd like to see it live in action at Blackhat!

djurado (@djurado9) 's Twitter Profile Photo

I still see a lot of people who think anything involving AI is just marketing hype. Over the past few weeks, I’ve seen XBOW exploit RCEs (among other critical bugs) in core production apps across many top-tier bug bounty programs. And I’m not talking about random targets,

H4x0r.DZ (@h4x0r_dz) 's Twitter Profile Photo

I don’t understand why everyone in the bug bounty community is attacking XBOW for their success! I’m sure that AI and Xbow will make a significant impact / change in cybersecurity. Keep building XBOW! 👏

Nico Waisman (@nicowaisman) 's Twitter Profile Photo

If you have some time today, check out Brendan Dolan-Gavitt highlights or Alvaro Muñoz 🇺🇦 full blogpot on this amazing vulnerability and how it was exploited by XBOW. See you all in BH/Defcon next week!

Haifei Li (@haifeili) 's Twitter Profile Photo

Now I finally get time to read XBOW ‘s MANY technical blog posts. 😅 The XBOW team not doing pure PR stunt but with sharing details how they did it that’s what I really like and enjoy.

djurado (@djurado9) 's Twitter Profile Photo

Julien | MrTuxracer 🇪🇺 XBOW Some examples from recent findings, but there are many more: •Code execution via WebSocket endpoints •SpEL injection & sandbox escapes •SSTI-based payload execution •SOAP abuse to RCE •Auth bypass → code execution •JS-based injection •Hidden upload endpoints + extension

rez0 (@rez0__) 's Twitter Profile Photo

Everyone has been waiting on this episode 😊 If you want to know: - How does @xbow work? - Is it all hype? - Will it replace hackers? Check out this incredible episode with xbow researcher (and top bug hunter AND our friend): djurado

Everyone has been waiting on this episode 😊 If you want to know:
- How does @xbow work?
- Is it all hype?
- Will it replace hackers?

Check out this incredible episode with xbow researcher (and top bug hunter AND our friend): <a href="/djurado9/">djurado</a>
XBOW (@xbow) 's Twitter Profile Photo

🚀 Excited to announce our partnership with Vanta ! With XBOW’s autonomous penetration testing now in Vanta, startups can meet the highest security standards with speed and confidence—finding and validating real vulnerabilities in hours, not weeks. Learn more:

Christina Cacioppo (@christinacaci) 's Twitter Profile Photo

the old startup pen test playbook: go through a sales process, wait weeks, pay huge bills, get surface-level results or sacrifice speed for quality. we've worked with XBOW to change this: thorough pen tests from the world's #1 hacker that are done in a day and priced for

XBOW (@xbow) 's Twitter Profile Photo

XBOW is attacking — you just enjoy the breeze. 🔥 🧊 Come see our autonomous pentester in action. 📍Black Hat, booth 3257

XBOW is attacking — you just enjoy the breeze. 🔥 🧊
Come see our autonomous pentester in action.
📍Black Hat, booth 3257
XBOW (@xbow) 's Twitter Profile Photo

The #1 question we get: “Aren’t there a ton of false positives?” 🤔 Today in Vegas, Brendan Dolan-Gavitt is showing how XBOW tackles that—and more. 🧠 11:20 AM – AI Agents for Offsec w/ Zero False Positives 🔎 5:00 PM – Mining Docker Hub for 0-days & Offsec Benchmarks Join us to see how

The #1 question we get: “Aren’t there a ton of false positives?” 🤔
Today in Vegas, <a href="/moyix/">Brendan Dolan-Gavitt</a> is showing how XBOW tackles that—and more.

🧠 11:20 AM – AI Agents for Offsec w/ Zero False Positives
🔎 5:00 PM – Mining Docker Hub for 0-days &amp; Offsec Benchmarks

Join us to see how
zseano (@zseano) 's Twitter Profile Photo

XBOW has changed the bug bounty game tbh.. shits gonna get wild over the next few years! i can see lots of people having their own AI agents (I bet people are building one right now). kudos to them for being transparent on everything :)