
Oege de Moor
@oegerikus
CEO and founder of XBOW. Previously: Founder of GitHub Next, founder of GitHub Copilot, CEO and founder of Semmle (GitHub Advanced Security), prof at Oxford.
ID: 921913627237478401
22-10-2017 01:38:31
1,1K Tweet
5,5K Followers
589 Following


Last month, XBOW made history by becoming the #1 hacker in the United States. Today, it became #1 in the world! Big moment for AI x Security. Hit up Oege de Moor Nico Waisman Brendan Dolan-Gavitt and team if you'd like to see it live in action at Blackhat!





If you have some time today, check out Brendan Dolan-Gavitt highlights or Alvaro Muñoz 🇺🇦 full blogpot on this amazing vulnerability and how it was exploited by XBOW. See you all in BH/Defcon next week!


Julien | MrTuxracer 🇪🇺 XBOW Some examples from recent findings, but there are many more: •Code execution via WebSocket endpoints •SpEL injection & sandbox escapes •SSTI-based payload execution •SOAP abuse to RCE •Auth bypass → code execution •JS-based injection •Hidden upload endpoints + extension





The #1 question we get: “Aren’t there a ton of false positives?” 🤔 Today in Vegas, Brendan Dolan-Gavitt is showing how XBOW tackles that—and more. 🧠 11:20 AM – AI Agents for Offsec w/ Zero False Positives 🔎 5:00 PM – Mining Docker Hub for 0-days & Offsec Benchmarks Join us to see how






