Brendan Dolan-Gavitt (@moyix) 's Twitter Profile
Brendan Dolan-Gavitt

@moyix

Building offsec agents: xbow.com

Associate Prof, NYU Tandon (on leave). PGP keybase.io/moyix/

MESS Lab: messlab.moyix.net

ID: 15194897

linkhttp://moyix.net calendar_today22-06-2008 04:06:26

23,23K Tweet

28,28K Followers

5,5K Following

Ian Butler (@kinglycrow) 's Twitter Profile Photo

If you haven't see it we put together a bench mark that thoroughly tests popular agents abilities to find and fix bugs. We found the most popular agents are also the worst at these tasks. (Bismuth is pretty hype tho ;)) sm100bench.com

payloadartist (@payloadartist) 's Twitter Profile Photo

The current top US-based hacker on Hackerone's leader board is "Xbow". You might wonder what the heck that is. No, it's not an experienced hacker. It's not even a human. It's an AI agent, that's fully automated trained on real vulnerability data. The future with AI is scary...

The current top US-based hacker on Hackerone's leader board is "Xbow".

You might wonder what the heck that is.

No, it's not an experienced hacker. It's not even a human. It's an AI agent, that's fully automated trained on real vulnerability data.

The future with AI is scary...
Brendan Dolan-Gavitt (@moyix) 's Twitter Profile Photo

Sometimes I think about the fact that if you include prompts used for our agents, my writing has been read by far, far more AIs than humans

Simon Willison (@simonw) 's Twitter Profile Photo

If you use "AI agents" (LLMs that call tools) you need to be aware of the Lethal Trifecta Any time you combine access to private data with exposure to untrusted content and the ability to externally communicate an attacker can trick the system into stealing your data!

If you use "AI agents" (LLMs that call tools) you need to be aware of the Lethal Trifecta

Any time you combine access to private data with exposure to untrusted content and the ability to externally communicate an attacker can trick the system into stealing your data!
Nico Waisman (@nicowaisman) 's Twitter Profile Photo

One of the benefits of working at XBOW, is you get to see first hand some amazing traces on how XBOW autonomously find new zero days. Trust me, Alvaro Muñoz 🇺🇦 is not easy to impress

One of the benefits of working at <a href="/Xbow/">XBOW</a>, is you get to see first hand some amazing traces on how XBOW autonomously find new zero days.
Trust me, <a href="/pwntester/">Alvaro Muñoz 🇺🇦</a> is not easy to impress