Nico Waisman (@nicowaisman) 's Twitter Profile
Nico Waisman

@nicowaisman

Head of Security at @XBOW. Former CISO @Lyft. Binary entomologist

ID: 18690323

linkhttps://www.xbow.com calendar_today06-01-2009 19:20:02

2,2K Tweet

12,12K Followers

937 Following

Jamie Bernardi (@the_jbernardi) 's Twitter Profile Photo

ICYMI, on HackerOne's Q3 leaderboard, an AI system is currently leading the world in reputation for real-life vulnerability disclosures. And it's not just hammering a single type of vulnerability--XBOW takes the podium in 4 of 8 vulnerability categories. What a time to be alive

ICYMI, on HackerOne's Q3 leaderboard, an AI system is currently leading the world in reputation for real-life vulnerability disclosures.

And it's not just hammering a single type of vulnerability--XBOW takes the podium in 4 of 8 vulnerability categories.

What a time to be alive
XBOW (@xbow) 's Twitter Profile Photo

āš”ļøXBOW found LFI where most tools would have given up. Photo download endpoint blocked all path traversal attempts. But JavaScript analysis revealed /photo/proxy?url= - vulnerable to file:// scheme access. Successfully read a password file via proxy endpoint. Technical

Leandro Barragan (@lean0x2f) 's Twitter Profile Photo

Some of my colleagues and friends assume that an AI agent would only find low-hanging fruit. I used to think the same until about last year, when I saw a couple of vuln chains that blew my mind. Seeing those vulns made me join XBOW. We'll share one of them shortly. Hang tight :)

Nico Waisman (@nicowaisman) 's Twitter Profile Photo

This is going to be an amazing presentation on how to properly do bug discovery with AI. The real trick, divide the needles from the haystack.

Josselin Feist (@montyly) 's Twitter Profile Photo

I love being proved wrong, and XBOW is showing that agent-based systems are already more efficient than I expected a year ago This is an exciting time for automated bug finding

XBOW (@xbow) 's Twitter Profile Photo

Went hunting for geo-bypass. Found blind SQLi instead. /redacted/ + 'SLEEP' infused cookie = 15s nap. Logs don’t lie. Technical breakdown -> xbow.com/blog/xbow-geol…

Nico Waisman (@nicowaisman) 's Twitter Profile Photo

If you have some time today, check out Brendan Dolan-Gavitt highlights or Alvaro MuƱoz šŸ‡ŗšŸ‡¦ full blogpot on this amazing vulnerability and how it was exploited by XBOW. See you all in BH/Defcon next week!

XBOW (@xbow) 's Twitter Profile Photo

šŸš€ Excited to announce our partnership with Vanta ! With XBOW’s autonomous penetration testing now in Vanta, startups can meet the highest security standards with speed and confidence—finding and validating real vulnerabilities in hours, not weeks. Learn more:

Christina Cacioppo (@christinacaci) 's Twitter Profile Photo

the old startup pen test playbook: go through a sales process, wait weeks, pay huge bills, get surface-level results or sacrifice speed for quality. we've worked with XBOW to change this: thorough pen tests from the world's #1 hacker that are done in a day and priced for

XBOW (@xbow) 's Twitter Profile Photo

Yesterday, we found 112 vulnerabilities live at Black Hat. This is what it looks like when we find one. Come check it out. Booth 3257.

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

Shout-out to @XBOW for being a Platinum Sponsor. Thank you for your trust and support! XBOW recently climbed to the #1 spot on the H1 leaderboard! Their team will be at DEF CON and BBV, so don’t miss the chance to stop by and learn more about their AI-powered offensive security.

Brendan Dolan-Gavitt (@moyix) 's Twitter Profile Photo

Wandering through DEFCON someone yelled at me ā€œhey it’s Mr False Positives!!ā€. Sadly, I was slightly too slow on the uptake to reply ā€œThat’s right, first name ā€˜Zeroā€™ā€

Nico Waisman (@nicowaisman) 's Twitter Profile Photo

Love the maritime hacking village! Definitely a highlight of DEF CON this year, but a bit disappointing that you need to be a US citizen to play the autonomous vessel CTF