Get the latest tech news

XBOW, an autonomous penetration tester, has reached the top spot on HackerOne


For the first time in bug bounty history, an autonomous penetration tester has reached the top spot on the US leaderboard.

This scoring criteria covered a broad range of signals, including target appearance, presence of WAFs and other protections, HTTP status codes, redirect behavior, authentication forms, number of reachable endpoints, underlying technologies, and more. XBOW identified a full spectrum of vulnerabilities including: Remote Code Execution, SQL Injection, XML External Entities (XXE), Path Traversal, Server-Side Request Forgery (SSRF), Cross-Site Scripting, Information DIsclosures, Cache Poisoning, Secret exposure, and more. In the spirit of transparency, and in accordance with the rules and regulations of POC || GTFO, our security team will be publishing a series of blog posts over the coming weeks, showcasing some of our favorite technical discoveries by XBOW.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of hacker

hacker

Photo of HackerOne

HackerOne

Photo of best Hacker

best Hacker

Related news:

News photo

Hacker steals 1 million Cock.li user records in webmail data breach

News photo

Car-sharing giant Zoomcar says hacker accessed personal data of 8.4 million users

News photo

Hacker selling critical Roundcube webmail exploit as tech info disclosed