Ewan Mellor's Avatar

Ewan Mellor

@ewanmellor.org

Research engineer at XBOW.

43
Followers
78
Following
15
Posts
14.11.2024
Joined
Posts Following

Latest posts by Ewan Mellor @ewanmellor.org

Video thumbnail

Ready to chat all things autonomous offensive security with our team at #RSAC? 🏹

From continuous pentesting to AI-enabled attacks, let’s explore together what your organization can do to stay ahead.

Connect with us at the event: https://bit.ly/4qWj9Db

02.03.2026 18:37 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

What’s on the agenda at RSAC?

Our CISO, Nico Waisman, will join Jason Haddix, CEO and CISO at Arcanum Information Security, and OpenAI's Dave Aitel for a fireside chat diving into the β€œChaos Phase” and how AI is breaking the old security model.

Save your seat: https://bit.ly/402mXXQ

26.02.2026 15:33 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Autonomous pentesting is one click closer. πŸ–±οΈ

XBOW is now available on AWS Marketplace.

To mark the launch, AWS customers can get 50% off XBOW Lightspeed for a limited time: https://bit.ly/46YLctI

18.02.2026 14:25 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Traditional scanners flood teams with alerts. Triage becomes the bottleneck.

Autonomous pentesting chains static + dynamic testing and validates exploits before reporting.

No noise. No false positives. πŸ“„ Read the whitepaper: https://xbow.com/whitepaper/autonomous-pentesting-without-false-positives

17.02.2026 17:45 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ“£ XBOW is now available on AWS Marketplace!

AWS customers can now purchase XBOW through their existing workflows & use committed spend, while getting pentest results in hours, backed by real exploit validation.

Read about the partnership & a limited-time 50% for XBOW Lightspeed: bit.ly/4qnVrPk

05.02.2026 19:00 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Aim for what matters every time. 🎯

Hear from our partner Rhymetec about how they conduct AI-powered pentesting in real-world deployments.

Here’s what autonomous offensive security in action looks like: https://bit.ly/4q95DLc

04.02.2026 18:56 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Traditional DAST β‰  dev-friendly.

That's why we go beyond traditional DAST, delivering AI-generated vulnerability reports that provide real exploit paths, app behavior, and code context, so teams can fix faster.

Read more in Tales from the Trace πŸ‘‰ https://bit.ly/4rr5Jz1

03.02.2026 18:53 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

The AI arms race doesn’t mean defenders lose.

Our CEO, Oege de Moor, joined @economist.com’s new "Boss Class" podcast to discuss how AI is accelerating real-world pentesting and ultimately giving the good guys better tools.

Link in replies πŸ”—

03.02.2026 16:02 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Post image

New look. Same mission. 🏹

Our visual identity is evolving, but our focus hasn’t changed: redefining how organizations think about offensive security by transforming application security with AI-powered, continuous offense.

Explore what’s new: https://bit.ly/3ZDQVkx

26.01.2026 17:53 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

We’re thrilled to welcome WonLae Lee, a respected offensive security leader with decades of experience, as General Manager of South Korea. His leadership will play a key role as XBOW continues to grow across the Asia-Pacific region! https://bit.ly/49yjRR4

22.01.2026 15:58 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Chiton sample under a microscope showing its β€œeyes”

Chiton sample under a microscope showing its β€œeyes”

Yes, but more like hundreds of eyeglasses! Image is a chiton sample under a microscope, by Richard L. Howey, from www.microscopy-uk.org.uk/mag/artmay16...

03.01.2026 06:16 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Not directly from rocks. The structures are formed biologically from Ca ions dissolved in the seawater (look up β€œbiomineralization”). Presumably chalk and limestone are good sources for the calcium to get into the seawater in the first place, but I’m guessing at this point.

01.01.2026 19:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Unraveling the Mystery of Chiton Visual Systems | UCSB Marine Science Institute

@dombrasted.bsky.social The eye lens is aragonite, a calcium carbonate crystal. They grow it, like they grow their shells. msi.ucsb.edu/news/unravel...

01.01.2026 17:51 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
The Real Impact of AI on Security Testing | XBOW & Seznam
The Real Impact of AI on Security Testing | XBOW & Seznam AI is transforming cybersecurity, but can it actually discover real vulnerabilities? In this XBOW & Seznam case study, we break down the practical impact of ...

Huge appreciation to the Seznam team!

On their first demo, XBOW identified a critical vulnerability with zero access and zero prep, just autonomous offensive security doing real work for a real customer.

It’s the kind of partnership that proves what matters.

www.youtube.com/watch?v=w4L2...

08.12.2025 18:14 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

AI-enabled attackers have already accelerated.

The question: can your offensive security match their speed?

Next week at Black Hat Europe, we’re showing how autonomous offense closes the security scale gap with human-level testing in hours.

Let us show you how @ booth #215

05.12.2025 13:13 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Presentation: Stargazing | San Francisco Public Library Astro Everywhere will give a short presentation about the solar system and stars in the sky. Look through a telescope to see planets, such as Saturn and Jupiter, "up close".

Are you looking to do more astronomy in the coming year? Astronomy is all about resolution(s)!! Join Astro Everywhere at the Parkside Library on January 7th.

sfpl.org/events/2026/...

04.12.2025 03:59 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

DM me if you’d like an employee discount on your first automated pentest!

03.12.2025 23:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Pentests that take weeks can’t secure software that changes daily.

XBOW Lightspeed uses autonomous multi-agent offense to deliver human-level testing in hours, with full exploit validation and continuous coverage.

xbow.com/pentest

03.12.2025 19:56 πŸ‘ 2 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Post image

It's been about six months since AE really took off as a business, and in that time we have now presented to more than 2000 people in our dome and other presentation spaces and about 700 people have been able to engage with our telescopes and other activities!

Here's to even more in the future!

20.11.2025 18:24 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Episode 23: War Stories with Brendan Dolan-Gavitt (XBOW)!

@tib3rius.bsky.social & @swiftsecur.bsky.social are joined by @moyix.net who shares some AI and human war stories with us!

Links below!

07.11.2025 15:03 πŸ‘ 5 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0
Astro Everywhere’s portable planetarium.

Astro Everywhere’s portable planetarium.

I sneakily took a candid photo of you working your tush off at Bay Area Science Festival this weekend.

27.10.2025 16:54 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

What a weekend! From the Bay Area Science Festival at Mission Bay to the outer Sunset for the Great Hauntway, Astro Everywhere has been EVERYWHERE across SF. Anyone in North Beach need a telescope night?

27.10.2025 02:30 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Walk round to Tunnel Tops Park. It’s not far from there and a much better view of the bridge.

16.10.2025 17:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Dutch late night TV has its take

19.09.2025 14:39 πŸ‘ 20921 πŸ” 8923 πŸ’¬ 511 πŸ“Œ 2082
Post image

1/ XBOW Unleashes GPT-5’s Hidden Hacking Power.Β 

OpenAI
's initial assessment of GPT-5 showed modest cyber capabilities. But when integrated into the XBOW platform, we saw a completely different story: performance more than doubled.Β 

More on what we found: 🧡

15.08.2025 21:31 πŸ‘ 9 πŸ” 2 πŸ’¬ 1 πŸ“Œ 1
Post image

See autonomous pentesting live at #BlackHat!

Next week, XBOW will run on active HackerOne programs from the expo floor.
Watch AI agents find and validate real vulnsβ€”fast.

πŸ“ Booth 3257

01.08.2025 17:00 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Number 1 πŸ’ƒπŸ•ΊπŸŽ‰

01.08.2025 02:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
XBOW – Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle A complete arbitrary local file read vulnerability achieved through an ingenious byte-by-byte exfiltration technique.

The trick to how it did it is in this post: xbow.com/blog/xbow-ti... Some details below...

28.07.2025 22:10 πŸ‘ 8 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Post image

False positives waste your time.
False negatives cost you breaches.

At @BlackHatEvents , @moyix shows how XBOW agents fight false positives β€” validating real exploits at scale, in hours.

πŸ“Aug 7 | 11:20am

28.07.2025 15:02 πŸ‘ 3 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
XBOW – Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution A methodical analysis of TiTiler's API endpoints and its expression parser, leading to arbitrary Python code execution on the server.

From SSRF discovery to RCE exploitation in 32 iterations.

XBOW systematically analyzed TiTiler's expression parser, discovered Python execution through error patterns, then crafted payloads using subclass traversal to achieve command execution.

Complete analysis: bit.ly/46XzOiA

24.07.2025 14:18 πŸ‘ 4 πŸ” 5 πŸ’¬ 1 πŸ“Œ 1