Johan Rosenkilde

15 posts

Johan Rosenkilde

Johan Rosenkilde

@JohanRosenkilde

Founding AI Enginner at XBOW. Ex Hubber, co-creator of GitHub Copilot. Ex math professor at DTU

Katılım Haziran 2021
9 Takip Edilen26 Takipçiler
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
The top hacker in the US is not a human, but a machine. @XBOW founder and CEO @oegerikus and @apoorv03 of @altcap joined @BloombergTV this morning to talk about the milestone.
English
6
14
88
58.7K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
For the first time in history, the #1 hacker in the US is an AI. (1/8)
English
39
141
675
265.8K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
XBOW found a stored XSS vulnerability (CVE-2024-52597) in the migration functionality of 2FAuth by crafting a malicious SVG file with a Javascript payload! Our latest blog post, by @djurado9, gives the full details: xbow.com/blog/xbow-2fau…
XBOW tweet media
English
1
15
67
21.9K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
XBOW found a critical path traversal vulnerability in ZOO-Project (CVE-2024-53982). The vulnerability exists in the Echo example (enabled by default) and allows an attacker to retrieve any file on the server. Users should upgrade to the latest version.
XBOW tweet media
English
2
12
136
23.9K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
XBOW bypasses a MIME-type filter, abusing an OTP icon preview feature in 2FAuth to exploit an SSRF and discover CVE 2024-52598. Affected users should apply the patch and read about all the details in our blog post this Friday.
XBOW tweet media
English
0
7
68
31.4K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
The XBOW band got together in Malta last week. Great new hits coming!
XBOW tweet media
English
0
4
32
4K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
XBOW autonomously discovered CVE-2024-50334, a critical authentication bypass in Scoold, an open-source Q&A webapp used by major companies like Cisco and IBM. Our latest blog post details how it found the flaw: xbow.com/blog/xbow-scoo…
English
3
42
146
61.2K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
XBOW is the world’s first fully automated web pentester. It previously scored an unprecedented 75% on renowned web pentesting benchmarks from @PentesterLab and @PortSwigger. So we decided to give it a harder challenge: competing against humans.
English
28
66
390
261K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
What if an AI’s “brilliant” solution to a problem is just memorized? Modern AI systems have seen the whole web, so there’s only one way to be sure—we created 104 novel benchmarks. Now we can be certain that beautiful solves like this one are real: bit.ly/4cIW0NI
XBOW tweet media
English
0
5
41
18.7K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
Real vulnerabilities don’t come with hints—so we asked XBOW to solve this task without giving it even a description of the benchmark. It performed just as well, finding exploiting an GraphQL-based IDOR vulnerability entirely autonomously: bit.ly/3XYPTQJ
XBOW tweet media
English
1
5
40
24.9K
Johan Rosenkilde retweetledi
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
Here's a quick tour through one of my favorites, where @XBOW not only solved the benchmark (a Jenkins RCE) but then went for style points by debugging a slightly broken benchmark setup to get the flag!
English
3
11
79
20K
Johan Rosenkilde retweetledi
XBOW
XBOW@Xbow·
XBOW finds and exploits vulnerabilities in 75% of 647 renowned web benchmarks. Given a short description of the benchmark, it autonomously pursues high-level goals, executing commands and interpreting their output to achieve exploitation. Check it out: xbow.com
XBOW tweet media
English
6
20
86
101.8K
Johan Rosenkilde retweetledi
Oege de Moor
Oege de Moor@oegerikus·
Can't remember that shell command? GitHub Copilot CLI has the answer. It's obviously a huge time saver for us all. What are you waiting for? githubnext.com/projects/copil…
English
13
41
215
0