top of page
large-logotype_01_3x-1 (1).png

XBOW at DEF CON 34: The Main Sponsor of the Bug Bounty Village CTF

The future is zero days away.

 

Offensive security is changing, and XBOW is the system bringing autonomy to it — finding, chaining, and exploiting vulnerabilities across your attack surface, and proving every finding with a working exploit. It runs the entire pentest autonomously and continuously, from the context you give it to a confirmed exploit, every time your applications change — and it already competes alongside human researchers in live bug bounty programs.

 

We built XBOW alongside the offensive-security community, and the Bug Bounty Village is home turf. We're here to meet the people driving this shift. Whether you're a seasoned bug hunter or just breaking into the field, come see how far autonomous hacking has come.

What XBOW Does

 

XBOW extends your team with autonomous hackers that discover, chain, and exploit vulnerabilities across your attack surface, and prove every finding with a working exploit. No scheduling. No waiting for the next pentest window. Point it at a target, and it goes.

Where to Find XBOW During Las Vegas Summer Camp

 

Black Hat (Aug 4–6) — Want to Talk Business?

 

A lot of the community is in town for the full week. If you (or your security team) want a closer look at autonomous offensive security:

 

  • Booth #3448 — Mandalay Bay Convention Center. Drop by for a live look at XBOW.

  • Sponsored session — "Exploitability Is the Ground Truth" — Thursday, Aug 6, 11:25am PT. Why a "noisy" finding costs real engineering time, and how AI changed the scale of vulnerability research without changing its hard problems.

  • Book time with the teamhttps://xbow.com/events/black-hat-usa-2026

 

Bug Bounty Village (DEF CON, Aug 6–9) — The CTF, plus XBOW researchers on the floor to talk shop, trade techniques, and answer "how does it actually work" questions.

 

XBOW is the Main Sponsor of this year's Bug Bounty Village CTF. Working with the village organizers, we've helped stand up a CTF built on a realistic, full-stack web application seeded with real-world vulnerability classes, the kind of layered attack surface you actually meet on a live bug bounty program, not isolated toy puzzles.

 

After the CTF, the postmortem. Once the dust settles, XBOW researchers will run a full postmortem of the CTF and a bug review: how the toughest flags fell, the most elegant chains we saw, and where human and autonomous approaches diverged. We'll publish it as an interview and a blog post.

Security Research from XBOW

 

Follow the latest from the XBOW Security Lab — LLM-powered offensive security, new vulnerability classes, exploit techniques, and lessons from real-world engagements:

 

 

Meet the Team Behind XBOW

  • Oege de Moor — CEO and founder; previously created CodeQL / Semmle.

  • Nico Waisman — Head of Security; longtime offensive-security leader and former CISO at Lyft.

  • Brendan Dolan-Gavitt — security researcher and professor; "200 Zero-Days, 0 False Positives: AI Agents for OffSec." 

  • Alvaro Muñoz — offensive-security

  • Federico Kirschbaum — AppSec research

Stay Connected

 

Follow XBOW on these channels and keep an eye on the Bug Bounty Village schedule at bugbountydefcon.com for updates:

 

----

We're proud to sponsor the Bug Bounty Village CTF, and we can't wait to see what you turn up at DEF CON 34.

bottom of page