Uploaded August 2026 | Updated September 2026, 2 weeks ago
Check out XBOW here: https://ul.live/xbow_yt
I had a really awesome chat with Nico from XBOW about how they're using AI to totally disrupt the offensive security space, from automating deep pentests to preparing for the next wave of AI-driven attacks. We geeked out over the absolute necessity of good asset management and got a sneak peek at some of the wild native vulnerability research his team is bringing to Vegas soon
What we talk about:
Disrupting the Industry: How Expo disrupted the cybersecurity industry by introducing AI to offensive security and navigating the initial pushback from the bug bounty community during their HackerOne experiments.
Continuous AI Assessments: The shift from traditional, point-in-time penetration testing to continuous, scalable AI-driven assessments that cover both deep application testing and broad attack surface areas.
The Power of Cartography: The absolute necessity of asset management and "cartography," highlighting why building a "world model" or memory of an organization's infrastructure is crucial for both modern defenders and future AI attackers.
Managing Scope and Budgets: How the platform handles scope, prioritizes targets to manage inference budgets effectively, and adapts to both external and internal testing environments.
Future Developments and Native Vulns: Exciting future product developments, including allowing customers to build customizable agent skills, and Expo's pivot into native vulnerability research (like browser and kernel exploits) ahead of Black Hat.
00:00 - Introduction and early industry disruption.
02:04 - Characterizing the core problem Expo is solving.
04:14 - Combining AI with Attack Surface Management (ASM).
07:40 - Ingesting external context and handling assessment scope.
09:55 - Prioritizing targets to manage time and inference budgets.
16:03 - The breakdown of external versus internal testing.
17:13 - Future product additions and moving to native vulnerabilities.
20:21 - Upcoming announcements and Black Hat plans.
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler
Check out XBOW here: https://ul.live/xbow_yt
I had a really awesome chat with Nico from XBOW about how they're using AI to totally disrupt the offensive security space, from automating deep pentests to preparing for the next wave of AI-driven attacks. We geeked out over the absolute necessity of good asset management and got a sneak peek at some of the wild native vulnerability research his team is bringing to Vegas soon
What we talk about:
Disrupting the Industry: How Expo disrupted the cybersecurity industry by introducing AI to offensive security and navigating the initial pushback from the bug bounty community during their HackerOne experiments.
Continuous AI Assessments: The shift from traditional, point-in-time penetration testing to continuous, scalable AI-driven assessments that cover both deep application testing and broad attack surface areas.
The Power of Cartography: The absolute necessity of asset management and "cartography," highlighting why building a "world model" or memory of an organization's infrastructure is crucial for both modern defenders and future AI attackers.
Managing Scope and Budgets: How the platform handles scope, prioritizes targets to manage inference budgets effectively, and adapts to both external and internal testing environments.
Future Developments and Native Vulns: Exciting future product developments, including allowing customers to build customizable agent skills, and Expo's pivot into native vulnerability research (like browser and kernel exploits) ahead of Black Hat.
00:00 - Introduction and early industry disruption.
02:04 - Characterizing the core problem Expo is solving.
04:14 - Combining AI with Attack Surface Management (ASM).
07:40 - Ingesting external context and handling assessment scope.
09:55 - Prioritizing targets to manage time and inference budgets.
16:03 - The breakdown of external versus internal testing.
17:13 - Future product additions and moving to native vulnerabilities.
20:21 - Upcoming announcements and Black Hat plans.
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler










