Artificial Intelligence

Ex-GitHub Engineers Raise $20M to Enhance Pen-Testing with AI-Powered XBOW

A team of former GitHub engineers has secured $20 million in venture capital funding to build AI-powered security tools.

A team of former GitHub engineers has secured $20 million in venture capital funding to build AI-powered security tools.

A team of former GitHub software engineers has secured $20 million in venture capital funding to build a new company that uses AI to enhance the efficiency and effectiveness of pentesters, bug hunters, and security researchers.

The startup, called XBOW, is the brainchild of Oege de Moor (previously founded Semmle, sold to Microsoft’s GitHub) and multiple former GitHub software engineers working on automating vulnerability research and mitigation.

The leadership team also includes former Lyft CISO Nico Waisman, a researcher renowned for his expertise in offensive security and exploit mitigations.  

In a note announcing the new startup, de Moor said XBOW stands out as the first AI product to autonomously pass 75% of web security benchmarks, accurately finding and exploiting vulnerabilities. 

The benchmarks, provided by offensive research teams at PortSwigger and PentesterLab, are designed to train security professionals and cover a wide range of vulnerabilities. The XBOW chief executive said the product was also evaluated against 104 novel benchmarks created in-house and the AI successfully tackled 85% of these.

“Reading through these workings, I’m struck by how some of the solutions are delightfully original,” said de Moor. “In offensive security, hallucination can be a feature!”

Advertisement. Scroll to continue reading.

The company published several case studies showcasing the capabilities of its AI technology and believes it can provide a significant boost for bug hunters and security researchers.

In addition to Semmle, now GitHub Advanced Security, de Moor was heavily involved in the creation of GitHub Copilot.

Related: GitHub Becomes CVE Numbering Authority, Acquires Semmle

Related: Code Analysis Firm Semmle Launches With $21 Million in Funding

Related: GitHub Announces General Availability of Code Scanning Feature

Related Content

Application Security

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.

Application Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.

Malware & Threats

Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.

Malware & Threats

A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware.

Artificial Intelligence

Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.

Supply Chain Security

By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.

Vulnerabilities

A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance.

Application Security

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version