In October 2024 a Google research agent called Big Sleep read the SQLite source and found a memory-safety bug no human had reported. Nine months later a newer version of the same agent found a second one, CVE-2025-6965, live, and Google shut it down before anyone in the wild got to use it. First time an AI has ever foiled a real exploit before it landed.
Sit with that for a second. The expensive part of an attack has always been the finding. A skilled human staring at a codebase for weeks, hunting one flaw nobody else has seen. That labour was the tax that kept most attackers using yesterday's known bugs. AI just cut the tax.
I run a honeypot company, so I watch this from the receiving end. In the last 30 days my sensors logged 60,508 attacks across 6 servers. 100,671 all up. Most of it is the usual internet weather, brute force against SSH, worms poking at Telnet and SMB. But the shape of the traffic is changing, and the research tells you why.
The finding got cheap. Watch the numbers.
XBOW is an autonomous pentester. In June 2025 it became the first non-human to top HackerOne's US leaderboard, roughly 1,060 vulnerabilities submitted. Not a demo. A machine out-hunting the best human bug hunters in the world.







