Security audit: autonomous research program XBOW credited with ~12 upstream bug fixes

moyix · x · 2026-09-23

An independent security audit rediscovered several bugs (12 leads) that had already been found and fixed upstream. Upstream fixed them in a heavy wave between April–August 2026, with most fixes credited to an autonomous research program called XBOW and only one to a human — a notable example of autonomous security research in practice.

Original post →

More from coding & agent

coding & agent channel →