logo
|
Blog

    XINT.IO BLOG

    Insights from the world's best offensive security researchers
    See AllCompetitions Vulnerability ResearchAI for SecurityNewsProductOpen Source Projects
    Kernel Vulns Uncovered by Xint in MacOS, iOS and iPadOS

    Kernel Vulns Uncovered by Xint in MacOS, iOS and iPadOS

    This is an overview of the two kernel-level vulnerabilities uncovered by Xint Code in MacOS, iOS and iPadOS which have been patched by Apple
    Hector Leano's avatar
    May 12, 2026
    Vulnerability ResearchAI for SecurityNews
    Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs

    Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs

    Zero data retention (ZDR) policies for LLMs in AppSec are not the default, but here's why they belong at the top of your AI procurement checklist.
    Hector Leano's avatar
    May 11, 2026
    Product
    What to Ask Every AI PenTest Vendor Before You Buy

    What to Ask Every AI PenTest Vendor Before You Buy

    These are the 8 questions that will tell you whether a vendor is selling a pen test alternative, a faster SAST tool, or a demo that doesn’t survive production
    May 06, 2026
    AI for SecurityProduct
    Vulnerabilities vs. Weaknesses: Why the Distinction Matters

    Vulnerabilities vs. Weaknesses: Why the Distinction Matters

    There's a difference between insecure code patterns and true vulnerabilities that hackers seek to exploit. Why does that matter?
    May 05, 2026
    Vulnerability ResearchAI for SecurityProduct
    Working With DARPA to Secure Open Source Infrastructure: CVE-2026-31789

    Working With DARPA to Secure Open Source Infrastructure: CVE-2026-31789

    The story behind CVE-2026-31789 demonstrates how DARPA and Xint are accelerating AI cyber defenses
    Hector Leano's avatar
    May 04, 2026
    CompetitionsNews Vulnerability ResearchOpen Source Projects
    Kernel Vulns Uncovered by Xint in MacOS, iOS and iPadOS

    Kernel Vulns Uncovered by Xint in MacOS, iOS and iPadOS

    This is an overview of the two kernel-level vulnerabilities uncovered by Xint Code in MacOS, iOS and iPadOS which have been patched by Apple
    Hector Leano's avatar
    May 12, 2026
    Vulnerability ResearchAI for SecurityNews
    Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs

    Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs

    Zero data retention (ZDR) policies for LLMs in AppSec are not the default, but here's why they belong at the top of your AI procurement checklist.
    Hector Leano's avatar
    May 11, 2026
    Product
    What to Ask Every AI PenTest Vendor Before You Buy

    What to Ask Every AI PenTest Vendor Before You Buy

    These are the 8 questions that will tell you whether a vendor is selling a pen test alternative, a faster SAST tool, or a demo that doesn’t survive production
    May 06, 2026
    AI for SecurityProduct
    Vulnerabilities vs. Weaknesses: Why the Distinction Matters

    Vulnerabilities vs. Weaknesses: Why the Distinction Matters

    There's a difference between insecure code patterns and true vulnerabilities that hackers seek to exploit. Why does that matter?
    May 05, 2026
    Vulnerability ResearchAI for SecurityProduct
    Working With DARPA to Secure Open Source Infrastructure: CVE-2026-31789

    Working With DARPA to Secure Open Source Infrastructure: CVE-2026-31789

    The story behind CVE-2026-31789 demonstrates how DARPA and Xint are accelerating AI cyber defenses
    Hector Leano's avatar
    May 04, 2026
    CompetitionsNews Vulnerability ResearchOpen Source Projects
    Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

    Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

    Xint Code disclosed CVE-2026-31431, an authencesn scratch-write bug chaining AF_ALG + splice() into a 4-byte page cache write. A 732-byte PoC gets root on Ubuntu, Amazon Linux, RHEL, SUSE.
    Juno Im's avatar
    Apr 29, 2026
    AI for Security Vulnerability ResearchOpen Source Projects
    System, Not Model: Why Off-the-Shelf LLMs Don’t Replace a Pen Test

    System, Not Model: Why Off-the-Shelf LLMs Don’t Replace a Pen Test

    What do buyers actually purchase when they pay for a vulnerability discovery platform, and why is the model the cheapest input in the bill?
    Apr 27, 2026
    Vulnerability ResearchAI for Security
    Theori Deploys AI Hacker ‘Xint’ to Samsung Electronics, Leading the Charge in Large-Scale IT Asset Security Automation

    Theori Deploys AI Hacker ‘Xint’ to Samsung Electronics, Leading the Charge in Large-Scale IT Asset Security Automation

    Press Release for April 21, 2026
    Hector Leano's avatar
    Apr 21, 2026
    News
    The Frontier Isn’t the Model: Why ‘Good Enough’ Reasoning + Scaffolding Is More Important

    The Frontier Isn’t the Model: Why ‘Good Enough’ Reasoning + Scaffolding Is More Important

    In this exclusive report, Xint researchers compare Mythos's publicly disclosed results versus what broadly available models can accomplish using advanced scaffolding
    Hector Leano's avatar
    Apr 16, 2026
    AI for Security Vulnerability Research
    AI Made Code Cheap. Trust Did Not.

    AI Made Code Cheap. Trust Did Not.

    While code is abundant, assurance is scarce. The winners won't be the teams that generate the most code, it’ll be the teams that can prove it's safe.
    Apr 13, 2026
    AI for Security
    Finding and Patching a CPython 0day in Hours: CVE-2026-6100

    Finding and Patching a CPython 0day in Hours: CVE-2026-6100

    A critical CPython CVE today took less than 45 minutes of human work to find, triage, and fix because of Xint Code
    Hector Leano's avatar
    Apr 13, 2026
    Vulnerability ResearchOpen Source Projects
    How Xint’s Predictable Pricing Solves the Token Burn Problem for AI in AppSec

    How Xint’s Predictable Pricing Solves the Token Burn Problem for AI in AppSec

    Linear increases in code are leading to exponential token burn increases. Xint's orchestration brings clear, predictable pricing.
    Hector Leano's avatar
    Apr 09, 2026
    AI for Security
    What are business logic vulnerabilities, and why are they so hard to catch?

    What are business logic vulnerabilities, and why are they so hard to catch?

    Even secure-looking code can hide dangerous flaws. Learn why business logic vulnerabilities are hard to detect and why most scanners miss them.
    Hector Leano's avatar
    Mar 05, 2026
    AI for Security
    Announcing Xint Code

    Announcing Xint Code

    Real Vulnerabilities. Actionable Results.
    Dec 15, 2025
    AI for SecurityProduct
    AI Cyber Challenge and Theori's RoboDuck

    AI Cyber Challenge and Theori's RoboDuck

    An introduction to DARPA's AI Cyber Challnge and Theori's third place cyber reasoning system
    Aug 08, 2025
    CompetitionsAI for Security
    Building Effective LLM Agents | AI Cyber Challenge

    Building Effective LLM Agents | AI Cyber Challenge

    How we learned to build effective LLM agents for hacking at DARPA's AI Cyber Challenge (AIxCC)
    Aug 08, 2025
    AI for SecurityCompetitions