Xint
Products
Xint Platform Xint Pulse
Resources
Blog Public Bug Tracker
About Theori
Login
Web App Code App
Talk to an Expert
EN KR
Products
Xint Platform Xint Pulse
Resources
Blog Public Bug Tracker
About Theori
Login
Web App Code App
Talk to an Expert
Language
EN KR

Xint Blog

Insights from the world's best offensive security researchers
Hector Leano's avatar
Hector Leano
Xint Code Discovers Three High Sev Bugs in Android

Xint Code Discovers Three High Sev Bugs in Android

This is an overview of the three high-severity vulnerabilities uncovered by Xint Code in Android which have now been patched by Google Devices
Hector Leano's avatar
Jul 20, 2026
Vulnerability ResearchOpen Source ProjectsAI for Security
Announcing Xint Pulse - The Full Capabilities of Xint Served One Scan at a Time

Announcing Xint Pulse - The Full Capabilities of Xint Served One Scan at a Time

Xint Pulse offers one-time scans of web applications powered by the full award-winning capabilities of the Xint enterprise platform
Hector Leano's avatar
Jul 15, 2026
ProductNewsAI for Security
Xint Achieves Dual ISO Certifications, Accelerating Global Security Compliance Roadmap

Xint Achieves Dual ISO Certifications, Accelerating Global Security Compliance Roadmap

Xint achieves the world's leading standard for information security management, evaluating an organization's security policies, risk management practices, access controls, and incident response procedures.
Hector Leano's avatar
Jun 23, 2026
ProductAI for SecurityNews
FAQ: Are the Incremental Improvements in New Models Worth the Higher Cost?

FAQ: Are the Incremental Improvements in New Models Worth the Higher Cost?

What are the incremental benefits to each new (more expensive) model and when does it make sense to update?
Hector Leano's avatar
Jun 16, 2026
AI for SecurityProductFAQ
AI Wrapper vs. AI Native

AI Wrapper vs. AI Native

Everyone is claiming AI in AppSec, but there are meaningful differences in how AI is used, leading to fundamentally differences in exposure
Hector Leano's avatar
Jun 10, 2026
AI for SecurityFAQ
FAQ: Is AI Application Security Testing Reliable If Results Vary Between Scans?

FAQ: Is AI Application Security Testing Reliable If Results Vary Between Scans?

Non-deterministic LLM vuln discovery is actually a strength for Xint since it can go beyond fixed rules or patterns that are easily gamed by attackers.
Hector Leano's avatar
May 28, 2026
ProductAI for SecurityFAQ
AI won’t replace human pentesters and security teams. It will be a force multiplier

AI won’t replace human pentesters and security teams. It will be a force multiplier

LLMs are changing the role of security researchers and engineers, but companies laying off human cyber experts just as AI coding generates more vulnerable code are in for a world of hurt.
Hector Leano's avatar
May 26, 2026
AI for SecurityFAQ
Xint’s False Positive Rate: Methodology and Purpose

Xint’s False Positive Rate: Methodology and Purpose

We don’t know the FP rate for the latest frontier models when it comes to AppSec. We share ours and how we arrived at it.
Hector Leano's avatar
May 18, 2026
ProductAI for Security
Kernel Vulns Uncovered by Xint in MacOS, iOS and iPadOS

Kernel Vulns Uncovered by Xint in MacOS, iOS and iPadOS

This is an overview of the two kernel-level vulnerabilities uncovered by Xint Code in MacOS, iOS and iPadOS which have been patched by Apple
Hector Leano's avatar
May 12, 2026
Vulnerability ResearchAI for SecurityNews
Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs

Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs

Zero data retention (ZDR) policies for LLMs in AppSec are not the default, but here's why they belong at the top of your AI procurement checklist.
Hector Leano's avatar
May 11, 2026
Product
What to Ask Every AI PenTest Vendor Before You Buy

What to Ask Every AI PenTest Vendor Before You Buy

These are the 8 questions that will tell you whether a vendor is selling a pen test alternative, a faster SAST tool, or a demo that doesn’t survive production
Hector Leano's avatar
May 06, 2026
AI for SecurityProduct
Working With DARPA to Secure Open Source Infrastructure: CVE-2026-31789

Working With DARPA to Secure Open Source Infrastructure: CVE-2026-31789

The story behind CVE-2026-31789 demonstrates how DARPA and Xint are accelerating AI cyber defenses
Hector Leano's avatar
May 04, 2026
CompetitionsNews Vulnerability ResearchOpen Source Projects
Theori Deploys AI Hacker ‘Xint’ to Samsung Electronics, Leading the Charge in Large-Scale IT Asset Security Automation

Theori Deploys AI Hacker ‘Xint’ to Samsung Electronics, Leading the Charge in Large-Scale IT Asset Security Automation

Press Release for April 21, 2026
Hector Leano's avatar
Apr 21, 2026
News
The Frontier Isn’t the Model: Why ‘Good Enough’ Reasoning + Scaffolding Is More Important

The Frontier Isn’t the Model: Why ‘Good Enough’ Reasoning + Scaffolding Is More Important

In this exclusive report, Xint researchers compare Mythos's publicly disclosed results versus what broadly available models can accomplish using advanced scaffolding
Hector Leano's avatar
Apr 16, 2026
AI for Security Vulnerability Research
AI Made Code Cheap. Trust Did Not.

AI Made Code Cheap. Trust Did Not.

While code is abundant, assurance is scarce. The winners won't be the teams that generate the most code, it’ll be the teams that can prove it's safe.
Hector Leano's avatar
Apr 13, 2026
AI for Security
Finding and Patching a CPython 0day in Hours: CVE-2026-6100

Finding and Patching a CPython 0day in Hours: CVE-2026-6100

A critical CPython CVE today took less than 45 minutes of human work to find, triage, and fix because of Xint Code
Hector Leano's avatar
Apr 13, 2026
Vulnerability ResearchOpen Source Projects
How Xint’s Predictable Pricing Solves the Token Burn Problem for AI in AppSec

How Xint’s Predictable Pricing Solves the Token Burn Problem for AI in AppSec

Linear increases in code are leading to exponential token burn increases. Xint's orchestration brings clear, predictable pricing.
Hector Leano's avatar
Apr 09, 2026
AI for Security
What are business logic vulnerabilities, and why are they so hard to catch?

What are business logic vulnerabilities, and why are they so hard to catch?

Even secure-looking code can hide dangerous flaws. Learn why business logic vulnerabilities are hard to detect and why most scanners miss them.
Hector Leano's avatar
Mar 05, 2026
AI for Security
Announcing Xint Code

Announcing Xint Code

Real Vulnerabilities. Actionable Results.
Hector Leano's avatar
Dec 15, 2025
AI for SecurityProduct
AI Cyber Challenge and Theori's RoboDuck

AI Cyber Challenge and Theori's RoboDuck

An introduction to DARPA's AI Cyber Challnge and Theori's third place cyber reasoning system
Hector Leano's avatar
Aug 08, 2025
CompetitionsAI for Security
Building Effective LLM Agents | AI Cyber Challenge

Building Effective LLM Agents | AI Cyber Challenge

How we learned to build effective LLM agents for hacking at DARPA's AI Cyber Challenge (AIxCC)
Hector Leano's avatar
Aug 08, 2025
AI for SecurityCompetitions
Xint

AI-powered vulnerability discovery that proves exploitability in your live application.

XLinkedInBlueskyFediverse
Products
Xint PlatformXint Pulse
Company
AboutContact
Resources
BlogPublic Bug Tracker
Legal
Privacy PolicyTerms of UseTrust Center
© 2026 Theori. All Rights Reserved.