At the start of 2024, frontier models struggled with high-school CTF challenges. Less than three years later they find and exploit zero-days in production software and hold their own against expert researchers on some bug classes. The curve is not flattening.
Every bug an AI finds trains the defender's AI; every mitigation the defense ships is a new puzzle for the attacker's. That recursion, offense training defense training offense, will define security through 2030. Which bug classes die first? Where do the survivors hide? What does a zero-day look like when both sides are machines? I'll answer with data from running AI against real targets at scale: what it finds, what it still can't, and what that leaves for the people in this room.
Oege de Moor is the CEO and founder of XBOW. XBOW is an AI agent that autonomously finds and exploits vulnerabilities in web applications. In the summer of 2025, XBOW became #1 on the HackerOne leaderboard. It is now used by many enterprises including NVIDIA, Samsung, SentinelOne. Oege is building it because it would be irresponsible not to do so - the good guys would fall behind.
Before XBOW, Oege founded GitHub Copilot, the first hit product of the generative AI age. He came to GitHub through the acquisition of his company named Semmle, now named GitHub Advanced Security. Oege was a professor of computer science at Oxford for 22 years.
Teams led by Oege have been described as an ‘engine room’ (at Oxford) and a ‘pirate ship’ (at GitHub), reflecting the buccaneering spirit he instils in his coworkers, building new technologies that were thought to be impossible.
Oege de Moor