XBOW評測:AI滲透測試奪下抓漏排行榜冠軍 | XBOW Review: AI Pentester Tops Bug Bounty Leaderboard
By Kit 小克 | AI Tool Observer | 2026-08-29
🇹🇼 XBOW評測:AI滲透測試奪下抓漏排行榜冠軍
XBOW是誰?一個沒有肉身的「頂尖駭客」
2025年第二季,XBOW這個名字第一次讓資安圈炸鍋——它是一套全自動的AI滲透測試系統,在漏洞獎金平台HackerOne的美國排行榜上,靠純軟體幹掉了將近一百名人類駭客,登上榜首。這不是概念展示,是實打實在90天內回報超過1,060個漏洞,涵蓋SQL注入、跨站腳本(XSS)、遠端程式碼執行(RCE)等,其中54個被判定為「重大」等級。
戰績驚人,但含金量呢?
先講清楚:這不是科幻電影裡的黑客AI。XBOW背後是一支至少25人的資安與AI研究團隊,每一份送出去的報告都經過人工審核才會提交,創辦人Oege de Moor自己也承認:「你得先決定要它打哪個目標」。批評者也直言,XBOW找到的多半是「表層」漏洞——資料外洩、存取控制錯誤、命令注入——這些正是自動化工具最擅長的類型,而不是需要理解商業邏輯的深層漏洞。HackerOne共同創辦人Michiel Prins也坦言,AI「目前還不擅長判斷商業影響」。
排行榜引發的公平性爭議
XBOW拿下的其實只是「美國、2025年4到6月」這個特定時段的排行榜,而非所有指標的第一名。批評聲音也指出,一個24小時不休息的AI本來就比人類更容易靠數量取勝。這場爭議逼得HackerOne後來把「工具/企業」和「個人獵人」的排行榜分開列,避免蘋果比橘子。
從刷榜到賣產品:XBOW的下一步
拿下排行榜第一之後,XBOW已經不再把刷榜當成重點,轉而把火力放在企業市場:推出隨選滲透測試服務,並在今年3月完成1.2億美元C輪募資。換句話說,「證明AI能打」的階段結束了,現在要證明AI能賣錢。
這對資安產業意味著什麼?
- AI滲透測試正在快速吃掉「重複性高、模式固定」的漏洞獵捕工作
- 複雜的商業邏輯漏洞、需要脈絡判斷的攻擊路徑,暫時還是人類的地盤
- 企業導入AI抓漏工具前,要問清楚「人工審核」佔比多少,別被行銷話術唬住
好不好用,試了才知道。
🇺🇸 XBOW Review: AI Pentester Tops Bug Bounty Leaderboard
XBOW: The AI That Topped a Human Hacker Leaderboard
XBOW is a fully automated AI penetration-testing system, and in Q2 2025 it did something no bot had done before: it hit #1 on HackerOne's US leaderboard, outranking nearly 100 human bug bounty hunters. Over a 90-day stretch it submitted more than 1,060 vulnerability reports — SQL injection, cross-site scripting, remote code execution — including 54 rated critical.
Impressive Numbers, Real Asterisks
Before you picture a rogue AI hacking on its own, know this: XBOW is backed by a team of at least 25 security and AI researchers, and every submitted report is human-reviewed before it goes out. Founder Oege de Moor has been upfront that "you need to decide what you point it at." Critics like former Walmart/EA security lead Amélie Koran describe most of XBOW's finds as "surface material" — data leaks, access control errors, command injection — exactly the kind of bugs automation is good at, not the deep, business-context-aware vulnerabilities that require human judgment. HackerOne co-founder Michiel Prins agrees: AI "does not yet excel in business impact."
The Leaderboard Fairness Debate
XBOW's #1 ranking technically applies to one specific window — the US leaderboard, April to June 2025 — not an all-time or all-metric crown. Skeptics point out an AI running 24/7 will naturally out-volume any human on raw report count. The backlash was loud enough that HackerOne later split its leaderboards into separate tool/company and individual-hunter tracks so the comparison wouldn't be apples-to-oranges.
From Leaderboard Stunt to Enterprise Product
Now that the point has been made, XBOW has stopped chasing leaderboard rank and pivoted to selling: an on-demand penetration testing product for enterprises, backed by a $120M Series C raised in March 2026. The "can AI hack?" phase is over — the "can AI hacking make money?" phase has begun.
What This Means If You Work in Security
- AI penetration testing is fast becoming the default for high-volume, pattern-matchable vulnerability classes
- Complex, context-dependent business-logic bugs remain a human specialty — for now
- Before adopting an AI pentest tool, ask exactly how much human review sits behind the reports — don't buy the "fully autonomous" pitch at face value
好不好用,試了才知道。
Sources / 資料來源
- CSO Online: The top red teamer in the US is an AI bot
- CyberScoop: Is XBOW's success the beginning of the end of human-led bug hunting?
- XBOW: XBOW on HackerOne — What's Next
延伸閱讀 / Related Articles
- AI IDE漏洞評測:Kiro等15款AI編碼工具中鏢 | AI IDE Vulnerability Review: Kiro Among 15 Tools Hit
- A2A協定評測:併入MCP陣營,AI代理終於同語言 | A2A Protocol Review: Joins MCP at Linux Foundation
- Meta智慧眼鏡評測:遮燈偷拍漏洞終於補上了 | Meta Smart Glasses Review: Recording Light Loophole Fixed
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言