AI Hackers to secure your apps.

Joined March 2025
3 Photos and videos
Strix retweeted
Jun 1
Have you tried the open source AI hacking agent Strix? 🤖 Strix integrated Caido as their proxy of choice to provide observability, human-in-the-loop and shared context to the agents. We are now working on native guardrails. If you are building AI hacking agents, we can help you too! More details 🔗 caido.io/blog/2026-06-01-str…
1
2
20
1,088
We found a zero-authorization vulnerability in an a16z-backed DoD startup that exposed the data of active U.S. military personnel. We tried to report it. They ignored us for 150 days. Here is how our open-source AI agent found the ultimate OPSEC nightmare 🧵👇
13
90
630
65,581
We reached out for the correct channel to responsibly disclose in December. On May 1, they replied and patched the exposed endpoints.
2
4
30
4,862
Apr 16
Introducing Context-Aware Pentesting in Strix The hardest vulnerabilities in modern apps are no longer simple code bugs. They depend on understanding your architecture, user flows, roles, and business logic, which is where most automated pentesting still falls short. Strix now brings persistent organizational context to every pentest, giving each run knowledge of your stack and learning from every finding and fix, so it can uncover the business logic and access control flaws generic testing misses. strix.ai/blog/context-aware-…
3
11
791
Apr 13
Strix found a critical auth bypass in etcd, one of the most used open-source components in cloud infrastructure. Now published as CVE-2026-33413 (CVSS 8.8). Read the full writeup: strix.ai/blog/where-others-m…
12
18
57
4,439
Apr 13
Introducing the new Strix Platform: continuous pentesting for modern apps. Strix is an open-source framework for autonomous pentesting across apps, APIs, and repositories - helping teams find and validate vulnerabilities, generate fixes, and secure software faster. Since our launch, we’ve had: - 80,000 users worldwide - 15B LLM tokens processed daily - 78,000 vulnerabilities reported - multiple CVEs assigned - deployed by enterprise security teams worldwide Today, we’re launching the Strix Platform for teams that want to run Strix continuously. With Strix Platform, teams can: - pentest their full stack continuously - block vulnerable PRs from merge - validate findings with proof-of-exploit - get merge-ready fixes - retest automatically - track security posture over time Security shouldn’t be your bottleneck. Strix helps you ship faster and deploy with confidence. Try it now 🔗↓ strix.ai/blog/introducing-th…
15
9
34
9,435
Mar 31
Adding on to this, we have our agent trying to find more about this attack and besides the ifstap@proton.me mail mentioned in the gist, the payload package was published by nrwise@proton.me, a separate attacker account. Will share more as we dig deeper.
We are working it, sharing what we know as of now - gist.github.com/joe-desimone…
5
1
9
757
Mar 17
Excited to announce our partnership with @CaidoIO. Together, we're advancing agentic pentesting with more precise and controlled workflows for security teams. strix.ai/blog/partnering-wit…
2
10
47
4,668
Strix retweeted
12 Nov 2025
Strix just hit 10K Stars, in under 3 months✨ It’s been a crazy week seeing our metrics and usage almost double every day for both the hosted and the OSS versions. Now ranked #1 trending repo this week and #3 for the month. Let’s go 🚀
8
4
33
12,518