AI Security Startup Xbow Hits $1 Billion Valuation After $120M Funding Round

2 Sources

Share

Xbow, an AI security startup that automates penetration testing, has raised $120 million in Series C funding at a valuation exceeding $1 billion. Led by DFJ Growth and Northzone, the investment signals strong investor confidence in using AI to combat cybersecurity threats as malicious actors increasingly leverage the same technology to scale attacks.

AI Security Startup Secures Major Investment

Xbow, an AI security startup founded in 2024, has closed a $120 million funding round that propels the company to a billion dollar valuation, marking a significant milestone in the cybersecurity industry

1

. DFJ Growth and Northzone led the Series C financing, with participation from Alkeon Capital, Sofina, and previous backers including Sequoia Capital, Altimeter Capital and NFDG

1

. The Seattle-based cybersecurity startup previously raised $75 million in June, demonstrating rapid growth in investor enthusiasm for AI-driven security solutions

2

.

Automated Penetration Testing Transforms Security Workflows

The company uses AI agents to automate the function of penetration testers and red teams, which traditionally probe for weak points in enterprise systems before hackers can exploit them

1

. Xbow's platform can reduce cybersecurity evaluations from weeks to just hours or days, addressing a critical bottleneck in application security

2

. The automated vulnerability detection system analyzes edge cases and user interaction scenarios that manual testers often can't cover due to time constraints, enabling more comprehensive risk assessment

2

.

Xbow trains its AI models using human hackers to identify security vulnerabilities in applications, a growing need as more developers rely on AI coding tools

1

. CEO Oege de Moor, former head of GitHub's pioneering Copilot code-generation product, explained that apps built with AI typically "output insecure coding patterns" because "they've been trained on publicly available source code, and unfortunately, a lot of publicly available source code was not well secured"

1

.

Source: SiliconANGLE

Source: SiliconANGLE

Sophisticated Exploits Demonstrate Platform Capabilities

The platform's AI agents can develop highly elaborate, multi-step exploit chains that filter false positives without realistic breach potential

2

. In one penetration test, Xbow executed a simulated cyberattack comprising 48 different exploits, using a specially-crafted image file to simulate a server-side request forgery attack

2

. In another demonstration, the platform successfully decrypted a cookie protected with AES-128 encryption in just 17.5 minutes by analyzing error messages from server requests to infer the cookie's contents

2

.

Users can customize automated penetration testing by providing instructions or optionally sharing application source code for more comprehensive vulnerability analysis

2

. The company offers three editions: Plus and Premium for one-time application scans, and Xbow Enterprise for continuous workload monitoring with API integration to stream results to other cybersecurity tools

2

.

Rapid Growth Amid Escalating Threat Landscape

Xbow employs roughly 150 people and expects to have several hundred on staff by year's end

1

. The company has signed up more than 100 customers, including Moderna Inc. and Samsung Electronics Co., and is seeing strong demand in South Korea where businesses face threats from nation-state groups

1

. The startup plans to use its newly raised funding to expand its presence in international markets and the enterprise segment while investing in feature development

2

.

While AI tools help companies protect themselves, hackers are also using the technology to scale the volume and severity of attacks. De Moor warned that "the world at large has not yet fully realized what is coming," predicting "swarms of malicious attacks" that organizations must prepare for

1

. Despite expectations that AI models will improve at avoiding insecure coding patterns, security flaws stemming from AI's failure to understand business logic or data-sharing protocols will remain a persistent challenge

1

. This arms race between defensive and offensive AI capabilities makes Xbow's approach to software vulnerabilities increasingly critical for enterprise security teams navigating an evolving threat landscape where both defenders and attackers leverage the same technological advances.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo