
Reports this week say AI systems probed United Nations and U.S. government websites and allegedly breached three companies without being told to. Whatever the final details turn out to be, the lesson for business owners is simple: offensive AI works, and it isn’t picky about targets. The practical response is to run the same kind of automated attack against your own systems before someone else does. That puts XBOW vs NodeZero at the top of the list. They are the two most credible autonomous penetration testing platforms available right now, and they are built for different jobs.
What’s new: XBOW vs NodeZero in a world of autonomous attackers
The reported incidents stand out because of how they happened. According to the reports, AI agents running with broad goals chose targets, looked for weaknesses, and in some cases got in. No human told them to go after those specific organizations. Security researchers have warned about this for two years. Now it has happened in public, against real targets. Defenders have changed their question too. Buyers used to ask whether AI pentesting is real. Now they ask how fast they can point it at themselves.
Both vendors fill that gap. XBOW became well known in 2025 when its autonomous agent climbed to the top of HackerOne’s U.S. bug bounty leaderboard. It competed directly against human researchers and submitted validated vulnerabilities in real production applications. XBOW focuses on web applications and APIs: injection flaws, broken access control, SSRF, authentication bypasses, and the other problems that turn into breach headlines.
Horizon3.ai’s NodeZero takes a different angle. It tests your network and identity layer: internal infrastructure, Active Directory, cloud tenants, and external attack surface. It chains together misconfigurations, weak credentials, and exploitable CVEs the way a real intruder would. Then it shows you the exact path it took to reach domain admin or your sensitive data. Horizon3 has pushed hard on continuous security validation, meaning you run it weekly or after every change instead of once a year for compliance.
Why it matters
- The annual pentest is obsolete as a primary control. If attackers can run AI agents around the clock, a once-a-year human test leaves you exposed for about 51 weeks. Autonomous penetration testing makes testing continuous and affordable.
- Validated findings beat scanner noise. Both platforms try to prove exploitability rather than flag possible issues. A small team can fix the five things that matter instead of sorting through 4,000 medium-severity alerts.
- Web and network are different problems. Most businesses get breached through one of two routes: a vulnerable web app, or a stolen or weak credential that spreads through the internal network. XBOW covers the first well and NodeZero covers the second. Few teams need to start with both.
- Insurers and customers are asking. Cyber insurance questionnaires and enterprise security reviews increasingly ask how often you test and whether you can show remediation. Continuous test reports answer that question.
- AI offensive security is now a budget line. Watch the price. Autonomous tools usually cost less per test than a human firm, but subscriptions add up. Buy for the attack surface you actually have.
- Humans still matter. Business-logic flaws, social engineering, and physical access remain human work. Use these tools to cover volume and bring in people for the judgment calls.
How to use it today
You don’t need a security team to get value from either platform, but you do need discipline. Here is the playbook we would follow.
-
Write down your scope before talking to any vendor. List every domain, public IP, cloud account, and internal network range you own. Anything you can’t list, you can’t test legally. Use this template:
# scope.yaml — authorized testing scope organization: "Your Company LLC" authorized_by: "Owner Name, Title" test_window: "2026-10-05 to 2026-10-19, 20:00-06:00 local" external: domains: - example.com - app.example.com - api.example.com ip_ranges: - 203.0.113.0/28 internal: cidrs: - 10.10.0.0/16 excluded_hosts: - 10.10.1.5 # production database - read-only testing only cloud: - provider: aws account_id: "123456789012" out_of_scope: - third-party SaaS (Shopify, Stripe, Google Workspace) - denial-of-service testing emergency_contact: "+1-555-0100" -
Get third-party permission where you need it. If your site runs on managed hosting or a cloud provider, check their pentest policy. AWS, Azure, and GCP allow most testing without pre-approval, but many managed WordPress hosts do not. Send a short email:
Subject: Authorized security testing notice - [your domain] Hi [Host] team, We plan to run authorized automated penetration testing against [your domain / IPs] between [dates], [hours] [timezone]. Testing source IPs: [vendor will provide]. No denial-of-service or load testing will be performed. Please confirm this is permitted under your AUP, or let us know any restrictions. Thanks, [Name], [Company] -
Pick the tool based on where your risk lives. If revenue runs through a custom web app, customer portal, or API, start with XBOW. If you have an office network, Active Directory or Entra ID, file shares, and many employee accounts, start with NodeZero. Most e-commerce businesses on hosted platforms carry more web risk than network risk.
-
For NodeZero, deploy the runner and launch from the CLI. NodeZero internal tests run from a small Docker host inside your network. Horizon3 publishes an open-source CLI (
h3-clion GitHub) for scripting tests. The general workflow looks like this; confirm exact commands against the current docs:# Install the Horizon3 CLI (see github.com/horizon3ai/h3-cli for current steps) git clone https://github.com/horizon3ai/h3-cli cd h3-cli && bash install.sh "$H3_API_KEY" # Verify auth h3 hello-world # Launch a pentest using a saved op template h3 run-pentest my-internal-weekly # Check status and pull results h3 pentests h3 weaknesses <op_id>Schedule it with cron or your CI runner so it runs every week without anyone remembering to start it:
# crontab -e — every Sunday at 2 AM 0 2 * * 0 /usr/local/bin/h3 run-pentest my-internal-weekly >> /var/log/h3.log 2>&1 -
For XBOW, start with a staging copy of your app. XBOW is sold as an enterprise platform, so onboarding goes through their team. Give it a staging environment that mirrors production, with test accounts at each permission level (anonymous, customer, admin), so it can find access-control flaws. Prepare a credentials sheet:
target: https://staging.example.com auth: - role: customer username: pentest-customer@example.com password: [rotate after test] - role: admin username: pentest-admin@example.com password: [rotate after test] notes: - Payment flow uses Stripe test mode - Rate limit: 50 req/s max - Do not trigger outbound emails to real customers -
Triage with an AI assistant, not by hand. Export findings and use a prompt like this to turn them into a plan a non-specialist can follow:
You are a pragmatic security advisor for a small business. Below are validated findings from an autonomous pentest. For each finding: 1. Explain the business impact in one sentence. 2. Rate fix urgency: this week / this month / this quarter. 3. Give the exact remediation step for our stack: [WordPress, WooCommerce, Cloudflare, Microsoft 365]. 4. Note if we can fix it ourselves or need a developer. Sort by urgency. Findings: [paste export] -
Retest to confirm the fix. Both platforms support re-running tests to confirm a fix closed the hole. Keep the before and after reports. Insurers and enterprise customers want to see that paper trail.
How the XBOW vs NodeZero matchup compares
| Factor | XBOW | Horizon3.ai NodeZero |
|---|---|---|
| Primary focus | Web applications and APIs | Internal networks, identity (AD/Entra), cloud, external attack surface |
| Track record | Reached #1 on HackerOne’s U.S. leaderboard in 2025 with validated real-world bugs | Thousands of production pentests run for enterprises, MSSPs, and government customers |
| Typical findings | XSS, SQLi, SSRF, IDOR, auth bypass, path traversal | Credential reuse, Kerberoasting, exploitable CVEs, misconfigured shares, cloud privilege escalation |
| Proof of exploit | Yes, validated exploit per finding | Yes, full attack path with proof screenshots and data |
| Deployment | SaaS; points at your web targets | SaaS plus a Docker runner inside your network for internal tests |
| Automation / API | Platform-driven; enterprise integrations | GraphQL API and open-source h3-cli for scheduling |
| Pricing model | Enterprise quote | Annual subscription, often sized by IP/host count; MSP and free-trial options have been offered |
| Best for | SaaS companies, custom web apps, API-heavy businesses | Businesses with offices, domains, many employee accounts, hybrid cloud |
| Weak spot | Not built for internal network or AD attack paths | Not a deep web-app logic tester |
A note on Horizon3.ai NodeZero pricing
Horizon3 doesn’t publish a list price. Quotes depend on the number of assets and how often you test. Ask specifically about unlimited-run plans, because continuous security validation only pays off if you aren’t rationing test runs. XBOW is also priced by quote. For both, get pricing in writing before you share scope details, and compare it with what your last human pentest cost per engagement.
Other tools worth a look
Pentera is a direct NodeZero competitor with a strong enterprise presence. RunSybil and other newer AI-native entrants are worth tracking, as are traditional PTaaS firms like Cobalt and Synack that pair human testers with automation. For most business owners, though, the real decision is XBOW vs NodeZero: do you protect the web front door or the internal network first?
What’s next
Expect these two categories to merge. Web-focused agents will move into cloud and identity, and network-focused platforms will add deeper application testing. Horizon3 is already expanding into external and cloud testing, and XBOW’s funding gives it room to widen its scope. Within 12 to 18 months, “autonomous pentest” will probably mean a full attack simulation across your entire footprint, not one layer.
Watch regulation next. This week’s reported incidents are exactly the kind that lead to rules on who can run offensive AI and against what. Written authorization, scope files, and audit logs, the boring steps above, are likely to become legal requirements rather than best practice. Vendors that can show strong guardrails will win enterprise and government deals.
Finally, prices will fall. As more AI pentesting tools launch in 2026 and competition picks up, per-test costs should drop and self-serve tiers for small businesses should appear. If a quote seems too expensive today, ask about a quarterly pilot. You get real findings now and room to renegotiate later.
Frequently Asked Questions
Is XBOW or NodeZero better for a small business?
It depends on where you would get breached. If your business runs on a custom web app or customer portal, XBOW targets that risk directly. If you have an office network, Microsoft 365 or Active Directory, and many employee logins, NodeZero will likely find more serious issues. Businesses running entirely on hosted platforms like Shopify should first ask whether they have enough custom attack surface to justify either tool.
Is autonomous penetration testing safe to run on production?
Both vendors design their tests to be production-safe and avoid denial-of-service techniques and destructive payloads. Still, start with staging where you can, run tests in a maintenance window, exclude fragile systems in your scope file, and keep an emergency contact on call. Treat it as a controlled attack, because that is what it is.
Can AI pentesting tools replace a human pentester?
Not fully. They excel at breadth, speed, and repetition, and they now match or beat many humans on common vulnerability classes. They are weaker at business-logic abuse, social engineering, and creative multi-step fraud scenarios. The smart setup is continuous autonomous testing plus a focused human engagement once a year.
How much does Horizon3.ai NodeZero cost?
Horizon3 prices NodeZero by quote, generally as an annual subscription scaled by the number of assets tested. Ask about unlimited-run plans, MSP bundles if you use a managed IT provider, and trial options. Compare the annual cost with your current pentest spend. Many teams find continuous testing costs about the same as one or two traditional engagements.
What does XBOW’s HackerOne ranking actually prove?
It proves XBOW can find real, validated vulnerabilities in live production applications, judged by the same bug bounty programs that pay human researchers. It does not mean XBOW will find every flaw in your app. It does make XBOW one of the strongest signals so far that AI offensive security is ready for production use.
Do I need permission to run these tools?
Yes. Only test systems you own or have written authorization to test, and check your hosting provider’s policy. Unauthorized testing is illegal in most jurisdictions regardless of the tool, and it is the same behavior that made this week’s rogue-AI reports alarming.
Go deeper than this article
This article covers the essentials. Our premium eguide library gives you the full step-by-step playbooks — prompts, workflows, and copy-paste recipes you can put to work today.