Xint Reinvents AppSec Testing for the LLM Era
AppSec Testing Enters an LLM-First Phase
Alan Shimel speaks with Andrew Wesie, co-founder and CTO of Xint, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on LLM AppSec testing and the way AI is changing vulnerability discovery, triage and remediation. Wesie explains how his cybersecurity path began with competitive hacking, Carnegie Mellon and the Plaid Parliament of Pwning CTF team.
Wesie also describes the path from Theori to Xint. Theori brought together elite security researchers to solve hard offensive security problems. Xint builds on that experience with an AI-first approach to application security testing, including black-box web testing and white-box source code analysis.
AI Expands the Vulnerability Discovery Problem
The interview explores why AI may create a new boundary point for vulnerability management. Wesie compares the current moment to the rise of fuzzing, when teams suddenly found many more software flaws. AI extends that idea beyond memory corruption. It can reason through source code, identify business logic issues and uncover vulnerabilities that traditional methods may miss.
That creates a scale problem. Many organizations already struggle to fix the vulnerabilities they know about. Adding AI-driven discovery can increase the volume of findings even further. Wesie says the real challenge is not only finding vulnerabilities. Teams also need better ways to triage, prioritize and verify fixes.
Xint Combines Black-Box and White-Box Testing
Xint is designed to rethink AppSec testing from first principles using LLMs. Wesie says the goal is not to add a small AI feature to older testing workflows. Instead, Xint uses LLMs as the foundation for black-box web application testing and white-box source code analysis.
That combination matters because modern attacks often involve multiple weak points. A single issue may not look critical on its own. Several issues chained together can create a much larger risk. LLM AppSec testing can help connect those signals and provide better context around exploitability and impact.
Better Triage Becomes the AppSec Priority
The discussion closes with a practical message for security and engineering leaders. AI can help find more vulnerabilities, but more findings are not useful without better prioritization. Teams need to understand whether an attacker can exploit a flaw in their production configuration. They also need to know whether remediation actually fixed the issue.
For AppSec teams, Xint’s approach points to a broader shift. LLM AppSec testing is moving the industry toward systems that combine discovery, context, impact analysis and validation. That shift could help organizations handle the growing scale of AI-driven vulnerability discovery without drowning in bad news.
Transcript
Hey, everyone. We're back here in our tour of the suites of Las Vegas, otherwise known as our Black Hat coverage for 2026. For whatever reason, we seem to be spending more time, and maybe this is a trend we're seeing, right?
Companies are taking suites and doing business here almost more than they're doing it on the show floor. For sure. Our next interview is with Andrew Wesie, who is the CTO co-founder of Zint, and that's Z-I-N-T.
And before we even go any further, Andrew, what's the website? io. io.
io. Let's get that out of the way. " It's our pleasure to have you here.
I mentioned you were co-founder, CTO. Tell us, though, a little bit, Andrew, before CTO co-founder story. Yeah.
For me, I've been involved with cybersecurity since, I would say, high school really is how I view it. So, I feel like a lot of practitioners, we really get started with video game hacking, and that sort of got me into- It's launched a lot of careers. Yes ...
got me into this passion, yeah. And then I went to Carnegie Mellon, computer science. Oh, really?
Great school. I met my co-founder there actually, and we started PPP, which is a competitive hacking team. And PPP has been participating in Def Con CTF for the past 15 years.
We've won it nine times. So, you know- That's great ... what we wanted to do is we wanted to sort of take that cyber expertise and then turn it into a company.
So, we founded our first company, Theori, and that was founded really on how do we offer great R&D, great services, how do we really solve the hard problems that our customers are facing. So, that really expanded then into South Korea. We were able to bring on a lot of great hackers there.
There's a lot of great talent over there. And then, it was roughly about three years ago, ChatGPT came online. We all started asking ourselves, what does this industry look like with AI in the picture?
And this got us to the point where we had to really start to invest in R&D with AI, and that's where we sort of got what we're doing now, which is Zint. So, Zint is really focused on both black box web testing as well as white box source code analysis. Mm-hmm.
So, the source code analysis is something that we did first with DARPA about three years ago. I'm not sure if your viewership's familiar with DARPA's AI FCC, but it was a big competition that DARPA did, tens of millions of dollars in prizes. " And that really sort of formed the technical basis of what we're now selling.
No, I love it. First of all, I got to give a shout-out to Carnegie Mellon. My friend, Chenxi Wang, I don't know if you know Chenxi.
She was a professor. She's Dr. Chenxi Wang, actually.
She was a professor at CMI on their cyber and tech stuff 20 years ago. Mm. And she's back there now this summer as a visiting- Oh, nice ...
yeah, doing some kind of new labs and stuff they have going on there. But I've had a chance to interact with a lot of companies that came out of Carnegie Mellon in the cyberspace. Always quality stuff.
Yeah. Carnegie Mellon has their CyLab program there- Sure ... really good research program.
Actually, shout out probably to our advisor, David Brumley, who was there, who is really an inspiration for us. Very cool. So, you come from good stock, right?
Yeah. That's the important thing there. But look, the Def Con Capture the Flag Tournament is sort of legend.
I've been in security myself 25 plus, 28 years. It's kind of a legendary thing. The fact that you've been able to capture it nine times is, that's kind of like the '27 Yankees, right?
And that kind of immortality. Yeah. You mentioned the South Korea connection with Theori.
Maybe I missed the connection. How did that, just because they're big video game players, or? Oh, no.
So, my co-founder, he's Korean American. Mm-hmm. He's our CEO.
One of the nice things about Korea is sort of everyone's in one city. Basically- Yeah. Sure ...
a lot of the country's in Seoul, and it's very easy for us to sort of have a real community within cybersecurity. And all of the hackers sort of know each other over there. And when we went over there, we saw that there was a real, an opening for a new entrant to come in, and so we're just bringing all these brilliant hackers together.
And so that's what we're able to do. And that gave you the base of... It's funny, if you look at Qualys, the founder of Qualys unfortunately passed away.
He did the same thing in Pune, India probably 15 years ago where he decided he wasn't going to build an engineering team in Silicon Valley anymore. Too competitive, too expensive, everything else. And he found not Bangalore or Mumbai, he found Pune, at the time, was untouched, if you will.
Mm-hmm. And was able to skim the cream of the talent and built a tremendous world-class engineering organization. It sounds like that's kind of what you're doing in Korea.
Yeah, exactly. I would say that we definitely got a lot of world-class hackers from there. And it's honestly impressive to see them work.
Yeah. No, and you know what? For our audience out here, we hear obviously about American, we hear about Eastern European, and the Israeli cyber industry, and all great.
We don't hear a lot about the South Koreans as much, frankly, and maybe you want to keep it a secret like that anyway. But anyway, Andrew, let's... So, the move from Theori to Zint.
Mm-hmm. You kind of did, Theori sort of wrapped, it's still ongoing? Or it is within- Yeah.
Correct. So, Zint is sort of a product company. It's focused on how do we use AI to solve these problems in cybersecurity, specifically around application security testing.
But Theori's still going. We still have a bunch of hackers that work for us, that are still out there, helping our customers. Got it.
All right. Let's turn to Zint now. Mm-hmm.
Some people may say, "Well, this is a funny time to get into vulnerability management. " People are not sure, are we having a vulnerability apocalypse, or is it overblown? It's a boundary layer time, kind of like when the dinosaurs disappeared, and there was that tertiary boundary, right, between the age of reptiles and the age of mammals.
Are we looking at that in vulnerability management right now? Or you think it's just too early to tell, or you know it's nothing, same old, same old? I wouldn't say it's nothing.
It rhymes a bit with fuzzing. So fuzzing- I remember when fuzzing came out. Yeah.
" It's now very easy to find a vulnerability that crashes a piece of software. However, that was very limited generally to sort of memory corruption vulnerabilities. Got it.
And so now with AI, it's that, but bigger, right? Mm-hmm. It's no longer limited memory corruption.
It's no longer just random mutations. It's now systems that are reasoning through your source code, finding business logic vulnerabilities, finding IDORs, also finding the memory corruptions that maybe were just too far down the call stack for fuzzing to be able to find. So, I definitely think it is a thing.
It is a big thing. There's, I would say, an open question still right now, which is Does the ability of the AI to find bugs peter out? Does it plateau?
Does fuzzing in some ways end up plateauing? Yeah, it did. There's a big spike, and then it kind of plateaued out.
Let me push on that a little bit. Yeah. Did fuzzing itself, the technology, plateau out, or did the size of the researcher hacking audience out there plateau out who used fuzzing?
I mean- Because fuzzing's not autonomous. Someone had to be pushing it. Exactly.
Is there just a finite amount of people out there that were fuzzing? Yeah, you definitely see that, especially if you... There's a syscaller.
So basically, there's a syscall fuzzer for the Linux kernel that would find a bunch of sort of crashes. And then those would just sort of sit there for months at a time because no one actually had the time to go through and triage them. Mm-hmm.
So, in some ways the limiting factor always was, how do we triage the vulnerability? How do we fix the vulnerability? That still required the man-hours.
Yeah. And that predates fuzzing, too, let me just say, right? 2003, we came out with a vulnerability manager product called VAM at a company I had co-founded.
Internally, the name for it was the Bad News Generator, because that's really what it became. We'd go to these companies, we'd run a scan, give them the phone book of all the vulnerabilities we found, and they would just look at it as like, "This is bad news. " Yep.
And that's what really scares me around the whole Mythos thing, to tell you the truth, is if we couldn't fix the vulnerabilities we were already finding, great, let's find more vulnerabilities that we can't fix. Yep. And there's a scale issue here that, same thing with the fuzzing.
It's not the fuzzing itself, it's the people who are doing the fuzzing. We didn't have more people. So now it's like you had this rough equilibrium, the amount of researchers, the amount of vulnerabilities found, the amount of remediation we could do.
There was this kind of equilibrium, right? Now you want to put an extra rock on this side. It just seems like it throws things out of balance.
" We are now way past that. There's vulnerabilities we've had with them that have been out there for six months, and they still haven't patched, and it's just because they're overloaded. There's just so many- But yet, you see, was it Google?
I forgot. Was it 500? In the most recent Chrome update, yeah.
It was like 500. Oracle, Microsoft. So it's not like they're sitting on them.
Right. They're just overwhelmed by the scale. The other thing I think is there are certain vulnerabilities that are easy to patch.
Right. And then there's vulnerabilities that are actually very hard to patch. And so, yes, there's 500.
Those are probably the 500 easiest ones. The lowest hanging fruit. Yeah.
No doubt about it. I agree with you. Here's the other thing, though, that kind of...
It doesn't keep me up at night because I'm on this side of the camera now, but keep maybe you up at night, is that it seems the way some of these Mythos level autonomous agents, whatever you want to call them, frontier models, are working is rather than find a vulnerability, they're able to string together a bunch of not so great, minor, you wouldn't call them severe or critical or anything like that, but when they string them together, they become something much more than the sum of the parts is much greater than the individual pieces. Yes, yes. And that is a scary thing to me, too, because it's like there's six different things in the chain.
I could kill any of those six and kill it. Mm-hmm. But if I don't recognize how those six come together, I may not view them as serious enough when I have other things on my plate.
For sure. Triage is a huge part of this, and correctly being able to evaluate the impact is not easy. For sure.
And, at the same time, what Mythos is doing now with chaining together six vulnerabilities, I mean, humans were doing that before. The solution is sort of the same as it was before- No ... which is you still just need to fix the vulnerabilities.
At the end of the day, that's how this gets done. That's how this gets fixed. And to your point, though, if you do rely on six vulnerabilities, and you can kill one of them, maybe that's good enough in the meantime.
So I don't think it's the end of the world, for sure. At the end of the day, layers of defenses is very useful. So, ultimately, if an attacker, say, can't get the packets to your system, they're not going to be able to exploit you.
So, I make an AppSec product. I think AppSec testing is very important, but I think all the other parts of cybersecurity are also very important. Defense in depth.
I don't think it's necessarily the end of the world either, but I do think we are seeing a different attitude. I think it's a ripe time for new solutions. I think, quite frankly, even on the AppSec...
So I came from before AppSec time when the scanners were in production. Mm-hmm. AppSec scans were happening before things were even deployed.
Mm-hmm. I think we got a little bit, not stagnant, but kind of stuck in our ways, right? The software composition analysis, just your DAST, SAST, all these things.
Great. And there were a lot of companies within AppSec that were kind of casting about from, what else can we do here? And now I think with this whole thing, it's not the Wild West, but we're open to new ideas.
Right. We're open to new ways of, all right, how do we do this in today's world, tomorrow's world? And I'm assuming that's what Zint really is about here as well.
So we talked a lot all about here. Now, Andrew, let's focus in on Zint. What exactly is it doing?
Zint is very focused on combining AppSec testing with LLMs, and not just doing it as like, okay, take AppSec testing and sprinkle a little bit of LLM on top, but instead, what if you reinvent AppSec testing from first principles using LLMs? This was what we did in AI FCC as part of that competition is we didn't solve it with fuzzing. We didn't solve it with fuzzing plus LLMs.
We just solved it with LLMs. And so that's the approach that we're really trying to bring with Zint. And we also think that with the reasoning that LLMs are able to do, we can sort of compose multiple things together.
So you mentioned SAST and DAST and SCA, and a system these days should be able to combine all those together and give you a better result. That's our belief, and that's what we're doing with Zint. So we have the black box web app pen testing.
Doesn't need any source code. We have the side of it that's doing white box source code analysis. Doesn't need an app that it can run against.
But it can also combine those together. So if you do have a web app with the source code, we can sort of combine those scans and give you a better result, not only meaning more vulnerabilities, but also a better idea of what is the impact of this vulnerability? Can an attacker actually exploit it in your production config?
And then at the end of the day, when you remediate it, is it fixed? I love it. Now, how does it offer people out there who say, "I want to check it out"?
What could they do? Yeah. io, we have a couple of different ways for people to try out the platform.
So, we started out, give you a little bit of mindset, honestly, Andrew, to the founder mindset here is that you start off wanting to just sell to all the big enterprises, and then you kind of really want to go to market with that. You get super excited for that. But you know what they say, right?
The problem with the Fortune 500, there's only 500. Yeah, exactly. So we've actually expanded it out now.
And so anyone, you can contact us. We have basically a self-serve option available now- Great ... for both the black box web app testing, as well as for the source code analysis, and we'd be excited, honestly, for anyone to get on board and try it out and let us know what they think.
io, just as you see on the bottom third of your screen at home. Andrew, it sounds great. I'm looking forward.
I think this is exactly what I was saying, when it's a time for looking at these things through a new lens, a new set of eyes, a new set of glasses. Built LLM first, if you will. Mm-hmm.
A little different. Back in the day, we were really running the Nessus engine, writing our own NASLs. So it was very different.
But we're also at a time, I think, where we need fresh ideas. So, excellent. Thank you so much.
Yeah. Thank you. I enjoyed it.
My pleasure. Hey, I hope you've enjoyed this. io.
Self-service option. What do you got to lose? "