<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CodeWall.ai Blog</title>
    <link>https://codewall.ai/blog</link>
    <description>Security research and vulnerability disclosures from CodeWall's autonomous offensive AI agents.</description>
    <language>en</language>
    <lastBuildDate>Wed, 15 Apr 2026 21:39:54 GMT</lastBuildDate>
    <atom:link href="https://codewall.ai/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>How We Hacked Bain's Competitive Intelligence Platform</title>
      <link>https://codewall.ai/blog/how-we-hacked-bains-competitive-intelligence-platform</link>
      <guid>https://codewall.ai/blog/how-we-hacked-bains-competitive-intelligence-platform</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate>
      <description>Our agent found hardcoded credentials in a public JavaScript file in under 18 minutes. A chained SQL injection gave us everything else — 159 billion rows of consumer data and the competitive strategies of some of the world's biggest brands.</description>
    </item>
    <item>
      <title>How We Hacked BCG's Data Warehouse — 3.17 Trillion Rows, Zero Authentication</title>
      <link>https://codewall.ai/blog/how-we-hacked-bcgs-data-warehouse-3-17-trillion-rows-zero-authentication</link>
      <guid>https://codewall.ai/blog/how-we-hacked-bcgs-data-warehouse-3-17-trillion-rows-zero-authentication</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <description>Our autonomous hacking agent found an unauthenticated SQL execution endpoint on BCG's X Portal. Behind it: 131 terabytes and 3.17 trillion rows of data.</description>
    </item>
    <item>
      <title>AI vs AI: How Our AI Agent Hacked a $20M-Funded AI Recruiter</title>
      <link>https://codewall.ai/blog/ai-vs-ai-how-our-ai-agent-hacked-a-20m-funded-ai-recruiter</link>
      <guid>https://codewall.ai/blog/ai-vs-ai-how-our-ai-agent-hacked-a-20m-funded-ai-recruiter</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <description>Our autonomous agent chained four harmless bugs into a CVSS 9.8 org takeover of a $20M-funded AI recruiter — then gave itself a voice and talked to the target's AI. Clients included Anthropic, Stripe, and Monzo.</description>
    </item>
    <item>
      <title>How We Hacked McKinsey's AI Platform</title>
      <link>https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform</link>
      <guid>https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform</guid>
      <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
      <description>An autonomous AI agent found a SQL injection in McKinsey's Lilli AI platform. What it extracted was worse than we expected.</description>
    </item>
  </channel>
</rss>
