Xint Reinvents AppSec Testing for the LLM Era
AppSec Testing Enters an LLM-First Phase
Alan Shimel speaks with Andrew Wesie, co-founder and CTO of Xint, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on LLM AppSec testing and the way AI is changing vulnerability discovery, triage and remediation. Wesie explains how his cybersecurity path began with competitive hacking, Carnegie Mellon and the Plaid Parliament of Pwning CTF team.
Wesie also describes the path from Theori to Xint. Theori brought together elite security researchers to solve hard offensive security problems. Xint builds on that experience with an AI-first approach to application security testing, including black-box web testing and white-box source code analysis.
AI Expands the Vulnerability Discovery Problem
The interview explores why AI may create a new boundary point for vulnerability management. Wesie compares the current moment to the rise of fuzzing, when teams suddenly found many more software flaws. AI extends that idea beyond memory corruption. It can reason through source code, identify business logic issues and uncover vulnerabilities that traditional methods may miss.
That creates a scale problem. Many organizations already struggle to fix the vulnerabilities they know about. Adding AI-driven discovery can increase the volume of findings even further. Wesie says the real challenge is not only finding vulnerabilities. Teams also need better ways to triage, prioritize and verify fixes.
Xint Combines Black-Box and White-Box Testing
Xint is designed to rethink AppSec testing from first principles using LLMs. Wesie says the goal is not to add a small AI feature to older testing workflows. Instead, Xint uses LLMs as the foundation for black-box web application testing and white-box source code analysis.
That combination matters because modern attacks often involve multiple weak points. A single issue may not look critical on its own. Several issues chained together can create a much larger risk. LLM AppSec testing can help connect those signals and provide better context around exploitability and impact.
Better Triage Becomes the AppSec Priority
The discussion closes with a practical message for security and engineering leaders. AI can help find more vulnerabilities, but more findings are not useful without better prioritization. Teams need to understand whether an attacker can exploit a flaw in their production configuration. They also need to know whether remediation actually fixed the issue.
For AppSec teams, Xint’s approach points to a broader shift. LLM AppSec testing is moving the industry toward systems that combine discovery, context, impact analysis and validation. That shift could help organizations handle the growing scale of AI-driven vulnerability discovery without drowning in bad news.