A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the
This week we get to take a look into some basic heap grooming techniques as we examine multiple heap
This week we talk a bit about newly released Black Hat 2020 and NDSS 2021 presentation videos, befor
A couple privacy violations, PDF exploits, and a complicated API being misused by developers. [00:0
"Beg Bounty" hunters, dependency confusion, iOS kernel vuln, and how not to respond to security rese
A lot of discussion this week about OSS security and security processes, an iOS kernel type confusio
Starting with a long discussion about the North Korean hackers targeting security reseachers, and so
This week is a shorter episode, but still some solid bugs to look at. From a full chain Chrome explo
Several lockscreen-related vulnerabilities this week, a cross-site leak, and the hijacking of
A new universal deserialization gadget for Ruby, a Rocket.Chat SAML auth bypass, and some heap explo
An update on Apple v. Corellium, some 3DS vulnerabilities, and some drama on this weeks episode. [0
Big news this week as several government agencies and contractors may have been compromised. We also
Some solid exploit development talk in this episode as we look at an iOS vuln, discuss the exploitab
More SD-PWN, more Tesla hacks, potential RCE in Drupal, and a couple windows vulns. [00:00:27] Congr
This week we talk a bit about some Black Friday deals before jumping into another SD-WAN pwn, some j
Some interesting tips and tricks as we look at multiple privileges escalations from XNU to Ubuntu, B
A Facebook DOM-based XSS, Rocket.chat and Github Actions RCEs, and a Brave Browser information discl
This week we are joined by CTS to discuss fuzzing. We also take at PEN-300/OSEP. Before jumping into
A lot to cover in this episode, from high performance fuzzing on GPUs, to low-cost pentesters, and A
It has been a while since we had an exploit extravaganza but here we are. Several binary-level issue
Its a web-exploit heavy episode impacing Apple, Hasicorp, Azure, Google, and even a DOMPurify Bypass