A weekly podcast for bounty hunters, exploit developers or anyone interesting in the details of the
A shorter episode this week, featuring some vulnerabilities impacting Google's AI and a SAML aut
VirtualBox has a very buggy driver, PostgreSQL has an Out of Bounds Access, and lifetime issues are
This week's episode features a cache deception issue, Joomla inherits a PHP bug, and a DOM clobb
Linux becomes a CNA and takes a stance on managing CVEs for themselves, and underutilized fuzzing st
In this bounty episode, some straightforward bugs were disclosed in GhostCMS and ClamAV, and Portswi
Google makes some changes to their kCTF competition, and a few kernel bugs shake out of the LogMeIn
DEF CON moves venues, the Canadian government moves to ban Flipper Zero, and some XSS issues affect
Libfuzzer goes into maintenance-only mode and syslog vulnerabilities plague some vendors in this wee
This week we have a crazy crypto fail where some Android devices had updates signed by publicly avai
This week's binary episode features a range of topics from discussion on Pwn2Own's first aut
A packed episode this week as we cover recent vulnerabilities from the last two weeks, including som
A bit of a game special this week, with a Counter-Strike: Global Offensive vulnerability and an expl
A short bounty episode featuring some logical bugs in Apache OFBiz, a GitLab Account Takeover, and a
This week's highly technical episode has discussion around the exploitation of a libwebp vulnera
Kicking off 2024 with a longer episode as we talk about some auditing desktop applications (in the c
A bit of a rambling episode to finish off 2023, we talk about some Linux kernel exploitation researc
A mix of issues this week, not traditionally bounty topics, but there are some lessons that can be a
A Samsung special this week, starting off with two Samsung specific vulnerabilities, one in the bas
This week brings up a pretty solid variety of issues. Starting off with some cookie smuggling (and o
This week kicks off with a a V8 misoptimization leading to out-of-bounds access, an unprotected MSR