Threatcast

47 Zero-Days, No Patches: Pwn2Own Berlin's Reckoning

10 scenes9 speakersBriefing
01 Cold Open: 47 Zero-Days, No Patches0:00
0:00
Chapters
01Cold Open: 47 Zero-Days, No Patches
02Sponsor — Blue Cortex AI
03Pwn2Own Berlin: Exchange, SharePoint, and the ESXi Tenant Escape
04NGINX and Microsoft Authenticator: The Other Urgent Patches
05Pwn2Own AI Category: LiteLLM's Dual-Vector Crisis
06DPRK's Two-Billion-Dollar Machine: Bybit, Lazarus, and the Attribution Question
07Sanctions Arbitrage: Is Financial Containment of DPRK Functionally Broken?
08Verus-Ethereum Bridge: The Eleven-Million-Dollar Trust-Model Failure
09Deepfake KYC Bypass: Production-Ready Tools and the Liability Gap
10Synthesis and Action Items
Speakers
HalilAlexJamesLenaDr.ViktorDr.IsabelleDr.
01Cold Open: 47 Zero-Days, No Patches00:00
Transcript not available for this scene
02Sponsor — Blue Cortex AI01:28
Transcript not available for this scene
03Pwn2Own Berlin: Exchange, SharePoint, and the ESXi Tenant Escape02:36
Transcript not available for this scene
04NGINX and Microsoft Authenticator: The Other Urgent Patches05:23
Transcript not available for this scene
05Pwn2Own AI Category: LiteLLM's Dual-Vector Crisis07:44
Transcript not available for this scene
06DPRK's Two-Billion-Dollar Machine: Bybit, Lazarus, and the Attribution Question11:19
Transcript not available for this scene
07Sanctions Arbitrage: Is Financial Containment of DPRK Functionally Broken?14:53
Transcript not available for this scene
08Verus-Ethereum Bridge: The Eleven-Million-Dollar Trust-Model Failure17:39
Transcript not available for this scene
09Deepfake KYC Bypass: Production-Ready Tools and the Liability Gap20:51
Transcript not available for this scene
10Synthesis and Action Items24:35
Transcript not available for this scene
Episodes
May 2026
Wed20May
Exploitation Overtakes Credentials: The DBIR Inflection Point
34:4711 sc
Tue19May
pgcrypto's Twenty-Year Debt, Storm-2949's Invisible Breach, and the @antv Worm
33:4910 sc
Mon18May
47 Zero-Days, No Patches: Pwn2Own Berlin's Reckoning
30:2910 sc
NOW PLAYING
Sun17May
TOTP Secrets, Silent Patches, and a 2005 Malware That Rewrites History
33:0110 sc
Sat16May
YellowKey: The USB That Unlocks Everything
24:409 sc
Fri15May
Fragnesia: The Root You Didn't See Coming
22:508 sc
Thu14May
OT Bridgehead: When PAN-OS Meets the Power Grid
28:3410 sc
Wed13May
Dynamics 365 Is Already Burning
22:129 sc
Tue12May
No Patch, No Problem — For the Attacker
30:5411 sc
Sun10May
40 Minutes to Zero Day
41:229 sc
Sat9May
Fire Drill: PAN-OS Zero-Day, AI Keys for the Taking, and a Trojan That Blinds Your EDR
31:2710 sc
Fri8May
Zero-Day Buried in Plain Sight: PAN-OS, ShinyHunters, and the Mislabeled Threat
27:5210 sc
Thu7May
AI Weaponization Convergence: The Day Three Threats Landed at Once
30:1011 sc
Wed6May
Grid on the Edge: Itron's OT Pivot, the Phantom Device Attack, and Coupang's $1.5B Insider Meltdown
30:0810 sc
Tue5May
Medtronic's Blurry Lines, GnuTLS's Silent Blast, and the AiTM Session Heist
30:5410 sc
Mon4May
Lease Files, Franchise Spyware, and the AI Hype Machine
34:3611 sc
Sun3May
Trust Collapse: Canvas Countdown, Worm in Three Ecosystems, and the AI Perimeter That Wasn't
26:5610 sc
Fri1May
Five Hundred Seventy-Seven Million Reasons to Audit Your Defaults
23:409 sc
Apr 2026
Tue28Apr
Grid in the Crosshairs: Cisco SD-WAN, Gemini CLI, and Two Deadlines Expiring Today
30:4311 sc
Sun26Apr
Correction Day: The LAPSUS$ Claim Falls Apart, Signal Phishing Is Real
29:2910 sc
Sat25Apr
Pay or Leak: The 48-Hour Clock, Two CVEs You Must Patch, and DeFi's Governance Confession
29:1912 sc
Fri24Apr
Shai-Hulud: The Worm That Ate the Pipeline
30:5411 sc
Thu23Apr
Autonomous Worm, Unseizable C2, and 19 Million Stolen Identities
31:5413 sc
Wed22Apr
Mythos Breached, Supply Chain Burning, Patch Everything Now
28:4313 sc
Tue21Apr
Cisco's 48-Hour Clock, Vercel's Roblox Problem, and France's Identity Meltdown
28:5112 sc
Mon20Apr
Trust Is the Vulnerability
29:5112 sc
Sun19Apr
Two Hundred Million in Bad Debt and the AI That Finds Zero-Days
29:1210 sc
Sat18Apr
RedSun Rising: Defender Becomes the Attacker
28:1011 sc
Fri17Apr
Nation-State Supply Chains, Iran's PLC Gambit, and the AI Exploit Machine
33:1812 sc