Skip to main content

Can agentic AI really find zero-days? Ask the hacker who won Pwn2Own Berlin 2026

18 июн. 2026 г. · 22 min

Featured guest

Valentina Palmiotti

Valentina Palmiotti

Vulnerability Researcher & Exploit Developer

Hosts

Johnny Hand

Johnny Hand

Global CISO · TrendAI™

Dustin Childs

Dustin Childs

Head of Threat Awareness · ZDI

PortableText [components.type] is missing "span"

AI Security Brief Episode 5 with guest Valentina Palmiotti

About the episode

At Pwn2Own Berlin 2026, a security researcher used agentic AI to help her win. The AI surfaced real, verified bugs, then wrongly called her winning bug “not exploitable in practice.” Spoiler - it was. That uneven record is exactly what security leaders need to understand about the promise and limits of agentic AI. In this episode, host Dustin Childs sits down with Valentina Palmiotti – better known as Chompie – who took home $70,000 for zero-days in the NVIDIA Container Toolkit and Red Hat Enterprise Linux. Drawing from firsthand experience, Chompie shares agentic AI’s proven value for defenders and why human expertise remains essential.

What you'll learn
  • What agentic AI can genuinely do in skilled hands today, and where it still fails
  • Why your real exposure isn't new bugs, it's the widening gap before known ones get patched
  • How agentic AI is best viewed as a tool that frees skilled teams for higher-value work

Episode chapters

  • 00:00 — When agentic AI became a vulnerability research breakthrough
  • 01:56 — Chompie’s path into vulnerability research
  • 02:52 — Using Claude Code to find a Pwn2Own vulnerability
  • 04:06 — Where autonomous exploit generation failed
  • 06:41 — Are we approaching a vulnerability apocalypse?
  • 08:14 — Exploiting a difficult race condition
  • 09:51 — How AI changes the vulnerability research process
  • 12:33 — What the security industry may be missing about AI
  • 17:08 — A commitment for the future of AI development

"I kind of just let it go and autonomously verify itself. I said, ‘Only show me the bugs that you were able to prove are real bugs.’ It came back with a few, and that was my holy sh*t moment."

— Valentina Palmiotti, Vulnerability Researcher & Exploit Developer

Hosts

Johnny Hand

As the Global CISO for TrendAI™ and veteran of enterprise security, Johnny brings a security leader’s lens to every conversation, separating exploitable risk from theoretical noise. Johnny is the person you want explaining AI-era threats before your board asks about them.

Johnny Hand
Dustin Childs

Dustin Childs

As Head of Threat Awareness for the TrendAI™ Zero Day Initiative (ZDI), Dustin brings a vulnerability researcher's eye to the AI security conversation. He’s dedicated to making sure the industry understands exploit development before it becomes a crisis.

More episodes

  • AI Security Brief Episode 10 with guest Zach Evans

    Episode 10 · 27 авг. 2026 г.

    What does hospital downtime teach us about building AI-native organizations?

    Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it.

  • AI Security Brief Episode 9 with guest Tom Kellermann

    Episode 9 · 13 авг. 2026 г.

    What do AI-driven ‘bank heist’ attacks mean for defenders?

    Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave?

  • AI Security Brief Episode 8 with guest Mark Houpt

    Episode 8 · 30 июл. 2026 г.

    Is AI security actually a physical problem?

    While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them.

  • AI Security Brief Episode 7 with guest Sundari Parekh

    Episode 7 · 16 июл. 2026 г.

    Who governs your AI agents?

    Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans.

  • AI Security Brief Episode 6 with guest Rob Bair

    Episode 6 · 2 июл. 2026 г.

    Is the next frontier model your biggest threat or your best defender?

    If you think the recent wave of AI-discovered vulnerabilities is a problem, Rob Bair of Anthropic has a reframe for you.

  • AI Security Brief Episode 4 with guest Dr. Grace Trinidad

    Episode 4 · 4 июн. 2026 г.

    Is your enterprise AI strategy delivering ROI yet?

    Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far.