Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
Sep 14, 2026 · 1h 40m
Summary
This episode analyzes the "0 Day Clock" website, debating whether AI-driven vulnerability discovery is creating a "boiling the ocean" problem without corresponding fixes. The hosts discuss a Caliph research lab demo of a WeChat-based mobile worm that could infect a billion phones in ten minutes, highlighting new telecom distribution vectors. They critique Anthropic’s Project Glasswing, noting that despite finding thousands of vulnerabilities, the vast majority remain unpatched due to economic misalignment. The discussion concludes with a call for positive, automated mitigation strategies an…
Topics discussed
Intro: Horizon 3, TV privacy, and news roundup
Hoagie etymology and InfoSec World announcement
Horizon 3: Automated validation and exploitability
Password analysis and MFA bypass techniques
Production safety and reinforcement learning loops
Edge cases: Load balancer DoS and attack surface
CIO perspective: Prioritizing risk and fixing what matters
AI gullibility, deception, and legal issues of agent hacking
Rubric ad and TV privacy segment intro
Smart TV usability, ACR, and privacy concerns
Network traffic analysis and wearable device privacy
Vibe check: AI agents in security operations
Acquisitions and the 0-day clock methodology debate
Accountability for insecure software and patching fatigue
WeChat worm: VoIP RCE and telecom distribution
AI remediation limits and Project Glasswing findings
Value of vulnerability finding vs. positive impact
SSH exposure and AI-driven threat intelligence
AI hardware gadgets and lazy workarounds
Outro and subscription call to action
Listen ad-free on Castria