# AI Found 5 CVEs in One Afternoon — The BEAM Security Wake-Up Call | Peter Ullrich & Jonathan Machen Page: https://stenobird.com/podcast/beam-there-done-that-7725251/ai-found-5-cves-in-one-afternoon-the-beam-security-wake-up-call-peter-ullrich-jonathan-machen Text version: https://stenobird.com/podcast/beam-there-done-that-7725251/ai-found-5-cves-in-one-afternoon-the-beam-security-wake-up-call-peter-ullrich-jonathan-machen.md Podcast: [BEAM There, Done That](https://stenobird.com/podcast/beam-there-done-that-7725251) Published: 2026-05-29T10:00:00+00:00 Episode link: https://podcasters.spotify.com/pod/show/beamtheredonethat/episodes/AI-Found-5-CVEs-in-One-Afternoon--The-BEAM-Security-Wake-Up-Call--Peter-Ullrich--Jonathan-Machen-e3jtbot Audio file: https://anchor.fm/s/10f787368/podcast/play/120548573/https%3A%2F%2Fd3ctxlq1ktw2nl.cloudfront.net%2Fstaging%2F2026-4-26%2F424898832-44100-2-ce1a178018a86.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/beam-there-done-that-7725251/episodes/ai-found-5-cves-in-one-afternoon-the-beam-security-wake-up-call-peter-ullrich-jonathan-machen Duration seconds: 3749 ## Resource The BEAM ecosystem spent decades flying under the radar - too niche to attract serious attackers. That era is over. In this episode, we sit down with Peter Ullrich, the developer who ran a $10 experiment at ElixirConf EU in Málaga and discovered a vulnerability that could crash the BEAM with a 13-character string - with zero prior security experience. Then we hear from Jonathan Machen, CISO of the Erlang Ecosystem Foundation, whose job is to catch and coordinate everything Peter finds. We cover: How Peter built a simple bash script that scanned the most-downloaded Hex packages - and what he found Why LLMs have changed the cost and skill floor for vulnerability research forever The CVE disclosure process: what happens from the moment a bug is found to the moment it's published How the EEF's CNA went from 9 CVEs in a year to more in a single week What library maintainers should do right now (spoiler: it's three clicks on GitHub) The AGES initiative, supply chain security, and the gap between what's been built and what the moment demands Why paying a vendor like Trivy isn't enough - and what actually needs to happen If you run Phoenix in production, this episode is required listening. Resources mentioned: Peter's blog post and prompts: github.com/pultrich (linked in post) Linux Foundation's Scrutineer project Report vulnerabilities: cna@erlef.org Support the Erlang Ecosystem Foundation: erlef.org ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/beam-there-done-that-7725251/episodes/ai-found-5-cves-in-one-afternoon-the-beam-security-wake-up-call-peter-ullrich-jonathan-machen/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/beam-there-done-that-7725251/ai-found-5-cves-in-one-afternoon-the-beam-security-wake-up-call-peter-ullrich-jonathan-machen.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.