Episode

When “safe” documents aren’t.

Podcast
Research Saturday
Published
Mar 28, 2026
Duration seconds
1263
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/418/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW2925735484.mp3?updated=1774547657
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/when-safe-documents-aren-t
Markdown
/podcast/research-saturday-1377435/when-safe-documents-aren-t.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/when-safe-documents-aren-t/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/when-safe-documents-aren-t.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Omer Ninburg, CTO of Novee Security, joins us on this episode of Research Saturday to discuss their work on "From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs." Historically, Portable Document Formats – the immutable, localized PDF – was once considered a “safe” component inside enterprise environments. That is no longer the case. To demonstrate how PDF services and engines can be exploited, the team at Novee used their proprietary, multi-agent LLM system to uncover vulnerability patterns, and systematically scale them into a broad discovery campaign across two PDF vendor ecosystems. The research uncovered 16 verified vulnerabilities across client-side PDF viewers, embedded plugins, and server-side PDF services. The research and executive brief can be found here: ⁠From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs Hacker-Trained AI Discovers 16 New 0-Day Vulnerabilities in PDF Engines