meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

When “safe” documents aren’t. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Technology, Tech News, Daily News, News

4.81.1K Ratings

🗓️ 28 March 2026

⏱️ 19 minutes

🧾️ Download transcript

Summary

Omer Ninburg, CTO of Novee Security, joins us on this episode of Research Saturday to discuss their work on "From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs." Historically, Portable Document Formats – the immutable, localized PDF – was once considered a “safe” component inside enterprise environments. That is no longer the case. To demonstrate how PDF services and engines can be exploited, the team at Novee used their proprietary, multi-agent LLM system to uncover vulnerability patterns, and systematically scale them into a broad discovery campaign across two PDF vendor ecosystems. The research uncovered 16 verified vulnerabilities across client-side PDF viewers, embedded plugins, and server-side PDF services. The research and executive brief can be found here: ⁠From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs Hacker-Trained AI Discovers 16 New 0-Day Vulnerabilities in PDF Engines Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:05.7

Hello, everyone, and welcome to the Cyberwire Research Saturday. I'm Dave Bittner,

0:21.9

and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,

0:27.1

solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace.

0:32.9

Thanks for joining us.

0:46.3

PDF engines are something that a lot of companies embed into their applications. And then if you have a vulnerability in one PDF engine, so as a third-party attack, you can compromise lots of companies and customers just by them

0:59.2

integrating those PDF engines inside of their applications.

1:03.7

That's Omer Ninberg, CTO of Novi Security.

1:07.8

The research we're discussing today is titled from PDF to Pone.

1:19.2

So before you all brought AI into this process, what did you all do to manually identify the issues inside of some of these PDF viewers?

1:30.2

What made you think there's something deeper here? This is worth pursuing.

1:34.9

When we start to investigate any application, you don't know if there is a vulnerability or not.

1:41.6

But you always presume that there is.

1:44.1

The mindset of a vulnerability

1:45.9

researcher is there's always another vulnerability. There's still something that nobody else

1:51.9

has found before. And if you keep on digging, you'll find it or find traces that will lead

1:57.9

you to the correct way. We didn't start this whole process because we thought we're going to find thousands of vulnerabilities,

2:06.6

but we wanted to understand what's the limits that we can do with AI.

2:11.6

And then we just started with the first engine, which was a PDF turned by Uprice,

2:18.2

because we found a few of our customers that had that engine.

2:22.6

Well, let's walk through it together.

2:24.5

It can take us through the story of how you all dug into these

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.