Security Conversations
244
Security Conversations
10.07.2026 | 1:08''31'
Valentina Palmiotti (chompie) on Vulnpocalypse, Matching Mythos on a Budget
About the episode
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem x Offensive AI Con: Live from OAIC, IBM X-Force’s Valentina Palmiotti (chompie) walks us through the autonomous Windows kernel exploit pipeline she built on older Claude models, which landed within a hair of Mythos for about $180 a chain.
Plus, the Pwn2Own bug Claude called unexploitable, why her Pwn2Own bugs still sit unpatched, disappearing exploit techniques, the dread of being a defender, and how Phrack found its way back into print.
Timestamps:
0:00 Intro and Pwn2Own war stories
3:46 What vibe hacking means
8:16 When long agent runs go sideways
10:31 Self-verification in an n-day kernel pipeline
16:11 Matching Mythos for $180 a chain
18:42 The bug Claude called unexploitable
21:49 Unpatched bugs and the defender gap
25:37 Mythos arrives through CVP
27:00 Models only know public techniques
32:01 Testing models on held-back bugs
37:45 Inside chompie’s daily workflow
46:07 Where’s the exploitpocalypse?
50:07 Pixel drops MTE
53:40 Advice for defenders: design for containment
58:34 Phrack is back
Links:
- Transcript
- Valentina Palmiotti (chompie) on Twitter
- chompie at the bits
- Valentina Palmiotti | LinkedIn
- Confirmed! @chompie1337 $20,000 Pwn2Own Victory
- Interview with Valentina Palmiotti, Pwn2Own Berlin 2026
- Expanding the Cyber Verification Program Anthropic
- Racing against the clock — hitting a tiny kernel race window – Project Zero
- Building an Autonomous N-day Exploit Generation Pipeline
- Pixel 11 lost a security feature (MTE)
- Firecracket – Secure and fast microVMs for serverless computing
- tmp.0ut
- Phrack Magazine
- Offensive AI Conference
- TLPBLACK