Fresh from Hacker Summer Camp in Las Vegas, our latest episode of runZero Hour brought together stories from the stage, new research tools, and some hard truths about vulnerability management. If you missed it live, here’s a look at what we covered and why it matters.

The hidden entry points that matter most #

The team had a strong showing this year, with (eight!!) talks across BSides, Black Hat, and DEF CON. HD Moore opened the episode by sharing highlights from his Turbo Tactical Exploitation talk, which boiled down years of pentesting experience into rapid-fire techniques. He reminded us that attackers don’t always storm the front gates. Instead, they target the systems that control access (like network management consoles, administrator workstations, or even forgotten printers) because those often open faster and wider doors into an environment than direct attacks on hardened endpoints.

It was a reminder that the weakest link isn’t always the most obvious one, and that defenders need to think more broadly about what “critical systems” really are.

Digging deeper with Akheron Proxy #

Making his runZero Hour debut, Matthew Kienow introduced Akheron Proxy, a tool (developed with Deral Heiland) for bridging, capturing, replaying, and manipulating UART inter-chip communications.

In practice, this kind of tool lets you find flaws in devices that seem locked down from the outside. Matthew demonstrated how something as ordinary as a garage door sensor can be reverse engineered at the hardware level, revealing hidden weaknesses in its communication patterns. It’s not a tool for the faint of heart. It requires soldering irons, wires, and patience..But it opens up a new dimension of analysis for embedded devices.

Detecting hidden OT assets #

Rob King presented highlights from his DEF CON talk, which shares tips on how to detect OT devices across protocol gateways. Rob walked through recursive enumeration techniques that let researchers uncover the full landscape of OT assets, not just the obvious endpoints. The takeaway was simple but important: in converged IT/OT environments, you can’t secure what you don’t know exists.

Making sense of vulnerability scores #

Tod Beardsley revisited his Black Hat talk and report, Divining Risk: Deciphering Signals from Vulnerability Scores. He compared CVSS, EPSS, and SSVC, the three different systems for measuring vulnerability risk.

Like haruspices, today’s defenders are trying to interpret patterns in imperfect data. Each scoring system offers a different lens, but no single one should dictate security priorities. To help make sense of fast-changing exploit predictions, Tod presented EPSS Pulse, a new tool from runZero for tracking daily shifts in EPSS scores and identifying vulnerabilities gaining traction with attackers.

Rapid response rundown #

We closed with a look at the latest rapid response updates, vulnerabilities that defenders should act on quickly. As always, runZero customers can find ready-to-run queries in the console to help identify impacted systems.

Watch the episode #

You can catch the full episode on demand below – be sure to register to join us next month!

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 5.0: Exposure management built to outpace AI-driven attacks
When you're up against AI, every minute counts. Get deep, actionable intelligence across your entire attack surface to close the gaps and hold the...
Product Videos
runZero 5.0: Platform Demo
With the new 5.0 release, runZero is giving defenders the edge they need to succeed in the AI-attack era.
runZero Perspective
BOD 26-04: A new era of prioritized remediation
A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.