Can Agentic AI Really Find Zero-Days? Ask the Hacker Who Won Pwn2Own Berlin 2026

June 18
22 mins

View Transcript

Episode Description

At Pwn2Own Berlin 2026, a security researcher used agentic AI to help her win. The AI surfaced real, verified bugs, then wrongly called her winning bug “not unexploitable in practice.” Spoiler - it was.That uneven record is exactly what security leaders need to understand about the promise and limits of agentic AI.

In this episode, host Dustin Childs sits down with Valentina Palmiotti – better known as Chompie – who took home $70,000 for zero-days in the NVIDIA Container Toolkit and Red Hat Enterprise Linux. Drawing from firsthand experience, Chompie shares agentic AI’s proven value for defenders and why human expertise remains essential.

What we cover:

  • What agentic AI can genuinely do in skilled hands today, and where it still fails

  • Why your real exposure isn't new bugs, it's the widening gap before known ones get patched

  • How agentic AI is best viewed as a tool that frees skilled teams for higher-value work

Why stick around:

This is a real-world view of agentic AI beyond the hype: what security work AI can accelerate and the judgement calls it can’t make without human input.

Episode resources:

About AI Security Brief

AI Security Brief is where security and technology leaders come to get ahead. Join us for real conversations on the AI trends, threats, and decisions that can’t wait.

About TrendAI™

TrendAI™ empowers organizations to lead the future of AI with proactive security designed to inspire innovation and eliminate risk. TrendAI™. AI Fearlessly.

See all episodes