CyberWire

When “safe” documents aren’t.




Omer Ninburg⁠, CTO of ⁠Novee Security⁠, joins us on this episode of Research Saturday to discuss their work on “From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs.” Historically, Portable Document Formats – the immutable, localized PDF – was once considered a “safe” component inside enterprise environments. That is no longer the case.

To demonstrate how PDF services and engines can be exploited, the team at Novee used their proprietary, multi-agent LLM system to uncover vulnerability patterns, and systematically scale them into a broad discovery campaign across two PDF vendor ecosystems.

The research uncovered 16 verified vulnerabilities across client-side PDF viewers, embedded plugins, and server-side PDF services.



Source link