Leader of the Zero Day Initiative. Pwn2Own organizer and adjudicator. Trafficker of export-controlled intrusion software. Bug Hunter.

Joined May 2010
17 Photos and videos
Brian Gorenc retweeted
Announcing #Pwn2Own Berlin 2026! We've got 10 categories for targets, including an expanded #AI target list. We have 4 AI categories - including coding agents (looking at you #Claude). More than $1,000,000 in cash & prizes available. Read the details at zerodayinitiative.com/blog/2…
6
33
189
64,259
Brian Gorenc retweeted
13 Nov 2025
Huge thanks for the keynote 💙 It was fantastic. Brian Gorenc (@MaliciousInput) – From Buffer Overflows to Breaking AI: Two Decades of ZDI Vulnerability Research 🎤 #POC2025
6
54
5,924
Brian Gorenc retweeted
Congrats to @mrpowell @izobashi and @chudyPB for making the list.
Congratulations to our MSRC 2023 Most Valuable Researchers! Thank you to all the researchers who have helped secure our customers. 👏🎉 Check out our blog for the full list: msft.it/60199yOc9
1
5
25
8,465
Brian Gorenc retweeted
Recapping #Pwn2Own Vancouver 2023. We had an amazing contest and awarded over $1 million (plus a Tesla Model 3) for 27 unique 0-days. Join ZDI's @MaliciousInput and @dustin_childs as they go through all the highlights of this year's event. youtu.be/c0cS4R0ja-I

1
13
69
34,987
Brian Gorenc retweeted
Since no one from the MSRC is here at #Pwn2Own, we're disclosing the Teams exploit over a Teams call. You can join us if you want to hear the details: msteams.link/ZPRX

6
15
65
25,127
Brian Gorenc retweeted
CONFIRMED! @Synacktiv used a heap overflow & an OOB write to exploit the Infotainment system on the Tesla. When they gave us the details, we determined they actually qualified for a Tier 2 award! They win $250,000 and 25 Master of Pwn points. 1st ever Tier 2 award. Stellar work!
6
116
476
114,836
Brian Gorenc retweeted
In a #Pwn2Own first, AI was involved in a successful exploit. The @claroty team used @openai 's #ChatGPT to write one of the backend modules used in their RCE of #Softing edgeAggregator. What a time to be alive.
2
23
71
16,434
Brian Gorenc retweeted
This year at #BHUSA, @MaliciousInput & @dustin_childs present “Calculating Risk in the Era of Obscurity: Reading Between the Lines of Security Advisories” - A look at how enterprises can estimate risk in an era where patches aren't what they used to be. blackhat.com/us-22/briefings…

6
19
Brian Gorenc retweeted
The @Synacktiv team shows off their remote exploit of the #Tesla Model 3. Earlier today, this research earned them $75,000 during #Pwn2Own.
7
87
249
Brian Gorenc retweeted
Happy to sponsor and look forward to attending.
Thank you @TrendMicro and @thezdi for supporting #OffensiveCon22 as gold sponsors! offensivecon.org/sponsors/
4
30
Brian Gorenc retweeted
Thank you @TrendMicro and @thezdi for supporting #OffensiveCon22 as gold sponsors! offensivecon.org/sponsors/

3
13
Brian Gorenc retweeted
Announcing #Pwn2Own Austin! Our fall contest includes phones, printers, NAS devices and more. More than $500,000 USD in cash and prizes are available as 22 different devices will be put to the test. Read all of the details at zerodayinitiative.com/blog/2…

3
51
119
Brian Gorenc retweeted
With that last award, we're now at $1,020,000 awarded for the contest with 9 attempts to go. It's the first time we've crossed the million dollar mark at #Pwn2Own. More to come...

ALT Dr Evil One Billion Dollars GIF

10
61
Brian Gorenc retweeted
The live drawing for #Pwn2Own will be at 9am Eastern tomorrow (April 6). You can watch the draw and all the contest live on YouTube at youtu.be/dA3aIMgRFY8

1
15
35
Brian Gorenc retweeted
Here's a quick preview of the Master of Pwn trophy for the upcoming #Pwn2Own. @creatify is adding LEDs to this version, and so far, it looks amazing.
1
4
41
Brian Gorenc retweeted
CVE-2021-27076: A complex bug that leads to reliable code execution. @HexKitchen details this replay-style deserialization attack against #Microsoft #SharePoint. As a reminder, we're paying $50k for SharePoint exploits at #Pwn2Own. bit.ly/3r4CGSt

51
108
Brian Gorenc retweeted
For everyone finding variants while analyzing the in-the-wild #Exchange bugs, remember they are worth $200K at the upcoming #Pwn2Own contest. Bugs reported at the event have a 90-day disclosure timeline. Remember, no more patch Tuesdays before the contest. bit.ly/3ooKM6J

15
34