Pressure Zone a podcast by Hack The Box
Jul 22, 2026 · 32 min · 10 segments
An unauthenticated Remote Code Execution (RCE) vulnerability hits a deep open-source dependency inside your production microservices. The solo maintainer drops a proof-of-concept exploit and refuses…
Christine BartlettHost
Caroline WongGuestokay let's dive in your global enterprise platform relies heavily on logback extension an open source utility buried thousands of levels deep within your production cloud microservices three hours ago the solo open source maintainer deeply burnt out and frustrated by tech giants profiting off of his unpaid labor posted a stunning announcement on github He has discovered a critical unauthenticated remote code execution RCE vulnerability affecting all current versions of the library.
Instead, he dropped a proof of concept showing it works and stated he will withhold the fix until major corporate users collectively pool a $600,000 sustainability fund.
The exploit is out there in the wild, no patches exist, your automated pipelines have nothing to pull, and malicious actors are already actively scanning the internet trying to reverse engineer his proof of concept.
Okay, Caroline, you've spent your career teaching us what gets measured gets managed.
You've built mature AppSec programs founded on software bill of materials, SBOMs, aka the ingredient list, scalable gates, and continuous improvement.
But right now, the open source foundation your entire software supply chain rests upon is facing an ethical strike.
Let's see if your metrics can save you when the open source world decides to collect its debt.
okay let's dive in your global enterprise platform relies heavily on logback extension an open source utility buried thousands of levels deep within your production cloud microservices three hours ago the solo open source maintainer deeply burnt out and frustrated by tech giants profiting off of his unpaid labor posted a stunning announcement on github He has discovered a critical unauthenticated remote code execution RCE vulnerability affecting all current versions of the library.
Instead, he dropped a proof of concept showing it works and stated he will withhold the fix until major corporate users collectively pool a $600,000 sustainability fund.
The exploit is out there in the wild, no patches exist, your automated pipelines have nothing to pull, and malicious actors are already actively scanning the internet trying to reverse engineer his proof of concept.
Okay, Caroline, you've spent your career teaching us what gets measured gets managed.
You've built mature AppSec programs founded on software bill of materials, SBOMs, aka the ingredient list, scalable gates, and continuous improvement.
But right now, the open source foundation your entire software supply chain rests upon is facing an ethical strike.
Let's see if your metrics can save you when the open source world decides to collect its debt.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.