{"id":5512,"date":"2025-05-06T08:18:40","date_gmt":"2025-05-06T06:18:40","guid":{"rendered":"https:\/\/security.humanativaspa.it\/?p=5512"},"modified":"2026-03-11T09:54:56","modified_gmt":"2026-03-11T09:54:56","slug":"my-zero-day-quest-bluehat-podcast","status":"publish","type":"post","link":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/","title":{"rendered":"My Zero Day Quest &#038; BlueHat Podcast"},"content":{"rendered":"<blockquote><p><em>&#8220;If you shame attack research, you misjudge its contribution.<br \/>\nOffense and defense aren&#8217;t peers. Defense is offense&#8217;s child.&#8221;<br \/>\n&#8212; John Lambert<br \/>\n<\/em><\/p><\/blockquote>\n<h3>TL;DR<\/h3>\n<p>Last month, some of the world&#8217;s <strong>top security researchers<\/strong> came together on the Microsoft campus for the first-ever <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/zero_day_quest_live_hacking_event\">Zero Day Quest Onsite Hacking Event<\/a>, an invite-only gathering focused on fostering collaboration, exchanging ideas, and finding vulnerabilities across Microsoft\u2019s <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/bounty-ai\">AI<\/a> and <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/bounty-microsoft-azure\">Cloud<\/a> programs.<\/p>\n<p><iframe title=\"Announcing Zero Day Quest, a hacking event focused on securing Cloud and AI | Microsoft Ignite 2024\" width=\"563\" height=\"1000\" src=\"https:\/\/www.youtube.com\/embed\/Ac069ty_E9o?feature=oembed&#038;width=840&#038;height=1000&#038;discover=1\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p class=\"p1\">From nonstop bug hunting sessions and deep dives with Microsoft engineers to exclusive social events like dinner at the Space Needle and a Seattle Mariners game, <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/microsoft-zero-day-quest\">Zero Day Quest<\/a> was equal parts <strong>security research and community building<\/strong>.<\/p>\n<p>As one of last year&#8217;s <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/04\/congratulations-to-the-top-msrc-2024-q1-security-researchers\/\">highest ranking<\/a> Azure security researchers and <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/08\/congratulations-to-the-msrc-2024-most-valuable-security-researchers\/\">Most Valuable Researcher (MVR)<\/a>, I was selected to participate in this event based on my expertise and contributions to Microsoft. Here\u2019s the story of how I qualified and my experience at the Zero Day Quest.<\/p>\n<p>As a bonus, after ZDQ I&#8217;ve also been a guest at the <a href=\"https:\/\/thecyberwire.com\/podcasts\/the-bluehat-podcast\">BlueHat Podcast<\/a>, Microsoft&#8217;s podcast that hosts conversations with researchers and industry leaders working to secure the planet&#8217;s technology and create a safer world for all. Catch my episode <a href=\"https:\/\/thecyberwire.com\/podcasts\/the-bluehat-podcast\/52\/notes\">here<\/a>! \ud83e\udde2<\/p>\n<h3>From Unix to Azure<\/h3>\n<p>It&#8217;s been one month since I attended the <strong>inaugural Zero Day Quest<\/strong>, the largest live hacking event of its kind that brought together top security researchers from around the world to find the highest-impact vulnerability scenarios in Microsoft&#8217;s <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/bounty-ai\">AI<\/a> and <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/bounty-microsoft-azure\">Cloud<\/a>.<\/p>\n<p>But how did a <a href=\"https:\/\/0xdeadbeef.info\/\">seasoned Unix hacker<\/a> like me qualify for a Microsoft event in the first place? Long story short, some time ago I became interested in source code review. I built <a href=\"https:\/\/hnsecurity.it\/a-collection-of-weggli-patterns-for-c-cpp-vulnerability-research\/\">some<\/a> <a href=\"https:\/\/hnsecurity.it\/big-update-to-my-semgrep-c-cpp-ruleset\/\">tooling<\/a> to automate part of it, and in 2023 I audited the most popular <strong>open-source IoT operating systems<\/strong>: <a href=\"https:\/\/hnsecurity.it\/ost2-zephyr-rtos-and-a-bunch-of-cves\/\">Zephyr<\/a>, <a href=\"https:\/\/hnsecurity.it\/multiple-vulnerabilities-in-rt-thread-rtos\/\">RT-Thread<\/a>, <a href=\"https:\/\/hnsecurity.it\/multiple-vulnerabilities-in-riot-os\/\">RIOT<\/a>, <a href=\"https:\/\/github.com\/FreeRTOS\/FreeRTOS-Plus-TCP\/pull\/1017\">FreeRTOS<\/a>, and more&#8230;<\/p>\n<p>At some point, I stumbled upon <strong>Azure RTOS<\/strong>. In December 2023, I reported to <a href=\"https:\/\/msrc.microsoft.com\/report\/vulnerability\">MSRC<\/a> a few vulnerabilities in this OS, two of which were found in a couple of hours of code review and <a href=\"https:\/\/github.com\/eclipse-threadx\/threadx\/commit\/39f3c86c61ec478720bac9fca8f17ccedb8f052b\">were<\/a> <a href=\"https:\/\/github.com\/eclipse-threadx\/threadx\/commit\/9f3e35d3dcacfac3eed6df8fb8cc6ed9a5a680d5\">fixed<\/a> right away. They alone earned me a whopping 240 points that <strong>landed me in the top positions<\/strong> of their <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/01\/congratulations-to-the-top-msrc-2023-q4-security-researchers\/\">quarterly leaderboards<\/a>!<\/p>\n<figure id=\"attachment_161438\" aria-describedby=\"caption-attachment-161438\" style=\"width: 728px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-161438 size-full\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2026\/03\/msrc-a-screenshot-of-a-computer-description-automatically-generated-3.png\" alt=\"\" width=\"728\" height=\"469\" srcset=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2026\/03\/msrc-a-screenshot-of-a-computer-description-automatically-generated-3.png 728w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2026\/03\/msrc-a-screenshot-of-a-computer-description-automatically-generated-3-300x193.png 300w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2026\/03\/msrc-a-screenshot-of-a-computer-description-automatically-generated-3-350x225.png 350w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/><figcaption id=\"caption-attachment-161438\" class=\"wp-caption-text\">Top MSRC 2023 Q4 Security Researcher Leaderboard for Azure<\/figcaption><\/figure>\n<p>Shortly after my first bug submissions, Azure RTOS was handed over to the Eclipse Foundation and became <a href=\"https:\/\/hnsecurity.it\/multiple-vulnerabilities-in-eclipse-threadx\/\">Eclipse ThreadX<\/a>. Therefore, all other vulnerabilities I reported in this software were not handled by MSRC anymore. In addition, I wasn&#8217;t awarded a bounty because Azure RTOS had been declared out of scope for the <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/bounty-microsoft-azure\">Azure bug bounty<\/a> in August 2023. It\u2019s not like I was expecting a bounty anyway, I\u2019m more old school than that. I\u2019m already happy if I don\u2019t get <a href=\"https:\/\/www.theregister.com\/2016\/10\/14\/ibm_asked_security_researcher_to_pull_exploit_code\/\">sued<\/a> \ud83e\udd37<\/p>\n<p>But I digress. The ease with which I was able to climb the MSRC leaderboard rankings became <strong>an incentive to look deeper<\/strong> into the <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/researcher-recognition-program\">Microsoft Researcher Recognition Program<\/a>. This brought me to <strong>audit the source code of other projects<\/strong> under the <a href=\"https:\/\/github.com\/Azure\/\">Azure organization<\/a> on GitHub.<\/p>\n<h3>Who wants to be an MVR?<\/h3>\n<p>Between January and April 2024, <strong>I reported more than 50 vulnerabilities in 20 Azure products<\/strong>. My research paid off with a substantial bounty and sparked a <a href=\"https:\/\/github.com\/Azure\/azure-osconfig\/commit\/ebcd13188250ffda99966a014cf2e26bbc80a299\">number<\/a> <a href=\"https:\/\/github.com\/Azure\/azure-c-shared-utility\/security\/advisories\/GHSA-m8wp-hc7w-x4xg\">of<\/a> <a href=\"https:\/\/github.com\/Azure\/azure-uamqp-c\/commit\/e02272b01687154d050768747ce41c776c4ddc36\">security<\/a> <a href=\"https:\/\/github.com\/Azure\/azure-iot-sdk-c\/commit\/e2cc0b4de238071f2a185030e32c6c4089e619d3\">improvements<\/a> <a href=\"https:\/\/github.com\/Azure\/azure-uhttp-c\/commit\/a538340f976b8f40542fece8c6c9a9a8461e0974\">in<\/a> <a href=\"https:\/\/github.com\/Azure\/azure-iot-sdk-c\/commit\/f91c1305c80cc548cf907c4a99b7edf07ad0dca2\">the<\/a> <a href=\"https:\/\/github.com\/Azure\/c-util\/commit\/581ab018a2010ae269c698cb1e55f532f916fe7d\">Azure<\/a> <a href=\"https:\/\/github.com\/sonic-net\/sonic-buildimage-msft\/commit\/1e1876a353bf7d4fd1c1e182c5070822c00fda19\">ecosystem<\/a>.<\/p>\n<figure id=\"attachment_5654\" aria-describedby=\"caption-attachment-5654\" style=\"width: 1720px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/msrc-2.png\"><img decoding=\"async\" class=\"wp-image-5654 size-full\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/msrc-2.png\" alt=\"\" width=\"1720\" height=\"1059\" \/><\/a><figcaption id=\"caption-attachment-5654\" class=\"wp-caption-text\">Some of the vulnerabilities I reported to MSRC<\/figcaption><\/figure>\n<p>My vulnerability reporting spree of early 2024 resulted in me being featured at the top of <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/04\/congratulations-to-the-top-msrc-2024-q1-security-researchers\/\">MSRC quarterly leaderboards<\/a> again.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Congrats! Cheers to your ongoing success and contributions to enhancing security. \ud83e\udd42<\/p>\n<p>&mdash; Microsoft Security Response Center (@msftsecresponse) <a href=\"https:\/\/twitter.com\/msftsecresponse\/status\/1780702295782793459?ref_src=twsrc%5Etfw\">April 17, 2024<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>But all good things must come to an end&#8230; After a few disagreements and some frustrating exchanges with MSRC, at the end of April 2024 I gave up and <strong>stopped reporting vulnerabilities to Microsoft<\/strong>. Still, in August 2024 my spare-time hobby was rewarded with the <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/08\/congratulations-to-the-msrc-2024-most-valuable-security-researchers\/\">25th place in the annual<\/a><a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/08\/congratulations-to-the-msrc-2024-most-valuable-security-researchers\/\">\u00a0<\/a><a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/08\/congratulations-to-the-msrc-2024-most-valuable-security-researchers\/\">MVR leaderboard<\/a>! Not too bad for a middle-aged Unix hacker \ud83d\ude1c<\/p>\n<p>Here are a few <strong>stats<\/strong> of the time I dedicated to vulnerability research in that 4-month period:<\/p>\n<ul>\n<li>24 hours spent auditing Azure RTOS \/ Eclipse ThreadX (not including the time dedicated to vulnerability disclosure)<\/li>\n<li>70 hours spent auditing other Azure software (not including the time dedicated to vulnerability disclosure)<\/li>\n<li>14 hours spent auditing other open-source Microsoft software before giving up<\/li>\n<\/ul>\n<p>I recently discovered that another well-known security researcher, <a href=\"https:\/\/x.com\/vv474172261\">VictorV<\/a>, had a <a href=\"https:\/\/v-v.space\/2025\/02\/18\/Azure-bounty-program-research\/\">similar experience<\/a> with the Microsoft Azure bounty program. Probably at least in part due to the sheer volume of our vulnerability reports combined together, <strong>open-source software was eventually declared out of scope<\/strong>. It was good while it lasted&#8230;<\/p>\n<h3>Welcome, hackers<\/h3>\n<p>Fast forward to early 2025, when I received an email from Microsoft with an <strong>exclusive invitation<\/strong> to their first-ever Zero Day Quest event!<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Well\u2026 It looks like I\u2019m going to Redmond! \u2708\ufe0f \ud83c\uddfa\ud83c\uddf8<\/p>\n<p>Many thanks to <a href=\"https:\/\/twitter.com\/msftsecresponse?ref_src=twsrc%5Etfw\">@msftsecresponse<\/a> for the exclusive invitation to their Zero Day Quest Onsite Event. Looking forward to meeting fellow top-notch security researchers from around the world and having fun!<a href=\"https:\/\/t.co\/bTjhp8XhJB\">https:\/\/t.co\/bTjhp8XhJB<\/a> <a href=\"https:\/\/t.co\/tHKDCNfi2w\">pic.twitter.com\/tHKDCNfi2w<\/a><\/p>\n<p>&mdash; raptor (@0xdea) <a href=\"https:\/\/twitter.com\/0xdea\/status\/1887755158194454876?ref_src=twsrc%5Etfw\">February 7, 2025<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>How could I&#8217;ve missed this extraordinary opportunity to <strong>peek behind the scenes<\/strong> of MSRC and <strong>meet fellow top-class security researchers<\/strong> from around the world?<\/p>\n<p>I registered for the event, booked my flights, and April came quickly. I found myself transported into this weird but surprisingly successful <strong>mix of corporate culture and hardcore hacking<\/strong>.<\/p>\n<figure id=\"attachment_5742\" aria-describedby=\"caption-attachment-5742\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-5742 size-large\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_welcome-768x1024.jpg\" alt=\"\" width=\"640\" height=\"853\" \/><figcaption id=\"caption-attachment-5742\" class=\"wp-caption-text\">Let me patch that for you, Clippy!<\/figcaption><\/figure>\n<p>There were attendees of all ages, from every corner of the world. I believe I was <strong>the oldest among the researchers<\/strong>, a full 30 years older than the youngest participant \ud83d\ude31<\/p>\n<figure id=\"attachment_5725\" aria-describedby=\"caption-attachment-5725\" style=\"width: 2560px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-5725 size-full\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1.jpg\" alt=\"\" width=\"2560\" height=\"1382\" srcset=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1.jpg 2560w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1-300x162.jpg 300w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1-1024x553.jpg 1024w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1-768x415.jpg 768w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1-1536x829.jpg 1536w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1-2048x1106.jpg 2048w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_group-scaled-1-350x189.jpg 350w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><figcaption id=\"caption-attachment-5725\" class=\"wp-caption-text\">The Zero Day Quest crew<\/figcaption><\/figure>\n<p>I had so many extraordinary encounters that I can&#8217;t possibly mention them all: from the <strong>17 years old prodigy<\/strong> (see above) who raked in what ought to be the <a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/04\/zero-day-quest-2025-1.6-million-awarded-for-vulnerability-research\/\">highest payout ever awarded<\/a> in an event like this to the music producer from Argentina with a touching life story who sported a <strong>Microsoft tattoo<\/strong>. From <strong>one of the most prolific bug hunters<\/strong> in the history of the Microsoft Researcher Recognition Program to the <strong>wine connoisseur<\/strong> of Ukrainian descent. From the full-time bug hunter who<strong> travels the world<\/strong> to the <strong>paranoid hacker<\/strong> who avoided cameras and had an obviously fake name (I&#8217;m joking, mate \ud83d\ude02). And many more&#8230;<\/p>\n<p>Not to mention Microsoft&#8217;s staff that took good care of us. I believe I made some <strong>real friends<\/strong> there!<\/p>\n<figure id=\"attachment_5729\" aria-describedby=\"caption-attachment-5729\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-5729 size-large\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-1024x1024.jpg\" alt=\"\" width=\"640\" height=\"640\" srcset=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-1024x1024.jpg 1024w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-300x300.jpg 300w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-150x150.jpg 150w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-768x768.jpg 768w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-1536x1536.jpg 1536w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-350x350.jpg 350w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1-348x348.jpg 348w, https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_ms-1.jpg 1800w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><figcaption id=\"caption-attachment-5729\" class=\"wp-caption-text\">Can you spot the odd one?<\/figcaption><\/figure>\n<p>I even got to briefly meet the great <strong>Mark Russinovich<\/strong> of <a href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/\">Sysinternals<\/a> fame \ud83e\udd29<\/p>\n<figure id=\"attachment_5734\" aria-describedby=\"caption-attachment-5734\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-5734 size-large\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_mark-768x1024.jpg\" alt=\"\" width=\"640\" height=\"853\" \/><figcaption id=\"caption-attachment-5734\" class=\"wp-caption-text\">We&#8217;re not worthy!<\/figcaption><\/figure>\n<h3>Old dog, new tricks<\/h3>\n<p>So, for me, the best part of ZDQ was definitely the people I met. A close second was\u00a0the <strong>constant pampering <\/strong>and the <strong>high-quality swag<\/strong>. I seriously risked not being able to close my suitcase when heading back to Italy!<\/p>\n<div class=\"zuzrh71p _1ubsyrw0 zuzrh73f zuzrh739 zuzrh73b zuzrh7b _1ubsyrw1 zuzrh73d zuzrh73h zuzrh73l _1ubsyrw3j _1ubsyrw7d _1ubsyrw7y \">\n<figure id=\"attachment_5738\" aria-describedby=\"caption-attachment-5738\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-5738 size-large\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/zdq_nike-1024x768.jpg\" alt=\"\" width=\"640\" height=\"480\" \/><figcaption id=\"caption-attachment-5738\" class=\"wp-caption-text\">Swag level: master<\/figcaption><\/figure>\n<p>Beside branded clothes and expensive gadgets, we got a full range of benefits, such as a professional <strong>photo shooting<\/strong>, a <strong>massage<\/strong> parlor, a bar stacked with <strong>good coffee and drinks<\/strong> for all tastes, a steady supply of <strong>food<\/strong>, and of course the amazing evening events: a thoroughly American <strong>baseball match<\/strong>, dinner at <strong>one of the best Italian restaurants<\/strong> in the area, a last-minute <strong>city tour<\/strong> of Seattle, and the closing ceremony at the iconic <strong>Space Needle<\/strong>!<\/p>\n<p>There was really a lot to unpack, both physically and metaphorically \ud83d\ude05<\/p>\n<figure id=\"attachment_5749\" aria-describedby=\"caption-attachment-5749\" style=\"width: 2560px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-5749 size-full\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/QuestEvent_Mariners_035-scaled-2.jpeg\" alt=\"\" width=\"2560\" height=\"1707\" \/><figcaption id=\"caption-attachment-5749\" class=\"wp-caption-text\">Tridents up!<\/figcaption><\/figure>\n<\/div>\n<p>What else is there to say? Even though the scope that was picked for the event didn\u2019t particularly agree with my specific talents, I can tell that this old dog has learned a couple of new tricks! It feels good to be <strong>#StillHacking<\/strong> after almost three decades \ud83d\udc36<\/p>\n<h3>The BlueHat Podcast<\/h3>\n<p>After the event, I joined <a href=\"https:\/\/www.linkedin.com\/in\/nicfill\/\" target=\"_blank\" rel=\"noopener\">Nic Fillingham\u2060<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.linkedin.com\/in\/wendyzenone\/\" target=\"_blank\" rel=\"noopener\">\u2060Wendy Zenone\u2060<\/a> in a new episode of Microsoft&#8217;s <a href=\"https:\/\/thecyberwire.com\/podcasts\/the-bluehat-podcast\">BlueHat Podcast<\/a>. You can catch it <a href=\"https:\/\/thecyberwire.com\/podcasts\/the-bluehat-podcast\/52\/notes\">here<\/a>!<\/p>\n<p>I shared <strong>raptor&#8217;s origin story<\/strong>, from <a href=\"https:\/\/www.msx.org\/wiki\/Philips_VG-8020\">my first computer<\/a> and hacking as a teenager to becoming part of the worldwide security research community. We chatted about <strong>my first-ever CVE<\/strong>, overlooked vulnerabilities that continue to pose significant risks today, Active Directory and <strong>password security<\/strong>, my unexpected journey into <strong>bug bounty hunting<\/strong> and my involvement in the Zero Day Quest, how to learn new things, mentorship and <strong>positive leadership<\/strong>, and of course pineapple pizza \ud83c\udf4d\ud83c\udf55<\/p>\n<figure id=\"attachment_5640\" aria-describedby=\"caption-attachment-5640\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/msx03-scaled-2.jpg\"><img decoding=\"async\" class=\"wp-image-5640 size-large\" src=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/04\/msx03-1024x768.jpg\" alt=\"\" width=\"640\" height=\"480\" \/><\/a><figcaption id=\"caption-attachment-5640\" class=\"wp-caption-text\">This is how you make a hacker<\/figcaption><\/figure>\n<p>It&#8217;s been truly special, thank you for having me! \ud83e\udef6<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;If you shame attack research, you misjudge its contribution. Offense and defense aren&#8217;t peers. Defense is offense&#8217;s child.&#8221; &#8212; John [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":159967,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[76,81,91],"tags":[226,227,553,82,117,123,223,224,225],"class_list":["post-5512","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-events","category-vulnerabilities","category-articles","tag-mvr","tag-zero-day-quest","tag-cloud","tag-vulnerability-research","tag-code-review","tag-microsoft","tag-azure","tag-bluehat","tag-bug-bounty"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HN Security - My Zero Day Quest &amp; BlueHat Podcast -<\/title>\n<meta name=\"description\" content=\"Our technical director Marco Ivaldi describes his experience at the first-ever Zero Day Quest event and at the BlueHat Podcast.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HN Security - My Zero Day Quest &amp; BlueHat Podcast -\" \/>\n<meta property=\"og:description\" content=\"Our technical director Marco Ivaldi describes his experience at the first-ever Zero Day Quest event and at the BlueHat Podcast.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/\" \/>\n<meta property=\"og:site_name\" content=\"HN Security\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-06T06:18:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-11T09:54:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"836\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Marco Ivaldi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@hnsec\" \/>\n<meta name=\"twitter:site\" content=\"@hnsec\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"Marco Ivaldi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/\"},\"author\":{\"name\":\"Marco Ivaldi\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#\\\/schema\\\/person\\\/89a4174c275f05d6148fb0fdedc8de4f\"},\"headline\":\"My Zero Day Quest &#038; BlueHat Podcast\",\"datePublished\":\"2025-05-06T06:18:40+00:00\",\"dateModified\":\"2026-03-11T09:54:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/\"},\"wordCount\":1381,\"publisher\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hnsecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ZERODAY.jpg\",\"keywords\":[\"mvr\",\"zero day quest\",\"cloud\",\"vulnerability research\",\"code review\",\"microsoft\",\"azure\",\"bluehat\",\"bug bounty\"],\"articleSection\":[\"Events\",\"Vulnerabilities\",\"Articles\"],\"inLanguage\":\"it-IT\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/\",\"url\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/\",\"name\":\"HN Security - My Zero Day Quest & BlueHat Podcast -\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hnsecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ZERODAY.jpg\",\"datePublished\":\"2025-05-06T06:18:40+00:00\",\"dateModified\":\"2026-03-11T09:54:56+00:00\",\"description\":\"Our technical director Marco Ivaldi describes his experience at the first-ever Zero Day Quest event and at the BlueHat Podcast.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#primaryimage\",\"url\":\"https:\\\/\\\/hnsecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ZERODAY.jpg\",\"contentUrl\":\"https:\\\/\\\/hnsecurity.it\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/ZERODAY.jpg\",\"width\":1600,\"height\":836,\"caption\":\"ZeroDay logo\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/my-zero-day-quest-bluehat-podcast\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"My Zero Day Quest &#038; BlueHat Podcast\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#website\",\"url\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/\",\"name\":\"HN Security\",\"description\":\"Offensive Security Specialists\",\"publisher\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#organization\",\"name\":\"HN Security\",\"url\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/hnsecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/hn-libellula.jpg\",\"contentUrl\":\"https:\\\/\\\/hnsecurity.it\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/hn-libellula.jpg\",\"width\":696,\"height\":696,\"caption\":\"HN Security\"},\"image\":{\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/hnsec\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hnsecurity\\\/\",\"https:\\\/\\\/github.com\\\/hnsecurity\",\"https:\\\/\\\/infosec.exchange\\\/@hnsec\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/#\\\/schema\\\/person\\\/89a4174c275f05d6148fb0fdedc8de4f\",\"name\":\"Marco Ivaldi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a8a96db06e7315a061d28b320ee7bb4c9d0f1535c58bf0f54218bf8a7569bea0?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a8a96db06e7315a061d28b320ee7bb4c9d0f1535c58bf0f54218bf8a7569bea0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a8a96db06e7315a061d28b320ee7bb4c9d0f1535c58bf0f54218bf8a7569bea0?s=96&d=mm&r=g\",\"caption\":\"Marco Ivaldi\"},\"url\":\"https:\\\/\\\/hnsecurity.it\\\/it\\\/blog\\\/author\\\/marco-ivaldi\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HN Security - My Zero Day Quest & BlueHat Podcast -","description":"Our technical director Marco Ivaldi describes his experience at the first-ever Zero Day Quest event and at the BlueHat Podcast.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/","og_locale":"it_IT","og_type":"article","og_title":"HN Security - My Zero Day Quest & BlueHat Podcast -","og_description":"Our technical director Marco Ivaldi describes his experience at the first-ever Zero Day Quest event and at the BlueHat Podcast.","og_url":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/","og_site_name":"HN Security","article_published_time":"2025-05-06T06:18:40+00:00","article_modified_time":"2026-03-11T09:54:56+00:00","og_image":[{"width":1600,"height":836,"url":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg","type":"image\/jpeg"}],"author":"Marco Ivaldi","twitter_card":"summary_large_image","twitter_creator":"@hnsec","twitter_site":"@hnsec","twitter_misc":{"Scritto da":"Marco Ivaldi","Tempo di lettura stimato":"8 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#article","isPartOf":{"@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/"},"author":{"name":"Marco Ivaldi","@id":"https:\/\/hnsecurity.it\/it\/#\/schema\/person\/89a4174c275f05d6148fb0fdedc8de4f"},"headline":"My Zero Day Quest &#038; BlueHat Podcast","datePublished":"2025-05-06T06:18:40+00:00","dateModified":"2026-03-11T09:54:56+00:00","mainEntityOfPage":{"@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/"},"wordCount":1381,"publisher":{"@id":"https:\/\/hnsecurity.it\/it\/#organization"},"image":{"@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#primaryimage"},"thumbnailUrl":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg","keywords":["mvr","zero day quest","cloud","vulnerability research","code review","microsoft","azure","bluehat","bug bounty"],"articleSection":["Events","Vulnerabilities","Articles"],"inLanguage":"it-IT"},{"@type":"WebPage","@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/","url":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/","name":"HN Security - My Zero Day Quest & BlueHat Podcast -","isPartOf":{"@id":"https:\/\/hnsecurity.it\/it\/#website"},"primaryImageOfPage":{"@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#primaryimage"},"image":{"@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#primaryimage"},"thumbnailUrl":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg","datePublished":"2025-05-06T06:18:40+00:00","dateModified":"2026-03-11T09:54:56+00:00","description":"Our technical director Marco Ivaldi describes his experience at the first-ever Zero Day Quest event and at the BlueHat Podcast.","breadcrumb":{"@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#primaryimage","url":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg","contentUrl":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg","width":1600,"height":836,"caption":"ZeroDay logo"},{"@type":"BreadcrumbList","@id":"https:\/\/hnsecurity.it\/it\/blog\/my-zero-day-quest-bluehat-podcast\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/hnsecurity.it\/it\/"},{"@type":"ListItem","position":2,"name":"My Zero Day Quest &#038; BlueHat Podcast"}]},{"@type":"WebSite","@id":"https:\/\/hnsecurity.it\/it\/#website","url":"https:\/\/hnsecurity.it\/it\/","name":"HN Security","description":"Offensive Security Specialists","publisher":{"@id":"https:\/\/hnsecurity.it\/it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/hnsecurity.it\/it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Organization","@id":"https:\/\/hnsecurity.it\/it\/#organization","name":"HN Security","url":"https:\/\/hnsecurity.it\/it\/","logo":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/hnsecurity.it\/it\/#\/schema\/logo\/image\/","url":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2026\/01\/hn-libellula.jpg","contentUrl":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2026\/01\/hn-libellula.jpg","width":696,"height":696,"caption":"HN Security"},"image":{"@id":"https:\/\/hnsecurity.it\/it\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/hnsec","https:\/\/www.linkedin.com\/company\/hnsecurity\/","https:\/\/github.com\/hnsecurity","https:\/\/infosec.exchange\/@hnsec"]},{"@type":"Person","@id":"https:\/\/hnsecurity.it\/it\/#\/schema\/person\/89a4174c275f05d6148fb0fdedc8de4f","name":"Marco Ivaldi","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/secure.gravatar.com\/avatar\/a8a96db06e7315a061d28b320ee7bb4c9d0f1535c58bf0f54218bf8a7569bea0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a8a96db06e7315a061d28b320ee7bb4c9d0f1535c58bf0f54218bf8a7569bea0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a8a96db06e7315a061d28b320ee7bb4c9d0f1535c58bf0f54218bf8a7569bea0?s=96&d=mm&r=g","caption":"Marco Ivaldi"},"url":"https:\/\/hnsecurity.it\/it\/blog\/author\/marco-ivaldi\/"}]}},"jetpack_featured_media_url":"https:\/\/hnsecurity.it\/wp-content\/uploads\/2025\/09\/ZERODAY.jpg","_links":{"self":[{"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/posts\/5512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/comments?post=5512"}],"version-history":[{"count":7,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/posts\/5512\/revisions"}],"predecessor-version":[{"id":161440,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/posts\/5512\/revisions\/161440"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/media\/159967"}],"wp:attachment":[{"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/media?parent=5512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/categories?post=5512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hnsecurity.it\/it\/wp-json\/wp\/v2\/tags?post=5512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}