From CVEs to Bounties + iOS Security on macOS

Aug 27, 8:00 – 10:00 AM (UTC)

Australia HackerOne Club

Educational Workshops

About this event!

Join us for an evening of security research, bug bounty hunting, and iOS security.

📅 27 August 2026
6:00 PM – 8:00 PM
📍 Room 401, UNSW CBD

Talk 1: Turning CVEs to Bounties by Animesh Acharya

Last year, I collaborated with Marcio to identify SimpleSAMLphp deployments affected by CVE-2024-52596, a pre-authentication XXE vulnerability. The collaboration began after Marcio reverse-engineered the exploit, and I started searching private bug bounty programmes I had access to for potentially vulnerable instances. As I began finding vulnerable instances across a surprisingly large number of hosts, I focused on making the process repeatable and scalable. This involved building automation to discover and test SimpleSAMLphp endpoints, including installations using non-default paths. After exhausting the targets we could identify ourselves, we extended the collaboration to other researchers that specialised in automation, and uncovered even more affected deployments. Using this experience as a case study, I will briefly explain the original vulnerability, the techniques we used to locate non-standard installations, and the open-source tooling we adapted to automate discovery across large numbers of bug bounty assets. I will also share lessons from improving detection, how different programmes assessed the impact of the findings, and what I now do differently to try obtain full impact. Finally, I will present GHSA-fqrg-5gph-5pf8, a new vulnerability I (claude ofc) recently identified in SimpleSAMLphp that bypassed the fix for the original issue.

Talk 2: Unlocking iOS on macOS: A Security Researcher’s Guide by James Young

James will explore the restrictions around running iOS apps on Apple Silicon Macs, the macOS internals behind them, and how researchers can better use macOS for iOS application security research.

Come along for two technical talks and a chance to connect with the security community!

Facilitator

  • Swaroop Yermalkar

    Cybersecurity Specialist

When

When

Thursday, August 27, 2026
8:00 AM – 10:00 AM (UTC)

Organizer

  • Swaroop Yermalkar

    swaroopy

Contact Us