Between Two Vulns
Popular topics
# Between Two Vulns
# AI/ML Security
# Beginner Content
# Community
# Huntr Spotlight
# Bug Bounty Tips
# LLMs
# Model File Vulnerability
# AI News
# Remote Code Execution
# AI Model File Formats
# AI Agents
# MLflow
# Server-Side Request Forgery
# Model Format Vulnerability
# Beginner's Guide
# Web Security
# Arbitrary File Overwrite
# Hugging Face
# ChuanhuChatGPT
Video
Between Two Vulns: Secrets in Triton's Inference Server and MLFlow
Join our favorite resident hackers, Dan and Marcello, as they dissect the latest vulnerabilities highlighted in Protect AI's January Vulnerability Report. Discovered by our elite community of huntrs, this month's findings are on FIRE. 🔥
# Between Two Vulns
# MLflow
# Arbitrary File Overwrite


Dan McInerney & Marcello Salvati · Apr 11th, 2024
Comment
8:06
Video
Between Two Vulns: Exploring Bugs in Hugging Face and Practical Vulnerabilities
Join Dan and Marcello in episode 2 of Between Two Vulns as they dissect the latest vulnerabilities featured in Protect AI's February Vulnerability Report. This month, our dedicated huntrs showcased their expertise by uncovering intriguing vulnerabilities within Hugging Face, ML Flow, and more. 🔍 🔥
# Between Two Vulns
# MLflow
# Hugging Face


Marcello Salvati & Dan McInerney · Apr 11th, 2024
Comment
10:40
Video
Between Two Vulns: Breaking Down March's Critical LLM Exploits
Welcome back to Between Two Vulns! In this episode, Dan and Marcello dive into the vulnerabilities highlighted in Protect AI's March Vulnerability Report. This month, they've got their sights set on vulnerabilities in applications handling LLMs, all thanks to the kickass submissions from our huntr community.
# Between Two Vulns
# LLMs


Dan McInerney & Marcello Salvati · Apr 11th, 2024
Comment
13:18
Video
Between Two Vulns: Inside Protect AI's Biggest Monthly Vulnerability Report Yet!
The fact that we're covering 48 vulnerabilities this month is insane. Seriously, our community has been on fire, relentlessly submitting bugs on huntr. From remote code execution in PyTorch Serve to server-side template injections in BerriAI/litellm, we're covering it all.
# Between Two Vulns


Marcello Salvati & Dan McInerney · Jun 11th, 2024
Comment
12:52
Video
Between Two Vulns: RSA Special - Fun Times and Critical Vulnerabilities
Welcome to a wild RSA edition of "Between Two Vulns"!
Join Dan and Marcello for a laugh-filled episode as they share their RSA Conference experiences and unpack critical vulnerabilities from Protect AI's May Vulnerability Report. We’re diving into a Remote Code Execution vulnerability in mintplex-labs/anything-llm and a Command Injection vulnerability in 'run_xtts_api_server' in parisneo/lollms-webui this episode.
# Between Two Vulns


Marcello Salvati & Dan McInerney · Jun 11th, 2024
Comment
7:01
Video
Between Two Vulns: Live Hacking This Month's Top Bugs!
Join the dynamic duo, Dan and Marcello, as they not only discuss the latest vulnerabilities from Protect AI's June Vulnerability Report but also guide you through replicating them live on huntr.com. This month, we're introducing exclusive segments designed to enhance your hacking skills like never before.
# Between Two Vulns
# Beginner Content


Marcello Salvati & Dan McInerney · Jul 3rd, 2024
Comment
19:15
Video
Between Two Vulns: LFI in lollms Exposed and More!
🔥 Get ready, huntrs! 🔥 Dive into the July edition of "Between Two Vulns" with our dynamic duo, Dan and Marcello. This month, they're tearing into Protect AI's latest Vulnerability Report, exposing some pretty gnarly vulns. As you can clearly tell by our thumbnail, we're not messing around this month.
# Between Two Vulns
# AI/ML Security
# Bug Bounty Tips
# LLMs


Marcello Salvati & Dan McInerney · Jul 24th, 2024
Comment
8:35
Video
Between Two Vulns: What Happens at Black Hat... Ends Up Here!
Get ready for the Black Hat Las Vegas edition of "Between Two Vulns," where Dan and Marcello, armed with nothing but sarcasm and some questionable life choices, tackle Protect AI's August Vulnerability Report.
# Between Two Vulns


Marcello Salvati & Dan McInerney · Sep 3rd, 2024
Comment
9:45
Video
Between Two Vulns: AI Security Headlines You Can’t Ignore + Meet Our New Threat Researcher
In Episode 9 of Between Two Vulns, Dan and Marcello mix things up with a fresh new segment where Dan breaks down the top 3 things happening in AI and how they tie into AI security. Plus, we’re excited to introduce Ethan Silvas, our newest threat researcher at huntr!
# Between Two Vulns
# AI/ML Security


Marcello Salvati & Dan McInerney · Oct 1st, 2024
Comment
12:59
Video
Between Two Vulns: RCEs, File Path Traversals, Drunk Chatbots – Oh My!
Between Two Vulns is BACK with your favorite hacker trio! Dan and Marcello dive into OpenAI Dev Day—coding with Canvas, “drunk” chatbots, and some spooky AI questions. Meanwhile, Ethan’s dropping insights from Protect AI’s October Vulnerability Report: RCEs, file path traversals, and more. If you’re here for AI hot takes, hacker humor, and a fresh vulnerability breakdown, you’re in the right spot.
# Between Two Vulns
# Beginner Content
# Bug Bounty Tips


Marcello Salvati & Dan McInerney · Oct 31st, 2024
Comment
13:38
Video
Between Two Vulns: $3k Bounties?! The Rise of Model File Vulnerabilities
# Between Two Vulns
# Model Format Vulnerability
# Model File Vulnerability
# Beginner Content


Dan McInerney & Marcello Salvati · Dec 2nd, 2024
Comment
19:08
Video
Between Two Vulns: OpenAI Drama, Quantum Multiverses, and Model Vulnerability Hunting
2024’s been a wild ride y'all, and we’re breaking it all down in this Between Two Vulns finale:
💥 OpenAI drops a $200/month GPT Pro plan—worth it or a cash grab?
💥 Anthropic tries to standardize agents with their Model Context Protocol.
💥 Google’s quantum chip solves problems that would take septillion years (and maybe proves the multiverse is real).
Then Ethan walks us through exploiting Keras Lambda vulnerabilities, and we close with shoutouts to the huntrs who crushed it this year. 🏆
# Between Two Vulns
# AI/ML Security
# AI Model File Formats


Dan McInerney & Marcello Salvati · Jan 9th, 2025
Comment
16:02
Video
Between Two Vulns: Prompt Injection, GPT-03, and the Future of AI Agents
Kicking off 2025, Dan and Marcello cover the latest in AI security:
🔹 NVIDIA’s Project Digits: A $3K supercomputer for running LLMs locally and securely.
🔹 OpenAI GPT-03: The model beating human performance on Arc AGI.
🔹 AI agents: Will 2025 be the year they replace employees?
🔹 Prompt injection: Why it’s still the #1 LLM security risk.
# Between Two Vulns
# Prompt Injection
# AI Agents
# AI News


Dan McInerney & Marcello Salvati · Jan 28th, 2025
Comment
10:54
Video
Between Two Vulns: AI Bots, Quantum Chips & The Future of Hacking
Hunker down, hackers—AI benchmarks just broke another record, quantum computing chips are threatening your GPU’s existence, and rumor has it Arnold might make a comeback (we kid, we kid). In this episode, Dan and Marcello dissect how AI is evolving faster than we can say “prompt injection.” Then Ethan steps in with a killer breakdown of Model File Vulnerabilities (MFVs) on huntr—perfect for those of you itching to exploit the next big bounty target.
# Between Two Vulns
# Model File Vulnerability
# AI News
# Beginner Content
# Bug Bounty Tips



Dan McInerney, Marcello Salvati & Ethan Silvas · Mar 4th, 2025
Comment
14:59
