Niels Teusink
Niels Teusink is a Principal IT Security Expert at Eye Security, bringing over 20 years of hands‑on technical cybersecurity experience to the stage. His background spans red teaming, incident response, and SOC operations, and he previously spent years performing high‑impact penetration tests for governments, banks, and critical infrastructure. Though he now focuses on the blue side of cybersecurity, Niels remains passionate about offensive techniques and attacker tradecraft.
Session
PopCorn Time was once one of the most popular BitTorrent streaming clients in the world. While the software has been abandoned for years, one of the forked versions (Time4Popcorn) has an update mechanism that never stopped running. During routine threat hunting, we discovered that millions of systems worldwide still have the updater process running in the background, connecting to domains that were no longer registered.
Intrigued, we registered one of these domains and were shocked to discover the number of requests that started pouring in every second. Over several months, we observed millions of unique hardware IDs across various platforms.
After taking a closer look at the closed-source updater binaries, we confirmed the worst: the update mechanism is horribly insecure. Anyone who registered the right domain could instantly compromise millions of machines, including systems on government, military, and corporate networks. This vulnerability was assigned CVE-2026-30612.
Since taking over all domains was not viable, we were faced with an unprecedented decision: do nothing and leave millions at risk or take matters into our own hands. Join our talk to find out what we did and why.