Uploaded March 2026 | Updated September 2026, 1 week ago
Learn more by visiting our website: ioactive.com
IOActive Senior Security Consultant Nick Dunn presented 'Reviewing COBOL for Fun and Profit' for our hack::soho that took place in November 2025. The abstract of the talk is below!
hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.
ABSTRACT
Despite their dull reputation, mainframe systems offer fun-filled potential for security and sometimes have surprising levels of vulnerability considering the amounts of money being moved around. Also, using a terminal with green text on a black background will impress your friends. This talk is being presented as despite their frequently predicted demise, mainframes are still here. This means that COBOL is also still here (despite similar predictions).
The talk covers the overlooked concept of COBOL code security reviews to compensate for a lack of publicly available information. For added amusement it also discusses how supposedly secure systems are sometimes more vulnerable than appreciated once a few basic things are understood.
Learn more by visiting our website: ioactive.com
IOActive Senior Security Consultant Nick Dunn presented 'Reviewing COBOL for Fun and Profit' for our hack::soho that took place in November 2025. The abstract of the talk is below!
hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.
ABSTRACT
Despite their dull reputation, mainframe systems offer fun-filled potential for security and sometimes have surprising levels of vulnerability considering the amounts of money being moved around. Also, using a terminal with green text on a black background will impress your friends. This talk is being presented as despite their frequently predicted demise, mainframes are still here. This means that COBOL is also still here (despite similar predictions).
The talk covers the overlooked concept of COBOL code security reviews to compensate for a lack of publicly available information. For added amusement it also discusses how supposedly secure systems are sometimes more vulnerable than appreciated once a few basic things are understood.










