Explore every episode of the podcast Three Buddy Problem
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Valentina Palmiotti (chompie) on Vulnpocalypse, Matching Mythos on a Budget | 07 Oct 2026 | 01:08:31 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Offensive AI Con: Live from OAIC, IBM X-Force's Valentina Palmiotti (chompie) walks us through the autonomous Windows kernel exploit pipeline she built on older Claude models, which landed within a hair of Mythos for about $180 a chain. Plus, the Pwn2Own bug Claude called unexploitable, why her Pwn2Own bugs still sit unpatched, disappearing exploit techniques, the dread of being a defender, and how Phrack found its way back into print. Timestamps: | |||
| Why is Anthropic Afraid of GLM 5.3? | 02 Oct 2026 | 02:33:46 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 115: We into Anthropic's Frontier Red Team fear-mongering on Zhipu's open-weight GLM 5.3 model and wonder why the AI labs' cyber programs do so little for defenders. Plus, Citrix NetScaler zero-days, a new iOS zero-day tied to WhatsApp, AI agents that act on your behalf, and whether security teams should buy DGX Sparks to run models locally. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Kernel Exploits in the iOS App Store, ShinyHunters Inside the FBI | 25 Sep 2026 | 02:16:03 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 114: We dig into TypeSafe AI's Jev and the new class of System One models, a new Transluce report on rogue OpenAI agents probing an Australian Medicare portal, Irregular's role in the latest Gemini test breakout, Hacktron's takeover of OpenAI employee accounts and the messy disclosure fight that followed, and what Costin would fix first as OpenAI's CISO for a day. Plus, the soaring price of DGX Sparks and home AI rigs, the White House pressing labs to hold models back from the UK AI Security Institute, Anthropic bringing in Accenture as an evaluator, the FomoPeek App Store app hiding iOS kernel exploits, ShinyHunters' claimed FBI breach, and Nightmare Eclipse going public with identity and a CrowdStrike exploit. Cast: Ryan Naraine, Juan Andres Guerrero-Saade and Costin Raiu. Timestamps: | |||
| AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit | 11 Sep 2026 | 02:37:12 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 113: On the show this week, the buddies dig into an Anthropic researcher quitting with a warning that AI could kill us all, the San Francisco "death cult" and their motives, and agent swarms leaving junk on public wikis and university URL shorteners. Plus, a high-quality Anthropic's threat report and the claim that Moonshot was quietly serving Claude tokens as Kimi K3, live MikroTik and Chrome zero-days that landed a day ahead of the patches, and a WeChat worm that hijacks an account via phone calls. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs. | 04 Sep 2026 | 02:07:23 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 112: The 'OpenAI hacks Hugging Face' fallout has turned into a story about AI civilizations rising from the ashes, politicians calling for super-intelligence bans, and the emergence of well-funding non-profits doing AI safety work. Who are these people and what's their security expertise? Plus, GPT-6 Astra lands in a trusted-access program nobody can get into, Costin ranks the local models he runs next to his desk, and CrowdStrike sinkholes a botnet that's been alive since 2003. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| A Thousand Agents Walk Into Hugging Face | 28 Aug 2026 | 02:27:25 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 111: OpenAI finally published a technical Hugging Face post-mortem, and Costin's verdict is blunt. He reads it as a document written for policymakers rather than for the blue teams who have to survive a thousand-agent swarm. We also dig into NVIDIA's $12.9 billion acquisition of Hugging Face, why JAGS thinks a frontier lab standing against open-source looks weak, and what that new industry open letter on cyber defense actually asks anyone to do. Plus, hotel Wi-Fi tradecraft after CaptiveCrunch, the FBI's ORB network takedown with Lumen, Chinese routers that ship backdoored from the factory, and the TeamPCP arrests in Australia. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure | 21 Aug 2026 | 02:11:08 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 110: We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup running sandboxes for OpenAI, Anthropic and Meta, drones over Romania's gas platforms, OpenAI's two-week training pause, and T-Mobile taking scissors to a cable during Salt Typhoon incident response. Stick around for a UFO segment that somehow involves Dr. Phil. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| A tiny 12 KB Windows backdoor, one victim, and a dead domain | 17 Aug 2026 | 02:23:31 | |
(Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.) Three Buddy Problem - Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this. Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance. Cast: Costin Raiu, Ryan Naraine and Juan Andres Guerrero-Saade Timestamps: | |||
| Inside OpenAI's Black Hat Confession | 08 Aug 2026 | 02:14:10 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 108: OpenAI got on the Black Hat stage and walked through how its own agent swarm hacked Hugging Face. We discuss and struggle to decide whether to clap or panic. Plus, why only the attacker can do forensics now, frontier models being built as cyber-weapons on purpose, APT29's "Dark Hotel" comeback in luxury hotels, China's swipe at Palo Alto, the Iran-water-system FUD, and an eye-opening Liechtenstein money-laundering hack. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats | 31 Jul 2026 | 03:26:39 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise | 28 Jul 2026 | 00:34:38 | |
Security Conversations: Kenneth Kinion, founder and CEO of Validin, joins Ryan Naraine on the show to unpack what "internet intelligence" really means for the analysts and responders chasing malicious infrastructure. We trace his path from Georgia Tech through Microsoft and Amazon to the frustrations that led to the creation of Validin, the competition from big AI, the value of AI-powered tools to speed up infrastructure hunting, and why defenders keep falling further behind fast-moving attackers. Timestamps: | |||
| OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16 | 23 Jul 2026 | 02:16:03 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 106: We dig into the news that OpenAI's models were the "autonomous agent" that breached Hugging Face, escaping a sandbox through a zero-day to cheat on a cyber benchmark, then getting spun into a partnership announcement. We argue about the implications of the incident, the PR masterclass, the absence of ethics and human oversight, and calls for "kill switches" to mitigate "AI lab leaks." Plus, SentinelLabs' new fast16 reverse-engineering benchmark, where GPT-5.6 Sol was the only public model to go the distance. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Hugging Face Just Got Hit by the First Fully Autonomous AI Attack | 18 Jul 2026 | 02:07:29 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen | 04 Jul 2026 | 01:36:03 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| US Gov Takes the Wheel: Who Gets to Use the Best AI? | 29 Jun 2026 | 01:53:54 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 103: We dive into the U.S. government's takeover of frontier-model rollouts (Mythos, Fable, and OpenAI's Sol/Terra/Luna) and what it means when intelligence gets commoditized but access gets rationed. Plus, Costin's all-Chinese open-weight stack, the economics of burning tokens, a fresh Salesforce OAuth breach, and jellyfish UFOs over Iran. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Katie Moussouris on the Anthropic Export-Control Mess | 19 Jun 2026 | 01:38:24 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 102: Software export controls expert Katie Moussouris joins the show to unpack the US government's abrupt move to suspend access to Anthropic's most powerful models over a so-called "jailbreak" that, on reading the paper, turned out to be a model doing exactly what defenders are supposed to do. We dig into the export-control chaos, the chemical-weapons framing of cybersecurity, the China question, and why Microsoft just resurrected a disclosure term the industry buried fifteen years ago. Cast: Katie Moussouris, Juan Andres Guerrero-Saade and Ryan Naraine. Costin is traveling. Timestamps: | |||
| Mythos, Fable, and Anthropic's Big Trust Problem | 12 Jun 2026 | 01:59:10 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 101: We discuss Anthropic's Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users' results, sparking a heated debate over guardrails, gatekeeping, and whether elite AI reasoning is becoming a privilege for the few. Plus, AI-generated N-day exploits killing the patch window, a record-shattering Patch Tuesday, Meta's latest court filing against spyware maker NSO Group, the return of cyber paleontology, and a detour into the new government UFO drops. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux | 05 Jun 2026 | 02:24:29 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay in cybersecurity. Plus, more on Anthropic's Mythos rollout and the thinly sourced Anthropic-NSA reports, the Fast16 sabotage of physics calculations, what researchers choose not to publish, Microsoft's bad Black Hat email, and Costin's Friday UFO files. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited | 30 May 2026 | 01:59:45 | |
(Presented by Ent.ai: Ent delivers intent-aware security that protects every action, adapts to every workflow, and works for every user. Enterprise threat detection, reimagined.) Three Buddy Problem - Episode 99: Microsoft is now threatening legal action against researchers who drop zero-days. We debate whether it's a fair line against extortion, or amateur-hour PR from a company that already torched its own research community? Costin plays reluctant defender, JAGS says the damage was done years ago, and Ryan reopens the long history of silent fixes and stolen bounties. Plus, on the 10th anniversary of the Shadow Brokers leak, we discuss some enduring mysteries, theories on attribution and an interesting trail that leads to Edward Snowden. We also unpack Rob Joyce's warning that China's cyber explosives are already planted in US infrastructure, and the Pope's warnings about around artificial intelligence. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense | 27 May 2026 | 00:40:09 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Aaron Portnoy (Zero Day Initiative alum, early Pwn2Own organizer, and now at Mindgard) joins us at Ekoparty Miami to reminisce on the early days of the hacking contest, where vulnerabilities actually live (the boundaries between systems, not inside them), why LLMs will take out the trash but can't dream up the next speculative-execution-class bug, and the coming patching apocalypse when discovery 10x's overnight. Plus, why your SOC is a forensic historian, the promise of hijacking an attacker's reward loop with deception tech, and the legendary story of carrying a Walmart "fat stack" of cash to bootstrap Ekoparty in Buenos Aires. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Aaron Portnoy. Timestamps: | |||
| Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code | 26 May 2026 | 00:40:27 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential. We get into why verifiers and proof engines are the key to effective AI, why vulnerability research is so far ahead of threat intel, and the case for baking security checks directly into code generation tools like Claude Code and Codex. Plus, designing a multi-million dollar challenge that's allowed to fail, the Mythos "too dangerous to release" debate, and musings on every LLM-discovered bug being a public bug by default. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Perri Adams. Timestamps: | |||
| Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap | 26 May 2026 | 00:49:37 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Gabriel Bernadett-Shapiro. Timestamps: | |||
| Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing | 25 May 2026 | 00:58:02 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Federico Kirschbaum, founder of Ekoparty and now head of Security Lab at XBOW, talks about what happens to offensive security when an autonomous AI hacker can find and exploit real vulnerabilities. Fede walks through XBOW's "Tales from the Trace," the surreal experience of watching a non-human adversary reason its way to an ASLR bypass, and why he believes pen-testing isn't dying but finally becoming accessible to far more than the world's biggest companies. Plus, where humans still matter in the loop, whether an LLM-discovered bug is public by definition, the looming reckoning over software liability, and Halvar Flake's very honest fear of getting lazy. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Federico Kirschbaum. Timestamps: | |||
| Jordan Wiens on AI, Offense vs. Defense, and the Dying CTF Pipeline | 24 May 2026 | 00:44:17 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Jordan Wiens, co-founder of Vector 35 and creator of Binary Ninja, talks about a decade spent building a decompiler in a market everyone told him not to enter. He walks through why accessibility drove the whole project, how Binja's intermediate-language system stacks up against IDA, Ghidra, and Radare, and why language-specific decompilation for Rust, C++, and Go is the next real frontier. Plus, thoughts on AI disruption and why "the model can do it" misses the point that the model is just driving the tool, what verifiability really means, whether AI tilts the field toward offense or defense, and questions around subsidized tokens, the collapse of the CTF talent pipeline, and what happens to a craft when the shortcut is always one prompt away. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Jordan Wiens. Timestamps: | |||
| The AI-powered 10x patch tsunami has arrived. Now what? | 15 May 2026 | 01:50:38 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 98: We dive back into the fast16 malware discovery with fresh speculation that it's targeting spherical implosion simulations for Iran's nuclear program, and wonder who on earth is qualified to confirm this. Plus, thoughts on OpenAI's new three-tier cyber access program, Microsoft's MDASH harness, the 10x Patch Tuesday tsunami, Cloudflare's 1,100 layoffs blamed on AI, and why frontier-lab guardrails may just be elaborate security theater. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| The disappointing death of big-game APT reporting | 10 May 2026 | 02:02:30 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 97: We discuss the disappearing art of Windows APT paleontology, the absence of complex malware documentation, and why so much threat-intel research has slipped behind paywalls and into private rooms. Plus, a surge in AI-discovered bugs in Firefox and Chrome, a rough week for Linux security flaw disclosures, and the usual Ivanti and Palo Alto zero-day bulletins that ship without a single IOC. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| Cracking the Fast16 sabotage malware mystery | 01 May 2026 | 01:47:54 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 96: We're joined by WIRED writer Andy Greenberg to dig into SentinelLabs' bombshell FAST16 research, a newly deciphered piece of sabotage malware that predates Stuxnet by five years and quietly tampered with physics modeling software likely tied to Iran's nuclear program. We discuss the attribution rabbit hole (NSA? Israel? someone else?), the eerie "spiritual warfare" implications of corrupting scientific calculations, and Antiy Labs' very dialectical Chinese rebuttal. Plus, what AI reverse-engineering means for the next decade of cyber paleontology. Cast: Andy Greenberg, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - WIRED’s Andy Greenberg joins the show | |||
| Mark Dowd on AI hacking, exploit chains, zero-day sales | 24 Apr 2026 | 02:02:18 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 95: Vigilant Labs director Mark Dowd joins the show to shed light on the state of offensive research, the economics of the exploit market, and why "Mark Dowd in a box" isn't quite the threat the AI hype machine suggests. He talks through the daily stresses of running an offensive shop, how AI is reshaping vulnerability discovery, exploit development, and the pricing of full exploit chains. Plus, thoughts on Lockdown Mode and Apple's MIE, whether mitigations actually work or just push attackers toward less access, the rise of HarmonyOS and the Balkanization of device security, persistence, baseband attacks, GrapheneOS, and Samsung Knox. We discuss customer vetting and OpSec fears, policymakers who've never written an exploit, and the strange afterlife of The Art of Software Security Assessment, the 20-year-old book now possibly training data for the very tools coming for his job. Cast: Mark Dowd, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| The Angry Spark APT Mystery: A Year-Long Backdoor, One Victim, Zero Attribution | 18 Apr 2026 | 02:35:23 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 94: We discuss a mysterious, VM-obfuscated backdoor that lived undetected on a single U.K. machine for a year before disappearing, finding clues pointing to an elite-level APT intrusion that still evades broader industry coverage. Plus, connecting the dots across AI-driven vulnerability discovery, Microsoft’s massive Patch Tuesday, Jensen Huang talks cybersecurity, Mythos dangers and Chinese chips, and the quiet erosion of CVE enrichment at NIST. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: | |||
| The Claude Mythos, Project Glasswing Shockwave | 10 Apr 2026 | 02:34:36 | |
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 93: We discuss Anthropic's release of Claude Mythos Preview (an AI model so capable and dangerous they won't release it publicly) and debate the looming patching crisis, bug bounty extinction, possible US government nationalization of frontier labs, and why the NSA might not be thrilled about all this bug-fixing. Plus, North Korea's six-month Drift Protocol con job, APT28's retro DNS hijacking campaign, and Microsoft's driver signing mess hitting WireGuard and VeraCrypt. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 00:00 — Opening banter | |||
| LLMs writing exploits, engineers losing skills, and a case for the generative OS | 03 Apr 2026 | 02:19:56 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 92: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 0:00 – Introductory banter | |||
| Jeremy Banon: Personal Exec Compromise as Corporate Incident | 01 Apr 2026 | 00:36:27 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Security Conversations: Jeremy Bannon, founder/CEO of The Cyber Health Company, joins Ryan Naraine to discuss why executive personal cybersecurity is a growing blind spot for organizations, and real-world incidents where personal compromises became corporate crises. Plus, why CISOs struggle to secure the C-suite's personal lives, and how a healthcare-inspired model (complete with risk scores, care plans, and concierge support) can help companies close the gap. 0:00 — Introduction to The Cyber Health Company | |||
| Google's Cyber Disruption Unit; Coruna is Triangulation, US Bans Foreign-Made Routers | 28 Mar 2026 | 02:32:24 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 91: This week we dig into Google's new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines. Plus, VCs and the breathless AI hype, Apple's iOS 26.4 and silent patches, the FCC's ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 0:00 Intro & Pre-Show Banter | |||
| The greatest APT hunter of all time, Apple's exploit kit problem, Microsoft FedRAMP mess | 20 Mar 2026 | 02:27:20 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 90: We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple's responsibility to hundreds of millions of users on older iOS versions; the ProPublica Microsoft/FedRAMP bombshell, Interlock ransomware sitting on a Cisco zero-day, the White House AI policy framework, and Supermicro co-founder $2.5 billion AI chip smuggling bust. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Handala wiper attacks, APT28 implant devs are back, Signal's verification problems | 14 Mar 2026 | 01:44:00 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 89: We discuss Iran hacktivist group 'Handala' wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran's cyber retaliation is as scary as the headlines suggest. Plus, ESET's discovery that Russia's APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit's proliferation chain. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Trenchant, Peter Williams, and the proliferation of a Shadow Brokers-level iOS exploit framework | 06 Mar 2026 | 01:59:43 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 88: We unpack the fallout from public documentation of the Coruna iOS exploit kit, the likely connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use, and the widening use of zero-days by surveillance vendors and cybercriminals. Plus, fresh signs of cyber-warfare activity tied to Iran and Israel, the FBI’s disclosure of a breach affecting internal surveillance systems, and the latest debate over AI, security tooling, and Anthropic’s public stumbles. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery | 05 Mar 2026 | 00:39:04 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Matthias Frielingsdorf (co-founder and VP of Research at iVerify) joins the show to discuss the mysterious US government connection to 'Coruna', an iOS exploit kit fitted with 23 exploits across five full chains targeting iPhones iOS 13 through 17.2.1. We talk about a "gut feeling" connecting this to the L3 Trenchant/Peter Williams exploit sale scandal, how a nation-state-grade exploit kit ended up in the hands of a Chinese cybercrime group chasing crypto wallets, and what it means that criminal organizations are now deploying iPhone zero-days at scale. Matthias walks through what iVerify can and can't do on Apple's locked-down platform, why he thinks Apple needs to give defenders more access, the Lockdown Mode debate, the thorny issue of sample sharing in the research community, and practical advice for everyday iPhone users facing a threat landscape that just got a lot more complicated. | |||
| Threat Hunter Greg Linares on the modern ransomware playbook | 03 Mar 2026 | 00:49:48 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Huntress threat intelligence analyst Greg Linares shares insights on the modern ransomware ecosystem, including how crews operate like businesses and why Akira, Medusa, RansomHub, and Qilin cause so much damage. Plus, signs of overlap between ransomware and nation-state activity, what “time to ransom” really means for defenders, and why techniques like ClickFix and credential theft keep working at scale. The conversation also covers the surge in RMM tool abuse, how “living off the land” attacks can unfold without traditional malware, and the basic defenses smaller organizations can prioritize. | |||
| War in Iran, Anthropic v Pentagon, Trenchant zero-day sanctions, AI stock market shocks | 28 Feb 2026 | 02:08:22 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 87: We wake up to news of U.S./Israel military action against Iran and the expected fallout, including Tehran’s cyber capabilities and proxy risks. Plus: Anthropic’s clash with the Pentagon over AI use in warfare, market shockwaves from AI-driven security tools, mass layoffs tied to automation, Trenchant exec sentencing and sanctions in the exploit trade, and fresh questions around Cisco’s SD-WAN breach and supply-chain trust. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| GitLab doxxes North Korea .gov hackers; fresh Ivanti zero-days; AI addiction and human purpose | 20 Feb 2026 | 02:16:39 | |
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 86: We dig into GitLab’s explosive look at North Korea’s “Contagious Interview” APT operation, the scale of fake IT worker infiltration, and what it means for companies chasing cheap talent. Plus, a fresh batch of already-exploited Ivanti and Dell zero-days, the return of Apple’s shutdown logs, and thoughts on addictive AI coding agents affecting human purpose. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Palo Alto and the uncomfortable politics of APT attribution | 13 Feb 2026 | 02:30:30 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 85: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft’s zero-day treadmill and AI-enabled attack surfaces; and Apple’s “extremely sophisticated” iOS exploits. Plus, Europe’s growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks | 08 Feb 2026 | 02:17:38 | |
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 84: We process the cybersecurity fallout from the latest Epstein document dump, focusing on why redactions fail in the AI era and how quickly modern tools can unravel them. The conversation moves from sloppy redaction practices and exploit mythology to harder questions about ethics, accountability, and silence within the infosec community. Plus, inside the Notepad++ supply-chain compromise attributed to a known Chinese APT, Microsoft’s security executive changes, Anthropic's AI-driven vulnerability discovery, China-linked network implants, and Lockdown Mode thwarting FBI investigators. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| A destructive cyberattack in Poland raises NATO 'red-line' questions | 30 Jan 2026 | 02:53:22 | |
(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 83: Poland's CERT documents a rare, explicit wiper attack on civilians in a NATO country, including detailed attribution of a Russian government op targeting the electric grid in the heart of winter. We examine why this crosses a long-avoided threshold, why attribution suddenly matters again, and what it says about pre-positioned access, vendor insecurity, and the shrinking gap between cyber operations and acts of war. Plus, another Fortinet fiasco, a new batch of Ivanti zero-days under attack, an emergency patch from Microsoft and the return of the mysterious KasperSekrets account. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware | 23 Jan 2026 | 02:09:06 | |
(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 82: We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA's new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland's electricity sector. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cybersecurity software | 16 Jan 2026 | 02:24:36 | |
(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 81: We dissect New York Times reporting on the "precision" of US cyber operations in Venezuela, the competing narratives around offensive cyber capabilities and "letters of marque" for private hackers. Plus, a mysterious failed cyber attack on Poland's power grid, internet blackouts in Iran (with fascinating DNS telemetry revealing Chinese bank traffic and Russian website spikes), and news of China's ban on US/Israeli cybersecurity software. We also cover Check Point's research on "VoidLink" (is it a successor to ShadowPad?), Microsoft's threat intelligence sharing practices, and Google Project Zero's disclosure of zero-click vulnerabilities caused by AI-powered transcription features. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Hamid Kashfi on the situation in Iran; Did cyber cause Venezuela blackouts? | 09 Jan 2026 | 02:13:55 | |
(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 80: Researcher Hamid Kashfi returns to unpack Iran’s latest unrest, separating economic reality from propaganda while examining how information control, cyber pressure, and state surveillance are shaping events on the ground. Plus, did cyber make the lights go out in Venezuela? Cast: Hamid Kashfi, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| A special mailbag episode with book recommendations | 02 Jan 2026 | 03:01:15 | |
(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 79: We cover MongoBleed (CVE‑2025‑14847), exposed MongoDB deployments, and the sad realization that zero-day attacks are a normal, everyday occurrence. Plus, AI’s expanding role and misuse across products and workflows, proximity attacks against Bluetooth audio devices, spyware sanctions de-listings, and ransomware economics. In a special mailbag segment, we give our book recommendations and respond to common questions from the listeners. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Quiet Wins, Loud Failures: A Year-End Cybersecurity Reckoning | 26 Dec 2025 | 03:19:04 | |
(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.) Three Buddy Problem - Episode 78: We close out the year with a no-budget, no-permission awards show, spotlighting the cybersecurity stories that actually mattered. Plus, a bizarre polygraph scandal at CISA, Chinese APT research dumps, ransomware pre-notification hiccups, foreign drone bans, and the growing gap between cyber theater and real operational value. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| What's behind US gov push to 'privatize' offensive cyber operations? | 20 Dec 2025 | 02:01:57 | |
(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.) Three Buddy Problem - Episode 77: New React2Shell data from Microsoft, fresh Apple and Cisco zero-days already in the wild, and state-linked campaigns from Russia and China that show a merging of espionage, crime, and infrastructure disruption. Plus, the US government's push to enlist private firms in offensive hacking, letters of marque for cartels, new discovery of spyware used against journalists in Belarus, and Amazon catching North Koreans via keystroke latency. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||
| Legal corruption, React2Shell exploitation, dual-use AI risks | 11 Dec 2025 | 02:12:25 | |
(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.) Three Buddy Problem - Episode 76: On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups. Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. | |||