Three Buddy Problem
Security Conversations
0
The Three Buddy Problem is a Security Conversations podcast that goes beyond industry talking points to discuss nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros — journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade — the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
Episodet
-
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16 23.07.2026 2h 16min(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 106: We dig into the news that OpenAI's models were the "autonomous agent" that breached Hugging Face, escaping a sandbox through a zero-day to cheat on a cyber benchmark, then getting spun into a partnership announcement. We argue about the implications of the incident, the PR masterclass, the absence of ethics and human oversight, and calls for "kill switches" to mitigate "AI lab leaks." Plus, SentinelLabs' new fast16 reverse-engineering benchmark, where GPT-5.6 Sol was the only public model to go the distance. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 5:24 OpenAI admits it was the Hugging Face "hacker" 10:06 What’s ExploitGym and who's on top of the leaderboard 12:59 Reward hacking: Did anyone train this thing not to cheat? 19:35 Marketing stunt or real incident? The zero-day in the package proxy 26:43 Was OpenAI already plugged into Hugging Face? 29:17 Paperclips, kill switches, and "going rogue" 34:49 Crisis comms, regulatory capture, and the second Cold War 43:02 Approve every action? Auto mode and swarms 50:10 "Lab leak" and calls for biosafety levels 1:00:31 The missing models: no Mythos, no Kimi, no independent referee 1:07:04 Costin's prediction: owning frontier-class hardware will require a license 1:13:41 fast16 as a benchmark: Inside the Sol Searching research 1:26:51 Compression and altitude: are reverse engineers being replaced? 1:41:24 Finding the gem in 100 samples, and the swarm frontier 2:00:41 Claude Opus 5 drops, Gemini 3.5 Flash CyberLinks:Transcript Sam Altman: "We had a significant security incident" OpenAI and Hugging Face partner to address security incident during model evaluation ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? US politicians float 'AI Kill Switch' US lawmakers push for AI 'kill switch' after OpenAI models go rogue OpenAI Daybreak Jensen Huang debuts on X Jensen Huang: Open Weights and American AI Leadership Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis? fast16 — IDA Databases and Analysis Artifacts Kimi K3 - API Platform Introducing Gemini 3.5 Flash Cyber NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Proofpoint: TA488 Targets Zimbra Mailservers with Half-Click Exploits CISA: Iran Cyber Actors Exploit PLCs Across US Critical Infrastructure Iran War Cyber Threat Landscape - A Midyear Assessment Thinkst Canary -
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack 18.07.2026 2h 7min(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outsLinks:Transcript Thinkst Canary Huggingface security incident disclosure White House Launches Gold Eagle Initiative for Vulnerability Coordination Trump admin unveils AI-supported clearinghouse for vulnerabilities YouTube: Xi Jinping speaks at world AI conference Microsoft Patch Tuesday by the numbers Rival Espionage Actors Converge On Pakistani Police Daxin Returns: Stealthy Malware Resurfaces in Taiwan GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets Paradigm Shift - Introducing usbliter8 LABScon 2026 TLPBLACK -
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen 04.07.2026 1h 36min(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from SeoulLinks:Transcript Redeploying Claude Fable 5 (Anthropic) Howard Lutnick on Anthropic export controls OpenAI proposes handing Trump administration 5% stake DOJ: Alleged Member of “Scattered Spider” Extradited to USA Full DOJ complaint on Scattered Spider arrest HBO Max -- Q: Into the Storm Q Into the Storm LABScon 2026 Thinkst Canary -
US Gov Takes the Wheel: Who Gets to Use the Best AI? 29.06.2026 1h 53min(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 103: We dive into the U.S. government's takeover of frontier-model rollouts (Mythos, Fable, and OpenAI's Sol/Terra/Luna) and what it means when intelligence gets commoditized but access gets rationed. Plus, Costin's all-Chinese open-weight stack, the economics of burning tokens, a fresh Salesforce OAuth breach, and jellyfish UFOs over Iran. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 — Introductory banter, Thinkst Canary sponsorship 2:55 — Why threat intel analysts are built for the AI moment 11:09 — Government takes the wheel: Mythos, Fable & the frontier labs 16:15 — Did the government go too far/not far enough? 25:42 — Anthropic's "best PR campaign in history" 31:52 — Alibaba, distillation & the model-router cartel 40:58 — Costin's stack: Chinese open-weight models & token economics 46:12 — Dumping, evals & the real work of AI engineering 1:04:32 — Soft power: how the world gets pushed toward China 1:14:43 — "The bullshit": over-refusal & the Opus 4.8 regression 1:32:03 — The trillion-dollar IPO endgame 1:35:49 — The Klue OAuth breach and secure-by-default 1:45:32 — Shout-outs: UAP jellyfish, LABScon 2026Links:Transcript Thinkst Canary Anthropic accuses Chinese rival Alibaba of illicitly extracting AI capabilities USG Executive Order on Promoting AI Innovation US allows Anthropic to release Mythos AI to 'trusted' US orgs US close to allowing Anthropic to restore Fable 5 model OpenAI: Previewing GPT-5.6 Sol NCSC on AI shift in cyber risk DeepSeek Alibaba Qwen NVIDIA DGX Spark StepFun Open AI Platform Xiaomi MiMo-V2.5 Z.ai - powered by GLM-5.2 Five Eyes Cyber Security Agencies Statement on AI Klue Security Incident Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims OAuth2 - OWASP Cheat Sheet Series OAuth 2.0 Policies (Google for Developers) Downed US pilot reported seeing Iranian drones swarm in ‘jellyfish’ formation LABScon 2026 -
Katie Moussouris on the Anthropic Export-Control Mess 19.06.2026 1h 38min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 102: Software export controls expert Katie Moussouris joins the show to unpack the US government's abrupt move to suspend access to Anthropic's most powerful models over a so-called "jailbreak" that, on reading the paper, turned out to be a model doing exactly what defenders are supposed to do. We dig into the export-control chaos, the chemical-weapons framing of cybersecurity, the China question, and why Microsoft just resurrected a disclosure term the industry buried fifteen years ago. Cast: Katie Moussouris, Juan Andres Guerrero-Saade and Ryan Naraine. Costin is traveling. Timestamps: 0:00 - Introductory banter 1:00 - Export Controls: Fable 5 and Mythos 5 suspended 3:40 - The Anthropic–USG relationship and USG’s surveillance claim 9:40 - Self-owns, doomsday cults, and why the guardrails are "so broad" 12:42 - What the Amazon paper actually says ("fix this code") 20:33 - The chemical-weapons framing problem 23:39 - The China question and the SK Telecom angle 41:17 - Why hasn't the paper been published? 57:01 - "Free Fable": are Chinese models only months behind? 1:00:13 - The unforgiving internet and the security poverty line 1:11:18 - Microsoft brings back "responsible disclosure" (and threatens researchers) 1:29:04 - Luta Security, the AI bug flood, and shout-outsLinks:Transcript Katie Moussouris | LinkedIn JAGS on NPR: Can computer hackers get inside your mind? Anthropic Statement on the USG Export Controls Moussouris: Fable 5 Export Controls Harm US Cyber Defense Anthropic's Fable Backlash (David Sacks podcast) AI imaging company Midjourney tackles MRI scanning Microsoft Threatens Vuln Researchers Microsoft blog on CVD and POC publications TLPBLACK LABScon CFP Luta Security -
Mythos, Fable, and Anthropic's Big Trust Problem 12.06.2026 1h 59min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 101: We discuss Anthropic's Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users' results, sparking a heated debate over guardrails, gatekeeping, and whether elite AI reasoning is becoming a privilege for the few. Plus, AI-generated N-day exploits killing the patch window, a record-shattering Patch Tuesday, Meta's latest court filing against spyware maker NSO Group, the return of cyber paleontology, and a detour into the new government UFO drops. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 3:22 - The Mythos 5 / Claude Fable 5 release 14:42 - Anthropic’s silent downgrade trust problem 26:18 - Anti-competitive behavior & the AV "stealing detection" parallel 32:29 - Distillation, China & the real motive 38:04 - "Too dangerous to release" & gatekeeping vs. guardrailing 45:53 - Is Mythos a threat to malware-analysis startups? 48:20 - Dario's AI regulation essay 56:48 - N-day exploits and death of the patch window 1:07:18 - Patch Tuesday and 10x vulnerability surge 1:10:34 - Meta catches NSO Group 1:14:45 - Cyber paleontology, Shadow Brokers leaks 1:28:29 - Moonlight Maze and learning from history 1:34:22 - UFOs, UAPs and Disclosure Day Links:Transcript SemiAnalysis: Anthropic's latest model silently degrades its IQ Researchers Are Furious Over Anthropic's Hidden AI Limits Anthropic Walks Back Policy That Could Have ‘Sabotaged’ AI Researchers Anthropic: Claude Fable 5 and Claude Mythos 5 System Card: Claude Fable 5 & Claude Mythos 5 Socket: Mini Shai-Hulud, Miasma, and Hades Worms Dario Amodei: Policy on the AI Exponential Patch Tuesday (Adobe/Microsoft) WhatsApp catches NSO Group spear phishing Department of War Publishes Third Release of Unidentified Anomalous Phenomena Files Pentagon releases 3rd batch of UFO files, detailing mysterious orb sightings Orbs over a pond (UFO video) fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet Penquin's Moonlit Maze LABScon Call for Papers -
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux 05.06.2026 2h 24min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay in cybersecurity. Plus, more on Anthropic's Mythos rollout and the thinly sourced Anthropic-NSA reports, the Fast16 sabotage of physics calculations, what researchers choose not to publish, Microsoft's bad Black Hat email, and Costin's Friday UFO files. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - JAGS at InfoSecurity Europe 3:40 - Sponsor: TLPBLACK 5:54 - A roadmap for security after the AI revolution 11:01 - Stripe Atlas and how easy it is to start a company 15:00 - If anyone could reverse engineer anything for $5 19:49 - Layoffs at Google's Threat Intelligence Group 21:06 - The death of reading the report 27:53 - Pitting the AI models against each other 32:07 - Grok, local models, and the DGX Spark 39:27 - Where is Google DeepMind? 45:29 - Will the frontier labs stay in cybersecurity? 52:41 - Mythos, Project Glasswing, and the NSA deal 1:16:33 - FAST16, Stuxnet, and sabotaging Iran's bomb 1:57:52 - Microsoft, Black Hat, and the chilling effect 2:14:14 - Shout-outs, UFO files, and 100 episodes Links:Transcript NSA using Anthropic's Mythos despite blacklist Anthropic: Mapping a year’s worth of AI-enabled cyber threats LLM ATT&CK Navigator (Anthropic) Ruben Santamarta on Fast16 sabotage malware A Fanny Equation: “I am your father, Stuxnet” TLPBLACK LABScon Call for Papers Disclosure Day | Official Teaser Disclosure Day -
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited 30.05.2026 1h 59min(Presented by Ent.ai: Ent delivers intent-aware security that protects every action, adapts to every workflow, and works for every user. Enterprise threat detection, reimagined.) Three Buddy Problem - Episode 99: Microsoft is now threatening legal action against researchers who drop zero-days. We debate whether it's a fair line against extortion, or amateur-hour PR from a company that already torched its own research community? Costin plays reluctant defender, JAGS says the damage was done years ago, and Ryan reopens the long history of silent fixes and stolen bounties. Plus, on the 10th anniversary of the Shadow Brokers leak, we discuss some enduring mysteries, theories on attribution and an interesting trail that leads to Edward Snowden. We also unpack Rob Joyce's warning that China's cyber explosives are already planted in US infrastructure, and the Pope's warnings about around artificial intelligence. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 2:03 - The Pope's AI paper 3:35 - New sponsor: Brandon Dixon's Ent Security 9:34 - Costin's Chinese-model OSINT rabbit hole 13:34 - Codex, GPT-5.5, and the "American AI welfare state" 23:20 - Microsoft threatens vulnerability researchers 27:06 - Is it extortion or retribution? The disclosure fight 40:48 - How Microsoft's consultant class broke MSRC and MSTIC 48:42 - Silent fixes, stolen bounties, and the marketing machine 1:02:29 - Ten years of the Shadow Brokers 1:14:20 - The Snowden theory 1:32:34 - Rob Joyce: China's cyber explosives are in place 1:53:26 - Shout-outs Links:Transcript MSRC threat against security researchers Nightmare Eclipse Dennis Fisher: The Past is Always Present in Vulnerability Disclosure Introducing Claude Opus 4.8 Stolen Device Protection for iPhone Rob Joyce: China’s Cyber Explosives are in Place. Where’s our Response? China AI Security Testing Contest Brandon Dixon parses the AI security hype Ent -- Intent-Aware Security for the Enterprise Ent on LinkedIn -
Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense 27.05.2026 40min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Aaron Portnoy (Zero Day Initiative alum, early Pwn2Own organizer, and now at Mindgard) joins us at Ekoparty Miami to reminisce on the early days of the hacking contest, where vulnerabilities actually live (the boundaries between systems, not inside them), why LLMs will take out the trash but can't dream up the next speculative-execution-class bug, and the coming patching apocalypse when discovery 10x's overnight. Plus, why your SOC is a forensic historian, the promise of hijacking an attacker's reward loop with deception tech, and the legendary story of carrying a Walmart "fat stack" of cash to bootstrap Ekoparty in Buenos Aires. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Aaron Portnoy. Timestamps: 0:00 — Introductory banter 1:17 — Dropping out, iDefense, and getting good at reversing everything 2:19 — How Pwn2Own got started 4:15 — The most impressive Pwn2Own ever: Nils, VUPEN, and exploit "art" 5:59 — "iPhone hacked in 30 seconds" — and the 18 months behind it 6:41 — Does Pwn2Own still have a place in the AI era? 9:16 — Why LLMs take out the trash but can't invent the next bug class 12:48 — Will LLMs deliver new mitigation classes? Aaron's skeptical 18:34 — The place of the human when the easy bugs run dry 21:08 — Cognitive offloading, Halvar's warning, and skill rot 22:39 — Decompiling 800k functions: Aaron's LLM "holy shit" moment 25:26 — The patching apocalypse and why "assume breach" breaks 28:15 — Compounding asymmetries: why offense just transcended defenseLinks:Transcript Aaron Portnoy | LinkedIn Mindgard - Automated AI Red Teaming Pwn2Own Ekoparty Miami Nils2Own: 'I want to see security flaws fixed' VUPEN Charlie Miller on hacking iPhones, Macbooks, Cars LABScon 2026 TLPBLACK -
Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code 26.05.2026 40min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential. We get into why verifiers and proof engines are the key to effective AI, why vulnerability research is so far ahead of threat intel, and the case for baking security checks directly into code generation tools like Claude Code and Codex. Plus, designing a multi-million dollar challenge that's allowed to fail, the Mythos "too dangerous to release" debate, and musings on every LLM-discovered bug being a public bug by default. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Perri Adams. Timestamps: 0:00 — Introductory banter 1:09 — Why LLMs just made formal methods relevant again 4:03 — Proof engines, explained 8:43 — Can a layman grab this fire? The calculus problem 11:58 — Vuln researchers are scrappy kids with a trust fund 14:55 — Pitching AIxCC inside DARPA: hard sell or easy sell? 18:00 — Designing a challenge that's allowed to fail 22:06 — Inside Team Atlanta's 150-page winning system 24:00 — Why this is bigger for defense than for offense 31:49 — Mythos, safeguards, and "every LLM bug is a public bug"Links:Transcript Perri Adams (@perribus) / X DARPA AIxCC - AI Cyber Challenge AIxCC Final Competition Winners Announcement Team Atlanta (AIxCC) Team Atlanta AIxCC Research Publications and Source Code DARPA's Perri Adams on CTF hacking, new $20M AI Cyber Challenge Microsoft MDASH OffensiveCon25 Keynote (Perri Adams) Binary Analysis: An AI Success Story TLPBLACK LABScon 2026 -
Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap 26.05.2026 49min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Gabriel Bernadett-Shapiro. Timestamps: 0:00 Introductory banter 4:55 Gabe returns: how the models got scary-good at code 8:45 Bay Area short-termism and the "10x in 18 months" trap 11:35 VCs as tastemakers, and why that's broken 13:00 The unpaid-labor pipeline into the AI labs 18:00 The real misunderstanding about security's moat 20:18 Bug bounties: a net negative for the industry? 22:20 The great vuln fire sale — find 50,000, fix zero 27:28 Who will maintain vetted open-source libraries? 29:29 FAST 16: how AI actually broke the case open 35:05 The rabbit-holing machine and the path to "AI psychosis" 41:05 Stuxnet, Kim Zetter, and the story we'll never be toldLinks:Transcript fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests AI & LLMs for Automation & Intel with Gabriel Bernadett-Shapiro SentinelLabs Security use-cases for AI chain-of-thought reasoning Daniel Miessler - A Conversation with Gabe Bernadett-Shapiro on AI Gabriel Bernadett-Shapiro on X TLPBLACK Ekoparty Miami -
Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing 25.05.2026 58min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Federico Kirschbaum, founder of Ekoparty and now head of Security Lab at XBOW, talks about what happens to offensive security when an autonomous AI hacker can find and exploit real vulnerabilities. Fede walks through XBOW's "Tales from the Trace," the surreal experience of watching a non-human adversary reason its way to an ASLR bypass, and why he believes pen-testing isn't dying but finally becoming accessible to far more than the world's biggest companies. Plus, where humans still matter in the loop, whether an LLM-discovered bug is public by definition, the looming reckoning over software liability, and Halvar Flake's very honest fear of getting lazy. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Federico Kirschbaum. Timestamps: 0:00 Fede's move to XBOW 2:20 What's XBOW building? An AI hacker for real vulnerabilities 5:53 Where the human stays in the loop 6:35 The Exim bug: a craftsman races the LLM to an ASLR bypass 10:49 Does bug discovery still need a human asking the right question? 16:24 A short history: Satan, CORE, Metasploit, bug bounties 18:48 An LLM-discovered bug is public by definition 24:12 Halvar Flake's laziness worry & the assembly-to-C parallel 29:47 Rising tides: script kiddies get the full gamut 41:02 The economics: does pentesting get cheap? 43:18 Argentina, Ekoparty, and an untapped talent pipelineLinks:Transcript Federico Kirschbaum on a life in the Argentina hacking scene Federico Kirschbaum on LinkedIn Federico Kirschbaum XBOW | Autonomous Offensive Security Platform Mythos for Offensive Security: XBOW's Evaluation Tales from the Trace: How Agentic AI Merges Static and Dynamic Testing Ekoparty Miami TLPBLACK -
Jordan Wiens on AI, Offense vs. Defense, and the Dying CTF Pipeline 24.05.2026 44min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Jordan Wiens, co-founder of Vector 35 and creator of Binary Ninja, talks about a decade spent building a decompiler in a market everyone told him not to enter. He walks through why accessibility drove the whole project, how Binja's intermediate-language system stacks up against IDA, Ghidra, and Radare, and why language-specific decompilation for Rust, C++, and Go is the next real frontier. Plus, thoughts on AI disruption and why "the model can do it" misses the point that the model is just driving the tool, what verifiability really means, whether AI tilts the field toward offense or defense, and questions around subsidized tokens, the collapse of the CTF talent pipeline, and what happens to a craft when the shortcut is always one prompt away. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Jordan Wiens. Timestamps: 0:00 Introductory banter 1:22 Vector 35 and the origin of Binary Ninja 2:32 From CTFs and SCIFs to building a decompiler 3:27 Before Ghidra: when an IDA license was out of reach 9:47 Language-specific decompilation: Rust, C++, and Go 12:47 Running a 17-person bootstrapped shop with no org chart 13:50 DARPA money, In-Q-Tel, and staying independent 15:23 AI as disruptor: the model drives the tool 18:06 Verifiability and the Fast16 reversing story 25:10 How AI actually gets used inside the company 28:52 Frontier models and guardrails 33:30 Will AI favor offense or defense? 40:51 Shrinking CTF talent pipelinesLinks:Transcript Jordan Wiens on LinkedIn Jordan Wiens (@psifertex) Vector 35 Binary Ninja Ghidra Releases AI x CC (AI Cyber Challenge) Ekoparty Miami TLPBLACK -
The AI-powered 10x patch tsunami has arrived. Now what? 15.05.2026 1h 50min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 98: We dive back into the fast16 malware discovery with fresh speculation that it's targeting spherical implosion simulations for Iran's nuclear program, and wonder who on earth is qualified to confirm this. Plus, thoughts on OpenAI's new three-tier cyber access program, Microsoft's MDASH harness, the 10x Patch Tuesday tsunami, Cloudflare's 1,100 layoffs blamed on AI, and why frontier-lab guardrails may just be elaborate security theater. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 3:19 - fast16 update: spherical implosion simulations? 9:01 - Manhattan Project precedent — why this matches Iran 12:28 - Who can actually reproduce the FAST 16 attack? 19:32 - Google GTIG's "AI-written" zero-day 22:13 - The rise of AI-backend "silent detections" 25:54 - Guardrails as security theater 38:47 - Are the 10x patch numbers real defense? 43:48 - OpenAI's Trusted Access tiers + Microsoft MDASH 53:35 - End of the ‘patch-and-pray’ model 57:50 - Sean Heelan: strict harnesses can make models worse 1:03:51 - Pwn2Own Berlin overflow and bug-density debate 1:12:24 - Cloudflare's 1,100 layoffs and AI as scapegoat 1:27:42 - RCS encryption, Android Intrusion Logging, Seedworm & KazuarLinks:Transcript fast16 malware targeting spherical implosion simulations fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet Cracking the Fast16 sabotage malware mystery GTIG on AI Exploit Generation Discovery iOS 26.5 Security Bulletin End-to-end encrypted RCS messaging hits beta Android adds 'Intrusion Logging' feature Google: Log your Android device activity Microsoft MDASH new multi-model agentic security system Daybreak | OpenAI for cybersecurity Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker Kazuar: Anatomy of a nation-state botnet (Microsoft) Ekoparty Miami LABScon 2026 TLPBLACK -
The disappointing death of big-game APT reporting 10.05.2026 2h 2min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 97: We discuss the disappearing art of Windows APT paleontology, the absence of complex malware documentation, and why so much threat-intel research has slipped behind paywalls and into private rooms. Plus, a surge in AI-discovered bugs in Firefox and Chrome, a rough week for Linux security flaw disclosures, and the usual Ivanti and Palo Alto zero-day bulletins that ship without a single IOC. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 1:17 - Inside TLP-Red: writing hashes by hand 3:57- fast16 fallout and the threat intel trust collapse 9:17 - The death of cyber paleontology on Windows 14:49 - Mobile is the new paleontology frontier 15:48 - When threat intel went private: the CrowdStrike effect 23:29 - Falling sideways into intelligence brokerage 36:05 -- AI, Easter eggs, and the loss of malware artistry 47:22 -- Will the Frontier Labs publish threat intel? 51:43 -- fast16 follow-up reports coming 1:09:38 - Mythos, Aardvark, and the patch tsunami 1:15:33 - CopyFail and the Linux reboot crisis 1:51:05 - UAPs, Pulitzers, last-ever LabsCon, and shoutoutsLinks:Transcript Where Have All the Complex Windows Malware and Their Analyses Gone? AcidBox: Rare Malware Repurposing Turla Group Exploit Google Chrome security update documentation Behind the Scenes Hardening Firefox with Mythos CVE-2026-0073 Android adbd TLS client-authentication bypass Urgent patch for Android zero-click vuln CVE-2026-0300: PAN-OS zero-day exploited in the wild Ivanti zero-day marked as exploited in the wild Copy Fail — CVE-2026-31431 Yael Grauer wins a Pulitzer Prize AJ Vicens wins a Pulitzer Prize Pacific Rim – Darknet Diaries Fast16, Stuxnet, and the History of Cyber Espionage TLPBLACK LABScon 2026 CFP US Gov on UAP Encounters -
Cracking the Fast16 sabotage malware mystery 01.05.2026 1h 47min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 96: We're joined by WIRED writer Andy Greenberg to dig into SentinelLabs' bombshell FAST16 research, a newly deciphered piece of sabotage malware that predates Stuxnet by five years and quietly tampered with physics modeling software likely tied to Iran's nuclear program. We discuss the attribution rabbit hole (NSA? Israel? someone else?), the eerie "spiritual warfare" implications of corrupting scientific calculations, and Antiy Labs' very dialectical Chinese rebuttal. Plus, what AI reverse-engineering means for the next decade of cyber paleontology. Cast: Andy Greenberg, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - WIRED’s Andy Greenberg joins the show 1:53 - How the FAST16 scoop landed in Andy's lap 6:45 - JAGS sat on this sample for 7 years 10:33 - How Costin and the Kaspersky team missed the sabotage routine 15:20 - The "holy moly" moment: what FAST16 actually does 18:26 - Territorial Dispute, Shadow Brokers, and the driver list 24:11 - The targets: MOHID, PKPM, and LS-DYNA's link to Iran 28:13 - No C&C, no victims: a worm built for air-gapped networks 34:45 - Was this part of a larger anti-Iran toolkit? 37:55 - Attribution: NSA, Israel, or someone else entirely? 51:39 - What was the actual sabotage? Unanswered questions 55:48 - "Spiritual warfare": the psychological angle and trust in computers 1:20:05 - Equities, going public, and the case for AI-powered reversing 1:32:19 - Antiy Labs' Chinese rebuttal and the apparatchik tone 1:43:04 - Shoutouts: Sergey Mineev, LabsCon CFP, PivotCon, and EkopartyLinks:Transcript fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet Flame: A complex malware for targeted attacks Territorial Dispute – NSA's perspective on APT landscape Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program - and Predates Stuxnet Kim Zetter's Countdown to Zero Day An Unprecedented Look at Stuxnet, the World's First Digital Weapon The Flame: Questions and Answers (Kaspersky) SentinelLabs Andy Greenberg on X TLPBLACK Antiy Labs: “Psychological Warfare” to Show Off Cyber Capabilities Who’s Really Spreading through the Bright Star? LABScon 2026 CFP Ekoparty Miami 2026 (Agenda) PIVOTcon Agenda Decipher: Fast16, Stuxnet, and the History of Cyber Espionage -
Mark Dowd on AI hacking, exploit chains, zero-day sales 24.04.2026 2h 2min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 95: Vigilant Labs director Mark Dowd joins the show to shed light on the state of offensive research, the economics of the exploit market, and why "Mark Dowd in a box" isn't quite the threat the AI hype machine suggests. He talks through the daily stresses of running an offensive shop, how AI is reshaping vulnerability discovery, exploit development, and the pricing of full exploit chains. Plus, thoughts on Lockdown Mode and Apple's MIE, whether mitigations actually work or just push attackers toward less access, the rise of HarmonyOS and the Balkanization of device security, persistence, baseband attacks, GrapheneOS, and Samsung Knox. We discuss customer vetting and OpSec fears, policymakers who've never written an exploit, and the strange afterlife of The Art of Software Security Assessment, the 20-year-old book now possibly training data for the very tools coming for his job. Cast: Mark Dowd, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductions 4:28 The origin story of Azimuth: why go offensive? 6:26 Stresses of running an offensive research business 12:10 "Mark Dowd in a box" — is AI an existential threat to vuln research? 16:13 Using AI in workflow: frontier models vs. local models 22:05 AI in bug-finding vs. exploit implementation 30:30 Watching AI tear through a firmware backdoor 38:23 Artificial guardrails and the "POC" wall 43:25 Will AI commoditize 0days? The high-end vs. low-end vendor split 57:30 How AI disrupts exploit chain pricing 1:05:18 Does persistence still matter? Should you reboot your phone? 1:09:33 Lockdown Mode, MIE, and Apple's "never been compromised" claim 1:14:25 Do mitigations really work, or are we stuck in an endless loop? 1:23:25 Android vs. iOS vs. Huawei's HarmonyOS Next 1:34:44 Exploit leaks, customer vetting, and OpSec fears 1:41:37 GrapheneOS, Samsung Knox and baseband attacks 1:53:56 Did the exploit market save us from encryption backdoors? 1:55:11 What does the threat-intel community get wrong about vuln research? Links:Transcript Vigilant Labs Mark Dowd at BlueHat: Inside the Zero Day Market The Art of Software Security Assessment [Book] Mark Dowd on X Trenchant, Peter Williams, and the proliferation of a Shadow Brokers-level iOS exploit framework Apple: Memory Integrity Enforcement Cost of Sandboxing Prompts Shift to Memory-Safe Languages Dowd: Memory Corruption Mitigations Doing Their Job TLPBLACK LABScon 2026 Call for Papers Apple paying big bounty for wireless proximity-based attacks -
The Angry Spark APT Mystery: A Year-Long Backdoor, One Victim, Zero Attribution 18.04.2026 2h 35min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 94: We discuss a mysterious, VM-obfuscated backdoor that lived undetected on a single U.K. machine for a year before disappearing, finding clues pointing to an elite-level APT intrusion that still evades broader industry coverage. Plus, connecting the dots across AI-driven vulnerability discovery, Microsoft’s massive Patch Tuesday, Jensen Huang talks cybersecurity, Mythos dangers and Chinese chips, and the quiet erosion of CVE enrichment at NIST. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 – Intros + AI news whiplash 5:10 – Patch Tuesday breakdown: Microsoft's second-largest CVE release ever 7:32 – AI accelerating vulnerability discovery at record pace 10:00 – Frontier lab cyber models, fine-tuning, guardrail removal & KYC 12:37 – FreeBSD NFS bug: Opus 4.6 was already finding critical vulns 14:26 – Anthropic's infrastructure strain: Is Opus being nerfed? 21:05 – OpenAI's Trusted Access for Cyber vs. Anthropic's Mythos cabal 28:45 – SharePoint zero-day CVE-2026-32201: The endless Microsoft tax 34:36 – Adobe Acrobat zero-day: A rare, real, Russia-linked exploit in the wild 41:36 – VirusTotal mining: The golden age of threat intel hunting 50:03 – ZionSiphon: Vibe-coded OT malware targeting Israeli water infrastructure 55:04 – Paleontology of threat research: When do you publish? Who do you trust? 1:13:53 – Angry Spark: A one-machine, one-year backdoor raises eyebrows 1:49:25 – Jensen Huang vs. Dwarkesh Patel on Mythos, China and chips 2:14:32 – Chinese AI distillation: 24,000 fake Anthropic accounts, DeepSeek & the catch-up questionLinks:Transcript Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulns ZDI: April 2026 Patch Tuesday Review Inside ZionSiphon: OT Malware Targeting Israeli Water Systems GenDigital: Chasing an Angry Spark MAD Bugs: Month of AI-Discovered Bugs (Calif) HackerOne: The Vulnerability Apocalypse is a Remediation Crisis OpenAI scaling up Trusted Access for Cyber (TAC) Program OpenAI Commits $10m in API credits for cybersecurity Anthropic: Introducing Claude Opus 4.7 OpenAI confirms Axios developer tool compromise Jensen Huang x Jensen Huang on Nvidia’s AI Moat Anthropic: Detecting and preventing distillation attacks NIST Updates NVD Operations to Address Record CVE Growth Dreadnode Open-Source Tools to Measure AI Offense-Defense Gap LABScon 2026 Call for Papers Cyber-Paleontology in the Age of AI (Black Hat Asia 2026) Ekoparty Miami Schedule TLPBLACK -
The Claude Mythos, Project Glasswing Shockwave 10.04.2026 2h 34min(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 93: We discuss Anthropic's release of Claude Mythos Preview (an AI model so capable and dangerous they won't release it publicly) and debate the looming patching crisis, bug bounty extinction, possible US government nationalization of frontier labs, and why the NSA might not be thrilled about all this bug-fixing. Plus, North Korea's six-month Drift Protocol con job, APT28's retro DNS hijacking campaign, and Microsoft's driver signing mess hitting WireGuard and VeraCrypt. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 00:00 — Opening banter 01:36 — Anthropic Mythos Preview + Project Glasswing 06:17 — USG reaction + Wall Street emergency meeting 10:54 — Mythos capabilities vs hype (technical reality check) 13:44 — PR stunt? Skepticism of Anthropic narrative 20:42 — The patching crisis + “defender advantage” 27:41 — Bug bounty model under threat from AI 33:37 — Mythos practical workflows 45:09 — Geopolitics, NSA angle, and nationalization discussion 01:40:18 — Fortinet zero-day + ongoing failures 01:42:39 — Drift Protocol heist ($285M) + long-term social engineering 01:44:07 — Revisiting XZ Utils / Jia Tan attribution 01:54:07 — Crypto security gaps + need for real CTI in blockchain 02:04:22 — APT28 DNS hijacking + router compromise campaign 02:18:57 — Microsoft driver signing meltdown + ecosystem impactLinks:Transcript TLPBLACK Claude Mythos Preview Accidental data leak reveals existence of Anthropic Mythos Project Glasswing System Card: Claude Mythos Preview Axios: OpenAI plans new product for cybersecurity use The $285M Drift Protocol Heist Was ‘6 Months in the Making’ Drift Protocol - Incident Report US Treasury to share threat-intel with crypto companies Fortinet customers confront actively exploited zero-day Fortinet advisory: CVE-2026-35616 (exploited in the wild) SOHO router compromise leads to DNS hijacking APT28 exploit routers to enable DNS hijacking operations DOJ Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Lumen on 'Frost Armada' Forest Blizzard DNS Hijacking WireGuard (Account Suspended) OSR on Microsoft Driver Signing Lockout Microsoft: Account Verification for Windows Hardware Program US Warns of Iran-Linked Cyber Hacks on Water, Energy Systems CISA bulletin: Iranian Hackers Exploiting PLCs Across US Critical Infrastructure Watch S4: The Bob Lazar Story YouTube: Dan Guido at [un]prompted -
LLMs writing exploits, engineers losing skills, and a case for the generative OS 03.04.2026 2h 19min(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 92: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 0:00 – Introductory banter 2:00 – Costin's ransomware incident response work 3:30 – How attackers break in: Fortinet vulnerabilities everywhere 6:30 – Hunting for ransomware decryption keys 9:00 – Breaking into ransomware C2s and monitoring leak sites 12:00 – The ransom payment debate: should you ever pay? 16:00 – Why "don't pay the ransom" is overgeneralized 21:00 – How ransomware gangs price their demands 24:00 – The AI-pilling of the security industry 28:30 – Nicholas Carlini, Ptacek, and "vulnerability research is cooked" 35:00 – Towards a generative-first operating system 41:00 – Code factories, trusted computing, and killing dependencies 48:00 – Microsoft and Apple's AI positioning 56:00 – Chris St. Myers' "Cognitive Rust Belt" essay 1:18:00 – Choice, The Matrix, and the illusion of control 1:38:00 – Supply chain attacks, North Korea, and dependency sprawlLinks:Transcript Nicholas Carlini - Black-hat LLMs Ptacek: Vulnerability Research Is Cooked Chris St Myers: Why Organizations Are Confusing Temporary Friction with Permanent Safety Dan Geer: Children of the Magenta Calif: Month of AI-Discovered Bugs Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell Internet Bug Bounty Pauses Bug Bounty Program Node.js Bug Bounty Program Paused Due to Loss of Funding Elastic: How we caught the Axios supply chain attack Elastic tool: supply-chain-monitor Apple Will Push Out Rare ‘Backported’ Patches to iOS 18 Users WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware The Human-Machine Team Arsenal Recon Tool TLPBLACK
I/E popullarizuar në
Ky podkast shfaqet edhe në listat e podkasteve të këtyre shteteve.