Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware episode artwork

EPISODE · Jan 23, 2026 · 2H 9M

Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware

from Three Buddy Problem · host Security Conversations

(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 82: We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA's new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland's electricity sector. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Episode metadata supplied by the publisher feed · Published Jan 23, 2026

Embed this episode

( Presented by Material Security : We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices. ) Three Buddy Problem - Episode 82 : We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA's new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland's electricity sector. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Links: Transcript (unedited, AI-generated) Material Security (use cases) Sean Heelan on the coming industrialisation of exploit generation with LLMs VoidLink Shows AI-Generated Malware Has Begun LLMs in the SOC: Why Benchmarks Fail Security Operations Teams CISA advisory on BRICKSTORM backdoor Node.js — New HackerOne Signal Requirement AI slop security reports submitted to cURL Arctic Wolf on FortiGate attacks via SSO accounts New Cisco Remote Code Execution Vulnerability From Protest to Peril: Cellebrite Used Against Jordanian Civil Society Microsoft on multi‑stage AiTM phishing and BEC campaign abusing SharePoint Microsoft Gave FBI BitLocker Encryption Keys The Mastermind: Drugs. Empire. Murder. Betrayal Kim Zetter: Cyberattack on Poland’s energy grid used a wiper ESET on 'DynoWiper' malware

Distinct summary based on available episode metadata or transcript content.

Ready to play

Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware

0:00 2:09:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Three Buddy Problem?

This episode is 2 hours and 9 minutes long.

When was this Three Buddy Problem episode published?

This episode was published on January 23, 2026.

Can I download this Three Buddy Problem episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!