LLMs writing exploits, engineers losing skills, and a case for the generative OS episode artwork

EPISODE · Apr 3, 2026 · 2H 19M

LLMs writing exploits, engineers losing skills, and a case for the generative OS

from Three Buddy Problem · host Security Conversations

(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 92: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 0:00 – Introductory banter 2:00 – Costin's ransomware incident response work 3:30 – How attackers break in: Fortinet vulnerabilities everywhere 6:30 – Hunting for ransomware decryption keys 9:00 – Breaking into ransomware C2s and monitoring leak sites 12:00 – The ransom payment debate: should you ever pay? 16:00 – Why "don't pay the ransom" is overgeneralized 21:00 – How ransomware gangs price their demands 24:00 – The AI-pilling of the security industry 28:30 – Nicholas Carlini, Ptacek, and "vulnerability research is cooked" 35:00 – Towards a generative-first operating system 41:00 – Code factories, trusted computing, and killing dependencies 48:00 – Microsoft and Apple's AI positioning 56:00 – Chris St. Myers' "Cognitive Rust Belt" essay 1:18:00 – Choice, The Matrix, and the illusion of control 1:38:00 – Supply chain attacks, North Korea, and dependency sprawl

Episode metadata supplied by the publisher feed · Published Apr 3, 2026

Embed this episode

( Presented by TLPBLACK : High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows. ) Three Buddy Problem - Episode 92 : Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . 0:00 – Introductory banter 2:00 – Costin's ransomware incident response work 3:30 – How attackers break in: Fortinet vulnerabilities everywhere 6:30 – Hunting for ransomware decryption keys 9:00 – Breaking into ransomware C2s and monitoring leak sites 12:00 – The ransom payment debate: should you ever pay? 16:00 – Why "don't pay the ransom" is overgeneralized 21:00 – How ransomware gangs price their demands 24:00 – The AI-pilling of the security industry 28:30 – Nicholas Carlini, Ptacek, and "vulnerability research is cooked" 35:00 – Towards a generative-first operating system 41:00 – Code factories, trusted computing, and killing dependencies 48:00 – Microsoft and Apple's AI positioning 56:00 – Chris St. Myers' "Cognitive Rust Belt" essay 1:18:00 – Choice, The Matrix, and the illusion of control 1:38:00 – Supply chain attacks, North Korea, and dependency sprawl Links: Transcript Nicholas Carlini - Black-hat LLMs Ptacek: Vulnerability Research Is Cooked Chris St Myers: Why Organizations Are Confusing Temporary Friction with Permanent Safety Dan Geer: Children of the Magenta Calif: Month of AI-Discovered Bugs Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell Internet Bug Bounty Pauses Bug Bounty Program Node.js Bug Bounty Program Paused Due to Loss of Funding Elastic: How we caught the Axios supply chain attack Elastic tool: supply-chain-monitor Apple Will Push Out Rare ‘Backported’ Patches to iOS 18 Users WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware The Human-Machine Team Arsenal Recon Tool TLPBLACK

Distinct summary based on available episode metadata or transcript content.

Ready to play

LLMs writing exploits, engineers losing skills, and a case for the generative OS

0:00 2:19:56

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Three Buddy Problem?

This episode is 2 hours and 19 minutes long.

When was this Three Buddy Problem episode published?

This episode was published on April 3, 2026.

Can I download this Three Buddy Problem episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!