Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats episode artwork

EPISODE · Jul 31, 2026 · 3H 26M

Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats

from Three Buddy Problem · host Security Conversations

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear’ advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

Episode metadata supplied by the publisher feed · Published Jul 31, 2026

Embed this episode

( Presented by Thinkst Canary : Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents. ) Three Buddy Problem - Episode 107 : Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich , Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear’ advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark Links: Transcript Greg Lesnewich | LinkedIn Proofpoint: TA488 Comes for Outlook with Another Half-Click Exploit TA488 Targets Zimbra Mailservers with Half-Click Exploits NSA: Russian APT Phishing Users of Zimbra Operation RoundPress Half-Click Webmail Zero-Days from TA458 Operation RoundPress targeting high-value webmail servers Anthropic: Investigating three real-world incidents in our cybersecurity evaluations Hugging Face: A Technical Timeline of OpenAI incident Microsoft Intros MAI-Cyber-1-Flash inside MDASH Google Updates Threat Actor Naming System Bill Marczak: An Angry Spark, or a Triangle in Disguise? Gen: Chasing an Angry Spark Amazon identifies North Korean hacker group behind open-source supply chain attacks Dana (Donella) Meadows Lecture: Sustainable Systems Outliers - Malcolm Gladwell 5-Year Data Hack Disclosed by SMS Giant Syniverse Practical Malware Analysis book Top 1 Million Websites Thinkst Canary

Distinct summary based on available episode metadata or transcript content.

Ready to play

Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats

0:00 3:26:39

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Three Buddy Problem?

This episode is 3 hours and 26 minutes long.

When was this Three Buddy Problem episode published?

This episode was published on July 31, 2026.

Can I download this Three Buddy Problem episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!