Three Buddy Problem cover art

All Episodes

Three Buddy Problem — 193 episodes

#
Title
1

AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit

2

Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs.

3

A Thousand Agents Walk Into Hugging Face

4

Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure

5

A tiny 12 KB Windows backdoor, one victim, and a dead domain

6

Inside OpenAI's Black Hat Confession

7

Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats

8

Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise

9

OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16

10

Hugging Face Just Got Hit by the First Fully Autonomous AI Attack

11

Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen

12

US Gov Takes the Wheel: Who Gets to Use the Best AI?

13

Katie Moussouris on the Anthropic Export-Control Mess

14

Mythos, Fable, and Anthropic's Big Trust Problem

15

Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux

16

Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited

17

Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense

18

Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code

19

Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap

20

Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing

21

Jordan Wiens on AI, Offense vs. Defense, and the Dying CTF Pipeline

22

The AI-powered 10x patch tsunami has arrived. Now what?

23

The disappointing death of big-game APT reporting

24

Cracking the Fast16 sabotage malware mystery

25

Mark Dowd on AI hacking, exploit chains, zero-day sales

26

The Angry Spark APT Mystery: A Year-Long Backdoor, One Victim, Zero Attribution

27

The Claude Mythos, Project Glasswing Shockwave

28

LLMs writing exploits, engineers losing skills, and a case for the generative OS

29

Jeremy Banon: Personal Exec Compromise as Corporate Incident

30

Google's Cyber Disruption Unit; Coruna is Triangulation, US Bans Foreign-Made Routers

31

The greatest APT hunter of all time, Apple's exploit kit problem, Microsoft FedRAMP mess

32

Handala wiper attacks, APT28 implant devs are back, Signal's verification problems

33

Trenchant, Peter Williams, and the proliferation of a Shadow Brokers-level iOS exploit framework

34

Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery

35

Threat Hunter Greg Linares on the modern ransomware playbook

36

War in Iran, Anthropic v Pentagon, Trenchant zero-day sanctions, AI stock market shocks

37

GitLab doxxes North Korea .gov hackers; fresh Ivanti zero-days; AI addiction and human purpose

38

Palo Alto and the uncomfortable politics of APT attribution

39

From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks

40

A destructive cyberattack in Poland raises NATO 'red-line' questions

41

Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware

42

Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cybersecurity software

43

Hamid Kashfi on the situation in Iran; Did cyber cause Venezuela blackouts?

44

A special mailbag episode with book recommendations

45

Quiet Wins, Loud Failures: A Year-End Cybersecurity Reckoning

46

What's behind US gov push to 'privatize' offensive cyber operations?

47

Legal corruption, React2Shell exploitation, dual-use AI risks

48

APTs pounce on React2Shell; BRICKSTORM backdoors; .gov surveillance

49

Shai-Hulud 2.0, Russia GRU Intrusions, and Microsoft’s Regulatory Capture

50

Gemini 3 reactions, Fortinet/Chrome zero-days, a Cloudflare monoculture and a billion-dollar crypto twist

51

Anthropic Claude Code automating APT hacks, KnownSec leak, Chinese buses with remote access

52

LIVE from Ring0 COUNTERMEASURE: Google v FFmpeg, Ransomware Turncoats, Samsung 0days

53

OpenAI’s Dave Aitel talks Aardvark, economics of bug-hunting with LLMs

54

Apple’s iOS forensics freeze, WhatsApp zero-click, China outs NSA

55

JAGS LABScon 2025 keynote: Steps to an ecology of cyber

56

Apple Exploit-Chain Bounties, Wireless Proximity Exploits and Tactical Suitcases

57

Chris Eng on lessons learned from the NSA, @Stake, Veracode, and 20 years in cybersecurity

58

Oracle cl0p ransomware crisis, EU drone sightings, Cisco bootkit fallout

59

Cisco firewall zero-days and bootkits in the wild

60

Live at LABScon: Aurora Johnson and Trevor Hilligoss on China's 'internet toilets'

61

Live at LABScon: Visi Stark shares memories of creating the APT1 report

62

Live at LABScon: Lindsay Freeman on tracking Wagner Group war crimes

63

Can Apple's New Anti-Exploit Tech Stop iPhone Spyware Attacks?

64

Salt Typhoon IOCs, Google floats ‘cyber disruption unit’, WhatsApp 0-click

65

Zero-day reality check: iOS exploits, MAPP in China and the hack-back temptation

66

On AI’s future, security’s failures, and what comes next...

67

Live from Black Hat: Brandon Dixon parses the AI security hype

68

Rethinking APT Attribution: Dakota Cary on Chinese Contractors and Espionage-as-a-Service

69

Microsoft Sharepoint security crisis: Faulty patches, Toolshell zero-days

70

Train brake hack, GRU sanctions, Wagner war crimes, Microsoft's Chinese ‘digital escorts’

71

How did China get Microsoft's zero-day exploits?

72

Who’s hacking who? Ivanti 0-days in France, China outs 'Night Eagle' APT

73

Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, destructive bank hacks

74

Cyber flashpoints in Israel-Iran war, the 'magnet of threats', Mossad drone swarms

75

Mikko Hypponen talks drone warfare, APT naming schemes

76

The dark hole of 'friendlies' and Western APTs

77

Russia hacks Ukraine war supply lines, Signal blocks Windows screenshots, BadSuccessor vuln disclosure debate

78

A Coinbase breach with bribes, rogue contractors and a $20M ransom demand

79

JAGS keynote: The intricacies of wartime cyber threat intelligence

80

Signalgate redux, OpenAI's Aardvark, normalizing cyber offense

81

Thomas Rid joins the show: AI consciousness, TP-Link's China connection, trust in hardware security

82

China doxxes NSA, CVE's funding crisis, Apple's zero-day troubles

83

NSA director fired, Ivanti's 0day screw-up, backdoor in robot dogs

84

Signalgate and ID management hiccups, PuzzleMaker and Chrome 0days, Lab Dookhtegan returns

85

China exposing Taiwan hacks, Paragon spyware and WhatsApp exploits, CISA budget cuts

86

A half-dozen Microsoft zero-days, Juniper router backdoors, advanced bootkit hunting

87

Revisiting the Lamberts, i-Soon indictments, VMware zero-days

88

Lazarus ByBit $1.4B heist was supply chain attack on developer

89

North Korea's biggest ever crypto heist: $1.4B stolen from Bybit

90

An 'extremely sophisticated' iPhone hack; Google flags major AMD microcode bug

91

Unpacking the UK government's secret iCloud backdoor demand

92

Inside the DeepSeek AI existential crisis, Chinese 'backdoor' in medical devices

93

Death of the CSRB, zero-days storms at the edge, Juniper router backdoors

94

Inside the PlugX malware removal operation, CISA takes victory lap and another Fortinet 0day

95

Hijacking .gov backdoors, Ivanti 0days and a Samsung 0-click vuln

96

US Treasury hacked via BeyondTrust, MISP and the threat actor naming mess

97

Palo Alto network edge device backdoor, Cyberhaven browser extension hack, 2024 research highlights

98

US government's VPN advice, dropping bombs on ransomware gangs

99

Surveillance economics, Turla and Careto, and the AI screenshots nobody asked for

100

Inside the Turla Playbook: Hijacking APTs and fourth-party espionage

101

Volexity’s Steven Adair on Russian Wi-Fi hacks, memory forensics, appliance 0days and network inspectability

102

Sid Trivedi on the RSA Innovation Sandbox $5 million investment gambit

103

Russian APT weaponized nearby Wi-Fi networks in DC, new macOS zero-days, DOJ v Chrome

104

What happens to CISA now? Is deterrence in cyber possible?

105

Mysterious rebooting iPhones, EDR vendors spying on hackers, Bitcoin 'meatspace' attacks

106

The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela

107

Fortinet 0days, Appin hack-for-hire exposé, crypto heists, Russians booted from Linux kernel

108

ESET Israel wiper malware, China's Volt Typhoon response, Kaspersky sanctions and isolation

109

Typhoons and Blizzards: Cyberespionage and national security on front burner

110

Careto returns, IDA Pro pricing controversy, crypto's North Korea problem

111

Exploding beepers, critical CUPS flaws, Windows Recall rebuilt for security

112

Ep13: The Consolation of Threat Intel (JAG-S LABScon keynote)

113

Ep12: Security use-cases for AI chain-of-thought reasoning

114

Ep11: Cyberwarfare takes an ominous turn

115

Ep10: Volt Typhoon zero-day, Russia's APT29 reusing spyware exploits, Pavel Durov's arrest

116

Ep9: The blurring lines between nation-state APTs and the ransomware epidemic

117

Ep8: Microsoft's zero-days and a wormable Windows TCP/IP flaw known to China

118

Ep7: Crowd2K and the kernel, PKFail supply chain failures, Paris trains sabotage and Russian Olympic attacks

119

Ep6: After CrowdStrike chaos, should Microsoft kick EDR agents out of Windows kernel?

120

Ep5: CrowdStrike's faulty update shuts down global networks

121

Ep4: The AT&T mega-breach, iPhone mercenary spyware, Microsoft zero-days

122

Ep3: Dave Aitel joins debate on nation-state hacking responsibilities

123

Ep2: A deep-dive on disrupting and exposing nation-state malware ops

124

Ep1: The Microsoft Recall debacle, Brad Smith and the CSRB, Apple Private Cloud Compute

125

Cris Neckar on the early days of securing Chrome, chasing browser exploits

126

Costin Raiu joins the XZ Utils backdoor investigation

127

Katie Moussouris on building a different cybersecurity businesses

128

Costin Raiu: The GReAT exit interview

129

Danny Adamitis on an 'unkillable' router botnet used by Chinese .gov hackers

130

Allison Miller talks about CISO life, protecting identities at scale

131

Rob Ragan on the excitement of AI solving security problems

132

Seth Spergel on venture capital bets in cybersecurity

133

Dan Lorenc on fixing the 'crappy' CVE ecosystem

134

Cisco Talos researcher Nick Biasini on chasing APTs, mercenary hackers

135

Allison Nixon on disturbing elements in cybercriminal ecosystem

136

Dakota Cary on China's weaponization of software vulnerabilities

137

Abhishek Arya on Google's AI cybersecurity experiments

138

Dr Sergey Bratus on the 'citizen science' of hacking

139

DARPA's Perri Adams on CTF hacking, new $20M AI Cyber Challenge

140

Ryan Hurst on tech innovation and unsolved problems in security

141

Jason Chan on Microsoft's security problems, layoffs and startups

142

GitHub security chief Mike Hanley on secure coding, AI and SBOMs

143

Jason Shockey, Chief Information Security Officer, Cenlar FSB

144

Federico Kirschbaum on a life in the Argentina hacking scene

145

Kymberlee Price reflects on life at the MSRC, hacker/vendor engagement, bug bounties

146

OpenSSF GM Omkhar Arasaratnam on open-source software security

147

Serial entrepreneur Rishi Bhargava on building another cybersecurity company

148

Claude Mandy on CISO priorities, data security principles

149

Sidra Ahmed Lefort dishes on VC investments and cyber uncertainties

150

Paul Roberts on wins and losses in the 'right to repair' battle

151

Katie Moussouris on where bug bounties went wrong

152

Robinhood CSO Caleb Sima on a career in the security trenches

153

Charlie Miller on hacking iPhones, Macbooks, Jeep and Self-Driving Cars

154

JAG-S on big-game malware hunting and a very mysterious APT

155

Chainguard's Dan Lorenc gets real on software supply chain problems

156

Vinnie Liu discusses a life in the offensive security trenches

157

Down memory lane with Snort and Sourcefire creator Marty Roesch

158

Subbu Rama, co-founder and CEO, BalkanID

159

Project Zero's Maddie Stone on the surge in zero-day discoveries

160

Prof. Mohit Tiwari on the future of securing data at scale

161

Google's Shane Huntley on zero-days and the nation-state threat landscape

162

Lamont Orange, CISO, Netskope

163

Haroon Meer on the business of cybersecurity

164

Tony Pepper, co-founder and CEO, Egress

165

Microsoft's Justin Campbell on offensive security research

166

Costin Raiu on the .gov mobile exploitation business

167

Amanda Gorton, co-founder and CEO, Corellium

168

Intel's Venky Venkateswaran on hardware-enabled security

169

Sounil Yu on SBOMs, software supply chain security

170

Algirde Pipikaite, Centre for Cybersecurity, World Economic Forum

171

Josh Schwartz on red-teaming and proactive security engineering

172

Michael Laventure, threat detection and response, Netflix

173

Google's Heather Adkins on defenders playing the long game

174

Collin Greene, head of product security, Facebook

175

Alex Matrosov on the state of security at the firmware layer

176

Charles Nwatu, Security Technology & Risk, Netflix

177

Doug Madory on the mysterious AS8003 global routing story

178

Crossbeam CISO Chris Castaldo on securing the start-up

179

Shubs Shah on finding riches (and lessons) from bug bounty hacking

180

Fahmida Rashid, Executive Editor, VentureBeat

181

Microsoft's David Weston on the surge in firmware attacks

182

Lena Smart, CISO, MongoDB

183

Patrick Howell O'Neill, Cybersecurity Editor, MIT Technology Review

184

Nico Waisman, Head of Privacy & Security, Lyft

185

Ron Brash on the water plant hacks and the state of ICS security

186

Throwback: Zero-day exploit broker Chaouki Bekrar

187

Selena Larson, Intelligence Analyst, Dragos

188

Fredrick Lee, Chief Security Officer, Gusto

189

Zack Whittaker, Security Editor, TechCrunch

190

Jason Chan, VP, Information Security, Netflix

191

Matt Honea, Senior Director, Cybersecurity, Guidewire

192

Andy Greenberg, Senior Writer, Wired

193

Brooke Pearson, Security Awareness, Uber