Saltar al contenido
PodcastsNoticiasThree Buddy Problem

Three Buddy Problem

Security Conversations
Three Buddy Problem
Último episodio

241 episodios

  • Three Buddy Problem

    AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit

    11/09/2026 | 2 h 37 min
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 113: On the show this week, the buddies dig into an Anthropic researcher quitting with a warning that AI could kill us all, the San Francisco "death cult" and their motives, and agent swarms leaving junk on public wikis and university URL shorteners.

    Plus, a high-quality Anthropic's threat report and the claim that Moonshot was quietly serving Claude tokens as Kimi K3, live MikroTik and Chrome zero-days that landed a day ahead of the patches, and a WeChat worm that hijacks an account via phone calls.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:

    0:00 Introductory banter, TLP Black

    5:05 LabsCon, the last one, and JAGS on his keynote

    8:24 Costin's agentic CTI training and what old-school CTI is missing

    16:27 Anthropic's threat-intel report + IOCs

    20:00 APT29 and DarkSword on hotel Wi-Fi

    23:34 Bioweapons, guardrails, and what got shut down

    28:07 Why is anyone running these attacks on Claude at all?

    35:53 Distillation at industrial scale and the Kimi K3 fraud claim

    48:43 Chinese models, Americanized, running on DGX Spark

    55:00 Mr. America: local AI and the seven-layer cake

    1:04:34 Should frontier AI labs poison the distillers?

    1:27:05 What the frontier labs did to the security ecosystem

    1:34:22 Jacob Coxon quits, and the doomer argument falls apart

    1:59:13 Agent swarms littering the internet

    2:07:29 Chrome zero-days, MikroTik, patch-gaps
  • Three Buddy Problem

    Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs.

    04/09/2026 | 2 h 7 min
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 112: The 'OpenAI hacks Hugging Face' fallout has turned into a story about AI civilizations rising from the ashes, politicians calling for super-intelligence bans, and the emergence of well-funding non-profits doing AI safety work. Who are these people and what's their security expertise?

    Plus, GPT-6 Astra lands in a trusted-access program nobody can get into, Costin ranks the local models he runs next to his desk, and CrowdStrike sinkholes a botnet that's been alive since 2003.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:

    0:00 Introductory banter

    1:02 Conference season: LabsCon, Offensive AI Con, Countermeasure

    5:40 The Hugging Face story hits the front page

    7:04 Dwarkesh, Greenblatt, and the AI-pilled framing

    11:51 Swap "agents" for "Python" and the panic goes away

    16:34 Does anyone actually know what happened?

    21:18 Bernie Sanders wants to ban superintelligence

    34:03 Defending against swarms: the 2026 SOC

    39:15 Logs, Splunk, and the business model in the way

    44:11 What EDR vendors are actually building with AI

    56:16 The security poverty line and the endgame

    1:07:53 GPT-6 Astra, Fable 5.1, and local model rankings

    1:27:25 Google's Fairwind, CodeMender, and agents running Linux

    1:45:31 Apple's bet on local inference

    1:53:21 The Sality takedown and endgame advice
  • Three Buddy Problem

    A Thousand Agents Walk Into Hugging Face

    28/08/2026 | 2 h 27 min
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 111: OpenAI finally published a technical Hugging Face post-mortem, and Costin's verdict is blunt. He reads it as a document written for policymakers rather than for the blue teams who have to survive a thousand-agent swarm.

    We also dig into NVIDIA's $12.9 billion acquisition of Hugging Face, why JAGS thinks a frontier lab standing against open-source looks weak, and what that new industry open letter on cyber defense actually asks anyone to do. Plus, hotel Wi-Fi tradecraft after CaptiveCrunch, the FBI's ORB network takedown with Lumen, Chinese routers that ship backdoored from the factory, and the TeamPCP arrests in Australia.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:

    0:00 Introductory banter

    1:11 TLPBlack, incident response, and why it starts at the router

    4:11 CaptiveCrunch and Juanito's travel router kit

    7:59 Costin's VPN/hotel WiFi stack

    12:36 State of Statecraft, LABScon, and Offensive AI Con

    17:16 OpenAI's Hugging Face post-mortem technical report

    21:43 A swarm of a thousand agents

    27:35 Who was OpenAI’s report written for?

    33:05 Fail2ban, canaries, and catching agents in your logs

    40:34 NVIDIA buys Hugging Face for $12.9 billion

    44:42 The open weights fight and rooting for China

    52:47 Nemotron, DGX Spark, and the RAM price spiral

    1:03:26 Open letter on collective AI-powered cyber defense

    1:30:21 Lumen's Quartermaster and the FBI ORB takedown

    1:59:05 Backdoored ZBT routers, Chinese phones, and the TeamPCP arrests
  • Three Buddy Problem

    Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure

    21/08/2026 | 2 h 11 min
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 110: We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup running sandboxes for OpenAI, Anthropic and Meta, drones over Romania's gas platforms, OpenAI's two-week training pause, and T-Mobile taking scissors to a cable during Salt Typhoon incident response.

    Stick around for a UFO segment that somehow involves Dr. Phil.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:

    0:00 Introductory banter; LabsCon speakers announced

    9:06 A naval drone reaches the Neptun Deep gas platform

    17:38 OpenAI pauses RL training: what "slowing the pace of scaling" costs

    24:34 Guardrails vs refusals vs alignment.

    33:54 Irregular, formerly Pattern Labs: $80M, $450M valuation, one job

    46:11 JAGS on why security needs a new batch of startups right now

    1:06:52 EncroChat revealed: a GitHub-sourced implant, IOCs

    1:15:12 Law enforcement malware vs intelligence malware

    1:21:07 T-Mobile, Salt Typhoon, and cutting the cable with a pair of scissors

    1:32:06 Captive Crunch: hotel Wi-Fi, OAuth token theft, and the MSP supply chain

    1:47:00 ICE RELIC, UNC6293, and the trouble with subcluster naming

    2:00:39 UFO corner: David Grusch, Dr. Phil, and the Skywatcher Project

    2:05:44 Shout outs, the Costin Challenge
  • Three Buddy Problem

    A tiny 12 KB Windows backdoor, one victim, and a dead domain

    17/08/2026 | 2 h 23 min
    (Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.)

    Three Buddy Problem - Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this.

    Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance.

    Cast: Costin Raiu, Ryan Naraine and Juan Andres Guerrero-Saade

    Timestamps:

    0:00 Introductory banter

    0:58 State of Statecraft, and a late CFP window

    3:24 The White House offensive hacking memo

    6:37 "Hack back" is the wrong frame for what's being authorized

    11:20 Ransomware cases sitting on the shelf

    17:01 The million-dollar bond and who can realistically play

    22:29 Where DPRK crypto theft falls under the new definitions

    28:15 Would TLP Black take a contract?

    36:55 Gen Digital's 12 KB backdoor hiding its C2 in desktop.ini whitespace

    46:57 Passive DNS, registration patterns, and pivoting on a dead domain

    57:32 Feeding a one-off find back into detection engineering

    1:02:14 Metador, Mafalda, and the mercenaries who love telcos

    1:17:07 Armored Likho and what "Western APT" really means

    1:28:16 The IOC market, private reporting, and CTI’s matching problem

    1:58:10 Google's culture problem, the weekly model churn, and Patch Tuesday math
Más podcasts de Noticias
Acerca de Three Buddy Problem
The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).
Sitio web del podcast

Escucha Three Buddy Problem, El Cartel de La Mega y muchos más podcasts de todo el mundo con la aplicación de radio.net

Descarga la app gratuita: radio.net

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app