『Three Buddy Problem』のカバーアート

Three Buddy Problem

Three Buddy Problem

著者: Security Conversations
無料で聴く

The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).© 2026 The Naraine Group 政治・政府
エピソード
  • A Thousand Agents Walk Into Hugging Face
    2026/08/28

    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 111: OpenAI finally published a technical Hugging Face post-mortem, and Costin's verdict is blunt. He reads it as a document written for policymakers rather than for the blue teams who have to survive a thousand-agent swarm.

    We also dig into NVIDIA's $12.9 billion acquisition of Hugging Face, why JAGS thinks a frontier lab standing against open-source looks weak, and what that new industry open letter on cyber defense actually asks anyone to do. Plus, hotel Wi-Fi tradecraft after CaptiveCrunch, the FBI's ORB network takedown with Lumen, Chinese routers that ship backdoored from the factory, and the TeamPCP arrests in Australia.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:
    0:00 Introductory banter
    1:11 TLPBlack, incident response, and why it starts at the router
    4:11 CaptiveCrunch and Juanito's travel router kit
    7:59 Costin's VPN/hotel WiFi stack
    12:36 State of Statecraft, LABScon, and Offensive AI Con
    17:16 OpenAI's Hugging Face post-mortem technical report
    21:43 A swarm of a thousand agents
    27:35 Who was OpenAI’s report written for?
    33:05 Fail2ban, canaries, and catching agents in your logs
    40:34 NVIDIA buys Hugging Face for $12.9 billion
    44:42 The open weights fight and rooting for China
    52:47 Nemotron, DGX Spark, and the RAM price spiral
    1:03:26 Open letter on collective AI-powered cyber defense
    1:30:21 Lumen's Quartermaster and the FBI ORB takedown
    1:59:05 Backdoored ZBT routers, Chinese phones, and the TeamPCP arrests

    続きを読む 一部表示
    2 時間 27 分
  • Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure
    2026/08/21

    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 110: We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup running sandboxes for OpenAI, Anthropic and Meta, drones over Romania's gas platforms, OpenAI's two-week training pause, and T-Mobile taking scissors to a cable during Salt Typhoon incident response.

    Stick around for a UFO segment that somehow involves Dr. Phil.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:
    0:00 Introductory banter; LabsCon speakers announced
    9:06 A naval drone reaches the Neptun Deep gas platform
    17:38 OpenAI pauses RL training: what "slowing the pace of scaling" costs
    24:34 Guardrails vs refusals vs alignment.
    33:54 Irregular, formerly Pattern Labs: $80M, $450M valuation, one job
    46:11 JAGS on why security needs a new batch of startups right now
    1:06:52 EncroChat revealed: a GitHub-sourced implant, IOCs
    1:15:12 Law enforcement malware vs intelligence malware
    1:21:07 T-Mobile, Salt Typhoon, and cutting the cable with a pair of scissors
    1:32:06 Captive Crunch: hotel Wi-Fi, OAuth token theft, and the MSP supply chain
    1:47:00 ICE RELIC, UNC6293, and the trouble with subcluster naming
    2:00:39 UFO corner: David Grusch, Dr. Phil, and the Skywatcher Project
    2:05:44 Shout outs, the Costin Challenge

    続きを読む 一部表示
    2 時間 11 分
  • A tiny 12 KB Windows backdoor, one victim, and a dead domain
    2026/08/17

    (Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.)

    Three Buddy Problem - Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this.

    Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance.

    Cast: Costin Raiu, Ryan Naraine and Juan Andres Guerrero-Saade

    Timestamps:
    0:00 Introductory banter
    0:58 State of Statecraft, and a late CFP window
    3:24 The White House offensive hacking memo
    6:37 "Hack back" is the wrong frame for what's being authorized
    11:20 Ransomware cases sitting on the shelf
    17:01 The million-dollar bond and who can realistically play
    22:29 Where DPRK crypto theft falls under the new definitions
    28:15 Would TLP Black take a contract?
    36:55 Gen Digital's 12 KB backdoor hiding its C2 in desktop.ini whitespace
    46:57 Passive DNS, registration patterns, and pivoting on a dead domain
    57:32 Feeding a one-off find back into detection engineering
    1:02:14 Metador, Mafalda, and the mercenaries who love telcos
    1:17:07 Armored Likho and what "Western APT" really means
    1:28:16 The IOC market, private reporting, and CTI’s matching problem
    1:58:10 Google's culture problem, the weekly model churn, and Patch Tuesday math

    続きを読む 一部表示
    2 時間 24 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません