Home Podcasts Three Buddy Problem
Three Buddy Problem

Three Buddy Problem

Security Conversations 232 Episodes Aug 21, 2026

The Three Buddy Problem is a Security Conversations podcast that goes beyond industry talking points to discuss nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros — journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade — the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.

Episodes

Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure
Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure Aug 21, 2026 2:11:08 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 110: We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup runni
A tiny 12 KB Windows backdoor, one victim, and a dead domain
A tiny 12 KB Windows backdoor, one victim, and a dead domain Aug 17, 2026 2:23:31 (Presented by State of Statecraft: A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors.) Three Buddy Problem - Episode 109: The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Cost
Inside OpenAI's Black Hat Confession
Inside OpenAI's Black Hat Confession Aug 8, 2026 2:14:10 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 108: OpenAI got on the Black Hat stage and walked through how its own agent swarm hacked Hugging Face. We discuss and struggle to decide whether to clap or panic. Plus, why only the a
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats Jul 31, 2026 3:26:39 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise
Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise Jul 28, 2026 34:38 Security Conversations: Kenneth Kinion, founder and CEO of Validin, joins Ryan Naraine on the show to unpack what "internet intelligence" really means for the analysts and responders chasing malicious infrastructure. We trace his path from Georgia Tech through Microsoft and Amazon to the frustrations that led to the creation of Validin, the competition from big AI, the value of AI-powere
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16 Jul 23, 2026 2:16:03 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack Jul 18, 2026 2:07:29 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen Jul 4, 2026 1:36:03 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
US Gov Takes the Wheel: Who Gets to Use the Best AI?
US Gov Takes the Wheel: Who Gets to Use the Best AI? Jun 29, 2026 1:53:54 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Katie Moussouris on the Anthropic Export-Control Mess
Katie Moussouris on the Anthropic Export-Control Mess Jun 19, 2026 1:38:24 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 102: Software export controls expert Katie Moussouris joins the show to unpack the US government's abrupt move to suspend access to Anthropic's most powerful models over a so-called "jai
Mythos, Fable, and Anthropic's Big Trust Problem
Mythos, Fable, and Anthropic's Big Trust Problem Jun 12, 2026 1:59:10 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 101: We discuss Anthropic's Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users' results, sparking a heated debate over guardrails,
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux Jun 5, 2026 2:24:29 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay

Recommended