Home Podcasts Three Buddy Problem
Three Buddy Problem

Three Buddy Problem

Security Conversations 232 Episodes Jul 23, 2026

The Three Buddy Problem is a Security Conversations podcast that goes beyond industry talking points to discuss nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros — journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade — the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.

Episodes

OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16 Jul 23, 2026 2:16:03 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack Jul 18, 2026 2:07:29 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen Jul 4, 2026 1:36:03 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
US Gov Takes the Wheel: Who Gets to Use the Best AI?
US Gov Takes the Wheel: Who Gets to Use the Best AI? Jun 29, 2026 1:53:54 (Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Katie Moussouris on the Anthropic Export-Control Mess
Katie Moussouris on the Anthropic Export-Control Mess Jun 19, 2026 1:38:24 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 102: Software export controls expert Katie Moussouris joins the show to unpack the US government's abrupt move to suspend access to Anthropic's most powerful models over a so-called "jai
Mythos, Fable, and Anthropic's Big Trust Problem
Mythos, Fable, and Anthropic's Big Trust Problem Jun 12, 2026 1:59:10 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 101: We discuss Anthropic's Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users' results, sparking a heated debate over guardrails,
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux Jun 5, 2026 2:24:29 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited May 30, 2026 1:59:45 (Presented by Ent.ai: Ent delivers intent-aware security that protects every action, adapts to every workflow, and works for every user. Enterprise threat detection, reimagined.) Three Buddy Problem - Episode 99: Microsoft is now threatening legal action against researchers who drop zero-days. We debate whether it's a fair line against extortion, or amateur-hour PR from a company that al
Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense
Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense May 27, 2026 40:09 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Aaron Portnoy (Zero Day Initiative alum, early Pwn2Own organizer, and now at Mindgard) joins us at Ekoparty Miami to reminisce on the early days of the hacking contest, where vul
Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code
Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code May 26, 2026 40:27 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential. W
Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap
Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap May 26, 2026 49:37 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the
Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing
Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing May 25, 2026 58:02 (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Federico Kirschbaum, founder of Ekoparty and now head of Security Lab at XBOW, talks about what happens to offensive security when an autonomous AI hacker can find and exploit r

Recommended