246 episodes
- (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem x Offensive AI Con: Umbriel AI's Aaron Grattafiori breaks down the new offensive-security playbook, using LLMs for patch variant analysis, why the vuln apocalypse hasn't become an exploit apocalypse, and how the death of security through obscurity puts closed-source binaries and firmware within reach.
Plus, we discuss rogue agents escaping sandboxes, the eval-driven loop behind recursive self-improvement, and the brutal cost asymmetry that makes offense cheap and defense almost unaffordable.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Aaron Grattafiori.
Timestamps:
0:00 Introductory banter
1:12 Umbriel AI pitch: "Smart people in a place to cook”
3:08 Weird, exhausting, exciting time in security
4:00 What AI really changed: speed (and a 30-minute reimplementation)
6:36 Incomplete fixes and the variant-analysis pipeline
9:21 Uplifting, abstraction, and representing vulnerabilities
11:48 Experimentation and the new shape of security companies
14:46 The vuln apocalypse vs. the exploit apocalypse
16:36 Triage, verification, and reward hacking
18:08 Do models reintroduce bugs? Is vuln-free code possible?
24:22 Specialized models and the rise of Jev-style classifiers
26:47 Binaries, firmware, and the death of security through obscurity
31:15 Open source as a requirement and corporate contracting
33:54 Rogue agents: Hugging Face, OpenAI, and lab escapes
39:17 Why defense is so expensive, and running the rig - (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem x Offensive AI Con: Former US intelligence and national security official Joel Todoroff joins us live from OffensiveAIcon to explain why his new startup Phyle is building AI for the recon and targeting work that happens long before anyone fires an exploit.
We get into bribable sysadmins, the military framing that boxes in Western cyber operations, letters of marque, AI doomerism, and what happens when a frontier model decides mid-project that your use case is off-limits.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Joel Todoroff.
Timestamps:
0:00 Live from OffensiveAIcon in Oceanside
1:23 What Phyle builds for governments
3:02 Skepticism of the AI 0-day factory
5:57 Paying a sysadmin vs. burning tokens
9:30 Recon gets less love than weaponization
12:41 Exploit shelf life and target No. 1,000
17:30 Why attacker costs will keep rising
22:23 What HUMINT looks like in 2026
27:06 Why intelligence stovepipes persist
32:16 Cyber as statecraft beyond the military frame
41:23 People will keep making dumb mistakes
48:03 The White House memo and letters of marque
54:06 Doomerism vs. near-term AI harms
1:04:20 PSOA concerns and building guardrails in
1:26:03 Open models, guardrails and zero data retention - (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem x Offensive AI Con: Live from OAIC, IBM X-Force's Valentina Palmiotti (chompie) walks us through the autonomous Windows kernel exploit pipeline she built on older Claude models, which landed within a hair of Mythos for about $180 a chain.
Plus, the Pwn2Own bug Claude called unexploitable, why her Pwn2Own bugs still sit unpatched, disappearing exploit techniques, the dread of being a defender, and how Phrack found its way back into print.
Timestamps:
0:00 Intro and Pwn2Own war stories
3:46 What vibe hacking means
8:16 When long agent runs go sideways
10:31 Self-verification in an n-day kernel pipeline
16:11 Matching Mythos for $180 a chain
18:42 The bug Claude called unexploitable
21:49 Unpatched bugs and the defender gap
25:37 Mythos arrives through CVP
27:00 Models only know public techniques
32:01 Testing models on held-back bugs
37:45 Inside chompie's daily workflow
46:07 Where's the exploitpocalypse?
50:07 Pixel drops MTE
53:40 Advice for defenders: design for containment
58:34 Phrack is back - (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem - Episode 115: We into Anthropic's Frontier Red Team fear-mongering on Zhipu's open-weight GLM 5.3 model and wonder why the AI labs' cyber programs do so little for defenders.
Plus, Citrix NetScaler zero-days, a new iOS zero-day tied to WhatsApp, AI agents that act on your behalf, and whether security teams should buy DGX Sparks to run models locally.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Timestamps:
0:00 Introductory banter, TLPBLACK
3:38 OffensiveAI Con and the missing defensive con
9:28 Anthropic's GLM 5.3 post
23:21 What do defensive AI coalitions do?
29:08 Inside Glasswing
36:01 Why can't vuln-finding models patch?
42:44 Gemini for Argon and Grok's CVE-Bench tie
47:54 Is hallucination a solved problem?
57:41 Zhipu's program and 4,000 zero-days
1:02:32 Citrix NetScaler zero-days
1:10:42 Half-days and automated patching
1:26:45 iOS 27.0.1 zero-day and WhatsApp
1:32:36 Dots, Instinct and agent monetization
1:52:06 DGX Spark 64GB and local AI hardware
2:18:38 Anthropic visits the Pope, then UFOs - (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem - Episode 114: We dig into TypeSafe AI's Jev and the new class of System One models, a new Transluce report on rogue OpenAI agents probing an Australian Medicare portal, Irregular's role in the latest Gemini test breakout, Hacktron's takeover of OpenAI employee accounts and the messy disclosure fight that followed, and what Costin would fix first as OpenAI's CISO for a day.
Plus, the soaring price of DGX Sparks and home AI rigs, the White House pressing labs to hold models back from the UK AI Security Institute, Anthropic bringing in Accenture as an evaluator, the FomoPeek App Store app hiding iOS kernel exploits, ShinyHunters' claimed FBI breach, and Nightmare Eclipse going public with identity and a CrowdStrike exploit.
Cast: Ryan Naraine, Juan Andres Guerrero-Saade and Costin Raiu.
Timestamps:
0:00 Introductory banter
1:57 The Last LABScon wrap-up
9:35 TypeSafe AI's Jev and System One models
26:18 Step-down transformers and lab economics
30:58 Rogue OpenAI agents and the Transluce report
41:40 Irregular and Gemini's test breakout
49:28 Hacktron's OpenAI hack and the disclosure fight
54:57 Costin as OpenAI CISO for a day
1:05:44 Hugging Face defends itself with GLM 5.2
1:17:08 What a home AI rig costs now
1:30:02 White House vs. UK AISI pre-release testing
1:36:52 FomoPeek kernel exploits in the App Store
1:51:19 ShinyHunters claims an FBI breach
2:02:40 Nightmare Eclipse unmasked
More Business News podcasts
Trending Business News podcasts
About Three Buddy Problem
The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).
Podcast websiteListen to Three Buddy Problem, Receipts with Catherine Rampell and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Three Buddy Problem
Scan code,
download the app,
start listening.
download the app,
start listening.








