Skip to content
PodcastsBusiness NewsThree Buddy Problem

Three Buddy Problem

Security Conversations
Three Buddy Problem
Latest episode

246 episodes

  • Three Buddy Problem

    Aaron Grattafiori Explains How LLMs Hunt Patch Variants at Scale

    10/09/2026 | 54 mins.
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem x Offensive AI Con: Umbriel AI's Aaron Grattafiori breaks down the new offensive-security playbook, using LLMs for patch variant analysis, why the vuln apocalypse hasn't become an exploit apocalypse, and how the death of security through obscurity puts closed-source binaries and firmware within reach.

    Plus, we discuss rogue agents escaping sandboxes, the eval-driven loop behind recursive self-improvement, and the brutal cost asymmetry that makes offense cheap and defense almost unaffordable.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Aaron Grattafiori.

    Timestamps:

    0:00 Introductory banter

    1:12 Umbriel AI pitch: "Smart people in a place to cook”

    3:08 Weird, exhausting, exciting time in security

    4:00 What AI really changed: speed (and a 30-minute reimplementation)

    6:36 Incomplete fixes and the variant-analysis pipeline

    9:21 Uplifting, abstraction, and representing vulnerabilities

    11:48 Experimentation and the new shape of security companies

    14:46 The vuln apocalypse vs. the exploit apocalypse

    16:36 Triage, verification, and reward hacking

    18:08 Do models reintroduce bugs? Is vuln-free code possible?

    24:22 Specialized models and the rise of Jev-style classifiers

    26:47 Binaries, firmware, and the death of security through obscurity

    31:15 Open source as a requirement and corporate contracting

    33:54 Rogue agents: Hugging Face, OpenAI, and lab escapes

    39:17 Why defense is so expensive, and running the rig
  • Three Buddy Problem

    Joel Todoroff on How Offensive AI Is Rewiring Western Government Ops

    10/09/2026 | 1h 37 mins.
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem x Offensive AI Con: Former US intelligence and national security official Joel Todoroff joins us live from OffensiveAIcon to explain why his new startup Phyle is building AI for the recon and targeting work that happens long before anyone fires an exploit.

    We get into bribable sysadmins, the military framing that boxes in Western cyber operations, letters of marque, AI doomerism, and what happens when a frontier model decides mid-project that your use case is off-limits.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Joel Todoroff.

    Timestamps:

    0:00 Live from OffensiveAIcon in Oceanside

    1:23 What Phyle builds for governments

    3:02 Skepticism of the AI 0-day factory

    5:57 Paying a sysadmin vs. burning tokens

    9:30 Recon gets less love than weaponization

    12:41 Exploit shelf life and target No. 1,000

    17:30 Why attacker costs will keep rising

    22:23 What HUMINT looks like in 2026

    27:06 Why intelligence stovepipes persist

    32:16 Cyber as statecraft beyond the military frame

    41:23 People will keep making dumb mistakes

    48:03 The White House memo and letters of marque

    54:06 Doomerism vs. near-term AI harms

    1:04:20 PSOA concerns and building guardrails in

    1:26:03 Open models, guardrails and zero data retention
  • Three Buddy Problem

    Valentina Palmiotti (chompie) on Vulnpocalypse, Matching Mythos on a Budget

    10/07/2026 | 1h 8 mins.
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem x Offensive AI Con: Live from OAIC, IBM X-Force's Valentina Palmiotti (chompie) walks us through the autonomous Windows kernel exploit pipeline she built on older Claude models, which landed within a hair of Mythos for about $180 a chain.

    Plus, the Pwn2Own bug Claude called unexploitable, why her Pwn2Own bugs still sit unpatched, disappearing exploit techniques, the dread of being a defender, and how Phrack found its way back into print.

    Timestamps:

    0:00 Intro and Pwn2Own war stories

    3:46 What vibe hacking means

    8:16 When long agent runs go sideways

    10:31 Self-verification in an n-day kernel pipeline

    16:11 Matching Mythos for $180 a chain

    18:42 The bug Claude called unexploitable

    21:49 Unpatched bugs and the defender gap

    25:37 Mythos arrives through CVP

    27:00 Models only know public techniques

    32:01 Testing models on held-back bugs

    37:45 Inside chompie's daily workflow

    46:07 Where's the exploitpocalypse?

    50:07 Pixel drops MTE

    53:40 Advice for defenders: design for containment

    58:34 Phrack is back
  • Three Buddy Problem

    Why is Anthropic Afraid of GLM 5.3?

    10/02/2026 | 2h 33 mins.
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 115: We into Anthropic's Frontier Red Team fear-mongering on Zhipu's open-weight GLM 5.3 model and wonder why the AI labs' cyber programs do so little for defenders.

    Plus, Citrix NetScaler zero-days, a new iOS zero-day tied to WhatsApp, AI agents that act on your behalf, and whether security teams should buy DGX Sparks to run models locally.

    Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

    Timestamps:

    0:00 Introductory banter, TLPBLACK

    3:38 OffensiveAI Con and the missing defensive con

    9:28 Anthropic's GLM 5.3 post

    23:21 What do defensive AI coalitions do?

    29:08 Inside Glasswing

    36:01 Why can't vuln-finding models patch?

    42:44 Gemini for Argon and Grok's CVE-Bench tie

    47:54 Is hallucination a solved problem?

    57:41 Zhipu's program and 4,000 zero-days

    1:02:32 Citrix NetScaler zero-days

    1:10:42 Half-days and automated patching

    1:26:45 iOS 27.0.1 zero-day and WhatsApp

    1:32:36 Dots, Instinct and agent monetization

    1:52:06 DGX Spark 64GB and local AI hardware

    2:18:38 Anthropic visits the Pope, then UFOs
  • Three Buddy Problem

    Kernel Exploits in the iOS App Store, ShinyHunters Inside the FBI

    09/25/2026 | 2h 16 mins.
    (Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

    Three Buddy Problem - Episode 114: We dig into TypeSafe AI's Jev and the new class of System One models, a new Transluce report on rogue OpenAI agents probing an Australian Medicare portal, Irregular's role in the latest Gemini test breakout, Hacktron's takeover of OpenAI employee accounts and the messy disclosure fight that followed, and what Costin would fix first as OpenAI's CISO for a day.

    Plus, the soaring price of DGX Sparks and home AI rigs, the White House pressing labs to hold models back from the UK AI Security Institute, Anthropic bringing in Accenture as an evaluator, the FomoPeek App Store app hiding iOS kernel exploits, ShinyHunters' claimed FBI breach, and Nightmare Eclipse going public with identity and a CrowdStrike exploit.

    Cast: Ryan Naraine, Juan Andres Guerrero-Saade and Costin Raiu.

    Timestamps:

    0:00 Introductory banter

    1:57 The Last LABScon wrap-up

    9:35 TypeSafe AI's Jev and System One models

    26:18 Step-down transformers and lab economics

    30:58 Rogue OpenAI agents and the Transluce report

    41:40 Irregular and Gemini's test breakout

    49:28 Hacktron's OpenAI hack and the disclosure fight

    54:57 Costin as OpenAI CISO for a day

    1:05:44 Hugging Face defends itself with GLM 5.2

    1:17:08 What a home AI rig costs now

    1:30:02 White House vs. UK AISI pre-release testing

    1:36:52 FomoPeek kernel exploits in the App Store

    1:51:19 ShinyHunters claims an FBI breach

    2:02:40 Nightmare Eclipse unmasked
More Business News podcasts
About Three Buddy Problem
The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).
Podcast website

Listen to Three Buddy Problem, Receipts with Catherine Rampell and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features