Episode Archive

178 episodes of Three Buddy Problem since the first episode, which aired on December 6th, 2017.

  • Salt Typhoon IOCs, Google floats ‘cyber disruption unit’, WhatsApp 0-click

    August 29th, 2025  |  2 hrs 24 mins
    apt research, china, microsoft, nation-state, russia, zero-day

    Three Buddy Problem - Episode 60: We dissect a fresh multi-agency Salt Typhoon advisory (with IOCs and YARA rules!), why it landed late, why the wall of logos matters (and doesn’t), and what’s actually usable for defenders: new YARA, tool hashes, naming ambiguity across reports, the mention of Chinese vendors, and a Dutch note that smaller ISPs were hit.

    Plus, Costin details his hunting stack and philosophy (historic IOC/malware hoarding, fast pivots, and AI as analyst “wingman”) and a new Chinese APT report that may intersect with LightBasin and the murky PSOA world.

    We also debate Google’s proposed “cyber disruption unit” versus Microsoft’s DCU (legal vs. “ethical” takedowns, PR, and business models); react to Anthropic’s report on real attacker use of Claude; note Amazon’s APT29 watering-hole disruption; and close on a fresh WhatsApp-to-ImageIO zero-click chain and practical phone OPSEC.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • Zero-day reality check: iOS exploits, MAPP in China and the hack-back temptation

    August 22nd, 2025  |  2 hrs 32 mins
    apt research, cyberespionage, nation-state, ransomware, zero-day

    Three Buddy Problem - Episode 59: Apple drops another emergency iOS patch and we unpack what that “may have been exploited” language really means: zero-click chains, why notifications help but forensics don’t, and the uncomfortable truth that Lockdown Mode is increasingly the default for high-risk users. We connect the dots from ImageIO bugs to geopolitics, discuss who’s likely using these exploits, why Apple’s guidance stops short, and the practical playbook (ADP on, reboot often, reduce attack surface) that actually works.

    Plus, we debate Microsoft throttling MAPP access for Chinese vendors, the idea of “letters of marque” for cyber (outsourced offense: smart deterrent or Pandora’s box?), and dissect two case studies that blur APT and crimeware: PipeMagic’s CLFS zero-day and Russia-linked “Static Tundra” riding seven-year-old Cisco bugs.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • On AI’s future, security’s failures, and what comes next...

    August 15th, 2025  |  1 hr 57 mins
    ai, apt research, backdoors, nation-state, zero-day

    Three Buddy Problem - Episode 58: Indepth reaction to the Brandon Dixon episode, digging into what it’s really like to scale products inside a tech giant, navigate politics, and bring features to millions of machines. Plus, an exploration of the AI cybersecurity gold-rush, the promise and hype, and the gamble for startups versus the slow-moving advantage of incumbents.

    We revisit the Chinese "cyber militia" discussion and the looming AI “dot-com bubble,” the value of owning infrastructure, Nvidia and export controls, China’s manufacturing edge, and the geopolitics of supply chains.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • Live from Black Hat: Brandon Dixon parses the AI security hype

    August 7th, 2025  |  1 hr 30 mins
    ai, apt research, nation-state, zero-day

    Three Buddy Problem - Episode 57: Brandon Dixon (PassiveTotal/RiskIQ, Microsoft) leads a deep-dive into the collision of AI and cybersecurity. We tackle Google’s “Big Sleep” project, XBOW’s automation hype, the long-running tension between big tech ownership of critical security tools and the community’s need for open access.

    Plus, the future of SOC automation to AI-assisted pen testing, how agentic AI could transform cyber talent bottlenecks and operational inefficiencies, geopolitical debates over backdoors in GPUs and the strategic implications of China’s AI model development.

    Cast: Brandon Dixon, Juan Andres Guerrero-Saade and Ryan Naraine.

  • Rethinking APT Attribution: Dakota Cary on Chinese Contractors and Espionage-as-a-Service

    August 1st, 2025  |  1 hr 51 mins
    apt research, cyberespionage, nation-state, ransomware, zero-day

    Three Buddy Problem - Episode 56: China-focused researcher Dakota Cary joins the buddies to dig into China’s sprawling cyber ecosystem, from the HAFNIUM indictments and MSS tasking pipelines to the murky world of APT contractors and the ransomware hustle. We break down China’s “entrepreneurial” model of intelligence collection, why public visibility into these threat actors is so hard to get right, and how companies like Microsoft get caught in the geopolitical crossfire.

    Plus: a deep dive on suspected MAPP leaks and Sharepoint zero-days, Singapore targeted by extremely sophisticated China-nexus hacking group, soft censorship in corporate threat-intel, and whether the U.S. should rethink how it fills its intelligence gaps.

    Cast: Dakota Cary, Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • Microsoft Sharepoint security crisis: Faulty patches, Toolshell zero-days

    July 25th, 2025  |  1 hr 55 mins
    ai, apt research, nation-state, zero-day

    Three Buddy Problem - Episode 55: We dig into Microsoft's latest security nightmare: a SharePoint zero-day exploit chain from Pwn2Own Berlin becomes a full-blown security crisis, with Chinese nation-state actors exploiting vulnerabilities that Microsoft struggled to patch properly, leading to trivial bypasses and a cascade of new CVEs. The timeline is messy, the patches are faulty, and ransomware groups are lining up to join the party.

    We also revisit the ProPublica bombshell about Microsoft's "digital escorts" and U.S. government data exposure to Chinese adversaries and the company's "oops, we will stop" response. Plus, trusting Google's Big Sleep AI claims and a cautionary tale about AI agents gone rogue that wiped out a production database.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • Train brake hack, GRU sanctions, Wagner war crimes, Microsoft's Chinese ‘digital escorts’

    July 18th, 2025  |  1 hr 48 mins
    apt research, cyberwar, nation-state, zero-day

    Three Buddy Problem - Episode 54: Europol busted pro‑Russian hacktivist crew NoName 057(16), the Brits announce sanctions on Russia’s GRU cyber units, Wagner‑linked “war influencers” streamed atrocities from Africa, and fresh tech worries ranged from a $500 RF flaw that can hijack U.S. train brakes.

    Plus, ProPublica on Microsoft’s China‑based “digital escorts,” Google’s headline‑grabbing AI‑found SQLite zero‑day, and OpenAI’s new task‑running agents. Meanwhile, Ukraine’s hackers wiped a Russian drone maker, ransomware crippled a major vodka producer, and another Chrome zero‑day quietly underscored how routine critical exploits have become.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • How did China get Microsoft's zero-day exploits?

    July 10th, 2025  |  1 hr 49 mins
    apt research, cyberespionage, drone, nation-state, ransomware, zero-day

    Three Buddy Problem - Episode 53: We dig into news of the first-ever arrest of a Chinese intelligence-linked hacker in Italy, unpack the mystery behind HAFNIUM and how they somehow got their hands on the same Microsoft Exchange zero-days that researcher Orange Tsai discovered - was it coincidence, inside access, or something more sinister?

    Plus, China's massive cyber capabilities pipeline, ‘theCom’ teenagers arrested in the UK after ransomware binge, and spyware attacks against Russian organizations.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • Who’s hacking who? Ivanti 0-days in France, China outs 'Night Eagle' APT

    July 3rd, 2025  |  1 hr 34 mins
    apt research, cyberwarfare, exploits, nation-state, zero-day

    Three Buddy Problem - Episode 52: Fresh intelligence reports out of Europe and China: France’s ANSSI documents a string of Ivanti VPN zero-days ('Houken'), and Quanxin frames a stealth Microsoft Exchange-zero-day chain linked to a North American 'Night Eagle' threat actor. We dissect the technical bread-crumbs, questions the attribution math, and connects Houken to SentinelOne’s “Purple Haze” research.

    Plus, the FBI’s claim that China’s “Salt Typhoon” has been “contained,” Iran’s Nobitex crypto-exchange breach (Predatory Sparrow torches $90 million and leaks the source code), Iranian cyber capabilities and sanctions avoidance.

    Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.

  • Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, destructive bank hacks

    June 20th, 2025  |  3 hrs 7 mins
    apt research, cryptocurrency, cyberwar, nation-state, zero-day

    Three Buddy Problem - Episode 51: Former Immunity/Trail of Bits researcher Hamid Kashfi joins the buddies for a fast-moving tour of cyber activities in the Israel-Iran war. The crew unpacks who 'Predatory Sparrow' is, why Sepah Bank and the Nobitex crypto exchange were hit, and what a $90 million cryptocurrency burn really means. Plus, radar-blinding cyberattacks that paved the way for Israel’s air raid, the human cost of sudden ATM outages and unpaid salaries, and the puzzling “Code Breakers” data leak that preceded it all.

    Hamid shares on-the-ground context, the buddies debate whether cyber operations can sway a shooting war, and everyone tries to gauge Iran’s true offensive muscle under sanctions.

    Cast: Hamid Kashfi, Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.

  • Cyber flashpoints in Israel-Iran war, the 'magnet of threats', Mossad drone swarms

    June 13th, 2025  |  1 hr 51 mins
    apt research, cyberwar, nation-state, zero-day

    Three Buddy Problem - Episode 50: This week, we dissect cyber flashpoints in the Iran-Israel war, revisit the “magnet of threats” server in Iran that attracted APTs from multiple nation-states, and react to Israel's Mossad sneaking explosive drone swarms deep into Iran to support airstrikes.

    Plus, Stealth Falcon’s new WebDAV zero-day, SentinelOne’s brush with Chinese APTs, Citizen Lab’s forensic takedown of Paragon’s iPhone spyware, and the sneaky Meta/Yandex trick that links Android web browsing to app IDs.

    Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.

  • Mikko Hypponen talks drone warfare, APT naming schemes

    June 6th, 2025  |  1 hr 29 mins
    apt research, drones, nation-state, zero-day

    Three Buddy Problem - Episode 49: Cybersecurity veteran Mikko Hypponen joins the show to discuss the fast-changing life and times on NATO’s newest frontline, how Ukraine’s long-range “Spiderweb” drone swarms punched holes in Russian air bases, the cyber connections to the escalating drone warfare, and the coming wave of autonomous “killer robots”.

    Plus, news on Ukraine’s hack of bomber-maker Tupolev, the industry’s never-ending APT naming mess, iVerify’s newly disclosed iMessage zero-click bug, fresh Qualcomm GPU exploits still unpatched on Android devices, and Cellebrite’s purchase of Corellium.

    Cast: Costin Raiu, Ryan Naraine and Mikko Hypponen.

    • Juan Andres Guerrero-Saade is out this week at Sleuthcon.