Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats
July 31st, 2026
3 hrs 26 mins 39 secs
Tags
About this Episode
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies.
Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills.
Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Timestamps:
0:00 Sponsor - Thinkst Canary
1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team
5:23 Inside the NSA ‘Laundry Bear’ advisory
7:15 What does "half-click" mean?
9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence
12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress
17:05 Targeting Ukraine, US universities, and magnetic fusion research
19:34 How threat hunters actually build intuition
32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table
54:48 The dopamine hit of a real find and the deleted "never mind" messages
1:00:42 Magnets of threats: under 1% of customers ever see an APT
1:25:21 Getting detections into the product, and coordinating a release with NSA
1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox
2:17:45 The case for killing the CFAA and bricking vulnerable devices
2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark
Episode Links
- Transcript
- Greg Lesnewich | LinkedIn
- Proofpoint: TA488 Comes for Outlook with Another Half-Click Exploit
- TA488 Targets Zimbra Mailservers with Half-Click Exploits
- NSA: Russian APT Phishing Users of Zimbra
- Operation RoundPress Half-Click Webmail Zero-Days from TA458
- Operation RoundPress targeting high-value webmail servers
- Anthropic: Investigating three real-world incidents in our cybersecurity evaluations
- Hugging Face: A Technical Timeline of OpenAI incident
- Microsoft Intros MAI-Cyber-1-Flash inside MDASH
- Google Updates Threat Actor Naming System
- Bill Marczak: An Angry Spark, or a Triangle in Disguise?
- Gen: Chasing an Angry Spark
- Amazon identifies North Korean hacker group behind open-source supply chain attacks
- Dana (Donella) Meadows Lecture: Sustainable Systems
- Outliers - Malcolm Gladwell
- 5-Year Data Hack Disclosed by SMS Giant Syniverse
- Practical Malware Analysis book
- Top 1 Million Websites
- Thinkst Canary