Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cybersecurity software
January 16th, 2026
2 hrs 24 mins 36 secs
Tags
About this Episode
(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 81: We dissect New York Times reporting on the "precision" of US cyber operations in Venezuela, the competing narratives around offensive cyber capabilities and "letters of marque" for private hackers. Plus, a mysterious failed cyber attack on Poland's power grid, internet blackouts in Iran (with fascinating DNS telemetry revealing Chinese bank traffic and Russian website spikes), and news of China's ban on US/Israeli cybersecurity software.
We also cover Check Point's research on "VoidLink" (is it a successor to ShadowPad?), Microsoft's threat intelligence sharing practices, and Google Project Zero's disclosure of zero-click vulnerabilities caused by AI-powered transcription features.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Episode Links
- Transcript (unedited, AI-generated)
- Sponsor: Material Security
- Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities
- Massive cyberattack on Polish power system in December failed, minister says
- What happened in Poland? (Ruben Santamarta)
- Costin Raiu: What’s Happening in Iran?
- Verizon just had a big outage. Here’s what we know
- Beijing tells Chinese firms to stop using US and Israeli cyber products
- MS Patch Tuesday CVE-2026-20805 (exploited in the wild)
- VoidLink: The Cloud-Native Malware Framework
- Microsoft disrupts global cybercrime subscription service
- Project Zero: A 0-click exploit chain for the Pixel 9
- Joint statement from Google and Apple
- Sean Plankey re-nominated to lead CISA
- TLPBLACK
- DistrictCon Agenda
- Ekoparty Miami
- The Thinking Game (Full Documentary)