<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Mon, 13 Apr 2026 01:42:30 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Apt Research”</title>
    <link>https://securityconversations.fireside.fm/tags/apt%20research</link>
    <pubDate>Fri, 10 Apr 2026 13:30:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>The Claude Mythos, Project Glasswing Shockwave</title>
  <link>http://securityconversations.fireside.fm/claude-mythos-project-glasslight-shockwave</link>
  <guid isPermaLink="false">cc2c69d7-921c-4ac8-b034-4546ab0e3de8</guid>
  <pubDate>Fri, 10 Apr 2026 13:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cc2c69d7-921c-4ac8-b034-4546ab0e3de8.mp3" length="127570297" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals).

Three Buddy Problem - Episode 93: We discuss Anthropic's release of Claude Mythos Preview (an AI model so capable and dangerous they won't release it publicly) and debate the looming patching crisis, bug bounty extinction, possible US government nationalization of frontier labs, and why the NSA might not be thrilled about all this bug-fixing. 

Plus, North Korea's six-month Drift Protocol con job, APT28's retro DNS hijacking campaign, and Microsoft's driver signing mess hitting WireGuard and VeraCrypt.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.   

0:00 — Opening banter
1:36 — Claude Mythos Preview, Project Glasswing Announcement
7:22 — Parsing the Hype: Is Mythos Really a Step Change?
11:31 — Costin's Take: Is This All a PR Stunt?
17:10 — The Patching Problem: What Happens After the Zero Days?
28:11 — Bug Bounty Programs Under Threat from AI
33:37 — What Will Companies Actually Do With Mythos?
45:09 — Geopolitics: Where Is the US Government? Nationalization Talk
53:01 — Source Code vs. Binary: The Real Limits of Mythos
1:00:01 — Model Recklessness, Guardrails and the Psychiatrist
1:06:17 — Fortinet: Another Zero Day, No Patch, No IOCs
1:09:08 — North Korean Drift Protocol Heist: $285 Million Stolen
1:24:39 — SOHO Router DNS Hijacking: APT28 and FBI Disruption
1:32:34 — Microsoft Suspensions Hit WireGuard, VeraCrypt, OSR
1:38:49 — Shout-Outs, Conferences &amp; Closing
</itunes:subtitle>
  <itunes:duration>2:34:36</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/c/cc2c69d7-921c-4ac8-b034-4546ab0e3de8/cover.jpg?v=1"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem - Episode 93: We discuss Anthropic's release of Claude Mythos Preview (an AI model so capable and dangerous they won't release it publicly) and debate the looming patching crisis, bug bounty extinction, possible US government nationalization of frontier labs, and why the NSA might not be thrilled about all this bug-fixing. 
Plus, North Korea's six-month Drift Protocol con job, APT28's retro DNS hijacking campaign, and Microsoft's driver signing mess hitting WireGuard and VeraCrypt.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
00:00 — Opening banter
01:36 — Anthropic Mythos Preview + Project Glasswing
06:17 — USG reaction + Wall Street emergency meeting
10:54 — Mythos capabilities vs hype (technical reality check)
13:44 — PR stunt? Skepticism of Anthropic narrative
20:42 — The patching crisis + “defender advantage”
27:41 — Bug bounty model under threat from AI
33:37 — Mythos practical workflows
45:09 — Geopolitics, NSA angle, and nationalization discussion
01:40:18 — Fortinet zero-day + ongoing failures
01:42:39 — Drift Protocol heist ($285M) + long-term social engineering
01:44:07 — Revisiting XZ Utils / Jia Tan attribution
01:54:07 — Crypto security gaps + need for real CTI in blockchain
02:04:22 — APT28 DNS hijacking + router compromise campaign
02:18:57 — Microsoft driver signing meltdown + ecosystem impact
</description>
  <itunes:keywords>Anthropic, Claude, Mythos, Drift, North Korea, Jia Tan, xzutils, Solana, OpenAI, Codex, ChatGPT, Opus, Lumen, routers, FrostArmada, Project Glasswing, CISA, Microsoft, drivers, WireGuard, Iran, LUA, Cisco Talos</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.</em>)</p>

<p><strong>Three Buddy Problem - Episode 93</strong>: We discuss Anthropic&#39;s release of Claude Mythos Preview (an AI model so capable and dangerous they won&#39;t release it publicly) and debate the looming patching crisis, bug bounty extinction, possible US government nationalization of frontier labs, and why the NSA might not be thrilled about all this bug-fixing. </p>

<p>Plus, North Korea&#39;s six-month Drift Protocol con job, APT28&#39;s retro DNS hijacking campaign, and Microsoft&#39;s driver signing mess hitting WireGuard and VeraCrypt.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p>

<p>00:00 — Opening banter<br>
01:36 — Anthropic Mythos Preview + Project Glasswing<br>
06:17 — USG reaction + Wall Street emergency meeting<br>
10:54 — Mythos capabilities vs hype (technical reality check)<br>
13:44 — PR stunt? Skepticism of Anthropic narrative<br>
20:42 — The patching crisis + “defender advantage”<br>
27:41 — Bug bounty model under threat from AI<br>
33:37 — Mythos practical workflows<br>
45:09 — Geopolitics, NSA angle, and nationalization discussion<br>
01:40:18 — Fortinet zero-day + ongoing failures<br>
01:42:39 — Drift Protocol heist ($285M) + long-term social engineering<br>
01:44:07 — Revisiting XZ Utils / Jia Tan attribution<br>
01:54:07 — Crypto security gaps + need for real CTI in blockchain<br>
02:04:22 — APT28 DNS hijacking + router compromise campaign<br>
02:18:57 — Microsoft driver signing meltdown + ecosystem impact</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/14G3lVzHmbLtwhI8daMVzH-GWVj8PHI6CO1jVah1dW_g/edit?tab=t.0">Transcript</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Claude Mythos Preview " rel="nofollow" href="https://red.anthropic.com/2026/mythos-preview/">Claude Mythos Preview </a></li><li><a title="Accidental data leak reveals existence of Anthropic Mythos" rel="nofollow" href="https://archive.ph/oqiUD">Accidental data leak reveals existence of Anthropic Mythos</a></li><li><a title="Project Glasswing" rel="nofollow" href="https://www.anthropic.com/glasswing">Project Glasswing</a></li><li><a title="System Card: Claude Mythos Preview" rel="nofollow" href="https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf">System Card: Claude Mythos Preview</a></li><li><a title="Axios: OpenAI plans new product for cybersecurity use" rel="nofollow" href="https://www.axios.com/2026/04/09/openai-new-model-cyber-mythos-anthopic">Axios: OpenAI plans new product for cybersecurity use</a></li><li><a title="The $285M Drift Protocol Heist Was ‘6 Months in the Making’" rel="nofollow" href="https://decipher.sc/2026/04/05/the-285m-drift-protocol-heist-was-6-months-in-the-making/">The $285M Drift Protocol Heist Was ‘6 Months in the Making’</a></li><li><a title="Drift Protocol - Incident Report" rel="nofollow" href="https://x.com/DriftProtocol/status/2040611161121370409">Drift Protocol - Incident Report</a></li><li><a title="US Treasury to share threat-intel with crypto companies" rel="nofollow" href="https://home.treasury.gov/news/press-releases/sb0437">US Treasury to share threat-intel with crypto companies</a></li><li><a title="Fortinet customers confront actively exploited zero-day" rel="nofollow" href="https://cyberscoop.com/fortinet-forticlient-ems-zero-day-cve-2026-35616-hotfix-known-exploited/">Fortinet customers confront actively exploited zero-day</a></li><li><a title="Fortinet advisory: CVE-2026-35616 (exploited in the wild)" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">Fortinet advisory: CVE-2026-35616 (exploited in the wild)</a></li><li><a title="SOHO router compromise leads to DNS hijacking" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/">SOHO router compromise leads to DNS hijacking</a></li><li><a title="APT28 exploit routers to enable DNS hijacking operations" rel="nofollow" href="https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations">APT28 exploit routers to enable DNS hijacking operations</a></li><li><a title="DOJ Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled">DOJ Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military</a></li><li><a title="Lumen on &#39;Frost Armada&#39; Forest Blizzard DNS Hijacking" rel="nofollow" href="https://www.lumen.com/blog-and-news/en-us/frostarmada-forest-blizzard-dns-hijacking">Lumen on 'Frost Armada' Forest Blizzard DNS Hijacking</a></li><li><a title="WireGuard (Account Suspended)" rel="nofollow" href="https://news.ycombinator.com/item?id=47687884">WireGuard (Account Suspended)</a></li><li><a title="OSR on Microsoft Driver Signing Lockout" rel="nofollow" href="https://x.com/OSRDrivers/status/2042286973461709183">OSR on Microsoft Driver Signing Lockout</a></li><li><a title="Microsoft: Account Verification for Windows Hardware Program" rel="nofollow" href="https://techcommunity.microsoft.com/blog/hardware-dev-center/action-required-account-verification-for-windows-hardware-program-begins-october/4455452">Microsoft: Account Verification for Windows Hardware Program</a></li><li><a title="US Warns of Iran-Linked Cyber Hacks on Water, Energy Systems" rel="nofollow" href="https://archive.ph/nqUvK">US Warns of Iran-Linked Cyber Hacks on Water, Energy Systems</a></li><li><a title="CISA bulletin: Iranian Hackers Exploiting PLCs Across US Critical Infrastructure" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">CISA bulletin: Iranian Hackers Exploiting PLCs Across US Critical Infrastructure</a></li><li><a title="Watch S4: The Bob Lazar Story" rel="nofollow" href="https://www.amazon.com/S4-Lazar-Story-Luigi-Vendittelli/dp/B0GL9JHLGW">Watch S4: The Bob Lazar Story</a></li><li><a title="YouTube: Dan Guido at [un]prompted" rel="nofollow" href="https://www.youtube.com/watch?v=kgwvAyF7qsA">YouTube: Dan Guido at [un]prompted</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.</em>)</p>

<p><strong>Three Buddy Problem - Episode 93</strong>: We discuss Anthropic&#39;s release of Claude Mythos Preview (an AI model so capable and dangerous they won&#39;t release it publicly) and debate the looming patching crisis, bug bounty extinction, possible US government nationalization of frontier labs, and why the NSA might not be thrilled about all this bug-fixing. </p>

<p>Plus, North Korea&#39;s six-month Drift Protocol con job, APT28&#39;s retro DNS hijacking campaign, and Microsoft&#39;s driver signing mess hitting WireGuard and VeraCrypt.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p>

<p>00:00 — Opening banter<br>
01:36 — Anthropic Mythos Preview + Project Glasswing<br>
06:17 — USG reaction + Wall Street emergency meeting<br>
10:54 — Mythos capabilities vs hype (technical reality check)<br>
13:44 — PR stunt? Skepticism of Anthropic narrative<br>
20:42 — The patching crisis + “defender advantage”<br>
27:41 — Bug bounty model under threat from AI<br>
33:37 — Mythos practical workflows<br>
45:09 — Geopolitics, NSA angle, and nationalization discussion<br>
01:40:18 — Fortinet zero-day + ongoing failures<br>
01:42:39 — Drift Protocol heist ($285M) + long-term social engineering<br>
01:44:07 — Revisiting XZ Utils / Jia Tan attribution<br>
01:54:07 — Crypto security gaps + need for real CTI in blockchain<br>
02:04:22 — APT28 DNS hijacking + router compromise campaign<br>
02:18:57 — Microsoft driver signing meltdown + ecosystem impact</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/14G3lVzHmbLtwhI8daMVzH-GWVj8PHI6CO1jVah1dW_g/edit?tab=t.0">Transcript</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Claude Mythos Preview " rel="nofollow" href="https://red.anthropic.com/2026/mythos-preview/">Claude Mythos Preview </a></li><li><a title="Accidental data leak reveals existence of Anthropic Mythos" rel="nofollow" href="https://archive.ph/oqiUD">Accidental data leak reveals existence of Anthropic Mythos</a></li><li><a title="Project Glasswing" rel="nofollow" href="https://www.anthropic.com/glasswing">Project Glasswing</a></li><li><a title="System Card: Claude Mythos Preview" rel="nofollow" href="https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf">System Card: Claude Mythos Preview</a></li><li><a title="Axios: OpenAI plans new product for cybersecurity use" rel="nofollow" href="https://www.axios.com/2026/04/09/openai-new-model-cyber-mythos-anthopic">Axios: OpenAI plans new product for cybersecurity use</a></li><li><a title="The $285M Drift Protocol Heist Was ‘6 Months in the Making’" rel="nofollow" href="https://decipher.sc/2026/04/05/the-285m-drift-protocol-heist-was-6-months-in-the-making/">The $285M Drift Protocol Heist Was ‘6 Months in the Making’</a></li><li><a title="Drift Protocol - Incident Report" rel="nofollow" href="https://x.com/DriftProtocol/status/2040611161121370409">Drift Protocol - Incident Report</a></li><li><a title="US Treasury to share threat-intel with crypto companies" rel="nofollow" href="https://home.treasury.gov/news/press-releases/sb0437">US Treasury to share threat-intel with crypto companies</a></li><li><a title="Fortinet customers confront actively exploited zero-day" rel="nofollow" href="https://cyberscoop.com/fortinet-forticlient-ems-zero-day-cve-2026-35616-hotfix-known-exploited/">Fortinet customers confront actively exploited zero-day</a></li><li><a title="Fortinet advisory: CVE-2026-35616 (exploited in the wild)" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">Fortinet advisory: CVE-2026-35616 (exploited in the wild)</a></li><li><a title="SOHO router compromise leads to DNS hijacking" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/">SOHO router compromise leads to DNS hijacking</a></li><li><a title="APT28 exploit routers to enable DNS hijacking operations" rel="nofollow" href="https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations">APT28 exploit routers to enable DNS hijacking operations</a></li><li><a title="DOJ Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled">DOJ Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military</a></li><li><a title="Lumen on &#39;Frost Armada&#39; Forest Blizzard DNS Hijacking" rel="nofollow" href="https://www.lumen.com/blog-and-news/en-us/frostarmada-forest-blizzard-dns-hijacking">Lumen on 'Frost Armada' Forest Blizzard DNS Hijacking</a></li><li><a title="WireGuard (Account Suspended)" rel="nofollow" href="https://news.ycombinator.com/item?id=47687884">WireGuard (Account Suspended)</a></li><li><a title="OSR on Microsoft Driver Signing Lockout" rel="nofollow" href="https://x.com/OSRDrivers/status/2042286973461709183">OSR on Microsoft Driver Signing Lockout</a></li><li><a title="Microsoft: Account Verification for Windows Hardware Program" rel="nofollow" href="https://techcommunity.microsoft.com/blog/hardware-dev-center/action-required-account-verification-for-windows-hardware-program-begins-october/4455452">Microsoft: Account Verification for Windows Hardware Program</a></li><li><a title="US Warns of Iran-Linked Cyber Hacks on Water, Energy Systems" rel="nofollow" href="https://archive.ph/nqUvK">US Warns of Iran-Linked Cyber Hacks on Water, Energy Systems</a></li><li><a title="CISA bulletin: Iranian Hackers Exploiting PLCs Across US Critical Infrastructure" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">CISA bulletin: Iranian Hackers Exploiting PLCs Across US Critical Infrastructure</a></li><li><a title="Watch S4: The Bob Lazar Story" rel="nofollow" href="https://www.amazon.com/S4-Lazar-Story-Luigi-Vendittelli/dp/B0GL9JHLGW">Watch S4: The Bob Lazar Story</a></li><li><a title="YouTube: Dan Guido at [un]prompted" rel="nofollow" href="https://www.youtube.com/watch?v=kgwvAyF7qsA">YouTube: Dan Guido at [un]prompted</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>LLMs writing exploits, engineers losing skills, and a case for the generative OS</title>
  <link>http://securityconversations.fireside.fm/llm-exploit-engineer-skills-generative-os</link>
  <guid isPermaLink="false">3522bb83-8f21-4dff-abdd-01c9891be4d6</guid>
  <pubDate>Fri, 03 Apr 2026 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/3522bb83-8f21-4dff-abdd-01c9891be4d6.mp3" length="113808314" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK - High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)

Three Buddy Problem - Episode 92: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.   

0:00 – Introductory banter
2:00 – Costin's ransomware incident response work
3:30 – How attackers break in: Fortinet vulnerabilities everywhere
6:30 – Hunting for ransomware decryption keys 
9:00 – Breaking into ransomware C2s and monitoring leak sites
12:00 – The ransom payment debate: should you ever pay?
16:00 – Why "don't pay the ransom" is overgeneralized
21:00 – How ransomware gangs price their demands
24:00 – The AI-pilling of the security industry
28:30 – Nicholas Carlini, Ptacek, and "vulnerability research is cooked"
35:00 – Towards a generative-first operating system
41:00 – Code factories, trusted computing, and killing dependencies
48:00 – Microsoft and Apple's AI positioning
56:00 – Chris St. Myers' "Cognitive Rust Belt" essay
1:18:00 – Choice, The Matrix, and the illusion of control
1:38:00 – Supply chain attacks, North Korea, and dependency sprawl
</itunes:subtitle>
  <itunes:duration>2:19:56</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/3/3522bb83-8f21-4dff-abdd-01c9891be4d6/cover.jpg?v=1"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Three Buddy Problem - Episode 92: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
0:00 – Introductory banter
2:00 – Costin's ransomware incident response work
3:30 – How attackers break in: Fortinet vulnerabilities everywhere
6:30 – Hunting for ransomware decryption keys 
9:00 – Breaking into ransomware C2s and monitoring leak sites
12:00 – The ransom payment debate: should you ever pay?
16:00 – Why "don't pay the ransom" is overgeneralized
21:00 – How ransomware gangs price their demands
24:00 – The AI-pilling of the security industry
28:30 – Nicholas Carlini, Ptacek, and "vulnerability research is cooked"
35:00 – Towards a generative-first operating system
41:00 – Code factories, trusted computing, and killing dependencies
48:00 – Microsoft and Apple's AI positioning
56:00 – Chris St. Myers' "Cognitive Rust Belt" essay
1:18:00 – Choice, The Matrix, and the illusion of control
1:38:00 – Supply chain attacks, North Korea, and dependency sprawl
</description>
  <itunes:keywords>ransomware, decryption, russia, AI, Apple, iOS, Coruna, DarkSword, iOS 18, exploit kit, WhatApp, spyware, axios, npm, north korea, blue noroff, supply chain, Elastic, Thomas Ptacek, Calif, AI bugs, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 92</strong>: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else&#39;s code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p>

<p>0:00 – Introductory banter<br>
2:00 – Costin&#39;s ransomware incident response work<br>
3:30 – How attackers break in: Fortinet vulnerabilities everywhere<br>
6:30 – Hunting for ransomware decryption keys <br>
9:00 – Breaking into ransomware C2s and monitoring leak sites<br>
12:00 – The ransom payment debate: should you ever pay?<br>
16:00 – Why &quot;don&#39;t pay the ransom&quot; is overgeneralized<br>
21:00 – How ransomware gangs price their demands<br>
24:00 – The AI-pilling of the security industry<br>
28:30 – Nicholas Carlini, Ptacek, and &quot;vulnerability research is cooked&quot;<br>
35:00 – Towards a generative-first operating system<br>
41:00 – Code factories, trusted computing, and killing dependencies<br>
48:00 – Microsoft and Apple&#39;s AI positioning<br>
56:00 – Chris St. Myers&#39; &quot;Cognitive Rust Belt&quot; essay<br>
1:18:00 – Choice, The Matrix, and the illusion of control<br>
1:38:00 – Supply chain attacks, North Korea, and dependency sprawl</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/1U_trUjJ2pr3MFSPJocqpD5zzFoPCq7w_zRqUaqAcoD8/edit?tab=t.0#heading=h.l8bcya3t95p">Transcript</a></li><li><a title="Nicholas Carlini - Black-hat LLMs" rel="nofollow" href="https://www.youtube.com/watch?v=1sd26pWhfmg">Nicholas Carlini - Black-hat LLMs</a></li><li><a title="Ptacek: Vulnerability Research Is Cooked" rel="nofollow" href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/">Ptacek: Vulnerability Research Is Cooked</a></li><li><a title="Chris St Myers: Why Organizations Are Confusing Temporary Friction with Permanent Safety" rel="nofollow" href="https://www.sentinelone.com/blog/the-implementation-blind-spot-why-organizations-are-confusing-temporary-friction-with-permanent-safety/">Chris St Myers: Why Organizations Are Confusing Temporary Friction with Permanent Safety</a></li><li><a title="Dan Geer: Children of the Magenta" rel="nofollow" href="https://www.computer.org/csdl/magazine/sp/2015/05/msp2015050104/13rRUxASutL">Dan Geer: Children of the Magenta</a></li><li><a title="Calif: Month of AI-Discovered Bugs" rel="nofollow" href="https://blog.calif.io/p/mad-bugs-month-of-ai-discovered-bugs">Calif: Month of AI-Discovered Bugs</a></li><li><a title="Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell" rel="nofollow" href="https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd">Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell</a></li><li><a title="Internet Bug Bounty Pauses Bug Bounty Program " rel="nofollow" href="https://hackerone.com/ibb/policy_versions?change=3771829&amp;type=team">Internet Bug Bounty Pauses Bug Bounty Program </a></li><li><a title="Node.js Bug Bounty Program Paused Due to Loss of Funding" rel="nofollow" href="https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties">Node.js Bug Bounty Program Paused Due to Loss of Funding</a></li><li><a title="Elastic: How we caught the Axios supply chain attack" rel="nofollow" href="https://www.elastic.co/security-labs/how-we-caught-the-axios-supply-chain-attack">Elastic: How we caught the Axios supply chain attack</a></li><li><a title="Elastic tool: supply-chain-monitor " rel="nofollow" href="https://github.com/elastic/supply-chain-monitor">Elastic tool: supply-chain-monitor </a></li><li><a title="Apple Will Push Out Rare ‘Backported’ Patches to iOS 18 Users" rel="nofollow" href="https://archive.ph/lnKTe">Apple Will Push Out Rare ‘Backported’ Patches to iOS 18 Users</a></li><li><a title="WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware" rel="nofollow" href="https://thehackernews.com/2026/04/whatsapp-alerts-200-users-after-fake.html">WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware</a></li><li><a title="The Human-Machine Team" rel="nofollow" href="https://www.amazon.com/Human-Machine-Team-Artificial-Intelligence-Revolutionize/dp/B0948LGS3K">The Human-Machine Team</a></li><li><a title="Arsenal Recon Tool" rel="nofollow" href="https://arsenalrecon.com/additional-products">Arsenal Recon Tool</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 92</strong>: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else&#39;s code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p>

<p>0:00 – Introductory banter<br>
2:00 – Costin&#39;s ransomware incident response work<br>
3:30 – How attackers break in: Fortinet vulnerabilities everywhere<br>
6:30 – Hunting for ransomware decryption keys <br>
9:00 – Breaking into ransomware C2s and monitoring leak sites<br>
12:00 – The ransom payment debate: should you ever pay?<br>
16:00 – Why &quot;don&#39;t pay the ransom&quot; is overgeneralized<br>
21:00 – How ransomware gangs price their demands<br>
24:00 – The AI-pilling of the security industry<br>
28:30 – Nicholas Carlini, Ptacek, and &quot;vulnerability research is cooked&quot;<br>
35:00 – Towards a generative-first operating system<br>
41:00 – Code factories, trusted computing, and killing dependencies<br>
48:00 – Microsoft and Apple&#39;s AI positioning<br>
56:00 – Chris St. Myers&#39; &quot;Cognitive Rust Belt&quot; essay<br>
1:18:00 – Choice, The Matrix, and the illusion of control<br>
1:38:00 – Supply chain attacks, North Korea, and dependency sprawl</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/1U_trUjJ2pr3MFSPJocqpD5zzFoPCq7w_zRqUaqAcoD8/edit?tab=t.0#heading=h.l8bcya3t95p">Transcript</a></li><li><a title="Nicholas Carlini - Black-hat LLMs" rel="nofollow" href="https://www.youtube.com/watch?v=1sd26pWhfmg">Nicholas Carlini - Black-hat LLMs</a></li><li><a title="Ptacek: Vulnerability Research Is Cooked" rel="nofollow" href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/">Ptacek: Vulnerability Research Is Cooked</a></li><li><a title="Chris St Myers: Why Organizations Are Confusing Temporary Friction with Permanent Safety" rel="nofollow" href="https://www.sentinelone.com/blog/the-implementation-blind-spot-why-organizations-are-confusing-temporary-friction-with-permanent-safety/">Chris St Myers: Why Organizations Are Confusing Temporary Friction with Permanent Safety</a></li><li><a title="Dan Geer: Children of the Magenta" rel="nofollow" href="https://www.computer.org/csdl/magazine/sp/2015/05/msp2015050104/13rRUxASutL">Dan Geer: Children of the Magenta</a></li><li><a title="Calif: Month of AI-Discovered Bugs" rel="nofollow" href="https://blog.calif.io/p/mad-bugs-month-of-ai-discovered-bugs">Calif: Month of AI-Discovered Bugs</a></li><li><a title="Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell" rel="nofollow" href="https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd">Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell</a></li><li><a title="Internet Bug Bounty Pauses Bug Bounty Program " rel="nofollow" href="https://hackerone.com/ibb/policy_versions?change=3771829&amp;type=team">Internet Bug Bounty Pauses Bug Bounty Program </a></li><li><a title="Node.js Bug Bounty Program Paused Due to Loss of Funding" rel="nofollow" href="https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties">Node.js Bug Bounty Program Paused Due to Loss of Funding</a></li><li><a title="Elastic: How we caught the Axios supply chain attack" rel="nofollow" href="https://www.elastic.co/security-labs/how-we-caught-the-axios-supply-chain-attack">Elastic: How we caught the Axios supply chain attack</a></li><li><a title="Elastic tool: supply-chain-monitor " rel="nofollow" href="https://github.com/elastic/supply-chain-monitor">Elastic tool: supply-chain-monitor </a></li><li><a title="Apple Will Push Out Rare ‘Backported’ Patches to iOS 18 Users" rel="nofollow" href="https://archive.ph/lnKTe">Apple Will Push Out Rare ‘Backported’ Patches to iOS 18 Users</a></li><li><a title="WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware" rel="nofollow" href="https://thehackernews.com/2026/04/whatsapp-alerts-200-users-after-fake.html">WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware</a></li><li><a title="The Human-Machine Team" rel="nofollow" href="https://www.amazon.com/Human-Machine-Team-Artificial-Intelligence-Revolutionize/dp/B0948LGS3K">The Human-Machine Team</a></li><li><a title="Arsenal Recon Tool" rel="nofollow" href="https://arsenalrecon.com/additional-products">Arsenal Recon Tool</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Google's Cyber Disruption Unit; Coruna is Triangulation, US Bans Foreign-Made Routers</title>
  <link>http://securityconversations.fireside.fm/1</link>
  <guid isPermaLink="false">020fab1b-ad5d-4221-95a4-910623065a2d</guid>
  <pubDate>Sat, 28 Mar 2026 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/020fab1b-ad5d-4221-95a4-910623065a2d.mp3" length="129104025" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK - High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)

Three Buddy Problem - Episode 91: This week we dig into Google's new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines. 

Plus, VCs and the breathless AI hype, Apple's iOS 26.4 and silent patches, the FCC's ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  

0:00 Intro &amp; Pre-Show Banter
3:08 JAGS in San Francisco: RSAC week recap
6:05 Google Launches Cyber Disruption Unit — What's Actually New?
13:43 Why Separate Disruption Units Matter: ROI &amp; Budget Justification
29:11 Haroon Meer's RSA Reality Check: The AI Hype Machine
32:37 The VC Ponzi Cycle &amp; How Easy Money Hollowed Out Cybersecurity
47:32 ENT.ai &amp; Tenex AI Hackathon at RSAC
53:08 Kaspersky Links Corona Exploit Kit to Operation Triangulation
1:08:09 Trenchant Cleanup &amp; Lessons from Equation Group Burns
1:19:31 Apple iOS Patches, Hong Kong Device Passcode Law 
1:27:53 Handala Hacks FBI Director Kash Patel's Personal Gmail
1:37:32 LeakBase Admin "Chucky" Arrested in Russia — FSB Gets the Data
1:45:38 Supply Chain Attacks: TeamPCP Hits LiteLLM &amp; Trivy
2:04:34 FCC Bans Foreign-Made Routers — But What Do We Buy?</itunes:subtitle>
  <itunes:duration>2:32:24</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/0/020fab1b-ad5d-4221-95a4-910623065a2d/cover.jpg?v=1"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Three Buddy Problem - Episode 91: This week we dig into Google's new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines. 
Plus, VCs and the breathless AI hype, Apple's iOS 26.4 and silent patches, the FCC's ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
0:00 Intro &amp;amp; Pre-Show Banter
3:08 JAGS in San Francisco: RSAC week recap
6:05 Google Launches Cyber Disruption Unit — What's Actually New?
13:43 Why Separate Disruption Units Matter: ROI &amp;amp; Budget Justification
29:11 Haroon Meer's RSA Reality Check: The AI Hype Machine
32:37 The VC Ponzi Cycle &amp;amp; How Easy Money Hollowed Out Cybersecurity
47:32 ENT.ai &amp;amp; Tenex AI Hackathon at RSAC
53:08 Kaspersky Links Corona Exploit Kit to Operation Triangulation
1:08:09 Trenchant Cleanup &amp;amp; Lessons from Equation Group Burns
1:19:31 Apple iOS Patches, Hong Kong Device Passcode Law 
1:27:53 Handala Hacks FBI Director Kash Patel's Personal Gmail
1:37:32 LeakBase Admin "Chucky" Arrested in Russia — FSB Gets the Data
1:45:38 Supply Chain Attacks: TeamPCP Hits LiteLLM &amp;amp; Trivy
2:04:34 FCC Bans Foreign-Made Routers — But What Do We Buy? 
</description>
  <itunes:keywords>Apple, iOS, iOS 26.4, Coruna, Triangulation, Kaspersky, Trenchant, DarkSword, Hong Kong, Cisco, Oracle, zero-day, RSAC, AI hype, Stryker, Handala, Russia, Leakbase, LiteLLM, PyPI, Trivy, Checkmarx, Claude, OpenAI, Anthropic, Speagle, google, TP-Link, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 91</strong>: This week we dig into Google&#39;s new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines. </p>

<p>Plus, VCs and the breathless AI hype, Apple&#39;s iOS 26.4 and silent patches, the FCC&#39;s ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p>

<p>0:00 Intro &amp; Pre-Show Banter<br>
3:08 JAGS in San Francisco: RSAC week recap<br>
6:05 Google Launches Cyber Disruption Unit — What&#39;s Actually New?<br>
13:43 Why Separate Disruption Units Matter: ROI &amp; Budget Justification<br>
29:11 Haroon Meer&#39;s RSA Reality Check: The AI Hype Machine<br>
32:37 The VC Ponzi Cycle &amp; How Easy Money Hollowed Out Cybersecurity<br>
47:32 ENT.ai &amp; Tenex AI Hackathon at RSAC<br>
53:08 Kaspersky Links Corona Exploit Kit to Operation Triangulation<br>
1:08:09 Trenchant Cleanup &amp; Lessons from Equation Group Burns<br>
1:19:31 Apple iOS Patches, Hong Kong Device Passcode Law <br>
1:27:53 Handala Hacks FBI Director Kash Patel&#39;s Personal Gmail<br>
1:37:32 LeakBase Admin &quot;Chucky&quot; Arrested in Russia — FSB Gets the Data<br>
1:45:38 Supply Chain Attacks: TeamPCP Hits LiteLLM &amp; Trivy<br>
2:04:34 FCC Bans Foreign-Made Routers — But What Do We Buy?</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/11MJU1XFXzjukFrkVnS6FtxHCXwfhX-WcoxmQOhcjYzU/edit?tab=t.0">Transcript</a></li><li><a title="TLPBLACK Solutions" rel="nofollow" href="https://tlpblack.net/#solutions-pdns">TLPBLACK Solutions</a></li><li><a title="Google launches threat disruption unit at RSAC" rel="nofollow" href="https://www.nextgov.com/cybersecurity/2026/03/google-launches-threat-disruption-unit-stops-short-calling-it-offensive/412321/">Google launches threat disruption unit at RSAC</a></li><li><a title="White House downplays cyber ‘letters of marque’ speculation" rel="nofollow" href="https://therecord.media/offensive-cyber-white-house-hacking">White House downplays cyber ‘letters of marque’ speculation</a></li><li><a title="Haroon Meer on RSAC 2026" rel="nofollow" href="https://blog.thinkst.com/2026/03/rsac-infosec-themes-and-crumby-products.html">Haroon Meer on RSAC 2026</a></li><li><a title="Kaspersky on Coruna/Triangulation Connection" rel="nofollow" href="https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/">Kaspersky on Coruna/Triangulation Connection</a></li><li><a title="Apple Security Bulletin - iOS 26.4" rel="nofollow" href="https://support.apple.com/en-us/126792">Apple Security Bulletin - iOS 26.4</a></li><li><a title="Reverse engineering Apple’s silent security fixes" rel="nofollow" href="https://blog.calif.io/p/reverse-engineering-apples-silent">Reverse engineering Apple’s silent security fixes</a></li><li><a title="New Hong Kong Law on Phone/Laptop Passwords" rel="nofollow" href="https://hk.usconsulate.gov/security-alert-2026032601/">New Hong Kong Law on Phone/Laptop Passwords</a></li><li><a title="Iran-linked hackers breach FBI director&#39;s personal email" rel="nofollow" href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">Iran-linked hackers breach FBI director's personal email</a></li><li><a title="US DOJ Disrupts Iranian Cyber Enabled Psychological Operations" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations">US DOJ Disrupts Iranian Cyber Enabled Psychological Operations</a></li><li><a title="Official Statement on Stryker Network Disruption" rel="nofollow" href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html">Official Statement on Stryker Network Disruption</a></li><li><a title="Russia arrests Leakbase admin" rel="nofollow" href="https://tass.ru/proisshestviya/26879969">Russia arrests Leakbase admin</a></li><li><a title="Trivy ecosystem supply chain compromised (Advisory)" rel="nofollow" href="https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23">Trivy ecosystem supply chain compromised (Advisory)</a></li><li><a title="Self-propagating malware poisons open source software and wipes Iran-based machines" rel="nofollow" href="https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/">Self-propagating malware poisons open source software and wipes Iran-based machines</a></li><li><a title="New Malware Targets Users of Cobra DocGuard Software" rel="nofollow" href="https://www.security.com/threat-intelligence/speagle-cobradocguard-infostealer">New Malware Targets Users of Cobra DocGuard Software</a></li><li><a title="FCC bans &#39;foreign made&#39; consumer routers (PDF)" rel="nofollow" href="https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf">FCC bans 'foreign made' consumer routers (PDF)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 91</strong>: This week we dig into Google&#39;s new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines. </p>

<p>Plus, VCs and the breathless AI hype, Apple&#39;s iOS 26.4 and silent patches, the FCC&#39;s ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p>

<p>0:00 Intro &amp; Pre-Show Banter<br>
3:08 JAGS in San Francisco: RSAC week recap<br>
6:05 Google Launches Cyber Disruption Unit — What&#39;s Actually New?<br>
13:43 Why Separate Disruption Units Matter: ROI &amp; Budget Justification<br>
29:11 Haroon Meer&#39;s RSA Reality Check: The AI Hype Machine<br>
32:37 The VC Ponzi Cycle &amp; How Easy Money Hollowed Out Cybersecurity<br>
47:32 ENT.ai &amp; Tenex AI Hackathon at RSAC<br>
53:08 Kaspersky Links Corona Exploit Kit to Operation Triangulation<br>
1:08:09 Trenchant Cleanup &amp; Lessons from Equation Group Burns<br>
1:19:31 Apple iOS Patches, Hong Kong Device Passcode Law <br>
1:27:53 Handala Hacks FBI Director Kash Patel&#39;s Personal Gmail<br>
1:37:32 LeakBase Admin &quot;Chucky&quot; Arrested in Russia — FSB Gets the Data<br>
1:45:38 Supply Chain Attacks: TeamPCP Hits LiteLLM &amp; Trivy<br>
2:04:34 FCC Bans Foreign-Made Routers — But What Do We Buy?</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/11MJU1XFXzjukFrkVnS6FtxHCXwfhX-WcoxmQOhcjYzU/edit?tab=t.0">Transcript</a></li><li><a title="TLPBLACK Solutions" rel="nofollow" href="https://tlpblack.net/#solutions-pdns">TLPBLACK Solutions</a></li><li><a title="Google launches threat disruption unit at RSAC" rel="nofollow" href="https://www.nextgov.com/cybersecurity/2026/03/google-launches-threat-disruption-unit-stops-short-calling-it-offensive/412321/">Google launches threat disruption unit at RSAC</a></li><li><a title="White House downplays cyber ‘letters of marque’ speculation" rel="nofollow" href="https://therecord.media/offensive-cyber-white-house-hacking">White House downplays cyber ‘letters of marque’ speculation</a></li><li><a title="Haroon Meer on RSAC 2026" rel="nofollow" href="https://blog.thinkst.com/2026/03/rsac-infosec-themes-and-crumby-products.html">Haroon Meer on RSAC 2026</a></li><li><a title="Kaspersky on Coruna/Triangulation Connection" rel="nofollow" href="https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/">Kaspersky on Coruna/Triangulation Connection</a></li><li><a title="Apple Security Bulletin - iOS 26.4" rel="nofollow" href="https://support.apple.com/en-us/126792">Apple Security Bulletin - iOS 26.4</a></li><li><a title="Reverse engineering Apple’s silent security fixes" rel="nofollow" href="https://blog.calif.io/p/reverse-engineering-apples-silent">Reverse engineering Apple’s silent security fixes</a></li><li><a title="New Hong Kong Law on Phone/Laptop Passwords" rel="nofollow" href="https://hk.usconsulate.gov/security-alert-2026032601/">New Hong Kong Law on Phone/Laptop Passwords</a></li><li><a title="Iran-linked hackers breach FBI director&#39;s personal email" rel="nofollow" href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">Iran-linked hackers breach FBI director's personal email</a></li><li><a title="US DOJ Disrupts Iranian Cyber Enabled Psychological Operations" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations">US DOJ Disrupts Iranian Cyber Enabled Psychological Operations</a></li><li><a title="Official Statement on Stryker Network Disruption" rel="nofollow" href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html">Official Statement on Stryker Network Disruption</a></li><li><a title="Russia arrests Leakbase admin" rel="nofollow" href="https://tass.ru/proisshestviya/26879969">Russia arrests Leakbase admin</a></li><li><a title="Trivy ecosystem supply chain compromised (Advisory)" rel="nofollow" href="https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23">Trivy ecosystem supply chain compromised (Advisory)</a></li><li><a title="Self-propagating malware poisons open source software and wipes Iran-based machines" rel="nofollow" href="https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/">Self-propagating malware poisons open source software and wipes Iran-based machines</a></li><li><a title="New Malware Targets Users of Cobra DocGuard Software" rel="nofollow" href="https://www.security.com/threat-intelligence/speagle-cobradocguard-infostealer">New Malware Targets Users of Cobra DocGuard Software</a></li><li><a title="FCC bans &#39;foreign made&#39; consumer routers (PDF)" rel="nofollow" href="https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf">FCC bans 'foreign made' consumer routers (PDF)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>The greatest APT hunter of all time, Apple's exploit kit problem, Microsoft FedRAMP mess</title>
  <link>http://securityconversations.fireside.fm/sergey-mineev-apple-darksword-exploit-kit-fedramp-microsoft</link>
  <guid isPermaLink="false">3faf0dca-154f-4bf1-a297-a945ce9c457c</guid>
  <pubDate>Fri, 20 Mar 2026 13:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/3faf0dca-154f-4bf1-a297-a945ce9c457c.mp3" length="120657732" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Thinkst Canary. Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)

Three Buddy Problem - Episode 90: We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. 

Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple's responsibility to hundreds of millions of users on older iOS versions; the ProPublica Microsoft/FedRAMP bombshell, Interlock ransomware sitting on a Cisco zero-day, the White House AI policy framework, and Supermicro co-founder $2.5 billion AI chip smuggling bust.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:27:20</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/3/3faf0dca-154f-4bf1-a297-a945ce9c457c/cover.jpg?v=1"/>
  <description>(Presented by Thinkst Canary (https://canary.tools): Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 90: We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. 
Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple's responsibility to hundreds of millions of users on older iOS versions; the ProPublica Microsoft/FedRAMP bombshell, Interlock ransomware sitting on a Cisco zero-day, the White House AI policy framework, and Supermicro co-founder $2.5 billion AI chip smuggling bust.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Apple, iOS, exploit kit, Coruna, DarkSword, iVerify, Google, zero-day, AWS, Interlock, ransomware, AI policy, US Gov, Iran, Israel</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 90</strong>: We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. </p>

<p>Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple&#39;s responsibility to hundreds of millions of users on older iOS versions; the ProPublica Microsoft/FedRAMP bombshell, Interlock ransomware sitting on a Cisco zero-day, the White House AI policy framework, and Supermicro co-founder $2.5 billion AI chip smuggling bust.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript " rel="nofollow" href="https://docs.google.com/document/d/1omZagfRGkZZLy3O_t_YmBl_dfbXPQ03QjnFAM2Sw9XE/edit?tab=t.0">Transcript </a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/">Thinkst Canary</a></li><li><a title="Equation Group: The Crown Creator of Cyber-Espionage" rel="nofollow" href="https://www.kaspersky.com/about/press-releases/equation-group-the-crown-creator-of-cyber-espionage">Equation Group: The Crown Creator of Cyber-Espionage</a></li><li><a title="The Project Sauron APT" rel="nofollow" href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07190154/The-ProjectSauron-APT_research_KL.pdf">The Project Sauron APT</a></li><li><a title="Google: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain">Google: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors</a></li><li><a title="iVerify: Inside DarkSword - A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites" rel="nofollow" href="https://iverify.io/blog/darksword-ios-exploit-kit-explained">iVerify: Inside DarkSword - A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites</a></li><li><a title="Lookout: Attackers Wielding DarkSword Threaten iOS Users" rel="nofollow" href="https://www.lookout.com/threat-intelligence/article/darksword">Lookout: Attackers Wielding DarkSword Threaten iOS Users</a></li><li><a title="Apple statement on Coruna, DarkSword" rel="nofollow" href="https://support.apple.com/en-us/126776">Apple statement on Coruna, DarkSword</a></li><li><a title="Amazon discovers Interlock ransomware hitting enterprise firewalls" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/">Amazon discovers Interlock ransomware hitting enterprise firewalls</a></li><li><a title="Cisco Secure Firewall Management Center RCE Flaw" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">Cisco Secure Firewall Management Center RCE Flaw</a></li><li><a title="CISA Urges Endpoint Management System Hardening After Stryker Attack" rel="nofollow" href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization">CISA Urges Endpoint Management System Hardening After Stryker Attack</a></li><li><a title="Stryker statements on wiper network disruption" rel="nofollow" href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html">Stryker statements on wiper network disruption</a></li><li><a title="Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway." rel="nofollow" href="https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government">Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.</a></li><li><a title="White House Unveils National AI Legislative Framework" rel="nofollow" href="https://www.whitehouse.gov/articles/2026/03/president-donald-j-trump-unveils-national-ai-legislative-framework/">White House Unveils National AI Legislative Framework</a></li><li><a title="Supermicro Founder Charged with Diverting AI tech to China" rel="nofollow" href="https://www.justice.gov/opa/pr/three-charged-conspiring-unlawfully-divert-cutting-edge-us-artificial-intelligence">Supermicro Founder Charged with Diverting AI tech to China</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 90</strong>: We remember GReAT teammate Sergey Mineev, the legendary malware hunter behind discoveries like Equation Group and Project Sauron (Remsec), including stories about his methods and why he was the best to ever do it. </p>

<p>Plus, another in-the-wild iOS exploit kit discovery and a long overdue conversation about Apple&#39;s responsibility to hundreds of millions of users on older iOS versions; the ProPublica Microsoft/FedRAMP bombshell, Interlock ransomware sitting on a Cisco zero-day, the White House AI policy framework, and Supermicro co-founder $2.5 billion AI chip smuggling bust.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript " rel="nofollow" href="https://docs.google.com/document/d/1omZagfRGkZZLy3O_t_YmBl_dfbXPQ03QjnFAM2Sw9XE/edit?tab=t.0">Transcript </a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/">Thinkst Canary</a></li><li><a title="Equation Group: The Crown Creator of Cyber-Espionage" rel="nofollow" href="https://www.kaspersky.com/about/press-releases/equation-group-the-crown-creator-of-cyber-espionage">Equation Group: The Crown Creator of Cyber-Espionage</a></li><li><a title="The Project Sauron APT" rel="nofollow" href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07190154/The-ProjectSauron-APT_research_KL.pdf">The Project Sauron APT</a></li><li><a title="Google: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain">Google: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors</a></li><li><a title="iVerify: Inside DarkSword - A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites" rel="nofollow" href="https://iverify.io/blog/darksword-ios-exploit-kit-explained">iVerify: Inside DarkSword - A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites</a></li><li><a title="Lookout: Attackers Wielding DarkSword Threaten iOS Users" rel="nofollow" href="https://www.lookout.com/threat-intelligence/article/darksword">Lookout: Attackers Wielding DarkSword Threaten iOS Users</a></li><li><a title="Apple statement on Coruna, DarkSword" rel="nofollow" href="https://support.apple.com/en-us/126776">Apple statement on Coruna, DarkSword</a></li><li><a title="Amazon discovers Interlock ransomware hitting enterprise firewalls" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/">Amazon discovers Interlock ransomware hitting enterprise firewalls</a></li><li><a title="Cisco Secure Firewall Management Center RCE Flaw" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">Cisco Secure Firewall Management Center RCE Flaw</a></li><li><a title="CISA Urges Endpoint Management System Hardening After Stryker Attack" rel="nofollow" href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization">CISA Urges Endpoint Management System Hardening After Stryker Attack</a></li><li><a title="Stryker statements on wiper network disruption" rel="nofollow" href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html">Stryker statements on wiper network disruption</a></li><li><a title="Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway." rel="nofollow" href="https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government">Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.</a></li><li><a title="White House Unveils National AI Legislative Framework" rel="nofollow" href="https://www.whitehouse.gov/articles/2026/03/president-donald-j-trump-unveils-national-ai-legislative-framework/">White House Unveils National AI Legislative Framework</a></li><li><a title="Supermicro Founder Charged with Diverting AI tech to China" rel="nofollow" href="https://www.justice.gov/opa/pr/three-charged-conspiring-unlawfully-divert-cutting-edge-us-artificial-intelligence">Supermicro Founder Charged with Diverting AI tech to China</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Handala wiper attacks, APT28 implant devs are back, Signal's verification problems</title>
  <link>http://securityconversations.fireside.fm/handala-wiper-stryker-apt28-signal-whatsapp-coruna-patches</link>
  <guid isPermaLink="false">21fe7ed6-897b-4dee-a445-18a9deab022a</guid>
  <pubDate>Fri, 13 Mar 2026 17:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/21fe7ed6-897b-4dee-a445-18a9deab022a.mp3" length="85654180" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK - High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)

Three Buddy Problem - Episode 89: We discuss Iran hacktivist group 'Handala' wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran's cyber retaliation is as scary as the headlines suggest.

Plus, ESET's discovery that Russia's APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit's proliferation chain.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>1:44:00</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/21fe7ed6-897b-4dee-a445-18a9deab022a/cover.jpg?v=1"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Three Buddy Problem - Episode 89: We discuss Iran hacktivist group 'Handala' wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran's cyber retaliation is as scary as the headlines suggest.
Plus, ESET's discovery that Russia's APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit's proliferation chain.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>russia, MIVD, AIVD, Signal, WhatsApp, Stryker, Iran, Israel, wiper, Handala, cyberwarfare, cyber strategy, Poland, nuclear, Apple, Coruna, Trenchant, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 89</strong>: We discuss Iran hacktivist group &#39;Handala&#39; wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran&#39;s cyber retaliation is as scary as the headlines suggest.</p>

<p>Plus, ESET&#39;s discovery that Russia&#39;s APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit&#39;s proliferation chain.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (raw, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1zhtku2XeCIhpAs7pa_p34-Rypy9WzyTdZc-pyyx6cTc/edit?tab=t.0">Transcript (raw, AI-generated)</a></li><li><a title="TLPBLACK Solutions" rel="nofollow" href="https://tlpblack.net/#solutions">TLPBLACK Solutions</a></li><li><a title="Kim Zetter: Iranian Hacktivists Strike Medical Device Maker Stryker in &quot;Severe&quot; Attack that Wiped Systems" rel="nofollow" href="https://www.zetter-zeroday.com/iranian-hacktivists-strike-medical-device-maker-stryker-in-severe-attack-that-wiped-systems/">Kim Zetter: Iranian Hacktivists Strike Medical Device Maker Stryker in "Severe" Attack that Wiped Systems</a></li><li><a title="Stryker Cyberattack Adds to Fears of New Front in Iran War" rel="nofollow" href="https://www.nytimes.com/2026/03/12/world/middleeast/stryker-iran-cyberattack.html">Stryker Cyberattack Adds to Fears of New Front in Iran War</a></li><li><a title="Bloomberg: Cyberattack Hits Stryker; Pro-Iran Group Claims Credit" rel="nofollow" href="https://archive.ph/7wpe7">Bloomberg: Cyberattack Hits Stryker; Pro-Iran Group Claims Credit</a></li><li><a title="Who is Handala? (Malpedia)" rel="nofollow" href="https://malpedia.caad.fkie.fraunhofer.de/actor/handala">Who is Handala? (Malpedia)</a></li><li><a title="Palo Alto: Increased Risk of Wiper Attacks" rel="nofollow" href="https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/">Palo Alto: Increased Risk of Wiper Attacks</a></li><li><a title="CISA Advisories on Iran State-Sponsored Cyber Threat" rel="nofollow" href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA Advisories on Iran State-Sponsored Cyber Threat</a></li><li><a title="Russia state actors targets Signal and WhatsApp accounts" rel="nofollow" href="https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign">Russia state actors targets Signal and WhatsApp accounts</a></li><li><a title="Dutch intel report on Signal, WhatsApp targeting" rel="nofollow" href="https://drive.google.com/file/d/1ZWvYkM_09GULHogLSlXA4Yb8PPlRfnBP/view">Dutch intel report on Signal, WhatsApp targeting</a></li><li><a title="Signal responds to Dutch Intel report" rel="nofollow" href="https://bsky.app/profile/signal.org/post/3mgnap76pnk2a">Signal responds to Dutch Intel report</a></li><li><a title="ESET: Resurgence of one of Russia’s most notorious APT groups" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/">ESET: Resurgence of one of Russia’s most notorious APT groups</a></li><li><a title="Poland says foiled cyberattack on nuclear centre may have come from Iran" rel="nofollow" href="https://www.reuters.com/world/poland-says-foiled-cyberattack-nuclear-centre-may-have-come-iran-2026-03-12/">Poland says foiled cyberattack on nuclear centre may have come from Iran</a></li><li><a title="Apple ships iOS 16.7.15 to cover &#39;Coruna&#39; exploits" rel="nofollow" href="https://support.apple.com/en-us/126646">Apple ships iOS 16.7.15 to cover 'Coruna' exploits</a></li><li><a title="Apple iOS 15.8.7 covers &#39;Coruna&#39; exploit kit" rel="nofollow" href="https://support.apple.com/en-us/126632">Apple iOS 15.8.7 covers 'Coruna' exploit kit</a></li><li><a title="Detection Engineering #148" rel="nofollow" href="https://www.detectionengineering.net/p/dew-148-detection-pipeline-maturity">Detection Engineering #148</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li><li><a title="Ekoparty Miami (May 21-22, 2026)" rel="nofollow" href="https://ekoparty.org/miami/">Ekoparty Miami (May 21-22, 2026)</a></li><li><a title="PIVOTcon Agenda" rel="nofollow" href="https://pivotcon.org/#agenda">PIVOTcon Agenda</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 89</strong>: We discuss Iran hacktivist group &#39;Handala&#39; wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran&#39;s cyber retaliation is as scary as the headlines suggest.</p>

<p>Plus, ESET&#39;s discovery that Russia&#39;s APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit&#39;s proliferation chain.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (raw, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1zhtku2XeCIhpAs7pa_p34-Rypy9WzyTdZc-pyyx6cTc/edit?tab=t.0">Transcript (raw, AI-generated)</a></li><li><a title="TLPBLACK Solutions" rel="nofollow" href="https://tlpblack.net/#solutions">TLPBLACK Solutions</a></li><li><a title="Kim Zetter: Iranian Hacktivists Strike Medical Device Maker Stryker in &quot;Severe&quot; Attack that Wiped Systems" rel="nofollow" href="https://www.zetter-zeroday.com/iranian-hacktivists-strike-medical-device-maker-stryker-in-severe-attack-that-wiped-systems/">Kim Zetter: Iranian Hacktivists Strike Medical Device Maker Stryker in "Severe" Attack that Wiped Systems</a></li><li><a title="Stryker Cyberattack Adds to Fears of New Front in Iran War" rel="nofollow" href="https://www.nytimes.com/2026/03/12/world/middleeast/stryker-iran-cyberattack.html">Stryker Cyberattack Adds to Fears of New Front in Iran War</a></li><li><a title="Bloomberg: Cyberattack Hits Stryker; Pro-Iran Group Claims Credit" rel="nofollow" href="https://archive.ph/7wpe7">Bloomberg: Cyberattack Hits Stryker; Pro-Iran Group Claims Credit</a></li><li><a title="Who is Handala? (Malpedia)" rel="nofollow" href="https://malpedia.caad.fkie.fraunhofer.de/actor/handala">Who is Handala? (Malpedia)</a></li><li><a title="Palo Alto: Increased Risk of Wiper Attacks" rel="nofollow" href="https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/">Palo Alto: Increased Risk of Wiper Attacks</a></li><li><a title="CISA Advisories on Iran State-Sponsored Cyber Threat" rel="nofollow" href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA Advisories on Iran State-Sponsored Cyber Threat</a></li><li><a title="Russia state actors targets Signal and WhatsApp accounts" rel="nofollow" href="https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign">Russia state actors targets Signal and WhatsApp accounts</a></li><li><a title="Dutch intel report on Signal, WhatsApp targeting" rel="nofollow" href="https://drive.google.com/file/d/1ZWvYkM_09GULHogLSlXA4Yb8PPlRfnBP/view">Dutch intel report on Signal, WhatsApp targeting</a></li><li><a title="Signal responds to Dutch Intel report" rel="nofollow" href="https://bsky.app/profile/signal.org/post/3mgnap76pnk2a">Signal responds to Dutch Intel report</a></li><li><a title="ESET: Resurgence of one of Russia’s most notorious APT groups" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/">ESET: Resurgence of one of Russia’s most notorious APT groups</a></li><li><a title="Poland says foiled cyberattack on nuclear centre may have come from Iran" rel="nofollow" href="https://www.reuters.com/world/poland-says-foiled-cyberattack-nuclear-centre-may-have-come-iran-2026-03-12/">Poland says foiled cyberattack on nuclear centre may have come from Iran</a></li><li><a title="Apple ships iOS 16.7.15 to cover &#39;Coruna&#39; exploits" rel="nofollow" href="https://support.apple.com/en-us/126646">Apple ships iOS 16.7.15 to cover 'Coruna' exploits</a></li><li><a title="Apple iOS 15.8.7 covers &#39;Coruna&#39; exploit kit" rel="nofollow" href="https://support.apple.com/en-us/126632">Apple iOS 15.8.7 covers 'Coruna' exploit kit</a></li><li><a title="Detection Engineering #148" rel="nofollow" href="https://www.detectionengineering.net/p/dew-148-detection-pipeline-maturity">Detection Engineering #148</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li><li><a title="Ekoparty Miami (May 21-22, 2026)" rel="nofollow" href="https://ekoparty.org/miami/">Ekoparty Miami (May 21-22, 2026)</a></li><li><a title="PIVOTcon Agenda" rel="nofollow" href="https://pivotcon.org/#agenda">PIVOTcon Agenda</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Trenchant, Peter Williams, and the proliferation of a Shadow Brokers-level iOS exploit framework</title>
  <link>http://securityconversations.fireside.fm/trenchant-peter-williams-coruna-ios-exploit-framework</link>
  <guid isPermaLink="false">502a67da-c82e-4e95-bfae-642c47b5faee</guid>
  <pubDate>Fri, 06 Mar 2026 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/502a67da-c82e-4e95-bfae-642c47b5faee.mp3" length="94165630" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Thinkst Canary. Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)

Three Buddy Problem - Episode 88: We unpack the fallout from public documentation of the Coruna iOS exploit kit, the likely connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use, and the widening use of zero-days by surveillance vendors and cybercriminals.

Plus, fresh signs of cyber-warfare activity tied to Iran and Israel, the FBI’s disclosure of a breach affecting internal surveillance systems, and the latest debate over AI, security tooling, and Anthropic’s public stumbles.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>1:59:43</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/5/502a67da-c82e-4e95-bfae-642c47b5faee/cover.jpg?v=1"/>
  <description>(Presented by Thinkst Canary (https://canary.tools): Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 88: We unpack the fallout from public documentation of the Coruna iOS exploit kit, the likely connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use, and the widening use of zero-days by surveillance vendors and cybercriminals.
Plus, fresh signs of cyber-warfare activity tied to Iran and Israel, the FBI’s disclosure of a breach affecting internal surveillance systems, and the latest debate over AI, security tooling, and Anthropic’s public stumbles.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Peter Williams, Trenchant, Apple, iOS, Trenchant, iVerify, exploit kit, condor, FBI, San Bernardino, zero-days, Kaspersky, surveillance, Israel, Iran, cyberwar, Anthropic, OpenAI, Aardvark, Codex</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 88</strong>: We unpack the fallout from public documentation of the Coruna iOS exploit kit, the likely connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use, and the widening use of zero-days by surveillance vendors and cybercriminals.</p>

<p>Plus, fresh signs of cyber-warfare activity tied to Iran and Israel, the FBI’s disclosure of a breach affecting internal surveillance systems, and the latest debate over AI, security tooling, and Anthropic’s public stumbles.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (raw, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1hjqvWGMuFA7K5oQ5ZWC8ZbMRg9sHsHYXEAi-liB2d9w/edit?usp=sharing">Transcript (raw, AI-generated)</a></li><li><a title="Thinkst Canary (how it works)" rel="nofollow" href="https://canary.tools/#how-it-works">Thinkst Canary (how it works)</a></li><li><a title="Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit">Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit</a></li><li><a title="iVerify Details First Known Mass iOS Attack" rel="nofollow" href="https://iverify.io/press-releases/first-known-mass-ios-attack">iVerify Details First Known Mass iOS Attack</a></li><li><a title="Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery" rel="nofollow" href="https://securityconversations.com/episode/matthias-frielingsdorf-on-the-mysterious-coruna-ios-exploit-kit-discovery/">Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery</a></li><li><a title="Matthias Frielingsdorf on Coruna (raw transcript)" rel="nofollow" href="https://docs.google.com/document/d/192CYhxiWAGXdhU7EEYB2SXLUq24f1E03/edit">Matthias Frielingsdorf on Coruna (raw transcript)</a></li><li><a title="Coruna-related hashes on VirusTotal" rel="nofollow" href="https://x.com/Now_on_VT/status/2029887800909156681">Coruna-related hashes on VirusTotal</a></li><li><a title="Kaspersky: No signs Coruna iPhone exploit kit made by US" rel="nofollow" href="https://www.theregister.com/2026/03/04/kaspersky_dismisses_claims_that_coruna/">Kaspersky: No signs Coruna iPhone exploit kit made by US</a></li><li><a title="Azimuth unlocked the San Bernardino shooter’s iPhone for the FBI" rel="nofollow" href="https://www.washingtonpost.com/technology/2021/04/14/azimuth-san-bernardino-apple-iphone-fbi/">Azimuth unlocked the San Bernardino shooter’s iPhone for the FBI</a></li><li><a title="2025 Zero-Days in Review (Google)" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">2025 Zero-Days in Review (Google)</a></li><li><a title="FBI investigating ‘suspicious’ cyber activities on critical surveillance network" rel="nofollow" href="https://edition.cnn.com/2026/03/05/politics/fbi-investigating-cyber-breach-critical-surveillance-network?cid=ios_app">FBI investigating ‘suspicious’ cyber activities on critical surveillance network</a></li><li><a title="Iranian Hacking Groups Go Dark Amid US, Israeli Military Strikes" rel="nofollow" href="https://archive.ph/KLQSf">Iranian Hacking Groups Go Dark Amid US, Israeli Military Strikes</a></li><li><a title="Interplay between Iranian Targeting of IP Cameras and Physical Warfare" rel="nofollow" href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/">Interplay between Iranian Targeting of IP Cameras and Physical Warfare</a></li><li><a title="Israel says it knocked out Iran’s cyber warfare headquarters" rel="nofollow" href="https://archive.ph/4IUgU">Israel says it knocked out Iran’s cyber warfare headquarters</a></li><li><a title="Amazon Bahrain facility targeted for U.S. military support" rel="nofollow" href="https://www.cnbc.com/2026/03/04/amazon-bahrain-data-centers-targeted-iran-drone-strike.html">Amazon Bahrain facility targeted for U.S. military support</a></li><li><a title="Full transcript of Anthropic CEO Dario Amodei interview" rel="nofollow" href="https://www.cbsnews.com/news/anthropic-ceo-dario-amodei-full-transcript/">Full transcript of Anthropic CEO Dario Amodei interview</a></li><li><a title="Codex Security (formerly Aardvark) now in research preview" rel="nofollow" href="https://openai.com/index/codex-security-now-in-research-preview/">Codex Security (formerly Aardvark) now in research preview</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 88</strong>: We unpack the fallout from public documentation of the Coruna iOS exploit kit, the likely connection to the Peter Williams/Trenchant exploit sale to Russians, how it slipped from government hands into criminal use, and the widening use of zero-days by surveillance vendors and cybercriminals.</p>

<p>Plus, fresh signs of cyber-warfare activity tied to Iran and Israel, the FBI’s disclosure of a breach affecting internal surveillance systems, and the latest debate over AI, security tooling, and Anthropic’s public stumbles.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (raw, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1hjqvWGMuFA7K5oQ5ZWC8ZbMRg9sHsHYXEAi-liB2d9w/edit?usp=sharing">Transcript (raw, AI-generated)</a></li><li><a title="Thinkst Canary (how it works)" rel="nofollow" href="https://canary.tools/#how-it-works">Thinkst Canary (how it works)</a></li><li><a title="Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit">Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit</a></li><li><a title="iVerify Details First Known Mass iOS Attack" rel="nofollow" href="https://iverify.io/press-releases/first-known-mass-ios-attack">iVerify Details First Known Mass iOS Attack</a></li><li><a title="Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery" rel="nofollow" href="https://securityconversations.com/episode/matthias-frielingsdorf-on-the-mysterious-coruna-ios-exploit-kit-discovery/">Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery</a></li><li><a title="Matthias Frielingsdorf on Coruna (raw transcript)" rel="nofollow" href="https://docs.google.com/document/d/192CYhxiWAGXdhU7EEYB2SXLUq24f1E03/edit">Matthias Frielingsdorf on Coruna (raw transcript)</a></li><li><a title="Coruna-related hashes on VirusTotal" rel="nofollow" href="https://x.com/Now_on_VT/status/2029887800909156681">Coruna-related hashes on VirusTotal</a></li><li><a title="Kaspersky: No signs Coruna iPhone exploit kit made by US" rel="nofollow" href="https://www.theregister.com/2026/03/04/kaspersky_dismisses_claims_that_coruna/">Kaspersky: No signs Coruna iPhone exploit kit made by US</a></li><li><a title="Azimuth unlocked the San Bernardino shooter’s iPhone for the FBI" rel="nofollow" href="https://www.washingtonpost.com/technology/2021/04/14/azimuth-san-bernardino-apple-iphone-fbi/">Azimuth unlocked the San Bernardino shooter’s iPhone for the FBI</a></li><li><a title="2025 Zero-Days in Review (Google)" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">2025 Zero-Days in Review (Google)</a></li><li><a title="FBI investigating ‘suspicious’ cyber activities on critical surveillance network" rel="nofollow" href="https://edition.cnn.com/2026/03/05/politics/fbi-investigating-cyber-breach-critical-surveillance-network?cid=ios_app">FBI investigating ‘suspicious’ cyber activities on critical surveillance network</a></li><li><a title="Iranian Hacking Groups Go Dark Amid US, Israeli Military Strikes" rel="nofollow" href="https://archive.ph/KLQSf">Iranian Hacking Groups Go Dark Amid US, Israeli Military Strikes</a></li><li><a title="Interplay between Iranian Targeting of IP Cameras and Physical Warfare" rel="nofollow" href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/">Interplay between Iranian Targeting of IP Cameras and Physical Warfare</a></li><li><a title="Israel says it knocked out Iran’s cyber warfare headquarters" rel="nofollow" href="https://archive.ph/4IUgU">Israel says it knocked out Iran’s cyber warfare headquarters</a></li><li><a title="Amazon Bahrain facility targeted for U.S. military support" rel="nofollow" href="https://www.cnbc.com/2026/03/04/amazon-bahrain-data-centers-targeted-iran-drone-strike.html">Amazon Bahrain facility targeted for U.S. military support</a></li><li><a title="Full transcript of Anthropic CEO Dario Amodei interview" rel="nofollow" href="https://www.cbsnews.com/news/anthropic-ceo-dario-amodei-full-transcript/">Full transcript of Anthropic CEO Dario Amodei interview</a></li><li><a title="Codex Security (formerly Aardvark) now in research preview" rel="nofollow" href="https://openai.com/index/codex-security-now-in-research-preview/">Codex Security (formerly Aardvark) now in research preview</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery</title>
  <link>http://securityconversations.fireside.fm/matthias-frielingsdorf-coruna-ios-exploit-kit</link>
  <guid isPermaLink="false">7669e3ee-6fd7-484c-a56f-bb6abb9f9207</guid>
  <pubDate>Thu, 05 Mar 2026 16:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7669e3ee-6fd7-484c-a56f-bb6abb9f9207.mp3" length="34892689" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK - High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)

Matthias Frielingsdorf (co-founder and VP of Research at iVerify) joins the show to discuss the mysterious US government connection to 'Coruna', an iOS exploit kit fitted with 23 exploits across five full chains targeting iPhones iOS 13 through 17.2.1. 

We talk about a "gut feeling" connecting this to the L3 Trenchant/Peter Williams exploit sale scandal, how a nation-state-grade exploit kit ended up in the hands of a Chinese cybercrime group chasing crypto wallets, and what it means that criminal organizations are now deploying iPhone zero-days at scale. 

Matthias walks through what iVerify can and can't do on Apple's locked-down platform, why he thinks Apple needs to give defenders more access, the Lockdown Mode debate, the thorny issue of sample sharing in the research community, and practical advice for everyday iPhone users facing a threat landscape that just got a lot more complicated.</itunes:subtitle>
  <itunes:duration>39:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7669e3ee-6fd7-484c-a56f-bb6abb9f9207/cover.jpg?v=4"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Matthias Frielingsdorf (co-founder and VP of Research at iVerify) joins the show to discuss the mysterious US government connection to 'Coruna', an iOS exploit kit fitted with 23 exploits across five full chains targeting iPhones iOS 13 through 17.2.1. 
We talk about a "gut feeling" connecting this to the L3 Trenchant/Peter Williams exploit sale scandal, how a nation-state-grade exploit kit ended up in the hands of a Chinese cybercrime group chasing crypto wallets, and what it means that criminal organizations are now deploying iPhone zero-days at scale. 
Matthias walks through what iVerify can and can't do on Apple's locked-down platform, why he thinks Apple needs to give defenders more access, the Lockdown Mode debate, the thorny issue of sample sharing in the research community, and practical advice for everyday iPhone users facing a threat landscape that just got a lot more complicated.
</description>
  <itunes:keywords>coruna, google, ios, apple, iphone, lockdown mode, peter williams, trenchant, exploit kit, china, russia, EDR, malware</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p>Matthias Frielingsdorf (co-founder and VP of Research at iVerify) joins the show to discuss the mysterious US government connection to &#39;Coruna&#39;, an iOS exploit kit fitted with 23 exploits across five full chains targeting iPhones iOS 13 through 17.2.1. </p>

<p>We talk about a &quot;gut feeling&quot; connecting this to the L3 Trenchant/Peter Williams exploit sale scandal, how a nation-state-grade exploit kit ended up in the hands of a Chinese cybercrime group chasing crypto wallets, and what it means that criminal organizations are now deploying iPhone zero-days at scale. </p>

<p>Matthias walks through what iVerify can and can&#39;t do on Apple&#39;s locked-down platform, why he thinks Apple needs to give defenders more access, the Lockdown Mode debate, the thorny issue of sample sharing in the research community, and practical advice for everyday iPhone users facing a threat landscape that just got a lot more complicated.</p><p>Links:</p><ul><li><a title="Raw Transcript" rel="nofollow" href="https://docs.google.com/document/d/192CYhxiWAGXdhU7EEYB2SXLUq24f1E03/edit">Raw Transcript</a></li><li><a title="Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit">Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit</a></li><li><a title="iVerify Details First Known Mass iOS Attack" rel="nofollow" href="https://iverify.io/press-releases/first-known-mass-ios-attack">iVerify Details First Known Mass iOS Attack</a></li><li><a title="Coruna: Inside the Nation-State-Grade iOS Exploit Kit (iVerify)" rel="nofollow" href="https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking">Coruna: Inside the Nation-State-Grade iOS Exploit Kit (iVerify)</a></li><li><a title="Wired: A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals" rel="nofollow" href="https://archive.ph/r7jGc">Wired: A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals</a></li><li><a title="Lockdown Mode or Nothing " rel="nofollow" href="https://www.youtube.com/watch?v=fAhTPMmvrB0">Lockdown Mode or Nothing </a></li><li><a title="Zero-day reality check: iOS exploitation " rel="nofollow" href="https://www.youtube.com/watch?v=YTRQ56n0yHA">Zero-day reality check: iOS exploitation </a></li><li><a title="About Lockdown Mode (Apple)" rel="nofollow" href="https://support.apple.com/en-us/105120">About Lockdown Mode (Apple)</a></li><li><a title="Charlie Miller on hacking iPhones, Macbooks" rel="nofollow" href="https://securityconversations.com/episode/charlie-miller-on-hacking-iphones-macbooks-jeep-and-self-driving-cars/">Charlie Miller on hacking iPhones, Macbooks</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/#solutions">TLPBLACK</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p>Matthias Frielingsdorf (co-founder and VP of Research at iVerify) joins the show to discuss the mysterious US government connection to &#39;Coruna&#39;, an iOS exploit kit fitted with 23 exploits across five full chains targeting iPhones iOS 13 through 17.2.1. </p>

<p>We talk about a &quot;gut feeling&quot; connecting this to the L3 Trenchant/Peter Williams exploit sale scandal, how a nation-state-grade exploit kit ended up in the hands of a Chinese cybercrime group chasing crypto wallets, and what it means that criminal organizations are now deploying iPhone zero-days at scale. </p>

<p>Matthias walks through what iVerify can and can&#39;t do on Apple&#39;s locked-down platform, why he thinks Apple needs to give defenders more access, the Lockdown Mode debate, the thorny issue of sample sharing in the research community, and practical advice for everyday iPhone users facing a threat landscape that just got a lot more complicated.</p><p>Links:</p><ul><li><a title="Raw Transcript" rel="nofollow" href="https://docs.google.com/document/d/192CYhxiWAGXdhU7EEYB2SXLUq24f1E03/edit">Raw Transcript</a></li><li><a title="Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit">Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit</a></li><li><a title="iVerify Details First Known Mass iOS Attack" rel="nofollow" href="https://iverify.io/press-releases/first-known-mass-ios-attack">iVerify Details First Known Mass iOS Attack</a></li><li><a title="Coruna: Inside the Nation-State-Grade iOS Exploit Kit (iVerify)" rel="nofollow" href="https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking">Coruna: Inside the Nation-State-Grade iOS Exploit Kit (iVerify)</a></li><li><a title="Wired: A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals" rel="nofollow" href="https://archive.ph/r7jGc">Wired: A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals</a></li><li><a title="Lockdown Mode or Nothing " rel="nofollow" href="https://www.youtube.com/watch?v=fAhTPMmvrB0">Lockdown Mode or Nothing </a></li><li><a title="Zero-day reality check: iOS exploitation " rel="nofollow" href="https://www.youtube.com/watch?v=YTRQ56n0yHA">Zero-day reality check: iOS exploitation </a></li><li><a title="About Lockdown Mode (Apple)" rel="nofollow" href="https://support.apple.com/en-us/105120">About Lockdown Mode (Apple)</a></li><li><a title="Charlie Miller on hacking iPhones, Macbooks" rel="nofollow" href="https://securityconversations.com/episode/charlie-miller-on-hacking-iphones-macbooks-jeep-and-self-driving-cars/">Charlie Miller on hacking iPhones, Macbooks</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/#solutions">TLPBLACK</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Threat Hunter Greg Linares on the modern ransomware playbook</title>
  <link>http://securityconversations.fireside.fm/greg-linares-modern-ransomware-playbook</link>
  <guid isPermaLink="false">b9815070-450a-43d3-8970-287ef88e305c</guid>
  <pubDate>Tue, 03 Mar 2026 13:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/b9815070-450a-43d3-8970-287ef88e305c.mp3" length="42939010" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK - High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)

Huntress threat intelligence analyst Greg Linares shares insights on the modern ransomware ecosystem, including how crews operate like businesses and why Akira, Medusa, RansomHub, and Qilin cause so much damage. Plus, signs of overlap between ransomware and nation-state activity, what “time to ransom” really means for defenders, and why techniques like ClickFix and credential theft keep working at scale. 

The conversation also covers the surge in RMM tool abuse, how “living off the land” attacks can unfold without traditional malware, and the basic defenses smaller organizations can prioritize.</itunes:subtitle>
  <itunes:duration>49:48</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/b/b9815070-450a-43d3-8970-287ef88e305c/cover.jpg?v=2"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Huntress threat intelligence analyst Greg Linares shares insights on the modern ransomware ecosystem, including how crews operate like businesses and why Akira, Medusa, RansomHub, and Qilin cause so much damage. Plus, signs of overlap between ransomware and nation-state activity, what “time to ransom” really means for defenders, and why techniques like ClickFix and credential theft keep working at scale. 
The conversation also covers the surge in RMM tool abuse, how “living off the land” attacks can unfold without traditional malware, and the basic defenses smaller organizations can prioritize.
</description>
  <itunes:keywords>huntress, greg linares, ransomware, akira, ransomhub, medusa, qilin, rmm abuse, remote monitoring, lolbins, LOTL</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p>Huntress threat intelligence analyst Greg Linares shares insights on the modern ransomware ecosystem, including how crews operate like businesses and why Akira, Medusa, RansomHub, and Qilin cause so much damage. Plus, signs of overlap between ransomware and nation-state activity, what “time to ransom” really means for defenders, and why techniques like ClickFix and credential theft keep working at scale. </p>

<p>The conversation also covers the surge in RMM tool abuse, how “living off the land” attacks can unfold without traditional malware, and the basic defenses smaller organizations can prioritize.</p><p>Links:</p><ul><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/1Fx1Ez2CK71rmn0RhDXXObDXTxio_aGvRxHByv6WvY0Y/edit?tab=t.0">Transcript</a></li><li><a title="Huntress 2025 Cyber Threat Report" rel="nofollow" href="https://www.huntress.com/resources/2025-cyber-threat-report">Huntress 2025 Cyber Threat Report</a></li><li><a title="Microsoft: Think before you Click(Fix)" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/">Microsoft: Think before you Click(Fix)</a></li><li><a title="Akira Ransomware" rel="nofollow" href="https://www.ic3.gov/CSA/2025/251113.pdf">Akira Ransomware</a></li><li><a title="CISA: Protecting Against Malicious Use of Remote Monitoring and Management Software" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a">CISA: Protecting Against Malicious Use of Remote Monitoring and Management Software</a></li><li><a title="Ep9: The blurring lines between nation-state APTs and the ransomware epidemic " rel="nofollow" href="https://securityconversations.com/episode/ep9-the-blurring-lines-between-nation-state-apts-and-the-ransomware-epidemic/">Ep9: The blurring lines between nation-state APTs and the ransomware epidemic </a></li><li><a title="Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines" rel="nofollow" href="https://www.securityweek.com/chinese-apt-tools-found-in-ransomware-schemes-blurring-attribution-lines/">Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p>Huntress threat intelligence analyst Greg Linares shares insights on the modern ransomware ecosystem, including how crews operate like businesses and why Akira, Medusa, RansomHub, and Qilin cause so much damage. Plus, signs of overlap between ransomware and nation-state activity, what “time to ransom” really means for defenders, and why techniques like ClickFix and credential theft keep working at scale. </p>

<p>The conversation also covers the surge in RMM tool abuse, how “living off the land” attacks can unfold without traditional malware, and the basic defenses smaller organizations can prioritize.</p><p>Links:</p><ul><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/1Fx1Ez2CK71rmn0RhDXXObDXTxio_aGvRxHByv6WvY0Y/edit?tab=t.0">Transcript</a></li><li><a title="Huntress 2025 Cyber Threat Report" rel="nofollow" href="https://www.huntress.com/resources/2025-cyber-threat-report">Huntress 2025 Cyber Threat Report</a></li><li><a title="Microsoft: Think before you Click(Fix)" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/">Microsoft: Think before you Click(Fix)</a></li><li><a title="Akira Ransomware" rel="nofollow" href="https://www.ic3.gov/CSA/2025/251113.pdf">Akira Ransomware</a></li><li><a title="CISA: Protecting Against Malicious Use of Remote Monitoring and Management Software" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a">CISA: Protecting Against Malicious Use of Remote Monitoring and Management Software</a></li><li><a title="Ep9: The blurring lines between nation-state APTs and the ransomware epidemic " rel="nofollow" href="https://securityconversations.com/episode/ep9-the-blurring-lines-between-nation-state-apts-and-the-ransomware-epidemic/">Ep9: The blurring lines between nation-state APTs and the ransomware epidemic </a></li><li><a title="Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines" rel="nofollow" href="https://www.securityweek.com/chinese-apt-tools-found-in-ransomware-schemes-blurring-attribution-lines/">Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>War in Iran, Anthropic v Pentagon, Trenchant zero-day sanctions, AI stock market shocks</title>
  <link>http://securityconversations.fireside.fm/war-iran-anthropic-usgov-trenchant-zero-day-sanctions</link>
  <guid isPermaLink="false">7d707098-e32e-45a7-9069-fb8a34620302</guid>
  <pubDate>Sat, 28 Feb 2026 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7d707098-e32e-45a7-9069-fb8a34620302.mp3" length="105895784" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Thinkst Canary. Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)

Three Buddy Problem - Episode 87:  We wake up to news of U.S./Israel military action against Iran and the expected fallout, including Tehran’s cyber capabilities and proxy risks. Plus: Anthropic’s clash with the Pentagon over AI use in warfare, market shockwaves from AI-driven security tools, mass layoffs tied to automation, sentencing and sanctions in the exploit trade, and fresh questions around Cisco’s SD-WAN breach and supply-chain trust.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:08:22</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7d707098-e32e-45a7-9069-fb8a34620302/cover.jpg?v=1"/>
  <description>(Presented by Thinkst Canary (https://canary.tools): Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 87: We wake up to news of U.S./Israel military action against Iran and the expected fallout, including Tehran’s cyber capabilities and proxy risks. Plus: Anthropic’s clash with the Pentagon over AI use in warfare, market shockwaves from AI-driven security tools, mass layoffs tied to automation, Trenchant exec sentencing and sanctions in the exploit trade, and fresh questions around Cisco’s SD-WAN breach and supply-chain trust.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Israel, Iran, cyberwar, Peter Williams, Operation Zero, Trenchant, Anthropic, OpenAI, CrowdStrike, Cisco Talos, China, DeepSeek, Meta, cyberespionage</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 87</strong>: We wake up to news of U.S./Israel military action against Iran and the expected fallout, including Tehran’s cyber capabilities and proxy risks. Plus: Anthropic’s clash with the Pentagon over AI use in warfare, market shockwaves from AI-driven security tools, mass layoffs tied to automation, Trenchant exec sentencing and sanctions in the exploit trade, and fresh questions around Cisco’s SD-WAN breach and supply-chain trust.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1pVVw2L0YShpPy1ArqBLUcvApTJcjFxSQBYUepjj1yF0/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/#pricing">Thinkst Canary</a></li><li><a title="Live updates: US and Israel strike Iran" rel="nofollow" href="https://apnews.com/live/live-updates-israel-iran-february-28-2026">Live updates: US and Israel strike Iran</a></li><li><a title="Episode 80: Hamid Kashfi on the situation in Iran" rel="nofollow" href="https://securityconversations.fireside.fm/hamid-kashfi-iran-protests-cyber-venezuela">Episode 80: Hamid Kashfi on the situation in Iran</a></li><li><a title="‘Incoherent’: Hegseth’s Anthropic ultimatum confounds AI policymakers" rel="nofollow" href="https://www.politico.com/news/2026/02/26/incoherent-hegseths-anthropic-ultimatum-confounds-ai-policymakers-00800135">‘Incoherent’: Hegseth’s Anthropic ultimatum confounds AI policymakers</a></li><li><a title="Anthropic Claude AI Security Tool Wipes Out Over $15 Billion From Cybersecurity Stocks" rel="nofollow" href="https://www.linkedin.com/pulse/anthropics-new-claude-ai-security-tool-wipes-out-17jje/">Anthropic Claude AI Security Tool Wipes Out Over $15 Billion From Cybersecurity Stocks</a></li><li><a title="CrowdStrike CEO responds to stock price hit" rel="nofollow" href="https://www.linkedin.com/feed/update/urn:li:activity:7431417202505064448/">CrowdStrike CEO responds to stock price hit</a></li><li><a title="Designation of Zero-Day Exploits Broker for Theft of U.S. Trade Secrets" rel="nofollow" href="https://www.state.gov/releases/office-of-the-spokesperson/2026/02/designation-of-russia-based-zero-day-exploits-broker-and-affiliates-for-theft-of-u-s-trade-secrets/">Designation of Zero-Day Exploits Broker for Theft of U.S. Trade Secrets</a></li><li><a title="Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools " rel="nofollow" href="https://home.treasury.gov/news/press-releases/sb0404">Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools </a></li><li><a title="Trenchant Exec Who Sold Zero-Day Exploits to Russian Buyer Sentenced to 7 Years in Prison" rel="nofollow" href="https://www.zetter-zeroday.com/trenchant-exec-who-sold-his-employers-zero-day-exploits-to-russian-buyer-sentenced-to-7-years-in-prison/">Trenchant Exec Who Sold Zero-Day Exploits to Russian Buyer Sentenced to 7 Years in Prison</a></li><li><a title="AWS says AI-augmented threat actor accesses FortiGate devices at scale" rel="nofollow" href="https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/">AWS says AI-augmented threat actor accesses FortiGate devices at scale</a></li><li><a title="Active exploitation of Cisco Catalyst SD-WAN by UAT-8616" rel="nofollow" href="https://blog.talosintelligence.com/uat-8616-sd-wan/">Active exploitation of Cisco Catalyst SD-WAN by UAT-8616</a></li><li><a title="Anthropic Claud Code Security" rel="nofollow" href="https://www.anthropic.com/news/claude-code-security">Anthropic Claud Code Security</a></li><li><a title="Anthropic: Detecting and preventing distillation attacks" rel="nofollow" href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks">Anthropic: Detecting and preventing distillation attacks</a></li><li><a title="GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use">GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</a></li><li><a title="iPhone and iPad approved to handle classified NATO information" rel="nofollow" href="https://www.apple.com/newsroom/2026/02/iphone-and-ipad-approved-to-handle-classified-nato-information/">iPhone and iPad approved to handle classified NATO information</a></li><li><a title="Fortinet Achieves Certification for Secure Product Development" rel="nofollow" href="https://www.fortinet.com/blog/operational-technology/fortinet-achieves-iec-62443-4-1-ml2-certification-for-secure-product-development">Fortinet Achieves Certification for Secure Product Development</a></li><li><a title="Cisco SD-WAN threat hunting guide" rel="nofollow" href="https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf">Cisco SD-WAN threat hunting guide</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 87</strong>: We wake up to news of U.S./Israel military action against Iran and the expected fallout, including Tehran’s cyber capabilities and proxy risks. Plus: Anthropic’s clash with the Pentagon over AI use in warfare, market shockwaves from AI-driven security tools, mass layoffs tied to automation, Trenchant exec sentencing and sanctions in the exploit trade, and fresh questions around Cisco’s SD-WAN breach and supply-chain trust.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1pVVw2L0YShpPy1ArqBLUcvApTJcjFxSQBYUepjj1yF0/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/#pricing">Thinkst Canary</a></li><li><a title="Live updates: US and Israel strike Iran" rel="nofollow" href="https://apnews.com/live/live-updates-israel-iran-february-28-2026">Live updates: US and Israel strike Iran</a></li><li><a title="Episode 80: Hamid Kashfi on the situation in Iran" rel="nofollow" href="https://securityconversations.fireside.fm/hamid-kashfi-iran-protests-cyber-venezuela">Episode 80: Hamid Kashfi on the situation in Iran</a></li><li><a title="‘Incoherent’: Hegseth’s Anthropic ultimatum confounds AI policymakers" rel="nofollow" href="https://www.politico.com/news/2026/02/26/incoherent-hegseths-anthropic-ultimatum-confounds-ai-policymakers-00800135">‘Incoherent’: Hegseth’s Anthropic ultimatum confounds AI policymakers</a></li><li><a title="Anthropic Claude AI Security Tool Wipes Out Over $15 Billion From Cybersecurity Stocks" rel="nofollow" href="https://www.linkedin.com/pulse/anthropics-new-claude-ai-security-tool-wipes-out-17jje/">Anthropic Claude AI Security Tool Wipes Out Over $15 Billion From Cybersecurity Stocks</a></li><li><a title="CrowdStrike CEO responds to stock price hit" rel="nofollow" href="https://www.linkedin.com/feed/update/urn:li:activity:7431417202505064448/">CrowdStrike CEO responds to stock price hit</a></li><li><a title="Designation of Zero-Day Exploits Broker for Theft of U.S. Trade Secrets" rel="nofollow" href="https://www.state.gov/releases/office-of-the-spokesperson/2026/02/designation-of-russia-based-zero-day-exploits-broker-and-affiliates-for-theft-of-u-s-trade-secrets/">Designation of Zero-Day Exploits Broker for Theft of U.S. Trade Secrets</a></li><li><a title="Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools " rel="nofollow" href="https://home.treasury.gov/news/press-releases/sb0404">Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools </a></li><li><a title="Trenchant Exec Who Sold Zero-Day Exploits to Russian Buyer Sentenced to 7 Years in Prison" rel="nofollow" href="https://www.zetter-zeroday.com/trenchant-exec-who-sold-his-employers-zero-day-exploits-to-russian-buyer-sentenced-to-7-years-in-prison/">Trenchant Exec Who Sold Zero-Day Exploits to Russian Buyer Sentenced to 7 Years in Prison</a></li><li><a title="AWS says AI-augmented threat actor accesses FortiGate devices at scale" rel="nofollow" href="https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/">AWS says AI-augmented threat actor accesses FortiGate devices at scale</a></li><li><a title="Active exploitation of Cisco Catalyst SD-WAN by UAT-8616" rel="nofollow" href="https://blog.talosintelligence.com/uat-8616-sd-wan/">Active exploitation of Cisco Catalyst SD-WAN by UAT-8616</a></li><li><a title="Anthropic Claud Code Security" rel="nofollow" href="https://www.anthropic.com/news/claude-code-security">Anthropic Claud Code Security</a></li><li><a title="Anthropic: Detecting and preventing distillation attacks" rel="nofollow" href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks">Anthropic: Detecting and preventing distillation attacks</a></li><li><a title="GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use">GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</a></li><li><a title="iPhone and iPad approved to handle classified NATO information" rel="nofollow" href="https://www.apple.com/newsroom/2026/02/iphone-and-ipad-approved-to-handle-classified-nato-information/">iPhone and iPad approved to handle classified NATO information</a></li><li><a title="Fortinet Achieves Certification for Secure Product Development" rel="nofollow" href="https://www.fortinet.com/blog/operational-technology/fortinet-achieves-iec-62443-4-1-ml2-certification-for-secure-product-development">Fortinet Achieves Certification for Secure Product Development</a></li><li><a title="Cisco SD-WAN threat hunting guide" rel="nofollow" href="https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf">Cisco SD-WAN threat hunting guide</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>GitLab doxxes North Korea .gov hackers; fresh Ivanti zero-days; AI addiction and human purpose</title>
  <link>http://securityconversations.fireside.fm/gitlab-north-korea-ivanti-zero-day-ai-human-purpose</link>
  <guid isPermaLink="false">6850debe-7ea0-498e-9857-123d30c24e8d</guid>
  <pubDate>Fri, 20 Feb 2026 01:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/6850debe-7ea0-498e-9857-123d30c24e8d.mp3" length="106607056" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by TLPBLACK - High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)

Three Buddy Problem - Episode 86: We dig into GitLab’s explosive look at North Korea’s “Contagious Interview” APT operation, the scale of fake IT worker infiltration, and what it means for companies chasing cheap talent.  

Plus, a fresh batch of already-exploited Ivanti and Dell zero-days, the return of Apple’s shutdown logs, and thoughts on addictive AI coding agents affecting human purpose. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:16:39</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/6850debe-7ea0-498e-9857-123d30c24e8d/cover.jpg?v=1"/>
  <description>(Presented by TLPBLACK (https://tlpblack.net): High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Three Buddy Problem - Episode 86:  We dig into GitLab’s explosive look at North Korea’s “Contagious Interview” APT operation, the scale of fake IT worker infiltration, and what it means for companies chasing cheap talent.  
Plus, a fresh batch of already-exploited Ivanti and Dell zero-days, the return of Apple’s shutdown logs, and thoughts on addictive AI coding agents affecting human purpose. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>GitLab, North Korea, Contageous Interview, China, Russia, Ivanti, Unit 42, zero-day, Mandiant, CVE-2026-22769, Dell, OpenAI, Aardvard, Codex Security, Deutsche Bahn, hybrid war, AIVD, MIVD, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 86</strong>:  We dig into GitLab’s explosive look at North Korea’s “Contagious Interview” APT operation, the scale of fake IT worker infiltration, and what it means for companies chasing cheap talent.  </p>

<p>Plus, a fresh batch of already-exploited Ivanti and Dell zero-days, the return of Apple’s shutdown logs, and thoughts on addictive AI coding agents affecting human purpose. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/#solutions-pdns">TLPBLACK</a></li><li><a title="GitLab exposes North Korean malware tradecraft" rel="nofollow" href="https://about.gitlab.com/blog/gitlab-threat-intelligence-reveals-north-korean-tradecraft/">GitLab exposes North Korean malware tradecraft</a></li><li><a title="Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets (Seongsu Park)" rel="nofollow" href="https://sp4rk.medium.com/beyond-the-backdoor-how-contagious-interview-is-surgically-tampering-with-metamask-wallets-0314ae901d85">Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets (Seongsu Park)</a></li><li><a title="Critical Vulnerabilities in Ivanti EPMM Exploited" rel="nofollow" href="https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/">Critical Vulnerabilities in Ivanti EPMM Exploited</a></li><li><a title="Dell RecoverPoint for Virtual Machines Zero-Day" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day">Dell RecoverPoint for Virtual Machines Zero-Day</a></li><li><a title="Dell Bulletin - RecoverPoint for Virtual Machines Hardcoded Credential Vulnerability" rel="nofollow" href="https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079">Dell Bulletin - RecoverPoint for Virtual Machines Hardcoded Credential Vulnerability</a></li><li><a title="Critical Dell bug exploited for two years" rel="nofollow" href="https://www.thestack.technology/dell-critical-vulnerability-vmware-cve-202622769/">Critical Dell bug exploited for two years</a></li><li><a title="OpenAI intros Lockdown Mode and Elevated Risk labels in ChatGPT" rel="nofollow" href="https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt/">OpenAI intros Lockdown Mode and Elevated Risk labels in ChatGPT</a></li><li><a title="OpenAI is rebranding Aardvark " rel="nofollow" href="https://x.com/btibor91/status/2024613054638608558">OpenAI is rebranding Aardvark </a></li><li><a title="Anthropic Claude Code Security " rel="nofollow" href="https://www.anthropic.com/news/claude-code-security">Anthropic Claude Code Security </a></li><li><a title="Jason Lang: Real Human Concerns In The Age of AI" rel="nofollow" href="https://x.com/curi0usJack/status/2024184571974000984">Jason Lang: Real Human Concerns In The Age of AI</a></li><li><a title="JAGS&#39; batteries-included Claude Code SDLC config" rel="nofollow" href="https://github.com/juanandresgs/claude-system">JAGS' batteries-included Claude Code SDLC config</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://tlpblack.net" rel="nofollow">TLPBLACK</a>: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.</em>)</p>

<p><strong>Three Buddy Problem - Episode 86</strong>:  We dig into GitLab’s explosive look at North Korea’s “Contagious Interview” APT operation, the scale of fake IT worker infiltration, and what it means for companies chasing cheap talent.  </p>

<p>Plus, a fresh batch of already-exploited Ivanti and Dell zero-days, the return of Apple’s shutdown logs, and thoughts on addictive AI coding agents affecting human purpose. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/#solutions-pdns">TLPBLACK</a></li><li><a title="GitLab exposes North Korean malware tradecraft" rel="nofollow" href="https://about.gitlab.com/blog/gitlab-threat-intelligence-reveals-north-korean-tradecraft/">GitLab exposes North Korean malware tradecraft</a></li><li><a title="Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets (Seongsu Park)" rel="nofollow" href="https://sp4rk.medium.com/beyond-the-backdoor-how-contagious-interview-is-surgically-tampering-with-metamask-wallets-0314ae901d85">Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets (Seongsu Park)</a></li><li><a title="Critical Vulnerabilities in Ivanti EPMM Exploited" rel="nofollow" href="https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/">Critical Vulnerabilities in Ivanti EPMM Exploited</a></li><li><a title="Dell RecoverPoint for Virtual Machines Zero-Day" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day">Dell RecoverPoint for Virtual Machines Zero-Day</a></li><li><a title="Dell Bulletin - RecoverPoint for Virtual Machines Hardcoded Credential Vulnerability" rel="nofollow" href="https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079">Dell Bulletin - RecoverPoint for Virtual Machines Hardcoded Credential Vulnerability</a></li><li><a title="Critical Dell bug exploited for two years" rel="nofollow" href="https://www.thestack.technology/dell-critical-vulnerability-vmware-cve-202622769/">Critical Dell bug exploited for two years</a></li><li><a title="OpenAI intros Lockdown Mode and Elevated Risk labels in ChatGPT" rel="nofollow" href="https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt/">OpenAI intros Lockdown Mode and Elevated Risk labels in ChatGPT</a></li><li><a title="OpenAI is rebranding Aardvark " rel="nofollow" href="https://x.com/btibor91/status/2024613054638608558">OpenAI is rebranding Aardvark </a></li><li><a title="Anthropic Claude Code Security " rel="nofollow" href="https://www.anthropic.com/news/claude-code-security">Anthropic Claude Code Security </a></li><li><a title="Jason Lang: Real Human Concerns In The Age of AI" rel="nofollow" href="https://x.com/curi0usJack/status/2024184571974000984">Jason Lang: Real Human Concerns In The Age of AI</a></li><li><a title="JAGS&#39; batteries-included Claude Code SDLC config" rel="nofollow" href="https://github.com/juanandresgs/claude-system">JAGS' batteries-included Claude Code SDLC config</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li><li><a title="NEBULA:FOG 2026 | AI x Security Hackathon" rel="nofollow" href="https://nebulafog.ai/">NEBULA:FOG 2026 | AI x Security Hackathon</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Palo Alto and the uncomfortable politics of APT attribution</title>
  <link>http://securityconversations.fireside.fm/drones-elpaso-palo-alto-china-attribution</link>
  <guid isPermaLink="false">1964971a-bff0-48c5-9d43-8874e3b38d67</guid>
  <pubDate>Fri, 13 Feb 2026 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/1964971a-bff0-48c5-9d43-8874e3b38d67.mp3" length="118296559" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Thinkst Canary. Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)

Three Buddy Problem - Episode 85: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft’s zero-day treadmill and AI-enabled attack surfaces; and Apple’s “extremely sophisticated” iOS exploits.

Plus, Europe’s growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:30:30</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/1964971a-bff0-48c5-9d43-8874e3b38d67/cover.jpg?v=1"/>
  <description>(Presented by Thinkst Canary (https://canary.tools): Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 85: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft’s zero-day treadmill and AI-enabled attack surfaces; and Apple’s “extremely sophisticated” iOS exploits.
Plus, Europe’s growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>drones, El Paso, FAA, anti-drone, notepad++, SUO5, Microsoft, Patch Tuesday, zeroday, ios 26.3, Estonia, Russia, China, Palo Alto, Singapore, Germany, Tianfu Cup</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 85</strong>: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft’s zero-day treadmill and AI-enabled attack surfaces; and Apple’s “extremely sophisticated” iOS exploits.</p>

<p>Plus, Europe’s growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/10uh_I7o0vdCt34EWS84SVdt_b6hmyXuigAPkP7HwYJQ/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Thinkst Canary - Customer Love" rel="nofollow" href="https://canary.tools/love">Thinkst Canary - Customer Love</a></li><li><a title="What We Know About the El Paso Airspace Shutdown" rel="nofollow" href="https://archive.ph/7JHqq">What We Know About the El Paso Airspace Shutdown</a></li><li><a title="El Paso Closure Caused by Firing Anti-Drone Laser " rel="nofollow" href="https://archive.ph/xi7BU">El Paso Closure Caused by Firing Anti-Drone Laser </a></li><li><a title="Notepad++ supply chain hack (new IOCs)" rel="nofollow" href="https://notepad-plus-plus.org/assets/data/IoCFromFormerHostingProvider.txt">Notepad++ supply chain hack (new IOCs)</a></li><li><a title="Ukatemi: Notepad++ attack related samples" rel="nofollow" href="https://blog.ukatemi.com/blog/2026-02-12-notepad++-supply-chain-samples/">Ukatemi: Notepad++ attack related samples</a></li><li><a title="Notepad&#39;s new Markdown powers served with a side of RCE" rel="nofollow" href="https://www.theregister.com/2026/02/11/notepad_rce_flaw/">Notepad's new Markdown powers served with a side of RCE</a></li><li><a title="Microsoft: Windows Notepad App RCE Vulnerability " rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841">Microsoft: Windows Notepad App RCE Vulnerability </a></li><li><a title="iOS 26.3 security advisory (exploited 0day)" rel="nofollow" href="https://support.apple.com/en-us/126346">iOS 26.3 security advisory (exploited 0day)</a></li><li><a title="Estonian Foreign Intelligence Service annual report" rel="nofollow" href="https://raport.valisluureamet.ee/2026/en/">Estonian Foreign Intelligence Service annual report</a></li><li><a title="PSIRT | FortiGuard Labs High-Risk Advisory" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1052">PSIRT | FortiGuard Labs High-Risk Advisory</a></li><li><a title="Germany prepares to attack cyber enemies" rel="nofollow" href="https://www.politico.eu/article/germany-prepares-hack-back-cyber-enemies/">Germany prepares to attack cyber enemies</a></li><li><a title="Palo Alto chose not to tie China to hacking campaign for fear of retaliation" rel="nofollow" href="https://www.reuters.com/world/china/palo-alto-chose-not-tie-china-hacking-campaign-fear-retaliation-beijing-sources-2026-02-12/">Palo Alto chose not to tie China to hacking campaign for fear of retaliation</a></li><li><a title="The Shadow Campaigns: Uncovering Global Espionage (Palo Alto)" rel="nofollow" href="https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/">The Shadow Campaigns: Uncovering Global Espionage (Palo Alto)</a></li><li><a title="Singapore .gov on nation-state telco hacks" rel="nofollow" href="https://www.csa.gov.sg/news-events/press-releases/largest-multi-agency-cyber-operation-mounted-to-counter-threat-posed-by-advanced-persistent-threat--apt--actor-unc3886-to-singapore-s-telecommunications-sector/">Singapore .gov on nation-state telco hacks</a></li><li><a title="TLP-BLACK" rel="nofollow" href="https://tlpblack.net/">TLP-BLACK</a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 85</strong>: Top stories this week include drone incursions over El Paso and the murky line between cartel activity, anti-drone tech testing, and full-blown hybrid warfare; updates on the Notepad++ supply chain fallout; Microsoft’s zero-day treadmill and AI-enabled attack surfaces; and Apple’s “extremely sophisticated” iOS exploits.</p>

<p>Plus, Europe’s growing appetite for offensive cyber, Palo Alto and the uncomfortable politics of cyber attribution, Singapore on telco intrusions, and the economics of end-of-life infrastructure.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/10uh_I7o0vdCt34EWS84SVdt_b6hmyXuigAPkP7HwYJQ/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Thinkst Canary - Customer Love" rel="nofollow" href="https://canary.tools/love">Thinkst Canary - Customer Love</a></li><li><a title="What We Know About the El Paso Airspace Shutdown" rel="nofollow" href="https://archive.ph/7JHqq">What We Know About the El Paso Airspace Shutdown</a></li><li><a title="El Paso Closure Caused by Firing Anti-Drone Laser " rel="nofollow" href="https://archive.ph/xi7BU">El Paso Closure Caused by Firing Anti-Drone Laser </a></li><li><a title="Notepad++ supply chain hack (new IOCs)" rel="nofollow" href="https://notepad-plus-plus.org/assets/data/IoCFromFormerHostingProvider.txt">Notepad++ supply chain hack (new IOCs)</a></li><li><a title="Ukatemi: Notepad++ attack related samples" rel="nofollow" href="https://blog.ukatemi.com/blog/2026-02-12-notepad++-supply-chain-samples/">Ukatemi: Notepad++ attack related samples</a></li><li><a title="Notepad&#39;s new Markdown powers served with a side of RCE" rel="nofollow" href="https://www.theregister.com/2026/02/11/notepad_rce_flaw/">Notepad's new Markdown powers served with a side of RCE</a></li><li><a title="Microsoft: Windows Notepad App RCE Vulnerability " rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841">Microsoft: Windows Notepad App RCE Vulnerability </a></li><li><a title="iOS 26.3 security advisory (exploited 0day)" rel="nofollow" href="https://support.apple.com/en-us/126346">iOS 26.3 security advisory (exploited 0day)</a></li><li><a title="Estonian Foreign Intelligence Service annual report" rel="nofollow" href="https://raport.valisluureamet.ee/2026/en/">Estonian Foreign Intelligence Service annual report</a></li><li><a title="PSIRT | FortiGuard Labs High-Risk Advisory" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1052">PSIRT | FortiGuard Labs High-Risk Advisory</a></li><li><a title="Germany prepares to attack cyber enemies" rel="nofollow" href="https://www.politico.eu/article/germany-prepares-hack-back-cyber-enemies/">Germany prepares to attack cyber enemies</a></li><li><a title="Palo Alto chose not to tie China to hacking campaign for fear of retaliation" rel="nofollow" href="https://www.reuters.com/world/china/palo-alto-chose-not-tie-china-hacking-campaign-fear-retaliation-beijing-sources-2026-02-12/">Palo Alto chose not to tie China to hacking campaign for fear of retaliation</a></li><li><a title="The Shadow Campaigns: Uncovering Global Espionage (Palo Alto)" rel="nofollow" href="https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/">The Shadow Campaigns: Uncovering Global Espionage (Palo Alto)</a></li><li><a title="Singapore .gov on nation-state telco hacks" rel="nofollow" href="https://www.csa.gov.sg/news-events/press-releases/largest-multi-agency-cyber-operation-mounted-to-counter-threat-posed-by-advanced-persistent-threat--apt--actor-unc3886-to-singapore-s-telecommunications-sector/">Singapore .gov on nation-state telco hacks</a></li><li><a title="TLP-BLACK" rel="nofollow" href="https://tlpblack.net/">TLP-BLACK</a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks</title>
  <link>http://securityconversations.fireside.fm/epstein-notepad-plus-zerodays-supply-chain-attacks</link>
  <guid isPermaLink="false">d4b5dfb8-20b2-4dc6-aa39-6f582bd8dae8</guid>
  <pubDate>Sun, 08 Feb 2026 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/d4b5dfb8-20b2-4dc6-aa39-6f582bd8dae8.mp3" length="113124412" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Thinkst Canary. Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With 0 admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)

Three Buddy Problem - Episode 84:  We process the cybersecurity fallout from the latest Epstein document dump, focusing on why redactions fail in the AI era and how quickly modern tools can unravel them. The conversation moves from sloppy redaction practices and exploit mythology to harder questions about ethics, accountability, and silence within the infosec community. 

Plus, inside the Notepad++ supply-chain compromise attributed to a known Chinese APT, Microsoft’s security executive changes, Anthropic's AI-driven vulnerability discovery, China-linked network implants, and Lockdown Mode thwarting FBI investigators.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:17:38</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/d/d4b5dfb8-20b2-4dc6-aa39-6f582bd8dae8/cover.jpg?v=2"/>
  <description>(Presented by Thinkst Canary (https://canary.tools): Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 84:  We process the cybersecurity fallout from the latest Epstein document dump, focusing on why redactions fail in the AI era and how quickly modern tools can unravel them. The conversation moves from sloppy redaction practices and exploit mythology to harder questions about ethics, accountability, and silence within the infosec community. 
Plus, inside the Notepad++ supply-chain compromise attributed to a known Chinese APT, Microsoft’s security executive changes, Anthropic's AI-driven vulnerability discovery, China-linked network implants, and Lockdown Mode thwarting FBI investigators.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 84</strong>:  We process the cybersecurity fallout from the latest Epstein document dump, focusing on why redactions fail in the AI era and how quickly modern tools can unravel them. The conversation moves from sloppy redaction practices and exploit mythology to harder questions about ethics, accountability, and silence within the infosec community. </p>

<p>Plus, inside the Notepad++ supply-chain compromise attributed to a known Chinese APT, Microsoft’s security executive changes, Anthropic&#39;s AI-driven vulnerability discovery, China-linked network implants, and Lockdown Mode thwarting FBI investigators.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Thinkst Canary - Customer Love" rel="nofollow" href="https://canary.tools/love">Thinkst Canary - Customer Love</a></li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1DamIQqfq_QYsYm7xby3ntH4bI30T98emmOSkNnQzY84/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Did a renowned hacker help Jeffrey Epstein get ‘dirt on other people&#39;?" rel="nofollow" href="https://www.yahoo.com/news/articles/did-renowned-hacker-help-jeffrey-120148711.html">Did a renowned hacker help Jeffrey Epstein get ‘dirt on other people'?</a></li><li><a title="DOJ releases details alleged talented hacker working for Jeffrey Epstein" rel="nofollow" href="https://securityaffairs.com/187515/laws-and-regulations/doj-releases-details-alleged-talented-hacker-working-for-jeffrey-epstein.html">DOJ releases details alleged talented hacker working for Jeffrey Epstein</a></li><li><a title="Claude Opus 4.6 \ Anthropic" rel="nofollow" href="https://www.anthropic.com/news/claude-opus-4-6">Claude Opus 4.6 \ Anthropic</a></li><li><a title="0-Days \ red.anthropic.com" rel="nofollow" href="https://red.anthropic.com/2026/zero-days/">0-Days \ red.anthropic.com</a></li><li><a title="JAGS&#39; Claude Code SDLC config" rel="nofollow" href="https://github.com/juanandresgs/claude-system">JAGS' Claude Code SDLC config</a></li><li><a title="CERT-Ukraine on zero-day attacks via MS Office" rel="nofollow" href="https://cert.gov.ua/article/6287250">CERT-Ukraine on zero-day attacks via MS Office</a></li><li><a title="Executive security shuffle at Microsoft" rel="nofollow" href="https://blogs.microsoft.com/blog/2026/02/04/updates-in-two-of-our-core-priorities/">Executive security shuffle at Microsoft</a></li><li><a title="TLPBLACK: What we know about the Notepad++ supply chain attack" rel="nofollow" href="https://medium.com/@costin.raiu/what-we-know-about-the-notepad-supply-chain-attack-0f428b4aee08">TLPBLACK: What we know about the Notepad++ supply chain attack</a></li><li><a title="Lotus Blossom APT targets critical infrastructure via Notepad++." rel="nofollow" href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/">Lotus Blossom APT targets critical infrastructure via Notepad++.</a></li><li><a title="Kaspersky: Notepad++ supply chain attack breakdown" rel="nofollow" href="https://securelist.com/notepad-supply-chain-attack/118708/">Kaspersky: Notepad++ supply chain attack breakdown</a></li><li><a title="Validin: Exploring the C2 Infrastructure of the Notepad++ Compromise" rel="nofollow" href="https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/">Validin: Exploring the C2 Infrastructure of the Notepad++ Compromise</a></li><li><a title="Hostinger server unauthorized access case: What happened with Notepad++ and how we resolved it" rel="nofollow" href="https://www.hostinger.com/blog/notepad-unauthorized-access">Hostinger server unauthorized access case: What happened with Notepad++ and how we resolved it</a></li><li><a title="Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework" rel="nofollow" href="https://blog.talosintelligence.com/knife-cutting-the-edge/">Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework</a></li><li><a title="Palo Alto Unit 42: The Shadow Campaigns - Uncovering Global Espionage" rel="nofollow" href="https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/">Palo Alto Unit 42: The Shadow Campaigns - Uncovering Global Espionage</a></li><li><a title="FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled" rel="nofollow" href="https://www.404media.co/fbi-couldnt-get-into-wapo-reporters-iphone-because-it-had-lockdown-mode-enabled/">FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled</a></li><li><a title="Court document: FBI Washington Post Lockdown Mode" rel="nofollow" href="https://www.documentcloud.org/documents/26808056-fbi-washington-post-lockdown-mode/">Court document: FBI Washington Post Lockdown Mode</a></li><li><a title="PIVOTcon" rel="nofollow" href="https://pivotcon.org/">PIVOTcon</a></li><li><a title="TLP BLACK" rel="nofollow" href="https://tlpblack.net/">TLP BLACK</a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026</a></li><li><a title="Decipher podcast (Dennis Fisher)" rel="nofollow" href="https://open.spotify.com/episode/5k9xpXyD7YSlJRkYqoCQde">Decipher podcast (Dennis Fisher)</a></li><li><a title="Detection Engineering newsletter (Zack Allen)" rel="nofollow" href="https://www.detectionengineering.net/p/dew-144-pyramid-of-permanence-and">Detection Engineering newsletter (Zack Allen)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://canary.tools" rel="nofollow">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.</em>)</p>

<p><strong>Three Buddy Problem - Episode 84</strong>:  We process the cybersecurity fallout from the latest Epstein document dump, focusing on why redactions fail in the AI era and how quickly modern tools can unravel them. The conversation moves from sloppy redaction practices and exploit mythology to harder questions about ethics, accountability, and silence within the infosec community. </p>

<p>Plus, inside the Notepad++ supply-chain compromise attributed to a known Chinese APT, Microsoft’s security executive changes, Anthropic&#39;s AI-driven vulnerability discovery, China-linked network implants, and Lockdown Mode thwarting FBI investigators.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Thinkst Canary - Customer Love" rel="nofollow" href="https://canary.tools/love">Thinkst Canary - Customer Love</a></li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1DamIQqfq_QYsYm7xby3ntH4bI30T98emmOSkNnQzY84/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Did a renowned hacker help Jeffrey Epstein get ‘dirt on other people&#39;?" rel="nofollow" href="https://www.yahoo.com/news/articles/did-renowned-hacker-help-jeffrey-120148711.html">Did a renowned hacker help Jeffrey Epstein get ‘dirt on other people'?</a></li><li><a title="DOJ releases details alleged talented hacker working for Jeffrey Epstein" rel="nofollow" href="https://securityaffairs.com/187515/laws-and-regulations/doj-releases-details-alleged-talented-hacker-working-for-jeffrey-epstein.html">DOJ releases details alleged talented hacker working for Jeffrey Epstein</a></li><li><a title="Claude Opus 4.6 \ Anthropic" rel="nofollow" href="https://www.anthropic.com/news/claude-opus-4-6">Claude Opus 4.6 \ Anthropic</a></li><li><a title="0-Days \ red.anthropic.com" rel="nofollow" href="https://red.anthropic.com/2026/zero-days/">0-Days \ red.anthropic.com</a></li><li><a title="JAGS&#39; Claude Code SDLC config" rel="nofollow" href="https://github.com/juanandresgs/claude-system">JAGS' Claude Code SDLC config</a></li><li><a title="CERT-Ukraine on zero-day attacks via MS Office" rel="nofollow" href="https://cert.gov.ua/article/6287250">CERT-Ukraine on zero-day attacks via MS Office</a></li><li><a title="Executive security shuffle at Microsoft" rel="nofollow" href="https://blogs.microsoft.com/blog/2026/02/04/updates-in-two-of-our-core-priorities/">Executive security shuffle at Microsoft</a></li><li><a title="TLPBLACK: What we know about the Notepad++ supply chain attack" rel="nofollow" href="https://medium.com/@costin.raiu/what-we-know-about-the-notepad-supply-chain-attack-0f428b4aee08">TLPBLACK: What we know about the Notepad++ supply chain attack</a></li><li><a title="Lotus Blossom APT targets critical infrastructure via Notepad++." rel="nofollow" href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/">Lotus Blossom APT targets critical infrastructure via Notepad++.</a></li><li><a title="Kaspersky: Notepad++ supply chain attack breakdown" rel="nofollow" href="https://securelist.com/notepad-supply-chain-attack/118708/">Kaspersky: Notepad++ supply chain attack breakdown</a></li><li><a title="Validin: Exploring the C2 Infrastructure of the Notepad++ Compromise" rel="nofollow" href="https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/">Validin: Exploring the C2 Infrastructure of the Notepad++ Compromise</a></li><li><a title="Hostinger server unauthorized access case: What happened with Notepad++ and how we resolved it" rel="nofollow" href="https://www.hostinger.com/blog/notepad-unauthorized-access">Hostinger server unauthorized access case: What happened with Notepad++ and how we resolved it</a></li><li><a title="Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework" rel="nofollow" href="https://blog.talosintelligence.com/knife-cutting-the-edge/">Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework</a></li><li><a title="Palo Alto Unit 42: The Shadow Campaigns - Uncovering Global Espionage" rel="nofollow" href="https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/">Palo Alto Unit 42: The Shadow Campaigns - Uncovering Global Espionage</a></li><li><a title="FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled" rel="nofollow" href="https://www.404media.co/fbi-couldnt-get-into-wapo-reporters-iphone-because-it-had-lockdown-mode-enabled/">FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled</a></li><li><a title="Court document: FBI Washington Post Lockdown Mode" rel="nofollow" href="https://www.documentcloud.org/documents/26808056-fbi-washington-post-lockdown-mode/">Court document: FBI Washington Post Lockdown Mode</a></li><li><a title="PIVOTcon" rel="nofollow" href="https://pivotcon.org/">PIVOTcon</a></li><li><a title="TLP BLACK" rel="nofollow" href="https://tlpblack.net/">TLP BLACK</a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026</a></li><li><a title="Decipher podcast (Dennis Fisher)" rel="nofollow" href="https://open.spotify.com/episode/5k9xpXyD7YSlJRkYqoCQde">Decipher podcast (Dennis Fisher)</a></li><li><a title="Detection Engineering newsletter (Zack Allen)" rel="nofollow" href="https://www.detectionengineering.net/p/dew-144-pyramid-of-permanence-and">Detection Engineering newsletter (Zack Allen)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>A destructive cyberattack in Poland raises NATO 'red-line' questions</title>
  <link>http://securityconversations.fireside.fm/destructive-cyber-poland-nato-red-line-questions</link>
  <guid isPermaLink="false">c425eddb-3de4-49f4-b6da-d3701d26642f</guid>
  <pubDate>Fri, 30 Jan 2026 13:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/c425eddb-3de4-49f4-b6da-d3701d26642f.mp3" length="134749410" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 83:  Poland's CERT documents a rare, explicit wiper attack on civilians in a NATO country, including detailed attribution of a Russian government op targeting the electric grid in the heart of winter. We examine why this crosses a long-avoided threshold, why attribution suddenly matters again, and what it says about pre-positioned access, vendor insecurity, and the shrinking gap between cyber operations and acts of war.

Plus, another Fortinet fiasco, a new batch of Ivanti zero-days under attack, an emergency patch from Microsoft and the return of the mysterious KasperSekrets account.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:53:22</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/c/c425eddb-3de4-49f4-b6da-d3701d26642f/cover.jpg?v=1"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 83:  Poland's CERT documents a rare, explicit wiper attack on civilians in a NATO country, including detailed attribution of a Russian government op targeting the electric grid in the heart of winter. We examine why this crosses a long-avoided threshold, why attribution suddenly matters again, and what it says about pre-positioned access, vendor insecurity, and the shrinking gap between cyber operations and acts of war.
Plus, another Fortinet fiasco, a new batch of Ivanti zero-days under attack, an emergency patch from Microsoft and the return of the mysterious KasperSekrets account.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>IOS, Apple, Poland, Sandworm, Berserk Bear, FSB, Russia, ESET, NATO, Fortinet, Ivanti, Microsoft, zero-day, WinRAR, China, Google,  WhatsApp, Singapore, CISA</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 83</strong>:  Poland&#39;s CERT documents a rare, explicit wiper attack on civilians in a NATO country, including detailed attribution of a Russian government op targeting the electric grid in the heart of winter. We examine why this crosses a long-avoided threshold, why attribution suddenly matters again, and what it says about pre-positioned access, vendor insecurity, and the shrinking gap between cyber operations and acts of war.</p>

<p>Plus, another Fortinet fiasco, a new batch of Ivanti zero-days under attack, an emergency patch from Microsoft and the return of the mysterious KasperSekrets account.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1imC13dSZLhHk1Lf7fEuVeuajlbgiqk2ypQdJow2qGkI/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Material Security (Use Cases)" rel="nofollow" href="https://material.security/use-cases">Material Security (Use Cases)</a></li><li><a title="ESET DynoWiper update: Technical analysis and attribution" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/">ESET DynoWiper update: Technical analysis and attribution</a></li><li><a title="Poland CERT on Russian wiper attacks" rel="nofollow" href="https://cert.pl/uploads/docs/CERT_Polska_Energy_Sector_Incident_Report_2025.pdf">Poland CERT on Russian wiper attacks</a></li><li><a title="Poland blames two Ukrainians allegedly working for Russia for railway blast" rel="nofollow" href="https://www.aljazeera.com/news/2025/11/18/poland-blames-two-ukrainians-allegedly-working-for-russia-for-railway-blast">Poland blames two Ukrainians allegedly working for Russia for railway blast</a></li><li><a title="Britain’s New Spy Chief Has a New Mission" rel="nofollow" href="https://archive.is/kbx9b">Britain’s New Spy Chief Has a New Mission</a></li><li><a title="Two New Ivanti 0days Exploited" rel="nofollow" href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">Two New Ivanti 0days Exploited</a></li><li><a title="Microsoft ships emergency Office patch to thwart attacks" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509">Microsoft ships emergency Office patch to thwart attacks</a></li><li><a title="Analysis of Single Sign-On Abuse on FortiOS" rel="nofollow" href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios">Analysis of Single Sign-On Abuse on FortiOS</a></li><li><a title="Fortinet PSIRT: Administrative FortiCloud SSO authentication bypass" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060">Fortinet PSIRT: Administrative FortiCloud SSO authentication bypass</a></li><li><a title="Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability">Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088</a></li><li><a title="WhatsApp Strict Account Settings" rel="nofollow" href="https://about.fb.com/news/2026/01/whatsapp-strict-account-settings-safeguarding-against-cyber-attacks/">WhatsApp Strict Account Settings</a></li><li><a title="China Executes 11 People Linked to Cyberscam Centers in Myanmar" rel="nofollow" href="https://archive.ph/5UTzW">China Executes 11 People Linked to Cyberscam Centers in Myanmar</a></li><li><a title="Singapore to start caning for scammers" rel="nofollow" href="https://www.police.gov.sg/Knowledge-Hub/Legislation/Caning-for-Scams-and-Scams-related-Offences">Singapore to start caning for scammers</a></li><li><a title="Germany on hacking attacks: &quot;We will strike back, including abroad&quot;" rel="nofollow" href="https://www.welt.de/politik/deutschland/article6973feeaf5499fb954b6401d/hackerangriffe-auf-deutschland-wir-werden-zurueckschlagen-auch-im-ausland-dobrindt-will-cyber-gegenwehr-verschaerfen.html">Germany on hacking attacks: "We will strike back, including abroad"</a></li><li><a title="Acting CISA chief uploaded sensitive files into a public version of ChatGPT" rel="nofollow" href="https://www.politico.com/news/2026/01/27/cisa-madhu-gottumukkala-chatgpt-00749361">Acting CISA chief uploaded sensitive files into a public version of ChatGPT</a></li><li><a title="TLP BLACK" rel="nofollow" href="https://tlpblack.net/">TLP BLACK</a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026</a></li><li><a title="KasperSekrets" rel="nofollow" href="https://x.com/kaspersekrets/">KasperSekrets</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 83</strong>:  Poland&#39;s CERT documents a rare, explicit wiper attack on civilians in a NATO country, including detailed attribution of a Russian government op targeting the electric grid in the heart of winter. We examine why this crosses a long-avoided threshold, why attribution suddenly matters again, and what it says about pre-positioned access, vendor insecurity, and the shrinking gap between cyber operations and acts of war.</p>

<p>Plus, another Fortinet fiasco, a new batch of Ivanti zero-days under attack, an emergency patch from Microsoft and the return of the mysterious KasperSekrets account.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1imC13dSZLhHk1Lf7fEuVeuajlbgiqk2ypQdJow2qGkI/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Material Security (Use Cases)" rel="nofollow" href="https://material.security/use-cases">Material Security (Use Cases)</a></li><li><a title="ESET DynoWiper update: Technical analysis and attribution" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/">ESET DynoWiper update: Technical analysis and attribution</a></li><li><a title="Poland CERT on Russian wiper attacks" rel="nofollow" href="https://cert.pl/uploads/docs/CERT_Polska_Energy_Sector_Incident_Report_2025.pdf">Poland CERT on Russian wiper attacks</a></li><li><a title="Poland blames two Ukrainians allegedly working for Russia for railway blast" rel="nofollow" href="https://www.aljazeera.com/news/2025/11/18/poland-blames-two-ukrainians-allegedly-working-for-russia-for-railway-blast">Poland blames two Ukrainians allegedly working for Russia for railway blast</a></li><li><a title="Britain’s New Spy Chief Has a New Mission" rel="nofollow" href="https://archive.is/kbx9b">Britain’s New Spy Chief Has a New Mission</a></li><li><a title="Two New Ivanti 0days Exploited" rel="nofollow" href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">Two New Ivanti 0days Exploited</a></li><li><a title="Microsoft ships emergency Office patch to thwart attacks" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509">Microsoft ships emergency Office patch to thwart attacks</a></li><li><a title="Analysis of Single Sign-On Abuse on FortiOS" rel="nofollow" href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios">Analysis of Single Sign-On Abuse on FortiOS</a></li><li><a title="Fortinet PSIRT: Administrative FortiCloud SSO authentication bypass" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060">Fortinet PSIRT: Administrative FortiCloud SSO authentication bypass</a></li><li><a title="Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability">Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088</a></li><li><a title="WhatsApp Strict Account Settings" rel="nofollow" href="https://about.fb.com/news/2026/01/whatsapp-strict-account-settings-safeguarding-against-cyber-attacks/">WhatsApp Strict Account Settings</a></li><li><a title="China Executes 11 People Linked to Cyberscam Centers in Myanmar" rel="nofollow" href="https://archive.ph/5UTzW">China Executes 11 People Linked to Cyberscam Centers in Myanmar</a></li><li><a title="Singapore to start caning for scammers" rel="nofollow" href="https://www.police.gov.sg/Knowledge-Hub/Legislation/Caning-for-Scams-and-Scams-related-Offences">Singapore to start caning for scammers</a></li><li><a title="Germany on hacking attacks: &quot;We will strike back, including abroad&quot;" rel="nofollow" href="https://www.welt.de/politik/deutschland/article6973feeaf5499fb954b6401d/hackerangriffe-auf-deutschland-wir-werden-zurueckschlagen-auch-im-ausland-dobrindt-will-cyber-gegenwehr-verschaerfen.html">Germany on hacking attacks: "We will strike back, including abroad"</a></li><li><a title="Acting CISA chief uploaded sensitive files into a public version of ChatGPT" rel="nofollow" href="https://www.politico.com/news/2026/01/27/cisa-madhu-gottumukkala-chatgpt-00749361">Acting CISA chief uploaded sensitive files into a public version of ChatGPT</a></li><li><a title="TLP BLACK" rel="nofollow" href="https://tlpblack.net/">TLP BLACK</a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026</a></li><li><a title="KasperSekrets" rel="nofollow" href="https://x.com/kaspersekrets/">KasperSekrets</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware</title>
  <link>http://securityconversations.fireside.fm/ai-generated-malware-real-meaning-advanced-attacks</link>
  <guid isPermaLink="false">40dc6ef5-03de-4767-ae99-5b8d91ba37f7</guid>
  <pubDate>Fri, 23 Jan 2026 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/40dc6ef5-03de-4767-ae99-5b8d91ba37f7.mp3" length="104173843" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 82:  We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. 

Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA's new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland's electricity sector.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:09:06</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/40dc6ef5-03de-4767-ae99-5b8d91ba37f7/cover.jpg?v=1"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 82:  We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. 
Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA's new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland's electricity sector.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>AI, Check Point, Sean Heelan, VoidLInk, CISA, BRICKSTORM, Node.js, Bard, cURL, zero-days, Microsoft, Google, FBI, BitLocker, Fortinet, Cisco, CISA,  </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 82</strong>:  We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. </p>

<p>Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA&#39;s new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland&#39;s electricity sector.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1VTSffx5pgJQd7V1V2XtIu9BS3AgzPZ82VWSkPNKCsqk/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Material Security (use cases)" rel="nofollow" href="https://material.security/use-cases">Material Security (use cases)</a></li><li><a title="Sean Heelan on the coming industrialisation of exploit generation with LLMs" rel="nofollow" href="https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/">Sean Heelan on the coming industrialisation of exploit generation with LLMs</a></li><li><a title="VoidLink Shows AI-Generated Malware Has Begun" rel="nofollow" href="https://research.checkpoint.com/2026/voidlink-early-ai-generated-malware-framework/">VoidLink Shows AI-Generated Malware Has Begun</a></li><li><a title="LLMs in the SOC: Why Benchmarks Fail Security Operations Teams" rel="nofollow" href="https://www.sentinelone.com/labs/llms-in-the-soc-part-1-why-benchmarks-fail-security-operations-teams/">LLMs in the SOC: Why Benchmarks Fail Security Operations Teams</a></li><li><a title="CISA advisory on BRICKSTORM backdoor" rel="nofollow" href="https://www.cisa.gov/news-events/analysis-reports/ar25-338a">CISA advisory on BRICKSTORM backdoor</a></li><li><a title="Node.js — New HackerOne Signal Requirement  " rel="nofollow" href="https://nodejs.org/en/blog/announcements/hackerone-signal-requirement">Node.js — New HackerOne Signal Requirement  </a></li><li><a title="AI slop security reports submitted to cURL" rel="nofollow" href="https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d1cd">AI slop security reports submitted to cURL</a></li><li><a title="Arctic Wolf on FortiGate attacks via SSO accounts" rel="nofollow" href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/">Arctic Wolf on FortiGate attacks via SSO accounts</a></li><li><a title="New Cisco Remote Code Execution Vulnerability" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b">New Cisco Remote Code Execution Vulnerability</a></li><li><a title="From Protest to Peril: Cellebrite Used Against Jordanian Civil Society" rel="nofollow" href="https://citizenlab.ca/research/from-protest-to-peril-cellebrite-used-against-jordanian-civil-society/">From Protest to Peril: Cellebrite Used Against Jordanian Civil Society</a></li><li><a title="Microsoft on multi‑stage AiTM phishing and BEC campaign abusing SharePoint" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/">Microsoft on multi‑stage AiTM phishing and BEC campaign abusing SharePoint</a></li><li><a title="Microsoft Gave FBI BitLocker Encryption Keys " rel="nofollow" href="https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/">Microsoft Gave FBI BitLocker Encryption Keys </a></li><li><a title="The Mastermind: Drugs. Empire. Murder. Betrayal " rel="nofollow" href="https://www.amazon.com/Mastermind-Drugs-Empire-Murder-Betrayal/dp/0399590412">The Mastermind: Drugs. Empire. Murder. Betrayal </a></li><li><a title="Kim Zetter: Cyberattack on Poland’s energy grid used a wiper" rel="nofollow" href="https://www.zetter-zeroday.com/cyberattack-targeting-polands-energy-grid-used-a-wiper/">Kim Zetter: Cyberattack on Poland’s energy grid used a wiper</a></li><li><a title="ESET on &#39;DynoWiper&#39; malware" rel="nofollow" href="https://x.com/ESETresearch/status/2014737644048044267">ESET on 'DynoWiper' malware</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 82</strong>:  We parse news that China-linked VoidLink is a malware framework created entirely by AI and the collapsing line between elite APT operations and everyday threat actors. </p>

<p>Plus, a new Sean Heelan essay on low-cost exploit generation and why “AI guardrails” are mostly a comforting myth; AI slop overwhelming bug bounty programs; CISA&#39;s new Brickstorm YARA rules; and fresh research on a wiper-malware found in Russian attacks against Poland&#39;s electricity sector.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1VTSffx5pgJQd7V1V2XtIu9BS3AgzPZ82VWSkPNKCsqk/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Material Security (use cases)" rel="nofollow" href="https://material.security/use-cases">Material Security (use cases)</a></li><li><a title="Sean Heelan on the coming industrialisation of exploit generation with LLMs" rel="nofollow" href="https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/">Sean Heelan on the coming industrialisation of exploit generation with LLMs</a></li><li><a title="VoidLink Shows AI-Generated Malware Has Begun" rel="nofollow" href="https://research.checkpoint.com/2026/voidlink-early-ai-generated-malware-framework/">VoidLink Shows AI-Generated Malware Has Begun</a></li><li><a title="LLMs in the SOC: Why Benchmarks Fail Security Operations Teams" rel="nofollow" href="https://www.sentinelone.com/labs/llms-in-the-soc-part-1-why-benchmarks-fail-security-operations-teams/">LLMs in the SOC: Why Benchmarks Fail Security Operations Teams</a></li><li><a title="CISA advisory on BRICKSTORM backdoor" rel="nofollow" href="https://www.cisa.gov/news-events/analysis-reports/ar25-338a">CISA advisory on BRICKSTORM backdoor</a></li><li><a title="Node.js — New HackerOne Signal Requirement  " rel="nofollow" href="https://nodejs.org/en/blog/announcements/hackerone-signal-requirement">Node.js — New HackerOne Signal Requirement  </a></li><li><a title="AI slop security reports submitted to cURL" rel="nofollow" href="https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d1cd">AI slop security reports submitted to cURL</a></li><li><a title="Arctic Wolf on FortiGate attacks via SSO accounts" rel="nofollow" href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/">Arctic Wolf on FortiGate attacks via SSO accounts</a></li><li><a title="New Cisco Remote Code Execution Vulnerability" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b">New Cisco Remote Code Execution Vulnerability</a></li><li><a title="From Protest to Peril: Cellebrite Used Against Jordanian Civil Society" rel="nofollow" href="https://citizenlab.ca/research/from-protest-to-peril-cellebrite-used-against-jordanian-civil-society/">From Protest to Peril: Cellebrite Used Against Jordanian Civil Society</a></li><li><a title="Microsoft on multi‑stage AiTM phishing and BEC campaign abusing SharePoint" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/">Microsoft on multi‑stage AiTM phishing and BEC campaign abusing SharePoint</a></li><li><a title="Microsoft Gave FBI BitLocker Encryption Keys " rel="nofollow" href="https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/">Microsoft Gave FBI BitLocker Encryption Keys </a></li><li><a title="The Mastermind: Drugs. Empire. Murder. Betrayal " rel="nofollow" href="https://www.amazon.com/Mastermind-Drugs-Empire-Murder-Betrayal/dp/0399590412">The Mastermind: Drugs. Empire. Murder. Betrayal </a></li><li><a title="Kim Zetter: Cyberattack on Poland’s energy grid used a wiper" rel="nofollow" href="https://www.zetter-zeroday.com/cyberattack-targeting-polands-energy-grid-used-a-wiper/">Kim Zetter: Cyberattack on Poland’s energy grid used a wiper</a></li><li><a title="ESET on &#39;DynoWiper&#39; malware" rel="nofollow" href="https://x.com/ESETresearch/status/2014737644048044267">ESET on 'DynoWiper' malware</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cybersecurity software</title>
  <link>http://securityconversations.fireside.fm/project-zero-click-pixel-attack-surface</link>
  <guid isPermaLink="false">9e16b30e-091e-44f0-bcf0-03e0f74e465f</guid>
  <pubDate>Fri, 16 Jan 2026 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/9e16b30e-091e-44f0-bcf0-03e0f74e465f.mp3" length="114472744" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 81:  We dissect New York Times reporting on the "precision" of US cyber operations in Venezuela, the competing narratives around offensive cyber capabilities and "letters of marque" for private hackers. Plus, a mysterious failed cyber attack on Poland's power grid, internet blackouts in Iran (with fascinating DNS telemetry revealing Chinese bank traffic and Russian website spikes), and news of China's ban on US/Israeli cybersecurity software.

We also cover Check Point's research on "VoidLink" (is it a successor to ShadowPad?), Microsoft's threat intelligence sharing practices, and Google Project Zero's disclosure of zero-click vulnerabilities caused by AI-powered transcription features.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:24:36</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/9/9e16b30e-091e-44f0-bcf0-03e0f74e465f/cover.jpg?v=1"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 81: We dissect New York Times reporting on the "precision" of US cyber operations in Venezuela, the competing narratives around offensive cyber capabilities and "letters of marque" for private hackers. Plus, a mysterious failed cyber attack on Poland's power grid, internet blackouts in Iran (with fascinating DNS telemetry revealing Chinese bank traffic and Russian website spikes), and news of China's ban on US/Israeli cybersecurity software.
We also cover Check Point's research on "VoidLink" (is it a successor to ShadowPad?), Microsoft's threat intelligence sharing practices, and Google Project Zero's disclosure of zero-click vulnerabilities caused by AI-powered transcription features.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Iran, Verizon, Israel, China, Palo Alto, Microsoft, CISA, Poland, Project Zero, Google, Apple, Pixel, zero-click, Venezuela, cyberwar</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 81</strong>: We dissect New York Times reporting on the &quot;precision&quot; of US cyber operations in Venezuela, the competing narratives around offensive cyber capabilities and &quot;letters of marque&quot; for private hackers. Plus, a mysterious failed cyber attack on Poland&#39;s power grid, internet blackouts in Iran (with fascinating DNS telemetry revealing Chinese bank traffic and Russian website spikes), and news of China&#39;s ban on US/Israeli cybersecurity software.</p>

<p>We also cover Check Point&#39;s research on &quot;VoidLink&quot; (is it a successor to ShadowPad?), Microsoft&#39;s threat intelligence sharing practices, and Google Project Zero&#39;s disclosure of zero-click vulnerabilities caused by AI-powered transcription features.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/14CwFDiK41p3VK3jeEiHVs9xK0oIF1iVs8midU-nvX7k/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Sponsor: Material Security" rel="nofollow" href="https://material.security/product">Sponsor: Material Security</a></li><li><a title="Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities " rel="nofollow" href="https://www.nytimes.com/2026/01/15/us/politics/cyberattack-venezuela-military.html">Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities </a></li><li><a title="Massive cyberattack on Polish power system in December failed, minister says  " rel="nofollow" href="https://www.reuters.com/sustainability/climate-energy/massive-cyberattack-polish-power-system-december-failed-minister-says-2026-01-13/">Massive cyberattack on Polish power system in December failed, minister says  </a></li><li><a title="What happened in Poland? (Ruben Santamarta)" rel="nofollow" href="https://www.linkedin.com/pulse/what-happened-poland-part-i-ruben-santamarta-bknye/">What happened in Poland? (Ruben Santamarta)</a></li><li><a title="Costin Raiu: What’s Happening in Iran?" rel="nofollow" href="https://medium.com/@costin.raiu/whats-happening-in-iran-93cc103863ab">Costin Raiu: What’s Happening in Iran?</a></li><li><a title="Verizon just had a big outage. Here’s what we know" rel="nofollow" href="https://www.npr.org/2026/01/15/nx-s1-5678889/verizon-outage-what-happened">Verizon just had a big outage. Here’s what we know</a></li><li><a title="Beijing tells Chinese firms to stop using US and Israeli cyber products" rel="nofollow" href="https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/">Beijing tells Chinese firms to stop using US and Israeli cyber products</a></li><li><a title=" MS Patch Tuesday CVE-2026-20805 (exploited in the wild)" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20805"> MS Patch Tuesday CVE-2026-20805 (exploited in the wild)</a></li><li><a title="VoidLink: The Cloud-Native Malware Framework" rel="nofollow" href="https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/">VoidLink: The Cloud-Native Malware Framework</a></li><li><a title="Microsoft disrupts global cybercrime subscription service" rel="nofollow" href="https://blogs.microsoft.com/on-the-issues/2026/01/14/microsoft-disrupts-cybercrime/">Microsoft disrupts global cybercrime subscription service</a></li><li><a title="Project Zero: A 0-click exploit chain for the Pixel 9 " rel="nofollow" href="https://projectzero.google/2026/01/pixel-0-click-part-1.html">Project Zero: A 0-click exploit chain for the Pixel 9 </a></li><li><a title="Joint statement from Google and Apple" rel="nofollow" href="https://blog.google/company-news/inside-google/company-announcements/joint-statement-google-apple/">Joint statement from Google and Apple</a></li><li><a title="Sean Plankey re-nominated to lead CISA " rel="nofollow" href="https://cyberscoop.com/sean-plankey-re-nominated-to-lead-cisa/">Sean Plankey re-nominated to lead CISA </a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="DistrictCon Agenda" rel="nofollow" href="https://www.districtcon.org/agenda">DistrictCon Agenda</a></li><li><a title="Ekoparty Miami  " rel="nofollow" href="https://ekoparty.org/miami/">Ekoparty Miami  </a></li><li><a title="The Thinking Game (Full Documentary)" rel="nofollow" href="https://www.youtube.com/watch?v=d95J8yzvjbQ">The Thinking Game (Full Documentary)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 81</strong>: We dissect New York Times reporting on the &quot;precision&quot; of US cyber operations in Venezuela, the competing narratives around offensive cyber capabilities and &quot;letters of marque&quot; for private hackers. Plus, a mysterious failed cyber attack on Poland&#39;s power grid, internet blackouts in Iran (with fascinating DNS telemetry revealing Chinese bank traffic and Russian website spikes), and news of China&#39;s ban on US/Israeli cybersecurity software.</p>

<p>We also cover Check Point&#39;s research on &quot;VoidLink&quot; (is it a successor to ShadowPad?), Microsoft&#39;s threat intelligence sharing practices, and Google Project Zero&#39;s disclosure of zero-click vulnerabilities caused by AI-powered transcription features.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/14CwFDiK41p3VK3jeEiHVs9xK0oIF1iVs8midU-nvX7k/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Sponsor: Material Security" rel="nofollow" href="https://material.security/product">Sponsor: Material Security</a></li><li><a title="Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities " rel="nofollow" href="https://www.nytimes.com/2026/01/15/us/politics/cyberattack-venezuela-military.html">Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities </a></li><li><a title="Massive cyberattack on Polish power system in December failed, minister says  " rel="nofollow" href="https://www.reuters.com/sustainability/climate-energy/massive-cyberattack-polish-power-system-december-failed-minister-says-2026-01-13/">Massive cyberattack on Polish power system in December failed, minister says  </a></li><li><a title="What happened in Poland? (Ruben Santamarta)" rel="nofollow" href="https://www.linkedin.com/pulse/what-happened-poland-part-i-ruben-santamarta-bknye/">What happened in Poland? (Ruben Santamarta)</a></li><li><a title="Costin Raiu: What’s Happening in Iran?" rel="nofollow" href="https://medium.com/@costin.raiu/whats-happening-in-iran-93cc103863ab">Costin Raiu: What’s Happening in Iran?</a></li><li><a title="Verizon just had a big outage. Here’s what we know" rel="nofollow" href="https://www.npr.org/2026/01/15/nx-s1-5678889/verizon-outage-what-happened">Verizon just had a big outage. Here’s what we know</a></li><li><a title="Beijing tells Chinese firms to stop using US and Israeli cyber products" rel="nofollow" href="https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/">Beijing tells Chinese firms to stop using US and Israeli cyber products</a></li><li><a title=" MS Patch Tuesday CVE-2026-20805 (exploited in the wild)" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20805"> MS Patch Tuesday CVE-2026-20805 (exploited in the wild)</a></li><li><a title="VoidLink: The Cloud-Native Malware Framework" rel="nofollow" href="https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/">VoidLink: The Cloud-Native Malware Framework</a></li><li><a title="Microsoft disrupts global cybercrime subscription service" rel="nofollow" href="https://blogs.microsoft.com/on-the-issues/2026/01/14/microsoft-disrupts-cybercrime/">Microsoft disrupts global cybercrime subscription service</a></li><li><a title="Project Zero: A 0-click exploit chain for the Pixel 9 " rel="nofollow" href="https://projectzero.google/2026/01/pixel-0-click-part-1.html">Project Zero: A 0-click exploit chain for the Pixel 9 </a></li><li><a title="Joint statement from Google and Apple" rel="nofollow" href="https://blog.google/company-news/inside-google/company-announcements/joint-statement-google-apple/">Joint statement from Google and Apple</a></li><li><a title="Sean Plankey re-nominated to lead CISA " rel="nofollow" href="https://cyberscoop.com/sean-plankey-re-nominated-to-lead-cisa/">Sean Plankey re-nominated to lead CISA </a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="DistrictCon Agenda" rel="nofollow" href="https://www.districtcon.org/agenda">DistrictCon Agenda</a></li><li><a title="Ekoparty Miami  " rel="nofollow" href="https://ekoparty.org/miami/">Ekoparty Miami  </a></li><li><a title="The Thinking Game (Full Documentary)" rel="nofollow" href="https://www.youtube.com/watch?v=d95J8yzvjbQ">The Thinking Game (Full Documentary)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Hamid Kashfi on the situation in Iran; Did cyber cause Venezuela blackouts?</title>
  <link>http://securityconversations.fireside.fm/hamid-kashfi-iran-protests-cyber-venezuela</link>
  <guid isPermaLink="false">e3dcead7-7b2e-4924-bde5-18c9ea6bd8e7</guid>
  <pubDate>Fri, 09 Jan 2026 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e3dcead7-7b2e-4924-bde5-18c9ea6bd8e7.mp3" length="103702632" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 80: Researcher Hamid Kashfi returns to unpack Iran’s latest unrest, separating economic reality from propaganda while examining how information control, cyber pressure, and state surveillance are shaping events on the ground.  

Plus, did cyber make the lights go out in Venezuela? 

Cast: Hamid Kashfi, Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:13:55</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e3dcead7-7b2e-4924-bde5-18c9ea6bd8e7/cover.jpg?v=1"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 80: Researcher Hamid Kashfi returns to unpack Iran’s latest unrest, separating economic reality from propaganda while examining how information control, cyber pressure, and state surveillance are shaping events on the ground.  
Plus, did cyber make the lights go out in Venezuela? 
Cast: Hamid Kashfi (https://twitter.com/hkashfi), Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Iran, Israel, Charming Kitten, KittenBusters, Hamid Kashfi, Venezuela, hacktivism, cyberwar, kinetic, blackout, CIA</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 80</strong>: Researcher Hamid Kashfi returns to unpack Iran’s latest unrest, separating economic reality from propaganda while examining how information control, cyber pressure, and state surveillance are shaping events on the ground.  </p>

<p>Plus, did cyber make the lights go out in Venezuela? </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/hkashfi" rel="nofollow">Hamid Kashfi</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/11KT2hDzyOlv3WdxyVfw9pjW2xV56p9dyACgqZenlDBk/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Sponsor: Material Security" rel="nofollow" href="https://material.security/">Sponsor: Material Security</a></li><li><a title="About Hamid Kashfi" rel="nofollow" href="https://www.darkcell.se/about">About Hamid Kashfi</a></li><li><a title="Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks" rel="nofollow" href="https://securityconversations.com/episode/israel-iran-cyberwar-predatory-sparrow-vanishing-crypto-bank-hacks/">Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks</a></li><li><a title="Venezuela strike marks a turning point for US cyber warfare" rel="nofollow" href="https://www.politico.com/news/2026/01/07/venezuela-us-cyber-warfare-00713507">Venezuela strike marks a turning point for US cyber warfare</a></li><li><a title="KittenBusters | CharmingKitten" rel="nofollow" href="https://github.com/KittenBusters/CharmingKitten">KittenBusters | CharmingKitten</a></li><li><a title="Comprehensive Threat Intelligence Report: Charming Kitten" rel="nofollow" href="https://gist.github.com/Hamid-K#comprehensive-threat-intelligence-report-charming-kitten">Comprehensive Threat Intelligence Report: Charming Kitten</a></li><li><a title="Between Three Nerds: The evolution of Iranian cyber espionage" rel="nofollow" href="https://risky.biz/BTN148/">Between Three Nerds: The evolution of Iranian cyber espionage</a></li><li><a title="Trump says U.S. will hit Iran &quot;very hard&quot; if violence continues at protests" rel="nofollow" href="https://www.cbsnews.com/video/trump-says-us-will-hit-iran-very-hard-if-violence-continues-at-protests/">Trump says U.S. will hit Iran "very hard" if violence continues at protests</a></li><li><a title="Venezuelan oil giant PVDSA hit by cyberattack" rel="nofollow" href="https://www.techradar.com/pro/security/venezuelan-oil-giant-pvdsa-hit-by-cyberattack-amid-us-conflict">Venezuelan oil giant PVDSA hit by cyberattack</a></li><li><a title="CIA cyberattacks targeting the Maduro regime didn’t satisfy Trump in his first term" rel="nofollow" href="https://edition.cnn.com/2025/10/29/politics/maduro-cyberattack-trump-cia">CIA cyberattacks targeting the Maduro regime didn’t satisfy Trump in his first term</a></li><li><a title="Antiy Report on cyber operations in Venezuela" rel="nofollow" href="https://www.antiy.cn/research/notice&amp;report/research_report/US_military_cyber_ops_in_Venezuela_spectrum_speculation-analysis.html">Antiy Report on cyber operations in Venezuela</a></li><li><a title="Nationwide internet blackout reported in Iran" rel="nofollow" href="https://www.reuters.com/world/middle-east/iran-warns-suppliers-against-overpricing-or-hoarding-goods-2026-01-08/">Nationwide internet blackout reported in Iran</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 80</strong>: Researcher Hamid Kashfi returns to unpack Iran’s latest unrest, separating economic reality from propaganda while examining how information control, cyber pressure, and state surveillance are shaping events on the ground.  </p>

<p>Plus, did cyber make the lights go out in Venezuela? </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/hkashfi" rel="nofollow">Hamid Kashfi</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/11KT2hDzyOlv3WdxyVfw9pjW2xV56p9dyACgqZenlDBk/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Sponsor: Material Security" rel="nofollow" href="https://material.security/">Sponsor: Material Security</a></li><li><a title="About Hamid Kashfi" rel="nofollow" href="https://www.darkcell.se/about">About Hamid Kashfi</a></li><li><a title="Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks" rel="nofollow" href="https://securityconversations.com/episode/israel-iran-cyberwar-predatory-sparrow-vanishing-crypto-bank-hacks/">Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks</a></li><li><a title="Venezuela strike marks a turning point for US cyber warfare" rel="nofollow" href="https://www.politico.com/news/2026/01/07/venezuela-us-cyber-warfare-00713507">Venezuela strike marks a turning point for US cyber warfare</a></li><li><a title="KittenBusters | CharmingKitten" rel="nofollow" href="https://github.com/KittenBusters/CharmingKitten">KittenBusters | CharmingKitten</a></li><li><a title="Comprehensive Threat Intelligence Report: Charming Kitten" rel="nofollow" href="https://gist.github.com/Hamid-K#comprehensive-threat-intelligence-report-charming-kitten">Comprehensive Threat Intelligence Report: Charming Kitten</a></li><li><a title="Between Three Nerds: The evolution of Iranian cyber espionage" rel="nofollow" href="https://risky.biz/BTN148/">Between Three Nerds: The evolution of Iranian cyber espionage</a></li><li><a title="Trump says U.S. will hit Iran &quot;very hard&quot; if violence continues at protests" rel="nofollow" href="https://www.cbsnews.com/video/trump-says-us-will-hit-iran-very-hard-if-violence-continues-at-protests/">Trump says U.S. will hit Iran "very hard" if violence continues at protests</a></li><li><a title="Venezuelan oil giant PVDSA hit by cyberattack" rel="nofollow" href="https://www.techradar.com/pro/security/venezuelan-oil-giant-pvdsa-hit-by-cyberattack-amid-us-conflict">Venezuelan oil giant PVDSA hit by cyberattack</a></li><li><a title="CIA cyberattacks targeting the Maduro regime didn’t satisfy Trump in his first term" rel="nofollow" href="https://edition.cnn.com/2025/10/29/politics/maduro-cyberattack-trump-cia">CIA cyberattacks targeting the Maduro regime didn’t satisfy Trump in his first term</a></li><li><a title="Antiy Report on cyber operations in Venezuela" rel="nofollow" href="https://www.antiy.cn/research/notice&amp;report/research_report/US_military_cyber_ops_in_Venezuela_spectrum_speculation-analysis.html">Antiy Report on cyber operations in Venezuela</a></li><li><a title="Nationwide internet blackout reported in Iran" rel="nofollow" href="https://www.reuters.com/world/middle-east/iran-warns-suppliers-against-overpricing-or-hoarding-goods-2026-01-08/">Nationwide internet blackout reported in Iran</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>A special mailbag episode with book recommendations</title>
  <link>http://securityconversations.fireside.fm/mongobleed-ai-misuse-books-to-read-mailbag</link>
  <guid isPermaLink="false">3e2f17a7-107f-4709-8697-d066d253fde2</guid>
  <pubDate>Fri, 02 Jan 2026 13:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/3e2f17a7-107f-4709-8697-d066d253fde2.mp3" length="146032941" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 79: We cover MongoBleed (CVE‑2025‑14847), exposed MongoDB deployments, and the sad realization that zero-day attacks are a normal, everyday occurrence.  Plus, AI’s expanding role and misuse across products and workflows, proximity attacks against Bluetooth audio devices, spyware sanctions de-listings, and ransomware economics.

In a special mailbag segment, we give our book recommendations and respond to common questions from the listeners. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>3:01:15</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/3/3e2f17a7-107f-4709-8697-d066d253fde2/cover.jpg?v=1"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 79: We cover MongoBleed (CVE‑2025‑14847), exposed MongoDB deployments, and the sad realization that zero-day attacks are a normal, everyday occurrence.  Plus, AI’s expanding role and misuse across products and workflows, proximity attacks against Bluetooth audio devices, spyware sanctions de-listings, and ransomware economics.
In a special mailbag segment, we give our book recommendations and respond to common questions from the listeners. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>mongodb, mongobleed, mailbag, book recommendations, CVE‑2025‑14847, book club, sanctions, intellexa, predator spyware, bluetooth, ransomware</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 79</strong>: We cover MongoBleed (CVE‑2025‑14847), exposed MongoDB deployments, and the sad realization that zero-day attacks are a normal, everyday occurrence.  Plus, AI’s expanding role and misuse across products and workflows, proximity attacks against Bluetooth audio devices, spyware sanctions de-listings, and ransomware economics.</p>

<p>In a special mailbag segment, we give our book recommendations and respond to common questions from the listeners. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/18T3pUHEZlaSS8CnjRBfeTTpYL9XG4xJaacMu-Z-QTmQ/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Sponsored by Material Security" rel="nofollow" href="https://material.security/">Sponsored by Material Security</a></li><li><a title="MongoDB Server Security Update (Dec 2025)" rel="nofollow" href="https://www.mongodb.com/company/blog/news/mongodb-server-security-update-december-2025">MongoDB Server Security Update (Dec 2025)</a></li><li><a title="CVE Record: CVE-2025-14847" rel="nofollow" href="https://www.cve.org/CVERecord?id=CVE-2025-14847">CVE Record: CVE-2025-14847</a></li><li><a title="Censys on MongoBleed" rel="nofollow" href="https://docs.censys.com/changelog/december-29-2025">Censys on MongoBleed</a></li><li><a title="European Space Agency hit by cyberattack" rel="nofollow" href="https://www.theregister.com/2025/12/31/european_space_agency_hacked/">European Space Agency hit by cyberattack</a></li><li><a title="Security pros plead guilty to ransomware " rel="nofollow" href="https://www.justice.gov/opa/pr/two-americans-plead-guilty-targeting-multiple-us-victims-using-alphv-blackcat-ransomware">Security pros plead guilty to ransomware </a></li><li><a title="US removes sanctions for three execs tied to spyware maker Intellexa" rel="nofollow" href="https://therecord.media/treasury-sanctions-intellexa-removed">US removes sanctions for three execs tied to spyware maker Intellexa</a></li><li><a title="Bluetooth Headphone Jacking: A Key to Your Phone " rel="nofollow" href="https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone">Bluetooth Headphone Jacking: A Key to Your Phone </a></li><li><a title="Dan Geer Black Hat 2015 keynote" rel="nofollow" href="http://geer.tinho.net/geer.blackhat.6viii14.txt">Dan Geer Black Hat 2015 keynote</a></li><li><a title="Book Review: Infected - A Candid Look at VirusTotal’s Birth and Legacy" rel="nofollow" href="https://www.securityweek.com/book-review-infected-a-candid-look-at-virustotals-birth-and-legacy/">Book Review: Infected - A Candid Look at VirusTotal’s Birth and Legacy</a></li><li><a title="Infected: From Side Project to Google: The Journey Behind VirusTotal " rel="nofollow" href="https://www.amazon.com/Infected-Project-Google-Journey-VirusTotal/dp/8409683660">Infected: From Side Project to Google: The Journey Behind VirusTotal </a></li><li><a title="The Human Factor (Inside the CIA&#39;s dysfunctional intelligence culture)" rel="nofollow" href="https://www.encounterbooks.com/books/the-human-factor-inside-the-cias-dysfunctional-intelligence-culture/?srsltid=AfmBOooKdoaZJkHxT2kjEpF8xemImXcVk9w-OtqZ-c4MJRxoyYHB_jve">The Human Factor (Inside the CIA's dysfunctional intelligence culture)</a></li><li><a title="A Killing Art: The Untold History of Tae Kwon Do" rel="nofollow" href="https://akillingart.com/read-the-book/">A Killing Art: The Untold History of Tae Kwon Do</a></li><li><a title="Thou Shall Prosper: Ten Commandments for Making Money" rel="nofollow" href="https://www.goodreads.com/book/show/944278.Thou_Shall_Prosper">Thou Shall Prosper: Ten Commandments for Making Money</a></li><li><a title="Cult of the Dead Cow (by Joseph Menn)" rel="nofollow" href="https://pageaday.com/products/cult-of-the-dead-cow-9781541706118?srsltid=AfmBOoo_14mI_IdJhn7tohBg_w05Y0o0IT0UzLNrekwl_b5kwK-j8mUQ">Cult of the Dead Cow (by Joseph Menn)</a></li><li><a title="The Nvidia Way: Jensen Huang and the Making of a Tech Giant" rel="nofollow" href="https://www.goodreads.com/book/show/218319936-the-nvidia-way">The Nvidia Way: Jensen Huang and the Making of a Tech Giant</a></li><li><a title="From Third World to First: The Singapore Story" rel="nofollow" href="https://www.goodreads.com/book/show/144409.From_Third_World_to_First">From Third World to First: The Singapore Story</a></li><li><a title="Thinking in Systems (PDF)" rel="nofollow" href="https://research.fit.edu/media/site-specific/researchfitedu/coast-climate-adaptation-library/climate-communications/psychology-amp-behavior/Meadows-2008.-Thinking-in-Systems.pdf">Thinking in Systems (PDF)</a></li><li><a title="AI Superpowers: China, Silicon Valley, and the New World Order" rel="nofollow" href="https://www.goodreads.com/book/show/38242135-ai-superpowers">AI Superpowers: China, Silicon Valley, and the New World Order</a></li><li><a title="The Denial of Death: Ernest Becker" rel="nofollow" href="https://www.amazon.com/Denial-Death-Ernest-Becker/dp/0684832402">The Denial of Death: Ernest Becker</a></li><li><a title="Energy and Civilization: A History by Vaclav Smil" rel="nofollow" href="https://www.goodreads.com/book/show/31850765-energy-and-civilization">Energy and Civilization: A History by Vaclav Smil</a></li><li><a title="DeepLearning.AI" rel="nofollow" href="https://www.deeplearning.ai/short-courses/claude-code-a-highly-agentic-coding-assistant/">DeepLearning.AI</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 79</strong>: We cover MongoBleed (CVE‑2025‑14847), exposed MongoDB deployments, and the sad realization that zero-day attacks are a normal, everyday occurrence.  Plus, AI’s expanding role and misuse across products and workflows, proximity attacks against Bluetooth audio devices, spyware sanctions de-listings, and ransomware economics.</p>

<p>In a special mailbag segment, we give our book recommendations and respond to common questions from the listeners. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/18T3pUHEZlaSS8CnjRBfeTTpYL9XG4xJaacMu-Z-QTmQ/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Sponsored by Material Security" rel="nofollow" href="https://material.security/">Sponsored by Material Security</a></li><li><a title="MongoDB Server Security Update (Dec 2025)" rel="nofollow" href="https://www.mongodb.com/company/blog/news/mongodb-server-security-update-december-2025">MongoDB Server Security Update (Dec 2025)</a></li><li><a title="CVE Record: CVE-2025-14847" rel="nofollow" href="https://www.cve.org/CVERecord?id=CVE-2025-14847">CVE Record: CVE-2025-14847</a></li><li><a title="Censys on MongoBleed" rel="nofollow" href="https://docs.censys.com/changelog/december-29-2025">Censys on MongoBleed</a></li><li><a title="European Space Agency hit by cyberattack" rel="nofollow" href="https://www.theregister.com/2025/12/31/european_space_agency_hacked/">European Space Agency hit by cyberattack</a></li><li><a title="Security pros plead guilty to ransomware " rel="nofollow" href="https://www.justice.gov/opa/pr/two-americans-plead-guilty-targeting-multiple-us-victims-using-alphv-blackcat-ransomware">Security pros plead guilty to ransomware </a></li><li><a title="US removes sanctions for three execs tied to spyware maker Intellexa" rel="nofollow" href="https://therecord.media/treasury-sanctions-intellexa-removed">US removes sanctions for three execs tied to spyware maker Intellexa</a></li><li><a title="Bluetooth Headphone Jacking: A Key to Your Phone " rel="nofollow" href="https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone">Bluetooth Headphone Jacking: A Key to Your Phone </a></li><li><a title="Dan Geer Black Hat 2015 keynote" rel="nofollow" href="http://geer.tinho.net/geer.blackhat.6viii14.txt">Dan Geer Black Hat 2015 keynote</a></li><li><a title="Book Review: Infected - A Candid Look at VirusTotal’s Birth and Legacy" rel="nofollow" href="https://www.securityweek.com/book-review-infected-a-candid-look-at-virustotals-birth-and-legacy/">Book Review: Infected - A Candid Look at VirusTotal’s Birth and Legacy</a></li><li><a title="Infected: From Side Project to Google: The Journey Behind VirusTotal " rel="nofollow" href="https://www.amazon.com/Infected-Project-Google-Journey-VirusTotal/dp/8409683660">Infected: From Side Project to Google: The Journey Behind VirusTotal </a></li><li><a title="The Human Factor (Inside the CIA&#39;s dysfunctional intelligence culture)" rel="nofollow" href="https://www.encounterbooks.com/books/the-human-factor-inside-the-cias-dysfunctional-intelligence-culture/?srsltid=AfmBOooKdoaZJkHxT2kjEpF8xemImXcVk9w-OtqZ-c4MJRxoyYHB_jve">The Human Factor (Inside the CIA's dysfunctional intelligence culture)</a></li><li><a title="A Killing Art: The Untold History of Tae Kwon Do" rel="nofollow" href="https://akillingart.com/read-the-book/">A Killing Art: The Untold History of Tae Kwon Do</a></li><li><a title="Thou Shall Prosper: Ten Commandments for Making Money" rel="nofollow" href="https://www.goodreads.com/book/show/944278.Thou_Shall_Prosper">Thou Shall Prosper: Ten Commandments for Making Money</a></li><li><a title="Cult of the Dead Cow (by Joseph Menn)" rel="nofollow" href="https://pageaday.com/products/cult-of-the-dead-cow-9781541706118?srsltid=AfmBOoo_14mI_IdJhn7tohBg_w05Y0o0IT0UzLNrekwl_b5kwK-j8mUQ">Cult of the Dead Cow (by Joseph Menn)</a></li><li><a title="The Nvidia Way: Jensen Huang and the Making of a Tech Giant" rel="nofollow" href="https://www.goodreads.com/book/show/218319936-the-nvidia-way">The Nvidia Way: Jensen Huang and the Making of a Tech Giant</a></li><li><a title="From Third World to First: The Singapore Story" rel="nofollow" href="https://www.goodreads.com/book/show/144409.From_Third_World_to_First">From Third World to First: The Singapore Story</a></li><li><a title="Thinking in Systems (PDF)" rel="nofollow" href="https://research.fit.edu/media/site-specific/researchfitedu/coast-climate-adaptation-library/climate-communications/psychology-amp-behavior/Meadows-2008.-Thinking-in-Systems.pdf">Thinking in Systems (PDF)</a></li><li><a title="AI Superpowers: China, Silicon Valley, and the New World Order" rel="nofollow" href="https://www.goodreads.com/book/show/38242135-ai-superpowers">AI Superpowers: China, Silicon Valley, and the New World Order</a></li><li><a title="The Denial of Death: Ernest Becker" rel="nofollow" href="https://www.amazon.com/Denial-Death-Ernest-Becker/dp/0684832402">The Denial of Death: Ernest Becker</a></li><li><a title="Energy and Civilization: A History by Vaclav Smil" rel="nofollow" href="https://www.goodreads.com/book/show/31850765-energy-and-civilization">Energy and Civilization: A History by Vaclav Smil</a></li><li><a title="DeepLearning.AI" rel="nofollow" href="https://www.deeplearning.ai/short-courses/claude-code-a-highly-agentic-coding-assistant/">DeepLearning.AI</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Quiet Wins, Loud Failures: A Year-End Cybersecurity Reckoning</title>
  <link>http://securityconversations.fireside.fm/quiet-wins-loud-failures-yearend-awards</link>
  <guid isPermaLink="false">1137add6-e8ef-419f-9e3e-ddf5bd1ecefb</guid>
  <pubDate>Fri, 26 Dec 2025 16:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/1137add6-e8ef-419f-9e3e-ddf5bd1ecefb.mp3" length="159884829" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code).

Three Buddy Problem - Episode 78: We close out the year with a no-budget, no-permission awards show, spotlighting the cybersecurity stories that actually mattered. 

Plus, a bizarre polygraph scandal at CISA, Chinese APT research dumps, ransomware pre-notification hiccups, foreign drone bans, and the growing gap between cyber theater and real operational value.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>3:19:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/1137add6-e8ef-419f-9e3e-ddf5bd1ecefb/cover.jpg?v=1"/>
  <description>(Presented by ThreatLocker (https://threatlocker.com/threebuddyproblem): Allow what you need. Block everything else by default, including ransomware and rogue code.)
Three Buddy Problem - Episode 78:  We close out the year with a no-budget, no-permission awards show, spotlighting the cybersecurity stories that actually mattered. 
Plus, a bizarre polygraph scandal at CISA, Chinese APT research dumps, ransomware pre-notification hiccups, foreign drone bans, and the growing gap between cyber theater and real operational value.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Iran, Israel, Bitcoin, Predatory Sparrow, Bitcoin, Novitex, nuclear, Stuxnet, drone swarms, autonomous warfare, China, Russia, Apple, Microsoft, Cloudflare, Romania</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 78</strong>:  We close out the year with a no-budget, no-permission awards show, spotlighting the cybersecurity stories that actually mattered. </p>

<p>Plus, a bizarre polygraph scandal at CISA, Chinese APT research dumps, ransomware pre-notification hiccups, foreign drone bans, and the growing gap between cyber theater and real operational value.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1uPUah0en4wBwUMpyQLWpSK26VZ4MeaQBtddaZQmwPec/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="ThreatLocker Solutions" rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker Solutions</a></li><li><a title="Acting CISA director failed a polygraph" rel="nofollow" href="https://www.politico.com/news/2025/12/21/cisa-acting-director-madhu-gottumukkala-polygraph-investigation-00701996">Acting CISA director failed a polygraph</a></li><li><a title="LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices" rel="nofollow" href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/">LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices</a></li><li><a title="Qianxin’s research on the CSDN watering hole attack" rel="nofollow" href="https://mp.weixin.qq.com/s/qQw1DXE25Gkz_P8pEPVaHg">Qianxin’s research on the CSDN watering hole attack</a></li><li><a title="ViciousTrap - Turning edge devices into honeypots en masse" rel="nofollow" href="https://blog.sekoia.io/vicioustrap-infiltrate-control-lure-turning-edge-devices-into-honeypots-en-masse/">ViciousTrap - Turning edge devices into honeypots en masse</a></li><li><a title="AyySSHush: Tradecraft of an emergent ASUS botnet" rel="nofollow" href="https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/?_ga=2.23890233.202841663.1766426904-1550568476.1766426904">AyySSHush: Tradecraft of an emergent ASUS botnet</a></li><li><a title="Intellexa’s Global Corporate Web (Recorded Future)" rel="nofollow" href="https://www.recordedfuture.com/research/intellexas-global-corporate-web">Intellexa’s Global Corporate Web (Recorded Future)</a></li><li><a title="Frozen in transit: Secret Blizzard’s AiTM hits embassies in Russia" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/">Frozen in transit: Secret Blizzard’s AiTM hits embassies in Russia</a></li><li><a title="GitHub - KittenBusters/CharmingKitten" rel="nofollow" href="https://github.com/KittenBusters/CharmingKitten">GitHub - KittenBusters/CharmingKitten</a></li><li><a title="Bunnie Huang Black Hat keynote (YouTube)" rel="nofollow" href="https://www.youtube.com/watch?v=Nv92TuocnwA">Bunnie Huang Black Hat keynote (YouTube)</a></li><li><a title="How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation" rel="nofollow" href="https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/">How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation</a></li><li><a title="DeepSeek Debates: Chinese Leadership On Cost, True Training Cost, Closed Model Margin Impacts" rel="nofollow" href="https://newsletter.semianalysis.com/p/deepseek-debates">DeepSeek Debates: Chinese Leadership On Cost, True Training Cost, Closed Model Margin Impacts</a></li><li><a title="Behind the Dismantling of Hezbollah " rel="nofollow" href="https://archive.ph/xcBeL">Behind the Dismantling of Hezbollah </a></li><li><a title="Israel Secretly Recruited Iranian Dissidents to Attack Iran From Within" rel="nofollow" href="https://www.propublica.org/article/israel-iran-war-mossad-iranian-recruits">Israel Secretly Recruited Iranian Dissidents to Attack Iran From Within</a></li><li><a title="Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets" rel="nofollow" href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets</a></li><li><a title="Code Orange: Cloudflare resilience plan following recent incidents" rel="nofollow" href="https://blog.cloudflare.com/fail-small-resilience-plan/">Code Orange: Cloudflare resilience plan following recent incidents</a></li><li><a title="Apple SEAR: Memory Integrity Enforcement" rel="nofollow" href="https://security.apple.com/blog/memory-integrity-enforcement/">Apple SEAR: Memory Integrity Enforcement</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 78</strong>:  We close out the year with a no-budget, no-permission awards show, spotlighting the cybersecurity stories that actually mattered. </p>

<p>Plus, a bizarre polygraph scandal at CISA, Chinese APT research dumps, ransomware pre-notification hiccups, foreign drone bans, and the growing gap between cyber theater and real operational value.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1uPUah0en4wBwUMpyQLWpSK26VZ4MeaQBtddaZQmwPec/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="ThreatLocker Solutions" rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker Solutions</a></li><li><a title="Acting CISA director failed a polygraph" rel="nofollow" href="https://www.politico.com/news/2025/12/21/cisa-acting-director-madhu-gottumukkala-polygraph-investigation-00701996">Acting CISA director failed a polygraph</a></li><li><a title="LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices" rel="nofollow" href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/">LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices</a></li><li><a title="Qianxin’s research on the CSDN watering hole attack" rel="nofollow" href="https://mp.weixin.qq.com/s/qQw1DXE25Gkz_P8pEPVaHg">Qianxin’s research on the CSDN watering hole attack</a></li><li><a title="ViciousTrap - Turning edge devices into honeypots en masse" rel="nofollow" href="https://blog.sekoia.io/vicioustrap-infiltrate-control-lure-turning-edge-devices-into-honeypots-en-masse/">ViciousTrap - Turning edge devices into honeypots en masse</a></li><li><a title="AyySSHush: Tradecraft of an emergent ASUS botnet" rel="nofollow" href="https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/?_ga=2.23890233.202841663.1766426904-1550568476.1766426904">AyySSHush: Tradecraft of an emergent ASUS botnet</a></li><li><a title="Intellexa’s Global Corporate Web (Recorded Future)" rel="nofollow" href="https://www.recordedfuture.com/research/intellexas-global-corporate-web">Intellexa’s Global Corporate Web (Recorded Future)</a></li><li><a title="Frozen in transit: Secret Blizzard’s AiTM hits embassies in Russia" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/">Frozen in transit: Secret Blizzard’s AiTM hits embassies in Russia</a></li><li><a title="GitHub - KittenBusters/CharmingKitten" rel="nofollow" href="https://github.com/KittenBusters/CharmingKitten">GitHub - KittenBusters/CharmingKitten</a></li><li><a title="Bunnie Huang Black Hat keynote (YouTube)" rel="nofollow" href="https://www.youtube.com/watch?v=Nv92TuocnwA">Bunnie Huang Black Hat keynote (YouTube)</a></li><li><a title="How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation" rel="nofollow" href="https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/">How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation</a></li><li><a title="DeepSeek Debates: Chinese Leadership On Cost, True Training Cost, Closed Model Margin Impacts" rel="nofollow" href="https://newsletter.semianalysis.com/p/deepseek-debates">DeepSeek Debates: Chinese Leadership On Cost, True Training Cost, Closed Model Margin Impacts</a></li><li><a title="Behind the Dismantling of Hezbollah " rel="nofollow" href="https://archive.ph/xcBeL">Behind the Dismantling of Hezbollah </a></li><li><a title="Israel Secretly Recruited Iranian Dissidents to Attack Iran From Within" rel="nofollow" href="https://www.propublica.org/article/israel-iran-war-mossad-iranian-recruits">Israel Secretly Recruited Iranian Dissidents to Attack Iran From Within</a></li><li><a title="Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets" rel="nofollow" href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets</a></li><li><a title="Code Orange: Cloudflare resilience plan following recent incidents" rel="nofollow" href="https://blog.cloudflare.com/fail-small-resilience-plan/">Code Orange: Cloudflare resilience plan following recent incidents</a></li><li><a title="Apple SEAR: Memory Integrity Enforcement" rel="nofollow" href="https://security.apple.com/blog/memory-integrity-enforcement/">Apple SEAR: Memory Integrity Enforcement</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>What's behind US gov push to 'privatize' offensive cyber operations?</title>
  <link>http://securityconversations.fireside.fm/us-gov-privatization-of-cyber-operations</link>
  <guid isPermaLink="false">7c985910-acfc-4782-aa15-94055ff20afc</guid>
  <pubDate>Sat, 20 Dec 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7c985910-acfc-4782-aa15-94055ff20afc.mp3" length="98212017" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code).

Three Buddy Problem - Episode 77:  New React2Shell data from Microsoft, fresh Apple and Cisco zero-days already in the wild, and state-linked campaigns from Russia and China that show a merging of espionage, crime, and infrastructure disruption.

Plus, the US government's push to enlist private firms in offensive hacking, letters of marque for cartels, new discovery of spyware used against journalists in Belarus, and Amazon catching North Koreans via keystroke latency.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:01:57</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7c985910-acfc-4782-aa15-94055ff20afc/cover.jpg?v=1"/>
  <description>(Presented by ThreatLocker (https://threatlocker.com/threebuddyproblem): Allow what you need. Block everything else by default, including ransomware and rogue code.)
Three Buddy Problem - Episode 77: New React2Shell data from Microsoft, fresh Apple and Cisco zero-days already in the wild, and state-linked campaigns from Russia and China that show a merging of espionage, crime, and infrastructure disruption.
Plus, the US government's push to enlist private firms in offensive hacking, letters of marque for cartels, new discovery of spyware used against journalists in Belarus, and Amazon catching North Koreans via keystroke latency.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>US government, letters of marque, offense, China, Amazon, GRU, iOS 26, Apple, zero-days, Cisco, AI, Russia, Belarus, spyware</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 77</strong>: New React2Shell data from Microsoft, fresh Apple and Cisco zero-days already in the wild, and state-linked campaigns from Russia and China that show a merging of espionage, crime, and infrastructure disruption.</p>

<p>Plus, the US government&#39;s push to enlist private firms in offensive hacking, letters of marque for cartels, new discovery of spyware used against journalists in Belarus, and Amazon catching North Koreans via keystroke latency.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="ThreatLocker Solutions " rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker Solutions </a></li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1DHHlaWwcW0CyTEEO6anEDavihfIqb7sxklsdXJzBNEQ/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Trump Admin Turning to Private Firms in Cyber Offensive" rel="nofollow" href="https://archive.ph/GIb8s">Trump Admin Turning to Private Firms in Cyber Offensive</a></li><li><a title="Microsoft on React2Shell" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/">Microsoft on React2Shell</a></li><li><a title="React2Shell and OpenAI (shoutout Andrew MacPherson)" rel="nofollow" href="https://openai.com/index/introducing-gpt-5-2-codex/">React2Shell and OpenAI (shoutout Andrew MacPherson)</a></li><li><a title="Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw" rel="nofollow" href="https://www.securityweek.com/apple-patches-two-zero-days-tied-to-mysterious-exploited-chrome-flaw/">Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw</a></li><li><a title="iOS 26.2 Security Patches" rel="nofollow" href="https://support.apple.com/en-us/125884">iOS 26.2 Security Patches</a></li><li><a title="Reporters Without Borders uncovers new spyware from Belarus" rel="nofollow" href="https://rsf.org/en/exclusive-rsf-uncovers-new-spyware-belarus">Reporters Without Borders uncovers new spyware from Belarus</a></li><li><a title="Cisco Talos on Cisco 0day attacks" rel="nofollow" href="https://blog.talosintelligence.com/uat-9686/">Cisco Talos on Cisco 0day attacks</a></li><li><a title="Hack of Chinese state time center hints at U.S. advanced missile defense" rel="nofollow" href="https://www.washingtontimes.com/news/2025/dec/17/hack-chinese-state-time-center-hints-us-advanced-missile-defense/">Hack of Chinese state time center hints at U.S. advanced missile defense</a></li><li><a title="Amazon on Russian APT targeting Western critical infrastructure" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-identifies-russian-cyber-threat-group-targeting-western-critical-infrastructure/">Amazon on Russian APT targeting Western critical infrastructure</a></li><li><a title="North Korean infiltrator caught in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location" rel="nofollow" href="https://www.tomshardware.com/tech-industry/cyber-security/north-korean-infiltrator-caught-working-in-amazon-it-department-thanks-to-lag-110ms-keystroke-input-raises-red-flags-over-true-location">North Korean infiltrator caught in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location</a></li><li><a title="Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs" rel="nofollow" href="https://intezer.com/blog/tracing-a-paper-werewolf-campaign-through-ai-generated-decoys-and-excel-xlls/">Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs</a></li><li><a title="Russian defense firms targeted by hackers using AI" rel="nofollow" href="https://www.reuters.com/world/europe/russian-defense-firms-targeted-by-hackers-using-ai-other-tactics-2025-12-19/">Russian defense firms targeted by hackers using AI</a></li><li><a title="TLPBLACK looks back at 2025" rel="nofollow" href="https://tlpblack.net/blog/20251218-cybersecurity-year-in-review">TLPBLACK looks back at 2025</a></li><li><a title="Inside Google&#39;s basement in Malaga: ChatGPT of Cybersecurity" rel="nofollow" href="https://www.surinenglish.com/malaga/malaga-city/inside-googles-basement-malaga-bernardo-quintero-and-20250929151803-nt.html">Inside Google's basement in Malaga: ChatGPT of Cybersecurity</a></li><li><a title="GitHub - xdanx/open-klara: Open KLara Project" rel="nofollow" href="https://github.com/xdanx/open-klara">GitHub - xdanx/open-klara: Open KLara Project</a></li><li><a title="Gepetto Web" rel="nofollow" href="https://blog.kwiatkowski.fr/gepetto-web">Gepetto Web</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 77</strong>: New React2Shell data from Microsoft, fresh Apple and Cisco zero-days already in the wild, and state-linked campaigns from Russia and China that show a merging of espionage, crime, and infrastructure disruption.</p>

<p>Plus, the US government&#39;s push to enlist private firms in offensive hacking, letters of marque for cartels, new discovery of spyware used against journalists in Belarus, and Amazon catching North Koreans via keystroke latency.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="ThreatLocker Solutions " rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker Solutions </a></li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1DHHlaWwcW0CyTEEO6anEDavihfIqb7sxklsdXJzBNEQ/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Trump Admin Turning to Private Firms in Cyber Offensive" rel="nofollow" href="https://archive.ph/GIb8s">Trump Admin Turning to Private Firms in Cyber Offensive</a></li><li><a title="Microsoft on React2Shell" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/">Microsoft on React2Shell</a></li><li><a title="React2Shell and OpenAI (shoutout Andrew MacPherson)" rel="nofollow" href="https://openai.com/index/introducing-gpt-5-2-codex/">React2Shell and OpenAI (shoutout Andrew MacPherson)</a></li><li><a title="Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw" rel="nofollow" href="https://www.securityweek.com/apple-patches-two-zero-days-tied-to-mysterious-exploited-chrome-flaw/">Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw</a></li><li><a title="iOS 26.2 Security Patches" rel="nofollow" href="https://support.apple.com/en-us/125884">iOS 26.2 Security Patches</a></li><li><a title="Reporters Without Borders uncovers new spyware from Belarus" rel="nofollow" href="https://rsf.org/en/exclusive-rsf-uncovers-new-spyware-belarus">Reporters Without Borders uncovers new spyware from Belarus</a></li><li><a title="Cisco Talos on Cisco 0day attacks" rel="nofollow" href="https://blog.talosintelligence.com/uat-9686/">Cisco Talos on Cisco 0day attacks</a></li><li><a title="Hack of Chinese state time center hints at U.S. advanced missile defense" rel="nofollow" href="https://www.washingtontimes.com/news/2025/dec/17/hack-chinese-state-time-center-hints-us-advanced-missile-defense/">Hack of Chinese state time center hints at U.S. advanced missile defense</a></li><li><a title="Amazon on Russian APT targeting Western critical infrastructure" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-identifies-russian-cyber-threat-group-targeting-western-critical-infrastructure/">Amazon on Russian APT targeting Western critical infrastructure</a></li><li><a title="North Korean infiltrator caught in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location" rel="nofollow" href="https://www.tomshardware.com/tech-industry/cyber-security/north-korean-infiltrator-caught-working-in-amazon-it-department-thanks-to-lag-110ms-keystroke-input-raises-red-flags-over-true-location">North Korean infiltrator caught in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location</a></li><li><a title="Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs" rel="nofollow" href="https://intezer.com/blog/tracing-a-paper-werewolf-campaign-through-ai-generated-decoys-and-excel-xlls/">Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs</a></li><li><a title="Russian defense firms targeted by hackers using AI" rel="nofollow" href="https://www.reuters.com/world/europe/russian-defense-firms-targeted-by-hackers-using-ai-other-tactics-2025-12-19/">Russian defense firms targeted by hackers using AI</a></li><li><a title="TLPBLACK looks back at 2025" rel="nofollow" href="https://tlpblack.net/blog/20251218-cybersecurity-year-in-review">TLPBLACK looks back at 2025</a></li><li><a title="Inside Google&#39;s basement in Malaga: ChatGPT of Cybersecurity" rel="nofollow" href="https://www.surinenglish.com/malaga/malaga-city/inside-googles-basement-malaga-bernardo-quintero-and-20250929151803-nt.html">Inside Google's basement in Malaga: ChatGPT of Cybersecurity</a></li><li><a title="GitHub - xdanx/open-klara: Open KLara Project" rel="nofollow" href="https://github.com/xdanx/open-klara">GitHub - xdanx/open-klara: Open KLara Project</a></li><li><a title="Gepetto Web" rel="nofollow" href="https://blog.kwiatkowski.fr/gepetto-web">Gepetto Web</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Legal corruption, React2Shell exploitation, dual-use AI risks</title>
  <link>http://securityconversations.fireside.fm/legal-corruption-react2shell-dual-use-ai</link>
  <guid isPermaLink="false">19aa0c04-e5f9-41d8-aaf1-ff63afa670c2</guid>
  <pubDate>Thu, 11 Dec 2025 00:15:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/19aa0c04-e5f9-41d8-aaf1-ff63afa670c2.mp3" length="109850621" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code).

Three Buddy Problem - Episode 76:  On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.  

Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:12:25</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/19aa0c04-e5f9-41d8-aaf1-ff63afa670c2/cover.jpg?v=1"/>
  <description>(Presented by ThreatLocker (https://threatlocker.com/threebuddyproblem): Allow what you need. Block everything else by default, including ransomware and rogue code.)
Three Buddy Problem - Episode 76:  On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.  
Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>React, zero-day, Patch Tuesday, Microsoft, Google, Russia, China, Chrome, OpenAI, ChatGPT, Ukraine</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 76</strong>:  On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.  </p>

<p>Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1QvJifziSlBUyaXKXsXw3-hdK5nXZpyi8ucx1YSr60gE/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="ThreatLocker : A security platform that prevents ransomware" rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker : A security platform that prevents ransomware</a></li><li><a title="The Anatomy of a React2Shell Compromise (TLPBLACK)" rel="nofollow" href="https://tlpblack.net/blog/20251209-the-anatomy-of-a-react2shell-compromise">The Anatomy of a React2Shell Compromise (TLPBLACK)</a></li><li><a title="CVE-2025-55182 Analysis Report (GreyNoise)" rel="nofollow" href="https://react2025cve-analysis.pages.dev/">CVE-2025-55182 Analysis Report (GreyNoise)</a></li><li><a title="Exploitation of Critical Vulnerability in React Server Components" rel="nofollow" href="https://unit42.paloaltonetworks.com/cve-2025-55182-react-and-CVE-2025-66478-next/">Exploitation of Critical Vulnerability in React Server Components</a></li><li><a title="PeerBlight Linux Backdoor Exploits React2Shell (Huntress)" rel="nofollow" href="https://www.huntress.com/blog/peerblight-linux-backdoor-exploits-react2shell">PeerBlight Linux Backdoor Exploits React2Shell (Huntress)</a></li><li><a title="Patch Tuesday round-up (ZDI)" rel="nofollow" href="https://www.zerodayinitiative.com/blog/2025/12/9/the-december-2025-security-update-review">Patch Tuesday round-up (ZDI)</a></li><li><a title="How Two Hackers Went From Cisco Academy to Cisco CVEs" rel="nofollow" href="https://www.sentinelone.com/labs/malicious-apprentice-how-two-hackers-went-from-cisco-academy-to-cisco-cves/">How Two Hackers Went From Cisco Academy to Cisco CVEs</a></li><li><a title="Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’ " rel="nofollow" href="https://archive.ph/bpdaU">Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’ </a></li><li><a title="OpenAI on dual-use AI risks" rel="nofollow" href="https://openai.com/index/strengthening-cyber-resilience/">OpenAI on dual-use AI risks</a></li><li><a title="Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite" rel="nofollow" href="https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/">Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite</a></li><li><a title="DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal">DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups</a></li><li><a title="Microsoft paying bounties for vulns in third-party code" rel="nofollow" href="https://www.microsoft.com/en-us/msrc/blog/2025/12/in-scope-by-default">Microsoft paying bounties for vulns in third-party code</a></li><li><a title="Cybersecurity 2026 Predictions (SentinelLABS)" rel="nofollow" href="https://www.sentinelone.com/blog/cybersecurity-2026-the-year-ahead-in-ai-adversaries-and-global-change/">Cybersecurity 2026 Predictions (SentinelLABS)</a></li><li><a title="Dakota Cary is in the &quot;anti-China Chorus&quot;" rel="nofollow" href="https://www.linkedin.com/posts/dakotacary_thanks-for-the-love-china-happy-to-be-part-activity-7402094307261706240-Bjr6/">Dakota Cary is in the "anti-China Chorus"</a></li><li><a title="Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing" rel="nofollow" href="https://arxiv.org/abs/2512.09882">Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing</a></li><li><a title="Automated React2Shell vulnerability patching is now available - Vercel" rel="nofollow" href="https://vercel.com/changelog/automated-react2shell-vulnerability-patching-is-now-available">Automated React2Shell vulnerability patching is now available - Vercel</a></li><li><a title="Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research" rel="nofollow" href="https://www.itweb.co.za/article/computer-olympiad-enters-new-era-as-iitpsa-hands-over-to-thinkst-applied-research/j5alrMQALdWMpYQk">Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 76</strong>:  On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.  </p>

<p>Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1QvJifziSlBUyaXKXsXw3-hdK5nXZpyi8ucx1YSr60gE/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="ThreatLocker : A security platform that prevents ransomware" rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker : A security platform that prevents ransomware</a></li><li><a title="The Anatomy of a React2Shell Compromise (TLPBLACK)" rel="nofollow" href="https://tlpblack.net/blog/20251209-the-anatomy-of-a-react2shell-compromise">The Anatomy of a React2Shell Compromise (TLPBLACK)</a></li><li><a title="CVE-2025-55182 Analysis Report (GreyNoise)" rel="nofollow" href="https://react2025cve-analysis.pages.dev/">CVE-2025-55182 Analysis Report (GreyNoise)</a></li><li><a title="Exploitation of Critical Vulnerability in React Server Components" rel="nofollow" href="https://unit42.paloaltonetworks.com/cve-2025-55182-react-and-CVE-2025-66478-next/">Exploitation of Critical Vulnerability in React Server Components</a></li><li><a title="PeerBlight Linux Backdoor Exploits React2Shell (Huntress)" rel="nofollow" href="https://www.huntress.com/blog/peerblight-linux-backdoor-exploits-react2shell">PeerBlight Linux Backdoor Exploits React2Shell (Huntress)</a></li><li><a title="Patch Tuesday round-up (ZDI)" rel="nofollow" href="https://www.zerodayinitiative.com/blog/2025/12/9/the-december-2025-security-update-review">Patch Tuesday round-up (ZDI)</a></li><li><a title="How Two Hackers Went From Cisco Academy to Cisco CVEs" rel="nofollow" href="https://www.sentinelone.com/labs/malicious-apprentice-how-two-hackers-went-from-cisco-academy-to-cisco-cves/">How Two Hackers Went From Cisco Academy to Cisco CVEs</a></li><li><a title="Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’ " rel="nofollow" href="https://archive.ph/bpdaU">Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’ </a></li><li><a title="OpenAI on dual-use AI risks" rel="nofollow" href="https://openai.com/index/strengthening-cyber-resilience/">OpenAI on dual-use AI risks</a></li><li><a title="Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite" rel="nofollow" href="https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/">Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite</a></li><li><a title="DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal">DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups</a></li><li><a title="Microsoft paying bounties for vulns in third-party code" rel="nofollow" href="https://www.microsoft.com/en-us/msrc/blog/2025/12/in-scope-by-default">Microsoft paying bounties for vulns in third-party code</a></li><li><a title="Cybersecurity 2026 Predictions (SentinelLABS)" rel="nofollow" href="https://www.sentinelone.com/blog/cybersecurity-2026-the-year-ahead-in-ai-adversaries-and-global-change/">Cybersecurity 2026 Predictions (SentinelLABS)</a></li><li><a title="Dakota Cary is in the &quot;anti-China Chorus&quot;" rel="nofollow" href="https://www.linkedin.com/posts/dakotacary_thanks-for-the-love-china-happy-to-be-part-activity-7402094307261706240-Bjr6/">Dakota Cary is in the "anti-China Chorus"</a></li><li><a title="Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing" rel="nofollow" href="https://arxiv.org/abs/2512.09882">Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing</a></li><li><a title="Automated React2Shell vulnerability patching is now available - Vercel" rel="nofollow" href="https://vercel.com/changelog/automated-react2shell-vulnerability-patching-is-now-available">Automated React2Shell vulnerability patching is now available - Vercel</a></li><li><a title="Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research" rel="nofollow" href="https://www.itweb.co.za/article/computer-olympiad-enters-new-era-as-iitpsa-hands-over-to-thinkst-applied-research/j5alrMQALdWMpYQk">Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>APTs pounce on React2Shell; BRICKSTORM backdoors; .gov surveillance</title>
  <link>http://securityconversations.fireside.fm/react2shell-group78-brickstorm-ai-smart-contract</link>
  <guid isPermaLink="false">e6afdf9b-3a12-408d-a9c0-59ed0c3b899a</guid>
  <pubDate>Sat, 06 Dec 2025 10:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e6afdf9b-3a12-408d-a9c0-59ed0c3b899a.mp3" length="80166900" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code).

Three Buddy Problem - Episode 75:  We dig into a CVSS 10/10 unauthenticated RCE bug causing chaos across the internet and early signs that Chinese APTs are already launching exploits, the cascading patch chaos, and a long tail of malware intrusions to come.

Plus, commentary on Chrome’s telemetry collection, Microsoft and the "SFI success story," newest BRICKSTORM backdoor intrusions, the US national security strategy, Anthropic's AI popping smart-contract bugs, a secret FBI ransomware-hunting unit getting weird, and a pair of sad stories in the security community.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>1:41:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e6afdf9b-3a12-408d-a9c0-59ed0c3b899a/cover.jpg?v=1"/>
  <description>(Presented by ThreatLocker (https://threatlocker.com/threebuddyproblem): Allow what you need. Block everything else by default, including ransomware and rogue code.)
Three Buddy Problem - Episode 75: We dig into a CVSS 10/10 unauthenticated RCE bug causing chaos across the internet and early signs that Chinese APTs are already launching exploits, the cascading patch chaos, and a long tail of malware intrusions to come.
Plus, commentary on Chrome’s telemetry collection, Microsoft and the "SFI success story," newest BRICKSTORM backdoor intrusions, the US national security strategy, Anthropic's AI popping smart-contract bugs, a secret FBI ransomware-hunting unit getting weird, and a pair of sad stories in the security community.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>ThreatLocker, React2Shell, Jackpot Panda, China, CVE-2025-55182, RCE, Warp Panda, Brickstorm, FirstWap, GrapheneOS, Group 78,  Intellexa, spyware, Calisto, Google, Microsoft</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 75</strong>: We dig into a CVSS 10/10 unauthenticated RCE bug causing chaos across the internet and early signs that Chinese APTs are already launching exploits, the cascading patch chaos, and a long tail of malware intrusions to come.</p>

<p>Plus, commentary on Chrome’s telemetry collection, Microsoft and the &quot;SFI success story,&quot; newest BRICKSTORM backdoor intrusions, the US national security strategy, Anthropic&#39;s AI popping smart-contract bugs, a secret FBI ransomware-hunting unit getting weird, and a pair of sad stories in the security community.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1DZ0EOVM_wbkXbdlKkiSsf1PpbjYqBTAcJLAxnO2TeYU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="ThreatLocker" rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker</a> &mdash; Meet the cybersecurity platform that prevents ransomware</li><li><a title="An essay by Vess" rel="nofollow" href="https://bontchev.nlcv.bas.bg/bye.html">An essay by Vess</a></li><li><a title="RIP Stealth" rel="nofollow" href="https://www.thc.org/404/stealth/eulogy.txt">RIP Stealth</a></li><li><a title="Google Goodbye to the Chrome Cleanup Tool" rel="nofollow" href="https://security.googleblog.com/2023/03/thank-you-and-goodbye-to-chrome-cleanup.html">Google Goodbye to the Chrome Cleanup Tool</a></li><li><a title="US National Security Strategy (PDF)" rel="nofollow" href="https://www.whitehouse.gov/wp-content/uploads/2025/12/2025-National-Security-Strategy.pdf">US National Security Strategy (PDF)</a></li><li><a title="Critical Security Vulnerability in React Server Components (CVE-2025-55182) " rel="nofollow" href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components">Critical Security Vulnerability in React Server Components (CVE-2025-55182) </a></li><li><a title="Chinese threat groups rapidly exploit React2Shell vuln" rel="nofollow" href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/">Chinese threat groups rapidly exploit React2Shell vuln</a></li><li><a title="AWS MadPot" rel="nofollow" href="https://aws.amazon.com/blogs/security/how-aws-tracks-the-clouds-biggest-security-threats-and-helps-shut-them-down/">AWS MadPot</a></li><li><a title="BRICKSTORM Backdoor (PDF)" rel="nofollow" href="https://media.defense.gov/2025/Dec/04/2003834878/-1/-1/0/MALWARE-ANALYSIS-REPORT-BRICKSTORM-BACKDOOR.PDF">BRICKSTORM Backdoor (PDF)</a></li><li><a title="WARP PANDA: A New Sophisticated China-Nexus Adversary" rel="nofollow" href="https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/">WARP PANDA: A New Sophisticated China-Nexus Adversary</a></li><li><a title="Meet Group 78, the secret US task force that fights cybercriminals" rel="nofollow" href="https://archive.vn/UKEmz">Meet Group 78, the secret US task force that fights cybercriminals</a></li><li><a title="Recorded Future: Intellexa’s Global Corporate Web" rel="nofollow" href="https://www.recordedfuture.com/research/intellexas-global-corporate-web">Recorded Future: Intellexa’s Global Corporate Web</a></li><li><a title="Intellexa’s Prolific Zero-Day Exploits Continue" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/intellexa-zero-day-exploits-continue">Intellexa’s Prolific Zero-Day Exploits Continue</a></li><li><a title="To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware" rel="nofollow" href="https://securitylab.amnesty.org/latest/2025/12/intellexa-leaks-predator-spyware-operations-exposed/">To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware</a></li><li><a title="Apple, Google send new round of threat notifications to users around world" rel="nofollow" href="https://www.reuters.com/technology/apple-sent-new-round-cyber-threat-notifications-users-84-countries-2025-12-05/">Apple, Google send new round of threat notifications to users around world</a></li><li><a title="Calisto Targets Reporters Without Borders in Phishing Campaign" rel="nofollow" href="https://blog.sekoia.io/ngo-reporters-without-borders-targeted-by-calisto-in-recent-campaign/">Calisto Targets Reporters Without Borders in Phishing Campaign</a></li><li><a title="Anthropic AI agents find $4.6M in blockchain smart contract exploits" rel="nofollow" href="https://red.anthropic.com/2025/smart-contracts/">Anthropic AI agents find $4.6M in blockchain smart contract exploits</a></li><li><a title="Lazarus hack largest South Korean crypto exchange" rel="nofollow" href="https://upbit.com/service_center/notice?id=5800&amp;view=share">Lazarus hack largest South Korean crypto exchange</a></li><li><a title="EU countries reach breakthrough on chat-scanning law despite intense pushback" rel="nofollow" href="https://www.euractiv.com/news/eu-countries-reach-breakthrough-on-chat-scanning-law-despite-intense-pushback/">EU countries reach breakthrough on chat-scanning law despite intense pushback</a></li><li><a title="The Denial of Death - by Ernest Becker" rel="nofollow" href="https://www.goodreads.com/book/show/2761.The_Denial_of_Death">The Denial of Death - by Ernest Becker</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://threatlocker.com/threebuddyproblem" rel="nofollow">ThreatLocker</a>: Allow what you need. Block everything else by default, including ransomware and rogue code.</em>)</p>

<p><strong>Three Buddy Problem - Episode 75</strong>: We dig into a CVSS 10/10 unauthenticated RCE bug causing chaos across the internet and early signs that Chinese APTs are already launching exploits, the cascading patch chaos, and a long tail of malware intrusions to come.</p>

<p>Plus, commentary on Chrome’s telemetry collection, Microsoft and the &quot;SFI success story,&quot; newest BRICKSTORM backdoor intrusions, the US national security strategy, Anthropic&#39;s AI popping smart-contract bugs, a secret FBI ransomware-hunting unit getting weird, and a pair of sad stories in the security community.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1DZ0EOVM_wbkXbdlKkiSsf1PpbjYqBTAcJLAxnO2TeYU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="ThreatLocker" rel="nofollow" href="https://www.threatlocker.com/threebuddyproblem">ThreatLocker</a> &mdash; Meet the cybersecurity platform that prevents ransomware</li><li><a title="An essay by Vess" rel="nofollow" href="https://bontchev.nlcv.bas.bg/bye.html">An essay by Vess</a></li><li><a title="RIP Stealth" rel="nofollow" href="https://www.thc.org/404/stealth/eulogy.txt">RIP Stealth</a></li><li><a title="Google Goodbye to the Chrome Cleanup Tool" rel="nofollow" href="https://security.googleblog.com/2023/03/thank-you-and-goodbye-to-chrome-cleanup.html">Google Goodbye to the Chrome Cleanup Tool</a></li><li><a title="US National Security Strategy (PDF)" rel="nofollow" href="https://www.whitehouse.gov/wp-content/uploads/2025/12/2025-National-Security-Strategy.pdf">US National Security Strategy (PDF)</a></li><li><a title="Critical Security Vulnerability in React Server Components (CVE-2025-55182) " rel="nofollow" href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components">Critical Security Vulnerability in React Server Components (CVE-2025-55182) </a></li><li><a title="Chinese threat groups rapidly exploit React2Shell vuln" rel="nofollow" href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/">Chinese threat groups rapidly exploit React2Shell vuln</a></li><li><a title="AWS MadPot" rel="nofollow" href="https://aws.amazon.com/blogs/security/how-aws-tracks-the-clouds-biggest-security-threats-and-helps-shut-them-down/">AWS MadPot</a></li><li><a title="BRICKSTORM Backdoor (PDF)" rel="nofollow" href="https://media.defense.gov/2025/Dec/04/2003834878/-1/-1/0/MALWARE-ANALYSIS-REPORT-BRICKSTORM-BACKDOOR.PDF">BRICKSTORM Backdoor (PDF)</a></li><li><a title="WARP PANDA: A New Sophisticated China-Nexus Adversary" rel="nofollow" href="https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/">WARP PANDA: A New Sophisticated China-Nexus Adversary</a></li><li><a title="Meet Group 78, the secret US task force that fights cybercriminals" rel="nofollow" href="https://archive.vn/UKEmz">Meet Group 78, the secret US task force that fights cybercriminals</a></li><li><a title="Recorded Future: Intellexa’s Global Corporate Web" rel="nofollow" href="https://www.recordedfuture.com/research/intellexas-global-corporate-web">Recorded Future: Intellexa’s Global Corporate Web</a></li><li><a title="Intellexa’s Prolific Zero-Day Exploits Continue" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/intellexa-zero-day-exploits-continue">Intellexa’s Prolific Zero-Day Exploits Continue</a></li><li><a title="To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware" rel="nofollow" href="https://securitylab.amnesty.org/latest/2025/12/intellexa-leaks-predator-spyware-operations-exposed/">To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware</a></li><li><a title="Apple, Google send new round of threat notifications to users around world" rel="nofollow" href="https://www.reuters.com/technology/apple-sent-new-round-cyber-threat-notifications-users-84-countries-2025-12-05/">Apple, Google send new round of threat notifications to users around world</a></li><li><a title="Calisto Targets Reporters Without Borders in Phishing Campaign" rel="nofollow" href="https://blog.sekoia.io/ngo-reporters-without-borders-targeted-by-calisto-in-recent-campaign/">Calisto Targets Reporters Without Borders in Phishing Campaign</a></li><li><a title="Anthropic AI agents find $4.6M in blockchain smart contract exploits" rel="nofollow" href="https://red.anthropic.com/2025/smart-contracts/">Anthropic AI agents find $4.6M in blockchain smart contract exploits</a></li><li><a title="Lazarus hack largest South Korean crypto exchange" rel="nofollow" href="https://upbit.com/service_center/notice?id=5800&amp;view=share">Lazarus hack largest South Korean crypto exchange</a></li><li><a title="EU countries reach breakthrough on chat-scanning law despite intense pushback" rel="nofollow" href="https://www.euractiv.com/news/eu-countries-reach-breakthrough-on-chat-scanning-law-despite-intense-pushback/">EU countries reach breakthrough on chat-scanning law despite intense pushback</a></li><li><a title="The Denial of Death - by Ernest Becker" rel="nofollow" href="https://www.goodreads.com/book/show/2761.The_Denial_of_Death">The Denial of Death - by Ernest Becker</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Shai-Hulud 2.0, Russia GRU Intrusions, and Microsoft’s Regulatory Capture</title>
  <link>http://securityconversations.fireside.fm/regulatory-retreats-russian-ai-fault-line</link>
  <guid isPermaLink="false">7c947947-5644-4334-baea-80d629cfb457</guid>
  <pubDate>Sat, 29 Nov 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7c947947-5644-4334-baea-80d629cfb457.mp3" length="97441193" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 74: We attempt to parse the rumor-fog around Microsoft’s CISO at CYBERWARCON and what it reveals about the company’s shifting posture on intel sharing, regulation, and its outsized grip on the security ecosystem.  Plus, coverage of the Shai-Hulud npm supply-chain mess, CISA’s mobile spyware guidance, NSO’s legal contortions, a sharp new GRU-linked intrusion from Arctic Wolf.

We also discuss the FCC retreating on telco security rules, and the emerging AI arms race shaping how cloud giants hunt threats and how Washington misunderstands all of it.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>1:57:12</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7c947947-5644-4334-baea-80d629cfb457/cover.jpg?v=3"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 74:  We attempt to parse the rumor-fog around Microsoft’s CISO at CYBERWARCON and what it reveals about the company’s shifting posture on intel sharing, regulation, and its outsized grip on the security ecosystem.  Plus, coverage of the Shai-Hulud npm supply-chain mess, CISA’s mobile spyware guidance, NSO’s legal contortions, a sharp new GRU-linked intrusion from Arctic Wolf.
We also discuss the FCC retreating on telco security rules, and the emerging AI arms race shaping how cloud giants hunt threats and how Washington misunderstands all of it.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Microsoft, CISO, CYBERWARCON, Geneva Convention, Shai-Hulud, npm, supply chain, GitHub, CISA, Apple, iOS, Android, spyware, Arctic Wolf, Russia, Ukraine, FCC, Amazon, telcos, Material Security</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 74</strong>:  We attempt to parse the rumor-fog around Microsoft’s CISO at CYBERWARCON and what it reveals about the company’s shifting posture on intel sharing, regulation, and its outsized grip on the security ecosystem.  Plus, coverage of the Shai-Hulud npm supply-chain mess, CISA’s mobile spyware guidance, NSO’s legal contortions, a sharp new GRU-linked intrusion from Arctic Wolf.</p>

<p>We also discuss the FCC retreating on telco security rules, and the emerging AI arms race shaping how cloud giants hunt threats and how Washington misunderstands all of it.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1t0o3sQmcv3EUJyMZCM25MH3SPB4cFAhVfB3qMvwvOQ4/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Microsoft CISO LinkedIn comments" rel="nofollow" href="https://www.linkedin.com/posts/igor-tsyganskiy-9385951_last-week-at-cyberwarcon-i-gave-a-short-activity-7398088148834086912-_Y1A/?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAAAAfLqABykGPZb2fgxnSm0cjGdhFUlQg658">Microsoft CISO LinkedIn comments</a></li><li><a title="Shai Hulud 2.0 Strikes Again" rel="nofollow" href="https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains">Shai Hulud 2.0 Strikes Again</a></li><li><a title="Wiz: Sha1-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposed" rel="nofollow" href="https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack">Wiz: Sha1-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposed</a></li><li><a title="CISA guidance on mobile spyware on iOS, Android" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2025-11/guidance-mobile-communications-best-practices-20251124_508c.pdf">CISA guidance on mobile spyware on iOS, Android</a></li><li><a title="NSO Group argues WhatsApp injunction threatens existence" rel="nofollow" href="https://cyberscoop.com/nso-group-whatsapp-injunction-appeal/">NSO Group argues WhatsApp injunction threatens existence</a></li><li><a title="Arctic Wolf: Russian APT targets U.S. Companies Supporting Ukraine" rel="nofollow" href="https://arcticwolf.com/resources/blog/romcom-utilizing-socgholish-to-deliver-mythic-agent-to-usa-companies-supporting-ukraine/">Arctic Wolf: Russian APT targets U.S. Companies Supporting Ukraine</a></li><li><a title="FCC revokes telecom cybersecurity rules after Salt Typhoon hacks" rel="nofollow" href="https://www.axios.com/2025/11/20/fcc-telecom-cybersecurity-rules-vote">FCC revokes telecom cybersecurity rules after Salt Typhoon hacks</a></li><li><a title="FCC Chairman statement on removing telco rules" rel="nofollow" href="https://www.fcc.gov/news-events/blog/2025/10/29/halloween-treats">FCC Chairman statement on removing telco rules</a></li><li><a title="Amazon Is Using Specialized AI Agents for Deep Bug Hunting" rel="nofollow" href="https://archive.ph/Vq28p">Amazon Is Using Specialized AI Agents for Deep Bug Hunting</a></li><li><a title="Anthropic CEO called to testify on AI cyber threats" rel="nofollow" href="https://www.axios.com/2025/11/26/anthropic-google-cloud-quantum-xchange-house-homeland-hearing">Anthropic CEO called to testify on AI cyber threats</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Material Security (Book a demo)" rel="nofollow" href="https://material.security/product">Material Security (Book a demo)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 74</strong>:  We attempt to parse the rumor-fog around Microsoft’s CISO at CYBERWARCON and what it reveals about the company’s shifting posture on intel sharing, regulation, and its outsized grip on the security ecosystem.  Plus, coverage of the Shai-Hulud npm supply-chain mess, CISA’s mobile spyware guidance, NSO’s legal contortions, a sharp new GRU-linked intrusion from Arctic Wolf.</p>

<p>We also discuss the FCC retreating on telco security rules, and the emerging AI arms race shaping how cloud giants hunt threats and how Washington misunderstands all of it.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1t0o3sQmcv3EUJyMZCM25MH3SPB4cFAhVfB3qMvwvOQ4/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Microsoft CISO LinkedIn comments" rel="nofollow" href="https://www.linkedin.com/posts/igor-tsyganskiy-9385951_last-week-at-cyberwarcon-i-gave-a-short-activity-7398088148834086912-_Y1A/?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAAAAfLqABykGPZb2fgxnSm0cjGdhFUlQg658">Microsoft CISO LinkedIn comments</a></li><li><a title="Shai Hulud 2.0 Strikes Again" rel="nofollow" href="https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains">Shai Hulud 2.0 Strikes Again</a></li><li><a title="Wiz: Sha1-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposed" rel="nofollow" href="https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack">Wiz: Sha1-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposed</a></li><li><a title="CISA guidance on mobile spyware on iOS, Android" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2025-11/guidance-mobile-communications-best-practices-20251124_508c.pdf">CISA guidance on mobile spyware on iOS, Android</a></li><li><a title="NSO Group argues WhatsApp injunction threatens existence" rel="nofollow" href="https://cyberscoop.com/nso-group-whatsapp-injunction-appeal/">NSO Group argues WhatsApp injunction threatens existence</a></li><li><a title="Arctic Wolf: Russian APT targets U.S. Companies Supporting Ukraine" rel="nofollow" href="https://arcticwolf.com/resources/blog/romcom-utilizing-socgholish-to-deliver-mythic-agent-to-usa-companies-supporting-ukraine/">Arctic Wolf: Russian APT targets U.S. Companies Supporting Ukraine</a></li><li><a title="FCC revokes telecom cybersecurity rules after Salt Typhoon hacks" rel="nofollow" href="https://www.axios.com/2025/11/20/fcc-telecom-cybersecurity-rules-vote">FCC revokes telecom cybersecurity rules after Salt Typhoon hacks</a></li><li><a title="FCC Chairman statement on removing telco rules" rel="nofollow" href="https://www.fcc.gov/news-events/blog/2025/10/29/halloween-treats">FCC Chairman statement on removing telco rules</a></li><li><a title="Amazon Is Using Specialized AI Agents for Deep Bug Hunting" rel="nofollow" href="https://archive.ph/Vq28p">Amazon Is Using Specialized AI Agents for Deep Bug Hunting</a></li><li><a title="Anthropic CEO called to testify on AI cyber threats" rel="nofollow" href="https://www.axios.com/2025/11/26/anthropic-google-cloud-quantum-xchange-house-homeland-hearing">Anthropic CEO called to testify on AI cyber threats</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Material Security (Book a demo)" rel="nofollow" href="https://material.security/product">Material Security (Book a demo)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Gemini 3 reactions, Fortinet/Chrome zero-days, a Cloudflare monoculture and a billion-dollar crypto twist</title>
  <link>http://securityconversations.fireside.fm/cyberwarcon-fortinet-chrome-zeroday-gemini</link>
  <guid isPermaLink="false">31f838fc-0034-4c68-9a05-ee1c232837dc</guid>
  <pubDate>Fri, 21 Nov 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/31f838fc-0034-4c68-9a05-ee1c232837dc.mp3" length="115839478" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>(Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices).

Three Buddy Problem - Episode 73:  The buddies react to Google’s release of Gemini 3 and its early performance, new Chrome interface changes landing on users’ machines, and major highlights from CYBERWARCON. We revisit the long-running debate over APT naming conventions, examine Amazon’s latest threat-intel reporting on Iranian activity, and walk through the Cloudflare outage that briefly knocked chunks of the internet offline. 

Plus, new APT reports from ESET, Positive Technologies, and SecurityScorecard, and China's CN-CERT (now validated claim) that the U.S. government seized billions in Bitcoin tied to the Lubian mining-pool hack. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:19:41</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/3/31f838fc-0034-4c68-9a05-ee1c232837dc/cover.jpg?v=2"/>
  <description>(Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.)
Three Buddy Problem - Episode 73:  The buddies react to Google’s release of Gemini 3 and its early performance, new Chrome interface changes landing on users’ machines, and major highlights from CYBERWARCON. We revisit the long-running debate over APT naming conventions, examine Amazon’s latest threat-intel reporting on Iranian activity, and walk through the Cloudflare outage that briefly knocked chunks of the internet offline. 
Plus, new APT reports from ESET, Positive Technologies, and SecurityScorecard, and China's CN-CERT (now validated claim) that the U.S. government seized billions in Bitcoin tied to the Lubian mining-pool hack.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Gemini, Google, Microsoft, CYBERWARCON, APT29, China, Russia, Volt Typhoon, Amazon, Venture Capital, Fortinet, Chrome, zero-day, Cloudflare, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 73</strong>:  The buddies react to Google’s release of Gemini 3 and its early performance, new Chrome interface changes landing on users’ machines, and major highlights from CYBERWARCON. We revisit the long-running debate over APT naming conventions, examine Amazon’s latest threat-intel reporting on Iranian activity, and walk through the Cloudflare outage that briefly knocked chunks of the internet offline. </p>

<p>Plus, new APT reports from ESET, Positive Technologies, and SecurityScorecard, and China&#39;s CN-CERT (now validated claim) that the U.S. government seized billions in Bitcoin tied to the Lubian mining-pool hack.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Material Security -- Stop Attacks, Secure Data " rel="nofollow" href="https://material.security/product">Material Security -- Stop Attacks, Secure Data </a></li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1se0fiX0sXOEpp5I6NiQJYfcji4_6b0uowkHl2sv8vuU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Why Microsoft Needs to Split Windows in Two" rel="nofollow" href="https://medium.com/@costin.raiu/is-it-time-for-a-divorce-why-microsoft-needs-to-split-windows-in-two-29a46b0621b6?postPublishedType=initial">Why Microsoft Needs to Split Windows in Two</a></li><li><a title="CYBERWARCON agenda" rel="nofollow" href="https://www.cyberwarcon.com/agenda-25">CYBERWARCON agenda</a></li><li><a title="Amazon: Nation-state actors bridging cyber and kinetic warfare" rel="nofollow" href="https://aws.amazon.com/blogs/security/new-amazon-threat-intelligence-findings-nation-state-actors-bridging-cyber-and-kinetic-warfare/">Amazon: Nation-state actors bridging cyber and kinetic warfare</a></li><li><a title="Cyber Warfare Startup Nabs Contracts to Give US Military Hackers AI Tools" rel="nofollow" href="https://archive.ph/YXh8Y">Cyber Warfare Startup Nabs Contracts to Give US Military Hackers AI Tools</a></li><li><a title="Fortinet documents 0day attacks" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-25-513">Fortinet documents 0day attacks</a></li><li><a title="Fortinet CVE-2025-64446 Under Active Attack" rel="nofollow" href="https://decipher.sc/2025/11/17/fortinet-cve-2025-64446-under-active-attack/">Fortinet CVE-2025-64446 Under Active Attack</a></li><li><a title="Google Chrome zero-day exploited" rel="nofollow" href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html">Google Chrome zero-day exploited</a></li><li><a title="Cloudflare statement on outage on November 18, 2025" rel="nofollow" href="https://blog.cloudflare.com/18-november-2025-outage/">Cloudflare statement on outage on November 18, 2025</a></li><li><a title="Cloudflare just got faster and more secure, powered by Rust" rel="nofollow" href="https://blog.cloudflare.com/20-percent-internet-upgrade/">Cloudflare just got faster and more secure, powered by Rust</a></li><li><a title="Russian alleged cyber-hacker faces extradition to US after arrest in Thailand" rel="nofollow" href="https://edition.cnn.com/2025/11/15/asia/denis-obrezko-russia-hacker-thailand-void-blizzard">Russian alleged cyber-hacker faces extradition to US after arrest in Thailand</a></li><li><a title="Russian detained over connection to Void Blizzard attacks" rel="nofollow" href="https://repoct.org/news/105205-ekc-sotrudnik_akademii_kriptografii_fsb_i_laboratorii_kasperskogo_zaderhan_v_tailande_po_delu_o_hakerskoj_gruppe_void_bl">Russian detained over connection to Void Blizzard attacks</a></li><li><a title="Positive Technologies: Attacks of the Striking Panda" rel="nofollow" href="https://ptsecurity.com/research/pt-esc-threat-intelligence/striking-panda-attacks-apt31-today/">Positive Technologies: Attacks of the Striking Panda</a></li><li><a title="PlushDaemon compromises network devices for adversary-in-the-middle attacks" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/">PlushDaemon compromises network devices for adversary-in-the-middle attacks</a></li><li><a title="PlushDaemon compromises supply chain of Korean VPN service" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/">PlushDaemon compromises supply chain of Korean VPN service</a></li><li><a title="ASUS Routers Hijacked in Global &#39;WrtHug&#39; Operation" rel="nofollow" href="https://securityscorecard.com/wp-content/uploads/2025/11/STRIKE_Asus_WrtHug-Report_V6.pdf">ASUS Routers Hijacked in Global 'WrtHug' Operation</a></li><li><a title="Arkham on Bitcoin Chen Zhi seized funds" rel="nofollow" href="https://intel.arkm.com/explorer/tx/55de9e33c7fd10705d0f1e05f5899ae27c61a3f13dd3ff5156ce794b504094ae">Arkham on Bitcoin Chen Zhi seized funds</a></li><li><a title="US DOJ $15 Billion Bitcoin Indictment" rel="nofollow" href="https://www.justice.gov/usao-edny/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged">US DOJ $15 Billion Bitcoin Indictment</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="PIVOTcon 2026" rel="nofollow" href="https://pivotcon.org/">PIVOTcon 2026</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li><li><a title="The Age of Disclosure (Prime Video)" rel="nofollow" href="https://www.amazon.com/Age-Disclosure-Dan-Farah/dp/B0FMF29BBJ">The Age of Disclosure (Prime Video)</a></li><li><a title="Amazon.com: Bullshit Jobs" rel="nofollow" href="https://www.amazon.com/dp/B079YYRGSB/">Amazon.com: Bullshit Jobs</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>(<em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em>)</p>

<p><strong>Three Buddy Problem - Episode 73</strong>:  The buddies react to Google’s release of Gemini 3 and its early performance, new Chrome interface changes landing on users’ machines, and major highlights from CYBERWARCON. We revisit the long-running debate over APT naming conventions, examine Amazon’s latest threat-intel reporting on Iranian activity, and walk through the Cloudflare outage that briefly knocked chunks of the internet offline. </p>

<p>Plus, new APT reports from ESET, Positive Technologies, and SecurityScorecard, and China&#39;s CN-CERT (now validated claim) that the U.S. government seized billions in Bitcoin tied to the Lubian mining-pool hack.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Material Security -- Stop Attacks, Secure Data " rel="nofollow" href="https://material.security/product">Material Security -- Stop Attacks, Secure Data </a></li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1se0fiX0sXOEpp5I6NiQJYfcji4_6b0uowkHl2sv8vuU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Why Microsoft Needs to Split Windows in Two" rel="nofollow" href="https://medium.com/@costin.raiu/is-it-time-for-a-divorce-why-microsoft-needs-to-split-windows-in-two-29a46b0621b6?postPublishedType=initial">Why Microsoft Needs to Split Windows in Two</a></li><li><a title="CYBERWARCON agenda" rel="nofollow" href="https://www.cyberwarcon.com/agenda-25">CYBERWARCON agenda</a></li><li><a title="Amazon: Nation-state actors bridging cyber and kinetic warfare" rel="nofollow" href="https://aws.amazon.com/blogs/security/new-amazon-threat-intelligence-findings-nation-state-actors-bridging-cyber-and-kinetic-warfare/">Amazon: Nation-state actors bridging cyber and kinetic warfare</a></li><li><a title="Cyber Warfare Startup Nabs Contracts to Give US Military Hackers AI Tools" rel="nofollow" href="https://archive.ph/YXh8Y">Cyber Warfare Startup Nabs Contracts to Give US Military Hackers AI Tools</a></li><li><a title="Fortinet documents 0day attacks" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-25-513">Fortinet documents 0day attacks</a></li><li><a title="Fortinet CVE-2025-64446 Under Active Attack" rel="nofollow" href="https://decipher.sc/2025/11/17/fortinet-cve-2025-64446-under-active-attack/">Fortinet CVE-2025-64446 Under Active Attack</a></li><li><a title="Google Chrome zero-day exploited" rel="nofollow" href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html">Google Chrome zero-day exploited</a></li><li><a title="Cloudflare statement on outage on November 18, 2025" rel="nofollow" href="https://blog.cloudflare.com/18-november-2025-outage/">Cloudflare statement on outage on November 18, 2025</a></li><li><a title="Cloudflare just got faster and more secure, powered by Rust" rel="nofollow" href="https://blog.cloudflare.com/20-percent-internet-upgrade/">Cloudflare just got faster and more secure, powered by Rust</a></li><li><a title="Russian alleged cyber-hacker faces extradition to US after arrest in Thailand" rel="nofollow" href="https://edition.cnn.com/2025/11/15/asia/denis-obrezko-russia-hacker-thailand-void-blizzard">Russian alleged cyber-hacker faces extradition to US after arrest in Thailand</a></li><li><a title="Russian detained over connection to Void Blizzard attacks" rel="nofollow" href="https://repoct.org/news/105205-ekc-sotrudnik_akademii_kriptografii_fsb_i_laboratorii_kasperskogo_zaderhan_v_tailande_po_delu_o_hakerskoj_gruppe_void_bl">Russian detained over connection to Void Blizzard attacks</a></li><li><a title="Positive Technologies: Attacks of the Striking Panda" rel="nofollow" href="https://ptsecurity.com/research/pt-esc-threat-intelligence/striking-panda-attacks-apt31-today/">Positive Technologies: Attacks of the Striking Panda</a></li><li><a title="PlushDaemon compromises network devices for adversary-in-the-middle attacks" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/">PlushDaemon compromises network devices for adversary-in-the-middle attacks</a></li><li><a title="PlushDaemon compromises supply chain of Korean VPN service" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/">PlushDaemon compromises supply chain of Korean VPN service</a></li><li><a title="ASUS Routers Hijacked in Global &#39;WrtHug&#39; Operation" rel="nofollow" href="https://securityscorecard.com/wp-content/uploads/2025/11/STRIKE_Asus_WrtHug-Report_V6.pdf">ASUS Routers Hijacked in Global 'WrtHug' Operation</a></li><li><a title="Arkham on Bitcoin Chen Zhi seized funds" rel="nofollow" href="https://intel.arkm.com/explorer/tx/55de9e33c7fd10705d0f1e05f5899ae27c61a3f13dd3ff5156ce794b504094ae">Arkham on Bitcoin Chen Zhi seized funds</a></li><li><a title="US DOJ $15 Billion Bitcoin Indictment" rel="nofollow" href="https://www.justice.gov/usao-edny/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged">US DOJ $15 Billion Bitcoin Indictment</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="PIVOTcon 2026" rel="nofollow" href="https://pivotcon.org/">PIVOTcon 2026</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li><li><a title="The Age of Disclosure (Prime Video)" rel="nofollow" href="https://www.amazon.com/Age-Disclosure-Dan-Farah/dp/B0FMF29BBJ">The Age of Disclosure (Prime Video)</a></li><li><a title="Amazon.com: Bullshit Jobs" rel="nofollow" href="https://www.amazon.com/dp/B079YYRGSB/">Amazon.com: Bullshit Jobs</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Anthropic Claude Code automating APT hacks, KnownSec leak, Chinese buses with remote access</title>
  <link>http://securityconversations.fireside.fm/claude-code-china-apt-knownsec-breach-bitcoin-blame</link>
  <guid isPermaLink="false">421221b9-44be-468b-9621-d645805efd84</guid>
  <pubDate>Fri, 14 Nov 2025 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/421221b9-44be-468b-9621-d645805efd84.mp3" length="108418078" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.

Three Buddy Problem - Episode 72: We unpack Anthropic’s conflicting self-promotion around the “first AI-orchestrated cyberattack” using Claude Code and the future of automated APT attacks. 

Plus, Chinese cyber vendor KnownSec falls victim to data breach, fresh accusations that the U.S. stole billions in Bitcoin, Amazon warning about Cisco/Citrix zero-days, Google’s new Private AI Compute and  Microsoft kernel zero-day marked as "actively exploited."

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>2:12:38</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/421221b9-44be-468b-9621-d645805efd84/cover.jpg?v=2"/>
  <description>Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.
Three Buddy Problem - Episode 72:  We unpack Anthropic’s conflicting self-promotion around the “first AI-orchestrated cyberattack” using Claude Code and the future of automated APT attacks. 
Plus, Chinese cyber vendor KnownSec falls victim to data breach, fresh accusations that the U.S. stole billions in Bitcoin, Amazon warning about Cisco/Citrix zero-days, Google’s new Private AI Compute and  Microsoft kernel zero-day marked as "actively exploited."
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>AI, OpenAI, Anthropic, Claude Code, Apple, Google, China, APT, Bitcoin, CISA, Cisco, Ivanti, KnownSec, Microsoft, AI Private Compute, Yutong</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em></p>

<p><strong>Three Buddy Problem - Episode 72</strong>:  We unpack Anthropic’s conflicting self-promotion around the “first AI-orchestrated cyberattack” using Claude Code and the future of automated APT attacks. </p>

<p>Plus, Chinese cyber vendor KnownSec falls victim to data breach, fresh accusations that the U.S. stole billions in Bitcoin, Amazon warning about Cisco/Citrix zero-days, Google’s new Private AI Compute and  Microsoft kernel zero-day marked as &quot;actively exploited.&quot;</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NrlNDzKbVm8tGd7n_ojvGTCMI6btaXLHQt0oMy57bxA/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Material Security case studies" rel="nofollow" href="https://material.security/customers">Material Security case studies</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign" rel="nofollow" href="https://www.anthropic.com/news/disrupting-AI-espionage">Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign</a></li><li><a title="Anthropic report on AI-orchestreated APT campaign ()DF)" rel="nofollow" href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">Anthropic report on AI-orchestreated APT campaign ()DF)</a></li><li><a title="Data breach at Chinese infosec firm reveals weapons arsenal" rel="nofollow" href="https://www.theregister.com/2025/11/09/asia_tech_news_roundup/">Data breach at Chinese infosec firm reveals weapons arsenal</a></li><li><a title="Twitter thread on KnownSec breach details" rel="nofollow" href="https://x.com/intcyberdigest/status/1988355649269387488?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Twitter thread on KnownSec breach details</a></li><li><a title="China Accuses US of Orchestrating $13 Billion Bitcoin Hack" rel="nofollow" href="https://archive.ph/5Iyes">China Accuses US of Orchestrating $13 Billion Bitcoin Hack</a></li><li><a title="CISA finds federal agencies missing critical (exploited) vulns" rel="nofollow" href="https://www.cisa.gov/ed-25-03-guidance-device-updates-and-patching">CISA finds federal agencies missing critical (exploited) vulns</a></li><li><a title="Amazon discovers APT exploiting Cisco and Citrix zero-days" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/">Amazon discovers APT exploiting Cisco and Citrix zero-days</a></li><li><a title="Amazon launches private AI bug bounty program" rel="nofollow" href="https://www.amazon.science/news/amazon-launches-private-ai-bug-bounty-to-strengthen-nova-models">Amazon launches private AI bug bounty program</a></li><li><a title="Amazon Nova" rel="nofollow" href="https://nova.amazon.com/chat">Amazon Nova</a></li><li><a title="Microsoft Warns of Exploited Windows Kernel Zero-Day" rel="nofollow" href="https://decipher.sc/2025/11/11/microsoft-warns-of-exploited-windows-kernel-zero-day/">Microsoft Warns of Exploited Windows Kernel Zero-Day</a></li><li><a title="Google intros Private AI Compute tech" rel="nofollow" href="https://blog.google/technology/ai/google-private-ai-compute/">Google intros Private AI Compute tech</a></li><li><a title="Google paper on Private AI Computer (PDF)" rel="nofollow" href="https://services.google.com/fh/files/misc/private_ai_compute_technical_brief.pdf">Google paper on Private AI Computer (PDF)</a></li><li><a title="OpenAI CISO on NYTimes request for ChatGPT conversations" rel="nofollow" href="https://openai.com/index/fighting-nyt-user-privacy-invasion/">OpenAI CISO on NYTimes request for ChatGPT conversations</a></li><li><a title="UK transport and cyber-security chiefs investigate Chinese-made buses " rel="nofollow" href="https://www.theguardian.com/uk-news/2025/nov/10/uk-transport-cyber-security-chiefs-investigate-chinese-made-buses">UK transport and cyber-security chiefs investigate Chinese-made buses </a></li><li><a title="Ruter pen-tests Chinese electric buses" rel="nofollow" href="https://ruter.no/en/ruter-with-extensive-security-testing-of-electric-buses">Ruter pen-tests Chinese electric buses</a></li><li><a title="DistrictCon" rel="nofollow" href="https://www.districtcon.org/">DistrictCon</a></li><li><a title="CYBERWARCON" rel="nofollow" href="https://www.cyberwarcon.com/">CYBERWARCON</a></li><li><a title="DefCamp 2025" rel="nofollow" href="https://def.camp/">DefCamp 2025</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em></p>

<p><strong>Three Buddy Problem - Episode 72</strong>:  We unpack Anthropic’s conflicting self-promotion around the “first AI-orchestrated cyberattack” using Claude Code and the future of automated APT attacks. </p>

<p>Plus, Chinese cyber vendor KnownSec falls victim to data breach, fresh accusations that the U.S. stole billions in Bitcoin, Amazon warning about Cisco/Citrix zero-days, Google’s new Private AI Compute and  Microsoft kernel zero-day marked as &quot;actively exploited.&quot;</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NrlNDzKbVm8tGd7n_ojvGTCMI6btaXLHQt0oMy57bxA/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Material Security case studies" rel="nofollow" href="https://material.security/customers">Material Security case studies</a></li><li><a title="TLPBLACK" rel="nofollow" href="https://tlpblack.net/">TLPBLACK</a></li><li><a title="Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign" rel="nofollow" href="https://www.anthropic.com/news/disrupting-AI-espionage">Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign</a></li><li><a title="Anthropic report on AI-orchestreated APT campaign ()DF)" rel="nofollow" href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">Anthropic report on AI-orchestreated APT campaign ()DF)</a></li><li><a title="Data breach at Chinese infosec firm reveals weapons arsenal" rel="nofollow" href="https://www.theregister.com/2025/11/09/asia_tech_news_roundup/">Data breach at Chinese infosec firm reveals weapons arsenal</a></li><li><a title="Twitter thread on KnownSec breach details" rel="nofollow" href="https://x.com/intcyberdigest/status/1988355649269387488?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Twitter thread on KnownSec breach details</a></li><li><a title="China Accuses US of Orchestrating $13 Billion Bitcoin Hack" rel="nofollow" href="https://archive.ph/5Iyes">China Accuses US of Orchestrating $13 Billion Bitcoin Hack</a></li><li><a title="CISA finds federal agencies missing critical (exploited) vulns" rel="nofollow" href="https://www.cisa.gov/ed-25-03-guidance-device-updates-and-patching">CISA finds federal agencies missing critical (exploited) vulns</a></li><li><a title="Amazon discovers APT exploiting Cisco and Citrix zero-days" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/">Amazon discovers APT exploiting Cisco and Citrix zero-days</a></li><li><a title="Amazon launches private AI bug bounty program" rel="nofollow" href="https://www.amazon.science/news/amazon-launches-private-ai-bug-bounty-to-strengthen-nova-models">Amazon launches private AI bug bounty program</a></li><li><a title="Amazon Nova" rel="nofollow" href="https://nova.amazon.com/chat">Amazon Nova</a></li><li><a title="Microsoft Warns of Exploited Windows Kernel Zero-Day" rel="nofollow" href="https://decipher.sc/2025/11/11/microsoft-warns-of-exploited-windows-kernel-zero-day/">Microsoft Warns of Exploited Windows Kernel Zero-Day</a></li><li><a title="Google intros Private AI Compute tech" rel="nofollow" href="https://blog.google/technology/ai/google-private-ai-compute/">Google intros Private AI Compute tech</a></li><li><a title="Google paper on Private AI Computer (PDF)" rel="nofollow" href="https://services.google.com/fh/files/misc/private_ai_compute_technical_brief.pdf">Google paper on Private AI Computer (PDF)</a></li><li><a title="OpenAI CISO on NYTimes request for ChatGPT conversations" rel="nofollow" href="https://openai.com/index/fighting-nyt-user-privacy-invasion/">OpenAI CISO on NYTimes request for ChatGPT conversations</a></li><li><a title="UK transport and cyber-security chiefs investigate Chinese-made buses " rel="nofollow" href="https://www.theguardian.com/uk-news/2025/nov/10/uk-transport-cyber-security-chiefs-investigate-chinese-made-buses">UK transport and cyber-security chiefs investigate Chinese-made buses </a></li><li><a title="Ruter pen-tests Chinese electric buses" rel="nofollow" href="https://ruter.no/en/ruter-with-extensive-security-testing-of-electric-buses">Ruter pen-tests Chinese electric buses</a></li><li><a title="DistrictCon" rel="nofollow" href="https://www.districtcon.org/">DistrictCon</a></li><li><a title="CYBERWARCON" rel="nofollow" href="https://www.cyberwarcon.com/">CYBERWARCON</a></li><li><a title="DefCamp 2025" rel="nofollow" href="https://def.camp/">DefCamp 2025</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>LIVE from Ring0 COUNTERMEASURE: Google v FFmpeg, Ransomware Turncoats, Samsung 0days </title>
  <link>http://securityconversations.fireside.fm/google-ffmpeg-ransomware-landfall</link>
  <guid isPermaLink="false">9d487a56-a0a1-4aeb-9568-dbb4b8ae98d4</guid>
  <pubDate>Mon, 10 Nov 2025 11:15:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/9d487a56-a0a1-4aeb-9568-dbb4b8ae98d4.mp3" length="62516613" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Presented by Material Security: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.

Three Buddy Problem - Episode 71:  The buddies travel to Canada for a live recording at the Countermeasure conference, discussing the Google v FFmpeg open-source patching brouhana, ransomware negotiators charged and linked to ransomware attacks, the looming TP-Link ban in the U.S.,  and the discovery of LANDFALL, an APT attack caught using a Samsung mobile zero-day.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.  </itunes:subtitle>
  <itunes:duration>1:09:59</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/9/9d487a56-a0a1-4aeb-9568-dbb4b8ae98d4/cover.jpg?v=2"/>
  <description>Presented by Material Security (https://material.security): We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.
Three Buddy Problem - Episode 71: The buddies travel to Canada for a live recording at the Countermeasure conference, discussing the Google v FFmpeg open-source patching brouhana, ransomware negotiators charged and linked to ransomware attacks, the looming TP-Link ban in the U.S.,  and the discovery of LANDFALL, an APT attack caught using a Samsung mobile zero-day.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Google, FFmpeg, ope-source, BigSleep, Aardvark, ransomware, TP-Link, Landfall, Samsung, 0day, zero-day</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em></p>

<p><strong>Three Buddy Problem - Episode 71</strong>: The buddies travel to Canada for a live recording at the Countermeasure conference, discussing the Google v FFmpeg open-source patching brouhana, ransomware negotiators charged and linked to ransomware attacks, the looming TP-Link ban in the U.S.,  and the discovery of LANDFALL, an APT attack caught using a Samsung mobile zero-day.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Material Security " rel="nofollow" href="https://material.security/">Material Security </a> &mdash; We protect your company’s most valuable materials — the emails, files, and accounts that live in your Google Workspace &amp; Microsoft 365 cloud offices.</li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1qXNE6Y3Z1tib1ERSeg_W58B8tYmR2iG1vvcMQNoJGWQ/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="FFmpeg complains about Google BigSleep AI" rel="nofollow" href="https://x.com/ffmpeg/status/1984178359354483058?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">FFmpeg complains about Google BigSleep AI</a></li><li><a title="Google v FFmpeg brouhaha" rel="nofollow" href="https://x.com/seanhn/status/1984941644517417263?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Google v FFmpeg brouhaha</a></li><li><a title="Curl&#39;s Daniel Stenberg on a new breed of AI analyzers" rel="nofollow" href="https://daniel.haxx.se/blog/2025/10/10/a-new-breed-of-analyzers/">Curl's Daniel Stenberg on a new breed of AI analyzers</a></li><li><a title="unit42.paloaltonetworks.com" rel="nofollow" href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/">unit42.paloaltonetworks.com</a></li><li><a title=" iOS 26.1 security updates" rel="nofollow" href="https://support.apple.com/en-us/125632"> iOS 26.1 security updates</a></li><li><a title="U.S. agencies back banning TP-Link home routers on security grounds" rel="nofollow" href="https://archive.ph/Ldmde">U.S. agencies back banning TP-Link home routers on security grounds</a></li><li><a title="TLP BLACK" rel="nofollow" href="https://tlpblack.net/">TLP BLACK</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><em>Presented by <a href="https://material.security" rel="nofollow">Material Security</a>: We protect your company’s most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.</em></p>

<p><strong>Three Buddy Problem - Episode 71</strong>: The buddies travel to Canada for a live recording at the Countermeasure conference, discussing the Google v FFmpeg open-source patching brouhana, ransomware negotiators charged and linked to ransomware attacks, the looming TP-Link ban in the U.S.,  and the discovery of LANDFALL, an APT attack caught using a Samsung mobile zero-day.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Material Security " rel="nofollow" href="https://material.security/">Material Security </a> &mdash; We protect your company’s most valuable materials — the emails, files, and accounts that live in your Google Workspace &amp; Microsoft 365 cloud offices.</li><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1qXNE6Y3Z1tib1ERSeg_W58B8tYmR2iG1vvcMQNoJGWQ/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="FFmpeg complains about Google BigSleep AI" rel="nofollow" href="https://x.com/ffmpeg/status/1984178359354483058?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">FFmpeg complains about Google BigSleep AI</a></li><li><a title="Google v FFmpeg brouhaha" rel="nofollow" href="https://x.com/seanhn/status/1984941644517417263?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Google v FFmpeg brouhaha</a></li><li><a title="Curl&#39;s Daniel Stenberg on a new breed of AI analyzers" rel="nofollow" href="https://daniel.haxx.se/blog/2025/10/10/a-new-breed-of-analyzers/">Curl's Daniel Stenberg on a new breed of AI analyzers</a></li><li><a title="unit42.paloaltonetworks.com" rel="nofollow" href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/">unit42.paloaltonetworks.com</a></li><li><a title=" iOS 26.1 security updates" rel="nofollow" href="https://support.apple.com/en-us/125632"> iOS 26.1 security updates</a></li><li><a title="U.S. agencies back banning TP-Link home routers on security grounds" rel="nofollow" href="https://archive.ph/Ldmde">U.S. agencies back banning TP-Link home routers on security grounds</a></li><li><a title="TLP BLACK" rel="nofollow" href="https://tlpblack.net/">TLP BLACK</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>OpenAI’s Dave Aitel talks Aardvark, economics of bug-hunting with LLMs </title>
  <link>http://securityconversations.fireside.fm/dave-aitel-openai-aardvark-bug-hunting</link>
  <guid isPermaLink="false">2a7863a7-7d3f-4891-b8d8-618b97a676dd</guid>
  <pubDate>Fri, 31 Oct 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/2a7863a7-7d3f-4891-b8d8-618b97a676dd.mp3" length="106001179" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 70:  Dave Aitel from OpenAI's technical staff joins the buddies to discuss the just-launched Aardvark, OpenAI’s agentic “security researcher” that claims to read code, finds bugs, validates exploits, and ships patches. We press him on where LLMs beat fuzzers, privacy boundaries, human-in-the-loop realities, SDLC budgets, pen-test cadence, and the zero-day economy.

Plus, L3 Harris/Trenchant exec pleads guilty to selling exploits to Russian brokers, Kaspersky catches the return of HackingTeam using Chrome zero-day exploit chain, and news of a proposed law in Russia to force researchers to report vulnerabilities first to goverment agencies.

Cast: Dave Aitel (Technical Staff, OpenAI), Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:10:48</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/2a7863a7-7d3f-4891-b8d8-618b97a676dd/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 70: Dave Aitel from OpenAI's technical staff joins the buddies to discuss the just-launched Aardvark, OpenAI’s agentic “security researcher” that claims to read code, finds bugs, validates exploits, and ships patches. We press him on where LLMs beat fuzzers, privacy boundaries, human-in-the-loop realities, SDLC budgets, pen-test cadence, and the zero-day economy.
Plus, L3 Harris/Trenchant exec pleads guilty to selling exploits to Russian brokers, Kaspersky catches the return of HackingTeam using Chrome zero-day exploit chain, and news of a proposed law in Russia to force researchers to report vulnerabilities first to goverment agencies.
Cast: Dave Aitel (https://www.linkedin.com/in/daveaitel/) (Technical Staff, OpenAI), Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>OpenAI, Aardvark, BigSleep, Google, LLM, Russia, China, HackingTeam, Kaspersky, APT, mercenary spyware, Chrome, zero-day, Trenchant, L3 Harris, Operation Zero, Dave Aitel</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 70</strong>: Dave Aitel from OpenAI&#39;s technical staff joins the buddies to discuss the just-launched Aardvark, OpenAI’s agentic “security researcher” that claims to read code, finds bugs, validates exploits, and ships patches. We press him on where LLMs beat fuzzers, privacy boundaries, human-in-the-loop realities, SDLC budgets, pen-test cadence, and the zero-day economy.</p>

<p>Plus, L3 Harris/Trenchant exec pleads guilty to selling exploits to Russian brokers, Kaspersky catches the return of HackingTeam using Chrome zero-day exploit chain, and news of a proposed law in Russia to force researchers to report vulnerabilities first to goverment agencies.</p>

<p><strong>Cast:</strong> <a href="https://www.linkedin.com/in/daveaitel/" rel="nofollow">Dave Aitel</a> (Technical Staff, OpenAI), <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Pz8JWiwA-ZrLMHG8di264ioCO9CVtl3ac_-N9fUDrls/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Episode 70 Livestream - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=7IkmOXujJTY">Episode 70 Livestream - YouTube</a></li><li><a title="Aardvark: OpenAI’s agentic security researcher" rel="nofollow" href="https://openai.com/index/introducing-aardvark/">Aardvark: OpenAI’s agentic security researcher</a></li><li><a title="TBP episode on OpenAI’s Aardvark " rel="nofollow" href="https://www.youtube.com/watch?v=1hBRiU1PIIY">TBP episode on OpenAI’s Aardvark </a></li><li><a title="How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation" rel="nofollow" href="https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/">How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation</a></li><li><a title="Ex-US cyber intel exec pleads guilty to selling spy tools to Russian broker" rel="nofollow" href="https://www.reuters.com/legal/government/ex-us-cyber-intel-exec-pleads-guilty-selling-spy-tools-russian-broker-2025-10-29/">Ex-US cyber intel exec pleads guilty to selling spy tools to Russian broker</a></li><li><a title="Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm" rel="nofollow" href="https://archive.ph/xuVuY">Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm</a></li><li><a title="Kim Zetter: Former Trenchant Exec Sold Stolen Code to Russian Buyer Even After Learning that Other Code He Sold Was Being &quot;Utilized&quot; by Different Broker in South Korea" rel="nofollow" href="https://www.zetter-zeroday.com/former-trenchant-exec-sold-stolen-code-to-russian-buyer-even-after-learning-that-other-code-he-sold-was-being-utilized-by-different-broker-in-south-korea/">Kim Zetter: Former Trenchant Exec Sold Stolen Code to Russian Buyer Even After Learning that Other Code He Sold Was Being "Utilized" by Different Broker in South Korea</a></li><li><a title="How we linked ForumTroll APT to Dante spyware by Memento Labs" rel="nofollow" href="https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/">How we linked ForumTroll APT to Dante spyware by Memento Labs</a></li><li><a title="CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware" rel="nofollow" href="https://techcrunch.com/2025/10/28/ceo-of-spyware-maker-memento-labs-confirms-one-of-its-government-customers-was-caught-using-its-malware/">CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware</a></li><li><a title="Russia&#39;s new vuln disclosure law proposal" rel="nofollow" href="https://www.rbc.ru/technology_and_media/23/10/2025/68f8d6c09a79473a09f38e93">Russia's new vuln disclosure law proposal</a></li><li><a title="TBP Live in Ottawa" rel="nofollow" href="https://ringzer0.training/countermeasure25/">TBP Live in Ottawa</a></li><li><a title="Binding Hook Live" rel="nofollow" href="https://bindinghooklive.com/about/">Binding Hook Live</a></li><li><a title="State of Statecraft" rel="nofollow" href="https://www.stateofstatecraft.com/">State of Statecraft</a></li><li><a title="Ekoparty Miami " rel="nofollow" href="https://ekoparty.org/miami/">Ekoparty Miami </a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 70</strong>: Dave Aitel from OpenAI&#39;s technical staff joins the buddies to discuss the just-launched Aardvark, OpenAI’s agentic “security researcher” that claims to read code, finds bugs, validates exploits, and ships patches. We press him on where LLMs beat fuzzers, privacy boundaries, human-in-the-loop realities, SDLC budgets, pen-test cadence, and the zero-day economy.</p>

<p>Plus, L3 Harris/Trenchant exec pleads guilty to selling exploits to Russian brokers, Kaspersky catches the return of HackingTeam using Chrome zero-day exploit chain, and news of a proposed law in Russia to force researchers to report vulnerabilities first to goverment agencies.</p>

<p><strong>Cast:</strong> <a href="https://www.linkedin.com/in/daveaitel/" rel="nofollow">Dave Aitel</a> (Technical Staff, OpenAI), <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Pz8JWiwA-ZrLMHG8di264ioCO9CVtl3ac_-N9fUDrls/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Episode 70 Livestream - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=7IkmOXujJTY">Episode 70 Livestream - YouTube</a></li><li><a title="Aardvark: OpenAI’s agentic security researcher" rel="nofollow" href="https://openai.com/index/introducing-aardvark/">Aardvark: OpenAI’s agentic security researcher</a></li><li><a title="TBP episode on OpenAI’s Aardvark " rel="nofollow" href="https://www.youtube.com/watch?v=1hBRiU1PIIY">TBP episode on OpenAI’s Aardvark </a></li><li><a title="How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation" rel="nofollow" href="https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/">How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation</a></li><li><a title="Ex-US cyber intel exec pleads guilty to selling spy tools to Russian broker" rel="nofollow" href="https://www.reuters.com/legal/government/ex-us-cyber-intel-exec-pleads-guilty-selling-spy-tools-russian-broker-2025-10-29/">Ex-US cyber intel exec pleads guilty to selling spy tools to Russian broker</a></li><li><a title="Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm" rel="nofollow" href="https://archive.ph/xuVuY">Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm</a></li><li><a title="Kim Zetter: Former Trenchant Exec Sold Stolen Code to Russian Buyer Even After Learning that Other Code He Sold Was Being &quot;Utilized&quot; by Different Broker in South Korea" rel="nofollow" href="https://www.zetter-zeroday.com/former-trenchant-exec-sold-stolen-code-to-russian-buyer-even-after-learning-that-other-code-he-sold-was-being-utilized-by-different-broker-in-south-korea/">Kim Zetter: Former Trenchant Exec Sold Stolen Code to Russian Buyer Even After Learning that Other Code He Sold Was Being "Utilized" by Different Broker in South Korea</a></li><li><a title="How we linked ForumTroll APT to Dante spyware by Memento Labs" rel="nofollow" href="https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/">How we linked ForumTroll APT to Dante spyware by Memento Labs</a></li><li><a title="CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware" rel="nofollow" href="https://techcrunch.com/2025/10/28/ceo-of-spyware-maker-memento-labs-confirms-one-of-its-government-customers-was-caught-using-its-malware/">CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware</a></li><li><a title="Russia&#39;s new vuln disclosure law proposal" rel="nofollow" href="https://www.rbc.ru/technology_and_media/23/10/2025/68f8d6c09a79473a09f38e93">Russia's new vuln disclosure law proposal</a></li><li><a title="TBP Live in Ottawa" rel="nofollow" href="https://ringzer0.training/countermeasure25/">TBP Live in Ottawa</a></li><li><a title="Binding Hook Live" rel="nofollow" href="https://bindinghooklive.com/about/">Binding Hook Live</a></li><li><a title="State of Statecraft" rel="nofollow" href="https://www.stateofstatecraft.com/">State of Statecraft</a></li><li><a title="Ekoparty Miami " rel="nofollow" href="https://ekoparty.org/miami/">Ekoparty Miami </a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Apple’s iOS forensics freeze, WhatsApp zero-click, China outs NSA</title>
  <link>http://securityconversations.fireside.fm/ios26-shutdown-whatsapp-zero-click-china-nsa</link>
  <guid isPermaLink="false">4b406c2c-80d5-4def-b5ec-acf81eed0801</guid>
  <pubDate>Fri, 24 Oct 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/4b406c2c-80d5-4def-b5ec-acf81eed0801.mp3" length="105748725" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 69: We dig into news that Apple's iOS 26 has quietly killed the shutdown.log forensic artifact used to spot signs of infections and what it means for threat hunters.  Plus, whispers of a million-dollar WhatsApp zero-click exploit that never materialized at Pwn2Own, a surreal court case linking a Trenchant exploit developer to Russian buyers, and Chinese threat intel reports pointing fingers at the NSA.

We also discuss calls for the US government to build a structured, lawful ecosystem for private-sector offensive operations to address existing chaos and market gaps. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:11:23</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/4b406c2c-80d5-4def-b5ec-acf81eed0801/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 69: We dig into news that Apple's iOS 26 has quietly killed the shutdown.log forensic artifact used to spot signs of infections and what it means for threat hunters.  Plus, whispers of a million-dollar WhatsApp zero-click exploit that never materialized at Pwn2Own, a surreal court case linking a Trenchant exploit developer to Russian buyers, and Chinese threat intel reports pointing fingers at the NSA.
We also discuss calls for the US government to build a structured, lawful ecosystem for private-sector offensive operations to address existing chaos and market gaps. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>Apple, iOS, iOS 26, iPhone, spyware, mercenary, Pegasus, Microsoft, WSUS, CVE-2025-59287, WhatApp, zero-click, Pwn2Own, China, Trenchant, Azimuth, L3Harris, NSA, Triangulation, CN-CERT, Sergey Bratus, Netherlands, AIVD, MIVD</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 69</strong>: We dig into news that Apple&#39;s iOS 26 has quietly killed the shutdown.log forensic artifact used to spot signs of infections and what it means for threat hunters.  Plus, whispers of a million-dollar WhatsApp zero-click exploit that never materialized at Pwn2Own, a surreal court case linking a Trenchant exploit developer to Russian buyers, and Chinese threat intel reports pointing fingers at the NSA.</p>

<p>We also discuss calls for the US government to build a structured, lawful ecosystem for private-sector offensive operations to address existing chaos and market gaps. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NVbbtz7e6xGLA4Er15yKN3M76nT9u9Yx2AkASmxZzUg/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Key IOCs for iPhone Spyware Cleaned With iOS 26 Update" rel="nofollow" href="https://iverify.io/blog/key-iocs-for-pegasus-and-predator-spyware-cleaned-with-ios-26-update">Key IOCs for iPhone Spyware Cleaned With iOS 26 Update</a></li><li><a title="Exploitation of WSUS Remote Code Execution Vulnerability (CVE-2025-59287) " rel="nofollow" href="https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability">Exploitation of WSUS Remote Code Execution Vulnerability (CVE-2025-59287) </a></li><li><a title="Hamid Kashfi on CVE-2025-59287" rel="nofollow" href="https://x.com/hkashfi/status/1980197996441510375">Hamid Kashfi on CVE-2025-59287</a></li><li><a title="Pwn2Own Ireland results" rel="nofollow" href="https://www.zerodayinitiative.com/blog/2025/10/23/pwn2own-ireland-2025-day-three-and-master-of-pwn">Pwn2Own Ireland results</a></li><li><a title="Hacking Lab Boss Charged with Seeking to Sell Secrets in Russia" rel="nofollow" href="https://archive.ph/YlVlm">Hacking Lab Boss Charged with Seeking to Sell Secrets in Russia</a></li><li><a title="Court doc (Peter Williams case)" rel="nofollow" href="https://storage.courtlistener.com/recap/gov.uscourts.dcd.285897/gov.uscourts.dcd.285897.1.0.pdf">Court doc (Peter Williams case)</a></li><li><a title="Cyber Insurer Sues Policyholder’s Cyber Pros" rel="nofollow" href="https://www.hunton.com/privacy-and-information-security-law/cyber-insurer-sues-policyholders-cyber-pros#page=1">Cyber Insurer Sues Policyholder’s Cyber Pros</a></li><li><a title="NSA Accused of Stealing Secrets from China&#39;s National Time Centre" rel="nofollow" href="https://moderndiplomacy.eu/2025/10/19/nsa-accused-of-stealing-secrets-from-chinas-national-time-centre/">NSA Accused of Stealing Secrets from China's National Time Centre</a></li><li><a title="China&#39;s CN-CERT on alleged NSA espionage operation" rel="nofollow" href="https://mp.weixin.qq.com/s/XPjT0BVOJPJxSmASW0tXTA">China's CN-CERT on alleged NSA espionage operation</a></li><li><a title="DanderSpritz documentation" rel="nofollow" href="https://danderspritz.com/">DanderSpritz documentation</a></li><li><a title="Building the US market for offensive cyber" rel="nofollow" href="https://sergeybratus.gitlab.io/papers/DartmouthCyberRoundtable2025.pdf">Building the US market for offensive cyber</a></li><li><a title="Netherlands Limits Intelligence-Sharing With US Amid Politicization, Russia Fears" rel="nofollow" href="https://www.kyivpost.com/post/62663">Netherlands Limits Intelligence-Sharing With US Amid Politicization, Russia Fears</a></li><li><a title="Agenda - Binding Hook Live" rel="nofollow" href="https://bindinghooklive.com/agenda/">Agenda - Binding Hook Live</a></li><li><a title="Agenda - State of Statecraft" rel="nofollow" href="https://www.stateofstatecraft.com/agenda">Agenda - State of Statecraft</a></li><li><a title="TBP Live at Countermeasures (Ottawa)" rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">TBP Live at Countermeasures (Ottawa)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 69</strong>: We dig into news that Apple&#39;s iOS 26 has quietly killed the shutdown.log forensic artifact used to spot signs of infections and what it means for threat hunters.  Plus, whispers of a million-dollar WhatsApp zero-click exploit that never materialized at Pwn2Own, a surreal court case linking a Trenchant exploit developer to Russian buyers, and Chinese threat intel reports pointing fingers at the NSA.</p>

<p>We also discuss calls for the US government to build a structured, lawful ecosystem for private-sector offensive operations to address existing chaos and market gaps. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NVbbtz7e6xGLA4Er15yKN3M76nT9u9Yx2AkASmxZzUg/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Key IOCs for iPhone Spyware Cleaned With iOS 26 Update" rel="nofollow" href="https://iverify.io/blog/key-iocs-for-pegasus-and-predator-spyware-cleaned-with-ios-26-update">Key IOCs for iPhone Spyware Cleaned With iOS 26 Update</a></li><li><a title="Exploitation of WSUS Remote Code Execution Vulnerability (CVE-2025-59287) " rel="nofollow" href="https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability">Exploitation of WSUS Remote Code Execution Vulnerability (CVE-2025-59287) </a></li><li><a title="Hamid Kashfi on CVE-2025-59287" rel="nofollow" href="https://x.com/hkashfi/status/1980197996441510375">Hamid Kashfi on CVE-2025-59287</a></li><li><a title="Pwn2Own Ireland results" rel="nofollow" href="https://www.zerodayinitiative.com/blog/2025/10/23/pwn2own-ireland-2025-day-three-and-master-of-pwn">Pwn2Own Ireland results</a></li><li><a title="Hacking Lab Boss Charged with Seeking to Sell Secrets in Russia" rel="nofollow" href="https://archive.ph/YlVlm">Hacking Lab Boss Charged with Seeking to Sell Secrets in Russia</a></li><li><a title="Court doc (Peter Williams case)" rel="nofollow" href="https://storage.courtlistener.com/recap/gov.uscourts.dcd.285897/gov.uscourts.dcd.285897.1.0.pdf">Court doc (Peter Williams case)</a></li><li><a title="Cyber Insurer Sues Policyholder’s Cyber Pros" rel="nofollow" href="https://www.hunton.com/privacy-and-information-security-law/cyber-insurer-sues-policyholders-cyber-pros#page=1">Cyber Insurer Sues Policyholder’s Cyber Pros</a></li><li><a title="NSA Accused of Stealing Secrets from China&#39;s National Time Centre" rel="nofollow" href="https://moderndiplomacy.eu/2025/10/19/nsa-accused-of-stealing-secrets-from-chinas-national-time-centre/">NSA Accused of Stealing Secrets from China's National Time Centre</a></li><li><a title="China&#39;s CN-CERT on alleged NSA espionage operation" rel="nofollow" href="https://mp.weixin.qq.com/s/XPjT0BVOJPJxSmASW0tXTA">China's CN-CERT on alleged NSA espionage operation</a></li><li><a title="DanderSpritz documentation" rel="nofollow" href="https://danderspritz.com/">DanderSpritz documentation</a></li><li><a title="Building the US market for offensive cyber" rel="nofollow" href="https://sergeybratus.gitlab.io/papers/DartmouthCyberRoundtable2025.pdf">Building the US market for offensive cyber</a></li><li><a title="Netherlands Limits Intelligence-Sharing With US Amid Politicization, Russia Fears" rel="nofollow" href="https://www.kyivpost.com/post/62663">Netherlands Limits Intelligence-Sharing With US Amid Politicization, Russia Fears</a></li><li><a title="Agenda - Binding Hook Live" rel="nofollow" href="https://bindinghooklive.com/agenda/">Agenda - Binding Hook Live</a></li><li><a title="Agenda - State of Statecraft" rel="nofollow" href="https://www.stateofstatecraft.com/agenda">Agenda - State of Statecraft</a></li><li><a title="TBP Live at Countermeasures (Ottawa)" rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">TBP Live at Countermeasures (Ottawa)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>JAGS LABScon 2025 keynote: Steps to an ecology of cyber</title>
  <link>http://securityconversations.fireside.fm/jags-labscon25-keynote-steps-ecology-cyber</link>
  <guid isPermaLink="false">67946d1b-d1a0-42f1-92b3-63c256a8288e</guid>
  <pubDate>Sat, 18 Oct 2025 06:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/67946d1b-d1a0-42f1-92b3-63c256a8288e.mp3" length="14882499" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem (Episode 68):   The buddies are trapped in timezone hell with cross-country travel this week. 

In this special episode, we present Juan Andres Guerrero-Saade's LABScon 2025 keynote-day presentation on the state of cybersecurity and why this phase of our collective project has failed, and how to build something smarter, more sustainable, and deeply interconnected in its place.

Juanito traces the field’s evolution from chaos to consolidation, weaving in cybernetics, standardization, and the dawning coexistence of human and artificial evaluative power. The result is part philosophical sermon, part rallying cry, an invitation to reject the industry’s slave morality, rethink our tools, and steer the next era of defense with intention.
</itunes:subtitle>
  <itunes:duration>31:00</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/67946d1b-d1a0-42f1-92b3-63c256a8288e/cover.jpg?v=1"/>
  <description>Three Buddy Problem (Episode 68):  The buddies are trapped in timezone hell with cross-country travel this week.
In this special episode, we present Juan Andres Guerrero-Saade's LABScon 2025 keynote-day presentation on the state of cybersecurity and why this phase of our collective project has failed, and how to build something smarter, more sustainable, and deeply interconnected in its place.
Juanito traces the field’s evolution from chaos to consolidation, weaving in cybernetics, standardization, and the dawning coexistence of human and artificial evaluative power. The result is part philosophical sermon, part rallying cry, an invitation to reject the industry’s slave morality, rethink our tools, and steer the next era of defense with intention.
</description>
  <itunes:keywords>LABScon, keynote, cybernetics, AI, OpenAI, ChatGPT, standardization, EDR, JAGS</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Three Buddy Problem (Episode 68):  The buddies are trapped in timezone hell with cross-country travel this week.</p>

<p>In this special episode, we present Juan Andres Guerrero-Saade&#39;s LABScon 2025 keynote-day presentation on the state of cybersecurity and why this phase of our collective project has failed, and how to build something smarter, more sustainable, and deeply interconnected in its place.</p>

<p>Juanito traces the field’s evolution from chaos to consolidation, weaving in cybernetics, standardization, and the dawning coexistence of human and artificial evaluative power. The result is part philosophical sermon, part rallying cry, an invitation to reject the industry’s slave morality, rethink our tools, and steer the next era of defense with intention.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/16WgWulN_0ICWJZVBVCNIb7pQkNYETAfNxGC5smAYgfA/edit?tab=t.0#heading=h.suqk765u8dr">Transcript (unedited, AI-generated)</a></li><li><a title="JAGS keynote: The intricacies of wartime cyber threat intelligence - Security Conversations" rel="nofollow" href="https://securityconversations.com/episode/jags-keynote-the-intricacies-of-wartime-cyber-threat-intelligence/">JAGS keynote: The intricacies of wartime cyber threat intelligence - Security Conversations</a></li><li><a title="LABScon - Security Research in Real Time" rel="nofollow" href="https://www.labscon.io/">LABScon - Security Research in Real Time</a></li><li><a title="JAGS on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/jags-is-fine/">JAGS on LinkedIn</a></li><li><a title="JAGS on Twitter" rel="nofollow" href="https://x.com/juanandres_gs">JAGS on Twitter</a></li><li><a title="The Consolation of Threat Intel (JAGS LABScon 2024 keynote)" rel="nofollow" href="https://securityconversations.com/episode/ep13-the-consolation-of-threat-intel-jag-s-labscon-keynote/">The Consolation of Threat Intel (JAGS LABScon 2024 keynote)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Three Buddy Problem (Episode 68):  The buddies are trapped in timezone hell with cross-country travel this week.</p>

<p>In this special episode, we present Juan Andres Guerrero-Saade&#39;s LABScon 2025 keynote-day presentation on the state of cybersecurity and why this phase of our collective project has failed, and how to build something smarter, more sustainable, and deeply interconnected in its place.</p>

<p>Juanito traces the field’s evolution from chaos to consolidation, weaving in cybernetics, standardization, and the dawning coexistence of human and artificial evaluative power. The result is part philosophical sermon, part rallying cry, an invitation to reject the industry’s slave morality, rethink our tools, and steer the next era of defense with intention.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/16WgWulN_0ICWJZVBVCNIb7pQkNYETAfNxGC5smAYgfA/edit?tab=t.0#heading=h.suqk765u8dr">Transcript (unedited, AI-generated)</a></li><li><a title="JAGS keynote: The intricacies of wartime cyber threat intelligence - Security Conversations" rel="nofollow" href="https://securityconversations.com/episode/jags-keynote-the-intricacies-of-wartime-cyber-threat-intelligence/">JAGS keynote: The intricacies of wartime cyber threat intelligence - Security Conversations</a></li><li><a title="LABScon - Security Research in Real Time" rel="nofollow" href="https://www.labscon.io/">LABScon - Security Research in Real Time</a></li><li><a title="JAGS on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/jags-is-fine/">JAGS on LinkedIn</a></li><li><a title="JAGS on Twitter" rel="nofollow" href="https://x.com/juanandres_gs">JAGS on Twitter</a></li><li><a title="The Consolation of Threat Intel (JAGS LABScon 2024 keynote)" rel="nofollow" href="https://securityconversations.com/episode/ep13-the-consolation-of-threat-intel-jag-s-labscon-keynote/">The Consolation of Threat Intel (JAGS LABScon 2024 keynote)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Apple Exploit-Chain Bounties, Wireless Proximity Exploits and Tactical Suitcases</title>
  <link>http://securityconversations.fireside.fm/apple-spyware-bounty-oracle-ivanti-virus-total</link>
  <guid isPermaLink="false">69c83695-1bbc-4044-bf24-2168d12ad7d6</guid>
  <pubDate>Sat, 11 Oct 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/69c83695-1bbc-4044-bf24-2168d12ad7d6.mp3" length="112087103" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 67:  We discuss the rise of automated red-teaming, Apple’s $2 million exploit chain bounties aimed at outbidding spyware brokers and the iPhone maker's focus on wireless proximity attacks and “tactical suitcase” Wi-Fi exploits. We also hit the news of Paragon spyware targeting European executives and the bizarre story of NSO Group’s supposed US investor buyout.

Plus, an update on Oracle’s zero-day ransomware fiasco, Ivanti’s endless patch delays, the ethics of journalists enabling ransomware operations on leak sites, Europe’s latest failed push for Chat Control, and VirusTotal’s new pricing tiers.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:23:02</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/69c83695-1bbc-4044-bf24-2168d12ad7d6/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 67:  We discuss the rise of automated red-teaming, Apple’s $2 million exploit chain bounties aimed at outbidding spyware brokers and the iPhone maker's focus on wireless proximity attacks and “tactical suitcase” Wi-Fi exploits. We also hit the news of Paragon spyware targeting European executives and the bizarre story of NSO Group’s supposed US investor buyout.
Plus, an update on Oracle’s zero-day ransomware fiasco, Ivanti’s endless patch delays, the ethics of journalists enabling ransomware operations on leak sites, Europe’s latest failed push for Chat Control, and VirusTotal’s new pricing tiers.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>Apple, Spyware, iOS, bug bounty, NSO Group, Paragon, zero-click, one-click, Ivanti, Oracle, VirusTotal, Tavis Ormandy</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 67</strong>:  We discuss the rise of automated red-teaming, Apple’s $2 million exploit chain bounties aimed at outbidding spyware brokers and the iPhone maker&#39;s focus on wireless proximity attacks and “tactical suitcase” Wi-Fi exploits. We also hit the news of Paragon spyware targeting European executives and the bizarre story of NSO Group’s supposed US investor buyout.</p>

<p>Plus, an update on Oracle’s zero-day ransomware fiasco, Ivanti’s endless patch delays, the ethics of journalists enabling ransomware operations on leak sites, Europe’s latest failed push for Chat Control, and VirusTotal’s new pricing tiers.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/13DMqnlQr7mbLPWGQrVk6BT1xo2R23npj1txnkQl-ctI/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Apple&#39;s new exploit-chain bounties" rel="nofollow" href="https://security.apple.com/blog/apple-security-bounty-evolved/">Apple's new exploit-chain bounties</a></li><li><a title="Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits" rel="nofollow" href="https://archive.ph/4UioF">Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits</a></li><li><a title="Paragon Strikes Again: UniCredit CEO Among the Targets" rel="nofollow" href="https://irpimedia.irpi.eu/paragon-colpisce-ancora-anche-lad-di-unicredit-tra-i-bersagli/">Paragon Strikes Again: UniCredit CEO Among the Targets</a></li><li><a title="NSO to be acquired by U.S. investors" rel="nofollow" href="https://www.calcalistech.com/ctechnews/article/s1jgvmitgx">NSO to be acquired by U.S. investors</a></li><li><a title="Oracle confirms exploited 0day - CVE-2025-61882" rel="nofollow" href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html">Oracle confirms exploited 0day - CVE-2025-61882</a></li><li><a title="Oracle Security Officer comms" rel="nofollow" href="https://blogs.oracle.com/security/post/apply-july-2025-cpu">Oracle Security Officer comms</a></li><li><a title="Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks" rel="nofollow" href="https://www.vulncheck.com/blog/oracle-e-business-suite-cve-2025-61882-exploited-in-extortion-attacks">Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks</a></li><li><a title="ZDI documents Ivanti 0days waiting for patches" rel="nofollow" href="https://www.zerodayinitiative.com/advisories/published/">ZDI documents Ivanti 0days waiting for patches</a></li><li><a title="One-man spam campaign ravages EU ‘chat control’ bill" rel="nofollow" href="https://www.politico.eu/article/one-man-spam-campaign-ravages-eu-chat-control-bill-fight-chat-control/">One-man spam campaign ravages EU ‘chat control’ bill</a></li><li><a title="VirusTotal new pricing tiers" rel="nofollow" href="https://blog.virustotal.com/2025/10/simpler-access-for-stronger-virustotal.html">VirusTotal new pricing tiers</a></li><li><a title="Tavis Ormandy Kaspersky 0day find" rel="nofollow" href="https://x.com/taviso/status/639992212164513792">Tavis Ormandy Kaspersky 0day find</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 67</strong>:  We discuss the rise of automated red-teaming, Apple’s $2 million exploit chain bounties aimed at outbidding spyware brokers and the iPhone maker&#39;s focus on wireless proximity attacks and “tactical suitcase” Wi-Fi exploits. We also hit the news of Paragon spyware targeting European executives and the bizarre story of NSO Group’s supposed US investor buyout.</p>

<p>Plus, an update on Oracle’s zero-day ransomware fiasco, Ivanti’s endless patch delays, the ethics of journalists enabling ransomware operations on leak sites, Europe’s latest failed push for Chat Control, and VirusTotal’s new pricing tiers.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/13DMqnlQr7mbLPWGQrVk6BT1xo2R23npj1txnkQl-ctI/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Apple&#39;s new exploit-chain bounties" rel="nofollow" href="https://security.apple.com/blog/apple-security-bounty-evolved/">Apple's new exploit-chain bounties</a></li><li><a title="Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits" rel="nofollow" href="https://archive.ph/4UioF">Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits</a></li><li><a title="Paragon Strikes Again: UniCredit CEO Among the Targets" rel="nofollow" href="https://irpimedia.irpi.eu/paragon-colpisce-ancora-anche-lad-di-unicredit-tra-i-bersagli/">Paragon Strikes Again: UniCredit CEO Among the Targets</a></li><li><a title="NSO to be acquired by U.S. investors" rel="nofollow" href="https://www.calcalistech.com/ctechnews/article/s1jgvmitgx">NSO to be acquired by U.S. investors</a></li><li><a title="Oracle confirms exploited 0day - CVE-2025-61882" rel="nofollow" href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html">Oracle confirms exploited 0day - CVE-2025-61882</a></li><li><a title="Oracle Security Officer comms" rel="nofollow" href="https://blogs.oracle.com/security/post/apply-july-2025-cpu">Oracle Security Officer comms</a></li><li><a title="Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks" rel="nofollow" href="https://www.vulncheck.com/blog/oracle-e-business-suite-cve-2025-61882-exploited-in-extortion-attacks">Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks</a></li><li><a title="ZDI documents Ivanti 0days waiting for patches" rel="nofollow" href="https://www.zerodayinitiative.com/advisories/published/">ZDI documents Ivanti 0days waiting for patches</a></li><li><a title="One-man spam campaign ravages EU ‘chat control’ bill" rel="nofollow" href="https://www.politico.eu/article/one-man-spam-campaign-ravages-eu-chat-control-bill-fight-chat-control/">One-man spam campaign ravages EU ‘chat control’ bill</a></li><li><a title="VirusTotal new pricing tiers" rel="nofollow" href="https://blog.virustotal.com/2025/10/simpler-access-for-stronger-virustotal.html">VirusTotal new pricing tiers</a></li><li><a title="Tavis Ormandy Kaspersky 0day find" rel="nofollow" href="https://x.com/taviso/status/639992212164513792">Tavis Ormandy Kaspersky 0day find</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Oracle cl0p ransomware crisis, EU drone sightings, Cisco bootkit fallout</title>
  <link>http://securityconversations.fireside.fm/oracle-ransomware-extortion-drones-cisco-bootkit</link>
  <guid isPermaLink="false">218ae2a2-77f7-4d79-b2f7-4e8eeec2a852</guid>
  <pubDate>Fri, 03 Oct 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/218ae2a2-77f7-4d79-b2f7-4e8eeec2a852.mp3" length="105237292" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 66:  We discuss drone sightings that shut down airports across Europe and what they reveal about hybrid warfare and the changing nature of conflict; Oracle ransomware/extortion campaign tied to unpatched E-Business Suite vulnerabilities and the company’s muted response. 

Plus, the TikTok–Oracle deal and the strange role Oracle now plays in U.S. national security; OpenAI’s Sora 2 launch and its implications for social media and human expression; Palo Alto’s “Phantom Taurus” APT report, a follow-up on Cisco’s ArcaneDoor disclosures, and the impact of the U.S. government shutdown on CISA.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:03:28</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/218ae2a2-77f7-4d79-b2f7-4e8eeec2a852/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 66:  We discuss drone sightings that shut down airports across Europe and what they reveal about hybrid warfare and the changing nature of conflict; Oracle ransomware/extortion campaign tied to unpatched E-Business Suite vulnerabilities and the company’s muted response. 
Plus, the TikTok–Oracle deal and the strange role Oracle now plays in U.S. national security; OpenAI’s Sora 2 launch and its implications for social media and human expression; Palo Alto’s “Phantom Taurus” APT report, a follow-up on Cisco’s ArcaneDoor disclosures, and the impact of the U.S. government shutdown on CISA.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>Europe, ransomware, airport disruptions, Oracle, Google, Mandiant, Cisco, TikTok, Sora 2, OpenAI, Palo Alto, Phantom Taurus, China, CISA, gov shutdown, GreyNoise</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 66</strong>:  We discuss drone sightings that shut down airports across Europe and what they reveal about hybrid warfare and the changing nature of conflict; Oracle ransomware/extortion campaign tied to unpatched E-Business Suite vulnerabilities and the company’s muted response. </p>

<p>Plus, the TikTok–Oracle deal and the strange role Oracle now plays in U.S. national security; OpenAI’s Sora 2 launch and its implications for social media and human expression; Palo Alto’s “Phantom Taurus” APT report, a follow-up on Cisco’s ArcaneDoor disclosures, and the impact of the U.S. government shutdown on CISA.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NKMz33dMs9mwRUiIVi7c0EDDTavZ8ImIAWiFS-3yq-Y/edit?tab=t.0#heading=h.c4jonnkp64kg">Transcript (unedited, AI-generated)</a></li><li><a title="Drone sightings prompt call for German police to gain shoot-down powers " rel="nofollow" href="https://www.reuters.com/world/europe/drone-sightings-disrupt-munich-airport-halt-flights-impact-thousands-2025-10-03/">Drone sightings prompt call for German police to gain shoot-down powers </a></li><li><a title="UK arrest following aerospace cyber incident" rel="nofollow" href="https://www.nationalcrimeagency.gov.uk/news/uk-arrest-following-aerospace-cyber-incident">UK arrest following aerospace cyber incident</a></li><li><a title="Oracle Probes Hacks of Customers’ E-Business Suite After Extortion Campaign" rel="nofollow" href="https://www.bloomberg.com/news/articles/2025-10-02/oracle-investigating-hacks-of-its-customers-e-business-suite?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1OTQzOTAzOCwiZXhwIjoxNzYwMDQzODM4LCJhcnRpY2xlSWQiOiJUM0lSMzhHT1lNVEgwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.QuSgdjT8F9224F4JvefS8gPfyOactHpsJ5b6DDpWozA&amp;leadSource=uverify%20wall">Oracle Probes Hacks of Customers’ E-Business Suite After Extortion Campaign</a></li><li><a title="Oracle Critical Patch Update Advisory - July 2025" rel="nofollow" href="https://www.oracle.com/security-alerts/cpujul2025.html#AppendixEBS">Oracle Critical Patch Update Advisory - July 2025</a></li><li><a title="Here is the email Clop attackers sent to Oracle customers" rel="nofollow" href="https://cyberscoop.com/extortion-email-clop-oracle-customers/">Here is the email Clop attackers sent to Oracle customers</a></li><li><a title="Oracle statement from Chief Security Officer" rel="nofollow" href="https://blogs.oracle.com/security/post/apply-july-2025-cpu">Oracle statement from Chief Security Officer</a></li><li><a title="TikTok’s Algorithm to Be Secured by Oracle in Trump-Backed Deal" rel="nofollow" href="https://archive.ph/ybbmk">TikTok’s Algorithm to Be Secured by Oracle in Trump-Backed Deal</a></li><li><a title="Phantom Taurus: A New Chinese Nexus APT" rel="nofollow" href="https://unit42.paloaltonetworks.com/phantom-taurus/">Phantom Taurus: A New Chinese Nexus APT</a></li><li><a title="China Hackers Breached Foreign Ministers’ Emails" rel="nofollow" href="https://archive.ph/Vpot0">China Hackers Breached Foreign Ministers’ Emails</a></li><li><a title="Cisco Statement on Attacks Against Cisco Firewalls" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks">Cisco Statement on Attacks Against Cisco Firewalls</a></li><li><a title="GreyNoise: 25,000 IPs Scanned Cisco ASA Devices in Early Sept" rel="nofollow" href="https://www.greynoise.io/blog/scanning-surge-cisco-asa-devices">GreyNoise: 25,000 IPs Scanned Cisco ASA Devices in Early Sept</a></li><li><a title="KeyDrop.io" rel="nofollow" href="https://keydrop.io/">KeyDrop.io</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 66</strong>:  We discuss drone sightings that shut down airports across Europe and what they reveal about hybrid warfare and the changing nature of conflict; Oracle ransomware/extortion campaign tied to unpatched E-Business Suite vulnerabilities and the company’s muted response. </p>

<p>Plus, the TikTok–Oracle deal and the strange role Oracle now plays in U.S. national security; OpenAI’s Sora 2 launch and its implications for social media and human expression; Palo Alto’s “Phantom Taurus” APT report, a follow-up on Cisco’s ArcaneDoor disclosures, and the impact of the U.S. government shutdown on CISA.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NKMz33dMs9mwRUiIVi7c0EDDTavZ8ImIAWiFS-3yq-Y/edit?tab=t.0#heading=h.c4jonnkp64kg">Transcript (unedited, AI-generated)</a></li><li><a title="Drone sightings prompt call for German police to gain shoot-down powers " rel="nofollow" href="https://www.reuters.com/world/europe/drone-sightings-disrupt-munich-airport-halt-flights-impact-thousands-2025-10-03/">Drone sightings prompt call for German police to gain shoot-down powers </a></li><li><a title="UK arrest following aerospace cyber incident" rel="nofollow" href="https://www.nationalcrimeagency.gov.uk/news/uk-arrest-following-aerospace-cyber-incident">UK arrest following aerospace cyber incident</a></li><li><a title="Oracle Probes Hacks of Customers’ E-Business Suite After Extortion Campaign" rel="nofollow" href="https://www.bloomberg.com/news/articles/2025-10-02/oracle-investigating-hacks-of-its-customers-e-business-suite?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1OTQzOTAzOCwiZXhwIjoxNzYwMDQzODM4LCJhcnRpY2xlSWQiOiJUM0lSMzhHT1lNVEgwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.QuSgdjT8F9224F4JvefS8gPfyOactHpsJ5b6DDpWozA&amp;leadSource=uverify%20wall">Oracle Probes Hacks of Customers’ E-Business Suite After Extortion Campaign</a></li><li><a title="Oracle Critical Patch Update Advisory - July 2025" rel="nofollow" href="https://www.oracle.com/security-alerts/cpujul2025.html#AppendixEBS">Oracle Critical Patch Update Advisory - July 2025</a></li><li><a title="Here is the email Clop attackers sent to Oracle customers" rel="nofollow" href="https://cyberscoop.com/extortion-email-clop-oracle-customers/">Here is the email Clop attackers sent to Oracle customers</a></li><li><a title="Oracle statement from Chief Security Officer" rel="nofollow" href="https://blogs.oracle.com/security/post/apply-july-2025-cpu">Oracle statement from Chief Security Officer</a></li><li><a title="TikTok’s Algorithm to Be Secured by Oracle in Trump-Backed Deal" rel="nofollow" href="https://archive.ph/ybbmk">TikTok’s Algorithm to Be Secured by Oracle in Trump-Backed Deal</a></li><li><a title="Phantom Taurus: A New Chinese Nexus APT" rel="nofollow" href="https://unit42.paloaltonetworks.com/phantom-taurus/">Phantom Taurus: A New Chinese Nexus APT</a></li><li><a title="China Hackers Breached Foreign Ministers’ Emails" rel="nofollow" href="https://archive.ph/Vpot0">China Hackers Breached Foreign Ministers’ Emails</a></li><li><a title="Cisco Statement on Attacks Against Cisco Firewalls" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks">Cisco Statement on Attacks Against Cisco Firewalls</a></li><li><a title="GreyNoise: 25,000 IPs Scanned Cisco ASA Devices in Early Sept" rel="nofollow" href="https://www.greynoise.io/blog/scanning-surge-cisco-asa-devices">GreyNoise: 25,000 IPs Scanned Cisco ASA Devices in Early Sept</a></li><li><a title="KeyDrop.io" rel="nofollow" href="https://keydrop.io/">KeyDrop.io</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Cisco firewall zero-days and bootkits in the wild</title>
  <link>http://securityconversations.fireside.fm/cisco-bootkit-brickstorm-china-sophisticated-attacks</link>
  <guid isPermaLink="false">25f09048-d490-4caa-800d-d4548e74ad12</guid>
  <pubDate>Sat, 27 Sep 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/25f09048-d490-4caa-800d-d4548e74ad12.mp3" length="96122969" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 65: We zero in on one of the biggest security stories of the year: the discovery of a persistent multi-stage bootkit implanting malware on Cisco ASA firewalls. Details on a new campaign, tied to the same threat actors behind ArcaneDoor, exploiting zero-days in Cisco’s 5500-X series appliances, devices that sit at the heart of government and enterprise networks worldwide.

Plus, Cisco’s controversial handling of these disclosures, CISA's emergency deadlines for patching, the absence of IOCs and samples, and China’s long-term positioning.  Plus, thoughts on the Secret Service SIM farm discovery in New York and evidence of Russians APTs Turla and Gamaredon collaborating to hit Ukraine targets.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:54:49</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/25f09048-d490-4caa-800d-d4548e74ad12/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 65: We zero in on one of the biggest security stories of the year: the discovery of a persistent multi-stage bootkit implanting malware on Cisco ASA firewalls. Details on a new campaign, tied to the same threat actors behind ArcaneDoor, exploiting zero-days in Cisco’s 5500-X series appliances, devices that sit at the heart of government and enterprise networks worldwide.
Plus, Cisco’s controversial handling of these disclosures, CISA's emergency deadlines for patching, the absence of IOCs and samples, and China’s long-term positioning.  Plus, thoughts on the Secret Service SIM farm discovery in New York and evidence of Russians APTs Turla and Gamaredon collaborating to hit Ukraine targets.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>Google, GTIG, Brickstorm, China, EDR, cyberespionage, trade negotiations, Cisco, ASA, firewall, bootkit, network appliance, Russia, Ukraine, ransomware, Europe</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 65</strong>: We zero in on one of the biggest security stories of the year: the discovery of a persistent multi-stage bootkit implanting malware on Cisco ASA firewalls. Details on a new campaign, tied to the same threat actors behind ArcaneDoor, exploiting zero-days in Cisco’s 5500-X series appliances, devices that sit at the heart of government and enterprise networks worldwide.</p>

<p>Plus, Cisco’s controversial handling of these disclosures, CISA&#39;s emergency deadlines for patching, the absence of IOCs and samples, and China’s long-term positioning.  Plus, thoughts on the Secret Service SIM farm discovery in New York and evidence of Russians APTs Turla and Gamaredon collaborating to hit Ukraine targets.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1cShztjZIHPCcCo5W0VY881-RSs37pXY_usC93b32R-E/edit?tab=t.0#heading=h.jbbo41oysex">Transcript (unedited, AI-generated)</a></li><li><a title="Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign">Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors</a></li><li><a title="Mandiant Brickstorm Scanner" rel="nofollow" href="https://github.com/mandiant/brickstorm-scanner">Mandiant Brickstorm Scanner</a></li><li><a title="Cisco advisory: Continued Attacks Against Cisco Firewalls" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks">Cisco advisory: Continued Attacks Against Cisco Firewalls</a></li><li><a title="NCSC report on Cisco ASA bootkit in the wild" rel="nofollow" href="https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/RayInitiator-LINE-VIPER/ncsc-mar-rayinitiator-line-viper.pdf">NCSC report on Cisco ASA bootkit in the wild</a></li><li><a title="U.S. government scrambles to stop new hacking campaign blamed on China" rel="nofollow" href="https://archive.ph/95lK1">U.S. government scrambles to stop new hacking campaign blamed on China</a></li><li><a title="US Secret Service Statement on SIM Farm Discovery" rel="nofollow" href="https://www.secretservice.gov/newsroom/releases/2025/09/us-secret-service-dismantles-imminent-telecommunications-threat-new-york">US Secret Service Statement on SIM Farm Discovery</a></li><li><a title="NYTimes: Cache of Devices Capable of Crashing Cell Network Is Found Near U.N." rel="nofollow" href="https://archive.ph/FpmSy">NYTimes: Cache of Devices Capable of Crashing Cell Network Is Found Near U.N.</a></li><li><a title="Airport chaos: Ransomware hits airport check-in systems" rel="nofollow" href="https://www.airport-technology.com/analyst-comment/chaos-in-the-air-ransomware-cripples-airport-check-in-systems/">Airport chaos: Ransomware hits airport check-in systems</a></li><li><a title="NCSC statement: Incident impacting Collins Aerospace" rel="nofollow" href="https://www.ncsc.gov.uk/news/collins-aerospace-incident">NCSC statement: Incident impacting Collins Aerospace</a></li><li><a title="Gamaredon X Turla collab" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/">Gamaredon X Turla collab</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 65</strong>: We zero in on one of the biggest security stories of the year: the discovery of a persistent multi-stage bootkit implanting malware on Cisco ASA firewalls. Details on a new campaign, tied to the same threat actors behind ArcaneDoor, exploiting zero-days in Cisco’s 5500-X series appliances, devices that sit at the heart of government and enterprise networks worldwide.</p>

<p>Plus, Cisco’s controversial handling of these disclosures, CISA&#39;s emergency deadlines for patching, the absence of IOCs and samples, and China’s long-term positioning.  Plus, thoughts on the Secret Service SIM farm discovery in New York and evidence of Russians APTs Turla and Gamaredon collaborating to hit Ukraine targets.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1cShztjZIHPCcCo5W0VY881-RSs37pXY_usC93b32R-E/edit?tab=t.0#heading=h.jbbo41oysex">Transcript (unedited, AI-generated)</a></li><li><a title="Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign">Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors</a></li><li><a title="Mandiant Brickstorm Scanner" rel="nofollow" href="https://github.com/mandiant/brickstorm-scanner">Mandiant Brickstorm Scanner</a></li><li><a title="Cisco advisory: Continued Attacks Against Cisco Firewalls" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks">Cisco advisory: Continued Attacks Against Cisco Firewalls</a></li><li><a title="NCSC report on Cisco ASA bootkit in the wild" rel="nofollow" href="https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/RayInitiator-LINE-VIPER/ncsc-mar-rayinitiator-line-viper.pdf">NCSC report on Cisco ASA bootkit in the wild</a></li><li><a title="U.S. government scrambles to stop new hacking campaign blamed on China" rel="nofollow" href="https://archive.ph/95lK1">U.S. government scrambles to stop new hacking campaign blamed on China</a></li><li><a title="US Secret Service Statement on SIM Farm Discovery" rel="nofollow" href="https://www.secretservice.gov/newsroom/releases/2025/09/us-secret-service-dismantles-imminent-telecommunications-threat-new-york">US Secret Service Statement on SIM Farm Discovery</a></li><li><a title="NYTimes: Cache of Devices Capable of Crashing Cell Network Is Found Near U.N." rel="nofollow" href="https://archive.ph/FpmSy">NYTimes: Cache of Devices Capable of Crashing Cell Network Is Found Near U.N.</a></li><li><a title="Airport chaos: Ransomware hits airport check-in systems" rel="nofollow" href="https://www.airport-technology.com/analyst-comment/chaos-in-the-air-ransomware-cripples-airport-check-in-systems/">Airport chaos: Ransomware hits airport check-in systems</a></li><li><a title="NCSC statement: Incident impacting Collins Aerospace" rel="nofollow" href="https://www.ncsc.gov.uk/news/collins-aerospace-incident">NCSC statement: Incident impacting Collins Aerospace</a></li><li><a title="Gamaredon X Turla collab" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/">Gamaredon X Turla collab</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Live at LABScon: Aurora Johnson and Trevor Hilligoss on China's 'internet toilets'</title>
  <link>http://securityconversations.fireside.fm/aurora-johnson-trevor-hilligoss-china-internet-toilets</link>
  <guid isPermaLink="false">f1783ca4-97ce-4db0-b3aa-144e6aba3db1</guid>
  <pubDate>Wed, 24 Sep 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/f1783ca4-97ce-4db0-b3aa-144e6aba3db1.mp3" length="22164014" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 64: SpyCloud Labs researchers Aurora Johnson and Trevor Hilligoss discuss the world of “internet toilets," the toxic online communities in China where harassment, stalking, and sextortion thrive. We explore how these groups operate, from doxing ex-lovers and enemies to running coordinated campaigns of cyberbullying that often spill into real-world harm. (Recorded at LABScon 2025).

Cast: Aurora Johnson, Trevor Hilligoss Ryan Naraine and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>22:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/f1783ca4-97ce-4db0-b3aa-144e6aba3db1/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 64: SpyCloud Labs researchers Aurora Johnson and Trevor Hilligoss discuss the world of “internet toilets," the toxic online communities in China where harassment, stalking, and sextortion thrive. We explore how these groups operate, from doxing ex-lovers and enemies to running coordinated campaigns of cyberbullying that often spill into real-world harm. (Recorded at LABScon 2025).
Cast: Aurora Johnson (https://www.labscon.io/speakers/aurora-johnson), Trevor Hilligoss (https://www.labscon.io/speakers/trevor-hilligoss/), Ryan Naraine (https://twitter.com/ryanaraine) and Juan Andres Guerrero-Saade (https://www.linkedin.com/in/jags-is-fine/). 
</description>
  <itunes:keywords>China, Internet Toilets, SpyCloud, doxxing, stalking, sextortion, the_com, LABScon</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 64:</strong> SpyCloud Labs researchers Aurora Johnson and Trevor Hilligoss discuss the world of “internet toilets,&quot; the toxic online communities in China where harassment, stalking, and sextortion thrive. We explore how these groups operate, from doxing ex-lovers and enemies to running coordinated campaigns of cyberbullying that often spill into real-world harm. (Recorded at LABScon 2025).</p>

<p><strong>Cast:</strong> <a href="https://www.labscon.io/speakers/aurora-johnson" rel="nofollow">Aurora Johnson</a>, <a href="https://www.labscon.io/speakers/trevor-hilligoss/" rel="nofollow">Trevor Hilligoss</a>, <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and <a href="https://www.linkedin.com/in/jags-is-fine/" rel="nofollow">Juan Andres Guerrero-Saade</a>.</p><p>Links:</p><ul><li><a title="Plunging China&#39;s internet toilets (LABScon)" rel="nofollow" href="https://www.labscon.io/speakers/aurora-johnson/">Plunging China's internet toilets (LABScon)</a></li><li><a title="SpyCloud Labs" rel="nofollow" href="https://spycloud.com/resources/spycloud-labs/">SpyCloud Labs</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 64:</strong> SpyCloud Labs researchers Aurora Johnson and Trevor Hilligoss discuss the world of “internet toilets,&quot; the toxic online communities in China where harassment, stalking, and sextortion thrive. We explore how these groups operate, from doxing ex-lovers and enemies to running coordinated campaigns of cyberbullying that often spill into real-world harm. (Recorded at LABScon 2025).</p>

<p><strong>Cast:</strong> <a href="https://www.labscon.io/speakers/aurora-johnson" rel="nofollow">Aurora Johnson</a>, <a href="https://www.labscon.io/speakers/trevor-hilligoss/" rel="nofollow">Trevor Hilligoss</a>, <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and <a href="https://www.linkedin.com/in/jags-is-fine/" rel="nofollow">Juan Andres Guerrero-Saade</a>.</p><p>Links:</p><ul><li><a title="Plunging China&#39;s internet toilets (LABScon)" rel="nofollow" href="https://www.labscon.io/speakers/aurora-johnson/">Plunging China's internet toilets (LABScon)</a></li><li><a title="SpyCloud Labs" rel="nofollow" href="https://spycloud.com/resources/spycloud-labs/">SpyCloud Labs</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Live at LABScon: Visi Stark shares memories of creating the APT1 report</title>
  <link>http://securityconversations.fireside.fm/visi-stark-vertex-project-apt1-report-recap</link>
  <guid isPermaLink="false">6a3b7094-57b6-438f-afe4-89b945eaf4cf</guid>
  <pubDate>Wed, 24 Sep 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/6a3b7094-57b6-438f-afe4-89b945eaf4cf.mp3" length="29489381" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 63:  Co-founder of the Vertex Project Visi Stark joins the buddies to reminisce about his work writing Mandiant's famous APT1 report, the China-nexus threat landscape, the value of cyber threat intelligence, APT-naming schemes, and more... (Recorded at LABScon 2025).

Cast: Visi Stark, Ryan Naraine and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>28:50</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/6a3b7094-57b6-438f-afe4-89b945eaf4cf/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 63: Co-founder of the Vertex Project Visi Stark joins the buddies to reminisce about his work writing Mandiant's famous APT1 report, the China-nexus threat landscape, the value of cyber threat intelligence, APT-naming schemes, and more... (Recorded at LABScon 2025)
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and Visi Stark (https://x.com/Invisig0th).
</description>
  <itunes:keywords>Visi Stark, Mandiant, APT1, China, Obama, Xi, threat-intel, Vertex, Synapse, APT-naming</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 63</strong>: Co-founder of the Vertex Project Visi Stark joins the buddies to reminisce about his work writing Mandiant&#39;s famous APT1 report, the China-nexus threat landscape, the value of cyber threat intelligence, APT-naming schemes, and more... (Recorded at LABScon 2025)</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and <a href="https://x.com/Invisig0th" rel="nofollow">Visi Stark</a>.</p><p>Links:</p><ul><li><a title="How the Infamous APT-1 Report Exposing China’s PLA Hackers Came to Be" rel="nofollow" href="https://www.zetter-zeroday.com/how-the-infamous-apt-1-report-exposing-chinas-pla-hackers-came-to-be/">How the Infamous APT-1 Report Exposing China’s PLA Hackers Came to Be</a></li><li><a title="Mandiant APT1 Report" rel="nofollow" href="https://services.google.com/fh/files/misc/mandiant-apt1-report.pdf?ref=zetter-zeroday.com">Mandiant APT1 Report</a></li><li><a title="A guide to U.S. allegations of China cyberspying" rel="nofollow" href="https://www.pbs.org/newshour/world/guide-u-s-allegations-china-cyberspying?ref=zetter-zeroday.com">A guide to U.S. allegations of China cyberspying</a></li><li><a title="The Vertex Project" rel="nofollow" href="https://vertex.link/">The Vertex Project</a></li><li><a title="LABScon 2025" rel="nofollow" href="https://www.labscon.io/">LABScon 2025</a></li><li><a title="Visi Stark on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/visi-stark-5bb092186/">Visi Stark on LinkedIn</a></li><li><a title="LABScon 2025: Plunging the Internet Toilets in China" rel="nofollow" href="https://www.labscon.io/speakers/aurora-johnson/">LABScon 2025: Plunging the Internet Toilets in China</a></li><li><a title="Aurora Johnson on Twitter" rel="nofollow" href="https://x.com/princessauroraj">Aurora Johnson on Twitter</a></li><li><a title="Trevor Hilligoss" rel="nofollow" href="https://www.labscon.io/speakers/trevor-hilligoss/">Trevor Hilligoss</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 63</strong>: Co-founder of the Vertex Project Visi Stark joins the buddies to reminisce about his work writing Mandiant&#39;s famous APT1 report, the China-nexus threat landscape, the value of cyber threat intelligence, APT-naming schemes, and more... (Recorded at LABScon 2025)</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and <a href="https://x.com/Invisig0th" rel="nofollow">Visi Stark</a>.</p><p>Links:</p><ul><li><a title="How the Infamous APT-1 Report Exposing China’s PLA Hackers Came to Be" rel="nofollow" href="https://www.zetter-zeroday.com/how-the-infamous-apt-1-report-exposing-chinas-pla-hackers-came-to-be/">How the Infamous APT-1 Report Exposing China’s PLA Hackers Came to Be</a></li><li><a title="Mandiant APT1 Report" rel="nofollow" href="https://services.google.com/fh/files/misc/mandiant-apt1-report.pdf?ref=zetter-zeroday.com">Mandiant APT1 Report</a></li><li><a title="A guide to U.S. allegations of China cyberspying" rel="nofollow" href="https://www.pbs.org/newshour/world/guide-u-s-allegations-china-cyberspying?ref=zetter-zeroday.com">A guide to U.S. allegations of China cyberspying</a></li><li><a title="The Vertex Project" rel="nofollow" href="https://vertex.link/">The Vertex Project</a></li><li><a title="LABScon 2025" rel="nofollow" href="https://www.labscon.io/">LABScon 2025</a></li><li><a title="Visi Stark on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/visi-stark-5bb092186/">Visi Stark on LinkedIn</a></li><li><a title="LABScon 2025: Plunging the Internet Toilets in China" rel="nofollow" href="https://www.labscon.io/speakers/aurora-johnson/">LABScon 2025: Plunging the Internet Toilets in China</a></li><li><a title="Aurora Johnson on Twitter" rel="nofollow" href="https://x.com/princessauroraj">Aurora Johnson on Twitter</a></li><li><a title="Trevor Hilligoss" rel="nofollow" href="https://www.labscon.io/speakers/trevor-hilligoss/">Trevor Hilligoss</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Live at LABScon: Lindsay Freeman on tracking Wagner Group war crimes </title>
  <link>http://securityconversations.fireside.fm/labscon-live-lindsay-freeman-tracking-war-crimes</link>
  <guid isPermaLink="false">2e770758-3cba-44bf-8c35-e468ad8cda65</guid>
  <pubDate>Wed, 24 Sep 2025 10:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/2e770758-3cba-44bf-8c35-e468ad8cda65.mp3" length="29899880" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 62:  Lindsay Freeman, Director of the Technology, Law &amp; Policy program at the Human Rights Center, UC Berkeley School of Law, joins the show to discuss her team's meticulous work to document the Wagner Group's chain of command, military operations in parts of Africa, and the broadcasting of war crimes on social media platforms like Telegram. (Recorded at LABScon 2025)

Cast: Lindsay Freeman, Ryan Naraine and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>31:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/2e770758-3cba-44bf-8c35-e468ad8cda65/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 62: Lindsay Freeman, Director of the Technology, Law &amp;amp; Policy program at the Human Rights Center, UC Berkeley School of Law, joins the show to discuss her team's meticulous work to document the Wagner Group's chain of command, military operations in parts of Africa, and the broadcasting of war crimes on social media platforms like Telegram. (Recorded at LABScon 2025)
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and Lindsay Freeman (https://x.com/lindsaysfreeman).
</description>
  <itunes:keywords>Wagner, Russia, Mali, Sahel, Africa, mercenaries, war crimes, ICC, Telegram, International Criminal Court, OSINT, AI tools, drone, satellite</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 62</strong>: Lindsay Freeman, Director of the Technology, Law &amp; Policy program at the Human Rights Center, UC Berkeley School of Law, joins the show to discuss her team&#39;s meticulous work to document the Wagner Group&#39;s chain of command, military operations in parts of Africa, and the broadcasting of war crimes on social media platforms like Telegram. (Recorded at LABScon 2025)</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and <a href="https://x.com/lindsaysfreeman" rel="nofollow">Lindsay Freeman</a>.</p><p>Links:</p><ul><li><a title="LABScon Speaker 2025: Lindsay Freeman" rel="nofollow" href="https://www.labscon.io/speakers/lindsay-freeman/">LABScon Speaker 2025: Lindsay Freeman</a></li><li><a title="War Crimes for Fun and Profit (Lawfare)" rel="nofollow" href="https://www.lawfaremedia.org/article/war-crimes-for-fun-and-profit">War Crimes for Fun and Profit (Lawfare)</a></li><li><a title="Mali: Army, Wagner Group Atrocities Against Civilians" rel="nofollow" href="https://www.hrw.org/news/2024/03/28/mali-army-wagner-group-atrocities-against-civilians">Mali: Army, Wagner Group Atrocities Against Civilians</a></li><li><a title="The Wagner Group’s Atrocities in Africa: Lies and Truth " rel="nofollow" href="https://2021-2025.state.gov/the-wagner-groups-atrocities-in-africa-lies-and-truth/">The Wagner Group’s Atrocities in Africa: Lies and Truth </a></li><li><a title="Massacres, Executions, and Falsified Graves: The Wagner Group’s Mounting Humanitarian Cost in Mali" rel="nofollow" href="https://www.csis.org/analysis/massacres-executions-and-falsified-graves-wagner-groups-mounting-humanitarian-cost-mali">Massacres, Executions, and Falsified Graves: The Wagner Group’s Mounting Humanitarian Cost in Mali</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 62</strong>: Lindsay Freeman, Director of the Technology, Law &amp; Policy program at the Human Rights Center, UC Berkeley School of Law, joins the show to discuss her team&#39;s meticulous work to document the Wagner Group&#39;s chain of command, military operations in parts of Africa, and the broadcasting of war crimes on social media platforms like Telegram. (Recorded at LABScon 2025)</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and <a href="https://x.com/lindsaysfreeman" rel="nofollow">Lindsay Freeman</a>.</p><p>Links:</p><ul><li><a title="LABScon Speaker 2025: Lindsay Freeman" rel="nofollow" href="https://www.labscon.io/speakers/lindsay-freeman/">LABScon Speaker 2025: Lindsay Freeman</a></li><li><a title="War Crimes for Fun and Profit (Lawfare)" rel="nofollow" href="https://www.lawfaremedia.org/article/war-crimes-for-fun-and-profit">War Crimes for Fun and Profit (Lawfare)</a></li><li><a title="Mali: Army, Wagner Group Atrocities Against Civilians" rel="nofollow" href="https://www.hrw.org/news/2024/03/28/mali-army-wagner-group-atrocities-against-civilians">Mali: Army, Wagner Group Atrocities Against Civilians</a></li><li><a title="The Wagner Group’s Atrocities in Africa: Lies and Truth " rel="nofollow" href="https://2021-2025.state.gov/the-wagner-groups-atrocities-in-africa-lies-and-truth/">The Wagner Group’s Atrocities in Africa: Lies and Truth </a></li><li><a title="Massacres, Executions, and Falsified Graves: The Wagner Group’s Mounting Humanitarian Cost in Mali" rel="nofollow" href="https://www.csis.org/analysis/massacres-executions-and-falsified-graves-wagner-groups-mounting-humanitarian-cost-mali">Massacres, Executions, and Falsified Graves: The Wagner Group’s Mounting Humanitarian Cost in Mali</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Can Apple's New Anti-Exploit Tech Stop iPhone Spyware Attacks?</title>
  <link>http://securityconversations.fireside.fm/apple-new-memory-safety-anti-exploit-iphone-spyware</link>
  <guid isPermaLink="false">25a25e4d-d101-4a90-af30-ae85214f326e</guid>
  <pubDate>Tue, 09 Sep 2025 15:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/25a25e4d-d101-4a90-af30-ae85214f326e.mp3" length="133531462" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 61: We cover a pair of software supply chain breaches (Salesforce Salesloft Drift and NPM/GitHub) that raises big questions about SaaS integrations and the ripple effects across major security vendors. 

Plus, Apple’s new Memory Integrity Enforcement in iPhone 17 and discussion on commercial spyware infections and the value of Apple notifications; concerns around Chinese hardware and surveillance equipment in US infrastructure; Silicon Valley profiting from China’s surveillance ecosystem; and controversy around a Huntress disclosure of an attacker’s operations after an EDR agent was mistakenly installed.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:45:46</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/25a25e4d-d101-4a90-af30-ae85214f326e/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 61: We cover a pair of software supply chain breaches (Salesforce Salesloft Drift and NPM/GitHub) that raises big questions about SaaS integrations and the ripple effects across major security vendors. 
Plus, Apple’s new Memory Integrity Enforcement in iPhone 17 and discussion on commercial spyware infections and the value of Apple notifications; concerns around Chinese hardware and surveillance equipment in US infrastructure; Silicon Valley profiting from China’s surveillance ecosystem; and controversy around a Huntress disclosure of an attacker’s operations after an EDR agent was mistakenly installed.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>supply chain, Salesforce, Apple, China, Russia, Israel, Iran, Google, Microsoft, CISA, NPM, GitHub, Signal, Android, zero-day, WhatsApp, Meta, Apple, MIE, Memory Safety</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 61</strong>: We cover a pair of software supply chain breaches (Salesforce Salesloft Drift and NPM/GitHub) that raises big questions about SaaS integrations and the ripple effects across major security vendors. </p>

<p>Plus, Apple’s new Memory Integrity Enforcement in iPhone 17 and discussion on commercial spyware infections and the value of Apple notifications; concerns around Chinese hardware and surveillance equipment in US infrastructure; Silicon Valley profiting from China’s surveillance ecosystem; and controversy around a Huntress disclosure of an attacker’s operations after an EDR agent was mistakenly installed.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1TFCmWNzyYKL35z_3jmiaXs6xpR7egZOjyY4WhScJTzg/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Salesforce advisory on Salesloft Drift hack" rel="nofollow" href="https://status.salesforce.com/generalmessages/20000217">Salesforce advisory on Salesloft Drift hack</a></li><li><a title="Salesloft Drift Breach Tracker" rel="nofollow" href="https://www.driftbreach.com/">Salesloft Drift Breach Tracker</a></li><li><a title="Mandiant Drift and Salesloft Application Investigations" rel="nofollow" href="https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations">Mandiant Drift and Salesloft Application Investigations</a></li><li><a title="Widespread Data Theft Targets Salesforce Instances via Salesloft Drift" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift">Widespread Data Theft Targets Salesforce Instances via Salesloft Drift</a></li><li><a title="Large-Scale NPM Attack" rel="nofollow" href="https://cointelegraph.com/news/large-scale-npm-attack-compromised-less-50-dollars">Large-Scale NPM Attack</a></li><li><a title="NPM attack failed, with almost no victims" rel="nofollow" href="https://x.com/P3b7_/status/1965336272550899932">NPM attack failed, with almost no victims</a></li><li><a title="Chinese Hackers Pretended to Be a Top U.S. Lawmaker" rel="nofollow" href="https://archive.ph/KlhAo">Chinese Hackers Pretended to Be a Top U.S. Lawmaker</a></li><li><a title="Czech cyber agency warns against using services and products that send data to China" rel="nofollow" href="https://therecord.media/czech-nukib-warns-against-products-sending-data-china">Czech cyber agency warns against using services and products that send data to China</a></li><li><a title="Apple Debuts Memory Integrity Enforcement (MIE)" rel="nofollow" href="https://security.apple.com/blog/memory-integrity-enforcement/">Apple Debuts Memory Integrity Enforcement (MIE)</a></li><li><a title="Huntress: An Attacker’s Blunder Gave Us a Look Into Their Operations" rel="nofollow" href="https://www.huntress.com/blog/rare-look-inside-attacker-operation">Huntress: An Attacker’s Blunder Gave Us a Look Into Their Operations</a></li><li><a title="LABScon 2025 Agenda" rel="nofollow" href="https://events.sentinelone.com/event/LABScon2025/agenda">LABScon 2025 Agenda</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 61</strong>: We cover a pair of software supply chain breaches (Salesforce Salesloft Drift and NPM/GitHub) that raises big questions about SaaS integrations and the ripple effects across major security vendors. </p>

<p>Plus, Apple’s new Memory Integrity Enforcement in iPhone 17 and discussion on commercial spyware infections and the value of Apple notifications; concerns around Chinese hardware and surveillance equipment in US infrastructure; Silicon Valley profiting from China’s surveillance ecosystem; and controversy around a Huntress disclosure of an attacker’s operations after an EDR agent was mistakenly installed.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1TFCmWNzyYKL35z_3jmiaXs6xpR7egZOjyY4WhScJTzg/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Salesforce advisory on Salesloft Drift hack" rel="nofollow" href="https://status.salesforce.com/generalmessages/20000217">Salesforce advisory on Salesloft Drift hack</a></li><li><a title="Salesloft Drift Breach Tracker" rel="nofollow" href="https://www.driftbreach.com/">Salesloft Drift Breach Tracker</a></li><li><a title="Mandiant Drift and Salesloft Application Investigations" rel="nofollow" href="https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations">Mandiant Drift and Salesloft Application Investigations</a></li><li><a title="Widespread Data Theft Targets Salesforce Instances via Salesloft Drift" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift">Widespread Data Theft Targets Salesforce Instances via Salesloft Drift</a></li><li><a title="Large-Scale NPM Attack" rel="nofollow" href="https://cointelegraph.com/news/large-scale-npm-attack-compromised-less-50-dollars">Large-Scale NPM Attack</a></li><li><a title="NPM attack failed, with almost no victims" rel="nofollow" href="https://x.com/P3b7_/status/1965336272550899932">NPM attack failed, with almost no victims</a></li><li><a title="Chinese Hackers Pretended to Be a Top U.S. Lawmaker" rel="nofollow" href="https://archive.ph/KlhAo">Chinese Hackers Pretended to Be a Top U.S. Lawmaker</a></li><li><a title="Czech cyber agency warns against using services and products that send data to China" rel="nofollow" href="https://therecord.media/czech-nukib-warns-against-products-sending-data-china">Czech cyber agency warns against using services and products that send data to China</a></li><li><a title="Apple Debuts Memory Integrity Enforcement (MIE)" rel="nofollow" href="https://security.apple.com/blog/memory-integrity-enforcement/">Apple Debuts Memory Integrity Enforcement (MIE)</a></li><li><a title="Huntress: An Attacker’s Blunder Gave Us a Look Into Their Operations" rel="nofollow" href="https://www.huntress.com/blog/rare-look-inside-attacker-operation">Huntress: An Attacker’s Blunder Gave Us a Look Into Their Operations</a></li><li><a title="LABScon 2025 Agenda" rel="nofollow" href="https://events.sentinelone.com/event/LABScon2025/agenda">LABScon 2025 Agenda</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Salt Typhoon IOCs, Google floats ‘cyber disruption unit’, WhatsApp 0-click </title>
  <link>http://securityconversations.fireside.fm/salt-typhoon-iocs-google-disruption-unit-whatsapp-zero-click</link>
  <guid isPermaLink="false">1ec2ef88-a1b1-4df7-b737-24542f8462c8</guid>
  <pubDate>Fri, 29 Aug 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/1ec2ef88-a1b1-4df7-b737-24542f8462c8.mp3" length="101225542" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 60: We dissect a fresh multi-agency Salt Typhoon advisory (with IOCs and YARA rules!), why it landed late, why the wall of logos matters (and doesn’t), and what’s actually usable for defenders: new YARA, tool hashes, naming ambiguity across reports, the mention of Chinese vendors, and a Dutch note that smaller ISPs were hit.

Plus, Costin details his hunting stack and philosophy (historic IOC/malware hoarding, fast pivots, and AI as analyst “wingman”) and a new Chinese APT report that may intersect with LightBasin and the murky PSOA world. 

We also debate Google’s proposed “cyber disruption unit” versus Microsoft’s DCU (legal vs. “ethical” takedowns, PR, and business models); react to Anthropic’s report on real attacker use of Claude; note Amazon’s APT29 watering-hole disruption; and close on a fresh WhatsApp-to-ImageIO zero-click chain and practical phone OPSEC.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:24:48</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/1ec2ef88-a1b1-4df7-b737-24542f8462c8/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 60: We dissect a fresh multi-agency Salt Typhoon advisory (with IOCs and YARA rules!), why it landed late, why the wall of logos matters (and doesn’t), and what’s actually usable for defenders: new YARA, tool hashes, naming ambiguity across reports, the mention of Chinese vendors, and a Dutch note that smaller ISPs were hit.
Plus, Costin details his hunting stack and philosophy (historic IOC/malware hoarding, fast pivots, and AI as analyst “wingman”) and a new Chinese APT report that may intersect with LightBasin and the murky PSOA world. 
We also debate Google’s proposed “cyber disruption unit” versus Microsoft’s DCU (legal vs. “ethical” takedowns, PR, and business models); react to Anthropic’s report on real attacker use of Claude; note Amazon’s APT29 watering-hole disruption; and close on a fresh WhatsApp-to-ImageIO zero-click chain and practical phone OPSEC.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu).
</description>
  <itunes:keywords>Salt Typhoon, Cisco, Ivanti, YARA, Ghost Emperor, UNC5807, Dutch MIVD AIVD, Mirai, LIghtBasin, Google, active-defense, hacking back, WhatsApp, Apple, iOS</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 60</strong>: We dissect a fresh multi-agency Salt Typhoon advisory (with IOCs and YARA rules!), why it landed late, why the wall of logos matters (and doesn’t), and what’s actually usable for defenders: new YARA, tool hashes, naming ambiguity across reports, the mention of Chinese vendors, and a Dutch note that smaller ISPs were hit.</p>

<p>Plus, Costin details his hunting stack and philosophy (historic IOC/malware hoarding, fast pivots, and AI as analyst “wingman”) and a new Chinese APT report that may intersect with LightBasin and the murky PSOA world. </p>

<p>We also debate Google’s proposed “cyber disruption unit” versus Microsoft’s DCU (legal vs. “ethical” takedowns, PR, and business models); react to Anthropic’s report on real attacker use of Claude; note Amazon’s APT29 watering-hole disruption; and close on a fresh WhatsApp-to-ImageIO zero-click chain and practical phone OPSEC.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1s08A637odGBsqPX2lWWqtG5IM2hj6dWGtTzaxKbfWt4/edit?tab=t.0#heading=h.jbbo41oysex">Transcript (unedited, AI-generated)</a></li><li><a title="NSA, Allies Report on Salt Typhoon" rel="nofollow" href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4287371/nsa-and-others-provide-guidance-to-counter-china-state-sponsored-actors-targeti/">NSA, Allies Report on Salt Typhoon</a></li><li><a title="UK and allies expose China tech companies" rel="nofollow" href="https://www.ncsc.gov.uk/news/uk-allies-expose-china-tech-companies-enabling-cyber-campaign">UK and allies expose China tech companies</a></li><li><a title="Joint Advisory on Salt Typhoon (IOCs)" rel="nofollow" href="https://media.defense.gov/2025/Aug/22/2003786665/-1/-1/0/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.PDF">Joint Advisory on Salt Typhoon (IOCs)</a></li><li><a title="Dutch providers targeted by Salt Typhoon" rel="nofollow" href="https://www.defensie.nl/actueel/nieuws/2025/08/28/nederlandse-providers-doelwit-van-salt-typhoon">Dutch providers targeted by Salt Typhoon</a></li><li><a title="Silent Control: The Hidden Penetration of MystRodX" rel="nofollow" href="https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor/">Silent Control: The Hidden Penetration of MystRodX</a></li><li><a title="Google previews cyber ‘disruption unit&#39;" rel="nofollow" href="https://cyberscoop.com/google-cybersecurity-disruption-unit-active-defense-hack-back/">Google previews cyber ‘disruption unit'</a></li><li><a title="Anthropic report on misuse of Claude AI" rel="nofollow" href="https://www.anthropic.com/news/detecting-countering-misuse-aug-2025">Anthropic report on misuse of Claude AI</a></li><li><a title="WhatsApp 0day exploited (iOS attack chain)" rel="nofollow" href="https://www.whatsapp.com/security/advisories/2025/">WhatsApp 0day exploited (iOS attack chain)</a></li><li><a title="RationalEdge - Intelligence Meets Accuracy" rel="nofollow" href="https://rationaledge.io/">RationalEdge - Intelligence Meets Accuracy</a></li><li><a title="LABScon Speakers 2025" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon Speakers 2025</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 60</strong>: We dissect a fresh multi-agency Salt Typhoon advisory (with IOCs and YARA rules!), why it landed late, why the wall of logos matters (and doesn’t), and what’s actually usable for defenders: new YARA, tool hashes, naming ambiguity across reports, the mention of Chinese vendors, and a Dutch note that smaller ISPs were hit.</p>

<p>Plus, Costin details his hunting stack and philosophy (historic IOC/malware hoarding, fast pivots, and AI as analyst “wingman”) and a new Chinese APT report that may intersect with LightBasin and the murky PSOA world. </p>

<p>We also debate Google’s proposed “cyber disruption unit” versus Microsoft’s DCU (legal vs. “ethical” takedowns, PR, and business models); react to Anthropic’s report on real attacker use of Claude; note Amazon’s APT29 watering-hole disruption; and close on a fresh WhatsApp-to-ImageIO zero-click chain and practical phone OPSEC.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1s08A637odGBsqPX2lWWqtG5IM2hj6dWGtTzaxKbfWt4/edit?tab=t.0#heading=h.jbbo41oysex">Transcript (unedited, AI-generated)</a></li><li><a title="NSA, Allies Report on Salt Typhoon" rel="nofollow" href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4287371/nsa-and-others-provide-guidance-to-counter-china-state-sponsored-actors-targeti/">NSA, Allies Report on Salt Typhoon</a></li><li><a title="UK and allies expose China tech companies" rel="nofollow" href="https://www.ncsc.gov.uk/news/uk-allies-expose-china-tech-companies-enabling-cyber-campaign">UK and allies expose China tech companies</a></li><li><a title="Joint Advisory on Salt Typhoon (IOCs)" rel="nofollow" href="https://media.defense.gov/2025/Aug/22/2003786665/-1/-1/0/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.PDF">Joint Advisory on Salt Typhoon (IOCs)</a></li><li><a title="Dutch providers targeted by Salt Typhoon" rel="nofollow" href="https://www.defensie.nl/actueel/nieuws/2025/08/28/nederlandse-providers-doelwit-van-salt-typhoon">Dutch providers targeted by Salt Typhoon</a></li><li><a title="Silent Control: The Hidden Penetration of MystRodX" rel="nofollow" href="https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor/">Silent Control: The Hidden Penetration of MystRodX</a></li><li><a title="Google previews cyber ‘disruption unit&#39;" rel="nofollow" href="https://cyberscoop.com/google-cybersecurity-disruption-unit-active-defense-hack-back/">Google previews cyber ‘disruption unit'</a></li><li><a title="Anthropic report on misuse of Claude AI" rel="nofollow" href="https://www.anthropic.com/news/detecting-countering-misuse-aug-2025">Anthropic report on misuse of Claude AI</a></li><li><a title="WhatsApp 0day exploited (iOS attack chain)" rel="nofollow" href="https://www.whatsapp.com/security/advisories/2025/">WhatsApp 0day exploited (iOS attack chain)</a></li><li><a title="RationalEdge - Intelligence Meets Accuracy" rel="nofollow" href="https://rationaledge.io/">RationalEdge - Intelligence Meets Accuracy</a></li><li><a title="LABScon Speakers 2025" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon Speakers 2025</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Zero-day reality check: iOS exploits, MAPP in China and the hack-back temptation</title>
  <link>http://securityconversations.fireside.fm/zero-day-ios-mapp-china-letters-of-marque</link>
  <guid isPermaLink="false">3a700ea9-ec69-4472-bade-414c4c7a53b2</guid>
  <pubDate>Fri, 22 Aug 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/3a700ea9-ec69-4472-bade-414c4c7a53b2.mp3" length="118144375" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 59: Apple drops another emergency iOS patch and we unpack what that “may have been exploited” language really means: zero-click chains, why notifications help but forensics don’t, and the uncomfortable truth that Lockdown Mode is increasingly the default for high-risk users. We connect the dots from ImageIO bugs to geopolitics, discuss who’s likely using these exploits, why Apple’s guidance stops short, and the practical playbook (ADP on, reboot often, reduce attack surface) that actually works.

Plus, we debate Microsoft throttling MAPP access for Chinese vendors, the idea of “letters of marque” for cyber (outsourced offense: smart deterrent or Pandora’s box?), and dissect two case studies that blur APT and crimeware: PipeMagic’s CLFS zero-day and Russia-linked “Static Tundra” riding seven-year-old Cisco bugs. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:32:15</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/3/3a700ea9-ec69-4472-bade-414c4c7a53b2/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 59: Apple drops another emergency iOS patch and we unpack what that “may have been exploited” language really means: zero-click chains, why notifications help but forensics don’t, and the uncomfortable truth that Lockdown Mode is increasingly the default for high-risk users. We connect the dots from ImageIO bugs to geopolitics, discuss who’s likely using these exploits, why Apple’s guidance stops short, and the practical playbook (ADP on, reboot often, reduce attack surface) that actually works.
Plus, we debate Microsoft throttling MAPP access for Chinese vendors, the idea of “letters of marque” for cyber (outsourced offense: smart deterrent or Pandora’s box?), and dissect two case studies that blur APT and crimeware: PipeMagic’s CLFS zero-day and Russia-linked “Static Tundra” riding seven-year-old Cisco bugs. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Apple, iOS, iOS 18.6.2, Lockdown Mode, Citizen Lab, iPhone, ImageIO, Microsoft, MAPP, China, Letters of Marque, PipeMagic, Static Tundra, Russia</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 59</strong>: Apple drops another emergency iOS patch and we unpack what that “may have been exploited” language really means: zero-click chains, why notifications help but forensics don’t, and the uncomfortable truth that Lockdown Mode is increasingly the default for high-risk users. We connect the dots from ImageIO bugs to geopolitics, discuss who’s likely using these exploits, why Apple’s guidance stops short, and the practical playbook (ADP on, reboot often, reduce attack surface) that actually works.</p>

<p>Plus, we debate Microsoft throttling MAPP access for Chinese vendors, the idea of “letters of marque” for cyber (outsourced offense: smart deterrent or Pandora’s box?), and dissect two case studies that blur APT and crimeware: PipeMagic’s CLFS zero-day and Russia-linked “Static Tundra” riding seven-year-old Cisco bugs. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1s08A637odGBsqPX2lWWqtG5IM2hj6dWGtTzaxKbfWt4/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Apple bulletin: iOS 18.6.2" rel="nofollow" href="https://support.apple.com/en-us/124925">Apple bulletin: iOS 18.6.2</a></li><li><a title="Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS" rel="nofollow" href="https://cyberscoop.com/apple-zero-day-ios-macos-ipados-august-2025/">Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS</a></li><li><a title="UK drops demand for backdoor into Apple encryption" rel="nofollow" href="https://www.theverge.com/news/761240/uk-apple-us-encryption-back-door-demands-dropped">UK drops demand for backdoor into Apple encryption</a></li><li><a title="Tulsi Gabbard on UK dropping Apple backdoor mandate" rel="nofollow" href="https://x.com/DNIGabbard/status/1957623737232007638">Tulsi Gabbard on UK dropping Apple backdoor mandate</a></li><li><a title="Microsoft Curbs Early Notifications for Chinese Firms on Security Flaws" rel="nofollow" href="https://archive.ph/S1Qxw">Microsoft Curbs Early Notifications for Chinese Firms on Security Flaws</a></li><li><a title="Kaspersky report on PipeMagic" rel="nofollow" href="https://securelist.com/pipemagic/117270/">Kaspersky report on PipeMagic</a></li><li><a title="Microsoft: Dissecting PipeMagic Backdoor Framework" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a-modular-backdoor-framework/">Microsoft: Dissecting PipeMagic Backdoor Framework</a></li><li><a title="Cisco Talos on Static Tundra " rel="nofollow" href="https://blog.talosintelligence.com/static-tundra/">Cisco Talos on Static Tundra </a></li><li><a title="FBI advisory on end-of-life network devices" rel="nofollow" href="https://www.ic3.gov/PSA/2025/PSA250820">FBI advisory on end-of-life network devices</a></li><li><a title="SIM-Swapper, Scattered Spider Hacker Gets 10 Years" rel="nofollow" href="https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/">SIM-Swapper, Scattered Spider Hacker Gets 10 Years</a></li><li><a title="Qubic Claims Majority Control of Monero Hashrate, Raising 51% Attack Fears" rel="nofollow" href="https://www.coindesk.com/business/2025/08/12/qubic-claims-majority-control-of-monero-hashrate-raising-51-attack-fears">Qubic Claims Majority Control of Monero Hashrate, Raising 51% Attack Fears</a></li><li><a title="State of Statecraft Call for Papers" rel="nofollow" href="https://www.stateofstatecraft.com/cfp">State of Statecraft Call for Papers</a></li><li><a title="LABScon 2025 Speaker Roster" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon 2025 Speaker Roster</a></li><li><a title="Offensive AI Con" rel="nofollow" href="https://events.humanitix.com/offensive-ai-con?utm_term=&amp;utm_campaign=&amp;utm_source=adwords&amp;utm_medium=ppc&amp;hsa_acc=7180819758&amp;hsa_cam=20991033514&amp;hsa_grp=161185120489&amp;hsa_ad=689601156905&amp;hsa_src=g&amp;hsa_tgt=dsa-19959388920&amp;hsa_kw=&amp;hsa_mt=&amp;hsa_net=adwords&amp;hsa_ver=3&amp;gad_source=1&amp;gad_campaignid=20991033514&amp;gbraid=0AAAAABav_m8gbgDxsU7DmjBLke8XU8eai&amp;gclid=Cj0KCQjwwZDFBhCpARIsAB95qO0xhRhywMTqp0V9unCeS1_eXiTN5xZ6F78DxunKdzZZ2VCLYm3GZqMaAuuLEALw_wcB">Offensive AI Con</a></li><li><a title="Three Buddy Problem: LIVE in Canada " rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">Three Buddy Problem: LIVE in Canada </a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 59</strong>: Apple drops another emergency iOS patch and we unpack what that “may have been exploited” language really means: zero-click chains, why notifications help but forensics don’t, and the uncomfortable truth that Lockdown Mode is increasingly the default for high-risk users. We connect the dots from ImageIO bugs to geopolitics, discuss who’s likely using these exploits, why Apple’s guidance stops short, and the practical playbook (ADP on, reboot often, reduce attack surface) that actually works.</p>

<p>Plus, we debate Microsoft throttling MAPP access for Chinese vendors, the idea of “letters of marque” for cyber (outsourced offense: smart deterrent or Pandora’s box?), and dissect two case studies that blur APT and crimeware: PipeMagic’s CLFS zero-day and Russia-linked “Static Tundra” riding seven-year-old Cisco bugs. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1s08A637odGBsqPX2lWWqtG5IM2hj6dWGtTzaxKbfWt4/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Apple bulletin: iOS 18.6.2" rel="nofollow" href="https://support.apple.com/en-us/124925">Apple bulletin: iOS 18.6.2</a></li><li><a title="Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS" rel="nofollow" href="https://cyberscoop.com/apple-zero-day-ios-macos-ipados-august-2025/">Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS</a></li><li><a title="UK drops demand for backdoor into Apple encryption" rel="nofollow" href="https://www.theverge.com/news/761240/uk-apple-us-encryption-back-door-demands-dropped">UK drops demand for backdoor into Apple encryption</a></li><li><a title="Tulsi Gabbard on UK dropping Apple backdoor mandate" rel="nofollow" href="https://x.com/DNIGabbard/status/1957623737232007638">Tulsi Gabbard on UK dropping Apple backdoor mandate</a></li><li><a title="Microsoft Curbs Early Notifications for Chinese Firms on Security Flaws" rel="nofollow" href="https://archive.ph/S1Qxw">Microsoft Curbs Early Notifications for Chinese Firms on Security Flaws</a></li><li><a title="Kaspersky report on PipeMagic" rel="nofollow" href="https://securelist.com/pipemagic/117270/">Kaspersky report on PipeMagic</a></li><li><a title="Microsoft: Dissecting PipeMagic Backdoor Framework" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a-modular-backdoor-framework/">Microsoft: Dissecting PipeMagic Backdoor Framework</a></li><li><a title="Cisco Talos on Static Tundra " rel="nofollow" href="https://blog.talosintelligence.com/static-tundra/">Cisco Talos on Static Tundra </a></li><li><a title="FBI advisory on end-of-life network devices" rel="nofollow" href="https://www.ic3.gov/PSA/2025/PSA250820">FBI advisory on end-of-life network devices</a></li><li><a title="SIM-Swapper, Scattered Spider Hacker Gets 10 Years" rel="nofollow" href="https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/">SIM-Swapper, Scattered Spider Hacker Gets 10 Years</a></li><li><a title="Qubic Claims Majority Control of Monero Hashrate, Raising 51% Attack Fears" rel="nofollow" href="https://www.coindesk.com/business/2025/08/12/qubic-claims-majority-control-of-monero-hashrate-raising-51-attack-fears">Qubic Claims Majority Control of Monero Hashrate, Raising 51% Attack Fears</a></li><li><a title="State of Statecraft Call for Papers" rel="nofollow" href="https://www.stateofstatecraft.com/cfp">State of Statecraft Call for Papers</a></li><li><a title="LABScon 2025 Speaker Roster" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon 2025 Speaker Roster</a></li><li><a title="Offensive AI Con" rel="nofollow" href="https://events.humanitix.com/offensive-ai-con?utm_term=&amp;utm_campaign=&amp;utm_source=adwords&amp;utm_medium=ppc&amp;hsa_acc=7180819758&amp;hsa_cam=20991033514&amp;hsa_grp=161185120489&amp;hsa_ad=689601156905&amp;hsa_src=g&amp;hsa_tgt=dsa-19959388920&amp;hsa_kw=&amp;hsa_mt=&amp;hsa_net=adwords&amp;hsa_ver=3&amp;gad_source=1&amp;gad_campaignid=20991033514&amp;gbraid=0AAAAABav_m8gbgDxsU7DmjBLke8XU8eai&amp;gclid=Cj0KCQjwwZDFBhCpARIsAB95qO0xhRhywMTqp0V9unCeS1_eXiTN5xZ6F78DxunKdzZZ2VCLYm3GZqMaAuuLEALw_wcB">Offensive AI Con</a></li><li><a title="Three Buddy Problem: LIVE in Canada " rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">Three Buddy Problem: LIVE in Canada </a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>On AI’s future, security’s failures, and what comes next...</title>
  <link>http://securityconversations.fireside.fm/ai-futire-security-failures-whats-next</link>
  <guid isPermaLink="false">a144cfba-560a-41b9-a9db-8138273862b2</guid>
  <pubDate>Fri, 15 Aug 2025 13:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/a144cfba-560a-41b9-a9db-8138273862b2.mp3" length="56518966" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 58:  Indepth reaction to the Brandon Dixon episode, digging into what it’s really like to scale products inside a tech giant, navigate politics, and bring features to millions of machines. Plus, an exploration of the AI cybersecurity gold-rush, the promise and hype, and the gamble for startups versus the slow-moving advantage of incumbents. 

We revisit the Chinese "cyber militia" discussion and the looming AI “dot-com bubble,” the value of owning infrastructure, Nvidia and export controls, China’s manufacturing edge, and the geopolitics of supply chains.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:57:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/a144cfba-560a-41b9-a9db-8138273862b2/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 58:  The buddies react to the Brandon Dixon episode, digging into what it’s really like to scale products inside a tech giant, navigate politics, and bring features to millions of machines. Plus, an exploration of the AI cybersecurity gold rush, the promise and hype, and the gamble for startups versus the slow-moving advantage of incumbents. 
We revisit the Chinese "cyber militia" discussion and the looming AI “dot-com bubble,” the value of owning infrastructure, Nvidia and export controls, China’s manufacturing edge, and the geopolitics of supply chains.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>OpenAI, ChatGPT5, Claude, Mistral, Apple, Russia, China, zero-day, Microsoft, AI, NVIDIA</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 58</strong>:  The buddies react to the Brandon Dixon episode, digging into what it’s really like to scale products inside a tech giant, navigate politics, and bring features to millions of machines. Plus, an exploration of the AI cybersecurity gold rush, the promise and hype, and the gamble for startups versus the slow-moving advantage of incumbents. </p>

<p>We revisit the Chinese &quot;cyber militia&quot; discussion and the looming AI “dot-com bubble,” the value of owning infrastructure, Nvidia and export controls, China’s manufacturing edge, and the geopolitics of supply chains.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1VZcPDkqbuB4MZihxH8wKDEnpcFo7Kq70Kl-JV9i_p5s/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Live from Black Hat: Brandon Dixon" rel="nofollow" href="https://podcasts.apple.com/us/podcast/live-from-black-hat-brandon-dixon-parses-the-ai/id1414525622?i=1000721209590">Live from Black Hat: Brandon Dixon</a></li><li><a title="PSIRT | FortiGuard Labs" rel="nofollow" href="https://www.fortiguard.com/psirt/FG-IR-25-152">PSIRT | FortiGuard Labs</a></li><li><a title="SonicWall Firewalls – SSLVPN Recent Threat Activity" rel="nofollow" href="https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430">SonicWall Firewalls – SSLVPN Recent Threat Activity</a></li><li><a title="Cisco CVSS 1.0 RCE" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79">Cisco CVSS 1.0 RCE</a></li><li><a title="Margin Research: Cyber Militias Redux" rel="nofollow" href="https://margin.re/2025/08/cyber-militias-redux-or-why-your-boss-might-also-be-your-platoon-leader-in-china-2/">Margin Research: Cyber Militias Redux</a></li><li><a title="Russia Is Suspected to Be Behind Breach of Federal Court Filing System" rel="nofollow" href="https://archive.ph/iVhTS">Russia Is Suspected to Be Behind Breach of Federal Court Filing System</a></li><li><a title="Russian hackers seized control of Norwegian dam" rel="nofollow" href="https://www.theguardian.com/world/2025/aug/14/russian-hackers-control-norwegian-dam-norway">Russian hackers seized control of Norwegian dam</a></li><li><a title="Poland foiled cyberattack on big city&#39;s water supply" rel="nofollow" href="https://www.reuters.com/en/poland-foiled-cyberattack-big-citys-water-supply-deputy-pm-says-2025-08-14/">Poland foiled cyberattack on big city's water supply</a></li><li><a title="EU Parliament pressing for agreement on chat scanning bill" rel="nofollow" href="https://www.techradar.com/computing/cyber-security/a-political-blackmail-the-eu-parliament-is-pressing-for-new-mandatory-scanning-of-your-private-chats?utm_source=chatgpt.com">EU Parliament pressing for agreement on chat scanning bill</a></li><li><a title="LABScon 2025" rel="nofollow" href="https://www.labscon.io/">LABScon 2025</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 58</strong>:  The buddies react to the Brandon Dixon episode, digging into what it’s really like to scale products inside a tech giant, navigate politics, and bring features to millions of machines. Plus, an exploration of the AI cybersecurity gold rush, the promise and hype, and the gamble for startups versus the slow-moving advantage of incumbents. </p>

<p>We revisit the Chinese &quot;cyber militia&quot; discussion and the looming AI “dot-com bubble,” the value of owning infrastructure, Nvidia and export controls, China’s manufacturing edge, and the geopolitics of supply chains.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1VZcPDkqbuB4MZihxH8wKDEnpcFo7Kq70Kl-JV9i_p5s/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Live from Black Hat: Brandon Dixon" rel="nofollow" href="https://podcasts.apple.com/us/podcast/live-from-black-hat-brandon-dixon-parses-the-ai/id1414525622?i=1000721209590">Live from Black Hat: Brandon Dixon</a></li><li><a title="PSIRT | FortiGuard Labs" rel="nofollow" href="https://www.fortiguard.com/psirt/FG-IR-25-152">PSIRT | FortiGuard Labs</a></li><li><a title="SonicWall Firewalls – SSLVPN Recent Threat Activity" rel="nofollow" href="https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430">SonicWall Firewalls – SSLVPN Recent Threat Activity</a></li><li><a title="Cisco CVSS 1.0 RCE" rel="nofollow" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79">Cisco CVSS 1.0 RCE</a></li><li><a title="Margin Research: Cyber Militias Redux" rel="nofollow" href="https://margin.re/2025/08/cyber-militias-redux-or-why-your-boss-might-also-be-your-platoon-leader-in-china-2/">Margin Research: Cyber Militias Redux</a></li><li><a title="Russia Is Suspected to Be Behind Breach of Federal Court Filing System" rel="nofollow" href="https://archive.ph/iVhTS">Russia Is Suspected to Be Behind Breach of Federal Court Filing System</a></li><li><a title="Russian hackers seized control of Norwegian dam" rel="nofollow" href="https://www.theguardian.com/world/2025/aug/14/russian-hackers-control-norwegian-dam-norway">Russian hackers seized control of Norwegian dam</a></li><li><a title="Poland foiled cyberattack on big city&#39;s water supply" rel="nofollow" href="https://www.reuters.com/en/poland-foiled-cyberattack-big-citys-water-supply-deputy-pm-says-2025-08-14/">Poland foiled cyberattack on big city's water supply</a></li><li><a title="EU Parliament pressing for agreement on chat scanning bill" rel="nofollow" href="https://www.techradar.com/computing/cyber-security/a-political-blackmail-the-eu-parliament-is-pressing-for-new-mandatory-scanning-of-your-private-chats?utm_source=chatgpt.com">EU Parliament pressing for agreement on chat scanning bill</a></li><li><a title="LABScon 2025" rel="nofollow" href="https://www.labscon.io/">LABScon 2025</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Live from Black Hat: Brandon Dixon parses the AI security hype</title>
  <link>http://securityconversations.fireside.fm/live-black-hat-brandon-dixon-ai-security-hype</link>
  <guid isPermaLink="false">e0829cc5-9719-41bd-92d8-865d133d21cf</guid>
  <pubDate>Thu, 07 Aug 2025 09:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e0829cc5-9719-41bd-92d8-865d133d21cf.mp3" length="43316889" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 57:  Brandon Dixon (PassiveTotal/RiskIQ, Microsoft) leads a deep-dive into the collision of AI and cybersecurity. We tackle Google’s “Big Sleep” project, XBOW’s automation hype, the long-running tension between big tech ownership of critical security tools and the community’s need for open access.

Plus, the future of SOC automation to AI-assisted pen testing, how agentic AI could transform cyber talent bottlenecks and operational inefficiencies, geopolitical debates over backdoors in GPUs and the strategic implications of China’s AI model development. 

Cast: Brandon Dixon, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:30:14</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e0829cc5-9719-41bd-92d8-865d133d21cf/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 57: Brandon Dixon (PassiveTotal/RiskIQ, Microsoft) leads a deep-dive into the collision of AI and cybersecurity. We tackle Google’s “Big Sleep” project, XBOW’s HackerOne automation hype, the long-running tension between big tech ownership of critical security tools and the community’s need for open access.
Plus, the future of SOC automation to AI-assisted pen testing, how agentic AI could transform the cyber talent bottlenecks and operational inefficiencies, geopolitical debates over backdoors in GPUs and the strategic implications of China’s AI model development. 
Cast:  Brandon Dixon (https://www.linkedin.com/in/brandonsdixon/), Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>OpenAI, Aardvark, Microsoft, Google, Big Sleep, gen-AI, agentic AI, Black Hat, NVIDIA, XBOW, PassiveTotal, RiskIQ, VirusTotal, China</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 57</strong>: Brandon Dixon (PassiveTotal/RiskIQ, Microsoft) leads a deep-dive into the collision of AI and cybersecurity. We tackle Google’s “Big Sleep” project, XBOW’s HackerOne automation hype, the long-running tension between big tech ownership of critical security tools and the community’s need for open access.</p>

<p>Plus, the future of SOC automation to AI-assisted pen testing, how agentic AI could transform the cyber talent bottlenecks and operational inefficiencies, geopolitical debates over backdoors in GPUs and the strategic implications of China’s AI model development. </p>

<p><strong>Cast:</strong>  <a href="https://www.linkedin.com/in/brandonsdixon/" rel="nofollow">Brandon Dixon</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1qK9qf59EbwAZvr_zjR3FvmEN_nlpFPGAaTKNZYCVQFY/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Brandon Dixon | LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/brandonsdixon/">Brandon Dixon | LinkedIn</a></li><li><a title="Google &#39;Big Sleep&#39; AI Issue Tracker" rel="nofollow" href="https://issuetracker.google.com/issues?q=componentid:1836411&amp;s=type:desc&amp;s=issue_id:desc">Google 'Big Sleep' AI Issue Tracker</a></li><li><a title="XBOW - The road to Top 1: How XBOW did it" rel="nofollow" href="https://xbow.com/blog/top-1-how-xbow-did-it?utm_source=chatgpt.com">XBOW - The road to Top 1: How XBOW did it</a></li><li><a title="Does “XBOW AI Hacker” Deserve the Hype?" rel="nofollow" href="https://utkusen.substack.com/p/does-xbow-ai-hacker-deserve-the-hype">Does “XBOW AI Hacker” Deserve the Hype?</a></li><li><a title="XBOW - Taking the Top Hacker in the US to New Heights: XBOW Raises $75M Series B" rel="nofollow" href="https://xbow.com/blog/series-b">XBOW - Taking the Top Hacker in the US to New Heights: XBOW Raises $75M Series B</a></li><li><a title="NVIDIA: No Backdoors. No Kill Switches. No Spyware " rel="nofollow" href="https://blogs.nvidia.com/blog/no-backdoors-no-kill-switches-no-spyware/">NVIDIA: No Backdoors. No Kill Switches. No Spyware </a></li><li><a title="Nvidia reiterates its chips have no backdoors, urges US against location verification" rel="nofollow" href="https://www.reuters.com/world/china/nvidia-reiterates-its-chips-have-no-backdoors-urges-us-against-location-2025-08-06/?utm_source=chatgpt.com">Nvidia reiterates its chips have no backdoors, urges US against location verification</a></li><li><a title="Google: Our Big Sleep agent makes a big leap" rel="nofollow" href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-our-big-sleep-agent-makes-big-leap">Google: Our Big Sleep agent makes a big leap</a></li><li><a title="Microsoft announces acquisition of RiskIQ " rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2021/07/12/microsoft-to-acquire-riskiq-to-strengthen-cybersecurity-of-digital-transformation-and-hybrid-work/">Microsoft announces acquisition of RiskIQ </a></li><li><a title="RiskIQ attack surface management" rel="nofollow" href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/riskiq1592493552392.riskiq-saas?tab=overview">RiskIQ attack surface management</a></li><li><a title="Brandon Dixon (SecurityConversations podcast)" rel="nofollow" href="https://securityconversations.com/episode/brandon-dixon-vice-president-riskiq/">Brandon Dixon (SecurityConversations podcast)</a></li><li><a title="Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution" rel="nofollow" href="https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html">Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 57</strong>: Brandon Dixon (PassiveTotal/RiskIQ, Microsoft) leads a deep-dive into the collision of AI and cybersecurity. We tackle Google’s “Big Sleep” project, XBOW’s HackerOne automation hype, the long-running tension between big tech ownership of critical security tools and the community’s need for open access.</p>

<p>Plus, the future of SOC automation to AI-assisted pen testing, how agentic AI could transform the cyber talent bottlenecks and operational inefficiencies, geopolitical debates over backdoors in GPUs and the strategic implications of China’s AI model development. </p>

<p><strong>Cast:</strong>  <a href="https://www.linkedin.com/in/brandonsdixon/" rel="nofollow">Brandon Dixon</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1qK9qf59EbwAZvr_zjR3FvmEN_nlpFPGAaTKNZYCVQFY/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Brandon Dixon | LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/brandonsdixon/">Brandon Dixon | LinkedIn</a></li><li><a title="Google &#39;Big Sleep&#39; AI Issue Tracker" rel="nofollow" href="https://issuetracker.google.com/issues?q=componentid:1836411&amp;s=type:desc&amp;s=issue_id:desc">Google 'Big Sleep' AI Issue Tracker</a></li><li><a title="XBOW - The road to Top 1: How XBOW did it" rel="nofollow" href="https://xbow.com/blog/top-1-how-xbow-did-it?utm_source=chatgpt.com">XBOW - The road to Top 1: How XBOW did it</a></li><li><a title="Does “XBOW AI Hacker” Deserve the Hype?" rel="nofollow" href="https://utkusen.substack.com/p/does-xbow-ai-hacker-deserve-the-hype">Does “XBOW AI Hacker” Deserve the Hype?</a></li><li><a title="XBOW - Taking the Top Hacker in the US to New Heights: XBOW Raises $75M Series B" rel="nofollow" href="https://xbow.com/blog/series-b">XBOW - Taking the Top Hacker in the US to New Heights: XBOW Raises $75M Series B</a></li><li><a title="NVIDIA: No Backdoors. No Kill Switches. No Spyware " rel="nofollow" href="https://blogs.nvidia.com/blog/no-backdoors-no-kill-switches-no-spyware/">NVIDIA: No Backdoors. No Kill Switches. No Spyware </a></li><li><a title="Nvidia reiterates its chips have no backdoors, urges US against location verification" rel="nofollow" href="https://www.reuters.com/world/china/nvidia-reiterates-its-chips-have-no-backdoors-urges-us-against-location-2025-08-06/?utm_source=chatgpt.com">Nvidia reiterates its chips have no backdoors, urges US against location verification</a></li><li><a title="Google: Our Big Sleep agent makes a big leap" rel="nofollow" href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-our-big-sleep-agent-makes-big-leap">Google: Our Big Sleep agent makes a big leap</a></li><li><a title="Microsoft announces acquisition of RiskIQ " rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2021/07/12/microsoft-to-acquire-riskiq-to-strengthen-cybersecurity-of-digital-transformation-and-hybrid-work/">Microsoft announces acquisition of RiskIQ </a></li><li><a title="RiskIQ attack surface management" rel="nofollow" href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/riskiq1592493552392.riskiq-saas?tab=overview">RiskIQ attack surface management</a></li><li><a title="Brandon Dixon (SecurityConversations podcast)" rel="nofollow" href="https://securityconversations.com/episode/brandon-dixon-vice-president-riskiq/">Brandon Dixon (SecurityConversations podcast)</a></li><li><a title="Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution" rel="nofollow" href="https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html">Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Rethinking APT Attribution: Dakota Cary on Chinese Contractors and Espionage-as-a-Service</title>
  <link>http://securityconversations.fireside.fm/china-microsoft-mapp-zero-days-singapore-warning</link>
  <guid isPermaLink="false">7d8831a2-e2e9-4a1f-aef7-a7c2ae778589</guid>
  <pubDate>Fri, 01 Aug 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7d8831a2-e2e9-4a1f-aef7-a7c2ae778589.mp3" length="53618956" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 56: China-focused researcher Dakota Cary joins the buddies to dig into China’s sprawling cyber ecosystem, from the HAFNIUM indictments and MSS tasking pipelines to the murky world of APT contractors and the ransomware hustle. We break down China’s “entrepreneurial” model of intelligence collection, why public visibility into these threat actors is so hard to get right, and how companies like Microsoft get caught in the geopolitical crossfire. 

Plus: a deep dive on suspected MAPP leaks and Sharepoint zero-days, Singapore targeted by extremely sophisticated China-nexus hacking group, soft censorship in corporate threat-intel, and whether the U.S. should rethink how it fills its intelligence gaps.

Cast: Dakota Cary, Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:51:42</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7d8831a2-e2e9-4a1f-aef7-a7c2ae778589/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 56: China-focused researcher Dakota Cary joins the buddies to dig into China’s sprawling cyber ecosystem, from the HAFNIUM indictments and MSS tasking pipelines to the murky world of APT contractors and the ransomware hustle. We break down China’s “entrepreneurial” model of intelligence collection, why public visibility into these threat actors is so hard to get right, and how companies like Microsoft get caught in the geopolitical crossfire. 
Plus: a deep dive on suspected MAPP leaks and Sharepoint zero-days, Singapore targeted by extremely sophisticated China-nexus hacking group, soft censorship in corporate threat-intel, and whether the U.S. should rethink how it fills its intelligence gaps.
Cast: Dakota Cary (https://www.linkedin.com/in/dakotacary/), Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>China, Microsoft, MAPP, zero-day, Sharepoint, ISoon leaks, HAFNIUM, MSS, ransomware, Singapore, Fire ANT, geopolitics</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 56</strong>: China-focused researcher Dakota Cary joins the buddies to dig into China’s sprawling cyber ecosystem, from the HAFNIUM indictments and MSS tasking pipelines to the murky world of APT contractors and the ransomware hustle. We break down China’s “entrepreneurial” model of intelligence collection, why public visibility into these threat actors is so hard to get right, and how companies like Microsoft get caught in the geopolitical crossfire. </p>

<p>Plus: a deep dive on suspected MAPP leaks and Sharepoint zero-days, Singapore targeted by extremely sophisticated China-nexus hacking group, soft censorship in corporate threat-intel, and whether the U.S. should rethink how it fills its intelligence gaps.</p>

<p><strong>Cast:</strong> <a href="https://www.linkedin.com/in/dakotacary/" rel="nofollow">Dakota Cary</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1gBEQbXUnmY-LmQ8f8SsaW9IgDIn8b4Sis6vHl8xoaJU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Dakota Cary on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/dakotacary/">Dakota Cary on LinkedIn</a></li><li><a title="China’s Covert Capabilities -- Silk Spun From Hafnium" rel="nofollow" href="https://www.sentinelone.com/labs/chinas-covert-capabilities-silk-spun-from-hafnium/">China’s Covert Capabilities -- Silk Spun From Hafnium</a></li><li><a title="HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem" rel="nofollow" href="https://nattothoughts.substack.com/p/hafnium-linked-hacker-xu-zewei-riding">HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem</a></li><li><a title="Microsoft Probing Whether Chinese Hackers Found Flaw Via MAPP " rel="nofollow" href="https://archive.ph/txvJ5">Microsoft Probing Whether Chinese Hackers Found Flaw Via MAPP </a></li><li><a title="Cybersecurity Law of the People’s Republic of China" rel="nofollow" href="https://digichina.stanford.edu/work/translation-cybersecurity-law-of-the-peoples-republic-of-china-effective-june-1-2017/">Cybersecurity Law of the People’s Republic of China</a></li><li><a title="Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/">Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats</a></li><li><a title="Fire Ant: Hypervisor-Level Espionage Targeting VMware ESXi &amp; vCenter" rel="nofollow" href="https://www.sygnia.co/blog/fire-ant-a-deep-dive-into-hypervisor-level-espionage/">Fire Ant: Hypervisor-Level Espionage Targeting VMware ESXi &amp; vCenter</a></li><li><a title="Singapore actively dealing with ongoing China cyberattack" rel="nofollow" href="https://www.channelnewsasia.com/singapore/unc3886-cyber-security-threat-actor-attack-singapore-5245791">Singapore actively dealing with ongoing China cyberattack</a></li><li><a title="Iranians Targeted With Spyware in Lead-Up to War With Israel" rel="nofollow" href="https://archive.ph/GDKIo#selection-1523.32-1523.125">Iranians Targeted With Spyware in Lead-Up to War With Israel</a> &mdash;  all inside Iran and working either in the country’s technology sector or for the government.</li><li><a title="LABScon 2025" rel="nofollow" href="https://www.labscon.io/">LABScon 2025</a></li><li><a title="Apple in China (book)" rel="nofollow" href="https://www.simonandschuster.com/books/Apple-in-China/Patrick-McGee/9781668053379">Apple in China (book)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 56</strong>: China-focused researcher Dakota Cary joins the buddies to dig into China’s sprawling cyber ecosystem, from the HAFNIUM indictments and MSS tasking pipelines to the murky world of APT contractors and the ransomware hustle. We break down China’s “entrepreneurial” model of intelligence collection, why public visibility into these threat actors is so hard to get right, and how companies like Microsoft get caught in the geopolitical crossfire. </p>

<p>Plus: a deep dive on suspected MAPP leaks and Sharepoint zero-days, Singapore targeted by extremely sophisticated China-nexus hacking group, soft censorship in corporate threat-intel, and whether the U.S. should rethink how it fills its intelligence gaps.</p>

<p><strong>Cast:</strong> <a href="https://www.linkedin.com/in/dakotacary/" rel="nofollow">Dakota Cary</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1gBEQbXUnmY-LmQ8f8SsaW9IgDIn8b4Sis6vHl8xoaJU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Dakota Cary on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/dakotacary/">Dakota Cary on LinkedIn</a></li><li><a title="China’s Covert Capabilities -- Silk Spun From Hafnium" rel="nofollow" href="https://www.sentinelone.com/labs/chinas-covert-capabilities-silk-spun-from-hafnium/">China’s Covert Capabilities -- Silk Spun From Hafnium</a></li><li><a title="HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem" rel="nofollow" href="https://nattothoughts.substack.com/p/hafnium-linked-hacker-xu-zewei-riding">HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem</a></li><li><a title="Microsoft Probing Whether Chinese Hackers Found Flaw Via MAPP " rel="nofollow" href="https://archive.ph/txvJ5">Microsoft Probing Whether Chinese Hackers Found Flaw Via MAPP </a></li><li><a title="Cybersecurity Law of the People’s Republic of China" rel="nofollow" href="https://digichina.stanford.edu/work/translation-cybersecurity-law-of-the-peoples-republic-of-china-effective-june-1-2017/">Cybersecurity Law of the People’s Republic of China</a></li><li><a title="Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/">Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats</a></li><li><a title="Fire Ant: Hypervisor-Level Espionage Targeting VMware ESXi &amp; vCenter" rel="nofollow" href="https://www.sygnia.co/blog/fire-ant-a-deep-dive-into-hypervisor-level-espionage/">Fire Ant: Hypervisor-Level Espionage Targeting VMware ESXi &amp; vCenter</a></li><li><a title="Singapore actively dealing with ongoing China cyberattack" rel="nofollow" href="https://www.channelnewsasia.com/singapore/unc3886-cyber-security-threat-actor-attack-singapore-5245791">Singapore actively dealing with ongoing China cyberattack</a></li><li><a title="Iranians Targeted With Spyware in Lead-Up to War With Israel" rel="nofollow" href="https://archive.ph/GDKIo#selection-1523.32-1523.125">Iranians Targeted With Spyware in Lead-Up to War With Israel</a> &mdash;  all inside Iran and working either in the country’s technology sector or for the government.</li><li><a title="LABScon 2025" rel="nofollow" href="https://www.labscon.io/">LABScon 2025</a></li><li><a title="Apple in China (book)" rel="nofollow" href="https://www.simonandschuster.com/books/Apple-in-China/Patrick-McGee/9781668053379">Apple in China (book)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Microsoft Sharepoint security crisis: Faulty patches, Toolshell zero-days</title>
  <link>http://securityconversations.fireside.fm/msft-sharepoint-zero-day-faulty-patches-</link>
  <guid isPermaLink="false">fe4d62a3-cad0-4b3d-b729-d0e94654c458</guid>
  <pubDate>Fri, 25 Jul 2025 02:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/fe4d62a3-cad0-4b3d-b729-d0e94654c458.mp3" length="93250682" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 55:  We dig into Microsoft's latest security nightmare: a SharePoint zero-day exploit chain from Pwn2Own Berlin becomes a full-blown security crisis, with Chinese nation-state actors exploiting vulnerabilities that Microsoft struggled to patch properly, leading to trivial bypasses and a cascade of new CVEs. The timeline is messy, the patches are faulty, and ransomware groups are lining up to join the party.

We also revisit the ProPublica bombshell about Microsoft's "digital escorts" and U.S. government data exposure to Chinese adversaries and the company's "oops, we will stop" response. Plus, trusting Google's Big Sleep AI claims and a cautionary tale about AI agents gone rogue that wiped out a production database.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:55:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/fe4d62a3-cad0-4b3d-b729-d0e94654c458/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 55: A SharePoint zero-day exploit chain from Pwn2Own Berlin becomes a full-blown security crisis with Chinese nation-state actors exploiting vulnerabilities that Microsoft struggled to patch properly, leading to trivial bypasses and a cascade of new CVEs. The timeline is messy, the patches are faulty, and ransomware groups are lining up to join the party.
We also revisit the ProPublica bombshell about Microsoft's "digital escorts" and U.S. government data exposure to Chinese adversaries and the company's "oops, we will stop" response. Plus, trusting Google's Big Sleep AI claims and a cautionary tale about AI agents gone rogue that wiped out a production database.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>microsoft, sharepoint, zero-day, china, luckymouse, apt31, digital escorts, Hegseth, Big Sleep, ProPublica, Replit, artificial intelligence, AI, vibe coding</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 55</strong>: A SharePoint zero-day exploit chain from Pwn2Own Berlin becomes a full-blown security crisis with Chinese nation-state actors exploiting vulnerabilities that Microsoft struggled to patch properly, leading to trivial bypasses and a cascade of new CVEs. The timeline is messy, the patches are faulty, and ransomware groups are lining up to join the party.</p>

<p>We also revisit the ProPublica bombshell about Microsoft&#39;s &quot;digital escorts&quot; and U.S. government data exposure to Chinese adversaries and the company&#39;s &quot;oops, we will stop&quot; response. Plus, trusting Google&#39;s Big Sleep AI claims and a cautionary tale about AI agents gone rogue that wiped out a production database.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1G_OoBEvmZiGCO-FUMr9dr87X5g80K7fHPda6QY_avQQ/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Three Buddy Problem LIVE at Black Hat" rel="nofollow" href="https://lu.ma/e2ys3k72">Three Buddy Problem LIVE at Black Hat</a></li><li><a title="TBP at Countermeasures 2025" rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">TBP at Countermeasures 2025</a></li><li><a title="CODE WHITE GmbH ToolShell exploit" rel="nofollow" href="https://infosec.exchange/@codewhitesec/114851715379861407">CODE WHITE GmbH ToolShell exploit</a></li><li><a title="Microsoft guidance for SharePoint vulnerability CVE-2025-53770" rel="nofollow" href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">Microsoft guidance for SharePoint vulnerability CVE-2025-53770</a></li><li><a title="Kaspersky on ToolShell: A story of five Sharepoint vulns" rel="nofollow" href="https://securelist.com/toolshell-explained/117045/">Kaspersky on ToolShell: A story of five Sharepoint vulns</a></li><li><a title="Ryan&#39;s EkoParty keynote on Microsoft culture" rel="nofollow" href="https://x.com/juanandres_gs/status/1587794147448016896">Ryan's EkoParty keynote on Microsoft culture</a></li><li><a title="Microsoft Disrupting active exploitation of on-prem SharePoint flaws" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/">Microsoft Disrupting active exploitation of on-prem SharePoint flaws</a></li><li><a title="SentinelLabs on Sharepoint zero-day in-the-wild" rel="nofollow" href="https://www.sentinelone.com/blog/sharepoint-toolshell-zero-day-exploited-in-the-wild-targets-enterprise-servers/">SentinelLabs on Sharepoint zero-day in-the-wild</a></li><li><a title="ESET on ToolShell: An all-you-can-eat buffet for threat actors" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/toolshell-an-all-you-can-eat-buffet-for-threat-actors/">ESET on ToolShell: An all-you-can-eat buffet for threat actors</a></li><li><a title="Microsoft Stops Using China-Based Engineers for DoD Computer Systems" rel="nofollow" href="https://www.propublica.org/article/defense-department-pentagon-microsoft-digital-escort-china">Microsoft Stops Using China-Based Engineers for DoD Computer Systems</a></li><li><a title="AI coding platform goes rogue during code freeze and deletes entire company database" rel="nofollow" href="https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-coding-platform-goes-rogue-during-code-freeze-and-deletes-entire-company-database-replit-ceo-apologizes-after-ai-engine-says-it-made-a-catastrophic-error-in-judgment-and-destroyed-all-production-data">AI coding platform goes rogue during code freeze and deletes entire company database</a></li><li><a title="Jason Lemkin: Replit goes rogue" rel="nofollow" href="https://x.com/jasonlk/status/1946069562723897802">Jason Lemkin: Replit goes rogue</a></li><li><a title="John Hultquist on Big Dream AI" rel="nofollow" href="https://x.com/JohnHultquist/status/1947309146581119369">John Hultquist on Big Dream AI</a></li><li><a title="LABScon 2025 " rel="nofollow" href="https://www.labscon.io/">LABScon 2025 </a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 55</strong>: A SharePoint zero-day exploit chain from Pwn2Own Berlin becomes a full-blown security crisis with Chinese nation-state actors exploiting vulnerabilities that Microsoft struggled to patch properly, leading to trivial bypasses and a cascade of new CVEs. The timeline is messy, the patches are faulty, and ransomware groups are lining up to join the party.</p>

<p>We also revisit the ProPublica bombshell about Microsoft&#39;s &quot;digital escorts&quot; and U.S. government data exposure to Chinese adversaries and the company&#39;s &quot;oops, we will stop&quot; response. Plus, trusting Google&#39;s Big Sleep AI claims and a cautionary tale about AI agents gone rogue that wiped out a production database.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1G_OoBEvmZiGCO-FUMr9dr87X5g80K7fHPda6QY_avQQ/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Three Buddy Problem LIVE at Black Hat" rel="nofollow" href="https://lu.ma/e2ys3k72">Three Buddy Problem LIVE at Black Hat</a></li><li><a title="TBP at Countermeasures 2025" rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">TBP at Countermeasures 2025</a></li><li><a title="CODE WHITE GmbH ToolShell exploit" rel="nofollow" href="https://infosec.exchange/@codewhitesec/114851715379861407">CODE WHITE GmbH ToolShell exploit</a></li><li><a title="Microsoft guidance for SharePoint vulnerability CVE-2025-53770" rel="nofollow" href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">Microsoft guidance for SharePoint vulnerability CVE-2025-53770</a></li><li><a title="Kaspersky on ToolShell: A story of five Sharepoint vulns" rel="nofollow" href="https://securelist.com/toolshell-explained/117045/">Kaspersky on ToolShell: A story of five Sharepoint vulns</a></li><li><a title="Ryan&#39;s EkoParty keynote on Microsoft culture" rel="nofollow" href="https://x.com/juanandres_gs/status/1587794147448016896">Ryan's EkoParty keynote on Microsoft culture</a></li><li><a title="Microsoft Disrupting active exploitation of on-prem SharePoint flaws" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/">Microsoft Disrupting active exploitation of on-prem SharePoint flaws</a></li><li><a title="SentinelLabs on Sharepoint zero-day in-the-wild" rel="nofollow" href="https://www.sentinelone.com/blog/sharepoint-toolshell-zero-day-exploited-in-the-wild-targets-enterprise-servers/">SentinelLabs on Sharepoint zero-day in-the-wild</a></li><li><a title="ESET on ToolShell: An all-you-can-eat buffet for threat actors" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/toolshell-an-all-you-can-eat-buffet-for-threat-actors/">ESET on ToolShell: An all-you-can-eat buffet for threat actors</a></li><li><a title="Microsoft Stops Using China-Based Engineers for DoD Computer Systems" rel="nofollow" href="https://www.propublica.org/article/defense-department-pentagon-microsoft-digital-escort-china">Microsoft Stops Using China-Based Engineers for DoD Computer Systems</a></li><li><a title="AI coding platform goes rogue during code freeze and deletes entire company database" rel="nofollow" href="https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-coding-platform-goes-rogue-during-code-freeze-and-deletes-entire-company-database-replit-ceo-apologizes-after-ai-engine-says-it-made-a-catastrophic-error-in-judgment-and-destroyed-all-production-data">AI coding platform goes rogue during code freeze and deletes entire company database</a></li><li><a title="Jason Lemkin: Replit goes rogue" rel="nofollow" href="https://x.com/jasonlk/status/1946069562723897802">Jason Lemkin: Replit goes rogue</a></li><li><a title="John Hultquist on Big Dream AI" rel="nofollow" href="https://x.com/JohnHultquist/status/1947309146581119369">John Hultquist on Big Dream AI</a></li><li><a title="LABScon 2025 " rel="nofollow" href="https://www.labscon.io/">LABScon 2025 </a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Train brake hack, GRU sanctions, Wagner war crimes, Microsoft's Chinese ‘digital escorts’</title>
  <link>http://securityconversations.fireside.fm/train-brakes-gru-sanctions-wagner-telegram-digital-escorts</link>
  <guid isPermaLink="false">c52fc482-8ee7-498e-adeb-8e3584f74824</guid>
  <pubDate>Fri, 18 Jul 2025 10:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/c52fc482-8ee7-498e-adeb-8e3584f74824.mp3" length="86833367" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 54: Europol busted pro‑Russian hacktivist crew NoName 057(16), the Brits announce sanctions on  Russia’s GRU cyber units, Wagner‑linked “war influencers” streamed atrocities from Africa, and fresh tech worries ranged from a $500 RF flaw that can hijack U.S. train brakes.

Plus, ProPublica on Microsoft’s China‑based “digital escorts,” Google’s headline‑grabbing AI‑found SQLite zero‑day, and OpenAI’s new task‑running agents. Meanwhile, Ukraine’s hackers wiped a Russian drone maker, ransomware crippled a major vodka producer, and another Chrome zero‑day quietly underscored how routine critical exploits have become.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:48:45</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/c/c52fc482-8ee7-498e-adeb-8e3584f74824/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 54:  Europol busted pro‑Russian hacktivist crew NoName 057(16), the Brits announce sanctions on  Russia’s GRU cyber units, Wagner‑linked “war influencers” streamed atrocities from Africa, and fresh tech worries ranged from a $500 RF flaw that can hijack U.S. train brakes.
Plus, ProPublica on Microsoft’s China‑based “digital escorts,” Google’s headline‑grabbing AI‑found SQLite zero‑day, and OpenAI’s new task‑running agents. Meanwhile, Ukraine’s hackers wiped a Russian drone maker, ransomware crippled a major vodka producer, and another Chrome zero‑day quietly underscored how routine critical exploits have become.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Russia, NoName057(16), LABScon, UK sanctions, GRU, Wagner, ICC, railroad, trains, ICS, AI, OpenAI, Microsoft, China</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 54</strong>:  Europol busted pro‑Russian hacktivist crew NoName 057(16), the Brits announce sanctions on  Russia’s GRU cyber units, Wagner‑linked “war influencers” streamed atrocities from Africa, and fresh tech worries ranged from a $500 RF flaw that can hijack U.S. train brakes.</p>

<p>Plus, ProPublica on Microsoft’s China‑based “digital escorts,” Google’s headline‑grabbing AI‑found SQLite zero‑day, and OpenAI’s new task‑running agents. Meanwhile, Ukraine’s hackers wiped a Russian drone maker, ransomware crippled a major vodka producer, and another Chrome zero‑day quietly underscored how routine critical exploits have become.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1GBR7FpP8x6DamPjUA_YKRT1QJ3PeH5K_lFwib1XmeA0/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Europol targets NoName057(16) pro-Russian cybercrime network" rel="nofollow" href="https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network">Europol targets NoName057(16) pro-Russian cybercrime network</a></li><li><a title="Europe&#39;s most wanted list" rel="nofollow" href="https://eumostwanted.eu/">Europe's most wanted list</a></li><li><a title="UK sanctions Russian spies linked to Mariupol strikes" rel="nofollow" href="https://www.politico.eu/article/uk-sanctions-russian-spies-mariupol-strikes/">UK sanctions Russian spies linked to Mariupol strikes</a></li><li><a title="Profile: GRU cyber and hybrid threat operations" rel="nofollow" href="https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations">Profile: GRU cyber and hybrid threat operations</a></li><li><a title="Lindsay Freeman: War Crimes for Fun and Profit" rel="nofollow" href="https://www.lawfaremedia.org/article/war-crimes-for-fun-and-profit">Lindsay Freeman: War Crimes for Fun and Profit</a></li><li><a title="Lindsay Freeman bio" rel="nofollow" href="https://www.lawfaremedia.org/contributors/lfreeman">Lindsay Freeman bio</a></li><li><a title="CISA: End-of-Train and Head-of-Train Remote Linking Protocol" rel="nofollow" href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-10">CISA: End-of-Train and Head-of-Train Remote Linking Protocol</a></li><li><a title="Background of train vulnerability (CVE-2025-1727)" rel="nofollow" href="https://x.com/midwestneil/status/1943708133421101446">Background of train vulnerability (CVE-2025-1727)</a></li><li><a title="ProPublica on Microsoft “Digital Escorts”" rel="nofollow" href="https://www.propublica.org/article/microsoft-digital-escorts-pentagon-defense-department-china-hackers">ProPublica on Microsoft “Digital Escorts”</a></li><li><a title="Google’s Big Sleep AI bug-finding claims" rel="nofollow" href="https://blog.google/technology/safety-security/cybersecurity-updates-summer-2025/">Google’s Big Sleep AI bug-finding claims</a></li><li><a title="EchoLeak (CVE-2025-32711)" rel="nofollow" href="https://www.trendmicro.com/en_us/research/25/g/preventing-zero-click-ai-threats-insights-from-echoleak.html">EchoLeak (CVE-2025-32711)</a></li><li><a title="Russian vodka producer reports disruptions after ransomware attack" rel="nofollow" href="https://therecord.media/novabev-russia-vodka-maker-ransomware-attack">Russian vodka producer reports disruptions after ransomware attack</a></li><li><a title="Ukrainian Hackers Cripple IT Infrastructure of Russian Drone Manufacturer" rel="nofollow" href="https://prm.ua/en/ukrainian-hackers-destroyed-the-it-infrastructure-of-a-russian-drone-manufacturer-what-is-known/">Ukrainian Hackers Cripple IT Infrastructure of Russian Drone Manufacturer</a></li><li><a title="Another exploited Google Chrome zero-day" rel="nofollow" href="https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html">Another exploited Google Chrome zero-day</a></li><li><a title="Three Buddy Problem LIVE at Black Hat" rel="nofollow" href="https://lu.ma/e2ys3k72">Three Buddy Problem LIVE at Black Hat</a></li><li><a title="Ringzer0 COUNTERMEASURE" rel="nofollow" href="https://ringzer0.training/countermeasure25/">Ringzer0 COUNTERMEASURE</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 54</strong>:  Europol busted pro‑Russian hacktivist crew NoName 057(16), the Brits announce sanctions on  Russia’s GRU cyber units, Wagner‑linked “war influencers” streamed atrocities from Africa, and fresh tech worries ranged from a $500 RF flaw that can hijack U.S. train brakes.</p>

<p>Plus, ProPublica on Microsoft’s China‑based “digital escorts,” Google’s headline‑grabbing AI‑found SQLite zero‑day, and OpenAI’s new task‑running agents. Meanwhile, Ukraine’s hackers wiped a Russian drone maker, ransomware crippled a major vodka producer, and another Chrome zero‑day quietly underscored how routine critical exploits have become.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1GBR7FpP8x6DamPjUA_YKRT1QJ3PeH5K_lFwib1XmeA0/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Europol targets NoName057(16) pro-Russian cybercrime network" rel="nofollow" href="https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network">Europol targets NoName057(16) pro-Russian cybercrime network</a></li><li><a title="Europe&#39;s most wanted list" rel="nofollow" href="https://eumostwanted.eu/">Europe's most wanted list</a></li><li><a title="UK sanctions Russian spies linked to Mariupol strikes" rel="nofollow" href="https://www.politico.eu/article/uk-sanctions-russian-spies-mariupol-strikes/">UK sanctions Russian spies linked to Mariupol strikes</a></li><li><a title="Profile: GRU cyber and hybrid threat operations" rel="nofollow" href="https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations">Profile: GRU cyber and hybrid threat operations</a></li><li><a title="Lindsay Freeman: War Crimes for Fun and Profit" rel="nofollow" href="https://www.lawfaremedia.org/article/war-crimes-for-fun-and-profit">Lindsay Freeman: War Crimes for Fun and Profit</a></li><li><a title="Lindsay Freeman bio" rel="nofollow" href="https://www.lawfaremedia.org/contributors/lfreeman">Lindsay Freeman bio</a></li><li><a title="CISA: End-of-Train and Head-of-Train Remote Linking Protocol" rel="nofollow" href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-10">CISA: End-of-Train and Head-of-Train Remote Linking Protocol</a></li><li><a title="Background of train vulnerability (CVE-2025-1727)" rel="nofollow" href="https://x.com/midwestneil/status/1943708133421101446">Background of train vulnerability (CVE-2025-1727)</a></li><li><a title="ProPublica on Microsoft “Digital Escorts”" rel="nofollow" href="https://www.propublica.org/article/microsoft-digital-escorts-pentagon-defense-department-china-hackers">ProPublica on Microsoft “Digital Escorts”</a></li><li><a title="Google’s Big Sleep AI bug-finding claims" rel="nofollow" href="https://blog.google/technology/safety-security/cybersecurity-updates-summer-2025/">Google’s Big Sleep AI bug-finding claims</a></li><li><a title="EchoLeak (CVE-2025-32711)" rel="nofollow" href="https://www.trendmicro.com/en_us/research/25/g/preventing-zero-click-ai-threats-insights-from-echoleak.html">EchoLeak (CVE-2025-32711)</a></li><li><a title="Russian vodka producer reports disruptions after ransomware attack" rel="nofollow" href="https://therecord.media/novabev-russia-vodka-maker-ransomware-attack">Russian vodka producer reports disruptions after ransomware attack</a></li><li><a title="Ukrainian Hackers Cripple IT Infrastructure of Russian Drone Manufacturer" rel="nofollow" href="https://prm.ua/en/ukrainian-hackers-destroyed-the-it-infrastructure-of-a-russian-drone-manufacturer-what-is-known/">Ukrainian Hackers Cripple IT Infrastructure of Russian Drone Manufacturer</a></li><li><a title="Another exploited Google Chrome zero-day" rel="nofollow" href="https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html">Another exploited Google Chrome zero-day</a></li><li><a title="Three Buddy Problem LIVE at Black Hat" rel="nofollow" href="https://lu.ma/e2ys3k72">Three Buddy Problem LIVE at Black Hat</a></li><li><a title="Ringzer0 COUNTERMEASURE" rel="nofollow" href="https://ringzer0.training/countermeasure25/">Ringzer0 COUNTERMEASURE</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>How did China get Microsoft's zero-day exploits?</title>
  <link>http://securityconversations.fireside.fm/hafnium-hacker-arrested-china-microsoft-zerodays</link>
  <guid isPermaLink="false">05ea91d2-dd79-43f9-a534-4b641cacfe9b</guid>
  <pubDate>Thu, 10 Jul 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/05ea91d2-dd79-43f9-a534-4b641cacfe9b.mp3" length="88964480" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 53:  We dig into news of the first-ever arrest of a Chinese intelligence-linked hacker in Italy, unpack the mystery behind HAFNIUM and how they somehow got their hands on the same Microsoft Exchange zero-days that researcher Orange Tsai discovered - was it coincidence, inside access, or something more sinister? 

Plus, China's massive cyber capabilities pipeline, ‘theCom’ teenagers arrested in the UK after ransomware binge, and spyware attacks against Russian organizations.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:49:05</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/0/05ea91d2-dd79-43f9-a534-4b641cacfe9b/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 53:  We dig into news of the first-ever arrest of a Chinese intelligence-linked hacker in Italy, unpack the mystery behind HAFNIUM and how they somehow got their hands on the same Microsoft Exchange zero-days that researcher Orange Tsai discovered - was it coincidence, inside access, or something more sinister?
Plus, China's massive cyber capabilities pipeline, ‘theCom’ teenagers arrested in the UK after ransomware binge, and spyware attacks against Russian organizations.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Russia, China, Ukraine, HAFNIUM, Microsoft, Zero-day, Orange Tsai, drones, thecom, ransomware, Exchange</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 53</strong>:  We dig into news of the first-ever arrest of a Chinese intelligence-linked hacker in Italy, unpack the mystery behind HAFNIUM and how they somehow got their hands on the same Microsoft Exchange zero-days that researcher Orange Tsai discovered - was it coincidence, inside access, or something more sinister?</p>

<p>Plus, China&#39;s massive cyber capabilities pipeline, ‘theCom’ teenagers arrested in the UK after ransomware binge, and spyware attacks against Russian organizations.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1XBzJY0yzS-1jzb7u4TIq0SKkGFCYalbYS15LdYX7a3o/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title=" US Gov: Prolific Chinese state-sponsored contract hacker arrested" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-announces-arrest-prolific-chinese-state-sponsored-contract-hacker"> US Gov: Prolific Chinese state-sponsored contract hacker arrested</a></li><li><a title="Microsoft: HAFNIUM targeting Exchange Servers with 0-day exploits" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/">Microsoft: HAFNIUM targeting Exchange Servers with 0-day exploits</a></li><li><a title="Microsoft Exchange Server Attack Timeline" rel="nofollow" href="https://unit42.paloaltonetworks.com/microsoft-exchange-server-attack-timeline/">Microsoft Exchange Server Attack Timeline</a></li><li><a title="YouTube: Orange Tsai on ProxyLogon" rel="nofollow" href="https://www.youtube.com/watch?v=5mqid-7zp8k&amp;ab_channel=DEFCONConference">YouTube: Orange Tsai on ProxyLogon</a></li><li><a title="Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace" rel="nofollow" href="https://www.atlanticcouncil.org/in-depth-research-reports/report/crash-exploit-and-burn/">Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace</a></li><li><a title="The Growing Role of Cyber Militias in China’s Network Warfare Force Structure" rel="nofollow" href="https://margin.re/mobilizing-cyber-power-the-growing-role-of-cyber-militias-in-chinas-network-warfare-force-structure-2/">The Growing Role of Cyber Militias in China’s Network Warfare Force Structure</a></li><li><a title="NCA arrest four for attacks on M&amp;S, Co-op and Harrods" rel="nofollow" href="https://www.nationalcrimeagency.gov.uk/news/retail-cyber-attacks-nca-arrest-four-for-attacks-on-m-s-co-op-and-harrods">NCA arrest four for attacks on M&amp;S, Co-op and Harrods</a></li><li><a title="Four arrested by UK police over ransomware attacks on M&amp;S, Co-op and Harrods" rel="nofollow" href="https://therecord.media/uk-arrests-four-ransomware-ms-harrods-co-op">Four arrested by UK police over ransomware attacks on M&amp;S, Co-op and Harrods</a></li><li><a title="Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war" rel="nofollow" href="https://therecord.media/cyberattack-russia-firmware-blow-hackers">Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war</a></li><li><a title="Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war" rel="nofollow" href="https://therecord.media/cyberattack-russia-firmware-blow-hackers">Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war</a></li><li><a title="Batavia spyware targeting Russian organizations" rel="nofollow" href="https://securelist.com/batavia-spyware-steals-data-from-russian-organizations/116866/">Batavia spyware targeting Russian organizations</a></li><li><a title="Chainalysis: First-ever crypto seizure in Greece" rel="nofollow" href="https://www.chainalysis.com/blog/greece-first-ever-crypto-seizure-bybit-hack-2025/">Chainalysis: First-ever crypto seizure in Greece</a></li><li><a title="Ringzer0 COUNTERMEASURE" rel="nofollow" href="https://ringzer0.training/countermeasure25/">Ringzer0 COUNTERMEASURE</a> &mdash; Three Buddy Problem discount code for training: CM25-3BUDDY</li><li><a title="LABScon 2025" rel="nofollow" href="https://labscon.io">LABScon 2025</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 53</strong>:  We dig into news of the first-ever arrest of a Chinese intelligence-linked hacker in Italy, unpack the mystery behind HAFNIUM and how they somehow got their hands on the same Microsoft Exchange zero-days that researcher Orange Tsai discovered - was it coincidence, inside access, or something more sinister?</p>

<p>Plus, China&#39;s massive cyber capabilities pipeline, ‘theCom’ teenagers arrested in the UK after ransomware binge, and spyware attacks against Russian organizations.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1XBzJY0yzS-1jzb7u4TIq0SKkGFCYalbYS15LdYX7a3o/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title=" US Gov: Prolific Chinese state-sponsored contract hacker arrested" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-announces-arrest-prolific-chinese-state-sponsored-contract-hacker"> US Gov: Prolific Chinese state-sponsored contract hacker arrested</a></li><li><a title="Microsoft: HAFNIUM targeting Exchange Servers with 0-day exploits" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/">Microsoft: HAFNIUM targeting Exchange Servers with 0-day exploits</a></li><li><a title="Microsoft Exchange Server Attack Timeline" rel="nofollow" href="https://unit42.paloaltonetworks.com/microsoft-exchange-server-attack-timeline/">Microsoft Exchange Server Attack Timeline</a></li><li><a title="YouTube: Orange Tsai on ProxyLogon" rel="nofollow" href="https://www.youtube.com/watch?v=5mqid-7zp8k&amp;ab_channel=DEFCONConference">YouTube: Orange Tsai on ProxyLogon</a></li><li><a title="Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace" rel="nofollow" href="https://www.atlanticcouncil.org/in-depth-research-reports/report/crash-exploit-and-burn/">Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace</a></li><li><a title="The Growing Role of Cyber Militias in China’s Network Warfare Force Structure" rel="nofollow" href="https://margin.re/mobilizing-cyber-power-the-growing-role-of-cyber-militias-in-chinas-network-warfare-force-structure-2/">The Growing Role of Cyber Militias in China’s Network Warfare Force Structure</a></li><li><a title="NCA arrest four for attacks on M&amp;S, Co-op and Harrods" rel="nofollow" href="https://www.nationalcrimeagency.gov.uk/news/retail-cyber-attacks-nca-arrest-four-for-attacks-on-m-s-co-op-and-harrods">NCA arrest four for attacks on M&amp;S, Co-op and Harrods</a></li><li><a title="Four arrested by UK police over ransomware attacks on M&amp;S, Co-op and Harrods" rel="nofollow" href="https://therecord.media/uk-arrests-four-ransomware-ms-harrods-co-op">Four arrested by UK police over ransomware attacks on M&amp;S, Co-op and Harrods</a></li><li><a title="Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war" rel="nofollow" href="https://therecord.media/cyberattack-russia-firmware-blow-hackers">Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war</a></li><li><a title="Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war" rel="nofollow" href="https://therecord.media/cyberattack-russia-firmware-blow-hackers">Cyberattack deals blow to Russian firmware used to repurpose civilian drones for Ukraine war</a></li><li><a title="Batavia spyware targeting Russian organizations" rel="nofollow" href="https://securelist.com/batavia-spyware-steals-data-from-russian-organizations/116866/">Batavia spyware targeting Russian organizations</a></li><li><a title="Chainalysis: First-ever crypto seizure in Greece" rel="nofollow" href="https://www.chainalysis.com/blog/greece-first-ever-crypto-seizure-bybit-hack-2025/">Chainalysis: First-ever crypto seizure in Greece</a></li><li><a title="Ringzer0 COUNTERMEASURE" rel="nofollow" href="https://ringzer0.training/countermeasure25/">Ringzer0 COUNTERMEASURE</a> &mdash; Three Buddy Problem discount code for training: CM25-3BUDDY</li><li><a title="LABScon 2025" rel="nofollow" href="https://labscon.io">LABScon 2025</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Who’s hacking who? Ivanti 0-days in France, China outs 'Night Eagle' APT</title>
  <link>http://securityconversations.fireside.fm/whos-hacking-who-ivanti-0days-france-night-eagle</link>
  <guid isPermaLink="false">b604bf91-d5a1-45a7-bd2e-223ecfeee15b</guid>
  <pubDate>Thu, 03 Jul 2025 15:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/b604bf91-d5a1-45a7-bd2e-223ecfeee15b.mp3" length="77845642" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 52:  Fresh intelligence reports out of Europe and China: France’s ANSSI documents a string of Ivanti VPN zero-days ('Houken'), and Quanxin frames a stealth Microsoft Exchange-zero-day chain linked to a North American 'Night Eagle' threat actor. We dissect the technical bread-crumbs, questions the attribution math, and connects Houken to SentinelOne’s “Purple Haze” research.

Plus, the FBI’s claim that China’s “Salt Typhoon” has been “contained,” Iran’s Nobitex crypto-exchange breach (Predatory Sparrow torches $90 million and leaks the source code), Iranian cyber capabilities and sanctions avoidance.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:34:16</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/b/b604bf91-d5a1-45a7-bd2e-223ecfeee15b/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 52:  Fresh intelligence reports out of Europe and China: France’s ANSSI documents a string of Ivanti VPN zero-days ('Houken'), and Quanxin frames a stealth Microsoft Exchange-zero-day chain linked to a North American 'Night Eagle' threat actor. We dissect the technical bread-crumbs, questions the attribution math, and connects Houken to SentinelOne’s “Purple Haze” research.
Plus, the FBI’s claim that China’s “Salt Typhoon” has been “contained,” Iran’s Nobitex crypto-exchange breach (Predatory Sparrow torches $90 million and leaks the source code), Iranian cyber capabilities and sanctions avoidance.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>France, ANSSI, Houken, Ivanti, zero-day, North Korea, fake IT workers, Scattered Spider, Chrome, Google, Salt Typhoon, Nobitex, Israel, Iran</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 52</strong>:  Fresh intelligence reports out of Europe and China: France’s ANSSI documents a string of Ivanti VPN zero-days (&#39;Houken&#39;), and Quanxin frames a stealth Microsoft Exchange-zero-day chain linked to a North American &#39;Night Eagle&#39; threat actor. We dissect the technical bread-crumbs, questions the attribution math, and connects Houken to SentinelOne’s “Purple Haze” research.</p>

<p>Plus, the FBI’s claim that China’s “Salt Typhoon” has been “contained,” Iran’s Nobitex crypto-exchange breach (Predatory Sparrow torches $90 million and leaks the source code), Iranian cyber capabilities and sanctions avoidance.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/19xE1kF3peywdmaH9j5xEdCvLmspni0s6p68KY1laYhg/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Houken: Seeking a path by living on the edge with zero-days" rel="nofollow" href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf">Houken: Seeking a path by living on the edge with zero-days</a></li><li><a title="China-nexus APTs recon on top-tier targets" rel="nofollow" href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">China-nexus APTs recon on top-tier targets</a></li><li><a title="French cybersecurity agency confirms government affected by Ivanti hacks" rel="nofollow" href="https://therecord.media/france-anssi-report-ivanti-bugs-exploited">French cybersecurity agency confirms government affected by Ivanti hacks</a></li><li><a title="Top FBI cyber official: Salt Typhoon ‘largely contained’" rel="nofollow" href="https://cyberscoop.com/top-fbi-cyber-official-salt-typhoon-largely-contained-in-telecom-networks/">Top FBI cyber official: Salt Typhoon ‘largely contained’</a></li><li><a title="Operation Blockbuster (Novetta)" rel="nofollow" href="https://www.usna.edu/CyberCenter/_files/documents/Operation-Blockbuster-Report.pdf">Operation Blockbuster (Novetta)</a></li><li><a title=" Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks" rel="nofollow" href="https://www.youtube.com/watch?v=MKKzHseTUUQ&amp;t=5007s&amp;ab_channel=ThreeBuddyProblem"> Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks</a></li><li><a title="Inside the Nobitex Breach: What the Leaked Source Code Reveals About Iran’s Crypto Infrastructure" rel="nofollow" href="https://www.trmlabs.com/resources/blog/inside-the-nobitex-breach-what-the-leaked-source-code-reveals-about-irans-crypto-infrastructure">Inside the Nobitex Breach: What the Leaked Source Code Reveals About Iran’s Crypto Infrastructure</a></li><li><a title="cisagov/thorium" rel="nofollow" href="https://github.com/cisagov/thorium">cisagov/thorium</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 52</strong>:  Fresh intelligence reports out of Europe and China: France’s ANSSI documents a string of Ivanti VPN zero-days (&#39;Houken&#39;), and Quanxin frames a stealth Microsoft Exchange-zero-day chain linked to a North American &#39;Night Eagle&#39; threat actor. We dissect the technical bread-crumbs, questions the attribution math, and connects Houken to SentinelOne’s “Purple Haze” research.</p>

<p>Plus, the FBI’s claim that China’s “Salt Typhoon” has been “contained,” Iran’s Nobitex crypto-exchange breach (Predatory Sparrow torches $90 million and leaks the source code), Iranian cyber capabilities and sanctions avoidance.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/19xE1kF3peywdmaH9j5xEdCvLmspni0s6p68KY1laYhg/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Houken: Seeking a path by living on the edge with zero-days" rel="nofollow" href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf">Houken: Seeking a path by living on the edge with zero-days</a></li><li><a title="China-nexus APTs recon on top-tier targets" rel="nofollow" href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">China-nexus APTs recon on top-tier targets</a></li><li><a title="French cybersecurity agency confirms government affected by Ivanti hacks" rel="nofollow" href="https://therecord.media/france-anssi-report-ivanti-bugs-exploited">French cybersecurity agency confirms government affected by Ivanti hacks</a></li><li><a title="Top FBI cyber official: Salt Typhoon ‘largely contained’" rel="nofollow" href="https://cyberscoop.com/top-fbi-cyber-official-salt-typhoon-largely-contained-in-telecom-networks/">Top FBI cyber official: Salt Typhoon ‘largely contained’</a></li><li><a title="Operation Blockbuster (Novetta)" rel="nofollow" href="https://www.usna.edu/CyberCenter/_files/documents/Operation-Blockbuster-Report.pdf">Operation Blockbuster (Novetta)</a></li><li><a title=" Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks" rel="nofollow" href="https://www.youtube.com/watch?v=MKKzHseTUUQ&amp;t=5007s&amp;ab_channel=ThreeBuddyProblem"> Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, bank hacks</a></li><li><a title="Inside the Nobitex Breach: What the Leaked Source Code Reveals About Iran’s Crypto Infrastructure" rel="nofollow" href="https://www.trmlabs.com/resources/blog/inside-the-nobitex-breach-what-the-leaked-source-code-reveals-about-irans-crypto-infrastructure">Inside the Nobitex Breach: What the Leaked Source Code Reveals About Iran’s Crypto Infrastructure</a></li><li><a title="cisagov/thorium" rel="nofollow" href="https://github.com/cisagov/thorium">cisagov/thorium</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, destructive bank hacks</title>
  <link>http://securityconversations.fireside.fm/cyberwar-and-vanishing-bitcoins</link>
  <guid isPermaLink="false">01c3eb2d-69d5-4ea4-bc65-8a356a4f2b68</guid>
  <pubDate>Fri, 20 Jun 2025 02:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/01c3eb2d-69d5-4ea4-bc65-8a356a4f2b68.mp3" length="144334262" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 51: Former Immunity/Trail of Bits researcher Hamid Kashfi  joins the buddies for a fast-moving tour of cyber activities in the Israel-Iran war. The crew unpacks who 'Predatory Sparrow' is, why Sepah Bank and the Nobitex crypto exchange were hit, and what a $90 million cryptocurrency burn really means. Plus, radar-blinding cyberattacks that paved the way for Israel’s air raid, the human cost of sudden ATM outages and unpaid salaries, and the puzzling “Code Breakers” data leak that preceded it all.

Hamid shares on-the-ground context, the buddies debate whether cyber operations can sway a shooting war, and everyone tries to gauge Iran’s true offensive muscle under sanctions.

Cast: Hamid Kashfi, Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine. </itunes:subtitle>
  <itunes:duration>3:07:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/0/01c3eb2d-69d5-4ea4-bc65-8a356a4f2b68/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 51: Former Immunity/Trail of Bits researcher Hamid Kashfi  joins the buddies for a fast-moving tour of cyber activities in the Israel-Iran war. The crew unpacks who 'Predatory Sparrow' is, why Sepah Bank and the Nobitex crypto exchange were hit, and what a $90 million cryptocurrency burn really means. Plus, radar-blinding cyberattacks that paved the way for Israel’s air raid, the human cost of sudden ATM outages and unpaid salaries, and the puzzling “Code Breakers” data leak that preceded it all.
Hamid shares on-the-ground context, the buddies debate whether cyber operations can sway a shooting war, and everyone tries to gauge Iran’s true offensive muscle under sanctions.
Cast: Hamid Kashfi (https://twitter.com/hkashfi),  Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Iran, Israel, Bitcoin, Predatory Sparrow, Bitcoin, Novitex, nuclear, Stuxnet, drone swarms, autonomous warfare</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 51</strong>: Former Immunity/Trail of Bits researcher Hamid Kashfi  joins the buddies for a fast-moving tour of cyber activities in the Israel-Iran war. The crew unpacks who &#39;Predatory Sparrow&#39; is, why Sepah Bank and the Nobitex crypto exchange were hit, and what a $90 million cryptocurrency burn really means. Plus, radar-blinding cyberattacks that paved the way for Israel’s air raid, the human cost of sudden ATM outages and unpaid salaries, and the puzzling “Code Breakers” data leak that preceded it all.</p>

<p>Hamid shares on-the-ground context, the buddies debate whether cyber operations can sway a shooting war, and everyone tries to gauge Iran’s true offensive muscle under sanctions.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/hkashfi" rel="nofollow">Hamid Kashfi</a>,  <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1yKeeXGR_b7gfGWwIVv_dV5RmIFCrYAZQs5BUMClyFtU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Pro-Israel hackers take credit for cyberattack on Iran&#39;s Bank Sepah" rel="nofollow" href="https://www.axios.com/2025/06/17/iran-bank-sepah-cyberattack-israel">Pro-Israel hackers take credit for cyberattack on Iran's Bank Sepah</a></li><li><a title="Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War" rel="nofollow" href="https://www.securityweek.com/predatory-sparrow-burns-90-million-on-iranian-crypto-exchange-in-cyber-shadow-war/">Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War</a></li><li><a title="Codebreakers and Predatory Sparrow" rel="nofollow" href="https://x.com/hkashfi/status/1934898014658654226?s=46&amp;t=NxSQbkIl4wl2Ei8yYr-9IQ">Codebreakers and Predatory Sparrow</a></li><li><a title="Iranian Exchange Nobitex: The $90M Exploit" rel="nofollow" href="https://www.chainalysis.com/blog/nobitex-iranian-exchange-exploit-june-2025/">Iranian Exchange Nobitex: The $90M Exploit</a></li><li><a title="Iranian newspaper: Defense system was hacked" rel="nofollow" href="https://www.iranintl.com/fa/202506150578">Iranian newspaper: Defense system was hacked</a></li><li><a title="Iranian state TV shows footage of Israeli drone" rel="nofollow" href="https://www.cnn.com/2025/06/18/world/video/iran-state-tv-israel-drone-ldn-digvid">Iranian state TV shows footage of Israeli drone</a></li><li><a title="Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/unc1860-iran-middle-eastern-networks">Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks</a></li><li><a title="Israeli Officials Warn Iran Is Hijacking Security Cameras to Spy" rel="nofollow" href="https://archive.ph/cCMt9">Israeli Officials Warn Iran Is Hijacking Security Cameras to Spy</a></li><li><a title="LABScon - Security Research in Real Time" rel="nofollow" href="https://www.labscon.io/">LABScon - Security Research in Real Time</a></li><li><a title="Three Buddy Problem LIVE" rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">Three Buddy Problem LIVE</a></li><li><a title="Hamid Kashfi: The curious case of Predatory Sparrow" rel="nofollow" href="https://www.darkcell.se/sparrows">Hamid Kashfi: The curious case of Predatory Sparrow</a></li><li><a title="Glasshouse episode with Hamid Kashfi" rel="nofollow" href="https://www.youtube.com/watch?v=z05lKD0R5jo&amp;ab_channel=TheGlasshouseCenter">Glasshouse episode with Hamid Kashfi</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 51</strong>: Former Immunity/Trail of Bits researcher Hamid Kashfi  joins the buddies for a fast-moving tour of cyber activities in the Israel-Iran war. The crew unpacks who &#39;Predatory Sparrow&#39; is, why Sepah Bank and the Nobitex crypto exchange were hit, and what a $90 million cryptocurrency burn really means. Plus, radar-blinding cyberattacks that paved the way for Israel’s air raid, the human cost of sudden ATM outages and unpaid salaries, and the puzzling “Code Breakers” data leak that preceded it all.</p>

<p>Hamid shares on-the-ground context, the buddies debate whether cyber operations can sway a shooting war, and everyone tries to gauge Iran’s true offensive muscle under sanctions.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/hkashfi" rel="nofollow">Hamid Kashfi</a>,  <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1yKeeXGR_b7gfGWwIVv_dV5RmIFCrYAZQs5BUMClyFtU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Pro-Israel hackers take credit for cyberattack on Iran&#39;s Bank Sepah" rel="nofollow" href="https://www.axios.com/2025/06/17/iran-bank-sepah-cyberattack-israel">Pro-Israel hackers take credit for cyberattack on Iran's Bank Sepah</a></li><li><a title="Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War" rel="nofollow" href="https://www.securityweek.com/predatory-sparrow-burns-90-million-on-iranian-crypto-exchange-in-cyber-shadow-war/">Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War</a></li><li><a title="Codebreakers and Predatory Sparrow" rel="nofollow" href="https://x.com/hkashfi/status/1934898014658654226?s=46&amp;t=NxSQbkIl4wl2Ei8yYr-9IQ">Codebreakers and Predatory Sparrow</a></li><li><a title="Iranian Exchange Nobitex: The $90M Exploit" rel="nofollow" href="https://www.chainalysis.com/blog/nobitex-iranian-exchange-exploit-june-2025/">Iranian Exchange Nobitex: The $90M Exploit</a></li><li><a title="Iranian newspaper: Defense system was hacked" rel="nofollow" href="https://www.iranintl.com/fa/202506150578">Iranian newspaper: Defense system was hacked</a></li><li><a title="Iranian state TV shows footage of Israeli drone" rel="nofollow" href="https://www.cnn.com/2025/06/18/world/video/iran-state-tv-israel-drone-ldn-digvid">Iranian state TV shows footage of Israeli drone</a></li><li><a title="Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/unc1860-iran-middle-eastern-networks">Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks</a></li><li><a title="Israeli Officials Warn Iran Is Hijacking Security Cameras to Spy" rel="nofollow" href="https://archive.ph/cCMt9">Israeli Officials Warn Iran Is Hijacking Security Cameras to Spy</a></li><li><a title="LABScon - Security Research in Real Time" rel="nofollow" href="https://www.labscon.io/">LABScon - Security Research in Real Time</a></li><li><a title="Three Buddy Problem LIVE" rel="nofollow" href="https://ringzer0.training/countermeasure25-three-buddy-problem-live/">Three Buddy Problem LIVE</a></li><li><a title="Hamid Kashfi: The curious case of Predatory Sparrow" rel="nofollow" href="https://www.darkcell.se/sparrows">Hamid Kashfi: The curious case of Predatory Sparrow</a></li><li><a title="Glasshouse episode with Hamid Kashfi" rel="nofollow" href="https://www.youtube.com/watch?v=z05lKD0R5jo&amp;ab_channel=TheGlasshouseCenter">Glasshouse episode with Hamid Kashfi</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Cyber flashpoints in Israel-Iran war, the 'magnet of threats', Mossad drone swarms</title>
  <link>http://securityconversations.fireside.fm/israel-iran-war-magnet-of-threats-drone-swarms</link>
  <guid isPermaLink="false">f5778cef-4751-4110-b0ec-6d82e3b4b504</guid>
  <pubDate>Fri, 13 Jun 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/f5778cef-4751-4110-b0ec-6d82e3b4b504.mp3" length="81069877" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 50: This week, we dissect cyber flashpoints in the Iran-Israel war, revisit the “magnet of threats” server in Iran that attracted APTs from multiple nation-states, and react to Israel's Mossad sneaking explosive drone swarms deep into Iran to support airstrikes.

Plus, Stealth Falcon’s new WebDAV zero-day, SentinelOne’s brush with Chinese APTs, Citizen Lab’s forensic takedown of Paragon’s iPhone spyware, and the sneaky Meta/Yandex trick that links Android web browsing to app IDs.

Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:51:48</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/f5778cef-4751-4110-b0ec-6d82e3b4b504/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 50: This week, we dissect cyber flashpoints in the Iran-Israel war, revisit the “magnet of threats” server in Iran that attracted APTs from multiple nation-states, and react to Israel's Mossad sneaking explosive drone swarms deep into Iran to support airstrikes.
Plus, Stealth Falcon’s new WebDAV zero-day, SentinelOne’s brush with Chinese APTs, Citizen Lab’s forensic takedown of Paragon’s iPhone spyware, and the sneaky Meta/Yandex trick that links Android web browsing to app IDs.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Iran, Israel, Russia, Ukraine, nuclear, Stuxnet, drone swarms, autonomous warfare, magnet of threats, zero-day, SentinelOne</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 50</strong>: This week, we dissect cyber flashpoints in the Iran-Israel war, revisit the “magnet of threats” server in Iran that attracted APTs from multiple nation-states, and react to Israel&#39;s Mossad sneaking explosive drone swarms deep into Iran to support airstrikes.</p>

<p>Plus, Stealth Falcon’s new WebDAV zero-day, SentinelOne’s brush with Chinese APTs, Citizen Lab’s forensic takedown of Paragon’s iPhone spyware, and the sneaky Meta/Yandex trick that links Android web browsing to app IDs.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1tbYrbhOmz1LKRzB1TBkoRds50jCwZRGHMsMBnwTl3nc/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Israel-Iran war breaks out" rel="nofollow" href="https://www.bbc.com/news/live/c93ydeqyq71t">Israel-Iran war breaks out</a></li><li><a title="&#39;The magnet of threats&#39;" rel="nofollow" href="https://www.kaspersky.com/about/press-releases/spy-wars-how-nation-state-backed-threat-actors-steal-from-and-copy-each-other">'The magnet of threats'</a></li><li><a title="Mossad set up drone swarm base in Iran " rel="nofollow" href="https://www.timesofisrael.com/liveblog_entry/mossad-set-up-a-drone-base-in-iran-uavs-were-activated-overnight-to-strike-surface-to-surface-missile-launchers-aimed-at-israel/">Mossad set up drone swarm base in Iran </a></li><li><a title="Stealth Falcon&#39;s Exploit of Microsoft Zero Day " rel="nofollow" href="https://research.checkpoint.com/2025/stealth-falcon-zero-day/">Stealth Falcon's Exploit of Microsoft Zero Day </a></li><li><a title="CVE-2025-33053 - WebDAV remote code execution" rel="nofollow" href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053">CVE-2025-33053 - WebDAV remote code execution</a></li><li><a title="CISA, Microsoft warn of Windows zero-day " rel="nofollow" href="https://therecord.media/microsoft-cisa-zero-day-turkish-defense-org">CISA, Microsoft warn of Windows zero-day </a></li><li><a title="China-nexus Threat actors target SentinelOne  " rel="nofollow" href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">China-nexus Threat actors target SentinelOne  </a></li><li><a title="Chinese Espionage Crews Circle SentinelOne" rel="nofollow" href="https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/">Chinese Espionage Crews Circle SentinelOne</a></li><li><a title="Citizen Lab: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab" rel="nofollow" href="https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/">Citizen Lab: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab</a></li><li><a title="Meta and Yandex are de-anonymizing Android users’ web browsing identifiers" rel="nofollow" href="https://arstechnica.com/security/2025/06/meta-and-yandex-are-de-anonymizing-android-users-web-browsing-identifiers/">Meta and Yandex are de-anonymizing Android users’ web browsing identifiers</a></li><li><a title="Dreadnode Offensive AI Conference" rel="nofollow" href="https://www.offensiveaicon.com/">Dreadnode Offensive AI Conference</a></li><li><a title="LABScon Call for Papers" rel="nofollow" href="https://www.labscon.io/cfp/">LABScon Call for Papers</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 50</strong>: This week, we dissect cyber flashpoints in the Iran-Israel war, revisit the “magnet of threats” server in Iran that attracted APTs from multiple nation-states, and react to Israel&#39;s Mossad sneaking explosive drone swarms deep into Iran to support airstrikes.</p>

<p>Plus, Stealth Falcon’s new WebDAV zero-day, SentinelOne’s brush with Chinese APTs, Citizen Lab’s forensic takedown of Paragon’s iPhone spyware, and the sneaky Meta/Yandex trick that links Android web browsing to app IDs.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1tbYrbhOmz1LKRzB1TBkoRds50jCwZRGHMsMBnwTl3nc/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Israel-Iran war breaks out" rel="nofollow" href="https://www.bbc.com/news/live/c93ydeqyq71t">Israel-Iran war breaks out</a></li><li><a title="&#39;The magnet of threats&#39;" rel="nofollow" href="https://www.kaspersky.com/about/press-releases/spy-wars-how-nation-state-backed-threat-actors-steal-from-and-copy-each-other">'The magnet of threats'</a></li><li><a title="Mossad set up drone swarm base in Iran " rel="nofollow" href="https://www.timesofisrael.com/liveblog_entry/mossad-set-up-a-drone-base-in-iran-uavs-were-activated-overnight-to-strike-surface-to-surface-missile-launchers-aimed-at-israel/">Mossad set up drone swarm base in Iran </a></li><li><a title="Stealth Falcon&#39;s Exploit of Microsoft Zero Day " rel="nofollow" href="https://research.checkpoint.com/2025/stealth-falcon-zero-day/">Stealth Falcon's Exploit of Microsoft Zero Day </a></li><li><a title="CVE-2025-33053 - WebDAV remote code execution" rel="nofollow" href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053">CVE-2025-33053 - WebDAV remote code execution</a></li><li><a title="CISA, Microsoft warn of Windows zero-day " rel="nofollow" href="https://therecord.media/microsoft-cisa-zero-day-turkish-defense-org">CISA, Microsoft warn of Windows zero-day </a></li><li><a title="China-nexus Threat actors target SentinelOne  " rel="nofollow" href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/">China-nexus Threat actors target SentinelOne  </a></li><li><a title="Chinese Espionage Crews Circle SentinelOne" rel="nofollow" href="https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/">Chinese Espionage Crews Circle SentinelOne</a></li><li><a title="Citizen Lab: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab" rel="nofollow" href="https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/">Citizen Lab: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab</a></li><li><a title="Meta and Yandex are de-anonymizing Android users’ web browsing identifiers" rel="nofollow" href="https://arstechnica.com/security/2025/06/meta-and-yandex-are-de-anonymizing-android-users-web-browsing-identifiers/">Meta and Yandex are de-anonymizing Android users’ web browsing identifiers</a></li><li><a title="Dreadnode Offensive AI Conference" rel="nofollow" href="https://www.offensiveaicon.com/">Dreadnode Offensive AI Conference</a></li><li><a title="LABScon Call for Papers" rel="nofollow" href="https://www.labscon.io/cfp/">LABScon Call for Papers</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Mikko Hypponen talks drone warfare, APT naming schemes</title>
  <link>http://securityconversations.fireside.fm/mikko-hypponen-talks-drone-warfare-apt-naming</link>
  <guid isPermaLink="false">bb8df579-ce5b-4644-9e58-c03a46a5b736</guid>
  <pubDate>Fri, 06 Jun 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/bb8df579-ce5b-4644-9e58-c03a46a5b736.mp3" length="72656095" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 49: Cybersecurity veteran Mikko Hypponen joins the show to discuss the fast-changing life and times on NATO’s newest frontline, how Ukraine’s long-range “Spiderweb” drone swarms punched holes in Russian air bases, the cyber connections to the escalating drone warfare, and the coming wave of autonomous “killer robots”.

Plus, news on Ukraine’s hack of bomber-maker Tupolev, the industry’s never-ending APT naming mess, iVerify’s newly disclosed iMessage zero-click bug, fresh Qualcomm GPU exploits still unpatched on Android devices, and Cellebrite’s purchase of Corellium.  

Cast: Costin Raiu, Ryan Naraine and Mikko Hypponen.

* Juan Andres Guerrero-Saade is out this week at Sleuthcon.</itunes:subtitle>
  <itunes:duration>1:29:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/b/bb8df579-ce5b-4644-9e58-c03a46a5b736/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 49:  Cybersecurity veteran Mikko Hypponen joins the show to discuss the fast-changing life and times on NATO’s newest frontline, how Ukraine’s long-range “Spiderweb” drone swarms punched holes in Russian air bases, the cyber connections to the escalating drone warfare, and the coming wave of autonomous “killer robots”.
Plus, news on Ukraine’s hack of bomber-maker Tupolev, the industry’s never-ending APT naming mess, iVerify’s newly disclosed iMessage zero-click bug, fresh Qualcomm GPU exploits still unpatched on Android devices, and Cellebrite’s purchase of Corellium.  
Cast: Ryan Naraine (https://twitter.com/ryanaraine), Costin Raiu (https://twitter.com/craiu) and Mikko Hypponen (https://x.com/mikko)
Juan Andres Guerrero-Saade is out this week at Sleuthcon. 
</description>
  <itunes:keywords>Russia, Ukraine, drones, autonomous warfare, Microsoft, CrowdStrike, Google, Mikko Hypponen,  Sensofusion, malware names</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 49</strong>:  Cybersecurity veteran Mikko Hypponen joins the show to discuss the fast-changing life and times on NATO’s newest frontline, how Ukraine’s long-range “Spiderweb” drone swarms punched holes in Russian air bases, the cyber connections to the escalating drone warfare, and the coming wave of autonomous “killer robots”.</p>

<p>Plus, news on Ukraine’s hack of bomber-maker Tupolev, the industry’s never-ending APT naming mess, iVerify’s newly disclosed iMessage zero-click bug, fresh Qualcomm GPU exploits still unpatched on Android devices, and Cellebrite’s purchase of Corellium.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://x.com/mikko" rel="nofollow">Mikko Hypponen</a></p>

<ul>
<li>Juan Andres Guerrero-Saade is out this week at Sleuthcon.</li>
</ul><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/12-laS3yVtXJhfnR4V-qtjbhUpYdZcTZM5PQ5fdWMPsM/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Mikko Hyppönen pivots from infosec to drones inspired by war" rel="nofollow" href="https://www.theregister.com/2025/06/04/mikko_hypponen_drone/">Mikko Hyppönen pivots from infosec to drones inspired by war</a></li><li><a title="Mikko Hypponen Leaves Anti-Malware Industry to Fight Against Drones" rel="nofollow" href="https://www.securityweek.com/mikko-hypponen-joins-anti-drone-company-sensofusion/">Mikko Hypponen Leaves Anti-Malware Industry to Fight Against Drones</a></li><li><a title="Anti-drone system | Sensofusion" rel="nofollow" href="https://sensofusion.com/">Anti-drone system | Sensofusion</a></li><li><a title="Ukraine&#39;s military intelligence claims cyberattack on Russian strategic bomber maker" rel="nofollow" href="https://therecord.media/ukraine-military-russia-strategic-bomber">Ukraine's military intelligence claims cyberattack on Russian strategic bomber maker</a></li><li><a title="How Microsoft names threat actors" rel="nofollow" href="https://learn.microsoft.com/en-us/unified-secops-platform/microsoft-threat-actor-naming">How Microsoft names threat actors</a></li><li><a title="CrowdStrike and Microsoft Unite to Deconflict Cyber Threat Attribution" rel="nofollow" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-and-microsoft-unite-to-deconflict-cyber-threat-attribution/">CrowdStrike and Microsoft Unite to Deconflict Cyber Threat Attribution</a></li><li><a title="Qualcomm GPU driver 0days (exploitation detected)" rel="nofollow" href="https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html">Qualcomm GPU driver 0days (exploitation detected)</a></li><li><a title="Chrome 0day exploited in the wild" rel="nofollow" href="https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html">Chrome 0day exploited in the wild</a></li><li><a title="iVerify documents &#39;Nickname&#39; iMessage exploitation" rel="nofollow" href="https://welcome.iverify.io/hubfs/iVerify-Nickname-Vulnerability-Report.pdf">iVerify documents 'Nickname' iMessage exploitation</a></li><li><a title="Cellebrite to acquire mobile testing firm Corellium" rel="nofollow" href="https://cyberscoop.com/cellebrite-correllium-acquisition-ios-android/">Cellebrite to acquire mobile testing firm Corellium</a></li><li><a title="Hacker Chris Wade reveals the story of his presidential pardon, US government collaboration" rel="nofollow" href="https://www.semafor.com/article/01/10/2025/citizen-wade-the-life-of-a-legendary-hacker-to-receive-a-rare-presidential-pardon">Hacker Chris Wade reveals the story of his presidential pardon, US government collaboration</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 49</strong>:  Cybersecurity veteran Mikko Hypponen joins the show to discuss the fast-changing life and times on NATO’s newest frontline, how Ukraine’s long-range “Spiderweb” drone swarms punched holes in Russian air bases, the cyber connections to the escalating drone warfare, and the coming wave of autonomous “killer robots”.</p>

<p>Plus, news on Ukraine’s hack of bomber-maker Tupolev, the industry’s never-ending APT naming mess, iVerify’s newly disclosed iMessage zero-click bug, fresh Qualcomm GPU exploits still unpatched on Android devices, and Cellebrite’s purchase of Corellium.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://x.com/mikko" rel="nofollow">Mikko Hypponen</a></p>

<ul>
<li>Juan Andres Guerrero-Saade is out this week at Sleuthcon.</li>
</ul><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/12-laS3yVtXJhfnR4V-qtjbhUpYdZcTZM5PQ5fdWMPsM/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Mikko Hyppönen pivots from infosec to drones inspired by war" rel="nofollow" href="https://www.theregister.com/2025/06/04/mikko_hypponen_drone/">Mikko Hyppönen pivots from infosec to drones inspired by war</a></li><li><a title="Mikko Hypponen Leaves Anti-Malware Industry to Fight Against Drones" rel="nofollow" href="https://www.securityweek.com/mikko-hypponen-joins-anti-drone-company-sensofusion/">Mikko Hypponen Leaves Anti-Malware Industry to Fight Against Drones</a></li><li><a title="Anti-drone system | Sensofusion" rel="nofollow" href="https://sensofusion.com/">Anti-drone system | Sensofusion</a></li><li><a title="Ukraine&#39;s military intelligence claims cyberattack on Russian strategic bomber maker" rel="nofollow" href="https://therecord.media/ukraine-military-russia-strategic-bomber">Ukraine's military intelligence claims cyberattack on Russian strategic bomber maker</a></li><li><a title="How Microsoft names threat actors" rel="nofollow" href="https://learn.microsoft.com/en-us/unified-secops-platform/microsoft-threat-actor-naming">How Microsoft names threat actors</a></li><li><a title="CrowdStrike and Microsoft Unite to Deconflict Cyber Threat Attribution" rel="nofollow" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-and-microsoft-unite-to-deconflict-cyber-threat-attribution/">CrowdStrike and Microsoft Unite to Deconflict Cyber Threat Attribution</a></li><li><a title="Qualcomm GPU driver 0days (exploitation detected)" rel="nofollow" href="https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html">Qualcomm GPU driver 0days (exploitation detected)</a></li><li><a title="Chrome 0day exploited in the wild" rel="nofollow" href="https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html">Chrome 0day exploited in the wild</a></li><li><a title="iVerify documents &#39;Nickname&#39; iMessage exploitation" rel="nofollow" href="https://welcome.iverify.io/hubfs/iVerify-Nickname-Vulnerability-Report.pdf">iVerify documents 'Nickname' iMessage exploitation</a></li><li><a title="Cellebrite to acquire mobile testing firm Corellium" rel="nofollow" href="https://cyberscoop.com/cellebrite-correllium-acquisition-ios-android/">Cellebrite to acquire mobile testing firm Corellium</a></li><li><a title="Hacker Chris Wade reveals the story of his presidential pardon, US government collaboration" rel="nofollow" href="https://www.semafor.com/article/01/10/2025/citizen-wade-the-life-of-a-legendary-hacker-to-receive-a-rare-presidential-pardon">Hacker Chris Wade reveals the story of his presidential pardon, US government collaboration</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>The dark hole of 'friendlies' and Western APTs</title>
  <link>http://securityconversations.fireside.fm/western-on-western-apt-research-dark-hole</link>
  <guid isPermaLink="false">f98d445d-0600-4a4d-b800-332b7653b71e</guid>
  <pubDate>Fri, 30 May 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/f98d445d-0600-4a4d-b800-332b7653b71e.mp3" length="103003832" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 48:  We unpack a Dutch intelligence agencies report on ‘Laundry Bear’ and Microsoft’s parallel ‘Void Blizzard’  write-up, finding major gaps and bemoaning the absence of IOCs. Plus, discussion on why threat-intel naming is so messy, how initial-access brokers are powering even nation-state break-ins, and whether customers (or vendors) are to blame for the confusion.

Plus, thoughts on an academic paper on the vanishing art of Western companies exposing Western (friendly) APT operations, debate whether stealth or self-censorship is to blame, and the long-tail effects on cyber paleontology.

We also dig into Sean Heelan’s proof that OpenAI’s new reasoning model can spot a Linux kernel 0-day and the implications for humans in the bug-hunting chain. 

Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>2:11:19</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/f98d445d-0600-4a4d-b800-332b7653b71e/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 48: We unpack a Dutch intelligence agencies report on ‘Laundry Bear’ and Microsoft’s parallel ‘Void Blizzard’  write-up, finding major gaps and bemoaning the absence of IOCs. Plus, discussion on why threat-intel naming is so messy, how initial-access brokers are powering even nation-state break-ins, and whether customers (or vendors) are to blame for the confusion.
Plus, thoughts on an academic paper on the vanishing art of Western companies exposing Western (friendly) APT operations, debate whether stealth or self-censorship is to blame, and the long-tail effects on cyber paleontology.
We also dig into Sean Heelan’s proof that OpenAI’s new reasoning model can spot a Linux kernel 0-day and the implications for humans in the bug-hunting chain. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Netherlands, China, Russia, Laundry Bear, Void Blizzard, Microsoft, Triangulation, Equation, Stuxnet, Symantec, Duqu, Sean Heelan</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 48</strong>: We unpack a Dutch intelligence agencies report on ‘Laundry Bear’ and Microsoft’s parallel ‘Void Blizzard’  write-up, finding major gaps and bemoaning the absence of IOCs. Plus, discussion on why threat-intel naming is so messy, how initial-access brokers are powering even nation-state break-ins, and whether customers (or vendors) are to blame for the confusion.</p>

<p>Plus, thoughts on an academic paper on the vanishing art of Western companies exposing Western (friendly) APT operations, debate whether stealth or self-censorship is to blame, and the long-tail effects on cyber paleontology.</p>

<p>We also dig into Sean Heelan’s proof that OpenAI’s new reasoning model can spot a Linux kernel 0-day and the implications for humans in the bug-hunting chain. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1dw-7Zl4toiXBQ8nEWseDz82pk2Ss3NEXAUPsJ7CnDcU/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Dutch intelligence agency outs &#39;Laundry Bear&#39; Russian APT" rel="nofollow" href="https://www.defensie.nl/actueel/nieuws/2025/05/27/onbekende-russische-groep-achter-hacks-nederlandse-doelen">Dutch intelligence agency outs 'Laundry Bear' Russian APT</a></li><li><a title="Russian gov hackers buying passwords from cybercriminals" rel="nofollow" href="https://www.securityweek.com/russian-government-hackers-caught-buying-passwords-from-cybercriminals/">Russian gov hackers buying passwords from cybercriminals</a></li><li><a title="Microsoft: Russian actor Void Blizzard targets critical sectors for espionage" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/">Microsoft: Russian actor Void Blizzard targets critical sectors for espionage</a></li><li><a title="Censys data on AyySSHush ASUS router botnet" rel="nofollow" href="https://censys.com/blog/tracking-ayysshush-a-newly-discovered-asus-router-botnet-campaign">Censys data on AyySSHush ASUS router botnet</a></li><li><a title="Czech Republic statement on Chinese hack" rel="nofollow" href="https://mzv.gov.cz/jnp/en/issues_and_press/press_releases/statement_by_the_government_of_the_czech.html">Czech Republic statement on Chinese hack</a></li><li><a title="Czech gov condemns Chinese hack on critical infrastructure" rel="nofollow" href="https://www.securityweek.com/czech-government-condemns-chinese-hack-on-critical-infrastructure/">Czech gov condemns Chinese hack on critical infrastructure</a></li><li><a title="NATO floats cybersecurity included in new spending target" rel="nofollow" href="https://archive.ph/M9EaX">NATO floats cybersecurity included in new spending target</a></li><li><a title="Mark your Google Calendar: APT41 innovative tactics" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics">Mark your Google Calendar: APT41 innovative tactics</a></li><li><a title="The rise of responsible behavior: Western commercial reports on Western cyber threat actors" rel="nofollow" href="https://www.tandfonline.com/doi/full/10.1080/13523260.2025.2498711">The rise of responsible behavior: Western commercial reports on Western cyber threat actors</a></li><li><a title="How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation" rel="nofollow" href="https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/">How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation</a></li><li><a title="ASUS Botnet Tracker" rel="nofollow" href="https://lookerstudio.google.com/u/0/reporting/15a9fcb0-7ca3-4ba0-b5fc-a98904f32224/page/tEnnC">ASUS Botnet Tracker</a></li><li><a title="CISA: Logging Made Easy (LME)" rel="nofollow" href="https://github.com/cisagov/LME">CISA: Logging Made Easy (LME)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 48</strong>: We unpack a Dutch intelligence agencies report on ‘Laundry Bear’ and Microsoft’s parallel ‘Void Blizzard’  write-up, finding major gaps and bemoaning the absence of IOCs. Plus, discussion on why threat-intel naming is so messy, how initial-access brokers are powering even nation-state break-ins, and whether customers (or vendors) are to blame for the confusion.</p>

<p>Plus, thoughts on an academic paper on the vanishing art of Western companies exposing Western (friendly) APT operations, debate whether stealth or self-censorship is to blame, and the long-tail effects on cyber paleontology.</p>

<p>We also dig into Sean Heelan’s proof that OpenAI’s new reasoning model can spot a Linux kernel 0-day and the implications for humans in the bug-hunting chain. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1dw-7Zl4toiXBQ8nEWseDz82pk2Ss3NEXAUPsJ7CnDcU/edit?tab=t.0">Transcript (unedited, AI-generated)</a></li><li><a title="Dutch intelligence agency outs &#39;Laundry Bear&#39; Russian APT" rel="nofollow" href="https://www.defensie.nl/actueel/nieuws/2025/05/27/onbekende-russische-groep-achter-hacks-nederlandse-doelen">Dutch intelligence agency outs 'Laundry Bear' Russian APT</a></li><li><a title="Russian gov hackers buying passwords from cybercriminals" rel="nofollow" href="https://www.securityweek.com/russian-government-hackers-caught-buying-passwords-from-cybercriminals/">Russian gov hackers buying passwords from cybercriminals</a></li><li><a title="Microsoft: Russian actor Void Blizzard targets critical sectors for espionage" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/">Microsoft: Russian actor Void Blizzard targets critical sectors for espionage</a></li><li><a title="Censys data on AyySSHush ASUS router botnet" rel="nofollow" href="https://censys.com/blog/tracking-ayysshush-a-newly-discovered-asus-router-botnet-campaign">Censys data on AyySSHush ASUS router botnet</a></li><li><a title="Czech Republic statement on Chinese hack" rel="nofollow" href="https://mzv.gov.cz/jnp/en/issues_and_press/press_releases/statement_by_the_government_of_the_czech.html">Czech Republic statement on Chinese hack</a></li><li><a title="Czech gov condemns Chinese hack on critical infrastructure" rel="nofollow" href="https://www.securityweek.com/czech-government-condemns-chinese-hack-on-critical-infrastructure/">Czech gov condemns Chinese hack on critical infrastructure</a></li><li><a title="NATO floats cybersecurity included in new spending target" rel="nofollow" href="https://archive.ph/M9EaX">NATO floats cybersecurity included in new spending target</a></li><li><a title="Mark your Google Calendar: APT41 innovative tactics" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics">Mark your Google Calendar: APT41 innovative tactics</a></li><li><a title="The rise of responsible behavior: Western commercial reports on Western cyber threat actors" rel="nofollow" href="https://www.tandfonline.com/doi/full/10.1080/13523260.2025.2498711">The rise of responsible behavior: Western commercial reports on Western cyber threat actors</a></li><li><a title="How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation" rel="nofollow" href="https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/">How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation</a></li><li><a title="ASUS Botnet Tracker" rel="nofollow" href="https://lookerstudio.google.com/u/0/reporting/15a9fcb0-7ca3-4ba0-b5fc-a98904f32224/page/tEnnC">ASUS Botnet Tracker</a></li><li><a title="CISA: Logging Made Easy (LME)" rel="nofollow" href="https://github.com/cisagov/LME">CISA: Logging Made Easy (LME)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Russia hacks Ukraine war supply lines, Signal blocks Windows screenshots, BadSuccessor vuln disclosure debate</title>
  <link>http://securityconversations.fireside.fm/russia-ukraine-badsuccessor-debate</link>
  <guid isPermaLink="false">c29a1c55-dabb-4e6c-849f-9ce8e38326ac</guid>
  <pubDate>Fri, 23 May 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/c29a1c55-dabb-4e6c-849f-9ce8e38326ac.mp3" length="117693808" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 47:  We unpack a multi-agency report on Russia’s APT28/Fancy Bear hacking and spying on Ukraine war supply lines, CISA’s sloppy YARA rules riddled with false positives, the ethics of full-disclosure after Akamai dropped Windows Server “BadSuccessor” exploit details, and Sekoia’s discovery of thousands of hijacked edge devices repurposed as honeypots.

The back half veers into Microsoft’s resurrected Windows Recall, Signal’s new screenshot-blocking countermeasure, Japan’s fresh legal mandate for pre-emptive cyber strikes, and why appliance vendors like Ivanti keep landing in the headlines. 

Along the way you get hot takes on techno-feudalism, Johnny Ive’s rumored AI gadget, and a lively debate over whether publishing exploit code ever helps defenders.  

Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>2:30:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/c/c29a1c55-dabb-4e6c-849f-9ce8e38326ac/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 47: We unpack a multi-agency report on Russia’s APT28/Fancy Bear hacking and spying on Ukraine war supply lines, CISA’s sloppy YARA rules riddled with false positives, the ethics of full-disclosure after Akamai dropped Windows Server “BadSuccessor” exploit details, and Sekoia’s discovery of thousands of hijacked edge devices repurposed as honeypots.
The back half veers into Microsoft’s resurrected Windows Recall, Signal’s new screenshot-blocking countermeasure, Japan’s fresh legal mandate for pre-emptive cyber strikes, and why appliance vendors like Ivanti keep landing in the headlines. 
Along the way you get hot takes on techno-feudalism, Johnny Ive’s rumored AI gadget, and a lively debate over whether publishing exploit code ever helps defenders.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Russia, China, Ukraine, GRU, Fancy Bear, Sofacy, APT28, Akamai, Microsoft, responsible disclosure, Signal, Windows Recall, NSO, Japan, OpenAI, Privacy</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 47</strong>: We unpack a multi-agency report on Russia’s APT28/Fancy Bear hacking and spying on Ukraine war supply lines, CISA’s sloppy YARA rules riddled with false positives, the ethics of full-disclosure after Akamai dropped Windows Server “BadSuccessor” exploit details, and Sekoia’s discovery of thousands of hijacked edge devices repurposed as honeypots.</p>

<p>The back half veers into Microsoft’s resurrected Windows Recall, Signal’s new screenshot-blocking countermeasure, Japan’s fresh legal mandate for pre-emptive cyber strikes, and why appliance vendors like Ivanti keep landing in the headlines. </p>

<p>Along the way you get hot takes on techno-feudalism, Johnny Ive’s rumored AI gadget, and a lively debate over whether publishing exploit code ever helps defenders.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1LS6j5WB33HBmDELA1HTO9VWQaq-xtEmsdZdRvbrxBIE/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Russian hackers hitting logistics companies supplying Ukraine" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a">Russian hackers hitting logistics companies supplying Ukraine</a></li><li><a title="CISA says Russian hackers targeting Ukraine war supply lines" rel="nofollow" href="https://www.securityweek.com/cisa-says-russian-hackers-targeting-western-supply-lines-to-ukraine/">CISA says Russian hackers targeting Ukraine war supply lines</a></li><li><a title="ViciousTrap: Turning edge devices into honeypots" rel="nofollow" href="https://blog.sekoia.io/vicioustrap-infiltrate-control-lure-turning-edge-devices-into-honeypots-en-masse/">ViciousTrap: Turning edge devices into honeypots</a></li><li><a title="BadSuccessor: Abusing dMSA to escalate privileges in Active Directory" rel="nofollow" href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory">BadSuccessor: Abusing dMSA to escalate privileges in Active Directory</a></li><li><a title="Signal adds anti-screenshot to thwart Windows Recall" rel="nofollow" href="https://signal.org/blog/signal-doesnt-recall/">Signal adds anti-screenshot to thwart Windows Recall</a></li><li><a title="Controversial Windows Recall gets security makeover" rel="nofollow" href="https://www.securityweek.com/microsofts-controversial-recall-returns-with-proof-of-presence-encryption-data-isolation-opt-in-model/">Controversial Windows Recall gets security makeover</a></li><li><a title="Microsoft&#39;s International Criminal Court blockade" rel="nofollow" href="https://www.techzine.eu/news/privacy-compliance/131536/microsofts-icc-blockade-digital-dependence-comes-at-a-cost/">Microsoft's International Criminal Court blockade</a></li><li><a title="Japan enacts active cyberdefense law" rel="nofollow" href="https://www.japantimes.co.jp/news/2025/05/16/japan/politics/cyber-bill-enactment/">Japan enacts active cyberdefense law</a></li><li><a title="UAE recruiting US personnel Displaced by DOGE" rel="nofollow" href="https://www.zetter-zeroday.com/uae-recruiting-us-personnel-displaced-by-doge-to-work-on-ai-for-its-military/">UAE recruiting US personnel Displaced by DOGE</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 47</strong>: We unpack a multi-agency report on Russia’s APT28/Fancy Bear hacking and spying on Ukraine war supply lines, CISA’s sloppy YARA rules riddled with false positives, the ethics of full-disclosure after Akamai dropped Windows Server “BadSuccessor” exploit details, and Sekoia’s discovery of thousands of hijacked edge devices repurposed as honeypots.</p>

<p>The back half veers into Microsoft’s resurrected Windows Recall, Signal’s new screenshot-blocking countermeasure, Japan’s fresh legal mandate for pre-emptive cyber strikes, and why appliance vendors like Ivanti keep landing in the headlines. </p>

<p>Along the way you get hot takes on techno-feudalism, Johnny Ive’s rumored AI gadget, and a lively debate over whether publishing exploit code ever helps defenders.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1LS6j5WB33HBmDELA1HTO9VWQaq-xtEmsdZdRvbrxBIE/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Russian hackers hitting logistics companies supplying Ukraine" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a">Russian hackers hitting logistics companies supplying Ukraine</a></li><li><a title="CISA says Russian hackers targeting Ukraine war supply lines" rel="nofollow" href="https://www.securityweek.com/cisa-says-russian-hackers-targeting-western-supply-lines-to-ukraine/">CISA says Russian hackers targeting Ukraine war supply lines</a></li><li><a title="ViciousTrap: Turning edge devices into honeypots" rel="nofollow" href="https://blog.sekoia.io/vicioustrap-infiltrate-control-lure-turning-edge-devices-into-honeypots-en-masse/">ViciousTrap: Turning edge devices into honeypots</a></li><li><a title="BadSuccessor: Abusing dMSA to escalate privileges in Active Directory" rel="nofollow" href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory">BadSuccessor: Abusing dMSA to escalate privileges in Active Directory</a></li><li><a title="Signal adds anti-screenshot to thwart Windows Recall" rel="nofollow" href="https://signal.org/blog/signal-doesnt-recall/">Signal adds anti-screenshot to thwart Windows Recall</a></li><li><a title="Controversial Windows Recall gets security makeover" rel="nofollow" href="https://www.securityweek.com/microsofts-controversial-recall-returns-with-proof-of-presence-encryption-data-isolation-opt-in-model/">Controversial Windows Recall gets security makeover</a></li><li><a title="Microsoft&#39;s International Criminal Court blockade" rel="nofollow" href="https://www.techzine.eu/news/privacy-compliance/131536/microsofts-icc-blockade-digital-dependence-comes-at-a-cost/">Microsoft's International Criminal Court blockade</a></li><li><a title="Japan enacts active cyberdefense law" rel="nofollow" href="https://www.japantimes.co.jp/news/2025/05/16/japan/politics/cyber-bill-enactment/">Japan enacts active cyberdefense law</a></li><li><a title="UAE recruiting US personnel Displaced by DOGE" rel="nofollow" href="https://www.zetter-zeroday.com/uae-recruiting-us-personnel-displaced-by-doge-to-work-on-ai-for-its-military/">UAE recruiting US personnel Displaced by DOGE</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>A Coinbase breach with bribes, rogue contractors and a $20M ransom demand</title>
  <link>http://securityconversations.fireside.fm/coinbase-breach-ivanti-zero-days-android-intrusion-logging</link>
  <guid isPermaLink="false">e41fa5a7-38a9-4b9f-ab7a-ad6f9d00c2ad</guid>
  <pubDate>Fri, 16 May 2025 11:15:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e41fa5a7-38a9-4b9f-ab7a-ad6f9d00c2ad.mp3" length="101815632" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 46: We dig into a Coinbase breach headlined by bribes, rogue contractors and a $20 million ransom demands. Plus, (another!) batch of Ivanti and Microsoft zero-days being exploited in the wild, a new 'Intrusion Logging' feature coming to Android, Apple's iOS 18.5 patches, and the EU announcing its own vulnerability database and software vendor secure-coding pledge.

Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>2:23:34</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e41fa5a7-38a9-4b9f-ab7a-ad6f9d00c2ad/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 46:  We dig into a Coinbase breach headlined by bribes, rogue contractors and a $20 million ransom demand. Plus, (another!) batch of Ivanti and Microsoft zero-days being exploited in the wild, a new 'Intrusion Logging' feature coming to Android, Apple's iOS 18.5 patches, and the EU announcing its own vulnerability database and software vendor secure-coding pledge.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>Coinbase, ransomware, Ivanti, Fortinet, Sonicwall, zero-day, Microsoft, Intrusion Logging, Android, iOS, ENISA</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 46</strong>:  We dig into a Coinbase breach headlined by bribes, rogue contractors and a $20 million ransom demand. Plus, (another!) batch of Ivanti and Microsoft zero-days being exploited in the wild, a new &#39;Intrusion Logging&#39; feature coming to Android, Apple&#39;s iOS 18.5 patches, and the EU announcing its own vulnerability database and software vendor secure-coding pledge.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/18lG0HnPcDS4zsR7aVdhv6q5qnHBDF7wsbCkEuMU8iDc/edit?tab=t.0#heading=h.xoy008k76n3z">Transcript (unedited, AI-generated)</a></li><li><a title="Coinbase on $20m ransom demand" rel="nofollow" href="https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists">Coinbase on $20m ransom demand</a></li><li><a title="SEC filing on Coinbase breach" rel="nofollow" href="https://www.sec.gov/Archives/edgar/data/1679788/000167978825000094/coin-20250514.htm?7194ef805fa2d04b0f7e8c9521f97343">SEC filing on Coinbase breach</a></li><li><a title="Coinbase Rogue Contractors Bribed to Leak Customer Data" rel="nofollow" href="https://www.securityweek.com/coinbase-rejects-20m-ransom-after-rogue-contractors-bribed-to-leak-customer-data/">Coinbase Rogue Contractors Bribed to Leak Customer Data</a></li><li><a title="Ivanti 0day exploit chain (CVE-2025-4427 and CVE-2025-4428)" rel="nofollow" href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&amp;_gl=1*nrofxr*_gcl_au*MjQ3MzY1MzY5LjE3NDcxOTkyODY">Ivanti 0day exploit chain (CVE-2025-4427 and CVE-2025-4428)</a></li><li><a title="Watchtowr blog on new Ivanti 0days" rel="nofollow" href="https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/">Watchtowr blog on new Ivanti 0days</a></li><li><a title="CISA Known Exploited Vulnerabilities (KEV)" rel="nofollow" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities (KEV)</a></li><li><a title="&#39;Advanced Protection&#39; comes to Android 16" rel="nofollow" href="https://security.googleblog.com/2025/05/advanced-protection-mobile-devices.html?m=1">'Advanced Protection' comes to Android 16</a></li><li><a title="Europe launches it own vulnerability database" rel="nofollow" href="https://www.enisa.europa.eu/news/consult-the-european-vulnerability-database-to-enhance-your-digital-security">Europe launches it own vulnerability database</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 46</strong>:  We dig into a Coinbase breach headlined by bribes, rogue contractors and a $20 million ransom demand. Plus, (another!) batch of Ivanti and Microsoft zero-days being exploited in the wild, a new &#39;Intrusion Logging&#39; feature coming to Android, Apple&#39;s iOS 18.5 patches, and the EU announcing its own vulnerability database and software vendor secure-coding pledge.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/18lG0HnPcDS4zsR7aVdhv6q5qnHBDF7wsbCkEuMU8iDc/edit?tab=t.0#heading=h.xoy008k76n3z">Transcript (unedited, AI-generated)</a></li><li><a title="Coinbase on $20m ransom demand" rel="nofollow" href="https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists">Coinbase on $20m ransom demand</a></li><li><a title="SEC filing on Coinbase breach" rel="nofollow" href="https://www.sec.gov/Archives/edgar/data/1679788/000167978825000094/coin-20250514.htm?7194ef805fa2d04b0f7e8c9521f97343">SEC filing on Coinbase breach</a></li><li><a title="Coinbase Rogue Contractors Bribed to Leak Customer Data" rel="nofollow" href="https://www.securityweek.com/coinbase-rejects-20m-ransom-after-rogue-contractors-bribed-to-leak-customer-data/">Coinbase Rogue Contractors Bribed to Leak Customer Data</a></li><li><a title="Ivanti 0day exploit chain (CVE-2025-4427 and CVE-2025-4428)" rel="nofollow" href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&amp;_gl=1*nrofxr*_gcl_au*MjQ3MzY1MzY5LjE3NDcxOTkyODY">Ivanti 0day exploit chain (CVE-2025-4427 and CVE-2025-4428)</a></li><li><a title="Watchtowr blog on new Ivanti 0days" rel="nofollow" href="https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/">Watchtowr blog on new Ivanti 0days</a></li><li><a title="CISA Known Exploited Vulnerabilities (KEV)" rel="nofollow" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities (KEV)</a></li><li><a title="&#39;Advanced Protection&#39; comes to Android 16" rel="nofollow" href="https://security.googleblog.com/2025/05/advanced-protection-mobile-devices.html?m=1">'Advanced Protection' comes to Android 16</a></li><li><a title="Europe launches it own vulnerability database" rel="nofollow" href="https://www.enisa.europa.eu/news/consult-the-european-vulnerability-database-to-enhance-your-digital-security">Europe launches it own vulnerability database</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>JAGS keynote: The intricacies of wartime cyber threat intelligence </title>
  <link>http://securityconversations.fireside.fm/wartime-cyber-threat-intel-counterthreats-keynote</link>
  <guid isPermaLink="false">e86c0a26-27c7-44e7-a6fd-1d85e4e5b3d2</guid>
  <pubDate>Fri, 09 May 2025 09:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e86c0a26-27c7-44e7-a6fd-1d85e4e5b3d2.mp3" length="26254337" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 45: (The buddies are trapped in timezone hell with cross-continent travel this week). 

In the meantime, absorb this keynote presented by Juan Andres Guerrero-Saade (JAG-S) at CounterThreats 2023. It's a frank discussion on the role of cyber threat intelligence (CTI) during wartime and its importance in bridging information gaps between adversaries. Includes talk on the ethical challenges in CTI, questioning the impact of intelligence-sharing and how cyber operations affect real-world conflicts. He pointed to Ukraine and Israel as examples where CTI plays a critical, yet complicated, role. His message: cybersecurity pros need to be aware of the real-world consequences of their work and the ethical responsibility that comes with it.

Acknowledgment: Credit for the audio goes to CyberThreat 2023, SANS Institute, NCSC, and SentinelOne.

Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>31:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e86c0a26-27c7-44e7-a6fd-1d85e4e5b3d2/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 45: (The buddies are trapped in timezone hell with cross-continent travel this week). 
In the meantime, absorb this keynote presented by Juan Andres Guerrero-Saade (JAG-S) at CounterThreats 2023. It's a frank discussion on the role of cyber threat intelligence (CTI) during wartime and its importance in bridging information gaps between adversaries. Includes talk on the ethical challenges in CTI, questioning the impact of intelligence-sharing and how cyber operations affect real-world conflicts. He pointed to Ukraine and Israel as examples where CTI plays a critical, yet complicated, role. His message: cybersecurity pros need to be aware of the real-world consequences of their work and the ethical responsibility that comes with it.
Acknowledgment: Credit for the audio goes to CyberThreat 2023, SANS Institute, NCSC, and SentinelOne.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>CTI, threat intelligence, wartime, Ukraine, Israel, cyberwar, cyber offense, NCSC, CyberThreat, SANS Institute, SentinelOne</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 45</strong>: (The buddies are trapped in timezone hell with cross-continent travel this week). </p>

<p>In the meantime, absorb this keynote presented by Juan Andres Guerrero-Saade (JAG-S) at CounterThreats 2023. It&#39;s a frank discussion on the role of cyber threat intelligence (CTI) during wartime and its importance in bridging information gaps between adversaries. Includes talk on the ethical challenges in CTI, questioning the impact of intelligence-sharing and how cyber operations affect real-world conflicts. He pointed to Ukraine and Israel as examples where CTI plays a critical, yet complicated, role. His message: cybersecurity pros need to be aware of the real-world consequences of their work and the ethical responsibility that comes with it.</p>

<p><em>Acknowledgment: Credit for the audio goes to CyberThreat 2023, SANS Institute, NCSC, and SentinelOne.</em></p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Keynote transcript" rel="nofollow" href="https://docs.google.com/document/d/1ZBQuHSF3sAwT9acg8ng4AtCw04jPLFOwkuZjS1nnpbI/edit?tab=t.0#heading=h.pi42p8chtkss">Keynote transcript</a></li><li><a title="The ethics and perils of APT research" rel="nofollow" href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2017/10/20080228/Guerrero-Saade-VB2015.pdf">The ethics and perils of APT research</a></li><li><a title="Recommended Talks" rel="nofollow" href="https://www.epicturla.com/recommended-material">Recommended Talks</a></li><li><a title="The Lost APT Reports" rel="nofollow" href="https://www.epicturla.com/blog">The Lost APT Reports</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 45</strong>: (The buddies are trapped in timezone hell with cross-continent travel this week). </p>

<p>In the meantime, absorb this keynote presented by Juan Andres Guerrero-Saade (JAG-S) at CounterThreats 2023. It&#39;s a frank discussion on the role of cyber threat intelligence (CTI) during wartime and its importance in bridging information gaps between adversaries. Includes talk on the ethical challenges in CTI, questioning the impact of intelligence-sharing and how cyber operations affect real-world conflicts. He pointed to Ukraine and Israel as examples where CTI plays a critical, yet complicated, role. His message: cybersecurity pros need to be aware of the real-world consequences of their work and the ethical responsibility that comes with it.</p>

<p><em>Acknowledgment: Credit for the audio goes to CyberThreat 2023, SANS Institute, NCSC, and SentinelOne.</em></p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Keynote transcript" rel="nofollow" href="https://docs.google.com/document/d/1ZBQuHSF3sAwT9acg8ng4AtCw04jPLFOwkuZjS1nnpbI/edit?tab=t.0#heading=h.pi42p8chtkss">Keynote transcript</a></li><li><a title="The ethics and perils of APT research" rel="nofollow" href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2017/10/20080228/Guerrero-Saade-VB2015.pdf">The ethics and perils of APT research</a></li><li><a title="Recommended Talks" rel="nofollow" href="https://www.epicturla.com/recommended-material">Recommended Talks</a></li><li><a title="The Lost APT Reports" rel="nofollow" href="https://www.epicturla.com/blog">The Lost APT Reports</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Signalgate redux, OpenAI's Aardvark, normalizing cyber offense</title>
  <link>http://securityconversations.fireside.fm/signal-archiving-open-ai-aardvark-hacking-back-</link>
  <guid isPermaLink="false">6b6d31fa-9f59-4c43-81ac-cafcf58c799e</guid>
  <pubDate>Sat, 03 May 2025 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/6b6d31fa-9f59-4c43-81ac-cafcf58c799e.mp3" length="123764937" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 44: We unpack news that US government officials are using an obscure app to archive Signal messages, OpenAI’s new “Aardvark” code-evaluation and reasoning model and leapfrog implications, NSC cyber lead Alexei Bulazel on normalizing US offensive operations, and JP Morgan Chase CISO’s warning to software vendors.
Plus, fresh SentinelOne threat-intel notes, France’s attribution of GRU activity and a head-scratching $330 million Bitcoin heist.

Cast: Costin Raiu, Juan Andres Guerrero-Saade and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>2:38:40</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/6b6d31fa-9f59-4c43-81ac-cafcf58c799e/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 44:  We unpack news that US government officials are using an obscure app to archive Signal messages, OpenAI’s new “Aardvark” code-evaluation and reasoning model and leapfrog implications, NSC cyber lead Alexei Bulazel on normalizing US offensive operations, and JP Morgan Chase CISO’s warning to software vendors.
Plus, fresh SentinelOne threat-intel notes, France’s attribution of GRU activity and a head-scratching $330 million Bitcoin heist.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs),  Ryan Naraine (https://twitter.com/ryanaraine) and    Costin Raiu (https://twitter.com/craiu). 
</description>
  <itunes:keywords>OpenAI, Aardvark, RSA Conference, JP Morgan Chase, Apple, North Korea, Russia, zero-day, Google, Romania, CISA, crypto, Bitcoin</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 44</strong>:  We unpack news that US government officials are using an obscure app to archive Signal messages, OpenAI’s new “Aardvark” code-evaluation and reasoning model and leapfrog implications, NSC cyber lead Alexei Bulazel on normalizing US offensive operations, and JP Morgan Chase CISO’s warning to software vendors.</p>

<p>Plus, fresh SentinelOne threat-intel notes, France’s attribution of GRU activity and a head-scratching $330 million Bitcoin heist.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1K6oD3WVGNtnQZQy-1hBW3qoRNgVo1UrNKy2dktwL7RA/edit?tab=t.0#heading=h.iyimfr9zwj2b">Transcript (unedited, AI-generated)</a></li><li><a title="US government using obscure app to archive Signal messages" rel="nofollow" href="https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/">US government using obscure app to archive Signal messages</a></li><li><a title="Reuters photo of Mike Waltz phone" rel="nofollow" href="https://www.reutersconnect.com/item/us-national-security-advisor-mike-waltz-attends-a-cabinet-meeting-held-by-president-trump-at-the-white-house-in-washington/dGFnOnJldXRlcnMuY29tLDIwMjU6bmV3c21sX1JDMkg4RUFEOEtGRw%3D%3D?ref=404media.co">Reuters photo of Mike Waltz phone</a></li><li><a title="US revokes Romania visa waiver program" rel="nofollow" href="https://www.dhs.gov/news/2025/05/02/dhs-announces-rescission-romanias-designation-visa-waiver-program">US revokes Romania visa waiver program</a></li><li><a title="OpenSSH bug found by OpenAI &#39;Aardvark&#39;" rel="nofollow" href="https://github.com/openssh/openssh-portable/commit/c991273c18afc490313a9f282383eaf59d9c13b9">OpenSSH bug found by OpenAI 'Aardvark'</a></li><li><a title="JP Morgan Chase CISO: An open letter to third-party suppliers" rel="nofollow" href="https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliers">JP Morgan Chase CISO: An open letter to third-party suppliers</a></li><li><a title="JPMorgan Chase CISO Fires Warning Shot Ahead of RSA Conference" rel="nofollow" href="https://www.securityweek.com/jpmorgan-chase-ciso-fires-warning-shot-ahead-of-rsa-conference/">JPMorgan Chase CISO Fires Warning Shot Ahead of RSA Conference</a></li><li><a title="SentinelOne LABS on DPRK threat actor targeting" rel="nofollow" href="https://www.sentinelone.com/labs/top-tier-target-what-it-takes-to-defend-a-cybersecurity-company-from-todays-adversaries/">SentinelOne LABS on DPRK threat actor targeting</a></li><li><a title="Alexei Bulazel comments at RSA conference" rel="nofollow" href="https://cyberscoop.com/alexei-bulazel-white-house-national-security-councial-destigmatize-offensive-cyber-rsac-2025/">Alexei Bulazel comments at RSA conference</a></li><li><a title="Google report on 0day exploitation in 2024" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends">Google report on 0day exploitation in 2024</a></li><li><a title="Apple notifies new victims of spyware attacks across the world" rel="nofollow" href="https://techcrunch.com/2025/04/30/apple-notifies-new-victims-of-spyware-attacks-across-the-world/">Apple notifies new victims of spyware attacks across the world</a></li><li><a title="France attributes cyberattacks to Russia&#39;s military intelligence" rel="nofollow" href="https://www.diplomatie.gouv.fr/fr/dossiers-pays/russie/evenements/evenements-de-l-annee-2025/article/russie-attribution-de-cyberattaques-contre-la-france-au-service-de">France attributes cyberattacks to Russia's military intelligence</a></li><li><a title="RT-Solar on ViPNet backdoor from 2021" rel="nofollow" href="https://rt-solar.ru/solar-4rays/blog/5487/">RT-Solar on ViPNet backdoor from 2021</a></li><li><a title="Kaspersky: Sophisticated backdoor mimicking secure networking software updates" rel="nofollow" href="https://securelist.com/new-backdoor-mimics-security-software-update/116246/">Kaspersky: Sophisticated backdoor mimicking secure networking software updates</a></li><li><a title="$330m Bitcoin heist" rel="nofollow" href="https://x.com/zachxbt/status/1916756932763046273?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">$330m Bitcoin heist</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 44</strong>:  We unpack news that US government officials are using an obscure app to archive Signal messages, OpenAI’s new “Aardvark” code-evaluation and reasoning model and leapfrog implications, NSC cyber lead Alexei Bulazel on normalizing US offensive operations, and JP Morgan Chase CISO’s warning to software vendors.</p>

<p>Plus, fresh SentinelOne threat-intel notes, France’s attribution of GRU activity and a head-scratching $330 million Bitcoin heist.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>,  <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> and    <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1K6oD3WVGNtnQZQy-1hBW3qoRNgVo1UrNKy2dktwL7RA/edit?tab=t.0#heading=h.iyimfr9zwj2b">Transcript (unedited, AI-generated)</a></li><li><a title="US government using obscure app to archive Signal messages" rel="nofollow" href="https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/">US government using obscure app to archive Signal messages</a></li><li><a title="Reuters photo of Mike Waltz phone" rel="nofollow" href="https://www.reutersconnect.com/item/us-national-security-advisor-mike-waltz-attends-a-cabinet-meeting-held-by-president-trump-at-the-white-house-in-washington/dGFnOnJldXRlcnMuY29tLDIwMjU6bmV3c21sX1JDMkg4RUFEOEtGRw%3D%3D?ref=404media.co">Reuters photo of Mike Waltz phone</a></li><li><a title="US revokes Romania visa waiver program" rel="nofollow" href="https://www.dhs.gov/news/2025/05/02/dhs-announces-rescission-romanias-designation-visa-waiver-program">US revokes Romania visa waiver program</a></li><li><a title="OpenSSH bug found by OpenAI &#39;Aardvark&#39;" rel="nofollow" href="https://github.com/openssh/openssh-portable/commit/c991273c18afc490313a9f282383eaf59d9c13b9">OpenSSH bug found by OpenAI 'Aardvark'</a></li><li><a title="JP Morgan Chase CISO: An open letter to third-party suppliers" rel="nofollow" href="https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliers">JP Morgan Chase CISO: An open letter to third-party suppliers</a></li><li><a title="JPMorgan Chase CISO Fires Warning Shot Ahead of RSA Conference" rel="nofollow" href="https://www.securityweek.com/jpmorgan-chase-ciso-fires-warning-shot-ahead-of-rsa-conference/">JPMorgan Chase CISO Fires Warning Shot Ahead of RSA Conference</a></li><li><a title="SentinelOne LABS on DPRK threat actor targeting" rel="nofollow" href="https://www.sentinelone.com/labs/top-tier-target-what-it-takes-to-defend-a-cybersecurity-company-from-todays-adversaries/">SentinelOne LABS on DPRK threat actor targeting</a></li><li><a title="Alexei Bulazel comments at RSA conference" rel="nofollow" href="https://cyberscoop.com/alexei-bulazel-white-house-national-security-councial-destigmatize-offensive-cyber-rsac-2025/">Alexei Bulazel comments at RSA conference</a></li><li><a title="Google report on 0day exploitation in 2024" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends">Google report on 0day exploitation in 2024</a></li><li><a title="Apple notifies new victims of spyware attacks across the world" rel="nofollow" href="https://techcrunch.com/2025/04/30/apple-notifies-new-victims-of-spyware-attacks-across-the-world/">Apple notifies new victims of spyware attacks across the world</a></li><li><a title="France attributes cyberattacks to Russia&#39;s military intelligence" rel="nofollow" href="https://www.diplomatie.gouv.fr/fr/dossiers-pays/russie/evenements/evenements-de-l-annee-2025/article/russie-attribution-de-cyberattaques-contre-la-france-au-service-de">France attributes cyberattacks to Russia's military intelligence</a></li><li><a title="RT-Solar on ViPNet backdoor from 2021" rel="nofollow" href="https://rt-solar.ru/solar-4rays/blog/5487/">RT-Solar on ViPNet backdoor from 2021</a></li><li><a title="Kaspersky: Sophisticated backdoor mimicking secure networking software updates" rel="nofollow" href="https://securelist.com/new-backdoor-mimics-security-software-update/116246/">Kaspersky: Sophisticated backdoor mimicking secure networking software updates</a></li><li><a title="$330m Bitcoin heist" rel="nofollow" href="https://x.com/zachxbt/status/1916756932763046273?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">$330m Bitcoin heist</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Thomas Rid joins the show: AI consciousness, TP-Link's China connection, trust in hardware security</title>
  <link>http://securityconversations.fireside.fm/tom-rid-joins-the-show</link>
  <guid isPermaLink="false">a43a154a-06cd-4cf3-97fa-3945dc08f544</guid>
  <pubDate>Fri, 25 Apr 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/a43a154a-06cd-4cf3-97fa-3945dc08f544.mp3" length="77152373" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 43: Director of the Alperovitch Institute for Cybersecurity Studies Thomas Rid joins the show for a deep-dive into the philosophical and ethical considerations surrounding AI consciousness and anthropomorphism.  We dig into the multifaceted implications of AI technology, particularly focusing on data privacy, national security, and the philosophical questions surrounding AI consciousness and rights. 

Plus, TP-Link under US government investigation and the broader issues of consumer trust in hardware security, the need for regulation and inspectability of technology, and the struggles with patching network devices. 

Cast: Thomas Rid, Juan Andres Guerrero-Saade and Ryan Naraine.  

* Costin Raiu is away this week.</itunes:subtitle>
  <itunes:duration>1:33:42</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/a43a154a-06cd-4cf3-97fa-3945dc08f544/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 43:  Director of the Alperovitch Institute for Cybersecurity Studies Thomas Rid joins the show for a deep-dive into the philosophical and ethical considerations surrounding AI consciousness and anthropomorphism.  We dig into the multifaceted implications of AI technology, particularly focusing on data privacy, national security, and the philosophical questions surrounding AI consciousness and rights. 
Plus, TP-Link under US government investigation and the broader issues of consumer trust in hardware security, the need for regulation and inspectability of technology, and the struggles with patching network devices. 
Cast: Thomas Rid (https://sais.jhu.edu/users/trid2), Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) and Ryan Naraine (https://twitter.com/ryanaraine).   Costin Raiu (https://twitter.com/craiu) is away this week. 
</description>
  <itunes:keywords>China, NSA, attribution, Volt Typhoon, Apple iOS, zero-day, CVE, MITRE, CISA, Microsoft, Europe, Anthropic, TP-Link</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 43</strong>:  Director of the Alperovitch Institute for Cybersecurity Studies Thomas Rid joins the show for a deep-dive into the philosophical and ethical considerations surrounding AI consciousness and anthropomorphism.  We dig into the multifaceted implications of AI technology, particularly focusing on data privacy, national security, and the philosophical questions surrounding AI consciousness and rights. </p>

<p>Plus, TP-Link under US government investigation and the broader issues of consumer trust in hardware security, the need for regulation and inspectability of technology, and the struggles with patching network devices. </p>

<p><strong>Cast:</strong> <a href="https://sais.jhu.edu/users/trid2" rel="nofollow">Thomas Rid</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.   <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> is away this week.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NJq0S9X5LyFVv3-X9EpljGIOVsOszEGA82ZFHSfA428/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Anthropic: Exploring AI model welfare, consciousness" rel="nofollow" href="https://www.anthropic.com/research/exploring-model-welfare">Anthropic: Exploring AI model welfare, consciousness</a></li><li><a title="David Chalmers: Taking AI Welfare Seriously" rel="nofollow" href="https://arxiv.org/pdf/2411.00986">David Chalmers: Taking AI Welfare Seriously</a></li><li><a title="Sam Altman: AI privacy safeguards can’t be established before ‘problems emerge’" rel="nofollow" href="https://therecord.media/sam-altman-openai-privacy-safeguards">Sam Altman: AI privacy safeguards can’t be established before ‘problems emerge’</a></li><li><a title="TP-Link router pricing and China ties under US gov probe" rel="nofollow" href="https://www.techspot.com/news/107682-tp-link-router-pricing-china-ties-under-us.html">TP-Link router pricing and China ties under US gov probe</a></li><li><a title="Bloomberg: TP-Link’s US Future Hinges on Claimed Split From China" rel="nofollow" href="https://archive.ph/YWpQA">Bloomberg: TP-Link’s US Future Hinges on Claimed Split From China</a></li><li><a title="Verizon DBIR 2015 (full report)" rel="nofollow" href="https://www.verizon.com/business/resources/T2ff/reports/2025-dbir-data-breach-investigations-report.pdf">Verizon DBIR 2015 (full report)</a></li><li><a title="Mandiant M-Trends 2025 Report" rel="nofollow" href="https://services.google.com/fh/files/misc/m-trends-2025-en.pdf">Mandiant M-Trends 2025 Report</a></li><li><a title="FBI seeking tips about China&#39;s &#39;Salt Typhoon&#39; hackers" rel="nofollow" href="https://www.ic3.gov/PSA/2025/PSA250424-2">FBI seeking tips about China's 'Salt Typhoon' hackers</a></li><li><a title="North Korean Cryptocurrency Thieves Caught Hijacking Zoom ‘Remote Control’ Feature" rel="nofollow" href="https://www.securityweek.com/north-korean-cryptocurrency-thieves-caught-hijacking-zoom-remote-control-feature/">North Korean Cryptocurrency Thieves Caught Hijacking Zoom ‘Remote Control’ Feature</a></li><li><a title="Dan Geer on the realpolitik of cybersecurity" rel="nofollow" href="https://www.youtube.com/watch?v=nT-TGvYOBpI&amp;ab_channel=BlackHat">Dan Geer on the realpolitik of cybersecurity</a></li><li><a title="LABScon 2025 CFP is open" rel="nofollow" href="https://www.cvent.com/c/abstracts/fe3bffe0-6e1f-482d-9435-fb39af52138c">LABScon 2025 CFP is open</a></li><li><a title="Ransom War by Max Smeets" rel="nofollow" href="https://www.hurstpublishers.com/book/ransom-war/">Ransom War by Max Smeets</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 43</strong>:  Director of the Alperovitch Institute for Cybersecurity Studies Thomas Rid joins the show for a deep-dive into the philosophical and ethical considerations surrounding AI consciousness and anthropomorphism.  We dig into the multifaceted implications of AI technology, particularly focusing on data privacy, national security, and the philosophical questions surrounding AI consciousness and rights. </p>

<p>Plus, TP-Link under US government investigation and the broader issues of consumer trust in hardware security, the need for regulation and inspectability of technology, and the struggles with patching network devices. </p>

<p><strong>Cast:</strong> <a href="https://sais.jhu.edu/users/trid2" rel="nofollow">Thomas Rid</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.   <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> is away this week.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1NJq0S9X5LyFVv3-X9EpljGIOVsOszEGA82ZFHSfA428/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Anthropic: Exploring AI model welfare, consciousness" rel="nofollow" href="https://www.anthropic.com/research/exploring-model-welfare">Anthropic: Exploring AI model welfare, consciousness</a></li><li><a title="David Chalmers: Taking AI Welfare Seriously" rel="nofollow" href="https://arxiv.org/pdf/2411.00986">David Chalmers: Taking AI Welfare Seriously</a></li><li><a title="Sam Altman: AI privacy safeguards can’t be established before ‘problems emerge’" rel="nofollow" href="https://therecord.media/sam-altman-openai-privacy-safeguards">Sam Altman: AI privacy safeguards can’t be established before ‘problems emerge’</a></li><li><a title="TP-Link router pricing and China ties under US gov probe" rel="nofollow" href="https://www.techspot.com/news/107682-tp-link-router-pricing-china-ties-under-us.html">TP-Link router pricing and China ties under US gov probe</a></li><li><a title="Bloomberg: TP-Link’s US Future Hinges on Claimed Split From China" rel="nofollow" href="https://archive.ph/YWpQA">Bloomberg: TP-Link’s US Future Hinges on Claimed Split From China</a></li><li><a title="Verizon DBIR 2015 (full report)" rel="nofollow" href="https://www.verizon.com/business/resources/T2ff/reports/2025-dbir-data-breach-investigations-report.pdf">Verizon DBIR 2015 (full report)</a></li><li><a title="Mandiant M-Trends 2025 Report" rel="nofollow" href="https://services.google.com/fh/files/misc/m-trends-2025-en.pdf">Mandiant M-Trends 2025 Report</a></li><li><a title="FBI seeking tips about China&#39;s &#39;Salt Typhoon&#39; hackers" rel="nofollow" href="https://www.ic3.gov/PSA/2025/PSA250424-2">FBI seeking tips about China's 'Salt Typhoon' hackers</a></li><li><a title="North Korean Cryptocurrency Thieves Caught Hijacking Zoom ‘Remote Control’ Feature" rel="nofollow" href="https://www.securityweek.com/north-korean-cryptocurrency-thieves-caught-hijacking-zoom-remote-control-feature/">North Korean Cryptocurrency Thieves Caught Hijacking Zoom ‘Remote Control’ Feature</a></li><li><a title="Dan Geer on the realpolitik of cybersecurity" rel="nofollow" href="https://www.youtube.com/watch?v=nT-TGvYOBpI&amp;ab_channel=BlackHat">Dan Geer on the realpolitik of cybersecurity</a></li><li><a title="LABScon 2025 CFP is open" rel="nofollow" href="https://www.cvent.com/c/abstracts/fe3bffe0-6e1f-482d-9435-fb39af52138c">LABScon 2025 CFP is open</a></li><li><a title="Ransom War by Max Smeets" rel="nofollow" href="https://www.hurstpublishers.com/book/ransom-war/">Ransom War by Max Smeets</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>China doxxes NSA, CVE's funding crisis, Apple's zero-day troubles</title>
  <link>http://securityconversations.fireside.fm/china-doxxes-nsa-cisa-cve-apple-zero-days</link>
  <guid isPermaLink="false">4ef18f59-700b-4713-93c0-db500e43ed18</guid>
  <pubDate>Thu, 17 Apr 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/4ef18f59-700b-4713-93c0-db500e43ed18.mp3" length="82057286" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 42: We dig into news that China secretly fessed up to the Volt Typhoon hacks and followed up with claims that named NSA agents launched advanced cyberattacks against the Asian Winter Games.  Plus, the MITRE CVE funding crisis, new Apple 0days in the wild includes PAC bypass exploit, Microsoft Patch Tuesday zero-days.   

Plus, the effectiveness of Lockdown Mode, the rising costs of mobile exploits, Chris Krebs' exit from SentinelOne after a presidential executive order, and the value and effectiveness of security clearances.

Cast: Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:39:19</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/4ef18f59-700b-4713-93c0-db500e43ed18/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 42:  We dig into news that China secretly fessed up to the Volt Typhoon hacks and followed up with claims that named NSA agents launched advanced cyberattacks against the Asian Winter Games.  Plus, the MITRE CVE funding crisis, new Apple 0days in the wild includes PAC bypass exploit, Microsoft Patch Tuesday zero-days.   
Plus, the effectiveness of Lockdown Mode, the rising costs of mobile exploits, Chris Krebs' exit from SentinelOne after a presidential executive order, and the value and effectiveness of security clearances.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>China, NSA, attribution, Volt Typhoon, Apple iOS, zero-day, CVE, MITRE, CISA, Microsoft, Europe</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 42</strong>:  We dig into news that China secretly fessed up to the Volt Typhoon hacks and followed up with claims that named NSA agents launched advanced cyberattacks against the Asian Winter Games.  Plus, the MITRE CVE funding crisis, new Apple 0days in the wild includes PAC bypass exploit, Microsoft Patch Tuesday zero-days.   </p>

<p>Plus, the effectiveness of Lockdown Mode, the rising costs of mobile exploits, Chris Krebs&#39; exit from SentinelOne after a presidential executive order, and the value and effectiveness of security clearances.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1LM4EHnm8-uHKIur7iqOp3y4Z1wrItETvASD5IRnKJqo/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="China names alleged NSA cyberattack agents" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/chinas-harbin-says-us-launched-advanced-cyber-attacks-winter-games-2025-04-15/">China names alleged NSA cyberattack agents</a></li><li><a title="WSJ: In Secret Meeting, China Acknowledged Role in U.S. Infrastructure Hacks" rel="nofollow" href="https://archive.ph/yDvP3">WSJ: In Secret Meeting, China Acknowledged Role in U.S. Infrastructure Hacks</a></li><li><a title="Apple Quashes Two Zero-Days With iOS, MacOS Patches" rel="nofollow" href="https://www.securityweek.com/apple-pushes-ios-macos-patches-to-quash-two-zero-days/">Apple Quashes Two Zero-Days With iOS, MacOS Patches</a></li><li><a title="Apple bulletin - iOS 18.4.1 Security Vulnerabilities" rel="nofollow" href="https://support.apple.com/en-us/122282">Apple bulletin - iOS 18.4.1 Security Vulnerabilities</a></li><li><a title="Android zero-days documented" rel="nofollow" href="https://source.android.com/docs/security/bulletin/2025-04-01">Android zero-days documented</a></li><li><a title="MITRE CVE Program Gets Last-Hour Funding Reprieve" rel="nofollow" href="https://www.securityweek.com/mitre-cve-program-gets-last-hour-funding-reprieve/">MITRE CVE Program Gets Last-Hour Funding Reprieve</a></li><li><a title="NIST Still Struggling to Clear Vulnerability Submissions Backlog in NVD" rel="nofollow" href="https://www.securityweek.com/nist-still-struggling-to-clear-vulnerability-submissions-backlog-in-nvd/">NIST Still Struggling to Clear Vulnerability Submissions Backlog in NVD</a></li><li><a title="EU issues US-bound staff with burner phones to avoid espionage" rel="nofollow" href="https://archive.ph/VcBLY">EU issues US-bound staff with burner phones to avoid espionage</a></li><li><a title="Exploitation of CLFS zero-day leads to ransomware " rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/04/08/exploitation-of-clfs-zero-day-leads-to-ransomware-activity/">Exploitation of CLFS zero-day leads to ransomware </a></li><li><a title="Google announces Sec-Gemini v1 cybersecurity model" rel="nofollow" href="https://security.googleblog.com/2025/04/google-launches-sec-gemini-v1-new.html">Google announces Sec-Gemini v1 cybersecurity model</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 42</strong>:  We dig into news that China secretly fessed up to the Volt Typhoon hacks and followed up with claims that named NSA agents launched advanced cyberattacks against the Asian Winter Games.  Plus, the MITRE CVE funding crisis, new Apple 0days in the wild includes PAC bypass exploit, Microsoft Patch Tuesday zero-days.   </p>

<p>Plus, the effectiveness of Lockdown Mode, the rising costs of mobile exploits, Chris Krebs&#39; exit from SentinelOne after a presidential executive order, and the value and effectiveness of security clearances.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1LM4EHnm8-uHKIur7iqOp3y4Z1wrItETvASD5IRnKJqo/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="China names alleged NSA cyberattack agents" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/chinas-harbin-says-us-launched-advanced-cyber-attacks-winter-games-2025-04-15/">China names alleged NSA cyberattack agents</a></li><li><a title="WSJ: In Secret Meeting, China Acknowledged Role in U.S. Infrastructure Hacks" rel="nofollow" href="https://archive.ph/yDvP3">WSJ: In Secret Meeting, China Acknowledged Role in U.S. Infrastructure Hacks</a></li><li><a title="Apple Quashes Two Zero-Days With iOS, MacOS Patches" rel="nofollow" href="https://www.securityweek.com/apple-pushes-ios-macos-patches-to-quash-two-zero-days/">Apple Quashes Two Zero-Days With iOS, MacOS Patches</a></li><li><a title="Apple bulletin - iOS 18.4.1 Security Vulnerabilities" rel="nofollow" href="https://support.apple.com/en-us/122282">Apple bulletin - iOS 18.4.1 Security Vulnerabilities</a></li><li><a title="Android zero-days documented" rel="nofollow" href="https://source.android.com/docs/security/bulletin/2025-04-01">Android zero-days documented</a></li><li><a title="MITRE CVE Program Gets Last-Hour Funding Reprieve" rel="nofollow" href="https://www.securityweek.com/mitre-cve-program-gets-last-hour-funding-reprieve/">MITRE CVE Program Gets Last-Hour Funding Reprieve</a></li><li><a title="NIST Still Struggling to Clear Vulnerability Submissions Backlog in NVD" rel="nofollow" href="https://www.securityweek.com/nist-still-struggling-to-clear-vulnerability-submissions-backlog-in-nvd/">NIST Still Struggling to Clear Vulnerability Submissions Backlog in NVD</a></li><li><a title="EU issues US-bound staff with burner phones to avoid espionage" rel="nofollow" href="https://archive.ph/VcBLY">EU issues US-bound staff with burner phones to avoid espionage</a></li><li><a title="Exploitation of CLFS zero-day leads to ransomware " rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/04/08/exploitation-of-clfs-zero-day-leads-to-ransomware-activity/">Exploitation of CLFS zero-day leads to ransomware </a></li><li><a title="Google announces Sec-Gemini v1 cybersecurity model" rel="nofollow" href="https://security.googleblog.com/2025/04/google-launches-sec-gemini-v1-new.html">Google announces Sec-Gemini v1 cybersecurity model</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>NSA director fired, Ivanti's 0day screw-up, backdoor in robot dogs</title>
  <link>http://securityconversations.fireside.fm/bunnie-huang-black-hat-ivanti-zeroday-robodog</link>
  <guid isPermaLink="false">8ee6db1b-3fe7-45d5-ae76-01d697ffdff9</guid>
  <pubDate>Fri, 04 Apr 2025 10:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/8ee6db1b-3fe7-45d5-ae76-01d697ffdff9.mp3" length="84762978" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 41: Costin and Juanito join the show from Black Hat Asia in Singapore. We discuss Bunnie Huang's keynote on hardware supply chains and a classification system to establish a grounded perspective on trust in hardware, Ivanti's misdiagnosis of a critical VPN applicance flaw and Mandiant reporting on a Chinese APT exploiting Ivanti devices.  Plus, breaking news on the sudden firing of NSA director and head of Cyber Command Tim Haugh.

We also discuss Microsoft touting AI's value in finding open-source bootloader bugs, Silent Push report on a RUssian APT impersonating the CIA, a backdoor in a popular Chinese robot dog, and Chinese dominance of the robotics market.

 Cast: Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:36:57</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/8/8ee6db1b-3fe7-45d5-ae76-01d697ffdff9/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 41: Costin and Juanito join the show from Black Hat Asia in Singapore. We discuss Bunnie Huang's keynote on hardware supply chains and a classification system to establish a grounded perspective on trust in hardware, Ivanti's misdiagnosis of a critical VPN applicance flaw and Mandiant reporting on a Chinese APT exploiting Ivanti devices.  Plus, breaking news on the sudden firing of NSA director and head of Cyber Command Tim Haugh.
We also discuss Microsoft touting AI's value in finding open-source bootloader bugs, Silent Push report on a RUssian APT impersonating the CIA, a backdoor in a popular Chinese robot dog, and Chinese dominance of the robotics market.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Black Hat Asia, Singapore, Bunnie Huang, hardware trust, supply chain, China, Ivanti, Mandiant, Microsoft Security Copilot, Unitree, robotics</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 41</strong>: Costin and Juanito join the show from Black Hat Asia in Singapore. We discuss Bunnie Huang&#39;s keynote on hardware supply chains and a classification system to establish a grounded perspective on trust in hardware, Ivanti&#39;s misdiagnosis of a critical VPN applicance flaw and Mandiant reporting on a Chinese APT exploiting Ivanti devices.  Plus, breaking news on the sudden firing of NSA director and head of Cyber Command Tim Haugh.</p>

<p>We also discuss Microsoft touting AI&#39;s value in finding open-source bootloader bugs, Silent Push report on a RUssian APT impersonating the CIA, a backdoor in a popular Chinese robot dog, and Chinese dominance of the robotics market.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1kgNSEX2RyhL2Ph0OoTk1GwNRPaKGITQbe-XSMU21fgk/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="National Security Agency chief ousted after far-right activist urged his removal" rel="nofollow" href="https://archive.ph/tWaVv">National Security Agency chief ousted after far-right activist urged his removal</a></li><li><a title="Mandiant: China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability " rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability">Mandiant: China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability </a></li><li><a title="Ivanti security bulletin (CVE-2025-22457)" rel="nofollow" href="https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US">Ivanti security bulletin (CVE-2025-22457)</a></li><li><a title="Chinese APT exploits misdiagnosed RCE in Ivanti VPNs" rel="nofollow" href="https://www.securityweek.com/chinese-apt-pounces-on-misdiagnosed-rce-in-ivanti-vpn-appliances/">Chinese APT exploits misdiagnosed RCE in Ivanti VPNs</a></li><li><a title="Another exploited 0day in Apple iOS " rel="nofollow" href="https://support.apple.com/en-us/122346">Another exploited 0day in Apple iOS </a></li><li><a title="Android version of Lockdown Mode coming" rel="nofollow" href="https://www.androidauthority.com/android-inactivity-reboot-android-16-3539949/">Android version of Lockdown Mode coming</a></li><li><a title="Microsoft:  Using AI to find open-source bootloader flaws" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/">Microsoft:  Using AI to find open-source bootloader flaws</a></li><li><a title="Indiana University cybersecurity &quot;safe&quot; after FBI home searches" rel="nofollow" href="https://archive.ph/KIX8k#selection-465.0-465.84">Indiana University cybersecurity "safe" after FBI home searches</a></li><li><a title="Silent Push: Russians impersonate CIA to target Ukraine sympathizers" rel="nofollow" href="https://www.silentpush.com/blog/russian-intelligence-phishing/">Silent Push: Russians impersonate CIA to target Ukraine sympathizers</a></li><li><a title="Unitree Go1 robot dog backdoor documentation" rel="nofollow" href="https://think-awesome.com/download_unitree_report">Unitree Go1 robot dog backdoor documentation</a></li><li><a title="America is missing in the robotics race" rel="nofollow" href="https://semianalysis.com/2025/03/11/america-is-missing-the-new-labor-economy-robotics-part-1/">America is missing in the robotics race</a></li><li><a title="Automated AI Reverse Engineering with MCP for IDA and Ghidra" rel="nofollow" href="https://www.youtube.com/watch?v=iFxNuk3kxhk&amp;ab_channel=OALabs">Automated AI Reverse Engineering with MCP for IDA and Ghidra</a></li><li><a title="Bunny Huang: Perspectives on trust in hardware supply chains" rel="nofollow" href="https://www.blackhat.com/asia-25/briefings/schedule/#keynote-perspectives-on-trust-in-hardware-supply-chains-44613">Bunny Huang: Perspectives on trust in hardware supply chains</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 41</strong>: Costin and Juanito join the show from Black Hat Asia in Singapore. We discuss Bunnie Huang&#39;s keynote on hardware supply chains and a classification system to establish a grounded perspective on trust in hardware, Ivanti&#39;s misdiagnosis of a critical VPN applicance flaw and Mandiant reporting on a Chinese APT exploiting Ivanti devices.  Plus, breaking news on the sudden firing of NSA director and head of Cyber Command Tim Haugh.</p>

<p>We also discuss Microsoft touting AI&#39;s value in finding open-source bootloader bugs, Silent Push report on a RUssian APT impersonating the CIA, a backdoor in a popular Chinese robot dog, and Chinese dominance of the robotics market.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1kgNSEX2RyhL2Ph0OoTk1GwNRPaKGITQbe-XSMU21fgk/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="National Security Agency chief ousted after far-right activist urged his removal" rel="nofollow" href="https://archive.ph/tWaVv">National Security Agency chief ousted after far-right activist urged his removal</a></li><li><a title="Mandiant: China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability " rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability">Mandiant: China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability </a></li><li><a title="Ivanti security bulletin (CVE-2025-22457)" rel="nofollow" href="https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US">Ivanti security bulletin (CVE-2025-22457)</a></li><li><a title="Chinese APT exploits misdiagnosed RCE in Ivanti VPNs" rel="nofollow" href="https://www.securityweek.com/chinese-apt-pounces-on-misdiagnosed-rce-in-ivanti-vpn-appliances/">Chinese APT exploits misdiagnosed RCE in Ivanti VPNs</a></li><li><a title="Another exploited 0day in Apple iOS " rel="nofollow" href="https://support.apple.com/en-us/122346">Another exploited 0day in Apple iOS </a></li><li><a title="Android version of Lockdown Mode coming" rel="nofollow" href="https://www.androidauthority.com/android-inactivity-reboot-android-16-3539949/">Android version of Lockdown Mode coming</a></li><li><a title="Microsoft:  Using AI to find open-source bootloader flaws" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/">Microsoft:  Using AI to find open-source bootloader flaws</a></li><li><a title="Indiana University cybersecurity &quot;safe&quot; after FBI home searches" rel="nofollow" href="https://archive.ph/KIX8k#selection-465.0-465.84">Indiana University cybersecurity "safe" after FBI home searches</a></li><li><a title="Silent Push: Russians impersonate CIA to target Ukraine sympathizers" rel="nofollow" href="https://www.silentpush.com/blog/russian-intelligence-phishing/">Silent Push: Russians impersonate CIA to target Ukraine sympathizers</a></li><li><a title="Unitree Go1 robot dog backdoor documentation" rel="nofollow" href="https://think-awesome.com/download_unitree_report">Unitree Go1 robot dog backdoor documentation</a></li><li><a title="America is missing in the robotics race" rel="nofollow" href="https://semianalysis.com/2025/03/11/america-is-missing-the-new-labor-economy-robotics-part-1/">America is missing in the robotics race</a></li><li><a title="Automated AI Reverse Engineering with MCP for IDA and Ghidra" rel="nofollow" href="https://www.youtube.com/watch?v=iFxNuk3kxhk&amp;ab_channel=OALabs">Automated AI Reverse Engineering with MCP for IDA and Ghidra</a></li><li><a title="Bunny Huang: Perspectives on trust in hardware supply chains" rel="nofollow" href="https://www.blackhat.com/asia-25/briefings/schedule/#keynote-perspectives-on-trust-in-hardware-supply-chains-44613">Bunny Huang: Perspectives on trust in hardware supply chains</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Signalgate and ID management hiccups, PuzzleMaker and Chrome 0days, Lab Dookhtegan returns</title>
  <link>http://securityconversations.fireside.fm/signalgate-id-management-puzzlemaker-chrome-zero-day</link>
  <guid isPermaLink="false">b9f48f51-2a3a-4f4e-8e3a-1c9c5bf76f9c</guid>
  <pubDate>Fri, 28 Mar 2025 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/b9f48f51-2a3a-4f4e-8e3a-1c9c5bf76f9c.mp3" length="88112428" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 40: On the show this week, we look at the technical deficiencies and opsec concerns around the use of Signal for ultra-sensitive communications. Plus, some speculation on who's behind Kaspersky’s ‘Operation Forum Troll’ report, Chinese discussion on NSA/CIA mobile networks exploitation, and the return of ‘Lab Dookhtegan’ hack-and-leak exposures.

 Cast: Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:52:34</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/b/b9f48f51-2a3a-4f4e-8e3a-1c9c5bf76f9c/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 40: On the show this week, we look at the technical deficiencies and opsec concerns around the use of Signal for ultra-sensitive communications. Plus, some speculation on who's behind Kaspersky’s ‘Operation Forum Troll’ report, Chinese discussion on NSA/CIA mobile networks exploitation, and the return of ‘Lab Dookhtegan’ hack-and-leak exposures.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Signal, PuzzleMaker, encryption, secure messaging, Operation Forum Troll, Chrome, zero-day, China, NSA, CIA, Lab Dooktegan, Intrusion Truth, Tornado Cash, i-Soon, Pangu Labs</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 40</strong>: On the show this week, we look at the technical deficiencies and opsec concerns around the use of Signal for ultra-sensitive communications. Plus, some speculation on who&#39;s behind Kaspersky’s ‘Operation Forum Troll’ report, Chinese discussion on NSA/CIA mobile networks exploitation, and the return of ‘Lab Dookhtegan’ hack-and-leak exposures.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1u3s6n977qAHCEIChdXeRTrbseZ_2ZFYofneh8a5BMTg/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="The Atlantic: The Trump admin accidentally texted me its war plans" rel="nofollow" href="https://archive.ph/JEYep">The Atlantic: The Trump admin accidentally texted me its war plans</a></li><li><a title="The Atlantic: Here are the attack plans shared on Signal" rel="nofollow" href="https://archive.ph/fNUm7">The Atlantic: Here are the attack plans shared on Signal</a></li><li><a title="Signal statement on SignalGate" rel="nofollow" href="https://x.com/signalapp/status/1904666111989166408">Signal statement on SignalGate</a></li><li><a title="Our experts separate Signal from noise in the Trump team group chat" rel="nofollow" href="https://www.atlanticcouncil.org/blogs/new-atlanticist/our-experts-separate-signal-from-noise-in-the-trump-teams-messages-about-bombing-the-houthis/">Our experts separate Signal from noise in the Trump team group chat</a></li><li><a title="Operation ForumTroll exploits zero-days in Google Chrome" rel="nofollow" href="https://securelist.com/operation-forumtroll/115989/">Operation ForumTroll exploits zero-days in Google Chrome</a></li><li><a title="PuzzleMaker attacks with Chrome zero-day exploit chain" rel="nofollow" href="https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/">PuzzleMaker attacks with Chrome zero-day exploit chain</a></li><li><a title="Ten most mysterious APT campaigns that remain unattributed" rel="nofollow" href="https://securelist.com/top-10-unattributed-apt-mysteries/107676/">Ten most mysterious APT campaigns that remain unattributed</a></li><li><a title="Operation FishMedley linked to i-SOON" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/operation-fishmedley/">Operation FishMedley linked to i-SOON</a></li><li><a title="Chinese gov agency on mobile attacks by US intel agencies" rel="nofollow" href="http://www.news.cn/world/20250325/02ba448744ac4b75a81df613a88b4d26/2025032522b55fd15b244a5fac54e424c62be9b7_1616350dfed1c44ba786a82d574c86c30f.pdf">Chinese gov agency on mobile attacks by US intel agencies</a></li><li><a title="LabDookhtegan Telegram channel" rel="nofollow" href="https://t.me/Lab_Dookhtegan_Channel/254">LabDookhtegan Telegram channel</a></li><li><a title="Tornado Cash sanctions removed" rel="nofollow" href="https://home.treasury.gov/news/press-releases/sb0057">Tornado Cash sanctions removed</a></li><li><a title="Intrusion Truth " rel="nofollow" href="https://intrusiontruth.wordpress.com/">Intrusion Truth </a></li><li><a title="Lab Dookhtegan archives on CyberScoop" rel="nofollow" href="https://cyberscoop.com/tag/lab-dookhtegan/">Lab Dookhtegan archives on CyberScoop</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 40</strong>: On the show this week, we look at the technical deficiencies and opsec concerns around the use of Signal for ultra-sensitive communications. Plus, some speculation on who&#39;s behind Kaspersky’s ‘Operation Forum Troll’ report, Chinese discussion on NSA/CIA mobile networks exploitation, and the return of ‘Lab Dookhtegan’ hack-and-leak exposures.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1u3s6n977qAHCEIChdXeRTrbseZ_2ZFYofneh8a5BMTg/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="The Atlantic: The Trump admin accidentally texted me its war plans" rel="nofollow" href="https://archive.ph/JEYep">The Atlantic: The Trump admin accidentally texted me its war plans</a></li><li><a title="The Atlantic: Here are the attack plans shared on Signal" rel="nofollow" href="https://archive.ph/fNUm7">The Atlantic: Here are the attack plans shared on Signal</a></li><li><a title="Signal statement on SignalGate" rel="nofollow" href="https://x.com/signalapp/status/1904666111989166408">Signal statement on SignalGate</a></li><li><a title="Our experts separate Signal from noise in the Trump team group chat" rel="nofollow" href="https://www.atlanticcouncil.org/blogs/new-atlanticist/our-experts-separate-signal-from-noise-in-the-trump-teams-messages-about-bombing-the-houthis/">Our experts separate Signal from noise in the Trump team group chat</a></li><li><a title="Operation ForumTroll exploits zero-days in Google Chrome" rel="nofollow" href="https://securelist.com/operation-forumtroll/115989/">Operation ForumTroll exploits zero-days in Google Chrome</a></li><li><a title="PuzzleMaker attacks with Chrome zero-day exploit chain" rel="nofollow" href="https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/">PuzzleMaker attacks with Chrome zero-day exploit chain</a></li><li><a title="Ten most mysterious APT campaigns that remain unattributed" rel="nofollow" href="https://securelist.com/top-10-unattributed-apt-mysteries/107676/">Ten most mysterious APT campaigns that remain unattributed</a></li><li><a title="Operation FishMedley linked to i-SOON" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/operation-fishmedley/">Operation FishMedley linked to i-SOON</a></li><li><a title="Chinese gov agency on mobile attacks by US intel agencies" rel="nofollow" href="http://www.news.cn/world/20250325/02ba448744ac4b75a81df613a88b4d26/2025032522b55fd15b244a5fac54e424c62be9b7_1616350dfed1c44ba786a82d574c86c30f.pdf">Chinese gov agency on mobile attacks by US intel agencies</a></li><li><a title="LabDookhtegan Telegram channel" rel="nofollow" href="https://t.me/Lab_Dookhtegan_Channel/254">LabDookhtegan Telegram channel</a></li><li><a title="Tornado Cash sanctions removed" rel="nofollow" href="https://home.treasury.gov/news/press-releases/sb0057">Tornado Cash sanctions removed</a></li><li><a title="Intrusion Truth " rel="nofollow" href="https://intrusiontruth.wordpress.com/">Intrusion Truth </a></li><li><a title="Lab Dookhtegan archives on CyberScoop" rel="nofollow" href="https://cyberscoop.com/tag/lab-dookhtegan/">Lab Dookhtegan archives on CyberScoop</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>China exposing Taiwan hacks, Paragon spyware and WhatsApp exploits, CISA budget cuts</title>
  <link>http://securityconversations.fireside.fm/china-taiwan-paragon-whatsapp-cisa</link>
  <guid isPermaLink="false">eaa3f669-ac3a-4173-ad61-053f13fb6253</guid>
  <pubDate>Fri, 21 Mar 2025 13:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/eaa3f669-ac3a-4173-ad61-053f13fb6253.mp3" length="94023970" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 39:  Luta Security CEO Katie Moussouris joins the buddies to parse news around a coordinated Chinese exposure of Taiwan APT actors, CitizenLab's report on Paragon spyware and WhatsApp exploits, an “official” Russian government exploit-buying operation shopping for Telegram exploits, the fragmentation of exploit markets and the future of CISA in the face of budget cuts and layoffs.

 Cast: Katie Moussouris (Luta Security), Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:56:22</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/eaa3f669-ac3a-4173-ad61-053f13fb6253/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 39: Luta Security CEO Katie Moussouris joins the buddies to parse news around a coordinated Chinese exposure of Taiwan APT actors, CitizenLab's report on Paragon spyware and WhatsApp exploits, an “official” Russian government exploit-buying operation shopping for Telegram exploits, the fragmentation of exploit markets and the future of CISA in the face of budget cuts and layoffs.
Cast:   Katie Moussouris (https://lutasecurity.com), Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine).
</description>
  <itunes:keywords>China, Taiwan, Iran, APT15, Luta Security, Citizen Lab, Paragon, Operation Zero, Telegram, Russia, GitHub Actions, CISA, LNK, Lab Dooktegen, CISA</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 39</strong>: Luta Security CEO Katie Moussouris joins the buddies to parse news around a coordinated Chinese exposure of Taiwan APT actors, CitizenLab&#39;s report on Paragon spyware and WhatsApp exploits, an “official” Russian government exploit-buying operation shopping for Telegram exploits, the fragmentation of exploit markets and the future of CISA in the face of budget cuts and layoffs.</p>

<p><strong>Cast:</strong>   <a href="https://lutasecurity.com" rel="nofollow">Katie Moussouris</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1nr3Ug3XbuqcsIf7btZ2bdAQhTbBTUEfzphKG49_uYZ4/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="China&#39;s MSS discloses Taiwan APTs " rel="nofollow" href="http://eng.mod.gov.cn/xb/News_213114/TopStories/16375392.html">China's MSS discloses Taiwan APTs </a></li><li><a title="Antiy report Taiwan&#39;s &quot;Green Spot&quot; attack group" rel="nofollow" href="https://www.antiy.cn/research/notice&amp;report/research_report/GreenSpot_Analysis_202503.html">Antiy report Taiwan's "Green Spot" attack group</a></li><li><a title="Citizen Lab on Paragon’s Proliferating Spyware Operations" rel="nofollow" href="https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/">Citizen Lab on Paragon’s Proliferating Spyware Operations</a></li><li><a title="Operation Zero wants Telegram 1-click RCE exploits" rel="nofollow" href="https://x.com/opzero_en/status/1902665005675295186?s=46&amp;t=NxSQbkIl4wl2Ei8yYr-9IQ">Operation Zero wants Telegram 1-click RCE exploits</a></li><li><a title="Operation Zero 0day Vulnerability Platform" rel="nofollow" href="https://opzero.ru/en/">Operation Zero 0day Vulnerability Platform</a></li><li><a title="GitHub Action supply chain attack" rel="nofollow" href="https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised">GitHub Action supply chain attack</a></li><li><a title="Blast radius of GitHub Action supply chain attack" rel="nofollow" href="https://www.endorlabs.com/learn/blast-radius-of-the-tj-actions-changed-files-supply-chain-attack">Blast radius of GitHub Action supply chain attack</a></li><li><a title="Windows .lnk shortcut exploit abused as zero-day" rel="nofollow" href="https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html">Windows .lnk shortcut exploit abused as zero-day</a></li><li><a title="Sean Plankey nominated to lead CISA" rel="nofollow" href="https://www.congress.gov/nomination/119th-congress/26/38">Sean Plankey nominated to lead CISA</a></li><li><a title="Trump admin halts funding for two cybersecurity efforts" rel="nofollow" href="https://www.securityweek.com/trump-administration-halts-funding-for-two-cybersecurity-efforts-including-one-for-elections/">Trump admin halts funding for two cybersecurity efforts</a></li><li><a title="CISA publishes Jen Easterley&#39;s calendars" rel="nofollow" href="https://www.dhs.gov/publication/cisa-calendars">CISA publishes Jen Easterley's calendars</a></li><li><a title="CISA statement on &#39;red-team&#39; layoff reports" rel="nofollow" href="https://www.cisa.gov/news-events/news/statement-cisas-red-team">CISA statement on 'red-team' layoff reports</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 39</strong>: Luta Security CEO Katie Moussouris joins the buddies to parse news around a coordinated Chinese exposure of Taiwan APT actors, CitizenLab&#39;s report on Paragon spyware and WhatsApp exploits, an “official” Russian government exploit-buying operation shopping for Telegram exploits, the fragmentation of exploit markets and the future of CISA in the face of budget cuts and layoffs.</p>

<p><strong>Cast:</strong>   <a href="https://lutasecurity.com" rel="nofollow">Katie Moussouris</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1nr3Ug3XbuqcsIf7btZ2bdAQhTbBTUEfzphKG49_uYZ4/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="China&#39;s MSS discloses Taiwan APTs " rel="nofollow" href="http://eng.mod.gov.cn/xb/News_213114/TopStories/16375392.html">China's MSS discloses Taiwan APTs </a></li><li><a title="Antiy report Taiwan&#39;s &quot;Green Spot&quot; attack group" rel="nofollow" href="https://www.antiy.cn/research/notice&amp;report/research_report/GreenSpot_Analysis_202503.html">Antiy report Taiwan's "Green Spot" attack group</a></li><li><a title="Citizen Lab on Paragon’s Proliferating Spyware Operations" rel="nofollow" href="https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/">Citizen Lab on Paragon’s Proliferating Spyware Operations</a></li><li><a title="Operation Zero wants Telegram 1-click RCE exploits" rel="nofollow" href="https://x.com/opzero_en/status/1902665005675295186?s=46&amp;t=NxSQbkIl4wl2Ei8yYr-9IQ">Operation Zero wants Telegram 1-click RCE exploits</a></li><li><a title="Operation Zero 0day Vulnerability Platform" rel="nofollow" href="https://opzero.ru/en/">Operation Zero 0day Vulnerability Platform</a></li><li><a title="GitHub Action supply chain attack" rel="nofollow" href="https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised">GitHub Action supply chain attack</a></li><li><a title="Blast radius of GitHub Action supply chain attack" rel="nofollow" href="https://www.endorlabs.com/learn/blast-radius-of-the-tj-actions-changed-files-supply-chain-attack">Blast radius of GitHub Action supply chain attack</a></li><li><a title="Windows .lnk shortcut exploit abused as zero-day" rel="nofollow" href="https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html">Windows .lnk shortcut exploit abused as zero-day</a></li><li><a title="Sean Plankey nominated to lead CISA" rel="nofollow" href="https://www.congress.gov/nomination/119th-congress/26/38">Sean Plankey nominated to lead CISA</a></li><li><a title="Trump admin halts funding for two cybersecurity efforts" rel="nofollow" href="https://www.securityweek.com/trump-administration-halts-funding-for-two-cybersecurity-efforts-including-one-for-elections/">Trump admin halts funding for two cybersecurity efforts</a></li><li><a title="CISA publishes Jen Easterley&#39;s calendars" rel="nofollow" href="https://www.dhs.gov/publication/cisa-calendars">CISA publishes Jen Easterley's calendars</a></li><li><a title="CISA statement on &#39;red-team&#39; layoff reports" rel="nofollow" href="https://www.cisa.gov/news-events/news/statement-cisas-red-team">CISA statement on 'red-team' layoff reports</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>A half-dozen Microsoft zero-days, Juniper router backdoors, advanced bootkit hunting</title>
  <link>http://securityconversations.fireside.fm/zero-day-tuesday-juniper-custom-backdoor-bootkit-hunting</link>
  <guid isPermaLink="false">e8ceaea1-2a65-4964-9062-3aca6da98d36</guid>
  <pubDate>Fri, 14 Mar 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e8ceaea1-2a65-4964-9062-3aca6da98d36.mp3" length="99623327" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 38:  On the show this week, we look at a hefty batch of Microsoft zero-days exploited in the wild, iOS 18.3.2 fixing an exploited WebKit bug, a mysterious Unpatched.ai being credited with Microsoft Access RCE flaws, and OpenAI lobbying for the US to ban China's DeepSeek.

Plus, discussion on a Binarly technical paper with new approach to finding UEFI bootkits, Mandiant flagging custom backdoors on Juniper routers, and MEV 'sandwich attacks' front-running cryptocurrency transactions.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:05:43</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e8ceaea1-2a65-4964-9062-3aca6da98d36/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 38: On the show this week, we look at a hefty batch of Microsoft zero-days exploited in the wild, iOS 18.3.2 fixing an exploited WebKit bug, a mysterious Unpatched.ai being credited with Microsoft Access RCE flaws, and OpenAI lobbying for the US to ban China's DeepSeek.
Plus, discussion on a Binarly technical paper with new approach to finding UEFI bootkits, Mandiant flagging custom backdoors on Juniper routers, and MEV 'sandwich attacks' front-running cryptocurrency transactions.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Microsoft, Apple, Patch Tuesday, zero-day, WebKit, iOS 18.3.2, China, unpatched.ai, Microsoft Access, OpenAI, deepseek, UEFI, Binarly, bootkits, YARA, FWHunt, Mandian, Juniper, Jun OS, backdoor, router, MEV, sandwich attacks, cryptocurrency</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 38</strong>: On the show this week, we look at a hefty batch of Microsoft zero-days exploited in the wild, iOS 18.3.2 fixing an exploited WebKit bug, a mysterious Unpatched.ai being credited with Microsoft Access RCE flaws, and OpenAI lobbying for the US to ban China&#39;s DeepSeek.</p>

<p>Plus, discussion on a Binarly technical paper with new approach to finding UEFI bootkits, Mandiant flagging custom backdoors on Juniper routers, and MEV &#39;sandwich attacks&#39; front-running cryptocurrency transactions.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1eGHr2QVVzfFht4x-6NqNpiXOvU7qPYNbNoYLbnXo9JA/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Microsoft Flags Six Active Zero-Days, Patches 57 Flaws" rel="nofollow" href="https://www.securityweek.com/patch-tuesday-microsoft-patches-57-flaws-flags-six-active-zero-days/">Microsoft Flags Six Active Zero-Days, Patches 57 Flaws</a></li><li><a title="Unpatched.ai discoveries" rel="nofollow" href="https://www.unpatched.ai/reports">Unpatched.ai discoveries</a></li><li><a title="Apple Ships iOS 18.3.2 to Fix Already-Exploited WebKit Flaw" rel="nofollow" href="https://www.securityweek.com/apple-ships-ios-18-3-2-to-fix-already-exploited-webkit-flaw/">Apple Ships iOS 18.3.2 to Fix Already-Exploited WebKit Flaw</a></li><li><a title="Apple iOS 18.3.2 and iPadOS 18.3.2 documentation" rel="nofollow" href="https://support.apple.com/en-us/122281">Apple iOS 18.3.2 and iPadOS 18.3.2 documentation</a></li><li><a title="Citizen Lab: Predator in the wires" rel="nofollow" href="https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/">Citizen Lab: Predator in the wires</a></li><li><a title="FreeType Zero-Day Being Exploited in the Wild" rel="nofollow" href="https://www.securityweek.com/freetype-zero-day-being-exploited-in-the-wild/">FreeType Zero-Day Being Exploited in the Wild</a></li><li><a title="CVE-2020-15999: FreeType Heap Buffer Overflow" rel="nofollow" href="https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2020/CVE-2020-15999.html">CVE-2020-15999: FreeType Heap Buffer Overflow</a></li><li><a title="Mandiant : Ghost in the Juniper router" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers">Mandiant : Ghost in the Juniper router</a></li><li><a title="Jun OS out-of-cycle security bulletin (CVE-2025-21590)" rel="nofollow" href="https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US">Jun OS out-of-cycle security bulletin (CVE-2025-21590)</a></li><li><a title="Juniper Malware Removal Tool" rel="nofollow" href="https://www.juniper.net/documentation/us/en/software/junos/security-services/topics/concept/juniper-malware-removal-tool.html">Juniper Malware Removal Tool</a></li><li><a title="Binarly: UEFI Bootkit Hunting -- In-Depth Search for Unique Code Behavior" rel="nofollow" href="https://www.binarly.io/blog/uefi-bootkit-hunting-in-depth-search-for-unique-code-behavior">Binarly: UEFI Bootkit Hunting -- In-Depth Search for Unique Code Behavior</a></li><li><a title="Crypto Trader Loses $215,000 in MEV Sandwich Attack on Uniswap" rel="nofollow" href="https://blockonomi.com/crypto-trader-loses-215000-in-mev-sandwich-attack-on-uniswap/">Crypto Trader Loses $215,000 in MEV Sandwich Attack on Uniswap</a></li><li><a title="The Secretive World Of MEV, Where Bots Front-Run Crypto Investors For Big Profits" rel="nofollow" href="https://www.forbes.com/sites/jeffkauflin/2022/10/11/the-secretive-world-of-mev-where-crypto-bots-scalp-investors-for-big-profits/">The Secretive World Of MEV, Where Bots Front-Run Crypto Investors For Big Profits</a></li><li><a title="Reuters journalist Raphael Satter loses overseas citizenship" rel="nofollow" href="https://www.theguardian.com/world/2025/mar/13/us-journalist-sues-indian-government-after-losing-his-overseas-citizenship">Reuters journalist Raphael Satter loses overseas citizenship</a></li><li><a title="Yanis Varoufakis: Trump’s tariff chaos explained" rel="nofollow" href="https://www.youtube.com/watch?v=f1CdbCsetpw&amp;ab_channel=TimesRadio">Yanis Varoufakis: Trump’s tariff chaos explained</a></li><li><a title="Technofeudalism: What Killed Capitalism (Yanis Varoufakis)" rel="nofollow" href="https://www.goodreads.com/book/show/75560037-techno-feudalism">Technofeudalism: What Killed Capitalism (Yanis Varoufakis)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 38</strong>: On the show this week, we look at a hefty batch of Microsoft zero-days exploited in the wild, iOS 18.3.2 fixing an exploited WebKit bug, a mysterious Unpatched.ai being credited with Microsoft Access RCE flaws, and OpenAI lobbying for the US to ban China&#39;s DeepSeek.</p>

<p>Plus, discussion on a Binarly technical paper with new approach to finding UEFI bootkits, Mandiant flagging custom backdoors on Juniper routers, and MEV &#39;sandwich attacks&#39; front-running cryptocurrency transactions.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1eGHr2QVVzfFht4x-6NqNpiXOvU7qPYNbNoYLbnXo9JA/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Microsoft Flags Six Active Zero-Days, Patches 57 Flaws" rel="nofollow" href="https://www.securityweek.com/patch-tuesday-microsoft-patches-57-flaws-flags-six-active-zero-days/">Microsoft Flags Six Active Zero-Days, Patches 57 Flaws</a></li><li><a title="Unpatched.ai discoveries" rel="nofollow" href="https://www.unpatched.ai/reports">Unpatched.ai discoveries</a></li><li><a title="Apple Ships iOS 18.3.2 to Fix Already-Exploited WebKit Flaw" rel="nofollow" href="https://www.securityweek.com/apple-ships-ios-18-3-2-to-fix-already-exploited-webkit-flaw/">Apple Ships iOS 18.3.2 to Fix Already-Exploited WebKit Flaw</a></li><li><a title="Apple iOS 18.3.2 and iPadOS 18.3.2 documentation" rel="nofollow" href="https://support.apple.com/en-us/122281">Apple iOS 18.3.2 and iPadOS 18.3.2 documentation</a></li><li><a title="Citizen Lab: Predator in the wires" rel="nofollow" href="https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/">Citizen Lab: Predator in the wires</a></li><li><a title="FreeType Zero-Day Being Exploited in the Wild" rel="nofollow" href="https://www.securityweek.com/freetype-zero-day-being-exploited-in-the-wild/">FreeType Zero-Day Being Exploited in the Wild</a></li><li><a title="CVE-2020-15999: FreeType Heap Buffer Overflow" rel="nofollow" href="https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2020/CVE-2020-15999.html">CVE-2020-15999: FreeType Heap Buffer Overflow</a></li><li><a title="Mandiant : Ghost in the Juniper router" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers">Mandiant : Ghost in the Juniper router</a></li><li><a title="Jun OS out-of-cycle security bulletin (CVE-2025-21590)" rel="nofollow" href="https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US">Jun OS out-of-cycle security bulletin (CVE-2025-21590)</a></li><li><a title="Juniper Malware Removal Tool" rel="nofollow" href="https://www.juniper.net/documentation/us/en/software/junos/security-services/topics/concept/juniper-malware-removal-tool.html">Juniper Malware Removal Tool</a></li><li><a title="Binarly: UEFI Bootkit Hunting -- In-Depth Search for Unique Code Behavior" rel="nofollow" href="https://www.binarly.io/blog/uefi-bootkit-hunting-in-depth-search-for-unique-code-behavior">Binarly: UEFI Bootkit Hunting -- In-Depth Search for Unique Code Behavior</a></li><li><a title="Crypto Trader Loses $215,000 in MEV Sandwich Attack on Uniswap" rel="nofollow" href="https://blockonomi.com/crypto-trader-loses-215000-in-mev-sandwich-attack-on-uniswap/">Crypto Trader Loses $215,000 in MEV Sandwich Attack on Uniswap</a></li><li><a title="The Secretive World Of MEV, Where Bots Front-Run Crypto Investors For Big Profits" rel="nofollow" href="https://www.forbes.com/sites/jeffkauflin/2022/10/11/the-secretive-world-of-mev-where-crypto-bots-scalp-investors-for-big-profits/">The Secretive World Of MEV, Where Bots Front-Run Crypto Investors For Big Profits</a></li><li><a title="Reuters journalist Raphael Satter loses overseas citizenship" rel="nofollow" href="https://www.theguardian.com/world/2025/mar/13/us-journalist-sues-indian-government-after-losing-his-overseas-citizenship">Reuters journalist Raphael Satter loses overseas citizenship</a></li><li><a title="Yanis Varoufakis: Trump’s tariff chaos explained" rel="nofollow" href="https://www.youtube.com/watch?v=f1CdbCsetpw&amp;ab_channel=TimesRadio">Yanis Varoufakis: Trump’s tariff chaos explained</a></li><li><a title="Technofeudalism: What Killed Capitalism (Yanis Varoufakis)" rel="nofollow" href="https://www.goodreads.com/book/show/75560037-techno-feudalism">Technofeudalism: What Killed Capitalism (Yanis Varoufakis)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Revisiting the Lamberts, i-Soon indictments, VMware zero-days</title>
  <link>http://securityconversations.fireside.fm/revisiting-the-lamberts-apt</link>
  <guid isPermaLink="false">63a92335-8a4c-4f44-8bc4-b1f6a374ffed</guid>
  <pubDate>Sat, 08 Mar 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/63a92335-8a4c-4f44-8bc4-b1f6a374ffed.mp3" length="79756556" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 37: This week, we revisit the public reporting on a US/Russia cyber stand down order, CISA declaring no change to its position on tracking Russian threats, and the high-level diplomatic optics at play. 

Plus, a dissection of ‘The Lamberts’ APT and connections to US intelligence agencies, attribution around ‘Operation Triangulation’ and the lack of recent visibility into these actors. We also discuss a fresh batch of VMware zero-days, China’s i-Soon ‘hackers-for-hire’ indictments, the Pangu/i-Soon connection, and a new wave of Apple threat-intel warnings about mercenary spyware infections.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:39:32</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/63a92335-8a4c-4f44-8bc4-b1f6a374ffed/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 37: This week, we revisit the public reporting on a US/Russia cyber stand down order, CISA declaring no change to its position on tracking Russian threats, and the high-level diplomatic optics at play. 
Plus, a dissection of ‘The Lamberts’ APT and connections to US intelligence agencies, attribution around ‘Operation Triangulation’ and the lack of recent visibility into these actors. We also discuss a fresh batch of VMware zero-days, China’s i-Soon ‘hackers-for-hire’ indictments, the Pangu/i-Soon connection, and a new wave of Apple threat-intel warnings about mercenary spyware infections.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Russia, Kim Zetter, Cyber Command, CISA, Lambert, Black Lambert, Triangulation, VMware, i-Soon, zero-day, Pangu Team, Apple, iOS, Amnesty International</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 37</strong>: This week, we revisit the public reporting on a US/Russia cyber stand down order, CISA declaring no change to its position on tracking Russian threats, and the high-level diplomatic optics at play. </p>

<p>Plus, a dissection of ‘The Lamberts’ APT and connections to US intelligence agencies, attribution around ‘Operation Triangulation’ and the lack of recent visibility into these actors. We also discuss a fresh batch of VMware zero-days, China’s i-Soon ‘hackers-for-hire’ indictments, the Pangu/i-Soon connection, and a new wave of Apple threat-intel warnings about mercenary spyware infections.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/18Jv-csHfMCuSBFRIjwA55PKys4YIVDYCpc0Eq-BHWbU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Kim Zetter: Did Trump admin order a stand-down on Russia? " rel="nofollow" href="https://www.zetter-zeroday.com/did-trump-admin-order-u-s-cyber-command-and-cisa-to-stand-down-on-russia/">Kim Zetter: Did Trump admin order a stand-down on Russia? </a></li><li><a title="Unraveling the Lamberts Toolkit (Securelist)" rel="nofollow" href="https://securelist.com/unraveling-the-lamberts-toolkit/77990/">Unraveling the Lamberts Toolkit (Securelist)</a></li><li><a title="VB2019: King of the hill: nation-state counterintelligence for victim deconfliction" rel="nofollow" href="https://www.virusbulletin.com/virusbulletin/2020/01/vb2019-paper-king-hill-nation-state-counterintelligence-victim-deconfliction/">VB2019: King of the hill: nation-state counterintelligence for victim deconfliction</a></li><li><a title="VB2018: Draw me like one of your French APTs " rel="nofollow" href="https://www.virusbulletin.com/virusbulletin/2019/01/vb2018-paper-draw-me-one-your-french-apts-expanding-our-descriptive-palette-cyber-threat-actors/">VB2018: Draw me like one of your French APTs </a></li><li><a title="Symantec: Who is Longhorn?" rel="nofollow" href="https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=7ca2e331-2209-46a8-9e60-4cb83f9602de&amp;CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&amp;tab=librarydocuments">Symantec: Who is Longhorn?</a></li><li><a title="VMware: Three new zero-days exploited" rel="nofollow" href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390?utm_campaign=VCF_FY25_VCF_Security-Alert-VMSA-2025-0004_MKT_EM_2938&amp;utm_content=VCF_FY25_VCF_Security-Alert_2938_VMSA-2025-0004_MKT_TRANS_EM_5308&amp;utm_medium=email&amp;utm_source=eloqua">VMware: Three new zero-days exploited</a></li><li><a title="Broadcom patches 3 VMware zero-days exploited in the wild" rel="nofollow" href="https://www.securityweek.com/broadcom-patches-3-vmware-zero-days-exploited-in-the-wild/">Broadcom patches 3 VMware zero-days exploited in the wild</a></li><li><a title="DOJ indictments: i-Soon hackers for hire and APT27" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global">DOJ indictments: i-Soon hackers for hire and APT27</a></li><li><a title="Unmasking I-Soon " rel="nofollow" href="https://www.sentinelone.com/labs/unmasking-i-soon-the-leak-that-revealed-chinas-cyber-operations/">Unmasking I-Soon </a></li><li><a title="Catalan court orders former NSO Group execs be indicted for spyware abuses" rel="nofollow" href="https://therecord.media/catalan-court-orders-nso-execs-investigated">Catalan court orders former NSO Group execs be indicted for spyware abuses</a></li><li><a title="Apple sending &#39;mercenary spyware&#39; threat notifications" rel="nofollow" href="https://bsky.app/profile/donncha.is/post/3ljnm2u7tf225">Apple sending 'mercenary spyware' threat notifications</a></li><li><a title="How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist" rel="nofollow" href="https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/">How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist</a></li><li><a title="Safe{Wallet] post-mortem on ByBit $1.4B crypto heist" rel="nofollow" href="https://x.com/safe/status/1897663514975649938">Safe{Wallet] post-mortem on ByBit $1.4B crypto heist</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 37</strong>: This week, we revisit the public reporting on a US/Russia cyber stand down order, CISA declaring no change to its position on tracking Russian threats, and the high-level diplomatic optics at play. </p>

<p>Plus, a dissection of ‘The Lamberts’ APT and connections to US intelligence agencies, attribution around ‘Operation Triangulation’ and the lack of recent visibility into these actors. We also discuss a fresh batch of VMware zero-days, China’s i-Soon ‘hackers-for-hire’ indictments, the Pangu/i-Soon connection, and a new wave of Apple threat-intel warnings about mercenary spyware infections.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/18Jv-csHfMCuSBFRIjwA55PKys4YIVDYCpc0Eq-BHWbU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Kim Zetter: Did Trump admin order a stand-down on Russia? " rel="nofollow" href="https://www.zetter-zeroday.com/did-trump-admin-order-u-s-cyber-command-and-cisa-to-stand-down-on-russia/">Kim Zetter: Did Trump admin order a stand-down on Russia? </a></li><li><a title="Unraveling the Lamberts Toolkit (Securelist)" rel="nofollow" href="https://securelist.com/unraveling-the-lamberts-toolkit/77990/">Unraveling the Lamberts Toolkit (Securelist)</a></li><li><a title="VB2019: King of the hill: nation-state counterintelligence for victim deconfliction" rel="nofollow" href="https://www.virusbulletin.com/virusbulletin/2020/01/vb2019-paper-king-hill-nation-state-counterintelligence-victim-deconfliction/">VB2019: King of the hill: nation-state counterintelligence for victim deconfliction</a></li><li><a title="VB2018: Draw me like one of your French APTs " rel="nofollow" href="https://www.virusbulletin.com/virusbulletin/2019/01/vb2018-paper-draw-me-one-your-french-apts-expanding-our-descriptive-palette-cyber-threat-actors/">VB2018: Draw me like one of your French APTs </a></li><li><a title="Symantec: Who is Longhorn?" rel="nofollow" href="https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=7ca2e331-2209-46a8-9e60-4cb83f9602de&amp;CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&amp;tab=librarydocuments">Symantec: Who is Longhorn?</a></li><li><a title="VMware: Three new zero-days exploited" rel="nofollow" href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390?utm_campaign=VCF_FY25_VCF_Security-Alert-VMSA-2025-0004_MKT_EM_2938&amp;utm_content=VCF_FY25_VCF_Security-Alert_2938_VMSA-2025-0004_MKT_TRANS_EM_5308&amp;utm_medium=email&amp;utm_source=eloqua">VMware: Three new zero-days exploited</a></li><li><a title="Broadcom patches 3 VMware zero-days exploited in the wild" rel="nofollow" href="https://www.securityweek.com/broadcom-patches-3-vmware-zero-days-exploited-in-the-wild/">Broadcom patches 3 VMware zero-days exploited in the wild</a></li><li><a title="DOJ indictments: i-Soon hackers for hire and APT27" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global">DOJ indictments: i-Soon hackers for hire and APT27</a></li><li><a title="Unmasking I-Soon " rel="nofollow" href="https://www.sentinelone.com/labs/unmasking-i-soon-the-leak-that-revealed-chinas-cyber-operations/">Unmasking I-Soon </a></li><li><a title="Catalan court orders former NSO Group execs be indicted for spyware abuses" rel="nofollow" href="https://therecord.media/catalan-court-orders-nso-execs-investigated">Catalan court orders former NSO Group execs be indicted for spyware abuses</a></li><li><a title="Apple sending &#39;mercenary spyware&#39; threat notifications" rel="nofollow" href="https://bsky.app/profile/donncha.is/post/3ljnm2u7tf225">Apple sending 'mercenary spyware' threat notifications</a></li><li><a title="How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist" rel="nofollow" href="https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/">How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist</a></li><li><a title="Safe{Wallet] post-mortem on ByBit $1.4B crypto heist" rel="nofollow" href="https://x.com/safe/status/1897663514975649938">Safe{Wallet] post-mortem on ByBit $1.4B crypto heist</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Lazarus ByBit $1.4B heist was supply chain attack on developer</title>
  <link>http://securityconversations.fireside.fm/lazarus-bybit-supply-chain-cellebrite-cisa-russia</link>
  <guid isPermaLink="false">f12cd870-ed46-4801-84cc-74161e588723</guid>
  <pubDate>Sat, 01 Mar 2025 09:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/f12cd870-ed46-4801-84cc-74161e588723.mp3" length="95539533" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 36: Ryan and Juanito join the show from the RE//verse conference with discussion on Natalie Silvanovic’s keynote on hunting for bugs in mobile messengers, the thrill of looking at exposed attack surfaces and the grueling “losses” bug hunters endure before a breakthrough. 

We also cover the latest on the $1.4 billion ByBit hack pinned on the Lazarus Group and the malicious JavaScript supply chain attack at the center of the cryptocurrency heist. Plus, the ethical gray zones of tethered exploits via Cellebrite, the whiplash of AI-driven threat intel, and the looming pivot in U.S. cyber policy signaling a stand-down on Russia-focused APT ops. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:53:22</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/f12cd870-ed46-4801-84cc-74161e588723/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 36: Ryan and Juanito join the show from the RE//verse conference with discussion on Natalie Silvanovic’s keynote on hunting for bugs in mobile messengers, the thrill of looking at exposed attack surfaces and the grueling “losses” bug hunters endure before a breakthrough. 
We also cover the latest on the $1.4 billion ByBit hack pinned on the Lazarus Group and the malicious JavaScript supply chain attack at the center of the cryptocurrency heist. Plus, the ethical gray zones of tethered exploits via Cellebrite, the whiplash of AI-driven threat intel, and the looming pivot in U.S. cyber policy signaling a stand-down on Russia-focused ops. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>ByBit, Lazarus, TraderTraitor, North Korea, cryptocurrency, hot wallet, CISA, Russia, Cellebrite, Russia, CyberCommand</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 36</strong>: Ryan and Juanito join the show from the RE//verse conference with discussion on Natalie Silvanovic’s keynote on hunting for bugs in mobile messengers, the thrill of looking at exposed attack surfaces and the grueling “losses” bug hunters endure before a breakthrough. </p>

<p>We also cover the latest on the $1.4 billion ByBit hack pinned on the Lazarus Group and the malicious JavaScript supply chain attack at the center of the cryptocurrency heist. Plus, the ethical gray zones of tethered exploits via Cellebrite, the whiplash of AI-driven threat intel, and the looming pivot in U.S. cyber policy signaling a stand-down on Russia-focused ops. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1fIXGfKfpyh0ltjAvW31z-g1fGhQvtMV6SsEusbZlJo0/edit?tab=t.0#heading=h.m2k4a9q509q9">Transcript (unedited, AI-generated)</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li><li><a title="FBI Says North Korea Hacked Bybit as Details of $1.5B Heist Emerge" rel="nofollow" href="https://www.securityweek.com/fbi-says-north-korea-hacked-bybit-as-details-of-1-5b-heist-emerge/">FBI Says North Korea Hacked Bybit as Details of $1.5B Heist Emerge</a></li><li><a title="FBI alert on $1.5b crypto heist" rel="nofollow" href="https://www.ic3.gov/PSA/2025/PSA250226">FBI alert on $1.5b crypto heist</a></li><li><a title="CISA report on TraderTraitor " rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a">CISA report on TraderTraitor </a></li><li><a title="Bybit launches bug bounty program" rel="nofollow" href="https://www.bybit.com/en/press/post/bybit-launches-recovery-bounty-program-with-rewards-up-to-10-of-stolen-funds-bltcd3ebbb9445d5b74">Bybit launches bug bounty program</a></li><li><a title="Lazarus Bounty  " rel="nofollow" href="https://www.lazarusbounty.com/en/">Lazarus Bounty  </a></li><li><a title="Cellebrite zero-day exploit used to target phone of Serbian student activist " rel="nofollow" href="https://securitylab.amnesty.org/latest/2025/02/cellebrite-zero-day-exploit-used-to-target-phone-of-serbian-student-activist/">Cellebrite zero-day exploit used to target phone of Serbian student activist </a></li><li><a title="Trump administration retreats in fight against Russian cyber threats" rel="nofollow" href="https://www.theguardian.com/us-news/2025/feb/28/trump-russia-hacking-cyber-security">Trump administration retreats in fight against Russian cyber threats</a></li><li><a title="Hegseth orders Cyber Command to stand down on Russia planning" rel="nofollow" href="https://therecord.media/hegseth-orders-cyber-command-stand-down-russia-planning">Hegseth orders Cyber Command to stand down on Russia planning</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 36</strong>: Ryan and Juanito join the show from the RE//verse conference with discussion on Natalie Silvanovic’s keynote on hunting for bugs in mobile messengers, the thrill of looking at exposed attack surfaces and the grueling “losses” bug hunters endure before a breakthrough. </p>

<p>We also cover the latest on the $1.4 billion ByBit hack pinned on the Lazarus Group and the malicious JavaScript supply chain attack at the center of the cryptocurrency heist. Plus, the ethical gray zones of tethered exploits via Cellebrite, the whiplash of AI-driven threat intel, and the looming pivot in U.S. cyber policy signaling a stand-down on Russia-focused ops. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1fIXGfKfpyh0ltjAvW31z-g1fGhQvtMV6SsEusbZlJo0/edit?tab=t.0#heading=h.m2k4a9q509q9">Transcript (unedited, AI-generated)</a></li><li><a title="RE//verse Conference" rel="nofollow" href="https://re-verse.io/">RE//verse Conference</a></li><li><a title="FBI Says North Korea Hacked Bybit as Details of $1.5B Heist Emerge" rel="nofollow" href="https://www.securityweek.com/fbi-says-north-korea-hacked-bybit-as-details-of-1-5b-heist-emerge/">FBI Says North Korea Hacked Bybit as Details of $1.5B Heist Emerge</a></li><li><a title="FBI alert on $1.5b crypto heist" rel="nofollow" href="https://www.ic3.gov/PSA/2025/PSA250226">FBI alert on $1.5b crypto heist</a></li><li><a title="CISA report on TraderTraitor " rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a">CISA report on TraderTraitor </a></li><li><a title="Bybit launches bug bounty program" rel="nofollow" href="https://www.bybit.com/en/press/post/bybit-launches-recovery-bounty-program-with-rewards-up-to-10-of-stolen-funds-bltcd3ebbb9445d5b74">Bybit launches bug bounty program</a></li><li><a title="Lazarus Bounty  " rel="nofollow" href="https://www.lazarusbounty.com/en/">Lazarus Bounty  </a></li><li><a title="Cellebrite zero-day exploit used to target phone of Serbian student activist " rel="nofollow" href="https://securitylab.amnesty.org/latest/2025/02/cellebrite-zero-day-exploit-used-to-target-phone-of-serbian-student-activist/">Cellebrite zero-day exploit used to target phone of Serbian student activist </a></li><li><a title="Trump administration retreats in fight against Russian cyber threats" rel="nofollow" href="https://www.theguardian.com/us-news/2025/feb/28/trump-russia-hacking-cyber-security">Trump administration retreats in fight against Russian cyber threats</a></li><li><a title="Hegseth orders Cyber Command to stand down on Russia planning" rel="nofollow" href="https://therecord.media/hegseth-orders-cyber-command-stand-down-russia-planning">Hegseth orders Cyber Command to stand down on Russia planning</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>North Korea's biggest ever crypto heist: $1.4B stolen from Bybit</title>
  <link>http://securityconversations.fireside.fm/north-korea-biggest-crypto-heist-apple-icloud-backups</link>
  <guid isPermaLink="false">55aed9b5-d21a-47d5-8be2-1b104468b4fe</guid>
  <pubDate>Sun, 23 Feb 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/55aed9b5-d21a-47d5-8be2-1b104468b4fe.mp3" length="102684885" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 35: Juanito is live from DistrictCon with notes on discussion of an elusive iOS zero-day by a company called QuaDream and Apple’s controversial removal of iCloud backup end-to-end encryption in the UK. We also cover a staggering $1.4 billion hack by the Lazarus Group against Bybit, new angles in NSA-linked cyber-espionage against China’s top universities, Chinese hacking gangs moonlighting as ransomware criminals, and Russian APTs abusing Signal’s “linked devices” feature. Plus, Costin explains Microsoft’s quantum computing breakthrough.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:07:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/5/55aed9b5-d21a-47d5-8be2-1b104468b4fe/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 35: Juanito is live from DistrictCon with notes on discussion of an elusive iOS zero-day by a company called QuaDream and Apple’s controversial removal of iCloud backup end-to-end encryption in the UK.  We also cover a staggering $1.4 billion hack by the Lazarus Group against Bybit, new angles in NSA-linked cyber-espionage against China’s top universities, Chinese hacking gangs moonlighting as ransomware criminals, and Russian APTs abusing Signal’s “linked devices” feature. Plus, Costin explains Microsoft’s quantum computing breakthrough.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Citizen Lab, QuaDream, Apple, iCloud, Citizen Lab, Microsoft, Lazarus, ByBit, NSA, China, Russia, Signal, Quantum</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 35</strong>: Juanito is live from DistrictCon with notes on discussion of an elusive iOS zero-day by a company called QuaDream and Apple’s controversial removal of iCloud backup end-to-end encryption in the UK.  We also cover a staggering $1.4 billion hack by the Lazarus Group against Bybit, new angles in NSA-linked cyber-espionage against China’s top universities, Chinese hacking gangs moonlighting as ransomware criminals, and Russian APTs abusing Signal’s “linked devices” feature. Plus, Costin explains Microsoft’s quantum computing breakthrough.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1ZDN0kPbt0SY0cL2draq1L0347ZKSmMAoIVynCOz-1ns/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="DistrictCon: Dissecting a QuaDream iOS zero-day" rel="nofollow" href="https://www.districtcon.org/bios-and-talks-2025/sweetquadreams-or-nightmare-before-christmas">DistrictCon: Dissecting a QuaDream iOS zero-day</a></li><li><a title="Unpacking the UK government&#39;s secret iCloud backdoor demand" rel="nofollow" href="https://securityconversations.com/episode/unpacking-the-uk-governments-secret-icloud-backdoor-demand/">Unpacking the UK government's secret iCloud backdoor demand</a></li><li><a title="U.K. orders Apple to let it spy on users’ encrypted accounts" rel="nofollow" href="https://archive.ph/E6l15">U.K. orders Apple to let it spy on users’ encrypted accounts</a></li><li><a title="Apple Pulls Advanced Data Protection for New UK Users Amid Backdoor Demand" rel="nofollow" href="https://www.securityweek.com/apple-pulls-advanced-data-protection-for-new-uk-users-amid-backdoor-demand/">Apple Pulls Advanced Data Protection for New UK Users Amid Backdoor Demand</a></li><li><a title="Bybit Sees Over $4 Billion ‘Bank Run’ After Crypto’s Biggest Hack" rel="nofollow" href="https://www.coindesk.com/business/2025/02/22/bybit-sees-over-usd4-billion-bank-run-after-crypto-s-biggest-hack">Bybit Sees Over $4 Billion ‘Bank Run’ After Crypto’s Biggest Hack</a></li><li><a title="ByBit CEO explains crypto heist" rel="nofollow" href="https://x.com/benbybit/status/1892963530422505586">ByBit CEO explains crypto heist</a></li><li><a title="iVerify on Pegasus infections" rel="nofollow" href="https://iverify.io/blog/how-democratizing-threat-hunting-is-changing-mobile-security">iVerify on Pegasus infections</a></li><li><a title="Is there a Pangu Team/i-SOON connection?" rel="nofollow" href="https://nattothoughts.substack.com/p/the-pangu-teamios-jailbreak-and-vulnerability">Is there a Pangu Team/i-SOON connection?</a></li><li><a title="Russian hackers actively targeting Signal Messenger" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger">Russian hackers actively targeting Signal Messenger</a></li><li><a title="How Russian APTs abuse Signal &#39;linked devices&#39; for real-time spying" rel="nofollow" href="https://www.securityweek.com/how-russian-hackers-are-exploiting-signals-linked-devices-for-real-time-spying/">How Russian APTs abuse Signal 'linked devices' for real-time spying</a></li><li><a title="Cisco Talos: In the midst of a Typhoon" rel="nofollow" href="https://blog.talosintelligence.com/salt-typhoon-analysis/">Cisco Talos: In the midst of a Typhoon</a></li><li><a title="Satya Nadella: Reflections on a quantum computing breakthrough" rel="nofollow" href="https://x.com/satyanadella/status/1892242895094313420">Satya Nadella: Reflections on a quantum computing breakthrough</a></li><li><a title="Taiwan wants to ban Fortinet, Zoom" rel="nofollow" href="https://www.taipeitimes.com/News/taiwan/archives/2020/06/18/2003738438">Taiwan wants to ban Fortinet, Zoom</a></li><li><a title="Pangu Team Bvp47 report" rel="nofollow" href="https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf">Pangu Team Bvp47 report</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 35</strong>: Juanito is live from DistrictCon with notes on discussion of an elusive iOS zero-day by a company called QuaDream and Apple’s controversial removal of iCloud backup end-to-end encryption in the UK.  We also cover a staggering $1.4 billion hack by the Lazarus Group against Bybit, new angles in NSA-linked cyber-espionage against China’s top universities, Chinese hacking gangs moonlighting as ransomware criminals, and Russian APTs abusing Signal’s “linked devices” feature. Plus, Costin explains Microsoft’s quantum computing breakthrough.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1ZDN0kPbt0SY0cL2draq1L0347ZKSmMAoIVynCOz-1ns/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="DistrictCon: Dissecting a QuaDream iOS zero-day" rel="nofollow" href="https://www.districtcon.org/bios-and-talks-2025/sweetquadreams-or-nightmare-before-christmas">DistrictCon: Dissecting a QuaDream iOS zero-day</a></li><li><a title="Unpacking the UK government&#39;s secret iCloud backdoor demand" rel="nofollow" href="https://securityconversations.com/episode/unpacking-the-uk-governments-secret-icloud-backdoor-demand/">Unpacking the UK government's secret iCloud backdoor demand</a></li><li><a title="U.K. orders Apple to let it spy on users’ encrypted accounts" rel="nofollow" href="https://archive.ph/E6l15">U.K. orders Apple to let it spy on users’ encrypted accounts</a></li><li><a title="Apple Pulls Advanced Data Protection for New UK Users Amid Backdoor Demand" rel="nofollow" href="https://www.securityweek.com/apple-pulls-advanced-data-protection-for-new-uk-users-amid-backdoor-demand/">Apple Pulls Advanced Data Protection for New UK Users Amid Backdoor Demand</a></li><li><a title="Bybit Sees Over $4 Billion ‘Bank Run’ After Crypto’s Biggest Hack" rel="nofollow" href="https://www.coindesk.com/business/2025/02/22/bybit-sees-over-usd4-billion-bank-run-after-crypto-s-biggest-hack">Bybit Sees Over $4 Billion ‘Bank Run’ After Crypto’s Biggest Hack</a></li><li><a title="ByBit CEO explains crypto heist" rel="nofollow" href="https://x.com/benbybit/status/1892963530422505586">ByBit CEO explains crypto heist</a></li><li><a title="iVerify on Pegasus infections" rel="nofollow" href="https://iverify.io/blog/how-democratizing-threat-hunting-is-changing-mobile-security">iVerify on Pegasus infections</a></li><li><a title="Is there a Pangu Team/i-SOON connection?" rel="nofollow" href="https://nattothoughts.substack.com/p/the-pangu-teamios-jailbreak-and-vulnerability">Is there a Pangu Team/i-SOON connection?</a></li><li><a title="Russian hackers actively targeting Signal Messenger" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger">Russian hackers actively targeting Signal Messenger</a></li><li><a title="How Russian APTs abuse Signal &#39;linked devices&#39; for real-time spying" rel="nofollow" href="https://www.securityweek.com/how-russian-hackers-are-exploiting-signals-linked-devices-for-real-time-spying/">How Russian APTs abuse Signal 'linked devices' for real-time spying</a></li><li><a title="Cisco Talos: In the midst of a Typhoon" rel="nofollow" href="https://blog.talosintelligence.com/salt-typhoon-analysis/">Cisco Talos: In the midst of a Typhoon</a></li><li><a title="Satya Nadella: Reflections on a quantum computing breakthrough" rel="nofollow" href="https://x.com/satyanadella/status/1892242895094313420">Satya Nadella: Reflections on a quantum computing breakthrough</a></li><li><a title="Taiwan wants to ban Fortinet, Zoom" rel="nofollow" href="https://www.taipeitimes.com/News/taiwan/archives/2020/06/18/2003738438">Taiwan wants to ban Fortinet, Zoom</a></li><li><a title="Pangu Team Bvp47 report" rel="nofollow" href="https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf">Pangu Team Bvp47 report</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>An 'extremely sophisticated' iPhone hack; Google flags major AMD microcode bug</title>
  <link>http://securityconversations.fireside.fm/iphone-exploited-0day-amd-microcode</link>
  <guid isPermaLink="false">5ba11788-5a89-4134-81c1-fae481c8c05f</guid>
  <pubDate>Sat, 15 Feb 2025 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/5ba11788-5a89-4134-81c1-fae481c8c05f.mp3" length="69262992" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 34: We dig into the latest exploited Apple iPhone zero-day (USB Restricted Mode bypass), an AMD microcode flaw so serious it’s not being fully disclosed, a barrage of Patch Tuesday updates, the helpless nature of trying to defend corporate networks, Russian threat actor movements, and fresh intel from Rapid7, Volexity, and Microsoft.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>1:25:12</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/5/5ba11788-5a89-4134-81c1-fae481c8c05f/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 34: We dig into the latest exploited Apple iPhone zero-day (USB Restricted Mode bypass), an AMD microcode flaw so serious it’s not being fully disclosed, a barrage of Patch Tuesday updates, the helpless nature of trying to defend corporate networks, Russian threat actor movements, and fresh intel from Rapid7, Volexity, and Microsoft.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>apple, zero-day, patch tuesday, microsoft, beyondtrust, rapid7, amd, microcode, binarly, google, MSTIC, china, russia, CrowdStrike</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 34</strong>: We dig into the latest exploited Apple iPhone zero-day (USB Restricted Mode bypass), an AMD microcode flaw so serious it’s not being fully disclosed, a barrage of Patch Tuesday updates, the helpless nature of trying to defend corporate networks, Russian threat actor movements, and fresh intel from Rapid7, Volexity, and Microsoft.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1aYtBxxmypz4Tnjf4p7by8urvQ15CISg-xYC_D0_yCCU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Apple iOS 18.3.1 zero-day bulletin" rel="nofollow" href="https://support.apple.com/en-us/122174">Apple iOS 18.3.1 zero-day bulletin</a></li><li><a title="Apple Says iPhone USB Restricted Mode Exploited in ‘Extremely Sophisticated’ Attack" rel="nofollow" href="https://www.securityweek.com/apple-confirms-usb-restricted-mode-exploited-in-extremely-sophisticated-attack/">Apple Says iPhone USB Restricted Mode Exploited in ‘Extremely Sophisticated’ Attack</a></li><li><a title="Quarkslab: Analysis of USB Restricted Mode bypass (CVE-2025-24200)" rel="nofollow" href="https://blog.quarkslab.com/first-analysis-of-apples-usb-restricted-mode-bypass-cve-2025-24200.html">Quarkslab: Analysis of USB Restricted Mode bypass (CVE-2025-24200)</a></li><li><a title="ZDI Patch Tuesday recap (exploited Windows 0days)" rel="nofollow" href="https://www.zerodayinitiative.com/blog/2025/2/11/the-february-2025-security-update-review">ZDI Patch Tuesday recap (exploited Windows 0days)</a></li><li><a title="The BadPilot campaign (Seashell Blizzard subgroup)" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/02/12/the-badpilot-campaign-seashell-blizzard-subgroup-conducts-multiyear-global-access-operation/">The BadPilot campaign (Seashell Blizzard subgroup)</a></li><li><a title="Rapid7 on PostgreSQL zero-day linked to BeyondTrust 0days" rel="nofollow" href="https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis">Rapid7 on PostgreSQL zero-day linked to BeyondTrust 0days</a></li><li><a title="PostgreSQL 0day advisory (CVE-2025-1094)" rel="nofollow" href="https://www.postgresql.org/support/security/CVE-2025-1094/">PostgreSQL 0day advisory (CVE-2025-1094)</a></li><li><a title="Google partial disclosure of high-risk flaw in AMD microcode" rel="nofollow" href="https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w">Google partial disclosure of high-risk flaw in AMD microcode</a></li><li><a title="AMD SEV Confidential Computing Vulnerability (CVE-2024-56161)" rel="nofollow" href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html">AMD SEV Confidential Computing Vulnerability (CVE-2024-56161)</a></li><li><a title="Fortinet documents another exploited 0day" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535">Fortinet documents another exploited 0day</a></li><li><a title="Storm-2372 conducts device code phishing campaign" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/">Storm-2372 conducts device code phishing campaign</a></li><li><a title="CrowdStrike on malware naming schemes" rel="nofollow" href="https://www.crowdstrike.com/en-us/blog/how-adversary-taxonomies-strengthen-global-security/">CrowdStrike on malware naming schemes</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 34</strong>: We dig into the latest exploited Apple iPhone zero-day (USB Restricted Mode bypass), an AMD microcode flaw so serious it’s not being fully disclosed, a barrage of Patch Tuesday updates, the helpless nature of trying to defend corporate networks, Russian threat actor movements, and fresh intel from Rapid7, Volexity, and Microsoft.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1aYtBxxmypz4Tnjf4p7by8urvQ15CISg-xYC_D0_yCCU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Apple iOS 18.3.1 zero-day bulletin" rel="nofollow" href="https://support.apple.com/en-us/122174">Apple iOS 18.3.1 zero-day bulletin</a></li><li><a title="Apple Says iPhone USB Restricted Mode Exploited in ‘Extremely Sophisticated’ Attack" rel="nofollow" href="https://www.securityweek.com/apple-confirms-usb-restricted-mode-exploited-in-extremely-sophisticated-attack/">Apple Says iPhone USB Restricted Mode Exploited in ‘Extremely Sophisticated’ Attack</a></li><li><a title="Quarkslab: Analysis of USB Restricted Mode bypass (CVE-2025-24200)" rel="nofollow" href="https://blog.quarkslab.com/first-analysis-of-apples-usb-restricted-mode-bypass-cve-2025-24200.html">Quarkslab: Analysis of USB Restricted Mode bypass (CVE-2025-24200)</a></li><li><a title="ZDI Patch Tuesday recap (exploited Windows 0days)" rel="nofollow" href="https://www.zerodayinitiative.com/blog/2025/2/11/the-february-2025-security-update-review">ZDI Patch Tuesday recap (exploited Windows 0days)</a></li><li><a title="The BadPilot campaign (Seashell Blizzard subgroup)" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/02/12/the-badpilot-campaign-seashell-blizzard-subgroup-conducts-multiyear-global-access-operation/">The BadPilot campaign (Seashell Blizzard subgroup)</a></li><li><a title="Rapid7 on PostgreSQL zero-day linked to BeyondTrust 0days" rel="nofollow" href="https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis">Rapid7 on PostgreSQL zero-day linked to BeyondTrust 0days</a></li><li><a title="PostgreSQL 0day advisory (CVE-2025-1094)" rel="nofollow" href="https://www.postgresql.org/support/security/CVE-2025-1094/">PostgreSQL 0day advisory (CVE-2025-1094)</a></li><li><a title="Google partial disclosure of high-risk flaw in AMD microcode" rel="nofollow" href="https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w">Google partial disclosure of high-risk flaw in AMD microcode</a></li><li><a title="AMD SEV Confidential Computing Vulnerability (CVE-2024-56161)" rel="nofollow" href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html">AMD SEV Confidential Computing Vulnerability (CVE-2024-56161)</a></li><li><a title="Fortinet documents another exploited 0day" rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535">Fortinet documents another exploited 0day</a></li><li><a title="Storm-2372 conducts device code phishing campaign" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/">Storm-2372 conducts device code phishing campaign</a></li><li><a title="CrowdStrike on malware naming schemes" rel="nofollow" href="https://www.crowdstrike.com/en-us/blog/how-adversary-taxonomies-strengthen-global-security/">CrowdStrike on malware naming schemes</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Unpacking the UK government's secret iCloud backdoor demand</title>
  <link>http://securityconversations.fireside.fm/apple-cloud-back-up-backdoor</link>
  <guid isPermaLink="false">6b31620f-d604-4f80-b4b8-9c3a1acc658f</guid>
  <pubDate>Sat, 08 Feb 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/6b31620f-d604-4f80-b4b8-9c3a1acc658f.mp3" length="119291664" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 33:  In this episode, we unpack the UK government's secret push for backdoor access to encrypted iCloud data, Apple’s approach to iCloud encryption, and the broader implications for privacy and security on a global scale.  Plus, how security agencies handle zero-day vulnerabilities, surveillance spyware and mercenary hacking, and TikTok-powered election disinformation and interference.

From wormable exploits like Eternal Bue to the realities of AI-based spying, the episode offers a detailed look into how government oversight, private sector collaboration, and shifting market forces have reshaped the way we think about cybersecurity.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:22:42</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/6b31620f-d604-4f80-b4b8-9c3a1acc658f/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 33:  In this episode, we unpack the UK government's secret push for backdoor access to encrypted iCloud data, Apple’s approach to iCloud encryption, and the broader implications for privacy and security on a global scale.  Plus, how security agencies handle zero-day vulnerabilities, surveillance spyware and mercenary hacking, and TikTok-powered election disinformation and interference.
From wormable exploits like Eternal Bue to the realities of AI-based spying, the episode offers a detailed look into how government oversight, private sector collaboration, and shifting market forces have reshaped the way we think about cybersecurity.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>United Kingdom, iCloud, backdoor, Apple, Google, Android, zero-day, VEP, Romania elections</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 33</strong>:  In this episode, we unpack the UK government&#39;s secret push for backdoor access to encrypted iCloud data, Apple’s approach to iCloud encryption, and the broader implications for privacy and security on a global scale.  Plus, how security agencies handle zero-day vulnerabilities, surveillance spyware and mercenary hacking, and TikTok-powered election disinformation and interference.</p>

<p>From wormable exploits like Eternal Bue to the realities of AI-based spying, the episode offers a detailed look into how government oversight, private sector collaboration, and shifting market forces have reshaped the way we think about cybersecurity.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/14ISO1W7s7togIynY8gUu1EkmMELRFvsCJeMSTDW3aBU/edit?tab=t.0#heading=h.jbbo41oysex">Transcript (unedited, AI-generated)</a></li><li><a title="UK orders Apple to let it spy on users’ iCloud data" rel="nofollow" href="https://archive.ph/E6l15">UK orders Apple to let it spy on users’ iCloud data</a></li><li><a title="How to turn on Advanced Data Protection for iCloud" rel="nofollow" href="https://support.apple.com/en-us/108756">How to turn on Advanced Data Protection for iCloud</a></li><li><a title="Kim Zetter: US government disclosed 39 zero-days in 2023" rel="nofollow" href="https://www.zetter-zeroday.com/u-s-government-disclosed-39-zero-day-vulnerabilities-in-2023-per-first-ever-report/">Kim Zetter: US government disclosed 39 zero-days in 2023</a></li><li><a title="CISA alert on Trimble zero-day exploitation" rel="nofollow" href="https://www.cisa.gov/news-events/alerts/2025/02/07/trimble-releases-security-updates-address-vulnerability-cityworks-software">CISA alert on Trimble zero-day exploitation</a></li><li><a title="France VIGINUM report on foreign digital election interference" rel="nofollow" href="https://www.diplomatie.gouv.fr/en/french-foreign-policy/digital-diplomacy/news/article/foreign-digital-interference-publication-of-the-viginum-report-on-information">France VIGINUM report on foreign digital election interference</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 33</strong>:  In this episode, we unpack the UK government&#39;s secret push for backdoor access to encrypted iCloud data, Apple’s approach to iCloud encryption, and the broader implications for privacy and security on a global scale.  Plus, how security agencies handle zero-day vulnerabilities, surveillance spyware and mercenary hacking, and TikTok-powered election disinformation and interference.</p>

<p>From wormable exploits like Eternal Bue to the realities of AI-based spying, the episode offers a detailed look into how government oversight, private sector collaboration, and shifting market forces have reshaped the way we think about cybersecurity.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/14ISO1W7s7togIynY8gUu1EkmMELRFvsCJeMSTDW3aBU/edit?tab=t.0#heading=h.jbbo41oysex">Transcript (unedited, AI-generated)</a></li><li><a title="UK orders Apple to let it spy on users’ iCloud data" rel="nofollow" href="https://archive.ph/E6l15">UK orders Apple to let it spy on users’ iCloud data</a></li><li><a title="How to turn on Advanced Data Protection for iCloud" rel="nofollow" href="https://support.apple.com/en-us/108756">How to turn on Advanced Data Protection for iCloud</a></li><li><a title="Kim Zetter: US government disclosed 39 zero-days in 2023" rel="nofollow" href="https://www.zetter-zeroday.com/u-s-government-disclosed-39-zero-day-vulnerabilities-in-2023-per-first-ever-report/">Kim Zetter: US government disclosed 39 zero-days in 2023</a></li><li><a title="CISA alert on Trimble zero-day exploitation" rel="nofollow" href="https://www.cisa.gov/news-events/alerts/2025/02/07/trimble-releases-security-updates-address-vulnerability-cityworks-software">CISA alert on Trimble zero-day exploitation</a></li><li><a title="France VIGINUM report on foreign digital election interference" rel="nofollow" href="https://www.diplomatie.gouv.fr/en/french-foreign-policy/digital-diplomacy/news/article/foreign-digital-interference-publication-of-the-viginum-report-on-information">France VIGINUM report on foreign digital election interference</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Inside the DeepSeek AI existential crisis, Chinese 'backdoor' in medical devices</title>
  <link>http://securityconversations.fireside.fm/inside-the-deepseek-ai-existential-crisis</link>
  <guid isPermaLink="false">89f0f4d2-96eb-4a23-b08e-ebd2a9b550a1</guid>
  <pubDate>Fri, 31 Jan 2025 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/89f0f4d2-96eb-4a23-b08e-ebd2a9b550a1.mp3" length="110179568" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 32: In this episode, we rummage through the DeepSeek hype and break down what makes it different from OpenAI’s models, why it’s stirring up existential controversies, and what it means for the broader tech landscape. We get into the privacy concerns, the geo-political implications, how AI models handle data, the ongoing debate over IP theft and innovation, and the challenges that come with a Chinese company shipping an open-source alternative.

Beyond AI, we dig into some of the latest headlines; from a Chinese ‘backdoor’ in medical devices, problems with CISA’s backdoor bulletin, the risks of insecure IoT, phishing attacks on influencers, and ongoing battles over censorship in the VPN space. We also touch on WhatsApp catching spyware vendor Paragon Solutions and potential shifts in U.S. government policy on commercial mercenary hacking and surveillance companies.  

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade.</itunes:subtitle>
  <itunes:duration>2:19:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/8/89f0f4d2-96eb-4a23-b08e-ebd2a9b550a1/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 32: In this episode, we rummage through the DeepSeek hype and break down what makes it different from OpenAI’s models, why it’s stirring up existential controversies, and what it means for the broader tech landscape. We get into the privacy concerns, the geo-political implications, how AI models handle data, the ongoing debate over IP theft and innovation, and the challenges that come with a Chinese company shipping an open-source alternative.
Beyond AI, we dig into some of the latest headlines; from a Chinese ‘backdoor’ in medical devices, problems with CISA’s backdoor bulletin, the risks of insecure IoT, phishing attacks on influencers, and ongoing battles over censorship in the VPN space. We also touch on WhatsApp catching spyware vendor Paragon Solutions and potential shifts in U.S. government policy on commercial mercenary hacking and surveillance companies.  
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>DeepSeek, AI, OpenAI, privacy, IP theft, China, LLMs, Google, Mandiant, CISA, VPN, backdoor</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 32</strong>: In this episode, we rummage through the DeepSeek hype and break down what makes it different from OpenAI’s models, why it’s stirring up existential controversies, and what it means for the broader tech landscape. We get into the privacy concerns, the geo-political implications, how AI models handle data, the ongoing debate over IP theft and innovation, and the challenges that come with a Chinese company shipping an open-source alternative.</p>

<p>Beyond AI, we dig into some of the latest headlines; from a Chinese ‘backdoor’ in medical devices, problems with CISA’s backdoor bulletin, the risks of insecure IoT, phishing attacks on influencers, and ongoing battles over censorship in the VPN space. We also touch on WhatsApp catching spyware vendor Paragon Solutions and potential shifts in U.S. government policy on commercial mercenary hacking and surveillance companies.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Vg9du9EcqqdpQ-p4QJIcRu84XynZ5pFSAn8Q2CAoij8/edit?tab=t.0#heading=h.ywmge3vqzj3r">Transcript (unedited, AI-generated)</a></li><li><a title="DeepSeek Privacy Policy" rel="nofollow" href="https://archive.ph/PS9lR">DeepSeek Privacy Policy</a></li><li><a title="White House evaluates effect of China AI app DeepSeek on national security" rel="nofollow" href="https://www.reuters.com/technology/artificial-intelligence/white-house-evaluates-china-ai-app-deepseeks-affect-national-security-official-2025-01-28/">White House evaluates effect of China AI app DeepSeek on national security</a></li><li><a title="Why ‘Distillation’ Has Become the Scariest Word for AI Companies" rel="nofollow" href="https://archive.ph/uLjU4">Why ‘Distillation’ Has Become the Scariest Word for AI Companies</a></li><li><a title="Microsoft Probing If DeepSeek-Linked Group Improperly Obtained OpenAI Data" rel="nofollow" href="https://archive.ph/QAZNI">Microsoft Probing If DeepSeek-Linked Group Improperly Obtained OpenAI Data</a></li><li><a title="U.S. Navy bans use of DeepSeek AI" rel="nofollow" href="https://www.cnbc.com/2025/01/28/us-navy-restricts-use-of-deepseek-ai-imperative-to-avoid-using.html">U.S. Navy bans use of DeepSeek AI</a></li><li><a title="Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information" rel="nofollow" href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak">Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information</a></li><li><a title="ScatterBrain: Unmasking the Shadow of PoisonPlug&#39;s Obfuscator" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/scatterbrain-unmasking-poisonplug-obfuscator">ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator</a></li><li><a title="ScatterBrain: Deobfuscation library for PoisionPlug.SHADOW&#39;s ScatterBrain obfuscator" rel="nofollow" href="https://github.com/mandiant/poisonplug-scatterbrain">ScatterBrain: Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator</a></li><li><a title="CISA, FDA Warn of Dangerous Backdoor in Contec Patient Monitors" rel="nofollow" href="https://www.securityweek.com/cisa-fda-warn-of-dangerous-backdoor-in-contec-patient-monitors/">CISA, FDA Warn of Dangerous Backdoor in Contec Patient Monitors</a></li><li><a title="CISA advisory: Contec CMS8000 contains a backdoor" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2025-01/fact-sheet-contec-cms8000-contains-a-backdoor-508c.pdf">CISA advisory: Contec CMS8000 contains a backdoor</a></li><li><a title="Contec CMS 8000 product manual" rel="nofollow" href="https://www.gimaitaly.com/DocumentiGIMA/Manuali/EN/M35152EN.pdf">Contec CMS 8000 product manual</a></li><li><a title="NordVPN NordWhisper" rel="nofollow" href="https://nordvpn.com/blog/nordwhisper-protocol/">NordVPN NordWhisper</a></li><li><a title="WhatsApp: Spyware company Paragon targeted users in two dozen countries" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/metas-whatsapp-says-israeli-spyware-company-paragon-targeted-scores-users-2025-01-31/">WhatsApp: Spyware company Paragon targeted users in two dozen countries</a></li><li><a title="X Phishing Campaign Targeting High Profile Accounts, Promoting Crypto Scams" rel="nofollow" href="https://www.sentinelone.com/labs/phishing-on-x-high-profile-account-targeting-campaign-returns/">X Phishing Campaign Targeting High Profile Accounts, Promoting Crypto Scams</a></li><li><a title="LABScon24: Follow the Money -- CCP’s Ownership of Firms Investing in the USA (Elly Rostoum)" rel="nofollow" href="https://www.youtube.com/watch?v=glyHKbaS4Fs&amp;ab_channel=SentinelOne">LABScon24: Follow the Money -- CCP’s Ownership of Firms Investing in the USA (Elly Rostoum)</a></li><li><a title="Binarly Post-Quantum Readiness Technology" rel="nofollow" href="https://www.binarly.io/blog/binarly-transparency-platform-v2-7-propels-enterprises-toward-post-quantum-readiness">Binarly Post-Quantum Readiness Technology</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 32</strong>: In this episode, we rummage through the DeepSeek hype and break down what makes it different from OpenAI’s models, why it’s stirring up existential controversies, and what it means for the broader tech landscape. We get into the privacy concerns, the geo-political implications, how AI models handle data, the ongoing debate over IP theft and innovation, and the challenges that come with a Chinese company shipping an open-source alternative.</p>

<p>Beyond AI, we dig into some of the latest headlines; from a Chinese ‘backdoor’ in medical devices, problems with CISA’s backdoor bulletin, the risks of insecure IoT, phishing attacks on influencers, and ongoing battles over censorship in the VPN space. We also touch on WhatsApp catching spyware vendor Paragon Solutions and potential shifts in U.S. government policy on commercial mercenary hacking and surveillance companies.  </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Vg9du9EcqqdpQ-p4QJIcRu84XynZ5pFSAn8Q2CAoij8/edit?tab=t.0#heading=h.ywmge3vqzj3r">Transcript (unedited, AI-generated)</a></li><li><a title="DeepSeek Privacy Policy" rel="nofollow" href="https://archive.ph/PS9lR">DeepSeek Privacy Policy</a></li><li><a title="White House evaluates effect of China AI app DeepSeek on national security" rel="nofollow" href="https://www.reuters.com/technology/artificial-intelligence/white-house-evaluates-china-ai-app-deepseeks-affect-national-security-official-2025-01-28/">White House evaluates effect of China AI app DeepSeek on national security</a></li><li><a title="Why ‘Distillation’ Has Become the Scariest Word for AI Companies" rel="nofollow" href="https://archive.ph/uLjU4">Why ‘Distillation’ Has Become the Scariest Word for AI Companies</a></li><li><a title="Microsoft Probing If DeepSeek-Linked Group Improperly Obtained OpenAI Data" rel="nofollow" href="https://archive.ph/QAZNI">Microsoft Probing If DeepSeek-Linked Group Improperly Obtained OpenAI Data</a></li><li><a title="U.S. Navy bans use of DeepSeek AI" rel="nofollow" href="https://www.cnbc.com/2025/01/28/us-navy-restricts-use-of-deepseek-ai-imperative-to-avoid-using.html">U.S. Navy bans use of DeepSeek AI</a></li><li><a title="Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information" rel="nofollow" href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak">Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information</a></li><li><a title="ScatterBrain: Unmasking the Shadow of PoisonPlug&#39;s Obfuscator" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/scatterbrain-unmasking-poisonplug-obfuscator">ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator</a></li><li><a title="ScatterBrain: Deobfuscation library for PoisionPlug.SHADOW&#39;s ScatterBrain obfuscator" rel="nofollow" href="https://github.com/mandiant/poisonplug-scatterbrain">ScatterBrain: Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator</a></li><li><a title="CISA, FDA Warn of Dangerous Backdoor in Contec Patient Monitors" rel="nofollow" href="https://www.securityweek.com/cisa-fda-warn-of-dangerous-backdoor-in-contec-patient-monitors/">CISA, FDA Warn of Dangerous Backdoor in Contec Patient Monitors</a></li><li><a title="CISA advisory: Contec CMS8000 contains a backdoor" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2025-01/fact-sheet-contec-cms8000-contains-a-backdoor-508c.pdf">CISA advisory: Contec CMS8000 contains a backdoor</a></li><li><a title="Contec CMS 8000 product manual" rel="nofollow" href="https://www.gimaitaly.com/DocumentiGIMA/Manuali/EN/M35152EN.pdf">Contec CMS 8000 product manual</a></li><li><a title="NordVPN NordWhisper" rel="nofollow" href="https://nordvpn.com/blog/nordwhisper-protocol/">NordVPN NordWhisper</a></li><li><a title="WhatsApp: Spyware company Paragon targeted users in two dozen countries" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/metas-whatsapp-says-israeli-spyware-company-paragon-targeted-scores-users-2025-01-31/">WhatsApp: Spyware company Paragon targeted users in two dozen countries</a></li><li><a title="X Phishing Campaign Targeting High Profile Accounts, Promoting Crypto Scams" rel="nofollow" href="https://www.sentinelone.com/labs/phishing-on-x-high-profile-account-targeting-campaign-returns/">X Phishing Campaign Targeting High Profile Accounts, Promoting Crypto Scams</a></li><li><a title="LABScon24: Follow the Money -- CCP’s Ownership of Firms Investing in the USA (Elly Rostoum)" rel="nofollow" href="https://www.youtube.com/watch?v=glyHKbaS4Fs&amp;ab_channel=SentinelOne">LABScon24: Follow the Money -- CCP’s Ownership of Firms Investing in the USA (Elly Rostoum)</a></li><li><a title="Binarly Post-Quantum Readiness Technology" rel="nofollow" href="https://www.binarly.io/blog/binarly-transparency-platform-v2-7-propels-enterprises-toward-post-quantum-readiness">Binarly Post-Quantum Readiness Technology</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Death of the CSRB, zero-days storms at the edge, Juniper router backdoors</title>
  <link>http://securityconversations.fireside.fm/zero-day-storms-death-of-crsb</link>
  <guid isPermaLink="false">a8b5e326-37a9-40ab-b769-f92834d95934</guid>
  <pubDate>Fri, 24 Jan 2025 14:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/a8b5e326-37a9-40ab-b769-f92834d95934.mp3" length="91593748" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 31: Dennis Fisher steps in for Ryan Naraine to moderate discussion on a very busy week in cybersecurity. The cast dig into the wave of big research reports, the disbanding of the Cyber Safety Review Board (CSRB), the ongoing flood of exploits targeting security appliances from Ivanti and SonicWall, and the recent Lumen research on Juniper router backdoors. 

Plus, the challenges of coordinating disclosures, the tough realities of intelligence work, and the complex landscape of nation-state attacks -- especially around Chinese threat actors and Western defenses. 

Cast: Dennis Fisher (guest host), Costin Raiu and Juan Andres Guerrero-Saade.

* Ryan Naraine is on work travel.</itunes:subtitle>
  <itunes:duration>1:48:59</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/a8b5e326-37a9-40ab-b769-f92834d95934/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 31: Dennis Fisher steps in for Ryan Naraine to moderate discussion on a very busy week in cybersecurity. The cast dig into the wave of big research reports, the disbanding of the Cyber Safety Review Board (CSRB), the ongoing flood of exploits targeting security appliances from Ivanti and SonicWall, and the recent Lumen research on Juniper router backdoors. 
Plus, the challenges of coordinating disclosures, the tough realities of intelligence work, and the complex landscape of nation-state attacks -- especially around Chinese threat actors and Western defenses. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Dennis Fisher.
Ryan Naraine (https://twitter.com/ryanaraine) in on work travel. 
</description>
  <itunes:keywords>CSRB, CISA, FBI, Ivanti, SonicWall, network appliances, end-of-life devices, APTs, IOCs, YARA, Black Lotus Labs</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 31</strong>: Dennis Fisher steps in for Ryan Naraine to moderate discussion on a very busy week in cybersecurity. The cast dig into the wave of big research reports, the disbanding of the Cyber Safety Review Board (CSRB), the ongoing flood of exploits targeting security appliances from Ivanti and SonicWall, and the recent Lumen research on Juniper router backdoors. </p>

<p>Plus, the challenges of coordinating disclosures, the tough realities of intelligence work, and the complex landscape of nation-state attacks -- especially around Chinese threat actors and Western defenses. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and Dennis Fisher.</p>

<ul>
<li><a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> in on work travel.</li>
</ul><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1qT2olnStWy4-0PWd6KdBNHAG20hJxe83zyGqXO7_B9Y/edit?tab=t.0#heading=h.ywmge3vqzj3r">Transcript (unedited, AI-generated)</a></li><li><a title="DHS Disbands Cyber Safety Review Board, Ending One of CISA’s Few Bright Spots" rel="nofollow" href="https://www.securityweek.com/dhs-disbands-cyber-safety-review-board-ending-one-of-cisas-few-bright-spots/">DHS Disbands Cyber Safety Review Board, Ending One of CISA’s Few Bright Spots</a></li><li><a title="CSRB report on Microsoft Exchange Online Intrusion" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review_of_the_Summer_2023_MEO_Intrusion_Final_508c.pdf">CSRB report on Microsoft Exchange Online Intrusion</a></li><li><a title="Senator Ron Wyden on CSRB disbandment" rel="nofollow" href="https://bsky.app/profile/wyden.senate.gov/post/3lgbvtdltic2h">Senator Ron Wyden on CSRB disbandment</a></li><li><a title="CISA CSRB: good riddance" rel="nofollow" href="https://cybersect.substack.com/p/cisa-csrb-good-riddance">CISA CSRB: good riddance</a></li><li><a title="Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a">Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications</a></li><li><a title="SonicWall confirms new 0day exploited in the wild" rel="nofollow" href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002">SonicWall confirms new 0day exploited in the wild</a></li><li><a title="The J-Magic Show: Magic Packets and Where to Find Them" rel="nofollow" href="https://blog.lumen.com/the-j-magic-show-magic-packets-and-where-to-find-them/">The J-Magic Show: Magic Packets and Where to Find Them</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 31</strong>: Dennis Fisher steps in for Ryan Naraine to moderate discussion on a very busy week in cybersecurity. The cast dig into the wave of big research reports, the disbanding of the Cyber Safety Review Board (CSRB), the ongoing flood of exploits targeting security appliances from Ivanti and SonicWall, and the recent Lumen research on Juniper router backdoors. </p>

<p>Plus, the challenges of coordinating disclosures, the tough realities of intelligence work, and the complex landscape of nation-state attacks -- especially around Chinese threat actors and Western defenses. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and Dennis Fisher.</p>

<ul>
<li><a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> in on work travel.</li>
</ul><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1qT2olnStWy4-0PWd6KdBNHAG20hJxe83zyGqXO7_B9Y/edit?tab=t.0#heading=h.ywmge3vqzj3r">Transcript (unedited, AI-generated)</a></li><li><a title="DHS Disbands Cyber Safety Review Board, Ending One of CISA’s Few Bright Spots" rel="nofollow" href="https://www.securityweek.com/dhs-disbands-cyber-safety-review-board-ending-one-of-cisas-few-bright-spots/">DHS Disbands Cyber Safety Review Board, Ending One of CISA’s Few Bright Spots</a></li><li><a title="CSRB report on Microsoft Exchange Online Intrusion" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review_of_the_Summer_2023_MEO_Intrusion_Final_508c.pdf">CSRB report on Microsoft Exchange Online Intrusion</a></li><li><a title="Senator Ron Wyden on CSRB disbandment" rel="nofollow" href="https://bsky.app/profile/wyden.senate.gov/post/3lgbvtdltic2h">Senator Ron Wyden on CSRB disbandment</a></li><li><a title="CISA CSRB: good riddance" rel="nofollow" href="https://cybersect.substack.com/p/cisa-csrb-good-riddance">CISA CSRB: good riddance</a></li><li><a title="Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a">Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications</a></li><li><a title="SonicWall confirms new 0day exploited in the wild" rel="nofollow" href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002">SonicWall confirms new 0day exploited in the wild</a></li><li><a title="The J-Magic Show: Magic Packets and Where to Find Them" rel="nofollow" href="https://blog.lumen.com/the-j-magic-show-magic-packets-and-where-to-find-them/">The J-Magic Show: Magic Packets and Where to Find Them</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Inside the PlugX malware removal operation, CISA takes victory lap and another Fortinet 0day</title>
  <link>http://securityconversations.fireside.fm/cisa-victory-lap-plugx-removal-tiktok-ban</link>
  <guid isPermaLink="false">f31e117e-f570-453a-862f-604a0314c90b</guid>
  <pubDate>Fri, 17 Jan 2025 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/f31e117e-f570-453a-862f-604a0314c90b.mp3" length="95741011" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 30: We discuss French threat-intel Sekoia creating a portal to handle “sovereign disinfections” of the PlugX malware, CISA leadership taking a victory lap using the ‘Secure by Design’ pledge as a trophy, the new Biden cybersecurity Executive Order, another Fortinet zero-day, the TikTok ban and Ukrainian hackers targeting Russian companies. 

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade</itunes:subtitle>
  <itunes:duration>1:59:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/f31e117e-f570-453a-862f-604a0314c90b/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 30:  We discuss French threat-intel Sekoia creating a portal to handle “sovereign disinfections” of the PlugX malware, CISA leadership taking a victory lap using the ‘Secure by Design’ pledge as a trophy, the new Biden cybersecurity Executive Order, another Fortinet zero-day, the TikTok ban and Ukrainian hackers targeting Russian companies. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Sekoia, PlugX, FBI, China, CISA, Secure by Design Pledge, Jen Easterly, Executive Order, Fortinet, zero-day, TikTok, mobile tracking</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 30</strong>:  We discuss French threat-intel Sekoia creating a portal to handle “sovereign disinfections” of the PlugX malware, CISA leadership taking a victory lap using the ‘Secure by Design’ pledge as a trophy, the new Biden cybersecurity Executive Order, another Fortinet zero-day, the TikTok ban and Ukrainian hackers targeting Russian companies. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1HS3gbpFtueD9eaOkBNbgS5Hg-x7SNSKudF9gx84_qMU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Court-Authorized Operation Removes PlugX Malware from Over 4,200 Infected U.S. Computers" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed">Court-Authorized Operation Removes PlugX Malware from Over 4,200 Infected U.S. Computers</a></li><li><a title="PlugX removal affidavit" rel="nofollow" href="https://www.justice.gov/opa/media/1384136/dl">PlugX removal affidavit</a></li><li><a title="Sekoia -- PlugX worm disinfection campaign" rel="nofollow" href="https://blog.sekoia.io/plugx-worm-disinfection-campaign-feedbacks/">Sekoia -- PlugX worm disinfection campaign</a></li><li><a title="Jen Easterly: Building a secure by Design ecosystem " rel="nofollow" href="https://www.cisa.gov/news-events/news/building-secure-design-ecosystem">Jen Easterly: Building a secure by Design ecosystem </a></li><li><a title="Trump zeroes in on Sean Plankey to lead CISA" rel="nofollow" href="https://www.politico.com/live-updates/2025/01/15/congress/sean-plankey-likely-to-lead-u-s-cyber-agency-00198382">Trump zeroes in on Sean Plankey to lead CISA</a></li><li><a title="Sean Plankey bio" rel="nofollow" href="https://www.sans.org/profiles/sean-plankey/">Sean Plankey bio</a></li><li><a title="Biden cybersecurity executive order" rel="nofollow" href="https://www.whitehouse.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/">Biden cybersecurity executive order</a></li><li><a title="Biden executive order aims to shore up US cyber defenses" rel="nofollow" href="https://apnews.com/article/cybersecurity-biden-trump-china-russia-ai-quantum-3fc53784ad9d1c05d7de85224a762a36">Biden executive order aims to shore up US cyber defenses</a></li><li><a title="Gravy Analytics accused of negligence over location data breach" rel="nofollow" href="https://news.bloomberglaw.com/privacy-and-data-security/gravy-analytics-accused-of-negligence-over-location-data-breach">Gravy Analytics accused of negligence over location data breach</a></li><li><a title="Tracking the mobile trackers (Costin Raiu) - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=EG6sZA1N8NU&amp;ab_channel=OPCDE">Tracking the mobile trackers (Costin Raiu) - YouTube</a></li><li><a title="Russia&#39;s largest platform for state procurement hit by cyberattack from pro-Ukraine group" rel="nofollow" href="https://therecord.media/russian-platform-for-state-procurement-hit-cyberattack">Russia's largest platform for state procurement hit by cyberattack from pro-Ukraine group</a></li><li><a title="New Star Blizzard spear-phishing campaign targets WhatsApp accounts" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/01/16/new-star-blizzard-spear-phishing-campaign-targets-whatsapp-accounts/">New Star Blizzard spear-phishing campaign targets WhatsApp accounts</a></li><li><a title="UK proposes ransomware payment ban" rel="nofollow" href="https://www.gov.uk/government/news/world-leading-proposals-to-protect-businesses-from-cybercrime">UK proposes ransomware payment ban</a></li><li><a title="Fortinet authentication bypass zero-day " rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535">Fortinet authentication bypass zero-day </a></li><li><a title="Fortinet: Deep dive into a Linux rootkit malware" rel="nofollow" href="https://www.fortinet.com/blog/threat-research/deep-dive-into-a-linux-rootkit-malware">Fortinet: Deep dive into a Linux rootkit malware</a></li><li><a title="Bernardo Quintero&#39;s new book on VirusTotal (Spanish-language)" rel="nofollow" href="https://www.amazon.com/Infectado-Spectrum-emprendedor-accidental-Spanish/dp/8409666227/ref=sr_1_1?crid=27KFPUV4ECRH7&amp;dib=eyJ2IjoiMSJ9.RtftyW4qSxl2Q07QPDYz0JgOYLm_jlK0D5e4quXsVNSmjtQQ8abhBlRIA-Nf7U52lLy4zw2gX2NTgPAbcbW6n4rBuiAXNmN3-GgGABAjMjDXf_3a6-W0W9zIyiKdEYRWl2rlphl_tl5MwyE5wHHlBouzn8aE8_GS_Lk478PIl5G-bFxbGPG9Gd8OAzKjHaxqUbf7P4jpSzKvIsumlR5eaI3rVPfdcdYXyLaGM_LpxGk.B0D0HYHfmenDvtslyNwXiMtNFrsxLEiihfv4twDd4t8&amp;dib_tag=se&amp;keywords=bernardo+quintero&amp;qid=1737143167&amp;sprefix=%2Caps%2C143&amp;sr=8-1">Bernardo Quintero's new book on VirusTotal (Spanish-language)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 30</strong>:  We discuss French threat-intel Sekoia creating a portal to handle “sovereign disinfections” of the PlugX malware, CISA leadership taking a victory lap using the ‘Secure by Design’ pledge as a trophy, the new Biden cybersecurity Executive Order, another Fortinet zero-day, the TikTok ban and Ukrainian hackers targeting Russian companies. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1HS3gbpFtueD9eaOkBNbgS5Hg-x7SNSKudF9gx84_qMU/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Court-Authorized Operation Removes PlugX Malware from Over 4,200 Infected U.S. Computers" rel="nofollow" href="https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed">Court-Authorized Operation Removes PlugX Malware from Over 4,200 Infected U.S. Computers</a></li><li><a title="PlugX removal affidavit" rel="nofollow" href="https://www.justice.gov/opa/media/1384136/dl">PlugX removal affidavit</a></li><li><a title="Sekoia -- PlugX worm disinfection campaign" rel="nofollow" href="https://blog.sekoia.io/plugx-worm-disinfection-campaign-feedbacks/">Sekoia -- PlugX worm disinfection campaign</a></li><li><a title="Jen Easterly: Building a secure by Design ecosystem " rel="nofollow" href="https://www.cisa.gov/news-events/news/building-secure-design-ecosystem">Jen Easterly: Building a secure by Design ecosystem </a></li><li><a title="Trump zeroes in on Sean Plankey to lead CISA" rel="nofollow" href="https://www.politico.com/live-updates/2025/01/15/congress/sean-plankey-likely-to-lead-u-s-cyber-agency-00198382">Trump zeroes in on Sean Plankey to lead CISA</a></li><li><a title="Sean Plankey bio" rel="nofollow" href="https://www.sans.org/profiles/sean-plankey/">Sean Plankey bio</a></li><li><a title="Biden cybersecurity executive order" rel="nofollow" href="https://www.whitehouse.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/">Biden cybersecurity executive order</a></li><li><a title="Biden executive order aims to shore up US cyber defenses" rel="nofollow" href="https://apnews.com/article/cybersecurity-biden-trump-china-russia-ai-quantum-3fc53784ad9d1c05d7de85224a762a36">Biden executive order aims to shore up US cyber defenses</a></li><li><a title="Gravy Analytics accused of negligence over location data breach" rel="nofollow" href="https://news.bloomberglaw.com/privacy-and-data-security/gravy-analytics-accused-of-negligence-over-location-data-breach">Gravy Analytics accused of negligence over location data breach</a></li><li><a title="Tracking the mobile trackers (Costin Raiu) - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=EG6sZA1N8NU&amp;ab_channel=OPCDE">Tracking the mobile trackers (Costin Raiu) - YouTube</a></li><li><a title="Russia&#39;s largest platform for state procurement hit by cyberattack from pro-Ukraine group" rel="nofollow" href="https://therecord.media/russian-platform-for-state-procurement-hit-cyberattack">Russia's largest platform for state procurement hit by cyberattack from pro-Ukraine group</a></li><li><a title="New Star Blizzard spear-phishing campaign targets WhatsApp accounts" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/01/16/new-star-blizzard-spear-phishing-campaign-targets-whatsapp-accounts/">New Star Blizzard spear-phishing campaign targets WhatsApp accounts</a></li><li><a title="UK proposes ransomware payment ban" rel="nofollow" href="https://www.gov.uk/government/news/world-leading-proposals-to-protect-businesses-from-cybercrime">UK proposes ransomware payment ban</a></li><li><a title="Fortinet authentication bypass zero-day " rel="nofollow" href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535">Fortinet authentication bypass zero-day </a></li><li><a title="Fortinet: Deep dive into a Linux rootkit malware" rel="nofollow" href="https://www.fortinet.com/blog/threat-research/deep-dive-into-a-linux-rootkit-malware">Fortinet: Deep dive into a Linux rootkit malware</a></li><li><a title="Bernardo Quintero&#39;s new book on VirusTotal (Spanish-language)" rel="nofollow" href="https://www.amazon.com/Infectado-Spectrum-emprendedor-accidental-Spanish/dp/8409666227/ref=sr_1_1?crid=27KFPUV4ECRH7&amp;dib=eyJ2IjoiMSJ9.RtftyW4qSxl2Q07QPDYz0JgOYLm_jlK0D5e4quXsVNSmjtQQ8abhBlRIA-Nf7U52lLy4zw2gX2NTgPAbcbW6n4rBuiAXNmN3-GgGABAjMjDXf_3a6-W0W9zIyiKdEYRWl2rlphl_tl5MwyE5wHHlBouzn8aE8_GS_Lk478PIl5G-bFxbGPG9Gd8OAzKjHaxqUbf7P4jpSzKvIsumlR5eaI3rVPfdcdYXyLaGM_LpxGk.B0D0HYHfmenDvtslyNwXiMtNFrsxLEiihfv4twDd4t8&amp;dib_tag=se&amp;keywords=bernardo+quintero&amp;qid=1737143167&amp;sprefix=%2Caps%2C143&amp;sr=8-1">Bernardo Quintero's new book on VirusTotal (Spanish-language)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Hijacking .gov backdoors, Ivanti 0days and a Samsung 0-click vuln</title>
  <link>http://securityconversations.fireside.fm/ivanti-zero-day-samsung-zero-click-china-blame</link>
  <guid isPermaLink="false">84744251-fc7f-4c4c-bee0-e328e8ae3c02</guid>
  <pubDate>Fri, 10 Jan 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/84744251-fc7f-4c4c-bee0-e328e8ae3c02.mp3" length="91922860" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 29: Another day, another Ivanti zero-day being exploited in the wild.  Plus, China's strange response to Volt Typhoon attribution, Japan blames China for hacks, a Samsung 0-click vulnerability found by Project Zero, Kim Zetter's reporting on drone sightings and a nuclear scare. Plus, hijacking abandoned .gov backdoors and Ukrainian hacktivists wiping a major Russian ISP.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade</itunes:subtitle>
  <itunes:duration>1:48:21</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/8/84744251-fc7f-4c4c-bee0-e328e8ae3c02/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 29:  Another day, another Ivanti zero-day being exploited in the wild.  Plus, China's strange response to Volt Typhoon attribution, Japan blames China for hacks, a Samsung 0-click vulnerability found by Project Zero, Kim Zetter's reporting on drone sightings and a nuclear scare. Plus, hijacking abandoned .gov backdoors and Ukrainian hacktivists wiping a major Russian ISP.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Ivanti, zero-day, Mandiant, China, Vietnam, Japan, Samsung, zero-click, Project Zero, Nodex, Ukraine Cyber Alliance</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 29</strong>:  Another day, another Ivanti zero-day being exploited in the wild.  Plus, China&#39;s strange response to Volt Typhoon attribution, Japan blames China for hacks, a Samsung 0-click vulnerability found by Project Zero, Kim Zetter&#39;s reporting on drone sightings and a nuclear scare. Plus, hijacking abandoned .gov backdoors and Ukrainian hacktivists wiping a major Russian ISP.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1v4WDMg3bTW_lQ0cYU7LBrlLND9eVBt-wkpw4tLJI3f4/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Ivanti Connect Secure zero-day advisory" rel="nofollow" href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283?language=en_US">Ivanti Connect Secure zero-day advisory</a></li><li><a title="Mandiant report on new Ivanti zero-day" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day/">Mandiant report on new Ivanti zero-day</a></li><li><a title="China Daily responds to Volt Typhoon attribution" rel="nofollow" href="https://x.com/chinadaily/status/1876581637762457694?s=46&amp;t=NxSQbkIl4wl2Ei8yYr-9IQ">China Daily responds to Volt Typhoon attribution</a></li><li><a title="Japan warns about Chinese &#39;MirrorFace&#39; attacks" rel="nofollow" href="https://www.npa.go.jp/bureau/cyber/koho/caution/caution20250108.html">Japan warns about Chinese 'MirrorFace' attacks</a></li><li><a title="Who is MirrorFace?" rel="nofollow" href="https://malpedia.caad.fkie.fraunhofer.de/actor/mirrorface">Who is MirrorFace?</a></li><li><a title="Natalie Silvanovich on new Samsung 0-click" rel="nofollow" href="https://x.com/natashenka/status/1877507134474109437">Natalie Silvanovich on new Samsung 0-click</a></li><li><a title="Kim Zetter: Anatomy of a Nuclear Scare" rel="nofollow" href="https://www.zetter-zeroday.com/anatomy-of-a-nuclear-scare/">Kim Zetter: Anatomy of a Nuclear Scare</a></li><li><a title="Backdooring .gov backdoors via $20 domains" rel="nofollow" href="https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/">Backdooring .gov backdoors via $20 domains</a></li><li><a title="APT32 poisoning GitHub, targeting Chinese security pros" rel="nofollow" href="https://threatbook.io/blog/APT32-Poisoning-GitHub,-Targeting-Chinese-Cybersecurity-Professionals-and-Specific-Large-Enterprises">APT32 poisoning GitHub, targeting Chinese security pros</a></li><li><a title="Ukraine wipes Russian ISP" rel="nofollow" href="https://vk.com/wall-7622_825">Ukraine wipes Russian ISP</a></li><li><a title="Russian internet provider confirms network ‘destroyed’ by Ukrainian hackers" rel="nofollow" href="https://therecord.media/russian-internet-provider-says-network-destroyed-cyberattack">Russian internet provider confirms network ‘destroyed’ by Ukrainian hackers</a></li><li><a title="Mullvad: Quantum-resistant tunnels on desktop VPN" rel="nofollow" href="https://mullvad.net/en/blog/quantum-resistant-tunnels-are-now-the-default-on-desktop">Mullvad: Quantum-resistant tunnels on desktop VPN</a></li><li><a title="Fundraiser for Marc Rogers" rel="nofollow" href="https://www.gofundme.com/f/support-marc-rogers-road-to-recovery">Fundraiser for Marc Rogers</a></li><li><a title="CNN: Amit Yoran has died at 54 " rel="nofollow" href="https://www.cnn.com/2025/01/04/business/amit-yoran-dies-tenable-ceo/index.html">CNN: Amit Yoran has died at 54 </a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 29</strong>:  Another day, another Ivanti zero-day being exploited in the wild.  Plus, China&#39;s strange response to Volt Typhoon attribution, Japan blames China for hacks, a Samsung 0-click vulnerability found by Project Zero, Kim Zetter&#39;s reporting on drone sightings and a nuclear scare. Plus, hijacking abandoned .gov backdoors and Ukrainian hacktivists wiping a major Russian ISP.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1v4WDMg3bTW_lQ0cYU7LBrlLND9eVBt-wkpw4tLJI3f4/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Ivanti Connect Secure zero-day advisory" rel="nofollow" href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283?language=en_US">Ivanti Connect Secure zero-day advisory</a></li><li><a title="Mandiant report on new Ivanti zero-day" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day/">Mandiant report on new Ivanti zero-day</a></li><li><a title="China Daily responds to Volt Typhoon attribution" rel="nofollow" href="https://x.com/chinadaily/status/1876581637762457694?s=46&amp;t=NxSQbkIl4wl2Ei8yYr-9IQ">China Daily responds to Volt Typhoon attribution</a></li><li><a title="Japan warns about Chinese &#39;MirrorFace&#39; attacks" rel="nofollow" href="https://www.npa.go.jp/bureau/cyber/koho/caution/caution20250108.html">Japan warns about Chinese 'MirrorFace' attacks</a></li><li><a title="Who is MirrorFace?" rel="nofollow" href="https://malpedia.caad.fkie.fraunhofer.de/actor/mirrorface">Who is MirrorFace?</a></li><li><a title="Natalie Silvanovich on new Samsung 0-click" rel="nofollow" href="https://x.com/natashenka/status/1877507134474109437">Natalie Silvanovich on new Samsung 0-click</a></li><li><a title="Kim Zetter: Anatomy of a Nuclear Scare" rel="nofollow" href="https://www.zetter-zeroday.com/anatomy-of-a-nuclear-scare/">Kim Zetter: Anatomy of a Nuclear Scare</a></li><li><a title="Backdooring .gov backdoors via $20 domains" rel="nofollow" href="https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/">Backdooring .gov backdoors via $20 domains</a></li><li><a title="APT32 poisoning GitHub, targeting Chinese security pros" rel="nofollow" href="https://threatbook.io/blog/APT32-Poisoning-GitHub,-Targeting-Chinese-Cybersecurity-Professionals-and-Specific-Large-Enterprises">APT32 poisoning GitHub, targeting Chinese security pros</a></li><li><a title="Ukraine wipes Russian ISP" rel="nofollow" href="https://vk.com/wall-7622_825">Ukraine wipes Russian ISP</a></li><li><a title="Russian internet provider confirms network ‘destroyed’ by Ukrainian hackers" rel="nofollow" href="https://therecord.media/russian-internet-provider-says-network-destroyed-cyberattack">Russian internet provider confirms network ‘destroyed’ by Ukrainian hackers</a></li><li><a title="Mullvad: Quantum-resistant tunnels on desktop VPN" rel="nofollow" href="https://mullvad.net/en/blog/quantum-resistant-tunnels-are-now-the-default-on-desktop">Mullvad: Quantum-resistant tunnels on desktop VPN</a></li><li><a title="Fundraiser for Marc Rogers" rel="nofollow" href="https://www.gofundme.com/f/support-marc-rogers-road-to-recovery">Fundraiser for Marc Rogers</a></li><li><a title="CNN: Amit Yoran has died at 54 " rel="nofollow" href="https://www.cnn.com/2025/01/04/business/amit-yoran-dies-tenable-ceo/index.html">CNN: Amit Yoran has died at 54 </a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>US Treasury hacked via BeyondTrust, MISP and the threat actor naming mess</title>
  <link>http://securityconversations.fireside.fm/fixing-threat-actor-naming-mess</link>
  <guid isPermaLink="false">2702a1ec-2c6e-4d8c-902a-5f462b1a93be</guid>
  <pubDate>Fri, 03 Jan 2025 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/2702a1ec-2c6e-4d8c-902a-5f462b1a93be.mp3" length="88069225" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 28: In this episode, we explore the ongoing challenges of threat actor naming in cybersecurity and the confusion caused by a lack of standardization, methodological inconsistencies and skewed, marketing-driven incentives. 

Plus, the US Treasury/BeyondTrust hack, the surge in 0day discoveries, a new variant of the  Xdr33 CIA Hive malware, and exclusive new information on the Cyberhaven Chrome extension security incident.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade</itunes:subtitle>
  <itunes:duration>1:49:16</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/2/2702a1ec-2c6e-4d8c-902a-5f462b1a93be/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 28:  In this episode, we explore the ongoing challenges of threat actor naming in cybersecurity and the confusion caused by a lack of standardization, methodological inconsistencies and skewed, marketing-driven incentives. 
Plus, the US Treasury/BeyondTrust hack, the surge in 0day discoveries, a new variant of the  Xdr33 CIA Hive malware, and exclusive new information on the Cyberhaven Chrome extension security incident.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>BeyondTrust, OFAC, zero-day, Salt Typhoon, Aurora, BeyondCorp, Zero Trust, Google, MISP, Threat Intelligence, Synapse, Pink Lambert, Cyberhaven, US Sanctions,  </itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 28</strong>:  In this episode, we explore the ongoing challenges of threat actor naming in cybersecurity and the confusion caused by a lack of standardization, methodological inconsistencies and skewed, marketing-driven incentives. </p>

<p>Plus, the US Treasury/BeyondTrust hack, the surge in 0day discoveries, a new variant of the  Xdr33 CIA Hive malware, and exclusive new information on the Cyberhaven Chrome extension security incident.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Fozuh0j1k3EiKJr8mSxP__6O6dQ3iLgAxeEq8f9GKxI/edit?tab=t.0#heading=h.1u39inyn4ent">Transcript (unedited, AI-generated)</a></li><li><a title="BeyondTrust statement on hack investigation" rel="nofollow" href="https://www.beyondtrust.com/remote-support-saas-service-security-investigation">BeyondTrust statement on hack investigation</a></li><li><a title="U.S. Treasury says it was hacked by China-backed actors" rel="nofollow" href="https://archive.ph/0ELY2">U.S. Treasury says it was hacked by China-backed actors</a></li><li><a title="Another Palo Alto 0day exploited in the wild" rel="nofollow" href="https://security.paloaltonetworks.com/CVE-2024-3393">Another Palo Alto 0day exploited in the wild</a></li><li><a title="US telcos say they&#39;ve evicted Salt Typhoon Chinese hackers" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/chinese-salt-typhoon-cyberespionage-targets-att-networks-secure-carrier-says-2024-12-29/">US telcos say they've evicted Salt Typhoon Chinese hackers</a></li><li><a title="Google: What is BeyondCorp?" rel="nofollow" href="https://cloud.google.com/beyondcorp">Google: What is BeyondCorp?</a></li><li><a title="Introducing the MISP Threat Actor Naming Standard" rel="nofollow" href="https://www.misp-standard.org/blog/Naming-Threat-Actor/">Introducing the MISP Threat Actor Naming Standard</a></li><li><a title="MISP: Recommendations on Naming Threat Actors" rel="nofollow" href="https://www.misp-standard.org/rfc/threat-actor-naming.html">MISP: Recommendations on Naming Threat Actors</a></li><li><a title="New variant of the CIA HIVE attack kit" rel="nofollow" href="https://x.com/nextronresearch/status/1874690494930014703">New variant of the CIA HIVE attack kit</a></li><li><a title="Xdr33 Variant Of CIA&#39;s HIVE Attack Kit Emerges" rel="nofollow" href="https://blog.netlab.360.com/headsup_xdr33_variant_of_ciahive_emeerges/">Xdr33 Variant Of CIA's HIVE Attack Kit Emerges</a></li><li><a title="Savvy Seahorse connection to Cyberhaven incident" rel="nofollow" href="https://blogs.infoblox.com/threat-intelligence/beware-the-shallow-waters-savvy-seahorse-lures-victims-to-fake-investment-platforms-through-facebook-ads/">Savvy Seahorse connection to Cyberhaven incident</a></li><li><a title="US sanctions China&#39;s Integrity Technology over Flax Typhoon hacks" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/us-issues-cybersecurity-sanctions-against-chinas-integrity-technology-2025-01-03/">US sanctions China's Integrity Technology over Flax Typhoon hacks</a></li><li><a title="Operation Aurora" rel="nofollow" href="https://en.wikipedia.org/wiki/Operation_Aurora">Operation Aurora</a></li><li><a title="APT1 Exposing One of China’s Cyber Espionage Units" rel="nofollow" href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">APT1 Exposing One of China’s Cyber Espionage Units</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 28</strong>:  In this episode, we explore the ongoing challenges of threat actor naming in cybersecurity and the confusion caused by a lack of standardization, methodological inconsistencies and skewed, marketing-driven incentives. </p>

<p>Plus, the US Treasury/BeyondTrust hack, the surge in 0day discoveries, a new variant of the  Xdr33 CIA Hive malware, and exclusive new information on the Cyberhaven Chrome extension security incident.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Fozuh0j1k3EiKJr8mSxP__6O6dQ3iLgAxeEq8f9GKxI/edit?tab=t.0#heading=h.1u39inyn4ent">Transcript (unedited, AI-generated)</a></li><li><a title="BeyondTrust statement on hack investigation" rel="nofollow" href="https://www.beyondtrust.com/remote-support-saas-service-security-investigation">BeyondTrust statement on hack investigation</a></li><li><a title="U.S. Treasury says it was hacked by China-backed actors" rel="nofollow" href="https://archive.ph/0ELY2">U.S. Treasury says it was hacked by China-backed actors</a></li><li><a title="Another Palo Alto 0day exploited in the wild" rel="nofollow" href="https://security.paloaltonetworks.com/CVE-2024-3393">Another Palo Alto 0day exploited in the wild</a></li><li><a title="US telcos say they&#39;ve evicted Salt Typhoon Chinese hackers" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/chinese-salt-typhoon-cyberespionage-targets-att-networks-secure-carrier-says-2024-12-29/">US telcos say they've evicted Salt Typhoon Chinese hackers</a></li><li><a title="Google: What is BeyondCorp?" rel="nofollow" href="https://cloud.google.com/beyondcorp">Google: What is BeyondCorp?</a></li><li><a title="Introducing the MISP Threat Actor Naming Standard" rel="nofollow" href="https://www.misp-standard.org/blog/Naming-Threat-Actor/">Introducing the MISP Threat Actor Naming Standard</a></li><li><a title="MISP: Recommendations on Naming Threat Actors" rel="nofollow" href="https://www.misp-standard.org/rfc/threat-actor-naming.html">MISP: Recommendations on Naming Threat Actors</a></li><li><a title="New variant of the CIA HIVE attack kit" rel="nofollow" href="https://x.com/nextronresearch/status/1874690494930014703">New variant of the CIA HIVE attack kit</a></li><li><a title="Xdr33 Variant Of CIA&#39;s HIVE Attack Kit Emerges" rel="nofollow" href="https://blog.netlab.360.com/headsup_xdr33_variant_of_ciahive_emeerges/">Xdr33 Variant Of CIA's HIVE Attack Kit Emerges</a></li><li><a title="Savvy Seahorse connection to Cyberhaven incident" rel="nofollow" href="https://blogs.infoblox.com/threat-intelligence/beware-the-shallow-waters-savvy-seahorse-lures-victims-to-fake-investment-platforms-through-facebook-ads/">Savvy Seahorse connection to Cyberhaven incident</a></li><li><a title="US sanctions China&#39;s Integrity Technology over Flax Typhoon hacks" rel="nofollow" href="https://www.reuters.com/technology/cybersecurity/us-issues-cybersecurity-sanctions-against-chinas-integrity-technology-2025-01-03/">US sanctions China's Integrity Technology over Flax Typhoon hacks</a></li><li><a title="Operation Aurora" rel="nofollow" href="https://en.wikipedia.org/wiki/Operation_Aurora">Operation Aurora</a></li><li><a title="APT1 Exposing One of China’s Cyber Espionage Units" rel="nofollow" href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">APT1 Exposing One of China’s Cyber Espionage Units</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Palo Alto network edge device backdoor, Cyberhaven browser extension hack, 2024 research highlights</title>
  <link>http://securityconversations.fireside.fm/palo-alto-backdoor-cyberhaven-hack-year-review</link>
  <guid isPermaLink="false">55fe71f1-b9b4-4a31-8a0b-8f6a8d59b903</guid>
  <pubDate>Fri, 27 Dec 2024 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/55fe71f1-b9b4-4a31-8a0b-8f6a8d59b903.mp3" length="91383420" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 27:  We discuss the discovery of a Palo Alto network firewall attack and a stealthy network edge device backdoor (LITTLELAMB.WOOLTEA), the Cyberhaven hack and the shady world of browser extensions, and a look back at the top research projects that caught our attention in 2025.

Cast: Ryan Naraine, Costin Raiu and Juan Andres Guerrero-Saade</itunes:subtitle>
  <itunes:duration>1:53:11</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/5/55fe71f1-b9b4-4a31-8a0b-8f6a8d59b903/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 27:  We discuss the discovery of a Palo Alto network firewall attack and a stealthy network ed ge device backdoor (LITTLELAMB.WOOLTEA), the Cyberhaven hack and the shady world of browser extensions, and a look back at the top research projects that caught our attention in 2025.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Sora, AI, deepfake, cybersecurity, Cyberhaven, browser extensions, malware, insider threats, ChatGPT, privacy, Chrome, data security, malware, cybersecurity, attribution, corporate responsibility, cyber operations, physical conflict, research, cybersecurity, malware, nation-state threats, drone technology, election interference, CSRB, research, cybersecurity challenges, global conflicts, cyber warfare</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 27</strong>:  We discuss the discovery of a Palo Alto network firewall attack and a stealthy network ed ge device backdoor (LITTLELAMB.WOOLTEA), the Cyberhaven hack and the shady world of browser extensions, and a look back at the top research projects that caught our attention in 2025.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1321LDAuU5PosOnXODrFvvXAx8TiTXr1kbtQZE1PhhLw/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="LITTLELAMB.WOOLTEA: Stealthy Network Edge Device Backdoor " rel="nofollow" href="https://northwave-cybersecurity.com/hubfs/LITTLELAMB%20WOOLTEA%20technical%20writeup%20Schrijver%20and%20Oudenaarden.pdf">LITTLELAMB.WOOLTEA: Stealthy Network Edge Device Backdoor </a></li><li><a title="Palo Alto: Operation Lunar Peek" rel="nofollow" href="https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/">Palo Alto: Operation Lunar Peek</a></li><li><a title="Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-exploitation-persistence/">Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts</a></li><li><a title="“A Digital Prison”: Surveillance and the suppression of civil society in Serbia" rel="nofollow" href="https://securitylab.amnesty.org/latest/2024/12/a-digital-prison-surveillance-and-the-suppression-of-civil-society-in-serbia/">“A Digital Prison”: Surveillance and the suppression of civil society in Serbia</a></li><li><a title="Cyberhaven breach reported. Employee phished and pushed malicious chrome extension" rel="nofollow" href="https://x.com/cstanley/status/1872365853318225931">Cyberhaven breach reported. Employee phished and pushed malicious chrome extension</a></li><li><a title="GRU 29155 doing cyber operations" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a">GRU 29155 doing cyber operations</a></li><li><a title="How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar " rel="nofollow" href="https://www.wired.com/story/predatory-sparrow-cyberattack-timeline/">How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar </a></li><li><a title="Sophos Used Custom Implants to Surveil Chinese Hackers Targeting Firewall Zero-Days" rel="nofollow" href="https://www.securityweek.com/sophos-used-custom-implants-to-surveil-chinese-hackers-targeting-firewall-zero-days/">Sophos Used Custom Implants to Surveil Chinese Hackers Targeting Firewall Zero-Days</a></li><li><a title="Operation MiddleFloor: Unmasking the Disinformation Campaign Targeting Moldova&#39;s National Elections" rel="nofollow" href="https://blog.checkpoint.com/research/operation-middlefloor-unmasking-the-disinformation-campaign-targeting-moldovas-national-elections/">Operation MiddleFloor: Unmasking the Disinformation Campaign Targeting Moldova's National Elections</a></li><li><a title="NSPX30: A sophisticated AitM-enabled implant evolving since 2005" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/nspx30-sophisticated-aitm-enabled-implant-evolving-since-2005/">NSPX30: A sophisticated AitM-enabled implant evolving since 2005</a></li><li><a title="backdoor in upstream xz/liblzma leading to ssh server compromise" rel="nofollow" href="https://seclists.org/oss-sec/2024/q1/268">backdoor in upstream xz/liblzma leading to ssh server compromise</a></li><li><a title="PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem" rel="nofollow" href="https://www.binarly.io/blog/pkfail-untrusted-platform-keys-undermine-secure-boot-on-uefi-ecosystem">PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem</a></li><li><a title="The Tech Coup - How to Save Democracy from Silicon Valley" rel="nofollow" href="https://press.princeton.edu/books/hardcover/9780691241173/the-tech-coup?srsltid=AfmBOoq7pNBk27MtRxluxXHgYpx1hk2misTivpgZBRfkrplbw9t3q81i">The Tech Coup - How to Save Democracy from Silicon Valley</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 27</strong>:  We discuss the discovery of a Palo Alto network firewall attack and a stealthy network ed ge device backdoor (LITTLELAMB.WOOLTEA), the Cyberhaven hack and the shady world of browser extensions, and a look back at the top research projects that caught our attention in 2025.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1321LDAuU5PosOnXODrFvvXAx8TiTXr1kbtQZE1PhhLw/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="LITTLELAMB.WOOLTEA: Stealthy Network Edge Device Backdoor " rel="nofollow" href="https://northwave-cybersecurity.com/hubfs/LITTLELAMB%20WOOLTEA%20technical%20writeup%20Schrijver%20and%20Oudenaarden.pdf">LITTLELAMB.WOOLTEA: Stealthy Network Edge Device Backdoor </a></li><li><a title="Palo Alto: Operation Lunar Peek" rel="nofollow" href="https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/">Palo Alto: Operation Lunar Peek</a></li><li><a title="Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-exploitation-persistence/">Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts</a></li><li><a title="“A Digital Prison”: Surveillance and the suppression of civil society in Serbia" rel="nofollow" href="https://securitylab.amnesty.org/latest/2024/12/a-digital-prison-surveillance-and-the-suppression-of-civil-society-in-serbia/">“A Digital Prison”: Surveillance and the suppression of civil society in Serbia</a></li><li><a title="Cyberhaven breach reported. Employee phished and pushed malicious chrome extension" rel="nofollow" href="https://x.com/cstanley/status/1872365853318225931">Cyberhaven breach reported. Employee phished and pushed malicious chrome extension</a></li><li><a title="GRU 29155 doing cyber operations" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a">GRU 29155 doing cyber operations</a></li><li><a title="How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar " rel="nofollow" href="https://www.wired.com/story/predatory-sparrow-cyberattack-timeline/">How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar </a></li><li><a title="Sophos Used Custom Implants to Surveil Chinese Hackers Targeting Firewall Zero-Days" rel="nofollow" href="https://www.securityweek.com/sophos-used-custom-implants-to-surveil-chinese-hackers-targeting-firewall-zero-days/">Sophos Used Custom Implants to Surveil Chinese Hackers Targeting Firewall Zero-Days</a></li><li><a title="Operation MiddleFloor: Unmasking the Disinformation Campaign Targeting Moldova&#39;s National Elections" rel="nofollow" href="https://blog.checkpoint.com/research/operation-middlefloor-unmasking-the-disinformation-campaign-targeting-moldovas-national-elections/">Operation MiddleFloor: Unmasking the Disinformation Campaign Targeting Moldova's National Elections</a></li><li><a title="NSPX30: A sophisticated AitM-enabled implant evolving since 2005" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/nspx30-sophisticated-aitm-enabled-implant-evolving-since-2005/">NSPX30: A sophisticated AitM-enabled implant evolving since 2005</a></li><li><a title="backdoor in upstream xz/liblzma leading to ssh server compromise" rel="nofollow" href="https://seclists.org/oss-sec/2024/q1/268">backdoor in upstream xz/liblzma leading to ssh server compromise</a></li><li><a title="PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem" rel="nofollow" href="https://www.binarly.io/blog/pkfail-untrusted-platform-keys-undermine-secure-boot-on-uefi-ecosystem">PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem</a></li><li><a title="The Tech Coup - How to Save Democracy from Silicon Valley" rel="nofollow" href="https://press.princeton.edu/books/hardcover/9780691241173/the-tech-coup?srsltid=AfmBOoq7pNBk27MtRxluxXHgYpx1hk2misTivpgZBRfkrplbw9t3q81i">The Tech Coup - How to Save Democracy from Silicon Valley</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>US government's VPN advice, dropping bombs on ransomware gangs</title>
  <link>http://securityconversations.fireside.fm/cisa-vpn-advice-tp-link-cellebrite-novispy</link>
  <guid isPermaLink="false">4e8b8384-f9ae-4e42-87fe-d72ab006ab10</guid>
  <pubDate>Mon, 23 Dec 2024 12:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/4e8b8384-f9ae-4e42-87fe-d72ab006ab10.mp3" length="97305809" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 26:  We dive deep into the shadowy world of surveillance and cyber operations, unpacking Amnesty International's explosive report on NoviSpy, a previously unknown Android implant used against Serbian activists, and the links to Israeli forensics software vendor Cellebrite.

Plus, thoughts on the US government’s controversial guidance on VPNs, Chinese reports on US intel agency hacking, TP-Link sanctions chatter, Mossad's dramatic exploding beeper operation and the ethical, legal, and security implications of escalating cyber-deterrence.  Also, a mysterious BeyondTrust 0-day!

Cast: Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:58:40</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/4e8b8384-f9ae-4e42-87fe-d72ab006ab10/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 26:  We dive deep into the shadowy world of surveillance and cyber operations, unpacking Amnesty International's explosive report on NoviSpy, a previously unknown Android implant used against Serbian activists, and the links to Israeli forensics software vendor Cellebrite.
Plus, thoughts on the US government’s controversial guidance on VPNs, Chinese reports on US intel agency hacking, TP-Link sanctions chatter, Mossad's dramatic exploding beeper operation and the ethical, legal, and security implications of escalating cyber-deterrence.  Also, a mysterious BeyondTrust 0-day!
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>political interference, Romania, surveillance technology, digital security, iOS, Android, mobile exploits, activists, VPNs, VPN, privacy, CISA, cryptocurrency, anonymity, security solutions, software quality, government regulations, cybercrime, digital trust, cybersecurity, espionage, ransomware, supply chain attacks, cyber warfare, intelligence agencies, US-China relations, malware, cyber norms, innovation</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 26</strong>:  We dive deep into the shadowy world of surveillance and cyber operations, unpacking Amnesty International&#39;s explosive report on NoviSpy, a previously unknown Android implant used against Serbian activists, and the links to Israeli forensics software vendor Cellebrite.</p>

<p>Plus, thoughts on the US government’s controversial guidance on VPNs, Chinese reports on US intel agency hacking, TP-Link sanctions chatter, Mossad&#39;s dramatic exploding beeper operation and the ethical, legal, and security implications of escalating cyber-deterrence.  Also, a mysterious BeyondTrust 0-day!</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1v_-VcFPFydOVKG42d5hAO5MPx50HNR10l95h8Gh12WA/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Surveillance and the suppression of civil society in Serbia" rel="nofollow" href="https://www.amnesty.org/en/documents/eur70/8813/2024/en/">Surveillance and the suppression of civil society in Serbia</a></li><li><a title="CISA: VPN and mobile device security guidance" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf">CISA: VPN and mobile device security guidance</a></li><li><a title="Costin Raiu: Staying safe from Pegasus, Chrysaor and other APT mobile malware (2024 update)" rel="nofollow" href="https://medium.com/@costin.raiu/staying-safe-from-pegasus-chrysaor-and-other-apt-mobile-malware-a923b56d645f">Costin Raiu: Staying safe from Pegasus, Chrysaor and other APT mobile malware (2024 update)</a></li><li><a title="Bitsight: The Aftermath of the Kaspersky Ban" rel="nofollow" href="https://www.bitsight.com/blog/aftermath-kaspersky-ban">Bitsight: The Aftermath of the Kaspersky Ban</a></li><li><a title="US Probes China-Founded Router Maker TP-Link" rel="nofollow" href="https://archive.ph/tzycz">US Probes China-Founded Router Maker TP-Link</a></li><li><a title="Rob Joyce: Move away from TP-Link" rel="nofollow" href="https://bsky.app/profile/rgblights.bsky.social/post/3ldlr2lrfe22y">Rob Joyce: Move away from TP-Link</a></li><li><a title="China report on US intelligence corporate hacking" rel="nofollow" href="https://www.cert.org.cn/publish/main/8/2024/20241218184234131217571/20241218184234131217571_.html">China report on US intelligence corporate hacking</a></li><li><a title="Foreign hackers need to face real consequences" rel="nofollow" href="https://www.politico.com/news/2024/12/15/mike-waltz-hacking-foreign-penalties-00194415">Foreign hackers need to face real consequences</a></li><li><a title="Israel&#39;s Mossad spent years orchestrating Hezbollah pager plot" rel="nofollow" href="https://www.cbsnews.com/news/israeli-mossad-pager-walkie-talkie-hezbollah-plot-60-minutes/">Israel's Mossad spent years orchestrating Hezbollah pager plot</a></li><li><a title="BeyondTrust 0day" rel="nofollow" href="https://www.beyondtrust.com/remote-support-saas-service-security-investigation">BeyondTrust 0day</a></li><li><a title="Sophos Firewall CVSS 9.8 bulletin" rel="nofollow" href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce">Sophos Firewall CVSS 9.8 bulletin</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 26</strong>:  We dive deep into the shadowy world of surveillance and cyber operations, unpacking Amnesty International&#39;s explosive report on NoviSpy, a previously unknown Android implant used against Serbian activists, and the links to Israeli forensics software vendor Cellebrite.</p>

<p>Plus, thoughts on the US government’s controversial guidance on VPNs, Chinese reports on US intel agency hacking, TP-Link sanctions chatter, Mossad&#39;s dramatic exploding beeper operation and the ethical, legal, and security implications of escalating cyber-deterrence.  Also, a mysterious BeyondTrust 0-day!</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1v_-VcFPFydOVKG42d5hAO5MPx50HNR10l95h8Gh12WA/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Surveillance and the suppression of civil society in Serbia" rel="nofollow" href="https://www.amnesty.org/en/documents/eur70/8813/2024/en/">Surveillance and the suppression of civil society in Serbia</a></li><li><a title="CISA: VPN and mobile device security guidance" rel="nofollow" href="https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf">CISA: VPN and mobile device security guidance</a></li><li><a title="Costin Raiu: Staying safe from Pegasus, Chrysaor and other APT mobile malware (2024 update)" rel="nofollow" href="https://medium.com/@costin.raiu/staying-safe-from-pegasus-chrysaor-and-other-apt-mobile-malware-a923b56d645f">Costin Raiu: Staying safe from Pegasus, Chrysaor and other APT mobile malware (2024 update)</a></li><li><a title="Bitsight: The Aftermath of the Kaspersky Ban" rel="nofollow" href="https://www.bitsight.com/blog/aftermath-kaspersky-ban">Bitsight: The Aftermath of the Kaspersky Ban</a></li><li><a title="US Probes China-Founded Router Maker TP-Link" rel="nofollow" href="https://archive.ph/tzycz">US Probes China-Founded Router Maker TP-Link</a></li><li><a title="Rob Joyce: Move away from TP-Link" rel="nofollow" href="https://bsky.app/profile/rgblights.bsky.social/post/3ldlr2lrfe22y">Rob Joyce: Move away from TP-Link</a></li><li><a title="China report on US intelligence corporate hacking" rel="nofollow" href="https://www.cert.org.cn/publish/main/8/2024/20241218184234131217571/20241218184234131217571_.html">China report on US intelligence corporate hacking</a></li><li><a title="Foreign hackers need to face real consequences" rel="nofollow" href="https://www.politico.com/news/2024/12/15/mike-waltz-hacking-foreign-penalties-00194415">Foreign hackers need to face real consequences</a></li><li><a title="Israel&#39;s Mossad spent years orchestrating Hezbollah pager plot" rel="nofollow" href="https://www.cbsnews.com/news/israeli-mossad-pager-walkie-talkie-hezbollah-plot-60-minutes/">Israel's Mossad spent years orchestrating Hezbollah pager plot</a></li><li><a title="BeyondTrust 0day" rel="nofollow" href="https://www.beyondtrust.com/remote-support-saas-service-security-investigation">BeyondTrust 0day</a></li><li><a title="Sophos Firewall CVSS 9.8 bulletin" rel="nofollow" href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce">Sophos Firewall CVSS 9.8 bulletin</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Surveillance economics, Turla and Careto, and the AI screenshots nobody asked for</title>
  <link>http://securityconversations.fireside.fm/apple-microsoft-ai-screenshots-nobody-asked-for</link>
  <guid isPermaLink="false">1d7c6464-bcb3-4362-a308-5d0f46d2581a</guid>
  <pubDate>Fri, 13 Dec 2024 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/1d7c6464-bcb3-4362-a308-5d0f46d2581a.mp3" length="109974427" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 25:  An update on Romania’s cancelled election, the implications of TikTok on democratic processes, and the broader issues around surveillance capitalism and micro-targeting.  

Plus, news on Turla piggybacking on cybercriminal malware to hit Ukraine, the return of Careto and the absence of IOCs, Claroty report on an Iran-linked cyberweapon targeting critical infrastructure, ethical considerations in cyberwarfare, and the implications of quantum computing on security and cryptocurrencies. 

Cast: Juan Andres Guerrero-Saade, Costin Raiu and Ryan Naraine.</itunes:subtitle>
  <itunes:duration>2:14:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/1d7c6464-bcb3-4362-a308-5d0f46d2581a/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 25:  An update on Romania’s cancelled election, the implications of TikTok on democratic processes, and the broader issues around surveillance capitalism and micro-targeting.  
Plus, news on Turla piggybacking on cybercriminal malware to hit Ukraine, the return of Careto and the absence of IOCs, Claroty report on an Iran-linked cyberweapon targeting critical infrastructure, ethical considerations in cyberwarfare, and the implications of quantum computing on security and cryptocurrencies. 
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu) and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Romania, elections, TikTok, AI, surveillance, Apple, Microsoft, Patch Tuesday, iOS 18.2, zero-day, quantum, bitcoin, careto, turla, Iran Israel</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 25</strong>:  An update on Romania’s cancelled election, the implications of TikTok on democratic processes, and the broader issues around surveillance capitalism and micro-targeting.  </p>

<p>Plus, news on Turla piggybacking on cybercriminal malware to hit Ukraine, the return of Careto and the absence of IOCs, Claroty report on an Iran-linked cyberweapon targeting critical infrastructure, ethical considerations in cyberwarfare, and the implications of quantum computing on security and cryptocurrencies. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1iSaLwiCLiTifTLfiM0oQYIl_mBZBswfgVXOAsT8GY1g/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Turla using tools of other groups to attack Ukraine (Microsoft)" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/">Turla using tools of other groups to attack Ukraine (Microsoft)</a></li><li><a title="EpicTurla.com: The lost reports" rel="nofollow" href="https://www.epicturla.com/">EpicTurla.com: The lost reports</a></li><li><a title="Microsoft Recall screenshots credit cards and SSNs" rel="nofollow" href="https://www.tomshardware.com/software/windows/microsoft-recall-screenshots-credit-cards-and-social-security-numbers-even-with-the-sensitive-information-filter-enabled">Microsoft Recall screenshots credit cards and SSNs</a></li><li><a title="Stephan Casas: macOS applications quietly capturing screenshots" rel="nofollow" href="https://x.com/stephancasas/status/1867147973479805058?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Stephan Casas: macOS applications quietly capturing screenshots</a></li><li><a title="CVE-2024-49138 - MS 0day exploited in the wild" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49138">CVE-2024-49138 - MS 0day exploited in the wild</a></li><li><a title="Sanctions hit Chinese company behind Sophos 0day attack" rel="nofollow" href="https://home.treasury.gov/news/press-releases/jy2742">Sanctions hit Chinese company behind Sophos 0day attack</a></li><li><a title="SentinelLabs: Operation Digital Eye" rel="nofollow" href="https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/">SentinelLabs: Operation Digital Eye</a></li><li><a title="Careto APT’s recent attacks discovered" rel="nofollow" href="https://securelist.com/careto-is-back/114942/">Careto APT’s recent attacks discovered</a></li><li><a title="Claroty: Inside a New OT/IoT cyberweapon" rel="nofollow" href="https://claroty.com/team82/research/inside-a-new-ot-iot-cyber-weapon-iocontrol">Claroty: Inside a New OT/IoT cyberweapon</a></li><li><a title="Predatory Sparrow: cyber sabotage with a conscience?" rel="nofollow" href="https://bindinghook.com/articles-binding-edge/predatory-sparrow-cyber-sabotage-with-a-conscience/">Predatory Sparrow: cyber sabotage with a conscience?</a></li><li><a title="Willow, Google&#39;s state-of-the-art quantum chip" rel="nofollow" href="https://blog.google/technology/research/google-willow-quantum-chip/">Willow, Google's state-of-the-art quantum chip</a></li><li><a title="What sucks in security? Research findings from 50+ security leaders" rel="nofollow" href="https://mayakaczorowski.com/blogs/what-sucks-in-security">What sucks in security? Research findings from 50+ security leaders</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 25</strong>:  An update on Romania’s cancelled election, the implications of TikTok on democratic processes, and the broader issues around surveillance capitalism and micro-targeting.  </p>

<p>Plus, news on Turla piggybacking on cybercriminal malware to hit Ukraine, the return of Careto and the absence of IOCs, Claroty report on an Iran-linked cyberweapon targeting critical infrastructure, ethical considerations in cyberwarfare, and the implications of quantum computing on security and cryptocurrencies. </p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1iSaLwiCLiTifTLfiM0oQYIl_mBZBswfgVXOAsT8GY1g/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Turla using tools of other groups to attack Ukraine (Microsoft)" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/">Turla using tools of other groups to attack Ukraine (Microsoft)</a></li><li><a title="EpicTurla.com: The lost reports" rel="nofollow" href="https://www.epicturla.com/">EpicTurla.com: The lost reports</a></li><li><a title="Microsoft Recall screenshots credit cards and SSNs" rel="nofollow" href="https://www.tomshardware.com/software/windows/microsoft-recall-screenshots-credit-cards-and-social-security-numbers-even-with-the-sensitive-information-filter-enabled">Microsoft Recall screenshots credit cards and SSNs</a></li><li><a title="Stephan Casas: macOS applications quietly capturing screenshots" rel="nofollow" href="https://x.com/stephancasas/status/1867147973479805058?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Stephan Casas: macOS applications quietly capturing screenshots</a></li><li><a title="CVE-2024-49138 - MS 0day exploited in the wild" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49138">CVE-2024-49138 - MS 0day exploited in the wild</a></li><li><a title="Sanctions hit Chinese company behind Sophos 0day attack" rel="nofollow" href="https://home.treasury.gov/news/press-releases/jy2742">Sanctions hit Chinese company behind Sophos 0day attack</a></li><li><a title="SentinelLabs: Operation Digital Eye" rel="nofollow" href="https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/">SentinelLabs: Operation Digital Eye</a></li><li><a title="Careto APT’s recent attacks discovered" rel="nofollow" href="https://securelist.com/careto-is-back/114942/">Careto APT’s recent attacks discovered</a></li><li><a title="Claroty: Inside a New OT/IoT cyberweapon" rel="nofollow" href="https://claroty.com/team82/research/inside-a-new-ot-iot-cyber-weapon-iocontrol">Claroty: Inside a New OT/IoT cyberweapon</a></li><li><a title="Predatory Sparrow: cyber sabotage with a conscience?" rel="nofollow" href="https://bindinghook.com/articles-binding-edge/predatory-sparrow-cyber-sabotage-with-a-conscience/">Predatory Sparrow: cyber sabotage with a conscience?</a></li><li><a title="Willow, Google&#39;s state-of-the-art quantum chip" rel="nofollow" href="https://blog.google/technology/research/google-willow-quantum-chip/">Willow, Google's state-of-the-art quantum chip</a></li><li><a title="What sucks in security? Research findings from 50+ security leaders" rel="nofollow" href="https://mayakaczorowski.com/blogs/what-sucks-in-security">What sucks in security? Research findings from 50+ security leaders</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Inside the Turla Playbook: Hijacking APTs and fourth-party espionage</title>
  <link>http://securityconversations.fireside.fm/inside-turla-playbook-hijacking-apt-fourth-party-collection</link>
  <guid isPermaLink="false">af6d806f-6e02-4b8a-b12c-ed94b0f61215</guid>
  <pubDate>Sat, 07 Dec 2024 11:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/af6d806f-6e02-4b8a-b12c-ed94b0f61215.mp3" length="89199523" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 24:  In this episode, we dig into Lumen/Microsoft’s revelations on Russia's Turla APT stealing from a Pakistani APT, and issues around fourth-party espionage and problems with threat actor attribution.  We also discuss Citizen Lab’s findings on Monokle-like spyware implanted by Russian authorities, the slow pace of Salt Typhoon disinfection, the Solana web3.js supply chain attack affecting crypto projects, and the Romanian election crisis over Russian interference via TikTok.

Cast: Juan Andres Guerrero-Saade, Costin Raiu, Ryan Naraine.</itunes:subtitle>
  <itunes:duration>1:47:08</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/af6d806f-6e02-4b8a-b12c-ed94b0f61215/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 24:  In this episode, we did into Lumen/Microsoft’s revelations on Russia's Turla APT stealing from a Pakistani APT, and issues around fourth-party espionage and problems with threat actor attribution.  We also discuss Citizen Lab’s findings on Monokle-like spyware implanted by Russian authorities, the slow pace of Salt Typhoon disinfection, the Solana web3.js supply chain attack affecting crypto projects, and the Romanian election crisis over Russian interference via TikTok.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Costin Raiu (https://twitter.com/craiu)and Ryan Naraine (https://twitter.com/ryanaraine). 
</description>
  <itunes:keywords>Monokle, Salt Typhoon, Turla, Solana, spyware, cyberespionage, ransomware, crypto, hacking, surveillance, encryption, regulations, elections, drones, cybersecurity</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 24</strong>:  In this episode, we did into Lumen/Microsoft’s revelations on Russia&#39;s Turla APT stealing from a Pakistani APT, and issues around fourth-party espionage and problems with threat actor attribution.  We also discuss Citizen Lab’s findings on Monokle-like spyware implanted by Russian authorities, the slow pace of Salt Typhoon disinfection, the Solana web3.js supply chain attack affecting crypto projects, and the Romanian election crisis over Russian interference via TikTok.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1agQ0TqskvYwnB69rmf2jcUReWMJQDfiIv6nrphsEWo0/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Russian APT Turla Caught Stealing From Pakistani APT" rel="nofollow" href="https://www.securityweek.com/spy-v-spy-russian-apt-turla-caught-stealing-from-pakistani-apt/">Russian APT Turla Caught Stealing From Pakistani APT</a></li><li><a title="Snowblind: The Invisible Hand of Secret Blizzard" rel="nofollow" href="https://blog.lumen.com/snowblind-the-invisible-hand-of-secret-blizzard/">Snowblind: The Invisible Hand of Secret Blizzard</a></li><li><a title="Microsoft: Secret Blizzard compromising Storm-0156 infrastructure for espionage | Microsoft Security Blog" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2024/12/04/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/">Microsoft: Secret Blizzard compromising Storm-0156 infrastructure for espionage | Microsoft Security Blog</a></li><li><a title="EpicTurla.com" rel="nofollow" href="https://epicturla.com">EpicTurla.com</a></li><li><a title="Device Confiscated by Russian Authorities Returned with Monokle-Type Spyware" rel="nofollow" href="https://citizenlab.ca/2024/12/device-confiscated-by-russian-authorities-returned-with-monokle-type-spyware-installed/">Device Confiscated by Russian Authorities Returned with Monokle-Type Spyware</a></li><li><a title="Lookout Security research paper on Monokle spyware" rel="nofollow" href="https://www.lookout.com/documents/threat-reports/lookout-discovers-monokle-threat-report.pdf">Lookout Security research paper on Monokle spyware</a></li><li><a title="Parubets: How a programmer foiled his own FSB recruitment" rel="nofollow" href="https://dept.one/story/parubets/">Parubets: How a programmer foiled his own FSB recruitment</a></li><li><a title="CISA/FBI guidance to repel Salt Typhoon" rel="nofollow" href="https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure">CISA/FBI guidance to repel Salt Typhoon</a></li><li><a title="US officials say they still have not expelled Chinese telco hackers" rel="nofollow" href="https://archive.ph/pncES">US officials say they still have not expelled Chinese telco hackers</a></li><li><a title="Solana backdoored in supply chain hack" rel="nofollow" href="https://github.com/solana-labs/solana-web3.js/releases">Solana backdoored in supply chain hack</a></li><li><a title="Romania&#39;s top court annuls first round of presidential vote won by far-right candidate" rel="nofollow" href="https://apnews.com/article/romania-election-president-georgescu-court-585e8f8f3ce7013951f5c7cf4054179b">Romania's top court annuls first round of presidential vote won by far-right candidate</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 24</strong>:  In this episode, we did into Lumen/Microsoft’s revelations on Russia&#39;s Turla APT stealing from a Pakistani APT, and issues around fourth-party espionage and problems with threat actor attribution.  We also discuss Citizen Lab’s findings on Monokle-like spyware implanted by Russian authorities, the slow pace of Salt Typhoon disinfection, the Solana web3.js supply chain attack affecting crypto projects, and the Romanian election crisis over Russian interference via TikTok.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a>and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a>.</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1agQ0TqskvYwnB69rmf2jcUReWMJQDfiIv6nrphsEWo0/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Russian APT Turla Caught Stealing From Pakistani APT" rel="nofollow" href="https://www.securityweek.com/spy-v-spy-russian-apt-turla-caught-stealing-from-pakistani-apt/">Russian APT Turla Caught Stealing From Pakistani APT</a></li><li><a title="Snowblind: The Invisible Hand of Secret Blizzard" rel="nofollow" href="https://blog.lumen.com/snowblind-the-invisible-hand-of-secret-blizzard/">Snowblind: The Invisible Hand of Secret Blizzard</a></li><li><a title="Microsoft: Secret Blizzard compromising Storm-0156 infrastructure for espionage | Microsoft Security Blog" rel="nofollow" href="https://www.microsoft.com/en-us/security/blog/2024/12/04/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/">Microsoft: Secret Blizzard compromising Storm-0156 infrastructure for espionage | Microsoft Security Blog</a></li><li><a title="EpicTurla.com" rel="nofollow" href="https://epicturla.com">EpicTurla.com</a></li><li><a title="Device Confiscated by Russian Authorities Returned with Monokle-Type Spyware" rel="nofollow" href="https://citizenlab.ca/2024/12/device-confiscated-by-russian-authorities-returned-with-monokle-type-spyware-installed/">Device Confiscated by Russian Authorities Returned with Monokle-Type Spyware</a></li><li><a title="Lookout Security research paper on Monokle spyware" rel="nofollow" href="https://www.lookout.com/documents/threat-reports/lookout-discovers-monokle-threat-report.pdf">Lookout Security research paper on Monokle spyware</a></li><li><a title="Parubets: How a programmer foiled his own FSB recruitment" rel="nofollow" href="https://dept.one/story/parubets/">Parubets: How a programmer foiled his own FSB recruitment</a></li><li><a title="CISA/FBI guidance to repel Salt Typhoon" rel="nofollow" href="https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure">CISA/FBI guidance to repel Salt Typhoon</a></li><li><a title="US officials say they still have not expelled Chinese telco hackers" rel="nofollow" href="https://archive.ph/pncES">US officials say they still have not expelled Chinese telco hackers</a></li><li><a title="Solana backdoored in supply chain hack" rel="nofollow" href="https://github.com/solana-labs/solana-web3.js/releases">Solana backdoored in supply chain hack</a></li><li><a title="Romania&#39;s top court annuls first round of presidential vote won by far-right candidate" rel="nofollow" href="https://apnews.com/article/romania-election-president-georgescu-court-585e8f8f3ce7013951f5c7cf4054179b">Romania's top court annuls first round of presidential vote won by far-right candidate</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Volexity’s Steven Adair on Russian Wi-Fi hacks, memory forensics, appliance 0days and network inspectability</title>
  <link>http://securityconversations.fireside.fm/steven-adair-nearest-neighbor-wifi-hack</link>
  <guid isPermaLink="false">38eb067c-05af-457d-91b4-9e809083d842</guid>
  <pubDate>Sat, 30 Nov 2024 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/38eb067c-05af-457d-91b4-9e809083d842.mp3" length="68926322" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 23:  Volexity founder Steven Adair joins the show to explore the significance of memory analysis and the technical challenges associated with memory dumping and forensics. We dig into Volexity’s “nearest neighbor” Wi-Fi hack discovery, gaps in EDR detection and telemetry, and some real-talk on the Volt Typhoon intrusions.

We also cover news on a Firefox zero-day exploited on the Tor browser, the  professionalization of ransomware, ESET's discovery of a Linux bootkit (we have a scoop on the origins of this!), Binarly research on connections to LogoFAIL, and major visibility gaps in the firmware ecosystem.

Cast: Ryan Naraine (SecurityWeek), Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh).

Honorary buddy: Steven Adair (Volexity)</itunes:subtitle>
  <itunes:duration>1:18:33</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/3/38eb067c-05af-457d-91b4-9e809083d842/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 23: Volexity founder Steven Adair joins the show to explore the significance of memory analysis and the technical challenges associated with memory dumping and forensics. We dig into Volexity’s “nearest neighbor” Wi-Fi hack discovery, gaps in EDR detection and telemetry, and some real-talk on the Volt Typhoon intrusions.
We also cover news on a Firefox zero-day exploited on the Tor browser, the  professionalization of ransomware, ESET's discovery of a Linux bootkit (we have a scoop on the origins of this!), Binarly research on connections to LogoFAIL, and major visibility gaps in the firmware ecosystem.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
Honorary buddy: Steven Adair (https://twitter.com/sadair) (Volexity)
</description>
  <itunes:keywords>Volexity, memory analysis, incident response, EDR, DEFCAMP, network telemetry,  Wi-Fi security, edge devices, ESET, TOR, Binarly, Bootkitty,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 23</strong>: Volexity founder Steven Adair joins the show to explore the significance of memory analysis and the technical challenges associated with memory dumping and forensics. We dig into Volexity’s “nearest neighbor” Wi-Fi hack discovery, gaps in EDR detection and telemetry, and some real-talk on the Volt Typhoon intrusions.</p>

<p>We also cover news on a Firefox zero-day exploited on the Tor browser, the  professionalization of ransomware, ESET&#39;s discovery of a Linux bootkit (we have a scoop on the origins of this!), Binarly research on connections to LogoFAIL, and major visibility gaps in the firmware ecosystem.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p>

<p><strong>Honorary buddy:</strong> <a href="https://twitter.com/sadair" rel="nofollow">Steven Adair</a> (Volexity)</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/10qv33zxzGUqQFkFc3FQ8ErRIdEdg4P8wUjBoIW5V1ZY/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Steven Adair on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/sadair/">Steven Adair on LinkedIn</a></li><li><a title="The Nearest Neighbor Wi-Fi Attack " rel="nofollow" href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/">The Nearest Neighbor Wi-Fi Attack </a></li><li><a title="Detecting Compromise of Palo Alto Networks GlobalProtect Devices" rel="nofollow" href="https://www.volexity.com/blog/2024/05/15/detecting-compromise-of-cve-2024-3400-on-palo-alto-networks-globalprotect-devices/">Detecting Compromise of Palo Alto Networks GlobalProtect Devices</a></li><li><a title="Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days" rel="nofollow" href="https://www.securityweek.com/volexity-catches-chinese-hackers-exploiting-ivanti-vpn-zero-days/">Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days</a></li><li><a title="Volexity Warns of &#39;Active Exploitation&#39; of Zimbra Zero-Day" rel="nofollow" href="https://www.securityweek.com/volexity-warns-active-exploitation-zimbra-zero-day/">Volexity Warns of 'Active Exploitation' of Zimbra Zero-Day</a></li><li><a title="RomCom exploits Firefox and Windows zero days in the wild" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/romcom-exploits-firefox-and-windows-zero-days-in-the-wild/">RomCom exploits Firefox and Windows zero days in the wild</a></li><li><a title="Bootkitty: Analyzing the first UEFI bootkit for Linux" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/">Bootkitty: Analyzing the first UEFI bootkit for Linux</a></li><li><a title="Binarly: LogoFAIL Exploited to Deploy Bootkitty" rel="nofollow" href="https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux">Binarly: LogoFAIL Exploited to Deploy Bootkitty</a></li><li><a title="T-Mobile statement on Salt Typhooon" rel="nofollow" href="https://www.t-mobile.com/news/un-carrier/update-cyberattacks-targeting-us-wireless-companies">T-Mobile statement on Salt Typhooon</a></li><li><a title="LABScon24 Replay -- Cristina Cifuentes" rel="nofollow" href="https://www.youtube.com/watch?v=wo3xEa2elp4&amp;ab_channel=SentinelOne">LABScon24 Replay -- Cristina Cifuentes</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 23</strong>: Volexity founder Steven Adair joins the show to explore the significance of memory analysis and the technical challenges associated with memory dumping and forensics. We dig into Volexity’s “nearest neighbor” Wi-Fi hack discovery, gaps in EDR detection and telemetry, and some real-talk on the Volt Typhoon intrusions.</p>

<p>We also cover news on a Firefox zero-day exploited on the Tor browser, the  professionalization of ransomware, ESET&#39;s discovery of a Linux bootkit (we have a scoop on the origins of this!), Binarly research on connections to LogoFAIL, and major visibility gaps in the firmware ecosystem.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p>

<p><strong>Honorary buddy:</strong> <a href="https://twitter.com/sadair" rel="nofollow">Steven Adair</a> (Volexity)</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/10qv33zxzGUqQFkFc3FQ8ErRIdEdg4P8wUjBoIW5V1ZY/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Steven Adair on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/sadair/">Steven Adair on LinkedIn</a></li><li><a title="The Nearest Neighbor Wi-Fi Attack " rel="nofollow" href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/">The Nearest Neighbor Wi-Fi Attack </a></li><li><a title="Detecting Compromise of Palo Alto Networks GlobalProtect Devices" rel="nofollow" href="https://www.volexity.com/blog/2024/05/15/detecting-compromise-of-cve-2024-3400-on-palo-alto-networks-globalprotect-devices/">Detecting Compromise of Palo Alto Networks GlobalProtect Devices</a></li><li><a title="Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days" rel="nofollow" href="https://www.securityweek.com/volexity-catches-chinese-hackers-exploiting-ivanti-vpn-zero-days/">Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days</a></li><li><a title="Volexity Warns of &#39;Active Exploitation&#39; of Zimbra Zero-Day" rel="nofollow" href="https://www.securityweek.com/volexity-warns-active-exploitation-zimbra-zero-day/">Volexity Warns of 'Active Exploitation' of Zimbra Zero-Day</a></li><li><a title="RomCom exploits Firefox and Windows zero days in the wild" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/romcom-exploits-firefox-and-windows-zero-days-in-the-wild/">RomCom exploits Firefox and Windows zero days in the wild</a></li><li><a title="Bootkitty: Analyzing the first UEFI bootkit for Linux" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/">Bootkitty: Analyzing the first UEFI bootkit for Linux</a></li><li><a title="Binarly: LogoFAIL Exploited to Deploy Bootkitty" rel="nofollow" href="https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux">Binarly: LogoFAIL Exploited to Deploy Bootkitty</a></li><li><a title="T-Mobile statement on Salt Typhooon" rel="nofollow" href="https://www.t-mobile.com/news/un-carrier/update-cyberattacks-targeting-us-wireless-companies">T-Mobile statement on Salt Typhooon</a></li><li><a title="LABScon24 Replay -- Cristina Cifuentes" rel="nofollow" href="https://www.youtube.com/watch?v=wo3xEa2elp4&amp;ab_channel=SentinelOne">LABScon24 Replay -- Cristina Cifuentes</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Russian APT weaponized nearby Wi-Fi networks in DC, new macOS zero-days, DOJ v Chrome</title>
  <link>http://securityconversations.fireside.fm/tbp-ep22</link>
  <guid isPermaLink="false">afa36e08-3818-4a0c-ac7a-55ff9ff6c02b</guid>
  <pubDate>Fri, 22 Nov 2024 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/afa36e08-3818-4a0c-ac7a-55ff9ff6c02b.mp3" length="71756075" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 22:  We discuss Volexity’s presentation on Russian APT operators hacking Wi-Fi networks in “nearest neighbor attacks,” the Chinese surveillance state and its impact on global security, the NSA's strange call for better data sharing on Salt Typhoon intrusions, and the failures of regulatory bodies to address cybersecurity risks.

We also cover two new Apple zero-days being exploited in the wild, the US Government’s demand that Google sell the Chrome browser, and the value of data in the context of AI.

Cast: Ryan Naraine (SecurityWeek), Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh).</itunes:subtitle>
  <itunes:duration>1:28:22</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/afa36e08-3818-4a0c-ac7a-55ff9ff6c02b/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 22:  We discuss Volexity’s presentation on Russian APT operators hacking Wi-Fi networks in “nearest neighbor attacks,” the Chinese surveillance state and its impact on global security, the NSA's strange call for better data sharing on Salt Typhoon intrusions, and the failures of regulatory bodies to address cybersecurity risks.
We also cover two new Apple zero-days being exploited in the wild, the US Government’s demand that Google sell the Chrome browser, and the value of data in the context of AI.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>Cyberwarcon, APT 28, Wi-Fi hacking, cybersecurity, Chinese surveillance, data sharing, NSA, vendor accountability, cybersecurity, information sharing, regulatory failures, market solutions, NSA, Google breakup, data privacy, surveillance capitalism, antitrust, corporate relationships, Apple, cybersecurity, North Korea, gig economy, cryptocurrency, AI, exploits, security updates, fake IT workers, supply chain attacks</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 22</strong>:  We discuss Volexity’s presentation on Russian APT operators hacking Wi-Fi networks in “nearest neighbor attacks,” the Chinese surveillance state and its impact on global security, the NSA&#39;s strange call for better data sharing on Salt Typhoon intrusions, and the failures of regulatory bodies to address cybersecurity risks.</p>

<p>We also cover two new Apple zero-days being exploited in the wild, the US Government’s demand that Google sell the Chrome browser, and the value of data in the context of AI.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript - (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1-NW6qC6vrI-zQZMM1fQ7ldGgUwFUohtVun1CHsxl_TU/edit?tab=t.0">Transcript - (unedited, AI-generated)</a></li><li><a title="Russian APT WiFI Nearest Neighbor Attack " rel="nofollow" href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/">Russian APT WiFI Nearest Neighbor Attack </a></li><li><a title="Russian Spies Jumped From One Network to Another Via Wi-Fi" rel="nofollow" href="https://archive.ph/f0O3n">Russian Spies Jumped From One Network to Another Via Wi-Fi</a></li><li><a title="Advisory: New exploited Apple zero-days" rel="nofollow" href="https://support.apple.com/en-us/121753">Advisory: New exploited Apple zero-days</a></li><li><a title="NSA Director Wants Industry to Disclose Details of Telecom Hacks" rel="nofollow" href="https://archive.ph/2024.11.20-231241/https://www.bloomberg.com/news/articles/2024-11-20/nsa-director-wants-industry-to-disclose-details-of-telecom-hacks#selection-1321.13-1328.0">NSA Director Wants Industry to Disclose Details of Telecom Hacks</a></li><li><a title="Microsoft&#39;s &quot;Free&quot; Plan to Upgrade Government Cybersecurity Was Designed to Box Out Competitors and Drive Profits" rel="nofollow" href="https://www.propublica.org/article/microsoft-white-house-offer-cybersecurity-biden-nadella">Microsoft's "Free" Plan to Upgrade Government Cybersecurity Was Designed to Box Out Competitors and Drive Profits</a></li><li><a title="Microsoft accuses Google of &#39;Shadow Campaigns&#39;" rel="nofollow" href="https://blogs.microsoft.com/on-the-issues/2024/10/28/googles-shadow-campaigns/">Microsoft accuses Google of 'Shadow Campaigns'</a></li><li><a title="DOJ calls for breakup of Google and sale of Chrome" rel="nofollow" href="https://www.nbcnews.com/news/us-news/google-department-of-justice-chrome-sale-breakup-microsoft-apple-rcna181133">DOJ calls for breakup of Google and sale of Chrome</a></li><li><a title="DPRK IT Workers -- A Network of Active Front Companies and Their Links to China" rel="nofollow" href="https://www.sentinelone.com/labs/dprk-it-workers-a-network-of-active-front-companies-and-their-links-to-china/">DPRK IT Workers -- A Network of Active Front Companies and Their Links to China</a></li><li><a title="Be careful when coding with ChatGPT" rel="nofollow" href="https://x.com/r_cky0/status/1859656430888026524">Be careful when coding with ChatGPT</a></li><li><a title="GSM-Symbolic: Understanding the Limitations of Mathematical Reasoning in Large Language Models" rel="nofollow" href="https://arxiv.org/pdf/2410.05229">GSM-Symbolic: Understanding the Limitations of Mathematical Reasoning in Large Language Models</a></li><li><a title="PIVOTcon 2025" rel="nofollow" href="https://pivotcon.org/">PIVOTcon 2025</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 22</strong>:  We discuss Volexity’s presentation on Russian APT operators hacking Wi-Fi networks in “nearest neighbor attacks,” the Chinese surveillance state and its impact on global security, the NSA&#39;s strange call for better data sharing on Salt Typhoon intrusions, and the failures of regulatory bodies to address cybersecurity risks.</p>

<p>We also cover two new Apple zero-days being exploited in the wild, the US Government’s demand that Google sell the Chrome browser, and the value of data in the context of AI.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript - (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1-NW6qC6vrI-zQZMM1fQ7ldGgUwFUohtVun1CHsxl_TU/edit?tab=t.0">Transcript - (unedited, AI-generated)</a></li><li><a title="Russian APT WiFI Nearest Neighbor Attack " rel="nofollow" href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/">Russian APT WiFI Nearest Neighbor Attack </a></li><li><a title="Russian Spies Jumped From One Network to Another Via Wi-Fi" rel="nofollow" href="https://archive.ph/f0O3n">Russian Spies Jumped From One Network to Another Via Wi-Fi</a></li><li><a title="Advisory: New exploited Apple zero-days" rel="nofollow" href="https://support.apple.com/en-us/121753">Advisory: New exploited Apple zero-days</a></li><li><a title="NSA Director Wants Industry to Disclose Details of Telecom Hacks" rel="nofollow" href="https://archive.ph/2024.11.20-231241/https://www.bloomberg.com/news/articles/2024-11-20/nsa-director-wants-industry-to-disclose-details-of-telecom-hacks#selection-1321.13-1328.0">NSA Director Wants Industry to Disclose Details of Telecom Hacks</a></li><li><a title="Microsoft&#39;s &quot;Free&quot; Plan to Upgrade Government Cybersecurity Was Designed to Box Out Competitors and Drive Profits" rel="nofollow" href="https://www.propublica.org/article/microsoft-white-house-offer-cybersecurity-biden-nadella">Microsoft's "Free" Plan to Upgrade Government Cybersecurity Was Designed to Box Out Competitors and Drive Profits</a></li><li><a title="Microsoft accuses Google of &#39;Shadow Campaigns&#39;" rel="nofollow" href="https://blogs.microsoft.com/on-the-issues/2024/10/28/googles-shadow-campaigns/">Microsoft accuses Google of 'Shadow Campaigns'</a></li><li><a title="DOJ calls for breakup of Google and sale of Chrome" rel="nofollow" href="https://www.nbcnews.com/news/us-news/google-department-of-justice-chrome-sale-breakup-microsoft-apple-rcna181133">DOJ calls for breakup of Google and sale of Chrome</a></li><li><a title="DPRK IT Workers -- A Network of Active Front Companies and Their Links to China" rel="nofollow" href="https://www.sentinelone.com/labs/dprk-it-workers-a-network-of-active-front-companies-and-their-links-to-china/">DPRK IT Workers -- A Network of Active Front Companies and Their Links to China</a></li><li><a title="Be careful when coding with ChatGPT" rel="nofollow" href="https://x.com/r_cky0/status/1859656430888026524">Be careful when coding with ChatGPT</a></li><li><a title="GSM-Symbolic: Understanding the Limitations of Mathematical Reasoning in Large Language Models" rel="nofollow" href="https://arxiv.org/pdf/2410.05229">GSM-Symbolic: Understanding the Limitations of Mathematical Reasoning in Large Language Models</a></li><li><a title="PIVOTcon 2025" rel="nofollow" href="https://pivotcon.org/">PIVOTcon 2025</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>What happens to CISA now? Is deterrence in cyber possible?</title>
  <link>http://securityconversations.fireside.fm/tbp-ep21</link>
  <guid isPermaLink="false">fde7baf5-5ce2-4870-ac23-2881f78b9684</guid>
  <pubDate>Fri, 15 Nov 2024 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/fde7baf5-5ce2-4870-ac23-2881f78b9684.mp3" length="93206263" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 21:  We dig into an incredible government report on Iranian hacking group Emennet Pasargad and tradecraft during the Israel/Hamas war, why Predatory Sparrow could have been aimed at deterrence in cyber, and the significance of the FBI/CISA public confirmation of China-linked Salt Typhoon hacks. 

Plus, discussion on hina’s cyber capabilities, the narrative around “pre-positioning” for a Taiwan conflict, the blending of cyber and kinetic operations, and the long tail of Chinese researchers reporting Microsoft Windows vulnerabilities. The future of CISA is a recurring theme throughout this episode with some speculation about what happens to the agency under the Trump administration.

Cast: Ryan Naraine (SecurityWeek), Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh).</itunes:subtitle>
  <itunes:duration>1:53:51</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/f/fde7baf5-5ce2-4870-ac23-2881f78b9684/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 21:  We dig into an incredible government report on Iranian hacking group Emennet Pasargad and tradecraft during the Israel/Hamas war, why Predatory Sparrow could have been aimed at deterrence in cyber, and the FBI/CISA public confirmation of the mysterious Salt Typhoon hacks. 
Plus, discussion on hina’s cyber capabilities, the narrative around “pre-positioning” for a Taiwan conflict, the blending of cyber and kinetic operations, and the long tail of Chinese researchers reporting Microsoft Windows vulnerabilities. The future of CISA is a recurring theme throughout this episode with some speculation about what happens to the agency under the Trump administration.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>Iran, Hamas, FBI CISA report, Predatory Sparrow, FOMO Typhoon, Salt Typhoon, Volt Typhoon, cyber espionage, Volt Typhoon, cyber espionage,  firewall vulnerabilities, CISA, Bitcoin, cryptocurrency, ransomware, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 21</strong>:  We dig into an incredible government report on Iranian hacking group Emennet Pasargad and tradecraft during the Israel/Hamas war, why Predatory Sparrow could have been aimed at deterrence in cyber, and the FBI/CISA public confirmation of the mysterious Salt Typhoon hacks. </p>

<p>Plus, discussion on hina’s cyber capabilities, the narrative around “pre-positioning” for a Taiwan conflict, the blending of cyber and kinetic operations, and the long tail of Chinese researchers reporting Microsoft Windows vulnerabilities. The future of CISA is a recurring theme throughout this episode with some speculation about what happens to the agency under the Trump administration.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/19N5nXfxOZNhXeq_dlWVNx9kKQE3ldoUtgJbcq3huNDM/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="CISA/Israel gov report on Iranian hacking operations" rel="nofollow" href="https://www.ic3.gov/CSA/2024/241030.pdf">CISA/Israel gov report on Iranian hacking operations</a></li><li><a title="Check Point: A deep-dive of Iran&#39;s WezRat malware" rel="nofollow" href="https://research.checkpoint.com/2024/wezrat-malware-deep-dive/">Check Point: A deep-dive of Iran's WezRat malware</a></li><li><a title="Trend Micro report on Earth Estries" rel="nofollow" href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">Trend Micro report on Earth Estries</a></li><li><a title="FBI/CISA on China hacking US telcos" rel="nofollow" href="https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications">FBI/CISA on China hacking US telcos</a></li><li><a title="US accuses China of vast cyberespionage against telecoms" rel="nofollow" href="https://archive.ph/kdC7a">US accuses China of vast cyberespionage against telecoms</a></li><li><a title="Volt Typhoon hackers hit SingTel in Singapore" rel="nofollow" href="https://archive.ph/PefIJ">Volt Typhoon hackers hit SingTel in Singapore</a></li><li><a title="New Palo Alto firewall 0day attack" rel="nofollow" href="https://security.paloaltonetworks.com/PAN-SA-2024-0015">New Palo Alto firewall 0day attack</a></li><li><a title="CVE-2024-43450 - China reports Windows DNS Spoofing vuln" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43450">CVE-2024-43450 - China reports Windows DNS Spoofing vuln</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 21</strong>:  We dig into an incredible government report on Iranian hacking group Emennet Pasargad and tradecraft during the Israel/Hamas war, why Predatory Sparrow could have been aimed at deterrence in cyber, and the FBI/CISA public confirmation of the mysterious Salt Typhoon hacks. </p>

<p>Plus, discussion on hina’s cyber capabilities, the narrative around “pre-positioning” for a Taiwan conflict, the blending of cyber and kinetic operations, and the long tail of Chinese researchers reporting Microsoft Windows vulnerabilities. The future of CISA is a recurring theme throughout this episode with some speculation about what happens to the agency under the Trump administration.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/19N5nXfxOZNhXeq_dlWVNx9kKQE3ldoUtgJbcq3huNDM/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="CISA/Israel gov report on Iranian hacking operations" rel="nofollow" href="https://www.ic3.gov/CSA/2024/241030.pdf">CISA/Israel gov report on Iranian hacking operations</a></li><li><a title="Check Point: A deep-dive of Iran&#39;s WezRat malware" rel="nofollow" href="https://research.checkpoint.com/2024/wezrat-malware-deep-dive/">Check Point: A deep-dive of Iran's WezRat malware</a></li><li><a title="Trend Micro report on Earth Estries" rel="nofollow" href="https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html">Trend Micro report on Earth Estries</a></li><li><a title="FBI/CISA on China hacking US telcos" rel="nofollow" href="https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications">FBI/CISA on China hacking US telcos</a></li><li><a title="US accuses China of vast cyberespionage against telecoms" rel="nofollow" href="https://archive.ph/kdC7a">US accuses China of vast cyberespionage against telecoms</a></li><li><a title="Volt Typhoon hackers hit SingTel in Singapore" rel="nofollow" href="https://archive.ph/PefIJ">Volt Typhoon hackers hit SingTel in Singapore</a></li><li><a title="New Palo Alto firewall 0day attack" rel="nofollow" href="https://security.paloaltonetworks.com/PAN-SA-2024-0015">New Palo Alto firewall 0day attack</a></li><li><a title="CVE-2024-43450 - China reports Windows DNS Spoofing vuln" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43450">CVE-2024-43450 - China reports Windows DNS Spoofing vuln</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Mysterious rebooting iPhones, EDR vendors spying on hackers, Bitcoin 'meatspace' attacks</title>
  <link>http://securityconversations.fireside.fm/tbp-ep20</link>
  <guid isPermaLink="false">4b7375c6-6a49-4e92-8bd1-e706a996e883</guid>
  <pubDate>Sat, 09 Nov 2024 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/4b7375c6-6a49-4e92-8bd1-e706a996e883.mp3" length="76955697" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 20:  We revisit the ‘hack-back’ debate, the threshold for spying on adversaries, Palo Alto watching EDR bypass research to track threat actors, hot nuggets in Project Zero’s Clem Lecinge’s Hexacon talk, Apple’s new iOS update rebooting iPhones in law enforcement custody, the mysterious GoblinRAT backdoor, and physical ‘meatspace’ Bitcoin attacks and more details on North Korean cryptocurrency theft.

Cast: Ryan Naraine (SecurityWeek), Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh).</itunes:subtitle>
  <itunes:duration>1:37:00</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/4b7375c6-6a49-4e92-8bd1-e706a996e883/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 20:  We revisit the ‘hack-back’ debate, the threshold for spying on adversaries, Palo Alto watching EDR bypass research to track threat actors, hot nuggets in Project Zero’s Clem Lecinge’s Hexacon talk, Apple’s new iOS update rebooting iPhones in law enforcement custody, the mysterious GoblinRAT backdoor, and physical ‘meatspace’ Bitcoin attacks and more details on North Korean cryptocurrency theft.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>Keywords  cybersecurity, EDR software, Google Project Zero, telemetry, threat intelligence, information sharing, security research, exploitation techniques, legal considerations, transparency, EDR, Windows Defender, telemetry, security research, Apple, malware analysis, privacy, law enforcement, cybersecurity, antivirus, Salt Typhoon, Chinese APTs, cyber threats, Goblin Rat, Bitcoin attacks, North Korea, espionage, cybersecurity, iOS vulnerabilities, surveillance</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 20</strong>:  We revisit the ‘hack-back’ debate, the threshold for spying on adversaries, Palo Alto watching EDR bypass research to track threat actors, hot nuggets in Project Zero’s Clem Lecinge’s Hexacon talk, Apple’s new iOS update rebooting iPhones in law enforcement custody, the mysterious GoblinRAT backdoor, and physical ‘meatspace’ Bitcoin attacks and more details on North Korean cryptocurrency theft.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1_R5EC39CoxPRz67njLfqKVLjq8bdkdh6h7l7UwaVHAE/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="iPhones mysteriously rebooting themselves" rel="nofollow" href="https://archive.vn/JMEbq">iPhones mysteriously rebooting themselves</a></li><li><a title="Apple quietly ships iPhone reboot code" rel="nofollow" href="https://archive.ph/lpoLQ">Apple quietly ships iPhone reboot code</a></li><li><a title="FBI on China hacking US presidential campaigns iPhones" rel="nofollow" href="https://archive.ph/iAQzO">FBI on China hacking US presidential campaigns iPhones</a></li><li><a title="Chinese hackers Targeted Phones of Trump, Vance, Harris Campaigns" rel="nofollow" href="https://www.wsj.com/politics/national-security/chinese-hackers-targeted-phones-of-trump-vance-and-harris-campaign-e04abbdf?mod=article_inline">Chinese hackers Targeted Phones of Trump, Vance, Harris Campaigns</a></li><li><a title="Palo Alto: EDR Bypass Testing Reveals Threat Actor&#39;s Toolkit" rel="nofollow" href="https://unit42.paloaltonetworks.com/edr-bypass-extortion-attempt-thwarted/">Palo Alto: EDR Bypass Testing Reveals Threat Actor's Toolkit</a></li><li><a title="Palo Alto CVE-2024-5910 marked as exploited" rel="nofollow" href="https://security.paloaltonetworks.com/CVE-2024-5910">Palo Alto CVE-2024-5910 marked as exploited</a></li><li><a title="Toronto crypto company CEO kidnapped" rel="nofollow" href="https://www.cbc.ca/news/canada/toronto/kidnapping-toronto-businessman-cryptocurrency-1.7376679">Toronto crypto company CEO kidnapped</a></li><li><a title="A list of known &#39;meatspace&#39; crypto attacks" rel="nofollow" href="https://github.com/jlopp/physical-bitcoin-attacks">A list of known 'meatspace' crypto attacks</a></li><li><a title="North Korea crypto thieves targets macOS" rel="nofollow" href="https://www.sentinelone.com/labs/bluenoroff-hidden-risk-threat-actor-targets-macs-with-fake-crypto-news-and-novel-persistence/">North Korea crypto thieves targets macOS</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 20</strong>:  We revisit the ‘hack-back’ debate, the threshold for spying on adversaries, Palo Alto watching EDR bypass research to track threat actors, hot nuggets in Project Zero’s Clem Lecinge’s Hexacon talk, Apple’s new iOS update rebooting iPhones in law enforcement custody, the mysterious GoblinRAT backdoor, and physical ‘meatspace’ Bitcoin attacks and more details on North Korean cryptocurrency theft.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1_R5EC39CoxPRz67njLfqKVLjq8bdkdh6h7l7UwaVHAE/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="iPhones mysteriously rebooting themselves" rel="nofollow" href="https://archive.vn/JMEbq">iPhones mysteriously rebooting themselves</a></li><li><a title="Apple quietly ships iPhone reboot code" rel="nofollow" href="https://archive.ph/lpoLQ">Apple quietly ships iPhone reboot code</a></li><li><a title="FBI on China hacking US presidential campaigns iPhones" rel="nofollow" href="https://archive.ph/iAQzO">FBI on China hacking US presidential campaigns iPhones</a></li><li><a title="Chinese hackers Targeted Phones of Trump, Vance, Harris Campaigns" rel="nofollow" href="https://www.wsj.com/politics/national-security/chinese-hackers-targeted-phones-of-trump-vance-and-harris-campaign-e04abbdf?mod=article_inline">Chinese hackers Targeted Phones of Trump, Vance, Harris Campaigns</a></li><li><a title="Palo Alto: EDR Bypass Testing Reveals Threat Actor&#39;s Toolkit" rel="nofollow" href="https://unit42.paloaltonetworks.com/edr-bypass-extortion-attempt-thwarted/">Palo Alto: EDR Bypass Testing Reveals Threat Actor's Toolkit</a></li><li><a title="Palo Alto CVE-2024-5910 marked as exploited" rel="nofollow" href="https://security.paloaltonetworks.com/CVE-2024-5910">Palo Alto CVE-2024-5910 marked as exploited</a></li><li><a title="Toronto crypto company CEO kidnapped" rel="nofollow" href="https://www.cbc.ca/news/canada/toronto/kidnapping-toronto-businessman-cryptocurrency-1.7376679">Toronto crypto company CEO kidnapped</a></li><li><a title="A list of known &#39;meatspace&#39; crypto attacks" rel="nofollow" href="https://github.com/jlopp/physical-bitcoin-attacks">A list of known 'meatspace' crypto attacks</a></li><li><a title="North Korea crypto thieves targets macOS" rel="nofollow" href="https://www.sentinelone.com/labs/bluenoroff-hidden-risk-threat-actor-targets-macs-with-fake-crypto-news-and-novel-persistence/">North Korea crypto thieves targets macOS</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela</title>
  <link>http://securityconversations.fireside.fm/tbp-ep19</link>
  <guid isPermaLink="false">afe08ad2-3625-4575-aaae-280d146e474c</guid>
  <pubDate>Sun, 03 Nov 2024 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/afe08ad2-3625-4575-aaae-280d146e474c.mp3" length="89415224" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 19:  We explore Ivan Kwiatkowski’s essay on the limits of threat intelligence, Sophos using kernel implants to surveil Chinese hackers, the concept of ‘hack-back’ and legal implications, geopolitical layers of cyber espionage, CIA malware in Venezuela, Vatican/Mossad mentioned in high-profile Italy hacks, and Canada bracing for .gov attacks from India.

Cast: Ryan Naraine (SecurityWeek), Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh).</itunes:subtitle>
  <itunes:duration>1:54:14</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/afe08ad2-3625-4575-aaae-280d146e474c/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 19:   We explore Ivan Kwiatkowski’s essay on the limits of threat intelligence, Sophos using kernel implants to surveil Chinese hackers, the concept of ‘hack-back’ and legal implications, geopolitical layers of cyber espionage, CIA malware in Venezuela, Vatican/Mossad mentioned in high-profile Italy hacks, and Canada bracing for .gov attacks from India.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>Sophos, implants, firewall devices, appliances, China, Chengdu, CIA, Fortinet, Ivanti, Barracuda, India, Canada</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 19</strong>:   We explore Ivan Kwiatkowski’s essay on the limits of threat intelligence, Sophos using kernel implants to surveil Chinese hackers, the concept of ‘hack-back’ and legal implications, geopolitical layers of cyber espionage, CIA malware in Venezuela, Vatican/Mossad mentioned in high-profile Italy hacks, and Canada bracing for .gov attacks from India.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1U8q76wqVXIs9Sdc8vuqAr2S9CtknvnYryxS6l0IALv8/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Ivan Kwiatkowski: Threat intel truths inside" rel="nofollow" href="https://blog.kwiatkowski.fr/threat-intel-truths-inside">Ivan Kwiatkowski: Threat intel truths inside</a></li><li><a title="JAG-S LABScon keynote" rel="nofollow" href="https://securityconversations.com/episode/ep13-the-consolation-of-threat-intel-jag-s-labscon-keynote/">JAG-S LABScon keynote</a></li><li><a title="Sophos Used Custom Implants to Surveil Chinese Hackers" rel="nofollow" href="https://www.securityweek.com/sophos-used-custom-implants-to-surveil-chinese-hackers-targeting-firewall-zero-days/">Sophos Used Custom Implants to Surveil Chinese Hackers</a></li><li><a title="Sophos Pacific Rim report" rel="nofollow" href="https://www.sophos.com/en-us/content/pacific-rim">Sophos Pacific Rim report</a></li><li><a title="NCSC details ‘Pygmy Goat’ network backdoor" rel="nofollow" href="https://www.securityweek.com/ncsc-details-pygmy-goat-backdoor-planted-on-hacked-sophos-firewall-devices/">NCSC details ‘Pygmy Goat’ network backdoor</a></li><li><a title="NCSC &#39;Pygmy Goat&#39; report" rel="nofollow" href="https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/pygmy-goat/ncsc-mar-pygmy-goat.pdf">NCSC 'Pygmy Goat' report</a></li><li><a title="Massive hack-for-hire scandal rocks Italian political elites – POLITICO" rel="nofollow" href="https://www.politico.eu/article/hacking-scandal-italy-matteo-renzi-sergio-mattarella-equalize-nunzio-samuele-calamucci/">Massive hack-for-hire scandal rocks Italian political elites – POLITICO</a></li><li><a title="Vatican, Israel implicated in Italy hacking scandal" rel="nofollow" href="https://www.politico.eu/article/vatican-israel-italian-hacking-scandal-uk-lithuania-equalize/">Vatican, Israel implicated in Italy hacking scandal</a></li><li><a title="Wired on CIA hack of Venezuela military payroll system" rel="nofollow" href="https://www.wired.com/story/trump-cia-venezuela-maduro-regime-change-plot/?utm_medium=social&amp;mbid=social_twitter&amp;utm_social-type=owned&amp;utm_source=twitter&amp;utm_brand=wired">Wired on CIA hack of Venezuela military payroll system</a></li><li><a title="Is Now on VT!" rel="nofollow" href="https://x.com/Now_on_VT">Is Now on VT!</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 19</strong>:   We explore Ivan Kwiatkowski’s essay on the limits of threat intelligence, Sophos using kernel implants to surveil Chinese hackers, the concept of ‘hack-back’ and legal implications, geopolitical layers of cyber espionage, CIA malware in Venezuela, Vatican/Mossad mentioned in high-profile Italy hacks, and Canada bracing for .gov attacks from India.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1U8q76wqVXIs9Sdc8vuqAr2S9CtknvnYryxS6l0IALv8/edit?usp=sharing">Transcript (unedited, AI-generated)</a></li><li><a title="Ivan Kwiatkowski: Threat intel truths inside" rel="nofollow" href="https://blog.kwiatkowski.fr/threat-intel-truths-inside">Ivan Kwiatkowski: Threat intel truths inside</a></li><li><a title="JAG-S LABScon keynote" rel="nofollow" href="https://securityconversations.com/episode/ep13-the-consolation-of-threat-intel-jag-s-labscon-keynote/">JAG-S LABScon keynote</a></li><li><a title="Sophos Used Custom Implants to Surveil Chinese Hackers" rel="nofollow" href="https://www.securityweek.com/sophos-used-custom-implants-to-surveil-chinese-hackers-targeting-firewall-zero-days/">Sophos Used Custom Implants to Surveil Chinese Hackers</a></li><li><a title="Sophos Pacific Rim report" rel="nofollow" href="https://www.sophos.com/en-us/content/pacific-rim">Sophos Pacific Rim report</a></li><li><a title="NCSC details ‘Pygmy Goat’ network backdoor" rel="nofollow" href="https://www.securityweek.com/ncsc-details-pygmy-goat-backdoor-planted-on-hacked-sophos-firewall-devices/">NCSC details ‘Pygmy Goat’ network backdoor</a></li><li><a title="NCSC &#39;Pygmy Goat&#39; report" rel="nofollow" href="https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/pygmy-goat/ncsc-mar-pygmy-goat.pdf">NCSC 'Pygmy Goat' report</a></li><li><a title="Massive hack-for-hire scandal rocks Italian political elites – POLITICO" rel="nofollow" href="https://www.politico.eu/article/hacking-scandal-italy-matteo-renzi-sergio-mattarella-equalize-nunzio-samuele-calamucci/">Massive hack-for-hire scandal rocks Italian political elites – POLITICO</a></li><li><a title="Vatican, Israel implicated in Italy hacking scandal" rel="nofollow" href="https://www.politico.eu/article/vatican-israel-italian-hacking-scandal-uk-lithuania-equalize/">Vatican, Israel implicated in Italy hacking scandal</a></li><li><a title="Wired on CIA hack of Venezuela military payroll system" rel="nofollow" href="https://www.wired.com/story/trump-cia-venezuela-maduro-regime-change-plot/?utm_medium=social&amp;mbid=social_twitter&amp;utm_social-type=owned&amp;utm_source=twitter&amp;utm_brand=wired">Wired on CIA hack of Venezuela military payroll system</a></li><li><a title="Is Now on VT!" rel="nofollow" href="https://x.com/Now_on_VT">Is Now on VT!</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Fortinet 0days, Appin hack-for-hire exposé, crypto heists, Russians booted from Linux kernel</title>
  <link>http://securityconversations.fireside.fm/tbp-ep18</link>
  <guid isPermaLink="false">90ccac79-0895-4cbf-a28e-805a46c7e3da</guid>
  <pubDate>Fri, 25 Oct 2024 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/90ccac79-0895-4cbf-a28e-805a46c7e3da.mp3" length="63377599" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 18:  This week’s show covers the White House's new Traffic Light Protocol (TLP) guidance, Reuters expose of Appin as a hack-for-hire mercenary company, Fortinet zero-day exploitation and missing CSRB investigations, major cryptocurrency heists, Apple opening Private Cloud Compute to public inspection, Russians removed from Linux kernel maintenance and China’s Antiy beefing with Sentinel One over APT reporting.

Cast: Ryan Naraine (SecurityWeek), Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh).</itunes:subtitle>
  <itunes:duration>1:26:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/9/90ccac79-0895-4cbf-a28e-805a46c7e3da/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 18:  This week’s show covers the White House's new Traffic Light Protocol (TLP) guidance, Reuters expose of Appin as a hack-for-hire mercenary company, Fortinet zero-day exploitation and missing CSRB investigations, major cryptocurrency heists, Apple opening Private Cloud Compute to public inspection, Russians removed from Linux kernel maintenance and China’s Antiy beefing with Sentinel One over APT reporting.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>TLP, White House, Appin, Reuters, S1, hack-for-hire, Apple, Private Cloud Computer, Fortinet, Ivanti, Pulse Secure, CSRB, crypto, North Korea, Linux, Russia, Antiy, Sentinel One</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 18</strong>:  This week’s show covers the White House&#39;s new Traffic Light Protocol (TLP) guidance, Reuters expose of Appin as a hack-for-hire mercenary company, Fortinet zero-day exploitation and missing CSRB investigations, major cryptocurrency heists, Apple opening Private Cloud Compute to public inspection, Russians removed from Linux kernel maintenance and China’s Antiy beefing with Sentinel One over APT reporting.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1z-Dz25Mmb_97ulETvoKROgQPiN5BHQ_USGvArAqpFXs/edit?usp=sharing">Transcript (AI-generated)</a></li><li><a title="White House TLP guidance" rel="nofollow" href="https://www.whitehouse.gov/oncd/briefing-room/2024/10/22/doubling-down-on-trusted-partnerships-our-commitment-to-researchers/">White House TLP guidance</a></li><li><a title="Applin -- How an Indian startup hacked the world" rel="nofollow" href="https://www.reuters.com/investigates/special-report/usa-hackers-appin/">Applin -- How an Indian startup hacked the world</a></li><li><a title="Burning Zero Days: FortiJump FortiManager Flaw" rel="nofollow" href="https://doublepulsar.com/burning-zero-days-fortijump-fortimanager-vulnerability-used-by-nation-state-in-espionage-via-msps-c79abec59773">Burning Zero Days: FortiJump FortiManager Flaw</a></li><li><a title="Mandiant on FortiManager Zero-Day Exploitation" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/fortimanager-zero-day-exploitation-cve-2024-47575">Mandiant on FortiManager Zero-Day Exploitation</a></li><li><a title="Fortinet bulletin on new 0day exploitation" rel="nofollow" href="https://www.fortiguard.com/psirt/FG-IR-24-423">Fortinet bulletin on new 0day exploitation</a></li><li><a title="Radiant Capital $50M cryptocurrency theft" rel="nofollow" href="https://medium.com/@RadiantCapital/radiant-post-mortem-fecd6cd38081">Radiant Capital $50M cryptocurrency theft</a></li><li><a title="DPRK&#39;s Lazarus steals cryptocurrency with decoy MOBA game" rel="nofollow" href="https://securelist.com/lazarus-apt-steals-crypto-with-a-tank-game/114282/">DPRK's Lazarus steals cryptocurrency with decoy MOBA game</a></li><li><a title="Apple opens Private Cloud Compute to security inspection" rel="nofollow" href="https://security.apple.com/blog/pcc-security-research">Apple opens Private Cloud Compute to security inspection</a></li><li><a title="Russians booted from Linux kernel driver maintenance" rel="nofollow" href="https://www.phoronix.com/news/Russian-Linux-Maintainers-Drop">Russians booted from Linux kernel driver maintenance</a></li><li><a title="Antiy paper responding to SentinelOne" rel="nofollow" href="https://www.antiy.net/p/fight-against-the-bald-eagle-in-the-fog-relaying-cooperating-and-specific-contribution/">Antiy paper responding to SentinelOne</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 18</strong>:  This week’s show covers the White House&#39;s new Traffic Light Protocol (TLP) guidance, Reuters expose of Appin as a hack-for-hire mercenary company, Fortinet zero-day exploitation and missing CSRB investigations, major cryptocurrency heists, Apple opening Private Cloud Compute to public inspection, Russians removed from Linux kernel maintenance and China’s Antiy beefing with Sentinel One over APT reporting.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="Transcript (AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1z-Dz25Mmb_97ulETvoKROgQPiN5BHQ_USGvArAqpFXs/edit?usp=sharing">Transcript (AI-generated)</a></li><li><a title="White House TLP guidance" rel="nofollow" href="https://www.whitehouse.gov/oncd/briefing-room/2024/10/22/doubling-down-on-trusted-partnerships-our-commitment-to-researchers/">White House TLP guidance</a></li><li><a title="Applin -- How an Indian startup hacked the world" rel="nofollow" href="https://www.reuters.com/investigates/special-report/usa-hackers-appin/">Applin -- How an Indian startup hacked the world</a></li><li><a title="Burning Zero Days: FortiJump FortiManager Flaw" rel="nofollow" href="https://doublepulsar.com/burning-zero-days-fortijump-fortimanager-vulnerability-used-by-nation-state-in-espionage-via-msps-c79abec59773">Burning Zero Days: FortiJump FortiManager Flaw</a></li><li><a title="Mandiant on FortiManager Zero-Day Exploitation" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/fortimanager-zero-day-exploitation-cve-2024-47575">Mandiant on FortiManager Zero-Day Exploitation</a></li><li><a title="Fortinet bulletin on new 0day exploitation" rel="nofollow" href="https://www.fortiguard.com/psirt/FG-IR-24-423">Fortinet bulletin on new 0day exploitation</a></li><li><a title="Radiant Capital $50M cryptocurrency theft" rel="nofollow" href="https://medium.com/@RadiantCapital/radiant-post-mortem-fecd6cd38081">Radiant Capital $50M cryptocurrency theft</a></li><li><a title="DPRK&#39;s Lazarus steals cryptocurrency with decoy MOBA game" rel="nofollow" href="https://securelist.com/lazarus-apt-steals-crypto-with-a-tank-game/114282/">DPRK's Lazarus steals cryptocurrency with decoy MOBA game</a></li><li><a title="Apple opens Private Cloud Compute to security inspection" rel="nofollow" href="https://security.apple.com/blog/pcc-security-research">Apple opens Private Cloud Compute to security inspection</a></li><li><a title="Russians booted from Linux kernel driver maintenance" rel="nofollow" href="https://www.phoronix.com/news/Russian-Linux-Maintainers-Drop">Russians booted from Linux kernel driver maintenance</a></li><li><a title="Antiy paper responding to SentinelOne" rel="nofollow" href="https://www.antiy.net/p/fight-against-the-bald-eagle-in-the-fog-relaying-cooperating-and-specific-contribution/">Antiy paper responding to SentinelOne</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>ESET Israel wiper malware, China's Volt Typhoon response, Kaspersky sanctions and isolation</title>
  <link>http://securityconversations.fireside.fm/tbp-ep17</link>
  <guid isPermaLink="false">71d290f7-c156-48af-a22c-c4d3ca4b3f44</guid>
  <pubDate>Fri, 18 Oct 2024 12:45:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/71d290f7-c156-48af-a22c-c4d3ca4b3f44.mp3" length="78696217" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 17:  News of a wiper malware attack in Israel implicating ESET, threats from wartime hacktivists, China's strange response to Volt Typhoon attribution and Section 702 messaging, an IE zero-day discovery and web browser rot in South Korea, the ongoing isolation of Kaspersky due to sanctions, and the geopolitical influences affecting cybersecurity reporting.

Cast: Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh) and Ryan Naraine (SecurityWeek).</itunes:subtitle>
  <itunes:duration>1:38:18</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/71d290f7-c156-48af-a22c-c4d3ca4b3f44/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 17:  News of a wiper malware attack in Israel implicating ESET, threats from wartime hacktivists, China's strange response to Volt Typhoon attribution and Section 702 messaging, an IE zero-day discovery and web browser rot in South Korea, the ongoing isolation of Kaspersky due to sanctions, and the geopolitical influences affecting cybersecurity reporting.
Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs) (SentinelLabs), Costin Raiu (https://twitter.com/craiu) (Art of Noh) and Ryan Naraine (https://twitter.com/ryanaraine) (SecurityWeek).
</description>
  <itunes:keywords>ESET, Israel, wiper, disinformation, China, Section 702, quantum computing, chip backdoor, Internet Explorer, Kaspersky, MAPP, VirusTotal</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 17</strong>:  News of a wiper malware attack in Israel implicating ESET, threats from wartime hacktivists, China&#39;s strange response to Volt Typhoon attribution and Section 702 messaging, an IE zero-day discovery and web browser rot in South Korea, the ongoing isolation of Kaspersky due to sanctions, and the geopolitical influences affecting cybersecurity reporting.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="ESET Israel wiper attacks" rel="nofollow" href="https://doublepulsar.com/eiw-eset-israel-wiper-used-in-active-attacks-targeting-israeli-orgs-b1210aed7021">ESET Israel wiper attacks</a></li><li><a title="ESET comment on Israel wiper incident" rel="nofollow" href="https://x.com/ESETresearch/status/1847192384448172387">ESET comment on Israel wiper incident</a></li><li><a title="Dakota Cary on China’s Volt Typhoon Influence Ops" rel="nofollow" href="https://www.sentinelone.com/labs/chinas-influence-ops-twisting-tales-of-volt-typhoon-at-home-and-abroad/">Dakota Cary on China’s Volt Typhoon Influence Ops</a></li><li><a title="Volt Typhoon III (PDF)" rel="nofollow" href="https://www.cverc.org.cn/head/zhaiyao/futetaifeng3_EN.pdf">Volt Typhoon III (PDF)</a></li><li><a title="US Sanctions 12 Kaspersky Executives" rel="nofollow" href="https://www.securityweek.com/us-sanctions-12-kaspersky-executives/">US Sanctions 12 Kaspersky Executives</a></li><li><a title="Kaspersky closing down its UK office" rel="nofollow" href="https://techcrunch.com/2024/10/08/kasperksy-says-its-closing-down-its-uk-office-and-laying-off-dozens/">Kaspersky closing down its UK office</a></li><li><a title="MAPP vendor list" rel="nofollow" href="https://www.microsoft.com/en-us/msrc/mapp">MAPP vendor list</a></li><li><a title="VirusTotal" rel="nofollow" href="https://www.virustotal.com/gui/home/upload">VirusTotal</a></li><li><a title="Transcript (AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1w7-KN0SiU-wHiGlOXAfuydgwAgKkmEw-xKLEubNm19k/edit?usp=sharing">Transcript (AI-generated)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 17</strong>:  News of a wiper malware attack in Israel implicating ESET, threats from wartime hacktivists, China&#39;s strange response to Volt Typhoon attribution and Section 702 messaging, an IE zero-day discovery and web browser rot in South Korea, the ongoing isolation of Kaspersky due to sanctions, and the geopolitical influences affecting cybersecurity reporting.</p>

<p><strong>Cast:</strong> <a href="https://twitter.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade</a> (SentinelLabs), <a href="https://twitter.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh) and <a href="https://twitter.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek).</p><p>Links:</p><ul><li><a title="ESET Israel wiper attacks" rel="nofollow" href="https://doublepulsar.com/eiw-eset-israel-wiper-used-in-active-attacks-targeting-israeli-orgs-b1210aed7021">ESET Israel wiper attacks</a></li><li><a title="ESET comment on Israel wiper incident" rel="nofollow" href="https://x.com/ESETresearch/status/1847192384448172387">ESET comment on Israel wiper incident</a></li><li><a title="Dakota Cary on China’s Volt Typhoon Influence Ops" rel="nofollow" href="https://www.sentinelone.com/labs/chinas-influence-ops-twisting-tales-of-volt-typhoon-at-home-and-abroad/">Dakota Cary on China’s Volt Typhoon Influence Ops</a></li><li><a title="Volt Typhoon III (PDF)" rel="nofollow" href="https://www.cverc.org.cn/head/zhaiyao/futetaifeng3_EN.pdf">Volt Typhoon III (PDF)</a></li><li><a title="US Sanctions 12 Kaspersky Executives" rel="nofollow" href="https://www.securityweek.com/us-sanctions-12-kaspersky-executives/">US Sanctions 12 Kaspersky Executives</a></li><li><a title="Kaspersky closing down its UK office" rel="nofollow" href="https://techcrunch.com/2024/10/08/kasperksy-says-its-closing-down-its-uk-office-and-laying-off-dozens/">Kaspersky closing down its UK office</a></li><li><a title="MAPP vendor list" rel="nofollow" href="https://www.microsoft.com/en-us/msrc/mapp">MAPP vendor list</a></li><li><a title="VirusTotal" rel="nofollow" href="https://www.virustotal.com/gui/home/upload">VirusTotal</a></li><li><a title="Transcript (AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1w7-KN0SiU-wHiGlOXAfuydgwAgKkmEw-xKLEubNm19k/edit?usp=sharing">Transcript (AI-generated)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Ep10: Volt Typhoon zero-day, Russia's APT29 reusing spyware exploits, Pavel Durov's arrest</title>
  <link>http://securityconversations.fireside.fm/tbp-ep10</link>
  <guid isPermaLink="false">a8b95520-0c50-46d8-bc16-25bbab115bb9</guid>
  <pubDate>Fri, 30 Aug 2024 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/a8b95520-0c50-46d8-bc16-25bbab115bb9.mp3" length="60633397" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem - Episode 10 -- Top stories this week: Volt Typhoon zero-day exploitation of Versa Director servers, Chinese APT building botnets with EOL routers, the gap in security solutions for network devices and appliances, Russia's APT29 (Midnight Blizzard) caught reusing exploits from NSO Group and Intellexa, Microsoft’s upcoming Windows endpoint security summit in response to the CrowdStrike incident, and the arrest of Telegram’s Pavel Durov in France. Plus, the NSA is launching a podcast.

Hosts: Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh), Ryan Naraine (SecurityWeek)</itunes:subtitle>
  <itunes:duration>1:18:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/a8b95520-0c50-46d8-bc16-25bbab115bb9/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 10: Top stories this week -- Volt Typhoon zero-day exploitation of Versa Director servers, Chinese APT building botnets with EOL routers, the gap in security solutions for network devices and appliances, Russia's APT29 (Midnight Blizzard) caught reusing exploits from NSO Group and Intellexa, Microsoft’s upcoming Windows endpoint security summit in response to the CrowdStrike incident, and the arrest of Telegram’s Pavel Durov in France.  Plus, the NSA is launching a podcast.
Hosts: Costin Raiu (https://x.com/craiu) (Art of Noh), Juan Andres Guerrero-Saade  (https://x.com/juanandres_gs)(SentinelLabs), Ryan Naraine (https://x.com/ryanaraine) (SecurityWeek)
</description>
  <itunes:keywords>Volt Typhoon, Versa Director, zero-day, network-based attacks, ransomware, APT groups, exploit reuse, iOS exploitation, Pavel Durov, Telegram, encryption, LABScon</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 10</strong>: Top stories this week -- Volt Typhoon zero-day exploitation of Versa Director servers, Chinese APT building botnets with EOL routers, the gap in security solutions for network devices and appliances, Russia&#39;s APT29 (Midnight Blizzard) caught reusing exploits from NSO Group and Intellexa, Microsoft’s upcoming Windows endpoint security summit in response to the CrowdStrike incident, and the arrest of Telegram’s Pavel Durov in France.  Plus, the NSA is launching a podcast.</p>

<p><strong>Hosts:</strong> <a href="https://x.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh), <a href="https://x.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade </a>(SentinelLabs), <a href="https://x.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek)</p><p>Links:</p><ul><li><a title="Transcript (unedited)" rel="nofollow" href="https://docs.google.com/document/d/1Ke2F-qUJpxb6Mnx7wOFYeteoZqfDs_bPqg0jXAyXtGU/edit#heading=h.roy1ekwa04iz">Transcript (unedited)</a></li><li><a title="China&#39;s Volt Typhoon Exploiting Zero-Day in Servers Used by ISPs, MSPs" rel="nofollow" href="https://www.securityweek.com/chinese-apt-volt-typhoon-caught-exploiting-versa-networks-sd-wan-zero-day/">China's Volt Typhoon Exploiting Zero-Day in Servers Used by ISPs, MSPs</a></li><li><a title="Versa Director Zero-Day Exploitation - Black Lotus Labs" rel="nofollow" href="https://blog.lumen.com/taking-the-crossroads-the-versa-director-zero-day-exploitation/">Versa Director Zero-Day Exploitation - Black Lotus Labs</a></li><li><a title="CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability" rel="nofollow" href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/">CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability</a></li><li><a title="Google TAG: APT29 using same exploits as Intellexa, NSO Group" rel="nofollow" href="https://blog.google/threat-analysis-group/state-backed-attackers-and-commercial-surveillance-vendors-repeatedly-use-the-same-exploits/">Google TAG: APT29 using same exploits as Intellexa, NSO Group</a></li><li><a title="Russia&#39;s APT29 Reusing Exploits From Spyware Merchants" rel="nofollow" href="https://www.securityweek.com/google-catches-russian-apt-re-using-exploits-from-spyware-merchants-nso-group-intellexa/">Russia's APT29 Reusing Exploits From Spyware Merchants</a></li><li><a title="Official Pavel Durov charges (PDF)" rel="nofollow" href="https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-26%20-%20CP%20TELEGRAM%20.pdf">Official Pavel Durov charges (PDF)</a></li><li><a title="WSJ: Pavel Durov&#39;s iPhone was hacked by France, UAE" rel="nofollow" href="https://archive.ph/FFPt2">WSJ: Pavel Durov's iPhone was hacked by France, UAE</a></li><li><a title="Microsoft Calls EDR Summit" rel="nofollow" href="https://blogs.windows.com/windowsexperience/2024/08/23/microsoft-to-host-windows-endpoint-security-ecosystem-summit-in-september/">Microsoft Calls EDR Summit</a></li><li><a title="NSA to Launch ‘No Such Podcast’" rel="nofollow" href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/article/3888139/nsa-to-launch-no-such-podcast-pulling-back-curtain-on-mission-culture-people/">NSA to Launch ‘No Such Podcast’</a></li><li><a title="LABScon 2024 Speakers" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon 2024 Speakers</a></li><li><a title="APT29 / Midnight Blizzard" rel="nofollow" href="https://malpedia.caad.fkie.fraunhofer.de/actor/apt29">APT29 / Midnight Blizzard</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 10</strong>: Top stories this week -- Volt Typhoon zero-day exploitation of Versa Director servers, Chinese APT building botnets with EOL routers, the gap in security solutions for network devices and appliances, Russia&#39;s APT29 (Midnight Blizzard) caught reusing exploits from NSO Group and Intellexa, Microsoft’s upcoming Windows endpoint security summit in response to the CrowdStrike incident, and the arrest of Telegram’s Pavel Durov in France.  Plus, the NSA is launching a podcast.</p>

<p><strong>Hosts:</strong> <a href="https://x.com/craiu" rel="nofollow">Costin Raiu</a> (Art of Noh), <a href="https://x.com/juanandres_gs" rel="nofollow">Juan Andres Guerrero-Saade </a>(SentinelLabs), <a href="https://x.com/ryanaraine" rel="nofollow">Ryan Naraine</a> (SecurityWeek)</p><p>Links:</p><ul><li><a title="Transcript (unedited)" rel="nofollow" href="https://docs.google.com/document/d/1Ke2F-qUJpxb6Mnx7wOFYeteoZqfDs_bPqg0jXAyXtGU/edit#heading=h.roy1ekwa04iz">Transcript (unedited)</a></li><li><a title="China&#39;s Volt Typhoon Exploiting Zero-Day in Servers Used by ISPs, MSPs" rel="nofollow" href="https://www.securityweek.com/chinese-apt-volt-typhoon-caught-exploiting-versa-networks-sd-wan-zero-day/">China's Volt Typhoon Exploiting Zero-Day in Servers Used by ISPs, MSPs</a></li><li><a title="Versa Director Zero-Day Exploitation - Black Lotus Labs" rel="nofollow" href="https://blog.lumen.com/taking-the-crossroads-the-versa-director-zero-day-exploitation/">Versa Director Zero-Day Exploitation - Black Lotus Labs</a></li><li><a title="CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability" rel="nofollow" href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/">CVE-2024-39717 – Versa Director Dangerous File Type Upload Vulnerability</a></li><li><a title="Google TAG: APT29 using same exploits as Intellexa, NSO Group" rel="nofollow" href="https://blog.google/threat-analysis-group/state-backed-attackers-and-commercial-surveillance-vendors-repeatedly-use-the-same-exploits/">Google TAG: APT29 using same exploits as Intellexa, NSO Group</a></li><li><a title="Russia&#39;s APT29 Reusing Exploits From Spyware Merchants" rel="nofollow" href="https://www.securityweek.com/google-catches-russian-apt-re-using-exploits-from-spyware-merchants-nso-group-intellexa/">Russia's APT29 Reusing Exploits From Spyware Merchants</a></li><li><a title="Official Pavel Durov charges (PDF)" rel="nofollow" href="https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-26%20-%20CP%20TELEGRAM%20.pdf">Official Pavel Durov charges (PDF)</a></li><li><a title="WSJ: Pavel Durov&#39;s iPhone was hacked by France, UAE" rel="nofollow" href="https://archive.ph/FFPt2">WSJ: Pavel Durov's iPhone was hacked by France, UAE</a></li><li><a title="Microsoft Calls EDR Summit" rel="nofollow" href="https://blogs.windows.com/windowsexperience/2024/08/23/microsoft-to-host-windows-endpoint-security-ecosystem-summit-in-september/">Microsoft Calls EDR Summit</a></li><li><a title="NSA to Launch ‘No Such Podcast’" rel="nofollow" href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/article/3888139/nsa-to-launch-no-such-podcast-pulling-back-curtain-on-mission-culture-people/">NSA to Launch ‘No Such Podcast’</a></li><li><a title="LABScon 2024 Speakers" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon 2024 Speakers</a></li><li><a title="APT29 / Midnight Blizzard" rel="nofollow" href="https://malpedia.caad.fkie.fraunhofer.de/actor/apt29">APT29 / Midnight Blizzard</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Ep9: The blurring lines between nation-state APTs and the ransomware epidemic</title>
  <link>http://securityconversations.fireside.fm/tbp-ep9</link>
  <guid isPermaLink="false">7e54af0b-f1c0-4741-8b5c-e90eddd617b7</guid>
  <pubDate>Fri, 23 Aug 2024 10:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/7e54af0b-f1c0-4741-8b5c-e90eddd617b7.mp3" length="57472403" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>The 'Three Buddy Problem' Podcast Episode 9:  On this episode, we look at the hacking scene in Taiwan, the sad state of visibility into big malware campaigns, the absence of APTs linked to the prolific MIVD Dutch intelligence agency, the blurring lines between big ransomware heists and nation-state actors caught using ransomware as a tool for sabotage and misattribution. 

Plus, Chinese mobile OS vendor Xiaoimi caught disabling parts of its infrastructure -- including its global app store -- to thwart Pwn2Own contestants; and news of an addition to the LABScon 2024  keynote stage.

Hosts: Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh), Ryan Naraine (SecurityWeek)</itunes:subtitle>
  <itunes:duration>1:06:16</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/7/7e54af0b-f1c0-4741-8b5c-e90eddd617b7/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 9: On this episode, we look at the hacking scene in Taiwan, the sad state of visibility into big malware campaigns, the absence of APTs linked to the prolific MIVD Dutch intelligence agency, the blurring lines between big ransomware heists and nation-state actors caught using ransomware as a tool for sabotage and misattribution. 
Plus, Chinese mobile OS vendor Xiaoimi caught disabling parts of its infrastructure -- including its global app store -- to thwart Pwn2Own contestants; and news of an addition to the LABScon 2024 keynote stage.
Hosts: Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh), Ryan Naraine (SecurityWeek)
</description>
  <itunes:keywords>Taiwan, Hitcon, APTs, ransomware, visibility, attribution, threat intelligence, MIVD, Dutch Intel, Netherlands, Japan, Switzerland, cyber operations, ransomware, Iranian hacking, election interference, patching shenanigans, Xiaomi</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 9</strong>: On this episode, we look at the hacking scene in Taiwan, the sad state of visibility into big malware campaigns, the absence of APTs linked to the prolific MIVD Dutch intelligence agency, the blurring lines between big ransomware heists and nation-state actors caught using ransomware as a tool for sabotage and misattribution. </p>

<p>Plus, Chinese mobile OS vendor Xiaoimi caught disabling parts of its infrastructure -- including its global app store -- to thwart Pwn2Own contestants; and news of an addition to the LABScon 2024 keynote stage.</p>

<p><strong>Hosts:</strong> Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="WSJ: The Real Story of the Nord Stream Pipeline Sabotage" rel="nofollow" href="https://archive.ph/TR92c">WSJ: The Real Story of the Nord Stream Pipeline Sabotage</a></li><li><a title="MIVD - The Little Spy Agency That Can" rel="nofollow" href="https://www.spytalk.co/p/the-little-spy-agency-that-can">MIVD - The Little Spy Agency That Can</a></li><li><a title="Iran behind Trump campaign hack" rel="nofollow" href="https://www.reuters.com/world/trump-campaigns-iranian-hackers-have-dangerous-history-deep-expertise-2024-08-23/">Iran behind Trump campaign hack</a></li><li><a title="Xiaomi Caught Patching, Unpatching Pwn2Own RCE Vuln" rel="nofollow" href="https://hackhunting.com/2024/08/22/xiaomi-patched-an-rce-vulnerability-before-pwn2own-toronto-2023-and-removed-the-patch-afterwards/">Xiaomi Caught Patching, Unpatching Pwn2Own RCE Vuln</a></li><li><a title="Dakota Cary on Xiaomi Pwn2Own patch shenanigans" rel="nofollow" href="https://x.com/dakotaindc/status/1826774594159849586?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Dakota Cary on Xiaomi Pwn2Own patch shenanigans</a></li><li><a title="Transcript (unedited)" rel="nofollow" href="https://docs.google.com/document/d/1l51jwxKqG3mPAe646xgu7PlbqxLee8hIf3CvuHv1lkI/edit?usp=sharing">Transcript (unedited)</a></li><li><a title="Territorial Dispute by Boldi" rel="nofollow" href="https://www.crysys.hu/publications/files/tedi/ukatemicrysys_territorialdispute.pdf">Territorial Dispute by Boldi</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 9</strong>: On this episode, we look at the hacking scene in Taiwan, the sad state of visibility into big malware campaigns, the absence of APTs linked to the prolific MIVD Dutch intelligence agency, the blurring lines between big ransomware heists and nation-state actors caught using ransomware as a tool for sabotage and misattribution. </p>

<p>Plus, Chinese mobile OS vendor Xiaoimi caught disabling parts of its infrastructure -- including its global app store -- to thwart Pwn2Own contestants; and news of an addition to the LABScon 2024 keynote stage.</p>

<p><strong>Hosts:</strong> Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="WSJ: The Real Story of the Nord Stream Pipeline Sabotage" rel="nofollow" href="https://archive.ph/TR92c">WSJ: The Real Story of the Nord Stream Pipeline Sabotage</a></li><li><a title="MIVD - The Little Spy Agency That Can" rel="nofollow" href="https://www.spytalk.co/p/the-little-spy-agency-that-can">MIVD - The Little Spy Agency That Can</a></li><li><a title="Iran behind Trump campaign hack" rel="nofollow" href="https://www.reuters.com/world/trump-campaigns-iranian-hackers-have-dangerous-history-deep-expertise-2024-08-23/">Iran behind Trump campaign hack</a></li><li><a title="Xiaomi Caught Patching, Unpatching Pwn2Own RCE Vuln" rel="nofollow" href="https://hackhunting.com/2024/08/22/xiaomi-patched-an-rce-vulnerability-before-pwn2own-toronto-2023-and-removed-the-patch-afterwards/">Xiaomi Caught Patching, Unpatching Pwn2Own RCE Vuln</a></li><li><a title="Dakota Cary on Xiaomi Pwn2Own patch shenanigans" rel="nofollow" href="https://x.com/dakotaindc/status/1826774594159849586?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">Dakota Cary on Xiaomi Pwn2Own patch shenanigans</a></li><li><a title="Transcript (unedited)" rel="nofollow" href="https://docs.google.com/document/d/1l51jwxKqG3mPAe646xgu7PlbqxLee8hIf3CvuHv1lkI/edit?usp=sharing">Transcript (unedited)</a></li><li><a title="Territorial Dispute by Boldi" rel="nofollow" href="https://www.crysys.hu/publications/files/tedi/ukatemicrysys_territorialdispute.pdf">Territorial Dispute by Boldi</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Ep8: Microsoft's zero-days and a wormable Windows TCP/IP flaw known to China</title>
  <link>http://securityconversations.fireside.fm/tbp-ep8</link>
  <guid isPermaLink="false">41525c06-937d-4766-8bb0-e94c8a297650</guid>
  <pubDate>Sat, 17 Aug 2024 04:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/41525c06-937d-4766-8bb0-e94c8a297650.mp3" length="62622049" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>The 'Three Buddy Problem' Podcast Episode 8: This week’s show digs into Microsoft’s in-the-wild zero-day woes, Patch Tuesday and the absence of IOCs, a wormable Windows TCP/IP flaw that the Chinese government knew about for months, Iran’s aggressive hacking US election targets, CrowdStrike v Qihoo360 and major problems with APT naming conventions.

Hosts: Juan Andres Guerrero-Saade (SentinelLabs), Costin Raiu (Art of Noh), Ryan Naraine (SecurityWeek)</itunes:subtitle>
  <itunes:duration>1:17:45</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/4/41525c06-937d-4766-8bb0-e94c8a297650/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 8: This week’s show digs into Microsoft’s in-the-wild zero-day woes, Patch Tuesday and the absence of IOCs, a wormable Windows TCP/IP flaw that the Chinese government knew about for months, Iran’s aggressive hacking US election targets, CrowdStrike v Qihoo360 and major problems with APT naming conventions.
Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)
</description>
  <itunes:keywords>Microsoft, Black Hat, Defcon, LabsCon, Patch Tuesday, zero-day vulnerabilities, IPv6, China, transparency, cybersecurity, Microsoft, IOCs, Iranian hacking, APT names, Palo Alto, CrowdStrike, Qihoo 360, exploitability, balkanization </itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 8</strong>: This week’s show digs into Microsoft’s in-the-wild zero-day woes, Patch Tuesday and the absence of IOCs, a wormable Windows TCP/IP flaw that the Chinese government knew about for months, Iran’s aggressive hacking US election targets, CrowdStrike v Qihoo360 and major problems with APT naming conventions.</p>

<p><strong>Hosts:</strong> Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="Episode 8 Transcript" rel="nofollow" href="https://docs.google.com/document/d/1zhmvqqWPnK7FLZK38LWGBKm2u29leNXiVESA9mBtrns/edit#heading=h.79ibg3a5rrr7">Episode 8 Transcript</a></li><li><a title="Six Windows Zero-Days Being Actively Exploited" rel="nofollow" href="https://www.securityweek.com/microsoft-warns-of-six-windows-zero-days-being-actively-exploited/">Six Windows Zero-Days Being Actively Exploited</a></li><li><a title="CVE-2024-38063 - Windows Ping of Death" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063">CVE-2024-38063 - Windows Ping of Death</a></li><li><a title="Wormable TCP/IP flaw known to China" rel="nofollow" href="https://www.securityweek.com/zero-click-exploit-concerns-drive-urgent-patching-of-windows-tcp-ip-flaw/">Wormable TCP/IP flaw known to China</a> &mdash; Chinese researcher Xiao Wei of Cyber KunLun said he discovered the vulnerability “several months ago.”  </li><li><a title="Google TAG: Iran steps hacking against Israel, U.S." rel="nofollow" href="https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/">Google TAG: Iran steps hacking against Israel, U.S.</a></li><li><a title="Microsoft report on Iran election hacking" rel="nofollow" href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/5bc57431-a7a9-49ad-944d-b93b7d35d0fc.pdf">Microsoft report on Iran election hacking</a></li><li><a title="Qihoo claims CrowdStrike bug exploitable" rel="nofollow" href="https://mp-weixin-qq-com.translate.goog/s/uD7mhzyRSX1dTW-TMg4UhQ?_x_tr_sl=auto&amp;_x_tr_tl=en&amp;_x_tr_hl=en&amp;_x_tr_pto=wapp">Qihoo claims CrowdStrike bug exploitable</a></li><li><a title="CrowdStrike root cause analysis" rel="nofollow" href="https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf">CrowdStrike root cause analysis</a></li><li><a title="LABScon - Speakers 2024" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon - Speakers 2024</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 8</strong>: This week’s show digs into Microsoft’s in-the-wild zero-day woes, Patch Tuesday and the absence of IOCs, a wormable Windows TCP/IP flaw that the Chinese government knew about for months, Iran’s aggressive hacking US election targets, CrowdStrike v Qihoo360 and major problems with APT naming conventions.</p>

<p><strong>Hosts:</strong> Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="Episode 8 Transcript" rel="nofollow" href="https://docs.google.com/document/d/1zhmvqqWPnK7FLZK38LWGBKm2u29leNXiVESA9mBtrns/edit#heading=h.79ibg3a5rrr7">Episode 8 Transcript</a></li><li><a title="Six Windows Zero-Days Being Actively Exploited" rel="nofollow" href="https://www.securityweek.com/microsoft-warns-of-six-windows-zero-days-being-actively-exploited/">Six Windows Zero-Days Being Actively Exploited</a></li><li><a title="CVE-2024-38063 - Windows Ping of Death" rel="nofollow" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063">CVE-2024-38063 - Windows Ping of Death</a></li><li><a title="Wormable TCP/IP flaw known to China" rel="nofollow" href="https://www.securityweek.com/zero-click-exploit-concerns-drive-urgent-patching-of-windows-tcp-ip-flaw/">Wormable TCP/IP flaw known to China</a> &mdash; Chinese researcher Xiao Wei of Cyber KunLun said he discovered the vulnerability “several months ago.”  </li><li><a title="Google TAG: Iran steps hacking against Israel, U.S." rel="nofollow" href="https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/">Google TAG: Iran steps hacking against Israel, U.S.</a></li><li><a title="Microsoft report on Iran election hacking" rel="nofollow" href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/5bc57431-a7a9-49ad-944d-b93b7d35d0fc.pdf">Microsoft report on Iran election hacking</a></li><li><a title="Qihoo claims CrowdStrike bug exploitable" rel="nofollow" href="https://mp-weixin-qq-com.translate.goog/s/uD7mhzyRSX1dTW-TMg4UhQ?_x_tr_sl=auto&amp;_x_tr_tl=en&amp;_x_tr_hl=en&amp;_x_tr_pto=wapp">Qihoo claims CrowdStrike bug exploitable</a></li><li><a title="CrowdStrike root cause analysis" rel="nofollow" href="https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf">CrowdStrike root cause analysis</a></li><li><a title="LABScon - Speakers 2024" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon - Speakers 2024</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Ep6: After CrowdStrike chaos, should Microsoft kick EDR agents out of Windows kernel?</title>
  <link>http://securityconversations.fireside.fm/tbp-ep6</link>
  <guid isPermaLink="false">874c67ec-26cd-4395-8713-df1b58629041</guid>
  <pubDate>Fri, 26 Jul 2024 01:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/874c67ec-26cd-4395-8713-df1b58629041.mp3" length="71350827" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>The 'Three Buddy Problem' Podcast Episode 6:  As the dust settles on the CrowdStrike incident that blue-screened 8.5 million Windows computers worldwide, we dig into CrowdStrike’s preliminary incident report, the lack of transparency in the update process and the need for more robust testing and validation. We also discuss Microsoft's responsibility to avoid infinite BSOD loops, risks of deploying EDR agents on critical systems, and how an EU settlement is being blamed for EDR vendors having access to the Windows kernel.

Other topics on the show include Mandiant's attribution capabilities, North Korea’s gov-backed hacking teams launching ransomware on hospitals, KnowBe4 hiring a fake North Korean IT worker, and new developments in the NSO Group surveillance-ware lawsuit.

Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</itunes:subtitle>
  <itunes:duration>1:16:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/8/874c67ec-26cd-4395-8713-df1b58629041/cover.jpg?v=2"/>
  <description>Three Buddy Problem - Episode 6:   As the dust settles on the CrowdStrike incident that blue-screened 8.5 million Windows computers worldwide, we dig into CrowdStrike’s preliminary incident report, the lack of transparency in the update process and the need for more robust testing and validation. We also discuss Microsoft's responsibility to avoid infinite BSOD loops, risks of deploying EDR agents on critical systems, and how an EU settlement is being blamed for EDR vendors having access to the Windows kernel.
Other topics on the show include Mandiant's attribution capabilities, North Korea’s gov-backed hacking teams launching ransomware on hospitals, KnowBe4 hiring a fake North Korean IT worker, and new developments in the NSO Group surveillance-ware lawsuit.
Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)
</description>
  <itunes:keywords>CrowdStrike, Windows, BSOD, detection update, testing, validation, EDR, detection, APT45, groups, IOCs, North Korea, NSO lawsuit, surveillance industry, exploits, zero-days</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 6</strong>:   As the dust settles on the CrowdStrike incident that blue-screened 8.5 million Windows computers worldwide, we dig into CrowdStrike’s preliminary incident report, the lack of transparency in the update process and the need for more robust testing and validation. We also discuss Microsoft&#39;s responsibility to avoid infinite BSOD loops, risks of deploying EDR agents on critical systems, and how an EU settlement is being blamed for EDR vendors having access to the Windows kernel.</p>

<p>Other topics on the show include Mandiant&#39;s attribution capabilities, North Korea’s gov-backed hacking teams launching ransomware on hospitals, KnowBe4 hiring a fake North Korean IT worker, and new developments in the NSO Group surveillance-ware lawsuit.</p>

<p><strong>Hosts:</strong> Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="Episode transcript (Unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1ulo0dHr89aShLeHG4TFScq7wErMO7KvJdGX_7oCNlH4/edit?usp=sharing">Episode transcript (Unedited, AI-generated)</a></li><li><a title="Official CrowdStrike preliminary post-mortem" rel="nofollow" href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/">Official CrowdStrike preliminary post-mortem</a></li><li><a title="Microsoft VP David Weston on CrowdStrike outage" rel="nofollow" href="https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/">Microsoft VP David Weston on CrowdStrike outage</a></li><li><a title="Microsoft VP John Cable on the path forward" rel="nofollow" href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-resiliency-best-practices-and-the-path-forward/ba-p/4201550">Microsoft VP John Cable on the path forward</a></li><li><a title="Matt Suiche: Bob and Alice in Kernel-land" rel="nofollow" href="https://www.msuiche.com/posts/bob-and-alice-in-kernel-land/">Matt Suiche: Bob and Alice in Kernel-land</a></li><li><a title="Re-learning Lessons from the CrowdStrike Outage" rel="nofollow" href="https://www.lutasecurity.com/post/re-learning-lessons-from-the-crowdstrike-outage">Re-learning Lessons from the CrowdStrike Outage</a></li><li><a title="Ep5: CrowdStrike&#39;s faulty update" rel="nofollow" href="https://securityconversations.com/episode/ep5-crowdstrikes-faulty-update-shuts-down-global-networks/">Ep5: CrowdStrike's faulty update</a></li><li><a title="Mandiant Report on North Korea&#39;s APT45" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine">Mandiant Report on North Korea's APT45</a></li><li><a title="CISA Advisory on North Korea APT45" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a">CISA Advisory on North Korea APT45</a></li><li><a title="KnowBe4 Hires North Korean Fake IT Worker" rel="nofollow" href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us">KnowBe4 Hires North Korean Fake IT Worker</a></li><li><a title="Israel’s attempt to sway NSO/WhatsApp spyware case" rel="nofollow" href="https://securitylab.amnesty.org/latest/2024/07/israels-attempt-to-sway-whatsapp-case-casts-doubt-on-its-ability-to-deal-with-nso-spyware/?ref=news.risky.biz">Israel’s attempt to sway NSO/WhatsApp spyware case</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 6</strong>:   As the dust settles on the CrowdStrike incident that blue-screened 8.5 million Windows computers worldwide, we dig into CrowdStrike’s preliminary incident report, the lack of transparency in the update process and the need for more robust testing and validation. We also discuss Microsoft&#39;s responsibility to avoid infinite BSOD loops, risks of deploying EDR agents on critical systems, and how an EU settlement is being blamed for EDR vendors having access to the Windows kernel.</p>

<p>Other topics on the show include Mandiant&#39;s attribution capabilities, North Korea’s gov-backed hacking teams launching ransomware on hospitals, KnowBe4 hiring a fake North Korean IT worker, and new developments in the NSO Group surveillance-ware lawsuit.</p>

<p><strong>Hosts:</strong> Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="Episode transcript (Unedited, AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1ulo0dHr89aShLeHG4TFScq7wErMO7KvJdGX_7oCNlH4/edit?usp=sharing">Episode transcript (Unedited, AI-generated)</a></li><li><a title="Official CrowdStrike preliminary post-mortem" rel="nofollow" href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/">Official CrowdStrike preliminary post-mortem</a></li><li><a title="Microsoft VP David Weston on CrowdStrike outage" rel="nofollow" href="https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/">Microsoft VP David Weston on CrowdStrike outage</a></li><li><a title="Microsoft VP John Cable on the path forward" rel="nofollow" href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-resiliency-best-practices-and-the-path-forward/ba-p/4201550">Microsoft VP John Cable on the path forward</a></li><li><a title="Matt Suiche: Bob and Alice in Kernel-land" rel="nofollow" href="https://www.msuiche.com/posts/bob-and-alice-in-kernel-land/">Matt Suiche: Bob and Alice in Kernel-land</a></li><li><a title="Re-learning Lessons from the CrowdStrike Outage" rel="nofollow" href="https://www.lutasecurity.com/post/re-learning-lessons-from-the-crowdstrike-outage">Re-learning Lessons from the CrowdStrike Outage</a></li><li><a title="Ep5: CrowdStrike&#39;s faulty update" rel="nofollow" href="https://securityconversations.com/episode/ep5-crowdstrikes-faulty-update-shuts-down-global-networks/">Ep5: CrowdStrike's faulty update</a></li><li><a title="Mandiant Report on North Korea&#39;s APT45" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine">Mandiant Report on North Korea's APT45</a></li><li><a title="CISA Advisory on North Korea APT45" rel="nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a">CISA Advisory on North Korea APT45</a></li><li><a title="KnowBe4 Hires North Korean Fake IT Worker" rel="nofollow" href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us">KnowBe4 Hires North Korean Fake IT Worker</a></li><li><a title="Israel’s attempt to sway NSO/WhatsApp spyware case" rel="nofollow" href="https://securitylab.amnesty.org/latest/2024/07/israels-attempt-to-sway-whatsapp-case-casts-doubt-on-its-ability-to-deal-with-nso-spyware/?ref=news.risky.biz">Israel’s attempt to sway NSO/WhatsApp spyware case</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Ep5: CrowdStrike's faulty update shuts down global networks</title>
  <link>http://securityconversations.fireside.fm/tbp-ep5</link>
  <guid isPermaLink="false">85b284cc-9ab4-4a38-8a4e-9d6439345bcb</guid>
  <pubDate>Fri, 19 Jul 2024 08:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/85b284cc-9ab4-4a38-8a4e-9d6439345bcb.mp3" length="54810148" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>The 'Three Buddy Problem' Podcast Episode 5:  Hot off the press, we dive into the news of the CrowdStrike software update that caused blue screens on computers worldwide, the resulting chaos and potential connections to the Microsoft 365 outage, the fragility of modern computing and the risks of new software paradigms.

We also discuss the AT&amp;T mega-breach and the ransom paid to delete the stolen data; the challenges of ransomware and the uncertainty surrounding the deletion of stolen data; the FBI gaining access to a password-protected phone, the prices for zero-click exploits; and the resurgence of APT 41 with expanding targets.

Plus, some news on upcoming keynote speakers at LabsCon 2024.

Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</itunes:subtitle>
  <itunes:duration>59:51</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/8/85b284cc-9ab4-4a38-8a4e-9d6439345bcb/cover.jpg?v=2"/>
  <description>Three Buddy Problem - Episode 5:  Hot off the press, we dive into the news of the CrowdStrike software update that caused blue screens on computers worldwide, the resulting chaos and potential connections to the Microsoft 365 outage, the fragility of modern computing and the risks of new software paradigms.
We also discuss the AT&amp;amp;T mega-breach and the ransom paid to delete the stolen data; the challenges of ransomware and the uncertainty surrounding the deletion of stolen data; the FBI gaining access to a password-protected phone, the prices for zero-click exploits; and the resurgence of APT 41 with expanding targets.
Plus, some news on upcoming keynote speakers at LabsCon 2024.
Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)
</description>
  <itunes:keywords>CrowdStrike, software update, blue screens, Microsoft 365 outage, AT&amp;T breach, EDR, ransomware, stolen data, cybersecurity, AT&amp;T data breach, FBI, password-protected phone, zero-click exploits, APT 41, NullBulge, LabsCon,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 5</strong>:  Hot off the press, we dive into the news of the CrowdStrike software update that caused blue screens on computers worldwide, the resulting chaos and potential connections to the Microsoft 365 outage, the fragility of modern computing and the risks of new software paradigms.</p>

<p>We also discuss the AT&amp;T mega-breach and the ransom paid to delete the stolen data; the challenges of ransomware and the uncertainty surrounding the deletion of stolen data; the FBI gaining access to a password-protected phone, the prices for zero-click exploits; and the resurgence of APT 41 with expanding targets.</p>

<p>Plus, some news on upcoming keynote speakers at LabsCon 2024.</p>

<p>Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="Transcript (AI-generated, unedited)" rel="nofollow" href="https://docs.google.com/document/d/11C0JmY7o58yPUJs7jutahdmV1-ZI-fv6bL-QhoCW8ww/edit?usp=sharing">Transcript (AI-generated, unedited)</a></li><li><a title="CrowdStrike Statement on Falcon Content Update for Windows Hosts" rel="nofollow" href="https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/">CrowdStrike Statement on Falcon Content Update for Windows Hosts</a></li><li><a title="Microsoft-CrowdStrike blackout FAQ" rel="nofollow" href="https://www.cnbc.com/2024/07/19/latest-live-updates-on-a-major-it-outage-spreading-worldwide.html">Microsoft-CrowdStrike blackout FAQ</a></li><li><a title="Bad CrowdStrike Update Linked to Major IT Outages Worldwide" rel="nofollow" href="https://www.securityweek.com/major-outages-worldwide-linked-to-bsod-caused-by-bad-crowdstrike-update/">Bad CrowdStrike Update Linked to Major IT Outages Worldwide</a></li><li><a title="CrowdStrike CEO George Kurtz statement on Twitter" rel="nofollow" href="https://x.com/george_kurtz/status/1814235001745027317?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">CrowdStrike CEO George Kurtz statement on Twitter</a></li><li><a title="AT&amp;T Paid a Hacker $370,000 to Delete Stolen Phone Records" rel="nofollow" href="https://archive.ph/hjbYB">AT&amp;T Paid a Hacker $370,000 to Delete Stolen Phone Records</a></li><li><a title="T-Mobile Hacker Who Stole Data on 50 Million Customers: ‘Their Security Is Awful’" rel="nofollow" href="https://archive.ph/fClfV">T-Mobile Hacker Who Stole Data on 50 Million Customers: ‘Their Security Is Awful’</a></li><li><a title="LABScon 2024 Speakers" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon 2024 Speakers</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 5</strong>:  Hot off the press, we dive into the news of the CrowdStrike software update that caused blue screens on computers worldwide, the resulting chaos and potential connections to the Microsoft 365 outage, the fragility of modern computing and the risks of new software paradigms.</p>

<p>We also discuss the AT&amp;T mega-breach and the ransom paid to delete the stolen data; the challenges of ransomware and the uncertainty surrounding the deletion of stolen data; the FBI gaining access to a password-protected phone, the prices for zero-click exploits; and the resurgence of APT 41 with expanding targets.</p>

<p>Plus, some news on upcoming keynote speakers at LabsCon 2024.</p>

<p>Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)</p><p>Links:</p><ul><li><a title="Transcript (AI-generated, unedited)" rel="nofollow" href="https://docs.google.com/document/d/11C0JmY7o58yPUJs7jutahdmV1-ZI-fv6bL-QhoCW8ww/edit?usp=sharing">Transcript (AI-generated, unedited)</a></li><li><a title="CrowdStrike Statement on Falcon Content Update for Windows Hosts" rel="nofollow" href="https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/">CrowdStrike Statement on Falcon Content Update for Windows Hosts</a></li><li><a title="Microsoft-CrowdStrike blackout FAQ" rel="nofollow" href="https://www.cnbc.com/2024/07/19/latest-live-updates-on-a-major-it-outage-spreading-worldwide.html">Microsoft-CrowdStrike blackout FAQ</a></li><li><a title="Bad CrowdStrike Update Linked to Major IT Outages Worldwide" rel="nofollow" href="https://www.securityweek.com/major-outages-worldwide-linked-to-bsod-caused-by-bad-crowdstrike-update/">Bad CrowdStrike Update Linked to Major IT Outages Worldwide</a></li><li><a title="CrowdStrike CEO George Kurtz statement on Twitter" rel="nofollow" href="https://x.com/george_kurtz/status/1814235001745027317?s=46&amp;t=ePKy91eN-ionB9LpDaBXcA">CrowdStrike CEO George Kurtz statement on Twitter</a></li><li><a title="AT&amp;T Paid a Hacker $370,000 to Delete Stolen Phone Records" rel="nofollow" href="https://archive.ph/hjbYB">AT&amp;T Paid a Hacker $370,000 to Delete Stolen Phone Records</a></li><li><a title="T-Mobile Hacker Who Stole Data on 50 Million Customers: ‘Their Security Is Awful’" rel="nofollow" href="https://archive.ph/fClfV">T-Mobile Hacker Who Stole Data on 50 Million Customers: ‘Their Security Is Awful’</a></li><li><a title="LABScon 2024 Speakers" rel="nofollow" href="https://www.labscon.io/speakers/">LABScon 2024 Speakers</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Costin Raiu: The GReAT exit interview</title>
  <link>http://securityconversations.fireside.fm/costin-raiu-great-exit-interview</link>
  <guid isPermaLink="false">b70d7b98-2823-490b-8b70-f3a051c45709</guid>
  <pubDate>Mon, 15 Jan 2024 11:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/b70d7b98-2823-490b-8b70-f3a051c45709.mp3" length="90090088" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly, the supply chain security experts (https://binarly.io)
- FwHunt (https://fwhunt.run)

Costin Raiu has spent a lifetime in anti-malware research, working on some of the biggest nation-state APT cases in history, including Stuxnet, Duqu, Equation Group, Red October, Turla and Lazarus.   

In this exit interview, Costin digs into why he left the GReAT team after 13 years at the helm, ethical questions on exposing certain APT operations, changes in the nation-state malware attribution game, technically impressive APT attacks, and the 'dark spots' where future-thinking APTs are living.</itunes:subtitle>
  <itunes:duration>1:32:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/b/b70d7b98-2823-490b-8b70-f3a051c45709/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly, the supply chain security experts (https://binarly.io)
FwHunt (https://fwhunt.run)
Costin Raiu has spent a lifetime in anti-malware research, working on some of the biggest nation-state APT cases in history, including Stuxnet, Duqu, Equation Group, Red October, Turla and Lazarus.   
In this exit interview, Costin digs into why he left the GReAT team after 13 years at the helm, ethical questions on exposing certain APT operations, changes in the nation-state malware attribution game, technically impressive APT attacks, and the 'dark spots' where future-thinking APTs are living. 
</description>
  <itunes:keywords>APT, GReAT, Stuxnet, Duqu, Red October</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly, the supply chain security experts (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Costin Raiu has spent a lifetime in anti-malware research, working on some of the biggest nation-state APT cases in history, including Stuxnet, Duqu, Equation Group, Red October, Turla and Lazarus.   </p>

<p>In this exit interview, Costin digs into why he left the GReAT team after 13 years at the helm, ethical questions on exposing certain APT operations, changes in the nation-state malware attribution game, technically impressive APT attacks, and the &#39;dark spots&#39; where future-thinking APTs are living.</p><p>Links:</p><ul><li><a title="Costin Raiu on Twitter" rel="nofollow" href="https://twitter.com/craiu">Costin Raiu on Twitter</a></li><li><a title="How to Protect Your Phone from Pegasus and Other APTs" rel="nofollow" href="https://www.darkreading.com/cyber-risk/how-to-protect-your-phone-from-pegasus-and-other-apts">How to Protect Your Phone from Pegasus and Other APTs</a></li><li><a title="Costin Raiu: 10 big &#39;unattributed&#39; APT mysteries" rel="nofollow" href="https://twitter.com/craiu/status/1573272440704319488">Costin Raiu: 10 big 'unattributed' APT mysteries</a></li><li><a title="Costin Raiu on the .gov mobile exploitation business" rel="nofollow" href="https://securityconversations.com/episode/costin-raiu-on-the-gov-mobile-exploitation-business/">Costin Raiu on the .gov mobile exploitation business</a></li><li><a title="WannaCry Ransomware Linked to North Korean Hackers" rel="nofollow" href="https://www.wired.com/2017/05/wannacry-ransomware-link-suspected-north-korean-hackers/">WannaCry Ransomware Linked to North Korean Hackers</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly, the supply chain security experts (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Costin Raiu has spent a lifetime in anti-malware research, working on some of the biggest nation-state APT cases in history, including Stuxnet, Duqu, Equation Group, Red October, Turla and Lazarus.   </p>

<p>In this exit interview, Costin digs into why he left the GReAT team after 13 years at the helm, ethical questions on exposing certain APT operations, changes in the nation-state malware attribution game, technically impressive APT attacks, and the &#39;dark spots&#39; where future-thinking APTs are living.</p><p>Links:</p><ul><li><a title="Costin Raiu on Twitter" rel="nofollow" href="https://twitter.com/craiu">Costin Raiu on Twitter</a></li><li><a title="How to Protect Your Phone from Pegasus and Other APTs" rel="nofollow" href="https://www.darkreading.com/cyber-risk/how-to-protect-your-phone-from-pegasus-and-other-apts">How to Protect Your Phone from Pegasus and Other APTs</a></li><li><a title="Costin Raiu: 10 big &#39;unattributed&#39; APT mysteries" rel="nofollow" href="https://twitter.com/craiu/status/1573272440704319488">Costin Raiu: 10 big 'unattributed' APT mysteries</a></li><li><a title="Costin Raiu on the .gov mobile exploitation business" rel="nofollow" href="https://securityconversations.com/episode/costin-raiu-on-the-gov-mobile-exploitation-business/">Costin Raiu on the .gov mobile exploitation business</a></li><li><a title="WannaCry Ransomware Linked to North Korean Hackers" rel="nofollow" href="https://www.wired.com/2017/05/wannacry-ransomware-link-suspected-north-korean-hackers/">WannaCry Ransomware Linked to North Korean Hackers</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
