<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Wed, 22 Apr 2026 08:44:21 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Cve”</title>
    <link>https://securityconversations.fireside.fm/tags/cve</link>
    <pubDate>Tue, 14 Nov 2023 06:00:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>Dan Lorenc on fixing the 'crappy' CVE ecosystem </title>
  <link>http://securityconversations.fireside.fm/dan-lorenc-deciphers-cve-cvss-sbom-supply-chains</link>
  <guid isPermaLink="false">aa617e3f-5689-4e88-a3ea-69bf50679c6e</guid>
  <pubDate>Tue, 14 Nov 2023 06:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/aa617e3f-5689-4e88-a3ea-69bf50679c6e.mp3" length="40642471" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly, the firmware security experts (https://binarly.io)
- FwHunt (https://fwhunt.run)

Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a "growth mode" startup, massive funding rounds and VC expectations, fixing the "crappy" CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.</itunes:subtitle>
  <itunes:duration>41:45</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/aa617e3f-5689-4e88-a3ea-69bf50679c6e/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a "growth mode" startup, massive funding rounds and VC expectations, fixing the "crappy" CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.
</description>
  <itunes:keywords>Chainguard, supply chain, SBOMs, CVE, Venture Capital</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a &quot;growth mode&quot; startup, massive funding rounds and VC expectations, fixing the &quot;crappy&quot; CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.</p><p>Links:</p><ul><li><a title="SBOMs - All the right ingredients, but something is still missing" rel="nofollow" href="https://p72.vc/perspectives/software-bills-of-material-sboms/">SBOMs - All the right ingredients, but something is still missing</a></li><li><a title="Open Source Development Threatened in Europe" rel="nofollow" href="https://thenewstack.io/open-source-development-threatened-in-europe/">Open Source Development Threatened in Europe</a></li><li><a title="Chainguard Images: Reduce your attack surface" rel="nofollow" href="https://www.chainguard.dev/chainguard-images">Chainguard Images: Reduce your attack surface</a></li><li><a title="Dan Lorenc on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/danlorenc/">Dan Lorenc on LinkedIn</a></li><li><a title="Dan Lorenc on Twitter/X" rel="nofollow" href="https://twitter.com/lorenc_dan">Dan Lorenc on Twitter/X</a></li><li><a title="Chainguard Raises $61 Million Series B" rel="nofollow" href="https://www.chainguard.dev/unchained/series-b-funding">Chainguard Raises $61 Million Series B</a></li><li><a title="Binarly -- Firmware Supply Chain Security Platform" rel="nofollow" href="https://binarly.io/">Binarly -- Firmware Supply Chain Security Platform</a> &mdash; Binarly is the world's first automated firmware supply chain security platform. Using cutting-edge techniques, Binarly identifies both known and unknown vulnerabilities, misconfigurations, and malicious code in firmware and hardware components.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a &quot;growth mode&quot; startup, massive funding rounds and VC expectations, fixing the &quot;crappy&quot; CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.</p><p>Links:</p><ul><li><a title="SBOMs - All the right ingredients, but something is still missing" rel="nofollow" href="https://p72.vc/perspectives/software-bills-of-material-sboms/">SBOMs - All the right ingredients, but something is still missing</a></li><li><a title="Open Source Development Threatened in Europe" rel="nofollow" href="https://thenewstack.io/open-source-development-threatened-in-europe/">Open Source Development Threatened in Europe</a></li><li><a title="Chainguard Images: Reduce your attack surface" rel="nofollow" href="https://www.chainguard.dev/chainguard-images">Chainguard Images: Reduce your attack surface</a></li><li><a title="Dan Lorenc on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/danlorenc/">Dan Lorenc on LinkedIn</a></li><li><a title="Dan Lorenc on Twitter/X" rel="nofollow" href="https://twitter.com/lorenc_dan">Dan Lorenc on Twitter/X</a></li><li><a title="Chainguard Raises $61 Million Series B" rel="nofollow" href="https://www.chainguard.dev/unchained/series-b-funding">Chainguard Raises $61 Million Series B</a></li><li><a title="Binarly -- Firmware Supply Chain Security Platform" rel="nofollow" href="https://binarly.io/">Binarly -- Firmware Supply Chain Security Platform</a> &mdash; Binarly is the world's first automated firmware supply chain security platform. Using cutting-edge techniques, Binarly identifies both known and unknown vulnerabilities, misconfigurations, and malicious code in firmware and hardware components.</li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
