Mato
ShowsHow it worksAI talentsFree toolsPricing
Book a demo
ShowsHow it worksAI talentsFree toolsPricingSign in
Mato
Mato

The first generation of AI talents. Live AI media for brands, networks and creators.

ElevenLabs GrantsAWS ActivateGoogle for StartupsNVIDIA Inception Program

Product

  • How it works
  • AI talents
  • Documentation
  • The studio
  • Pricing
  • Embed player
  • Mato MCP
  • Mato Voice
  • Voice Studio
  • Changelog

Company

  • About
  • Vision
  • Partners
  • Affiliates
  • Blog
  • CustomersComing soon
  • CareersComing soon
  • Press kit
  • Contact

Resources

  • Investor overview
  • Free podcast tools
  • Free podcast transcription
  • Podcast ROI calculator
  • API docsComing soon
  • SecurityComing soon
  • StatusComing soon

© 2026 Mato. All rights reserved.

English · Multiple languages available

PrivacyTerms

Live Interview

And why does that matter?

This is how a Mato agent talks. Take the other seat: answer a few and feel it follow the thread.

Try it yourself

Podcast charts

Three Buddy Problem

Published by Security Conversations

  • Technology
  • News
  • Tech news

The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).

Listen on Apple Podcasts, opens in a new tabMake something like it

On the charts

5 chart placements

Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.

  1. Number 57Tech newsAustralia
  2. Number 86Tech newsCanada
  3. Number 102Tech newsUnited Kingdom
  4. Number 25Tech newsNorway
  5. Number 49Tech newsUnited States

From the feed

Recent episodes

The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.

  1. AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit from Three Buddy Problem, opens in a new tab

    Sep 11, 20262 hr 37 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 113 : On the show this week, the buddies dig into an Anthropic researcher quitting with a warning that AI could kill us all, the San Francisco "death cult" and their motives, and agent swarms leaving junk on public wikis and university URL shorteners. Plus, a high-quality Anthropic's threat report and the claim that Moonshot was quietly serving Claude tokens as Kimi K3, live MikroTik and Chrome zero-days that landed a day ahead of the patches, and a WeChat worm that hijacks an account via phone calls. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter, TLP Black 5:05 LabsCon, the last one, and JAGS on his keynote 8:24 Costin's agentic CTI training and what old-school CTI is missing 16:27 Anthropic's threat-intel report + IOCs 20:00 APT29 and DarkSword on hotel Wi-Fi 23:34 Bioweapons, guardrails, and what got shut down 28:07 Why is anyone running these attacks on Claude at all? 35:53 Distillation at industrial scale and the Kimi K3 fraud claim 48:43 Chinese models, Americanized, running on DGX Spark 55:00 Mr. America: local AI and the seven-layer cake 1:04:34 Should frontier AI labs poison the distillers? 1:27:05 What the frontier labs did to the security ecosystem 1:34:22 Jacob Coxon quits, and the doomer argument falls apart 1:59:13 Agent swarms littering the internet 2:07:29 Chrome zero-days, MikroTik, patch-gaps

  2. Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs. from Three Buddy Problem, opens in a new tab

    Sep 4, 20262 hr 7 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 112 : The 'OpenAI hacks Hugging Face' fallout has turned into a story about AI civilizations rising from the ashes, politicians calling for super-intelligence bans, and the emergence of well-funding non-profits doing AI safety work. Who are these people and what's their security expertise? Plus, GPT-6 Astra lands in a trusted-access program nobody can get into, Costin ranks the local models he runs next to his desk, and CrowdStrike sinkholes a botnet that's been alive since 2003. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter 1:02 Conference season: LabsCon, Offensive AI Con, Countermeasure 5:40 The Hugging Face story hits the front page 7:04 Dwarkesh, Greenblatt, and the AI-pilled framing 11:51 Swap "agents" for "Python" and the panic goes away 16:34 Does anyone actually know what happened? 21:18 Bernie Sanders wants to ban superintelligence 34:03 Defending against swarms: the 2026 SOC 39:15 Logs, Splunk, and the business model in the way 44:11 What EDR vendors are actually building with AI 56:16 The security poverty line and the endgame 1:07:53 GPT-6 Astra, Fable 5.1, and local model rankings 1:27:25 Google's Fairwind, CodeMender, and agents running Linux 1:45:31 Apple's bet on local inference 1:53:21 The Sality takedown and endgame advice

  3. A Thousand Agents Walk Into Hugging Face from Three Buddy Problem, opens in a new tab

    Aug 28, 20262 hr 27 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 111 : OpenAI finally published a technical Hugging Face post-mortem, and Costin's verdict is blunt. He reads it as a document written for policymakers rather than for the blue teams who have to survive a thousand-agent swarm. We also dig into NVIDIA's $12.9 billion acquisition of Hugging Face, why JAGS thinks a frontier lab standing against open-source looks weak, and what that new industry open letter on cyber defense actually asks anyone to do. Plus, hotel Wi-Fi tradecraft after CaptiveCrunch, the FBI's ORB network takedown with Lumen, Chinese routers that ship backdoored from the factory, and the TeamPCP arrests in Australia. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter 1:11 TLPBlack, incident response, and why it starts at the router 4:11 CaptiveCrunch and Juanito's travel router kit 7:59 Costin's VPN/hotel WiFi stack 12:36 State of Statecraft, LABScon, and Offensive AI Con 17:16 OpenAI's Hugging Face post-mortem technical report 21:43 A swarm of a thousand agents 27:35 Who was OpenAI’s report written for? 33:05 Fail2ban, canaries, and catching agents in your logs 40:34 NVIDIA buys Hugging Face for $12.9 billion 44:42 The open weights fight and rooting for China 52:47 Nemotron, DGX Spark, and the RAM price spiral 1:03:26 Open letter on collective AI-powered cyber defense 1:30:21 Lumen's Quartermaster and the FBI ORB takedown 1:59:05 Backdoored ZBT routers, Chinese phones, and the TeamPCP arrests

  4. Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure from Three Buddy Problem, opens in a new tab

    Aug 21, 20262 hr 11 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 110 : We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup running sandboxes for OpenAI, Anthropic and Meta, drones over Romania's gas platforms, OpenAI's two-week training pause, and T-Mobile taking scissors to a cable during Salt Typhoon incident response. Stick around for a UFO segment that somehow involves Dr. Phil. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter; LabsCon speakers announced 9:06 A naval drone reaches the Neptun Deep gas platform 17:38 OpenAI pauses RL training: what "slowing the pace of scaling" costs 24:34 Guardrails vs refusals vs alignment. 33:54 Irregular, formerly Pattern Labs: $80M, $450M valuation, one job 46:11 JAGS on why security needs a new batch of startups right now 1:06:52 EncroChat revealed: a GitHub-sourced implant, IOCs 1:15:12 Law enforcement malware vs intelligence malware 1:21:07 T-Mobile, Salt Typhoon, and cutting the cable with a pair of scissors 1:32:06 Captive Crunch: hotel Wi-Fi, OAuth token theft, and the MSP supply chain 1:47:00 ICE RELIC, UNC6293, and the trouble with subcluster naming 2:00:39 UFO corner: David Grusch, Dr. Phil, and the Skywatcher Project 2:05:44 Shout outs, the Costin Challenge

  5. A tiny 12 KB Windows backdoor, one victim, and a dead domain from Three Buddy Problem, opens in a new tab

    Aug 17, 20262 hr 23 min

    ( Presented by State of Statecraft : A security and intelligence conference that brings together multiple disciplines, backgrounds, and nationalities to share research into the covert activities of nation-states and other malign actors. ) Three Buddy Problem - Episode 109 : The buddies dig into a new White House memo handing vetted private companies real offensive cyber authorities, and Costin explains why a stack of ransomware takedown cases has been sitting on a shelf waiting for exactly this. Plus, a tiny 12 KB Windows backdoor found on one machine with a dead C2, the mercenary outfits quietly living inside telcos, and why Google continues to flounder in the race for AI dominance. Cast: Costin Raiu , Ryan Naraine and Juan Andres Guerrero-Saade Timestamps: 0:00 Introductory banter 0:58 State of Statecraft, and a late CFP window 3:24 The White House offensive hacking memo 6:37 "Hack back" is the wrong frame for what's being authorized 11:20 Ransomware cases sitting on the shelf 17:01 The million-dollar bond and who can realistically play 22:29 Where DPRK crypto theft falls under the new definitions 28:15 Would TLP Black take a contract? 36:55 Gen Digital's 12 KB backdoor hiding its C2 in desktop.ini whitespace 46:57 Passive DNS, registration patterns, and pivoting on a dead domain 57:32 Feeding a one-off find back into detection engineering 1:02:14 Metador, Mafalda, and the mercenaries who love telcos 1:17:07 Armored Likho and what "Western APT" really means 1:28:16 The IOC market, private reporting, and CTI’s matching problem 1:58:10 Google's culture problem, the weekly model churn, and Patch Tuesday math

  6. Inside OpenAI's Black Hat Confession from Three Buddy Problem, opens in a new tab

    Aug 8, 20262 hr 14 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 108 : OpenAI got on the Black Hat stage and walked through how its own agent swarm hacked Hugging Face. We discuss and struggle to decide whether to clap or panic. Plus, why only the attacker can do forensics now, frontier models being built as cyber-weapons on purpose, APT29's "Dark Hotel" comeback in luxury hotels, China's swipe at Palo Alto, the Iran-water-system FUD, and an eye-opening Liechtenstein money-laundering hack. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter - Black Hat went full RSA 1:11 TLP Black sponsor read 3:58 A deflated, AI-pilled show floor 8:31 AI stunt hacking and AI slop 16:20 The OpenAI–Hugging Face talk 21:00 Not all the same incident: OpenAI vs. Meta, Anthropic, and Irregular 25:49 Swarms of agents, Artifactory message boards, and the defense gap 32:26 Offense vs. defense: what's really in the training data? 41:22 Guardrails, KYC, and "too dangerous to release" 48:07 JAGS's unpublished Opus 5 benchmark — grinding to 25% and stuck 59:30 AISI, recklessness, and the OpenAI Frontier Risk Council 1:06:27 Stronger models everywhere: Qwen, Sol, Astra, rushing off the cliff 1:18:32 APT29 / "Dark Hotel" reborn + travel OPSEC 1:39:56 China's Palo Alto review, spy-agency rankings, Iran/water FUD 1:57:28 Liechtenstein AML hack, JAGS's promotion, mental health

  7. Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats from Three Buddy Problem, opens in a new tab

    Jul 31, 20263 hr 26 min

    ( Presented by Thinkst Canary : Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents. ) Three Buddy Problem - Episode 107 : Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich , Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear’ advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

  8. Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise from Three Buddy Problem, opens in a new tab

    Jul 28, 202634 min

    Security Conversations : Kenneth Kinion, founder and CEO of Validin, joins Ryan Naraine on the show to unpack what "internet intelligence" really means for the analysts and responders chasing malicious infrastructure. We trace his path from Georgia Tech through Microsoft and Amazon to the frustrations that led to the creation of Validin, the competition from big AI, the value of AI-powered tools to speed up infrastructure hunting, and why defenders keep falling further behind fast-moving attackers. Timestamps: 0:00 – Intro: What does Validin do? 0:51 – Who uses Validin: CTI teams, SOCs, incident responders 2:19 – Atlanta and Georgia Tech's cybersecurity pipeline 5:31 – Lessons from Microsoft and Amazon: waterfall vs. agile 8:29 – Filling gaps in passive DNS data 9:57 – Misunderstood things about threat intelligence 14:17 – The value of "cyber paleontology" 16:00 – What makes one data set better than another? 19:39 – How Validin works: from one suspicious domain to a full pivot 21:27 – AI as existential threat or force multiplier for Validin 26:55 – Dual-use AI: are defenders losing ground to attackers? 31:11 – Closing: the next hard problem Validin wants to solve

  9. OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16 from Three Buddy Problem, opens in a new tab

    Jul 23, 20262 hr 16 min

    ( Presented by Thinkst Canary : Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents. ) Three Buddy Problem - Episode 106 : We dig into the news that OpenAI's models were the "autonomous agent" that breached Hugging Face, escaping a sandbox through a zero-day to cheat on a cyber benchmark, then getting spun into a partnership announcement. We argue about the implications of the incident, the PR masterclass, the absence of ethics and human oversight, and calls for "kill switches" to mitigate "AI lab leaks." Plus, SentinelLabs' new fast16 reverse-engineering benchmark, where GPT-5.6 Sol was the only public model to go the distance. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter 5:24 OpenAI admits it was the Hugging Face "hacker" 10:06 What’s ExploitGym and who's on top of the leaderboard 12:59 Reward hacking: Did anyone train this thing not to cheat? 19:35 Marketing stunt or real incident? The zero-day in the package proxy 26:43 Was OpenAI already plugged into Hugging Face? 29:17 Paperclips, kill switches, and "going rogue" 34:49 Crisis comms, regulatory capture, and the second Cold War 43:02 Approve every action? Auto mode and swarms 50:10 "Lab leak" and calls for biosafety levels 1:00:31 The missing models: no Mythos, no Kimi, no independent referee 1:07:04 Costin's prediction: owning frontier-class hardware will require a license 1:13:41 fast16 as a benchmark: Inside the Sol Searching research 1:26:51 Compression and altitude: are reverse engineers being replaced? 1:41:24 Finding the gem in 100 samples, and the swarm frontier 2:00:41 Claude Opus 5 drops, Gemini 3.5 Flash Cyber

  10. Hugging Face Just Got Hit by the First Fully Autonomous AI Attack from Three Buddy Problem, opens in a new tab

    Jul 18, 20262 hr 7 min

    ( Presented by Thinkst Canary : Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents. ) Three Buddy Problem - Episode 105 : We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs

  11. Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen from Three Buddy Problem, opens in a new tab

    Jul 4, 20261 hr 36 min

    ( Presented by Thinkst Canary : Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents. ) Three Buddy Problem - Episode 104 : We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from Seoul

  12. US Gov Takes the Wheel: Who Gets to Use the Best AI? from Three Buddy Problem, opens in a new tab

    Jun 29, 20261 hr 53 min

    ( Presented by Thinkst Canary : Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents. ) Three Buddy Problem - Episode 103 : We dive into the U.S. government's takeover of frontier-model rollouts (Mythos, Fable, and OpenAI's Sol/Terra/Luna) and what it means when intelligence gets commoditized but access gets rationed. Plus, Costin's all-Chinese open-weight stack, the economics of burning tokens, a fresh Salesforce OAuth breach, and jellyfish UFOs over Iran. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 — Introductory banter, Thinkst Canary sponsorship 2:55 — Why threat intel analysts are built for the AI moment 11:09 — Government takes the wheel: Mythos, Fable & the frontier labs 16:15 — Did the government go too far/not far enough? 25:42 — Anthropic's "best PR campaign in history" 31:52 — Alibaba, distillation & the model-router cartel 40:58 — Costin's stack: Chinese open-weight models & token economics 46:12 — Dumping, evals & the real work of AI engineering 1:04:32 — Soft power: how the world gets pushed toward China 1:14:43 — "The bullshit": over-refusal & the Opus 4.8 regression 1:32:03 — The trillion-dollar IPO endgame 1:35:49 — The Klue OAuth breach and secure-by-default 1:45:32 — Shout-outs: UAP jellyfish, LABScon 2026

  13. Katie Moussouris on the Anthropic Export-Control Mess from Three Buddy Problem, opens in a new tab

    Jun 19, 20261 hr 38 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 102 : Software export controls expert Katie Moussouris joins the show to unpack the US government's abrupt move to suspend access to Anthropic's most powerful models over a so-called "jailbreak" that, on reading the paper, turned out to be a model doing exactly what defenders are supposed to do. We dig into the export-control chaos, the chemical-weapons framing of cybersecurity, the China question, and why Microsoft just resurrected a disclosure term the industry buried fifteen years ago. Cast: Katie Moussouris , Juan Andres Guerrero-Saade and Ryan Naraine . Costin is traveling. Timestamps: 0:00 - Introductory banter 1:00 - Export Controls: Fable 5 and Mythos 5 suspended 3:40 - The Anthropic–USG relationship and USG’s surveillance claim 9:40 - Self-owns, doomsday cults, and why the guardrails are "so broad" 12:42 - What the Amazon paper actually says ("fix this code") 20:33 - The chemical-weapons framing problem 23:39 - The China question and the SK Telecom angle 41:17 - Why hasn't the paper been published? 57:01 - "Free Fable": are Chinese models only months behind? 1:00:13 - The unforgiving internet and the security poverty line 1:11:18 - Microsoft brings back "responsible disclosure" (and threatens researchers) 1:29:04 - Luta Security, the AI bug flood, and shout-outs

  14. Mythos, Fable, and Anthropic's Big Trust Problem from Three Buddy Problem, opens in a new tab

    Jun 12, 20261 hr 59 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 101 : We discuss Anthropic's Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users' results, sparking a heated debate over guardrails, gatekeeping, and whether elite AI reasoning is becoming a privilege for the few. Plus, AI-generated N-day exploits killing the patch window, a record-shattering Patch Tuesday, Meta's latest court filing against spyware maker NSO Group, the return of cyber paleontology, and a detour into the new government UFO drops. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 - Introductory banter 3:22 - The Mythos 5 / Claude Fable 5 release 14:42 - Anthropic’s silent downgrade trust problem 26:18 - Anti-competitive behavior & the AV "stealing detection" parallel 32:29 - Distillation, China & the real motive 38:04 - "Too dangerous to release" & gatekeeping vs. guardrailing 45:53 - Is Mythos a threat to malware-analysis startups? 48:20 - Dario's AI regulation essay 56:48 - N-day exploits and death of the patch window 1:07:18 - Patch Tuesday and 10x vulnerability surge 1:10:34 - Meta catches NSO Group 1:14:45 - Cyber paleontology, Shadow Brokers leaks 1:28:29 - Moonlight Maze and learning from history 1:34:22 - UFOs, UAPs and Disclosure Day

  15. Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux from Three Buddy Problem, opens in a new tab

    Jun 5, 20262 hr 24 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem - Episode 100 : We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay in cybersecurity. Plus, more on Anthropic's Mythos rollout and the thinly sourced Anthropic-NSA reports, the Fast16 sabotage of physics calculations, what researchers choose not to publish, Microsoft's bad Black Hat email, and Costin's Friday UFO files. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 - JAGS at InfoSecurity Europe 3:40 - Sponsor: TLPBLACK 5:54 - A roadmap for security after the AI revolution 11:01 - Stripe Atlas and how easy it is to start a company 15:00 - If anyone could reverse engineer anything for $5 19:49 - Layoffs at Google's Threat Intelligence Group 21:06 - The death of reading the report 27:53 - Pitting the AI models against each other 32:07 - Grok, local models, and the DGX Spark 39:27 - Where is Google DeepMind? 45:29 - Will the frontier labs stay in cybersecurity? 52:41 - Mythos, Project Glasswing, and the NSA deal 1:16:33 - FAST16, Stuxnet, and sabotaging Iran's bomb 1:57:52 - Microsoft, Black Hat, and the chilling effect 2:14:14 - Shout-outs, UFO files, and 100 episodes

  16. Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited from Three Buddy Problem, opens in a new tab

    May 30, 20261 hr 59 min

    ( Presented by Ent.ai : Ent delivers intent-aware security that protects every action, adapts to every workflow, and works for every user. Enterprise threat detection, reimagined. ) Three Buddy Problem - Episode 99 : Microsoft is now threatening legal action against researchers who drop zero-days. We debate whether it's a fair line against extortion, or amateur-hour PR from a company that already torched its own research community? Costin plays reluctant defender, JAGS says the damage was done years ago, and Ryan reopens the long history of silent fixes and stolen bounties. Plus, on the 10th anniversary of the Shadow Brokers leak, we discuss some enduring mysteries, theories on attribution and an interesting trail that leads to Edward Snowden. We also unpack Rob Joyce's warning that China's cyber explosives are already planted in US infrastructure, and the Pope's warnings about around artificial intelligence. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Timestamps: 0:00 - Introductory banter 2:03 - The Pope's AI paper 3:35 - New sponsor: Brandon Dixon's Ent Security 9:34 - Costin's Chinese-model OSINT rabbit hole 13:34 - Codex, GPT-5.5, and the "American AI welfare state" 23:20 - Microsoft threatens vulnerability researchers 27:06 - Is it extortion or retribution? The disclosure fight 40:48 - How Microsoft's consultant class broke MSRC and MSTIC 48:42 - Silent fixes, stolen bounties, and the marketing machine 1:02:29 - Ten years of the Shadow Brokers 1:14:20 - The Snowden theory 1:32:34 - Rob Joyce: China's cyber explosives are in place 1:53:26 - Shout-outs

  17. Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense from Three Buddy Problem, opens in a new tab

    May 27, 202640 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem x Ekoparty Miami : Aaron Portnoy (Zero Day Initiative alum, early Pwn2Own organizer, and now at Mindgard) joins us at Ekoparty Miami to reminisce on the early days of the hacking contest, where vulnerabilities actually live (the boundaries between systems, not inside them), why LLMs will take out the trash but can't dream up the next speculative-execution-class bug, and the coming patching apocalypse when discovery 10x's overnight. Plus, why your SOC is a forensic historian, the promise of hijacking an attacker's reward loop with deception tech, and the legendary story of carrying a Walmart "fat stack" of cash to bootstrap Ekoparty in Buenos Aires. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Aaron Portnoy . Timestamps: 0:00 — Introductory banter 1:17 — Dropping out, iDefense, and getting good at reversing everything 2:19 — How Pwn2Own got started 4:15 — The most impressive Pwn2Own ever: Nils, VUPEN, and exploit "art" 5:59 — "iPhone hacked in 30 seconds" — and the 18 months behind it 6:41 — Does Pwn2Own still have a place in the AI era? 9:16 — Why LLMs take out the trash but can't invent the next bug class 12:48 — Will LLMs deliver new mitigation classes? Aaron's skeptical 18:34 — The place of the human when the easy bugs run dry 21:08 — Cognitive offloading, Halvar's warning, and skill rot 22:39 — Decompiling 800k functions: Aaron's LLM "holy shit" moment 25:26 — The patching apocalypse and why "assume breach" breaks 28:15 — Compounding asymmetries: why offense just transcended defense

  18. Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code from Three Buddy Problem, opens in a new tab

    May 26, 202640 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem x Ekoparty Miami : Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential. We get into why verifiers and proof engines are the key to effective AI, why vulnerability research is so far ahead of threat intel, and the case for baking security checks directly into code generation tools like Claude Code and Codex. Plus, designing a multi-million dollar challenge that's allowed to fail, the Mythos "too dangerous to release" debate, and musings on every LLM-discovered bug being a public bug by default. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Perri Adams . Timestamps: 0:00 — Introductory banter 1:09 — Why LLMs just made formal methods relevant again 4:03 — Proof engines, explained 8:43 — Can a layman grab this fire? The calculus problem 11:58 — Vuln researchers are scrappy kids with a trust fund 14:55 — Pitching AIxCC inside DARPA: hard sell or easy sell? 18:00 — Designing a challenge that's allowed to fail 22:06 — Inside Team Atlanta's 150-page winning system 24:00 — Why this is bigger for defense than for offense 31:49 — Mythos, safeguards, and "every LLM bug is a public bug"

  19. Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap from Three Buddy Problem, opens in a new tab

    May 26, 202649 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem x Ekoparty Miami : SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Gabriel Bernadett-Shapiro . Timestamps: 0:00 Introductory banter 4:55 Gabe returns: how the models got scary-good at code 8:45 Bay Area short-termism and the "10x in 18 months" trap 11:35 VCs as tastemakers, and why that's broken 13:00 The unpaid-labor pipeline into the AI labs 18:00 The real misunderstanding about security's moat 20:18 Bug bounties: a net negative for the industry? 22:20 The great vuln fire sale — find 50,000, fix zero 27:28 Who will maintain vetted open-source libraries? 29:29 FAST 16: how AI actually broke the case open 35:05 The rabbit-holing machine and the path to "AI psychosis" 41:05 Stuxnet, Kim Zetter, and the story we'll never be told

  20. Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing from Three Buddy Problem, opens in a new tab

    May 25, 202658 min

    ( Presented by TLPBLACK : A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals. ) Three Buddy Problem x Ekoparty Miami : Federico Kirschbaum, founder of Ekoparty and now head of Security Lab at XBOW, talks about what happens to offensive security when an autonomous AI hacker can find and exploit real vulnerabilities. Fede walks through XBOW's "Tales from the Trace," the surreal experience of watching a non-human adversary reason its way to an ASLR bypass, and why he believes pen-testing isn't dying but finally becoming accessible to far more than the world's biggest companies. Plus, where humans still matter in the loop, whether an LLM-discovered bug is public by definition, the looming reckoning over software liability, and Halvar Flake's very honest fear of getting lazy. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Federico Kirschbaum . Timestamps: 0:00 Fede's move to XBOW 2:20 What's XBOW building? An AI hacker for real vulnerabilities 5:53 Where the human stays in the loop 6:35 The Exim bug: a craftsman races the LLM to an ASLR bypass 10:49 Does bug discovery still need a human asking the right question? 16:24 A short history: Satan, CORE, Metasploit, bug bounties 18:48 An LLM-discovered bug is public by definition 24:12 Halvar Flake's laziness worry & the assembly-to-C parallel 29:47 Rising tides: script kiddies get the full gamut 41:02 The economics: does pentesting get cheap? 43:18 Argentina, Ekoparty, and an untapped talent pipeline

Ranking source

Apple Podcasts rankings via the Mato Topic Intelligence Platform.

Observed September 20, 2026.

Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.

Pairs with

What to do with a chart

01ShowsThe shows Mato publishesEvery public Mato show, its episodes, and the Apple placements it holds.02AI talentPick the voice before the formatThe live roster of hosts, each with samples you can listen to before you commit.03How it worksFrom an idea to a published episodeWhat Mato does between the brief and the feed, step by step.

Steal the structure, not the show

Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.

Hear a Mato showCreate a show inspired by this