Three Buddy Problem

Shai-Hulud 2.0, Russia GRU Intrusions, and Microsoft’s Regulatory Capture

4 snips
Nov 29, 2025
The hosts dive into Microsoft's shifting stance on intel sharing and what it means for the security landscape. They dissect the Shai-Hulud 2.0 npm supply-chain attack and its implications for trust in package ecosystems. CISA's guidance on mobile spyware elicits strong opinions, while NSO's legal troubles reveal the complexities of cyber capabilities. Arctic Wolf's report on GRU-linked intrusions shines a light on geopolitical cyber threats, and the FCC's rollback of telecom cybersecurity rules sparks vital debates on regulation and accountability.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Microsoft's Outsized Security Role

  • Microsoft holds unmatched telemetry and talent that make its sharing choices globally impactful.
  • Withholding publications or data harms defenders and concentrates power inside the company.
INSIGHT

Research Needs Independence

  • Research teams need operational independence to publish and engage the community effectively.
  • Putting research under CISO or nontechnical orgs risks silencing findings and reducing public contribution.
INSIGHT

Policy Push Can Be Regulatory Capture

  • Microsoft's policy push reads as regulatory capture: shape rules to protect cloud and AI market position.
  • Public advocacy for policy often doubles as strategic positioning to influence regulators.
Get the Snipd Podcast app to discover more snips from this episode
Get the app