Three Buddy Problem cover image

Three Buddy Problem

Latest episodes

undefined
13 snips
Jan 24, 2025 • 1h 49min

Death of the CSRB, zero-days storms at the edge, Juniper router backdoors

Dennis Fisher, a prominent cybersecurity journalist, fills in as guest host for a riveting discussion with experts Juan Andres Guerrero-Saade and Costin Raiu. They tackle the disbanding of the Cyber Safety Review Board and its significant implications. The conversation dives into the flood of exploits targeted at Ivanti and SonicWall devices and recent findings about Juniper router backdoors. Challenges in coordinating disclosures and the complexities of nation-state attack landscapes, particularly involving Chinese threat actors, underscore the urgent need for innovative cybersecurity solutions.
undefined
19 snips
Jan 17, 2025 • 1h 60min

Inside the PlugX malware removal operation, CISA takes victory lap and another Fortinet 0day

Discover the bold efforts of French intelligence in combating the PlugX malware through sovereign disinfections. CISA highlights progress with a new cybersecurity Executive Order, despite skepticism about real change. The podcast dives into critical vulnerabilities like the Fortinet zero-day, and debates the implications of TikTok bans on data privacy. Plus, hear about the evolving tactics of cybercriminals amid geopolitical tensions and the call for global cybersecurity collaboration to tackle these threats effectively.
undefined
11 snips
Jan 10, 2025 • 1h 48min

Hijacking .gov backdoors, Ivanti 0days and a Samsung 0-click vuln

The podcast dives into the troubling rise of Ivanti zero-day vulnerabilities, highlighting their constant exploitation. China's unusual reactions to cyber attribution are explored, alongside Japan's concerns over hacking incidents. The hosts discuss a shocking zero-click vulnerability found in Samsung devices, and the intense cyber warfare between Ukrainian hackers and Russian ISPs. They also touch on the implications of advanced technologies like quantum computing and the resilience of the cybersecurity community in facing these challenges.
undefined
32 snips
Jan 3, 2025 • 1h 49min

US Treasury hacked via BeyondTrust, MISP and the threat actor naming mess

Discover the chaos surrounding threat actor naming conventions and the push for a standardization via MISP. Dive into the breach of BeyondTrust that compromised the US Treasury, illustrating the urgent need for improved cybersecurity. Unpack the emergence of the XDR33 CIA Hive malware variant and explore its low detection rates. With insights into the distrust surrounding corporate cybersecurity pledges, the discussion emphasizes accountability and transparency in the face of escalating threats.
undefined
9 snips
Dec 27, 2024 • 1h 53min

Palo Alto network edge device backdoor, Cyberhaven browser extension hack, 2024 research highlights

Delve into the stealthy backdoor found in Palo Alto's network edge devices and the broader implications of the Cyberhaven browser extension hack. Explore the dangers of deepfake technology and its potential misuse in cyber threats. The discussion covers the pressing issues of browser extension security, phishing risks, and insider threats in today's landscape. Additionally, they highlight significant cybersecurity research from 2024, emphasizing the evolving tactics of state-sponsored cyber operations and the need for vigilance against increasing vulnerabilities.
undefined
11 snips
Dec 23, 2024 • 1h 59min

US government's VPN advice, dropping bombs on ransomware gangs

The podcast dives into the controversial U.S. government VPN recommendations and their risks, including potential backdoor access. It uncovers the ethical implications of spyware like NoviSpy used against activists in Serbia. The discussion on Mossad's clever tactics with ransomware exposes the murky depths of cyber warfare. Additionally, it highlights critical cybersecurity vulnerabilities and the challenge of navigating international cooperation amidst an evolving threat landscape. Funny anecdotes and personal updates keep the tone light and engaging.
undefined
16 snips
Dec 13, 2024 • 2h 14min

Surveillance economics, Turla and Careto, and the AI screenshots nobody asked for

Dive into the fraught intersection of technology and democracy, as discussions reveal TikTok's potential to sway elections and amplify misinformation. Explore the dark underbelly of cyber operations with insights into Turla's manipulative tactics and Careto's latest hacking efforts. The ethical ramifications of surveillance capitalism and the covert data capture on macOS raise eyebrows. Plus, a glance at quantum computing’s role in security challenges and the complexities of cyber warfare add layers to this riveting conversation.
undefined
7 snips
Dec 7, 2024 • 1h 47min

Inside the Turla Playbook: Hijacking APTs and fourth-party espionage

Dive into the intriguing world of cyber espionage as experts unravel the tactics of Russia's Turla APT, including its surprising theft from Pakistani networks. Discover the complexities of threat attribution and the challenges of identifying cyber actors. The episode also scrutinizes the concerning rise of spyware in Russia and the implications of supply chain vulnerabilities in Web3 technologies. On a more political note, explore the alarming election interference in Romania fueled by misinformation and social media dynamics.
undefined
4 snips
Nov 30, 2024 • 1h 19min

Volexity’s Steven Adair on Russian Wi-Fi hacks, memory forensics, appliance 0days and network inspectability

Steven Adair, the founder of Volexity and a cybersecurity expert, shares insights on crucial topics in the field. He discusses innovative approaches to memory forensics, emphasizing their importance in incident response. The conversation dives into Volexity's discoveries regarding Wi-Fi hacks and the complexities of EDR systems. Adair also addresses the rise of professional ransomware attacks, highlighting a recent Firefox zero-day and the emergence of a Linux bootkit. His expertise sheds light on significant vulnerabilities and the urgent need for robust network security.
undefined
Nov 28, 2024 • 1h 1min

Sid Trivedi on the RSA Innovation Sandbox $5 million investment gambit

In this conversation, Sid Trivedi, a partner at Foundation Capital specializing in early-stage cybersecurity investments, discusses the RSA Innovation Sandbox's new $5 million investment requirement for finalists. He highlights red-flag concerns regarding pro-rata rights and ethical dilemmas facing CISOs involved with startups. The dialogue also delves into the challenges of funding seed-stage companies in a platform-driven market, while reflecting on the complex relationships between venture capitalists and groundbreaking innovations in cybersecurity.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode