
Three Buddy Problem
The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks.
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
Connect with Ryan on Twitter (Open DMs).
Latest episodes

34 snips
Nov 15, 2024 • 1h 54min
What happens to CISA now? Is deterrence in cyber possible?
In this discussion, Juan Andres Guerrero-Saade, a security researcher from SentinelLabs, and Costin Raiu, Director at Kaspersky, dive into the intricacies of cyber deterrence and the evolving threats from Iranian groups. They examine the implications of the FBI and CISA's investigation into recent cyber espionage incidents, including the Salt Typhoon hacks. The conversation also explores the uncertain future of CISA amid political changes and the impact of emerging cyber capabilities from China. Insights into corporate transparency and the role of cryptocurrency in cybersecurity round out this compelling dialogue.

35 snips
Nov 9, 2024 • 1h 37min
Mysterious rebooting iPhones, EDR vendors spying on hackers, Bitcoin 'meatspace' attacks
Join security experts Juan Andres Guerrero-Saade from SentinelLabs and Costin Raiu from Kaspersky as they dive into intriguing topics. They unravel the mystery of iPhones rebooting in law enforcement custody due to a new iOS feature. They discuss malware like GoblinRAT and North Korea's cunning cryptocurrency theft tactics. The conversation also touches on the ethics of EDR software transparency and the dangers of physical attacks in the crypto world, offering essential insights for enthusiasts and professionals alike.

47 snips
Nov 3, 2024 • 1h 54min
The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela
Joined by Juan Andres Guerrero-Saade, a malware expert at SentinelLabs, and Costin Raiu, Kaspersky’s Director of Global Research, the conversation dives deep into contemporary cybersecurity challenges. They discuss the ethical quandaries of using Sophos's kernel implants for monitoring hackers and the controversial notion of 'hack-back.' The guests also explore CIA malware activities in Venezuela and an alarming espionage scandal involving the Vatican, highlighting the intricate ties between cyber operations and geopolitics.

8 snips
Oct 25, 2024 • 1h 27min
Fortinet 0days, Appin hack-for-hire exposé, crypto heists, Russians booted from Linux kernel
In this engaging discussion, Juan Andres Guerrero-Saade, a threat intelligence expert from SentinelLabs, and Costin Raiu, Kaspersky's Global Research Director, dive into critical cybersecurity issues. They unpack the alarming rise of cryptocurrency heists and the sophisticated tactics employed by cybercriminals. The conversation also touches on the implications of a major Fortinet zero-day exploit linked to potential nation-state actors and the exclusion of Russian contributors from the Linux kernel amid geopolitical tensions. Insights on accountability in tech vendors and investigative journalism add further depth.

16 snips
Oct 18, 2024 • 1h 38min
ESET Israel wiper malware, China's Volt Typhoon response, Kaspersky sanctions and isolation
Juan Andres Guerrero-Saade from SentinelLabs and Costin Raiu from Kaspersky dive into the recent wiper malware attack in Israel, revealing its ties to geopolitical tensions. They discuss the motivations behind hacktivism and the media's role in shaping cybersecurity narratives, cautioning against sensationalism. The conversation also touches on China's curious response to the Volt Typhoon incident and the ramifications for global security. Finally, they examine the ongoing isolation of Kaspersky amidst sanctions, highlighting the complexities of maintaining effective cybersecurity in a challenging landscape.

8 snips
Oct 11, 2024 • 1h 9min
Typhoons and Blizzards: Cyberespionage and national security on front burner
In this engaging discussion, Juan Andres Guerrero-Saade from SentinelLabs and Costin Raiu from Kaspersky delve into critical cybersecurity issues. They break down the GCHQ report on Russian cyber threats and the complexities of tracking advanced persistent threats like APT29. The risks of supply chain attacks and the alarming rise of zero-day vulnerabilities are explored. They also scrutinize the tension between lawful surveillance and abuse, while emphasizing the urgent need for improved cybersecurity measures in today’s volatile threat landscape.

9 snips
Oct 4, 2024 • 1h 31min
Careto returns, IDA Pro pricing controversy, crypto's North Korea problem
Juan Andres Guerrero-Saade, a security researcher at SentinelLabs specializing in malware analysis, and Costin Raiu, director at Kaspersky, dive into fascinating discussions. They unveil the reemergence of the Careto APT, exploring its unique methods and victimology. The controversial shift of IDA Pro to a subscription model raises concerns, while the duo delves into North Korea's cyber threats targeting crypto companies. They also tackle the pricing issues surrounding VirusTotal and the ethical dilemmas of commercial spyware use by the U.S. government.

Sep 28, 2024 • 1h 19min
Exploding beepers, critical CUPS flaws, Windows Recall rebuilt for security
Juan Andres Guerrero-Saade and Costin Raiu, both prominent security researchers, delve into the interplay of mental health and the demanding nature of cybersecurity. They discuss the revamped security architecture of Windows Recall, highlighting the implications for user privacy. The conversation shifts to a pressing Linux CUPS flaw with a CVSS score of 9.9 and the fascinating yet alarming use of exploding pagers in Lebanon's intelligence operations. Their insights offer a blend of humor and serious reflections on the evolving tech landscape.

Sep 21, 2024 • 32min
Ep13: The Consolation of Threat Intel (JAG-S LABScon keynote)
Juan Andres Guerrero-Saade is a leading expert in threat intelligence at SentinelLabs. In this engaging keynote, he tackles the challenges facing the industry, calling for a much-needed conversation about its future. Juan highlights the feelings of burnout among professionals and stresses the importance of meaningful work. He advocates for interdisciplinary collaboration and actionable insights to enhance threat intelligence. Ultimately, he urges the cybersecurity community to revitalize the field by aligning efforts with business value and fostering a spirit of engagement.

Sep 14, 2024 • 1h 14min
Ep12: Security use-cases for AI chain-of-thought reasoning
Gabriel Bernadett-Shapiro, an expert in AI and cybersecurity, joins fellow specialists Juan Andres Guerrero-Saade from SentinelLabs and Ryan Naraine from SecurityWeek for intriguing insights. They dive into the hype surrounding OpenAI's new model and its impact on AI reasoning in cybersecurity. The trio explores innovative use cases in threat intelligence, the clash between open-source and closed systems, and the balancing act between privacy regulations and technological advancement. Get ready for a thought-provoking discussion on AI's future and its implications!