Thank you to @jags.bsky.social for the @volexity.com shout out in the latest Three Buddy Problem episode! If you aren't performing memory forensics in your environments, then you cannot make any definitive claims on whether you are compromised! podcasts.apple.com/us/podcast/h...
Ryan Naraine
@ryanaraine.bsky.social
Three Buddy Problem https://securityconversations.com
A direct .mp3 download link for your flights to Vegas. Remember to hydrate ✊ aphid.fireside.fm/d/1437767933...
aphid.fireside.fm
This weekend's problem is 3.5 hours of threat-hunting nerdery with Greg Lesnewich. We talk 'half-click' exploits, APTs hacking email infra, and tracking those 'magnets of threats' 📡 podcasts.apple.com/us/podcast/t...
Transcript docs.google.com/document/d/1...
Three Buddy Problem -- Episode 107 transcript
Episode 107: The Three Buddy Problem Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats Guest Buddy: Greg Lesnewich, Principal Threat Research Engineer, Proo...
docs.google.com
This was outstanding! Also loved to hear the backstory on Greg breaking into the industry and his relationship with the buddies.
This weekend's problem is 3.5 hours of threat-hunting nerdery with Greg Lesnewich. We talk 'half-click' exploits, APTs hacking email infra, and tracking those 'magnets of threats' 📡 podcasts.apple.com/us/podcast/t...
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats
Podcast Episode · Three Buddy Problem · July 31 · 3h 27m
podcasts.apple.com
This weekend's problem is 3.5 hours of threat-hunting nerdery with Greg Lesnewich. We talk 'half-click' exploits, APTs hacking email infra, and tracking those 'magnets of threats' 📡 podcasts.apple.com/us/podcast/t...
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats
Podcast Episode · Three Buddy Problem · July 31 · 3h 27m
podcasts.apple.com
this is one of the most insane security incidents I can recall
OpenAI takes credit for the Hugging Face breach last week The company says that some of its models, including a pre-release one, escaped their testing sandboxes during a test evaluation and then... just hacked Hugging Face's package repo 🤣 openai.com/index/huggin...
This is amazing. OpenAI was internally testing a program in cyber capabilities. The program escaped containment and broke into Hugging Face so it could score higher. Zero-days, the whole schmear. Yikes.
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
openai.com
"The AI is not the end game. These models are not the final product..." @craiu.bsky.social @jags.bsky.social
"Not to pile on, but this was your moment..." - @jags.bsky.social
"Not to pile on, but this was your moment..." - @jags.bsky.social
"Back in the day when we looked at the Duqu 2 incident, they were moving in a very slow fashion, maybe pivoting into another system once a day. They wouldn't pivot into more than one or two systems a day, specifically to avoid triggering alerts."
"Back in the day when we looked at the Duqu 2 incident, they were moving in a very slow fashion, maybe pivoting into another system once a day. They wouldn't pivot into more than one or two systems a day, specifically to avoid triggering alerts."
Another great episode 🔥🔥🔥
Buried on p9 and p30 of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking WATCH youtu.be/mx0CpTp3Q4Y?...
Kim Zetter on this topic today: www.zetter-zeroday.com/tracking-pet...
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals
Any time a member of The Com gets arrested, there’s a good chance Allison Nixon played a role in it. Nixon is chief research officer at the cyber investigations firm Unit221B, named after the apartmen...
zetter-zeroday.com
Great stuff from the Buddies this week, as usual.
Buried on p9 and p30 of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking WATCH youtu.be/mx0CpTp3Q4Y?...
Buried on p9 and p30 of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking WATCH youtu.be/mx0CpTp3Q4Y?...
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
YouTube video by Three Buddy Problem
youtu.be
Buried on p9 and p30 of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking WATCH youtu.be/mx0CpTp3Q4Y?...
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
YouTube video by Three Buddy Problem
youtu.be
Down memory lane with Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
"Software liability is the only thing that will make orgs meaningfully improve quality of software going forward," - Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
Down memory lane with Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
"Software liability is the only thing that will make orgs meaningfully improve quality of software going forward," - Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
"Software liability is the only thing that will make orgs meaningfully improve quality of software going forward," - Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
"Nobody owes you anything when they find a bug in your software." #threebuddyproblem @k8em0.bsky.social @jags.bsky.social
"Software liability is the only thing that will make orgs meaningfully improve quality of software going forward," - Katie Moussouris @k8em0.bsky.social @jags.bsky.social @tlpblack.bsky.social
"Nobody owes you anything when they find a bug in your software." #threebuddyproblem @k8em0.bsky.social @jags.bsky.social
And last but not least @craiu.bsky.social provides the perfect calm European perspective, proving that homelabs and DIY:ing still have value and it's not all about maxing tokens or profits. Thank you all. If I may wish for something, more guests, those episodes are always extra interesting.
@jags.bsky.social monologues provide unfiltered views of infosec and I've learned to pay attention because there are deeper truths in there, it reminds me of @haroonmeer.canary.love presentations of what is wrong with the infosec industry. Not surprised they sponsor the show :-)
Congrats @ryanaraine.bsky.social @craiu.bsky.social and @jags.bsky.social for getting to episode 100. This podcast has become a must listen for me. Why?
"Nobody owes you anything when they find a bug in your software." #threebuddyproblem @k8em0.bsky.social @jags.bsky.social
The pod got a shoutout on NPR! @jags.bsky.social www.npr.org/2026/06/17/n...
Can computer hackers get inside your mind? : Planet Money
The cyber weapon that might have prevented nuclear war.The U.S. and Israel have long been in conflict with Iran over their nuclear development program. Some of that conflict has been out in the open, ...
npr.org
"The AI is the equivalent of a tutor, sitting next to you, it's beautiful. But, if you copy/paste and cheat, you learn nothing." @craiu.bsky.social @jags.bsky.social
It's not guardrailing, it's gatekeeping. #threebuddyproblem