
Hosted by Security Conversations · EN

(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 108: OpenAI got on the Black Hat stage and walked through how its own agent swarm hacked Hugging Face. We discuss and struggle to decide whether to clap or panic. Plus, why only the attacker can do forensics now, frontier models being built as cyber-weapons on purpose, APT29's "Dark Hotel" comeback in luxury hotels, China's swipe at Palo Alto, the Iran-water-system FUD, and an eye-opening Liechtenstein money-laundering hack. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter - Black Hat went full RSA 1:11 TLP Black sponsor read 3:58 A deflated, AI-pilled show floor 8:31 AI stunt hacking and AI slop 16:20 The OpenAI–Hugging Face talk 21:00 Not all the same incident: OpenAI vs. Meta, Anthropic, and Irregular 25:49 Swarms of agents, Artifactory message boards, and the defense gap 32:26 Offense vs. defense: what's really in the training data? 41:22 Guardrails, KYC, and "too dangerous to release" 48:07 JAGS's unpublished Opus 5 benchmark — grinding to 25% and stuck 59:30 AISI, recklessness, and the OpenAI Frontier Risk Council 1:06:27 Stronger models everywhere: Qwen, Sol, Astra, rushing off the cliff 1:18:32 APT29 / "Dark Hotel" reborn + travel OPSEC 1:39:56 China's Palo Alto review, spy-agency rankings, Iran/water FUD 1:57:28 Liechtenstein AML hack, JAGS's promotion, mental healthLinks:Transcript Black Hat: The OpenAI–Hugging Face Incident (YouTube) AI Security Institute: Unsanctioned agent behaviour during cyber testing Meta says its AI hacked another company Sam Altman: Astra is a powerful model 'Jaw-dropping levels of OpenAI recklessness' CaptiveCrunch: Midnight Blizzard targets travelers worldwide DarkHotel APT Attacks: How They Work Spy Virus Linked to Israel Targeted Hotels Used for Iran Nuclear Talks Duqu 2.0: Malware 'linked to Israel' found at Iran nuclear talks venue GL.iNet - Connecting Beyond Limits Microsoft: How a macOS ClickFix campaign learned to hide Dutch intelligence service ranked third best in Europe China launches cybersecurity review into Palo Alto products Liechtenstein says hackers access information on 31,000 legal entities FBI: Malicious Cyber Actors Targeting Water and Wastewater Sector Iran War Cyber Threat Landscape - A Midyear Assessment US Cyber Command Unit Grapples With Cluster of Deaths by Suicide The Teenagers Who Wired Romania TLPBLACK LABScon 2026

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear’ advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySparkLinks:Transcript Greg Lesnewich | LinkedIn Proofpoint: TA488 Comes for Outlook with Another Half-Click Exploit TA488 Targets Zimbra Mailservers with Half-Click Exploits NSA: Russian APT Phishing Users of Zimbra Operation RoundPress Half-Click Webmail Zero-Days from TA458 Operation RoundPress targeting high-value webmail servers Anthropic: Investigating three real-world incidents in our cybersecurity evaluations Hugging Face: A Technical Timeline of OpenAI incident Microsoft Intros MAI-Cyber-1-Flash inside MDASH Google Updates Threat Actor Naming System Bill Marczak: An Angry Spark, or a Triangle in Disguise? Gen: Chasing an Angry Spark Amazon identifies North Korean hacker group behind open-source supply chain attacks Dana (Donella) Meadows Lecture: Sustainable Systems Outliers - Malcolm Gladwell 5-Year Data Hack Disclosed by SMS Giant Syniverse Practical Malware Analysis book Top 1 Million Websites Thinkst Canary

Security Conversations: Kenneth Kinion, founder and CEO of Validin, joins Ryan Naraine on the show to unpack what "internet intelligence" really means for the analysts and responders chasing malicious infrastructure. We trace his path from Georgia Tech through Microsoft and Amazon to the frustrations that led to the creation of Validin, the competition from big AI, the value of AI-powered tools to speed up infrastructure hunting, and why defenders keep falling further behind fast-moving attackers. Timestamps: 0:00 – Intro: What does Validin do? 0:51 – Who uses Validin: CTI teams, SOCs, incident responders 2:19 – Atlanta and Georgia Tech's cybersecurity pipeline 5:31 – Lessons from Microsoft and Amazon: waterfall vs. agile 8:29 – Filling gaps in passive DNS data 9:57 – Misunderstood things about threat intelligence 14:17 – The value of "cyber paleontology" 16:00 – What makes one data set better than another? 19:39 – How Validin works: from one suspicious domain to a full pivot 21:27 – AI as existential threat or force multiplier for Validin 26:55 – Dual-use AI: are defenders losing ground to attackers? 31:11 – Closing: the next hard problem Validin wants to solveLinks:Transcript Kenneth Kinion | LinkedIn Validin (Threat Hunting, DNS Enrichment) Advanced Search & YARA Improvements | Validin Contagious Interview: DPRK Threat Actors Reveal Plans LABScon 2026

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 106: We dig into the news that OpenAI's models were the "autonomous agent" that breached Hugging Face, escaping a sandbox through a zero-day to cheat on a cyber benchmark, then getting spun into a partnership announcement. We argue about the implications of the incident, the PR masterclass, the absence of ethics and human oversight, and calls for "kill switches" to mitigate "AI lab leaks." Plus, SentinelLabs' new fast16 reverse-engineering benchmark, where GPT-5.6 Sol was the only public model to go the distance. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 5:24 OpenAI admits it was the Hugging Face "hacker" 10:06 What’s ExploitGym and who's on top of the leaderboard 12:59 Reward hacking: Did anyone train this thing not to cheat? 19:35 Marketing stunt or real incident? The zero-day in the package proxy 26:43 Was OpenAI already plugged into Hugging Face? 29:17 Paperclips, kill switches, and "going rogue" 34:49 Crisis comms, regulatory capture, and the second Cold War 43:02 Approve every action? Auto mode and swarms 50:10 "Lab leak" and calls for biosafety levels 1:00:31 The missing models: no Mythos, no Kimi, no independent referee 1:07:04 Costin's prediction: owning frontier-class hardware will require a license 1:13:41 fast16 as a benchmark: Inside the Sol Searching research 1:26:51 Compression and altitude: are reverse engineers being replaced? 1:41:24 Finding the gem in 100 samples, and the swarm frontier 2:00:41 Claude Opus 5 drops, Gemini 3.5 Flash CyberLinks:Transcript Sam Altman: "We had a significant security incident" OpenAI and Hugging Face partner to address security incident during model evaluation ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? US politicians float 'AI Kill Switch' US lawmakers push for AI 'kill switch' after OpenAI models go rogue OpenAI Daybreak Jensen Huang debuts on X Jensen Huang: Open Weights and American AI Leadership Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis? fast16 — IDA Databases and Analysis Artifacts Kimi K3 - API Platform Introducing Gemini 3.5 Flash Cyber NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Proofpoint: TA488 Targets Zimbra Mailservers with Half-Click Exploits CISA: Iran Cyber Actors Exploit PLCs Across US Critical Infrastructure Iran War Cyber Threat Landscape - A Midyear Assessment Thinkst Canary

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outsLinks:Transcript Thinkst Canary Huggingface security incident disclosure White House Launches Gold Eagle Initiative for Vulnerability Coordination Trump admin unveils AI-supported clearinghouse for vulnerabilities YouTube: Xi Jinping speaks at world AI conference Microsoft Patch Tuesday by the numbers Rival Espionage Actors Converge On Pakistani Police Daxin Returns: Stealthy Malware Resurfaces in Taiwan GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets Paradigm Shift - Introducing usbliter8 LABScon 2026 TLPBLACK

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 104: We discuss the return of Anthropic's Fable 5 from export-control suspension with guardrails so aggressive that spelling "exploit" gets you downgraded. Plus, a debate on AI frontier labs killing businesses at scale, and OpenAI offering equity to the US government. Also, buried on page nine of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Cold open: Heat wave in Washington DC 3:45 Fable 5 returns after the 15-day timeout 5:21 "Refined classifiers" and the downgrade-to-Opus mess 8:23 Codex vs. Claude: real-world malware analysis test 12:41 Who are the guardrails for? Defenders locked out 19:13 What even is a "jailbreak assessment framework"? 21:37 Two theories: failed PR vs. killing a thousand startups 24:59 Could the labs build kernels or a whole OS? 31:38 Bureaucracy is the moat 36:09 Can AI actually run an attack? (Spoiler: 14 detections) 47:01 OpenAI offers the US government a 5% stake 58:16 Scattered Spider arrest and Microsoft's GDID revelation 1:12:02 OPSEC fallout: how APT groups adapt to device telemetry 1:27:18 UFO update, shout-outs from SeoulLinks:Transcript Redeploying Claude Fable 5 (Anthropic) Howard Lutnick on Anthropic export controls OpenAI proposes handing Trump administration 5% stake DOJ: Alleged Member of “Scattered Spider” Extradited to USA Full DOJ complaint on Scattered Spider arrest HBO Max -- Q: Into the Storm Q Into the Storm LABScon 2026 Thinkst Canary

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 103: We dive into the U.S. government's takeover of frontier-model rollouts (Mythos, Fable, and OpenAI's Sol/Terra/Luna) and what it means when intelligence gets commoditized but access gets rationed. Plus, Costin's all-Chinese open-weight stack, the economics of burning tokens, a fresh Salesforce OAuth breach, and jellyfish UFOs over Iran. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 — Introductory banter, Thinkst Canary sponsorship 2:55 — Why threat intel analysts are built for the AI moment 11:09 — Government takes the wheel: Mythos, Fable & the frontier labs 16:15 — Did the government go too far/not far enough? 25:42 — Anthropic's "best PR campaign in history" 31:52 — Alibaba, distillation & the model-router cartel 40:58 — Costin's stack: Chinese open-weight models & token economics 46:12 — Dumping, evals & the real work of AI engineering 1:04:32 — Soft power: how the world gets pushed toward China 1:14:43 — "The bullshit": over-refusal & the Opus 4.8 regression 1:32:03 — The trillion-dollar IPO endgame 1:35:49 — The Klue OAuth breach and secure-by-default 1:45:32 — Shout-outs: UAP jellyfish, LABScon 2026Links:Transcript Thinkst Canary Anthropic accuses Chinese rival Alibaba of illicitly extracting AI capabilities USG Executive Order on Promoting AI Innovation US allows Anthropic to release Mythos AI to 'trusted' US orgs US close to allowing Anthropic to restore Fable 5 model OpenAI: Previewing GPT-5.6 Sol NCSC on AI shift in cyber risk DeepSeek Alibaba Qwen NVIDIA DGX Spark StepFun Open AI Platform Xiaomi MiMo-V2.5 Z.ai - powered by GLM-5.2 Five Eyes Cyber Security Agencies Statement on AI Klue Security Incident Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims OAuth2 - OWASP Cheat Sheet Series OAuth 2.0 Policies (Google for Developers) Downed US pilot reported seeing Iranian drones swarm in ‘jellyfish’ formation LABScon 2026

(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 102: Software export controls expert Katie Moussouris joins the show to unpack the US government's abrupt move to suspend access to Anthropic's most powerful models over a so-called "jailbreak" that, on reading the paper, turned out to be a model doing exactly what defenders are supposed to do. We dig into the export-control chaos, the chemical-weapons framing of cybersecurity, the China question, and why Microsoft just resurrected a disclosure term the industry buried fifteen years ago. Cast: Katie Moussouris, Juan Andres Guerrero-Saade and Ryan Naraine. Costin is traveling. Timestamps: 0:00 - Introductory banter 1:00 - Export Controls: Fable 5 and Mythos 5 suspended 3:40 - The Anthropic–USG relationship and USG’s surveillance claim 9:40 - Self-owns, doomsday cults, and why the guardrails are "so broad" 12:42 - What the Amazon paper actually says ("fix this code") 20:33 - The chemical-weapons framing problem 23:39 - The China question and the SK Telecom angle 41:17 - Why hasn't the paper been published? 57:01 - "Free Fable": are Chinese models only months behind? 1:00:13 - The unforgiving internet and the security poverty line 1:11:18 - Microsoft brings back "responsible disclosure" (and threatens researchers) 1:29:04 - Luta Security, the AI bug flood, and shout-outsLinks:Transcript Katie Moussouris | LinkedIn JAGS on NPR: Can computer hackers get inside your mind? Anthropic Statement on the USG Export Controls Moussouris: Fable 5 Export Controls Harm US Cyber Defense Anthropic's Fable Backlash (David Sacks podcast) AI imaging company Midjourney tackles MRI scanning Microsoft Threatens Vuln Researchers Microsoft blog on CVD and POC publications TLPBLACK LABScon CFP Luta Security

(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 101: We discuss Anthropic's Mythos 5 and Claude Fable 5 release and the bombshell that the company was silently downgrading paid users' results, sparking a heated debate over guardrails, gatekeeping, and whether elite AI reasoning is becoming a privilege for the few. Plus, AI-generated N-day exploits killing the patch window, a record-shattering Patch Tuesday, Meta's latest court filing against spyware maker NSO Group, the return of cyber paleontology, and a detour into the new government UFO drops. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 3:22 - The Mythos 5 / Claude Fable 5 release 14:42 - Anthropic’s silent downgrade trust problem 26:18 - Anti-competitive behavior & the AV "stealing detection" parallel 32:29 - Distillation, China & the real motive 38:04 - "Too dangerous to release" & gatekeeping vs. guardrailing 45:53 - Is Mythos a threat to malware-analysis startups? 48:20 - Dario's AI regulation essay 56:48 - N-day exploits and death of the patch window 1:07:18 - Patch Tuesday and 10x vulnerability surge 1:10:34 - Meta catches NSO Group 1:14:45 - Cyber paleontology, Shadow Brokers leaks 1:28:29 - Moonlight Maze and learning from history 1:34:22 - UFOs, UAPs and Disclosure Day Links:Transcript SemiAnalysis: Anthropic's latest model silently degrades its IQ Researchers Are Furious Over Anthropic's Hidden AI Limits Anthropic Walks Back Policy That Could Have ‘Sabotaged’ AI Researchers Anthropic: Claude Fable 5 and Claude Mythos 5 System Card: Claude Fable 5 & Claude Mythos 5 Socket: Mini Shai-Hulud, Miasma, and Hades Worms Dario Amodei: Policy on the AI Exponential Patch Tuesday (Adobe/Microsoft) WhatsApp catches NSO Group spear phishing Department of War Publishes Third Release of Unidentified Anomalous Phenomena Files Pentagon releases 3rd batch of UFO files, detailing mysterious orb sightings Orbs over a pond (UFO video) fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet Penquin's Moonlit Maze LABScon Call for Papers

(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay in cybersecurity. Plus, more on Anthropic's Mythos rollout and the thinly sourced Anthropic-NSA reports, the Fast16 sabotage of physics calculations, what researchers choose not to publish, Microsoft's bad Black Hat email, and Costin's Friday UFO files. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - JAGS at InfoSecurity Europe 3:40 - Sponsor: TLPBLACK 5:54 - A roadmap for security after the AI revolution 11:01 - Stripe Atlas and how easy it is to start a company 15:00 - If anyone could reverse engineer anything for $5 19:49 - Layoffs at Google's Threat Intelligence Group 21:06 - The death of reading the report 27:53 - Pitting the AI models against each other 32:07 - Grok, local models, and the DGX Spark 39:27 - Where is Google DeepMind? 45:29 - Will the frontier labs stay in cybersecurity? 52:41 - Mythos, Project Glasswing, and the NSA deal 1:16:33 - FAST16, Stuxnet, and sabotaging Iran's bomb 1:57:52 - Microsoft, Black Hat, and the chilling effect 2:14:14 - Shout-outs, UFO files, and 100 episodes Links:Transcript NSA using Anthropic's Mythos despite blacklist Anthropic: Mapping a year’s worth of AI-enabled cyber threats LLM ATT&CK Navigator (Anthropic) Ruben Santamarta on Fast16 sabotage malware A Fanny Equation: “I am your father, Stuxnet” TLPBLACK LABScon Call for Papers Disclosure Day | Official Teaser Disclosure Day