Three Buddy Problem
(Presented by TLPBLACK [https://tlpblack.net]: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 97: We discuss the disappearing art of Windows APT paleontology, the absence of complex malware documentation, and why so much threat-intel research has slipped behind paywalls and into private rooms. Plus, a surge in AI-discovered bugs in Firefox and Chrome, a rough week for Linux security flaw disclosures, and the usual Ivanti and Palo Alto zero-day bulletins that ship without a single IOC. Cast: Juan Andres Guerrero-Saade [https://twitter.com/juanandres_gs], Ryan Naraine [https://twitter.com/ryanaraine] and Costin Raiu [https://twitter.com/craiu]. Timestamps: 0:00 - Introductory banter 1:17 - Inside TLP-Red: writing hashes by hand 3:57- fast16 fallout and the threat intel trust collapse 9:17 - The death of cyber paleontology on Windows 14:49 - Mobile is the new paleontology frontier 15:48 - When threat intel went private: the CrowdStrike effect 23:29 - Falling sideways into intelligence brokerage 36:05 -- AI, Easter eggs, and the loss of malware artistry 47:22 -- Will the Frontier Labs publish threat intel? 51:43 -- fast16 follow-up reports coming 1:09:38 - Mythos, Aardvark, and the patch tsunami 1:15:33 - CopyFail and the Linux reboot crisis 1:51:05 - UAPs, Pulitzers, last-ever LabsCon, and shoutouts Links: * Transcript [https://docs.google.com/document/d/1XD-WeRNLra07UXmgRpBaiGNFo0PPiSkw3PntcdnMdI8/edit?tab=t.0] * Where Have All the Complex Windows Malware and Their Analyses Gone? [https://r136a1.dev/2026/05/07/where-have-all-the-complex-malware-and-their-analyses-gone/] * AcidBox: Rare Malware Repurposing Turla Group Exploit [https://unit42.paloaltonetworks.com/acidbox-rare-malware/] * Google Chrome security update documentation [https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html] * Behind the Scenes Hardening Firefox with Mythos [https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/] * CVE-2026-0073 Android adbd TLS client-authentication bypass [https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/] * Urgent patch for Android zero-click vuln [https://source.android.com/docs/security/bulletin/2026/2026-05-01] * CVE-2026-0300: PAN-OS zero-day exploited in the wild [https://security.paloaltonetworks.com/CVE-2026-0300] * Ivanti zero-day marked as exploited in the wild [https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US] * Copy Fail — CVE-2026-31431 [https://copy.fail/] * Yael Grauer wins a Pulitzer Prize [https://www.ap.org/media-center/press-releases/2026/ap-wins-pulitzer-prize-for-china-surveillance-reporting/] * AJ Vicens wins a Pulitzer Prize [https://www.reuters.com/investigations/charlie-kirk-purge-how-600-americans-were-punished-pro-trump-crackdown-2025-11-19/] * Pacific Rim – Darknet Diaries [https://darknetdiaries.com/episode/174/] * Fast16, Stuxnet, and the History of Cyber Espionage [https://www.youtube.com/watch?v=Nemom0_vCYU] * TLPBLACK [https://tlpblack.net/] * LABScon 2026 CFP [https://www.cvent.com/c/abstracts/0f2ae039-4175-42c2-a534-7f25ada9e539] * US Gov on UAP Encounters [https://www.war.gov/ufo/]
220 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Three Buddy Problem!