Three Buddy Problem

Legal corruption, React2Shell exploitation, dual-use AI risks


Listen Later

(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.)

Three Buddy Problem - Episode 76: On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.

Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.

Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Links:

  • Transcript (unedited, AI-generated)
  • ThreatLocker : A security platform that prevents ransomware
  • The Anatomy of a React2Shell Compromise (TLPBLACK)
  • CVE-2025-55182 Analysis Report (GreyNoise)
  • Exploitation of Critical Vulnerability in React Server Components
  • PeerBlight Linux Backdoor Exploits React2Shell (Huntress)
  • Patch Tuesday round-up (ZDI)
  • How Two Hackers Went From Cisco Academy to Cisco CVEs
  • Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’
  • OpenAI on dual-use AI risks
  • Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite
  • DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups
  • Microsoft paying bounties for vulns in third-party code
  • Cybersecurity 2026 Predictions (SentinelLABS)
  • Dakota Cary is in the "anti-China Chorus"
  • Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing
  • Automated React2Shell vulnerability patching is now available - Vercel
  • Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research
...more
View all episodesView all episodes
Download on the App Store

Three Buddy ProblemBy Security Conversations

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

61 ratings


More shows like Three Buddy Problem

View all
Hacked by Hacked

Hacked

185 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

370 Listeners

Risky Business by Patrick Gray

Risky Business

371 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

649 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

320 Listeners

Click Here by Recorded Future News

Click Here

422 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,086 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

178 Listeners

Hacking Humans by N2K Networks

Hacking Humans

316 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

186 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

389 Listeners