Three Buddy Problem

Mark Dowd on AI hacking, exploit chains, zero-day sales


Listen Later

(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)

Three Buddy Problem - Episode 95: Vigilant Labs director Mark Dowd joins the show to shed light on the state of offensive research, the economics of the exploit market, and why "Mark Dowd in a box" isn't quite the threat the AI hype machine suggests. He talks through the daily stresses of running an offensive shop, how AI is reshaping vulnerability discovery, exploit development, and the pricing of full exploit chains.

Plus, thoughts on Lockdown Mode and Apple's MIE, whether mitigations actually work or just push attackers toward less access, the rise of HarmonyOS and the Balkanization of device security, persistence, baseband attacks, GrapheneOS, and Samsung Knox.

We discuss customer vetting and OpSec fears, policymakers who've never written an exploit, and the strange afterlife of The Art of Software Security Assessment, the 20-year-old book now possibly training data for the very tools coming for his job.

Cast: Mark Dowd, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Timestamps:

0:00 Introductions
4:28 The origin story of Azimuth: why go offensive?
6:26 Stresses of running an offensive research business
12:10 "Mark Dowd in a box" — is AI an existential threat to vuln research?
16:13 Using AI in workflow: frontier models vs. local models
22:05 AI in bug-finding vs. exploit implementation
30:30 Watching AI tear through a firmware backdoor
38:23 Artificial guardrails and the "POC" wall
43:25 Will AI commoditize 0days? The high-end vs. low-end vendor split
57:30 How AI disrupts exploit chain pricing
1:05:18 Does persistence still matter? Should you reboot your phone?
1:09:33 Lockdown Mode, MIE, and Apple's "never been compromised" claim
1:14:25 Do mitigations really work, or are we stuck in an endless loop?
1:23:25 Android vs. iOS vs. Huawei's HarmonyOS Next
1:34:44 Exploit leaks, customer vetting, and OpSec fears
1:41:37 GrapheneOS, Samsung Knox and baseband attacks
1:53:56 Did the exploit market save us from encryption backdoors?
1:55:11 What does the threat-intel community get wrong about vuln research?

Links:

  • Transcript
  • Vigilant Labs
  • Mark Dowd at BlueHat: Inside the Zero Day Market
  • The Art of Software Security Assessment [Book]
  • Mark Dowd on X
  • Trenchant, Peter Williams, and the proliferation of a Shadow Brokers-level iOS exploit framework
  • Apple: Memory Integrity Enforcement
  • Cost of Sandboxing Prompts Shift to Memory-Safe Languages
  • Dowd: Memory Corruption Mitigations Doing Their Job
  • TLPBLACK
  • LABScon 2026 Call for Papers
  • Apple paying big bounty for wireless proximity-based attacks
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Three Buddy ProblemBy Security Conversations

    • 4.9
    • 4.9
    • 4.9
    • 4.9
    • 4.9

    4.9

    61 ratings


    More shows like Three Buddy Problem

    View all
    Hacked by Hacked

    Hacked

    188 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    369 Listeners

    Risky Business by Risky Business Media

    Risky Business

    376 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    648 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,030 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    316 Listeners

    Click Here by Recorded Future News

    Click Here

    421 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,059 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    178 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    313 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    192 Listeners

    Defense in Depth by CISO Series

    Defense in Depth

    73 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    136 Listeners

    Risky Bulletin by Risky Business Media

    Risky Bulletin

    45 Listeners

    The 404 Media Podcast by 404 Media

    The 404 Media Podcast

    392 Listeners