Three Buddy Problem

OpenAI’s Dave Aitel talks Aardvark, economics of bug-hunting with LLMs


Listen Later

Three Buddy Problem - Episode 70: Dave Aitel from OpenAI's technical staff joins the buddies to discuss the just-launched Aardvark, OpenAI’s agentic “security researcher” that claims to read code, finds bugs, validates exploits, and ships patches. We press him on where LLMs beat fuzzers, privacy boundaries, human-in-the-loop realities, SDLC budgets, pen-test cadence, and the zero-day economy.

Plus, L3 Harris/Trenchant exec pleads guilty to selling exploits to Russian brokers, Kaspersky catches the return of HackingTeam using Chrome zero-day exploit chain, and news of a proposed law in Russia to force researchers to report vulnerabilities first to goverment agencies.

Cast: Dave Aitel (Technical Staff, OpenAI), Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Links:

  • Transcript (unedited, AI-generated)
  • Episode 70 Livestream - YouTube
  • Aardvark: OpenAI’s agentic security researcher
  • TBP episode on OpenAI’s Aardvark
  • How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation
  • Ex-US cyber intel exec pleads guilty to selling spy tools to Russian broker
  • Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm
  • Kim Zetter: Former Trenchant Exec Sold Stolen Code to Russian Buyer Even After Learning that Other Code He Sold Was Being "Utilized" by Different Broker in South Korea
  • How we linked ForumTroll APT to Dante spyware by Memento Labs
  • CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware
  • Russia's new vuln disclosure law proposal
  • TBP Live in Ottawa
  • Binding Hook Live
  • State of Statecraft
  • Ekoparty Miami
...more
View all episodesView all episodes
Download on the App Store

Three Buddy ProblemBy Security Conversations

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

61 ratings


More shows like Three Buddy Problem

View all
Hacked by Hacked

Hacked

187 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Patrick Gray

Risky Business

376 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,020 Listeners

Smashing Security by Graham Cluley

Smashing Security

320 Listeners

Click Here by Recorded Future News

Click Here

416 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,016 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

177 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

136 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

46 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

314 Listeners