(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.)
Three Buddy Problem - Episode 91: This week we dig into Google's new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines.
Plus, VCs and the breathless AI hype, Apple's iOS 26.4 and silent patches, the FCC's ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
0:00 Intro & Pre-Show Banter
3:08 JAGS in San Francisco: RSAC week recap
6:05 Google Launches Cyber Disruption Unit — What's Actually New?
13:43 Why Separate Disruption Units Matter: ROI & Budget Justification
29:11 Haroon Meer's RSA Reality Check: The AI Hype Machine
32:37 The VC Ponzi Cycle & How Easy Money Hollowed Out Cybersecurity
47:32 ENT.ai & Tenex AI Hackathon at RSAC
53:08 Kaspersky Links Corona Exploit Kit to Operation Triangulation
1:08:09 Trenchant Cleanup & Lessons from Equation Group Burns
1:19:31 Apple iOS Patches, Hong Kong Device Passcode Law
1:27:53 Handala Hacks FBI Director Kash Patel's Personal Gmail
1:37:32 LeakBase Admin "Chucky" Arrested in Russia — FSB Gets the Data
1:45:38 Supply Chain Attacks: TeamPCP Hits LiteLLM & Trivy
2:04:34 FCC Bans Foreign-Made Routers — But What Do We Buy?
Links:
- Transcript
- TLPBLACK Solutions
- Google launches threat disruption unit at RSAC
- White House downplays cyber ‘letters of marque’ speculation
- Haroon Meer on RSAC 2026
- Kaspersky on Coruna/Triangulation Connection
- Apple Security Bulletin - iOS 26.4
- Reverse engineering Apple’s silent security fixes
- New Hong Kong Law on Phone/Laptop Passwords
- Iran-linked hackers breach FBI director's personal email
- US DOJ Disrupts Iranian Cyber Enabled Psychological Operations
- Official Statement on Stryker Network Disruption
- Russia arrests Leakbase admin
- Trivy ecosystem supply chain compromised (Advisory)
- Self-propagating malware poisons open source software and wipes Iran-based machines
- New Malware Targets Users of Cobra DocGuard Software
- FCC bans 'foreign made' consumer routers (PDF)