The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).

Security Conversations
Claim This Podcastby Security Conversations
Podcast Authority
Beta
Podcast Overview
The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers. Connect with Ryan on Twitter (Open DMs).
Language
🇺🇲
Publishing Since
12/6/2017
Unlock The Full Podcast Authority Score Report
See how your podcast performs across key metrics
Podcast Authority
Beta
Recommendations available
Unlock the full report to see detailed tips
Recommendations available
Unlock the full report to see detailed tips
Unlock comprehensive insights including:
- • YouTube presence analysis
- • Social media reach metrics
- • RSS compliance scoring
- • Podcast 2.0 features
- • Technical standards
Detailed Analytics
- Complete breakdown of all 19 authority metrics
- Personalized recommendations for each metric
- Industry benchmarks and comparisons
- Technical RSS feed analysis and compliance scoring
Growth Strategies
- Step-by-step action plans for improvement
- Quick wins to boost your score immediately
- Pro tips from successful podcasters
See how your show performs across every key metric
High authority scores make your podcast more attractive to industry leaders and influencers who want to appear on credible shows.
Sponsors look for podcasts with proven authority and engagement. Your score demonstrates your podcast's value to potential partners.
Understanding your strengths and weaknesses helps you make data-driven decisions to expand your listener base effectively.
1 verified contact email on file for Security Conversations
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

July 31, 2026
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats
<p>(Presented by <a href="https://canary.tools" rel="nofollow noopener">Thinkst Canary</a>: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)</p> <p><strong>Three Buddy Problem - Episode 107</strong>: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. </p> <p>Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills.</p> <p><strong>Cast:</strong> <a href="https://www.linkedin.com/in/greglesnewich/" rel="nofollow noopener">Greg Lesnewich</a>, <a href="https://twitter.com/juanandres_gs" rel="nofollow noopener">Juan Andres Guerrero-Saade</a>, <a href="https://twitter.com/ryanaraine" rel="nofollow noopener">Ryan Naraine</a> and <a href="https://twitter.com/craiu" rel="nofollow noopener">Costin Raiu</a>.</p> <p><strong>Timestamps:</strong><br> 0:00 Sponsor - Thinkst Canary<br> 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team<br> 5:23 Inside the NSA ‘Laundry Bear’ advisory<br> 7:15 What does "half-click" mean?<br> 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence<br> 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress<br> 17:05 Targeting Ukraine, US universities, and magnetic fusion research<br> 19:34 How threat hunters actually build intuition<br> 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table<br> 54:48 The dopamine hit of a real find and the deleted "never mind" messages<br> 1:00:42 Magnets of threats: under 1% of customers ever see an APT<br> 1:25:21 Getting detections into the product, and coordinating a release with NSA<br> 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox<br> 2:17:45 The case for killing the CFAA and bricking vulnerable devices<br> 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/1WrQgBfyDlsuCtHDFxt-Ennx59iPuNtfLnEsncQoejAk/edit?tab=t.0">Transcript </a></li><li><a title="Greg Lesnewich | LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/greglesnewich/">Greg Lesnewich | LinkedIn </a></li><li><a title="Proofpoint: TA488 Comes for Outlook with Another Half-Click Exploit" rel="nofollow" href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit">Proofpoint: TA488 Comes for Outlook with Another Half-Click Exploit </a></li><li><a title="TA488 Targets Zimbra Mailservers with Half-Click Exploits" rel="nofollow" href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits">TA488 Targets Zimbra Mailservers with Half-Click Exploits </a></li><li><a title="NSA: Russian APT Phishing Users of Zimbra" rel="nofollow" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">NSA: Russian APT Phishing Users of Zimbra </a></li><li><a title="Operation RoundPress Half-Click Webmail Zero-Days from TA458" rel="nofollow" href="https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits">Operation RoundPress Half-Click Webmail Zero-Days from TA458 </a></li><li><a title="Operation RoundPress targeting high-value webmail servers" rel="nofollow" href="https://www.welivesecurity.com/en/eset-research/operation-roundpress/">Operation RoundPress targeting high-value webmail servers </a></li><li><a title="Anthropic: Investigating three real-world incidents in our cybersecurity evaluations" rel="nofollow" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic: Investigating three real-world incidents in our cybersecurity evaluations </a></li><li><a title="Hugging Face: A Technical Timeline of OpenAI incident" rel="nofollow" href="https://huggingface.co/blog/agent-intrusion-technical-timeline">Hugging Face: A Technical Timeline of OpenAI incident </a></li><li><a title="Microsoft Intros MAI-Cyber-1-Flash inside MDASH" rel="nofollow" href="https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/">Microsoft Intros MAI-Cyber-1-Flash inside MDASH </a></li><li><a title="Google Updates Threat Actor Naming System" rel="nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/">Google Updates Threat Actor Naming System </a></li><li><a title="Bill Marczak: An Angry Spark, or a Triangle in Disguise?" rel="nofollow" href="https://medium.com/@billmarczak/an-angry-spark-or-a-triangle-in-disguise-ac32852a1be3">Bill Marczak: An Angry Spark, or a Triangle in Disguise? </a></li><li><a title="Gen: Chasing an Angry Spark" rel="nofollow" href="https://www.gendigital.com/blog/insights/research/chasing-an-angry-spark">Gen: Chasing an Angry Spark </a></li><li><a title="Amazon identifies North Korean hacker group behind open-source supply chain attacks" rel="nofollow" href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/">Amazon identifies North Korean hacker group behind open-source supply chain attacks </a></li><li><a title="Dana (Donella) Meadows Lecture: Sustainable Systems" rel="nofollow" href="https://www.youtube.com/watch?v=hhSpzQhvFS8">Dana (Donella) Meadows Lecture: Sustainable Systems </a></li><li><a title="Outliers - Malcolm Gladwell" rel="nofollow" href="https://en.wikipedia.org/wiki/Outliers_(book)">Outliers - Malcolm Gladwell </a></li><li><a title="5-Year Data Hack Disclosed by SMS Giant Syniverse" rel="nofollow" href="https://commsrisk.com/5-year-data-hack-disclosed-by-sms-giant-syniverse/">5-Year Data Hack Disclosed by SMS Giant Syniverse </a></li><li><a title="Practical Malware Analysis book" rel="nofollow" href="https://nostarch.com/malware">Practical Malware Analysis book </a></li><li><a title="Top 1 Million Websites" rel="nofollow" href="https://top1m.org/">Top 1 Million Websites </a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/">Thinkst Canary </a></li></ul>

July 28, 2026
Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise
<p><strong>Security Conversations</strong>: Kenneth Kinion, founder and CEO of Validin, joins Ryan Naraine on the show to unpack what "internet intelligence" really means for the analysts and responders chasing malicious infrastructure.</p> <p>We trace his path from Georgia Tech through Microsoft and Amazon to the frustrations that led to the creation of Validin, the competition from big AI, the value of AI-powered tools to speed up infrastructure hunting, and why defenders keep falling further behind fast-moving attackers.</p> <p><strong>Timestamps:</strong> <br> 0:00 – Intro: What does Validin do?<br> 0:51 – Who uses Validin: CTI teams, SOCs, incident responders<br> 2:19 – Atlanta and Georgia Tech's cybersecurity pipeline <br> 5:31 – Lessons from Microsoft and Amazon: waterfall vs. agile<br> 8:29 – Filling gaps in passive DNS data<br> 9:57 – Misunderstood things about threat intelligence<br> 14:17 – The value of "cyber paleontology"<br> 16:00 – What makes one data set better than another?<br> 19:39 – How Validin works: from one suspicious domain to a full pivot<br> 21:27 – AI as existential threat or force multiplier for Validin<br> 26:55 – Dual-use AI: are defenders losing ground to attackers?<br> 31:11 – Closing: the next hard problem Validin wants to solve</p><p>Links:</p><ul><li><a title="Transcript" rel="nofollow" href="https://docs.google.com/document/d/1rxpkHu2c1BwAkw0XFpfA5RDgcf6Za0Fzq8UPE8w_SKE/edit?tab=t.0">Transcript </a></li><li><a title="Kenneth Kinion | LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/kinion/">Kenneth Kinion | LinkedIn </a></li><li><a title="Validin (Threat Hunting, DNS Enrichment)" rel="nofollow" href="https://www.validin.com/">Validin (Threat Hunting, DNS Enrichment) </a></li><li><a title="Advanced Search & YARA Improvements | Validin" rel="nofollow" href="https://www.validin.com/blog/advanced_search_yara_improvements/">Advanced Search & YARA Improvements | Validin </a></li><li><a title="Contagious Interview: DPRK Threat Actors Reveal Plans" rel="nofollow" href="https://www.sentinelone.com/labs/contagious-interview-threat-actors-scout-cyber-intel-platforms-reveal-plans-and-ops/">Contagious Interview: DPRK Threat Actors Reveal Plans </a></li><li><a title="LABScon 2026" rel="nofollow" href="https://www.labscon.io/">LABScon 2026 </a></li></ul>

July 23, 2026
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16
Juan Andres Guerrero-Saade and Ryan Naraine interview Costin Raiu about OpenAI's models breaching Hugging Face, reward hacking ethics, and the fast16 benchmark.
235 total episodes available with 120 transcripts
Recent guests on Security Conversations
Guests from recent episodes — sign up to see every guest that has ever appeared on this show.
Katie Moussouris
Guest
Aaron Portnoy
Guest
Perri Adams
Guest
Gabriel Bernadett-Shapiro
Guest
Federico Kirschbaum
Guest
Jordan Wiens
Guest
Matthias Frielingsdorf
Guest
Greg Linares
Guest
Similar Podcasts
Discover related shows you might enjoy

Risky Business News
Risky Business Media

Risky Business
Risky Business Media

Risky Business Features
Risky Business Media

Geopolitics Decanted by Silverado
Silverado Policy Accelerator

Click Here
Recorded Future News

CyberWire Daily
N2K Networks

Darknet Diaries
Jack Rhysider

The Pragmatic Engineer Podcast
Gergely Orosz

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich

Machine Learning Street Talk (MLST)
Machine Learning Street Talk (MLST)

Oxide and Friends
Oxide Computer Company

In Machines We Trust
MIT Technology Review

Prof G Markets
Vox Media Podcast Network

Smashing Security
Graham Cluley

Black Hills Information Security
Black Hills Information Security
Deep-dive analytics for Security Conversations
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Security Conversations?
- How often does this podcast release new episodes?
This podcast updates daily.
- Where can I listen to this podcast?
This podcast is available on 10 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.