Three Buddy Problem
Three Buddy Problem

What's behind US gov push to 'privatize' cyber operations?

20 December 2025 2:01:57 Security Conversations

Listen to episode

About this episode

(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.)

Three Buddy Problem - Episode 77: New React2Shell data from Microsoft, fresh Apple and Cisco zero-days already in the wild, and state-linked campaigns from Russia and China that show a merging of espionage, crime, and infrastructure disruption.

Plus, the US government's push to enlist private firms in offensive hacking, letters of marque for cartels, new discovery of spyware used against journalists in Belarus, and Amazon catching North Koreans via keystroke latency.

Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Links:

  • ThreatLocker Solutions
  • Transcript (unedited, AI-generated)
  • Trump Admin Turning to Private Firms in Cyber Offensive
  • Microsoft on React2Shell
  • React2Shell and OpenAI (shoutout Andrew MacPherson)
  • Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw
  • iOS 26.2 Security Patches
  • Reporters Without Borders uncovers new spyware from Belarus
  • Cisco Talos on Cisco 0day attacks
  • Hack of Chinese state time center hints at U.S. advanced missile defense
  • Amazon on Russian APT targeting Western critical infrastructure
  • North Korean infiltrator caught in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location
  • Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs
  • Russian defense firms targeted by hackers using AI
  • TLPBLACK looks back at 2025
  • Inside Google's basement in Malaga: ChatGPT of Cybersecurity
  • GitHub - xdanx/open-klara: Open KLara Project
  • Gepetto Web

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 Three Buddy Problem. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.