Three Buddy Problem
Three Buddy Problem
Three Buddy Problem·Jul 31, 2026·3h 26m

Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats

Show notes

(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)

Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies.

Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills.

Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Timestamps:
0:00 Sponsor - Thinkst Canary
1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team
5:23 Inside the NSA ‘Laundry Bear’ advisory
7:15 What does "half-click" mean?
9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence
12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress
17:05 Targeting Ukraine, US universities, and magnetic fusion research
19:34 How threat hunters actually build intuition
32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table
54:48 The dopamine hit of a real find and the deleted "never mind" messages
1:00:42 Magnets of threats: under 1% of customers ever see an APT
1:25:21 Getting detections into the product, and coordinating a release with NSA
1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox
2:17:45 The case for killing the CFAA and bricking vulnerable devices
2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

Links: