
Three Buddy Problem Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware
Jan 23, 2026
They unpack claims that a malware framework may have been built by AI and what artifacts reveal about its creation. They debate whether AI lets low-cost actors produce advanced exploits and why verification and benchmarks matter. They cover a surge of noisy AI bug reports, new CISA YARA rules, a wiper used against Poland's grid, and risks around cloud keys and edge device compromises.
AI Snips
Chapters
Books
Transcript
Episode notes
LLMs Can Find Weaponizable Zero-Days Today
- LLMs are already effective at finding weaponizable vulnerabilities in code, not necessarily novel classes but usable zero-days.
- This capability lowers costs and increases frequency of exploitable bugs in the wild.
Assume Zero-Day Discovery Is Democratized
- Assume the industrialization of zero-day discovery is real and plan defenses accordingly.
- Treat unknown vulnerability discovery as an accessible capability and shift threat modeling and controls to match.
AI Slop Creates A Verification Crisis
- AI-produced low-quality 'slop' floods bug reporting channels, straining verification resources for open-source projects.
- The verification bottleneck is becoming the limiting factor, not report volume alone.



