Three Buddy Problem

Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware

Jan 23, 2026
They unpack claims that a malware framework may have been built by AI and what artifacts reveal about its creation. They debate whether AI lets low-cost actors produce advanced exploits and why verification and benchmarks matter. They cover a surge of noisy AI bug reports, new CISA YARA rules, a wiper used against Poland's grid, and risks around cloud keys and edge device compromises.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

LLMs Can Find Weaponizable Zero-Days Today

  • LLMs are already effective at finding weaponizable vulnerabilities in code, not necessarily novel classes but usable zero-days.
  • This capability lowers costs and increases frequency of exploitable bugs in the wild.
ADVICE

Assume Zero-Day Discovery Is Democratized

  • Assume the industrialization of zero-day discovery is real and plan defenses accordingly.
  • Treat unknown vulnerability discovery as an accessible capability and shift threat modeling and controls to match.
INSIGHT

AI Slop Creates A Verification Crisis

  • AI-produced low-quality 'slop' floods bug reporting channels, straining verification resources for open-source projects.
  • The verification bottleneck is becoming the limiting factor, not report volume alone.
Get the Snipd Podcast app to discover more snips from this episode
Get the app