Three Buddy Problem

GitLab doxxes North Korea .gov hackers; fresh Ivanti zero-days; AI addiction and human purpose

25 snips
Feb 20, 2026
An explosive dive into a North Korean operation using fake IT worker personas and large-scale synthetic identity pipelines. A rundown of fresh Ivanti and Dell zero-days actively exploited in the wild. Discussion of Apple restoring shutdown logs and how AI coding agents are reshaping skills, workflow and meaning for security practitioners.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Access To Code Is A Strategic Threat

  • Compromised contractors gaining access to private codebases can introduce zero-days or sabotage at scale.
  • Contagious Interview cells accessed dozens of private repos and tens of thousands of outbound leads.
ADVICE

Build A Synapse For Hiring Threat Intelligence

  • Ingest threat IOCs into a central platform and connect recruitment systems via API to correlate candidates with threat data.
  • Use enrichment and shared knowledge bases so IR and hiring teams can pivot on names, emails, and phone numbers.
INSIGHT

MDM Zero-Days Are Extremely Dangerous

  • Exploited Ivanti zero-days show how high-impact vulnerabilities in management infrastructure enable broad compromise.
  • Such vulnerabilities are often observed in attacks linked to nation-state actors but can also be used by criminals.
Get the Snipd Podcast app to discover more snips from this episode
Get the app