
Three Buddy Problem Palo Alto and the uncomfortable politics of APT attribution
18 snips
Feb 13, 2026 They unpack drone incursions over El Paso and whether cartels, anti‑drone tests, or hybrid warfare are to blame. They cover the Notepad++ supply chain fallout and new IOCs. They discuss Microsoft’s streak of exploited zero‑days and AI‑expanded attack surfaces. They dig into Apple’s zero‑click iOS exploits, Europe’s turn toward offensive cyber, and the politics around attributing major hacks.
AI Snips
Chapters
Books
Transcript
Episode notes
Drones Create Ambiguous Threat Narratives
- Drone incidents blur lines between criminal smuggling and state-level testing, creating confusing public narratives.
- Authorities need clearer communication when airspace closures or experimental defenses are involved.
SUO5: Golang Proxy Used By Red Teams And APTs
- Costin described SUO5, a Golang reverse-proxy tool popular with red teams and some APTs.
- He traced its author alias (Zima1) and emphasized its use for stealthy tunneling.
Kernel Flaws Linger Due To Reboot Practices
- Kernel exploits persist longer because operators delay reboots after patching.
- Live-patching can mitigate but many hosts lack it, extending attackers' windows.

