178 episodes
- On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
Iranian hackers take down a small-scale power generator in the UK
Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
Prompt injection isn’t going away
LLMs are deceiving us meat sacks and it’s a worry
Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
This episode is also available on YouTube
Show notes
Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com
Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com
Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts
US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com
The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com
CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer
Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive
Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer
Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer
Rust supply chain attack linked to North Korean hackers | securityweek.com
Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com
New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com
Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer
Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer
Hackers infect Android car head units with proxy botnet malware | BleepingComputer
ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer
New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer
Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer
AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com
EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com
Detections and customer notifications | Okta Threat Intelligence - On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:
Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
Anthropic’s models start a turf war when given the same task, surprising… nobody
We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
Much, much more
This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.
This episode is also available on YouTube
Show notes
Trump signs memo authorizing private sector to launch cyberattacks | washingtonpost.com
Trump taps cyber firms to go on offensive against criminals | therecord.media
OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue | wired.com
Pacing model development in an era of cyber-critical capabilities |
Anthropic set AI agents loose on the same task. They started a turf war. | TechCrunch Security
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan | cyberscoop.com
Researchers find AI-powered hacking tools for sale in underground forums | Cybersecurity Dive
Terabytes of credentials leaked in massive supply-chain attack | arstechnica.com
Trivy, Not LiteLLM Behind the 2,500 Org Compromise | securityweek.com
Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes | The Record
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators | TechCrunch Security
This Coin-Sized Device Can Hack a Boeing 737 | wired.com
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals | BleepingComputer
Max severity SAP Commerce Cloud flaw now targeted in attacks | BleepingComputer
Shell investigates 'potential incident' after Clop data theft claims | BleepingComputer
Philips and GE investigating Clop ransomware data theft claims | BleepingComputer
Uber Freight reportedly investigating after hacking group claims data breach | TechCrunch Security
Details emerge on BlackFile’s recent attacks on financial companies | cyberscoop.com
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch Security
Kimwolf botnet rebuilt to survive takedowns, researchers say | cyberscoop.com
Hundreds of fake Chrome VPN extensions route traffic through a proxy | BleepingComputer
Deepfake hiccup unmasks suspected digital certificate fraudster | theregister.com
Vulnerability giving attackers full control of Macs is under active exploitation | arstechnica.com
Critical VMware vCenter RCE flaw exploited for reverse SSH access | BleepingComputer
Poland probes MyDr healthcare software breach potentially affecting 19 million people | therecord.media
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts | TechCrunch Security
[un]prompted.au — AI × Cybersecurity Conference · Sydney, 18–19 September 2026 | [un]prompted.au - In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.
Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.
Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.
Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.
This episode is also available on YouTube
Show notes - On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:
The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
It turns out TeamPCP has been around longer than we thought and predates the AI era
Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
Much, much more
This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.
This episode is also available on YouTube
Show notes
How a simple request for AI to book a gym class exposed a major threat | Social Signals
OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com
OpenAI BlackHat talk re Hugging Face incident |
OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop
Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media
Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate | therecord.media
Local governments in four states dealing with cyberattacks that have shut down services | The Record
Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska
Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record
State Department says Trump raised cyber scam compound issue with Xi | therecord.media
Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | wired.com
Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun - Risky Business Media |
Chrome adopts what may be the best protection yet against account takeovers | Ars Technica
CSS:the bomb inside your inbox | PortSwigger Research
Security update available for Metabase - Please upgrade now | Social Signals
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media
British ‘Com’ member who abused more than 100 girls worldwide jailed for two years | therecord.media
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | TechCrunch Security
AI is getting better at election facts, but voters shouldn’t rely on it | CyberScoop
The FTC wants to regulate AI for ideological bias | cyberscoop.com
US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer
N-able N-central exploitation results in RMM tool deployment | Sophos
Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security
mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub - On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including:
Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny
The bugpocalypse is so chaotic, Microsoft can’t patch fast enough
A ColdCard wallet flaw led to millions in Bitcoin theft, but the back story behind the bug is bonkers
Iran hacks and disrupts water infrastructure in multiple American states
North Korea’s state-backed hackers turn criminal. Or their criminals turn into state-backed hackers. Or something. It’s all a bit confusing, actually.
Much, much more!
This week’s show is brought to you by Sondera. Co-founder Josh Devon joins Patrick and James to talk through some absolutely hilarious LLM horror stories.
This episode is also available on YouTube
Show notes
OpenAI says rogue agent behind Hugging Face hack broke into additional services | therecord.media
Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests | wired.com
Claude uploaded malware to PyPI in Anthropic's botched test | BleepingComputer
Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal | wired.com
Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets Truffle Security Co. |
Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling to Fix Them Fast Enough. | Social Signals
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting | wired.com
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI | TechCrunch Security
Mythos uncovers crypto weaknesses that went unknown for years | arstechnica.com
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft | BleepingComputer
Chris Masterjohn (@ChrisMasterjohn) on X | X (formerly Twitter)
wale.moca 🐳 (@waleswoosh) on X | X (formerly Twitter)
U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities | washingtonpost.com
FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems | washingtonpost.com
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world | cyberscoop.com
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran | wired.com
Russia accuses Telegram founder of aiding terrorism, seeks international arrest | The Record
Laundry Bear’s webmail hackers had more in store after February, report says | therecord.media
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Phishing service spoofs RingCentral to steal Microsoft 365 accounts | BleepingComputer
North Korean hackers behind major open-source supply chain attacks, Amazon says | therecord.media
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn | The Record
North Korea arrests hackers accused of laundering stolen bank funds through crypto |
US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security | TechCrunch Security
Judge says Trump admin still lacks evidence for Anthropic 'supply chain risk' label | TechCrunch
Cyber Command plans Silicon Valley office to drive innovation | therecord.media
Apple is getting this wrong | OpenAI
Tech industry alliance proposes AI agent safety reporting program | Cybersecurity Dive
Massive ChainDrop npm supply-chain attack infects hundreds of packages | BleepingComputer
Massive supply-chain attack compromises 440 packages under four hours | cyberscoop.com
More News podcasts
Trending News podcasts
About Risky Business
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Podcast websiteListen to Risky Business, SMWX and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Risky Business
Scan code,
download the app,
start listening.
download the app,
start listening.
Risky Business: Podcasts in Family


































