174 episodes
- On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including:
Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny
The bugpocalypse is so chaotic, Microsoft can’t patch fast enough
A ColdCard wallet flaw led to millions in Bitcoin theft, but the back story behind the bug is bonkers
Iran hacks and disrupts water infrastructure in multiple American states
North Korea’s state-backed hackers turn criminal. Or their criminals turn into state-backed hackers. Or something. It’s all a bit confusing, actually.
Much, much more!
This week’s show is brought to you by Sondera. Co-founder Josh Devon joins Patrick and James to talk through some absolutely hilarious LLM horror stories.
This episode is also available on YouTube
Show notes
OpenAI says rogue agent behind Hugging Face hack broke into additional services | therecord.media
Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests | wired.com
Claude uploaded malware to PyPI in Anthropic's botched test | BleepingComputer
Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal | wired.com
Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets Truffle Security Co. |
Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling to Fix Them Fast Enough. | Social Signals
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting | wired.com
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI | TechCrunch Security
Mythos uncovers crypto weaknesses that went unknown for years | arstechnica.com
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft | BleepingComputer
Chris Masterjohn (@ChrisMasterjohn) on X | X (formerly Twitter)
wale.moca 🐳 (@waleswoosh) on X | X (formerly Twitter)
U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities | washingtonpost.com
FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems | washingtonpost.com
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world | cyberscoop.com
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran | wired.com
Russia accuses Telegram founder of aiding terrorism, seeks international arrest | The Record
Laundry Bear’s webmail hackers had more in store after February, report says | therecord.media
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Phishing service spoofs RingCentral to steal Microsoft 365 accounts | BleepingComputer
North Korean hackers behind major open-source supply chain attacks, Amazon says | therecord.media
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn | The Record
North Korea arrests hackers accused of laundering stolen bank funds through crypto |
US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security | TechCrunch Security
Judge says Trump admin still lacks evidence for Anthropic 'supply chain risk' label | TechCrunch
Cyber Command plans Silicon Valley office to drive innovation | therecord.media
Apple is getting this wrong | OpenAI
Tech industry alliance proposes AI agent safety reporting program | Cybersecurity Dive
Massive ChainDrop npm supply-chain attack infects hundreds of packages | BleepingComputer
Massive supply-chain attack compromises 440 packages under four hours | cyberscoop.com - On this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
Everyone signs the open weights open letter, except Anthropic… of course.
OpenAI had no idea it had hacked Hugging Face
Kimi K3 open weights released and they’re massive!
Why a more aggressive response is needed to cyber attacks on OT
And much, much more!
This week’s show is brought to you by SpecterOps. In this week’s sponsor interview Justin Kohler and Jared Atkinson talk about how SpecterOps’ Bloodhound now supports AWS attack paths. Run it against your AWS infra, but only if you have a strong stomach. The results will terrify you.
This episode is also available on YouTube.
Show notes
Open Weights and American AI Leadership | Social Signals
Our position on open-weights models | Social Signals
Halvar Flake (@halvarflake) on X | X (formerly Twitter)
White House accuses Chinese company of distilling Anthropic’s Fable | cyberscoop.com
Jensen Huang (@JensenHuang) on X | X (formerly Twitter)
Its AI Agent Spent Days Hacking a Company, but Sources Say OpenAI Did Not Notice for a Week | reuters.com
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face | TechCrunch Security
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack | TechCrunch Security
Sens. Banks and Schiff Introduce Bill to Help American AI Companies Combat Chinese Espionage |
AI Kill Switch Act would let Trump admin order shutdown of rogue AI systems | Ars Technica
Marco Rubio tells diplomats to play down talk of American tech "kill switch" | reuters.com
Federal agencies broaden alert on Iran-linked OT attacks | therecord.media
Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities | CyberScoop
NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign | nsa.gov
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts | BleepingComputer
Microsoft responds to LG monitors installing McAfee ads on Windows | Ars Technica
LG to Ban Residential Proxies from Smart TV Apps | krebsonsecurity.com
Despite multiple takedowns, botnets continue to grow | cyberscoop.com
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill | therecord.media
Upbound says hack caused $13 million in fraudulent Acima leases | BleepingComputer
Fake Claude app promoted by Bing ads pushes SectopRAT malware | BleepingComputer
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin | BleepingComputer
Clop ransomware targets Windchill, FlexPLM in data theft attacks | BleepingComputer
'Wrench' attacks against crypto holders appear to be on the rise | therecord.media
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face | wired.com - On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
US and China trade AI model ban threats
Iran has been using SS7 queries to locate and target US troops
Scattered Spider is having a hard time, not just because of Microsoft’s GDID
And much, much more!
This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.
This episode is also available on YouTube.
Show notes
OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com
Security incident disclosure — July 2026 | Social Signals
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security
Cheating behaviour in frontier model evaluations | AISI Work | Social Signals
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals
Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica
EXCLUSIVE: Beijing is looking at curbing overseas access to China's top AI models, sources say | reuters.com
https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi |
Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com
Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security
Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com
Trump calls for new election security measures | NBC News Tech
Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media
Alleged longstanding member of Scattered Spider extradited to US | CyberScoop
https://www.justice.gov/usao-ndil/media/1450651/dl?inline |
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com
764 splinter group leader sentenced to 40 years in jail | cyberscoop.com
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | cyberscoop.com
Attackers vote themselves $20 million in BONK cryptocurrency | The Record
CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer
Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch Security
Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer
IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com
Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI | TechCrunch Security
Pegasus Spyware European Parliament Pega Committee Member | The Record
Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security
Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media | Social Signals
Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer
On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security - In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection.
Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections.
This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you’re going to build a good graph, do you want to build it for a person to use, or an agent to use?
This is truly a conversation for the security nerd’s nerd. Enjoy!
This episode is also available on YouTube
Show notes - On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail
Distillation, cheap tokens, and AI chat harvesting is an industry in China
Edge becomes a lolbin via a new malicious extension
An Iranian APT boss’s vacation in a beautiful place goes wrong
Much, much more!
In this week’s sponsor interview Daf Stuttard and Katie Warren from Portswigger pop along to talk about how they built an AI security testing product that people would actually feel comfortable using.
This episode is also available on YouTube.
Show notes
Anthropic (@AnthropicAI) on X | X (formerly Twitter)
Howard Lutnick (@howardlutnick) on X | X (formerly Twitter)
U.S. government gives Anthropic green light for limited re-release of Mythos 5 | NBC News Tech
OpenAI limits GPT-5.6 rollout after government request | TechCrunch
The U.S. government will decide who gets to use the latest American AI technology | washingtonpost.com
Anthropic says Alibaba illicitly extracted Claude AI model capabilities | reut.rs
How to Buy Cheap Claude Tokens in China |
Alex Stamos (@alexstamos) on X | X (formerly Twitter)
Synthesis of Exploitarium Mass Zero-Day Disclosure | detections.ai
Mythos on your desk? Using local LLMs for code reviews | Risky Business Media
Beyond Fable: Can a Local LLM Replace Cloud AI for Security Code Reviews | Security Research Labs
Accelerating EDR Evasion with LLM-Driven Analysis | SpecterOps
CISA: Windows BlueHammer flaw now exploited by ransomware gangs | BleepingComputer
When cybercriminals hire burglars: Inside an alleged Russian effort to infiltrate multibillion-dollar US law firms | CNN Politics | Social Signals
Microsoft quietly extends free Windows 10 ESU support to October 2027 | BleepingComputer
Edgecution: Malicious Edge Extension Backdoor | ThreatLabz | Social Signals
Bluekit phishing kit adopts browser-in-the-middle for login theft | BleepingComputer
New macOS malware embeds fake errors to confuse AI analysis tools | BleepingComputer
DraftKings hacker 'Snoopy' sentenced to 18 months in prison | BleepingComputer
Polymarket says hackers stole users’ funds | TechCrunch Security
Australia's spy chief warns of rising terror and cyber threats | japantimes.co.jp
Russian hackers were behind $2.5 billion hack of Jaguar Land Rover: Report | TechCrunch Security
Iranian national sought by US on hacking charges arrested in Montenegro | apnews.com
[un]prompted.au - AI x CyberSecurity: Notes from the Field: Call for Speakers |
More News podcasts
Trending News podcasts
About Risky Business
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Podcast websiteListen to Risky Business, Today in Focus and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Risky Business
Scan code,
download the app,
start listening.
download the app,
start listening.
Risky Business: Podcasts in Family
























