182 episodes
- On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including:
More tech guys penned more open letters and AI will destroy us all!
Another Wednesday, another congregation of OpenAI agents on wikis… yawn
OpenAI agents were behind the headscratching RubyGems hacking campaign in May
The FBI will disrupt more adversary operations, NSA is creating more mission centres, lawmakers want sanctions on hackers-for-hire… Release more hounds!
So many platforms, so many bugs, so many patches breaking other stuff
Much, much more…
This week’s show is brought to you by Airlock Digital. Its co-founders Daniel Schell and David Cottingham join Patrick to talk about how Airlock has integrated itself with Crowdstrike via its Falcon Foundry platform.
This episode is also available on YouTube
Show notes
AI researcher says there is 'substantial probability' AI could kill all humans in next decade | NBC News Tech
Dario Amodei — We Must Pace the Frontier | Social Signals
China spy chief points at US AI models in cyber threat warning | therecord.media
Weixin Official Accounts Platform |
Trump calls concerns over A.I. destroying humanity a “hoax” | NBC News Tech
Dr_Gingerballs (@Dr_Gingerballs) on X | X (formerly Twitter)
Sam Altman backs Anthropic CEO's call to slow down the global AI race | NBC News
Anthropic: Detecting and countering misuse of AI, September 2026 | anthropic.com
AI lets small actors run state-level hacking campaigns, Anthropic report finds | cyberscoop.com
Users in Houthi-held Yemen tried to develop advanced weapons with AI, Anthropic says | apnews.com
Anthropic caught Russia-linked spies using Claude in hacking operations | therecord.media
OpenAI's rogue agents used at least 10 more sites for unauthorized comms, researchers say | reuters.com
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems | cyberscoop.com
Anthropic claims Moonshot, DeepSeek secretly diverted user requests to Claude | South China Morning Post
WeWorm | Social Signals
Hackers exploit Tencent app flaw to deploy GrayRabbit malware | BleepingComputer
New FBI cyber strategy promises increase in adversary disruptions | Cybersecurity Dive
US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy | therecord.media
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI | therecord.media
Lawmakers call on Treasury to sanction hackers-for-hire | cyberscoop.com
CISA: WatchGuard RCE flaw now exploited in ransomware attacks | BleepingComputer
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent | BleepingComputer
GitLab’s critical flaw is already drawing internet-wide probes | cyberscoop.com
Cisco warns customers of actively exploited zero-day in email gateways | cyberscoop.com
4 groups caught using the same Chrome and Windows exploit kit | Ars Technica
September Windows Server updates break Remote Desktop Services | BleepingComputer
Microsoft confirms KB5002914 Excel update breaks copy and paste | BleepingComputer
Microsoft: September updates break audio on some Windows PCs | BleepingComputer
ClickFix attacks infecting PCs and Macs are going viral | arstechnica.com
Passkey-themed phishing attacks lead to Microsoft 365 data theft | BleepingComputer - In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:
watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do?
XBOW: The AI pentesting company pitches its approach
CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView!
This episode is also available on YouTube.
Show notes - On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:
ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits
The US government plans to pay private contractors to conduct military hacks
The US accuses China of distillation attacks, a.k.a. forbidden training
It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki
Much, much more…
This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace.
This episode is also available on YouTube
Show notes
FBI Probes Service Selling 153M+ Drivers Licenses | Krebs on Security
IDScan sued over alleged data breach affecting 153 million drivers | BleepingComputer
Senate Considers Allowing Contractors to Conduct Military Hacks | bloomberg.com
Feds accuse China of ‘systematic’ distillation of U.S. AI models | cyberscoop.com
Dropbox accounts breached through Lenovo email verification flaw | BleepingComputer
FBI raises alarm over deceptive phishing campaign targeting prominent people | cyberscoop.com
Microsoft warns of TerminalFix attacks deploying reverse tunnels | BleepingComputer
OpenAI agents discussed ways to escape their sandbox on public wiki | arstechnica.com
OpenAI releases new model that it says triggered internal security measures | NBC News Tech
Trump may be forced to reveal secret rules feds use for AI safety testing | Social Signals
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited | therecord.media
Security Incident – BGP Hijacking – Virtualizor |
Coder's registry infrastructure compromised to push malicious modules | BleepingComputer
Pegasus, NoviSpy variant spyware found on devices of Serbian activists | cyberscoop.com
European parliament members call for slowdown of Serbia’s EU entry over spyware use | CyberScoop
New pro-Ukraine hacker group targets Russian companies with custom ransomware | therecord.media
US military disabled ad tracking on troops’ devices following reports of targeted attacks | TechCrunch Security
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges | BleepingComputer
A hacker stole $340M in a crypto heist, then returned most of it | TechCrunch Security
‘White hat’ hackers take $47 million bounty after $320 million crypto theft | therecord.media Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms
2026/09/02 | 58 mins.On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including:
Two alleged TeamPCP hackers got arrested in Australia
The White House has a plan to boost security for water facilities, but we can’t see it working
OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief
Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots
Much, much more…
This week’s show is brought to you by Ent AI. Co-founder Brandon Dixon joins Pat to talk through some of the absolutely wild fraud and abuse the company’s endpoint security tool is finding when it’s deployed inside large organisations.
This episode is also available on YouTube
Show notes
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia | krebsonsecurity.com
How Brian Krebs doxxed TeamPCP - Risky Business Media | Social Signals
FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America’s water systems | Social Signals
OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers | wired.com
The Rise and Fall of Agent Civilizations |
clem 🤗 (@ClementDelangue) on X | X (formerly Twitter)
Matthew Zeitlin (@MattZeitlin) on X | X (formerly Twitter)
100-plus companies call for ‘global surge’ in AI-powered cyber defense | CyberScoop
China's AI-Enabled APT Operations Are Getting Interesting - Risky Business Media |
SilkParasite: Tracking a China-Nexus APT Across Central Asia |
DoD confirms ‘refrigeration disruption’ at military commissaries | Military Times
Claude, Codex, and Hermes installed unowned code inside corporate networks | arstechnica.com
Ukraine to give Britain access to battlefield data to train AI | therecord.media
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage | BleepingComputer
White House bans foreign-made equipment for power generation over cyber backdoor concerns | therecord.media
Large DDoS attack knocks Norwegian public services offline | The Record
Researchers warn about chained SharePoint sequence | Cybersecurity Dive
PaperCut warns of hackers using printer management software flaw in attacks | therecord.media
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes | BleepingComputer
Slovenian casinos reopen after cyberattack knocked gaming systems offline | therecord.media
DOJ firearms agency says hackers breached system containing investigation targets | therecord.media- On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
Iranian hackers take down a small-scale power generator in the UK
Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
Prompt injection isn’t going away
LLMs are deceiving us meat sacks and it’s a worry
Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
This episode is also available on YouTube
Show notes
Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com
Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com
Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts
US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com
The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com
CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer
Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive
Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer
Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer
Rust supply chain attack linked to North Korean hackers | securityweek.com
Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com
New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com
Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer
Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer
Hackers infect Android car head units with proxy botnet malware | BleepingComputer
ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer
New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer
Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer
AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com
EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com
Detections and customer notifications | Okta Threat Intelligence
More News podcasts
Trending News podcasts
About Risky Business
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Podcast websiteListen to Risky Business, Candace and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Risky Business
Scan code,
download the app,
start listening.
download the app,
start listening.
Risky Business: Podcasts in Family































