Risky Business #845 -- OpenAI's Skynet moment
On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
US and China trade AI model ban threats
Iran has been using SS7 queries to locate and target US troops
Scattered Spider is having a hard time, not just because of Microsoft’s GDID
And much, much more!
This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.
This episode is also available on YouTube.
Show notes
OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com
Security incident disclosure — July 2026 | Social Signals
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security
Cheating behaviour in frontier model evaluations | AISI Work | Social Signals
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals
Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica
EXCLUSIVE: Beijing is looking at curbing overseas access to China's top AI models, sources say | reuters.com
https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi |
Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com
Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security
Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com
Trump calls for new election security measures | NBC News Tech
Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media
Alleged longstanding member of Scattered Spider extradited to US | CyberScoop
https://www.justice.gov/usao-ndil/media/1450651/dl?inline |
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com
764 splinter group leader sentenced to 40 years in jail | cyberscoop.com
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | cyberscoop.com
Attackers vote themselves $20 million in BONK cryptocurrency | The Record
CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer
Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch Security
Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer
IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com
Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI | TechCrunch Security
Pegasus Spyware European Parliament Pega Committee Member | The Record
Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security
Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media | Social Signals
Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer
On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security
Risky Business #811 -- F5 is the tip of the crap software iceberg
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
China has been rummaging in F5’s networks for a couple of years
Meanwhile China tries to deflect by accusing the NSA of hacking its national timing system
Salesforce hackers use their stolen data trove to dox NSA, ICE employees
Crypto stealing, proxy-deploying, blockchain-C2-ing VS Code worm charms us with its chutzpah
Adam gets humbled by new Linux-capabilities backdoor trick
Microsoft ignores its own guidance on avoiding BinaryFormatter, gets WSUS owned.
This episode is sponsored by Push Security. Co-founder and Chief Product Officer Jacques Louw joins to talk through how Push traced a LinkedIn phishing campaign targeting CEOs, and the new logging capabilities that proved critical to understanding it.
This episode is also available on Youtube.
Show notes
Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks | WIRED
Breach at US-based cybersecurity provider F5 blamed on China, sources say | Reuters
Network security devices endanger orgs with ’90s era flaws | CSO Online
China claims it caught US attempting cyberattack on national time center | The Record from Recorded Future News
Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials
Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials
ICE amps up its surveillance powers, targeting immigrants and antifa - The Washington Post
John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
US court orders spyware company NSO to stop targeting WhatsApp, reduces damages | Reuters
Apple alerts exploit developer that his iPhone was targeted with government spyware | TechCrunch
A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones | WIRED
GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace | Koi Blog
European police bust network selling thousands of phone numbers to scammers | The Record from Recorded Future News
Stephan Berger on X: "We recently took over an APT investigation from another forensic company. While reviewing analysis reports from the other company, we discovered that the attackers had been active in the network for months and had deployed multiple backdoors. One way they could regain root" / X
Linux Capabilities Revisited | dfir.ch
CVE-2025-59287 WSUS Remote Code Execution | HawkTrace
TARmageddon (CVE-2025-62518): RCE Vulnerability Highlights the Challenges of Open Source Abandonware | Edera Blog
Browser threat detection & response | Push Security | Push Security
How Push stopped a high risk LinkedIn spear-phishing attack
Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Did the SharePoint bug leak out of the Microsoft MAPP program?
Expel retracts its FIDO bypass writeup
The mess surrounding the women-only dating-safety app Tea gets worse
Broadcom customers struggle to get patches for VMWare hypervisor escapes
Aeroflot gets hacked by the Cyber Partisans, disrupting flights
This week’s episode is sponsored by Push Security. Daniel Cuthbert joins and explains how having telemetry about identity from inside the browser is a key pillar for investigating intrusions in the browser-centric future.
This episode is also available on Youtube.
Show notes
Microsoft Probing Whether Cyber Alert Tipped Off Chinese Hackers
Microsoft says Warlock ransomware deployed in SharePoint attacks as governments scramble | The Record from Recorded Future News
What we know about the Microsoft SharePoint attacks | Cybersecurity Dive
An important update (and apology) on our PoisonSeed blog
Tea User Files Class Action After Women’s Safety App Exposes Data
A Second Tea Breach Reveals Users’ DMs About Abortions and Cheating
Top Lawyer for National Security Agency Is Fired
From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944
VMware prevents some perpetual license holders from downloading patches
Pro-Ukrainian hackers take credit for attack that snarls Russian flight travel - Ars Technica
КИБЕРУДАР ПО АЭРОФЛОТУ РФ!v
Treasury sanctions North Koreans involved in IT-worker schemes | Cybersecurity Dive
Minnesota governor activates National Guard amid St. Paul cyberattack | StateScoop
Outage was result of cyberattack, Post Luxembourg says
Clorox files $380 million suit blaming Cognizant for 2023 cyberattack | Cybersecurity Dive
Cisco network access security platform vulnerabilities under active exploitation | CyberScoop
Arizona woman sentenced to 8.5 years for running North Korean laptop farm | The Record from Recorded Future News
Cybercrime forum Leak Zone publicly exposed its users' IP addresses | TechCrunch
Risky Biz Soap Box: Push Security's browser-first twist on identity security
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.
Push has built an identity security platform that collects identity information and events from your users’ browsers. It can detect phish kits and shut down phishing attempts, protect SSO credentials, and find shadow/personal account that a user has spun up.
It’s extremely difficult to bypass. That’s because when you’re in the browser it doesn’t matter how a phishing link arrives, or how a threat actor has concealed it from your detection stack – if the user sees it, Push sees it.
There are solutions for protecting your users SSO credentials, like passkeys. But what about all the SaaS in your environment? Even if it’s enrolled into your SSO, are you sure that’s how your users are authenticating to it? What about the automation platforms your developers and admins use? What about data platforms like Snowflake? Are your using setting up passkeys for those accounts? How would you know, and what problems can it cause if those accounts are vulnerable?
This is a fun one!
This episode is also available on Youtube.
Show notes
Risky Business #777 -- It's SonicWall's turn
Coming to you from the same room in Risky Business headquarters Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. They talk through:
Sonicwall firewalls hand out remote code exec like candy
Mastercard make a slapstick-grade mistake with their DNS
The data breach at PowerSchool and other niche SaaS providers
Academic research proposes taking down Europe’s power grid
Apple CPUs get a new speculative execution side channel
And much, much more.
This week’s episode is sponsored by Push Security, who make an identity security product that runs inside browsers. Luke Jennings joins to discuss some of the pitfalls of federated authentication, like attackers using unexpected identity providers to log in to your apps.
This episode is also available on Youtube.
Show notes
SonicWall warns hackers targeting critical vulnerability in SMA 1000 series appliances | Cybersecurity Dive
MasterCard DNS Error Went Unnoticed for Years – Krebs on Security
Data breach hitting PowerSchool looks very, very bad - Ars Technica
OpenAI rival DeepSeek limits registration after ‘large-scale malicious attacks’ | The Record from Recorded Future News
Hackers imitate Kremlin-linked group to target Russian entities | The Record from Recorded Future News
UK to examine undersea cable vulnerability as Russian spy ship spotted in British waters | The Record from Recorded Future News
Questions grow over whether Baltic Sea cable damage was sabotage or accidental | The Record from Recorded Future News
Researchers say new attack could take down the European power grid - Ars Technica
At least $69 million stolen from crypto platform Phemex in suspected cyberattack | The Record from Recorded Future News
BreachForums admin to be resentenced after appeals court slams supervised release | The Record from Recorded Future News
Apple chips can be hacked to leak secrets from Gmail, iCloud, and more - Ars Technica
Apple fixes zero-day flaw affecting all devices | TechCrunch
I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny
Government websites vanish under Trump, from the Constitution to DEI
Trail of Bits: Director, Technical Marketing
Push Security: Security Researcher (remote in the USA)
A new class of phishing: Verification phishing and cross-IdP impersonation