Risky Business Podcast
April 01, 2026
Risky Business #831 -- The AI bugpocalypse begins
Presented by
Enterprise Technology Editor
Technology Editor
CEO and Publisher
On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
- Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package
- TeamPCP appear to have ransacked Cisco’s source and cloud environments
- AI is getting legitimately good at being told to “just go find some 0day in this”
- Kaspersky says Coruna and Triangulation do share code lineage
- Iranian hackers dump Kash Patel’s gmail spool
- Oh, and of course there’s a Citrix Netscaler memory leak being exploited in the wild
This week’s episode is sponsored by Dropzone AI, who make automated AI SOC analysts. Head honcho Ed Wu explains how they’ve built pre-canned ‘hunt packs’ to lead the AI off into your environment to find weird, interesting and security relevant things.
Brought to you by Dropzone AI
AI SOC Analysts that never sleep. So you can.
Show notes
Google links axios supply chain attack to North Korean group | The Record from Recorded Future News
Cisco source code stolen in Trivy-linked dev environment breach
h0mbre on X: "Claude is somehow better at kernel exploitation than creating meal plans."
Vulnerability Research Is Cooked — Quarrelsome
MAD Bugs: vim vs emacs vs Claude - Calif
MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
A Risky Biz Experiment: Hunting for iOS 0day with AI - Risky Business Media
Security leaders say the next two years are going to be 'insane' | CyberScoop
Coruna framework: an exploit kit and ties to Operation Triangulation | Securelist
Apple says no one using Lockdown Mode has been hacked with spyware | TechCrunch
Reverse engineering Apple’s silent security fixes - Calif
Meta and YouTube found liable in social media addiction trial
Iranian hackers publish emails allegedly stolen from Kash Patel
Drop Site on X: "IRGC: From now on, for every assassination, an American company will be destroyed"
Citrix NetScaler products confirmed to be under exploitation | Cybersecurity Dive
Using a VPN May Subject You to NSA Spying | WIRED
Post reporters called the White House. Their phones showed ‘Epstein Island.’ - The Washington Post