Risky Business #848 -- OpenAI comes clean

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

  • The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
  • Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
  • More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
  • It turns out TeamPCP has been around longer than we thought and predates the AI era
  • Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
  • Much, much more

This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.

This episode is also available on YouTube

Risky Business #848 -- OpenAI comes clean
0:00 / 59:47

Show notes

How a simple request for AI to book a gym class exposed a major threat | Social Signals

OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com

OpenAI BlackHat talk re Hugging Face incident |

OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop

Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media

Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate | therecord.media

Local governments in four states dealing with cyberattacks that have shut down services | The Record

Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record

State Department says Trump raised cyber scam compound issue with Xi | therecord.media

Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | wired.com

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun - Risky Business Media |

Chrome adopts what may be the best protection yet against account takeovers | Ars Technica

CSS:the bomb inside your inbox | PortSwigger Research

Security update available for Metabase - Please upgrade now | Social Signals

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media

British ‘Com’ member who abused more than 100 girls worldwide jailed for two years | therecord.media

FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | TechCrunch Security

AI is getting better at election facts, but voters shouldn’t rely on it | CyberScoop

The FTC wants to regulate AI for ideological bias | cyberscoop.com

US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer

N-able N-central exploitation results in RMM tool deployment | Sophos

Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security

mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub