Newsletters

Written content from the Risky Business Media team

Risky Bulletin: Authorities dismantle KillSec group, arrest members across Europe

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

European law enforcement agencies have cracked down and dismantled the KillSec ransomware group in a coordinated operation that seized servers, conducted several house searches across four countries, and detained three of the group's members.

The biggest arrest was a 16-year-old Romanian national living in Alicante, Spain, identified as the group's main administrator. The teen's name was not released, according to Spanish child privacy laws.

Two other suspects were arrested in Romania and the UK. The suspect arrested in the UK was identified as Fouad Eltibrizi, a Dutch national. The US has filed an extradition request for Eltibrizi, seeking him for a cyberattack against a Puerto Rico company in March 2025.

Srsly Risky Biz: "Rogue" AI Isn't Going Anywhere

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

OpenAI found dozens of examples of its agents acting in undesirable ways while reviewing recent agent behaviour, according to Reuters. 

Based on publicly-available details, each incident is pretty unsurprising, although we do expect they’ll result in a lengthy apology tour for the company. This type of behaviour isn't just limited to OpenAI or even frontier labs, though. Open weight models will catch up and will soon present the same risks.

Last week Australian Prime Minister Anthony Albanese revealed OpenAI agents had "infiltrated” the Medicare Statistics Reporting Portal, an Australian Government website. On Monday OpenAI disclosed that this occurred during its internal evaluation of an unreleased experimental model in June. 

Risky Bulletin: Sanctions force CAs to revoke TLS certs in Iran, Russia

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

For the past three months, certificate authorities have revoked TLS certificates for government and critical sector entities in countries sanctioned by the US.

Disruptions to government networks, agencies, and the banking sectors have been reported in Russia and Iran.

GlobalSign mass-revoked TLS certs for Russian customers in June and Russian banks had to switch to a state-run certificate authority in August to keep their apps and websites running.

Risky Bulletin: Intel ends paid bug bounties

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

American chipmaker Intel has removed financial rewards from its bug bounty program that previously used to offer up to $100,000 per confirmed vulnerability reports.

The company updated its bug bounty program page on the Intigriti platform earlier this month to remove any money payouts and add a "No bounty" marker.

The last snapshot of the page with bounties dates from September 13.

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A recently disclosed vulnerability can allow attackers to launch pre-authentication remote code execution attacks against TACACS+, a 33-year-old protocol that handles authentication on networking equipment.

The protocol—Terminal Access Controller Access-Control System Plus (TACACS+)—was released in 1993 by Cisco as an upgrade for the original TACACS protocol from 1984. 

It works on port 49 and handles authentication, authorisation, and accounting on networking devices. It checks usernames and passwords against a server, allows access to certain operations, and logs what users do on a system.

Srsly Risky Biz: Bring On the AI Lawsuits

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Last week US Treasury Secretary Scott Bessent argued that frontier AI labs should not be given liability exemptions. He's not buying that a recent string of hacking incidents are AI magic. Instead, they're equivalent to industrial accidents that would have been prevented by reasonable controls. Bessent's right, giving frontier labs a free pass would be a terrible idea. 

Bessent made his comments while testifying at a hearing of the House Financial Services Committee. When asked about AI safety, he replied "the best way to guarantee safety" is for those creating the technology to be "liable for what they build and generate". Frontier labs, he added, are instead asking for a liability exemption. 

Headlines detailing various frontier lab models escaping cyber security testing environments and embarking on hacking sprees have been coming thick and fast. Most recently, The Wall Street Journal reported last week that Google's Gemini model had hacked three companies during a cyber security test back in May. 

Risky Bulletin: Network of 10,000 AI servers masks Chinese malicious activity

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Security researchers have discovered more than 10,000 proxy servers that are masking malicious AI activity originating out of China.

Security firm Team Cymru calls the server "transfer stations," but they are more commonly known as API proxies, relays, or gateways. Typically, they are used in corporate environments to cache AI queries and cut down token costs, but in recent months they have also been adopted by a new section of the criminal underground, one dedicated to abusing public AI services.

These days, AI proxy relays are being used to hide activity from hacked AI accounts, mask the real location of a user, or power illegal AI services like nudify apps and others. Other malicious AI relay servers are also used in schemes to intercept legitimate AI caching activity and inject their own queries and harvest responses.

Risky Bulletin: Gemini hacked three companies too

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

There is no intro in this edition as we were a little busy catching up with the biggest news from last week, after our short vacation.

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and guest co-host Morgan Adamski at the helm!

Gemini hacks three companies: Google's Gemini AI model escaped a testing environment and hacked three real companies. The model escaped testing environments run by Irregular, the same AI security company behind similar incidents with Anthropic and Meta. Google notified the hacked companies and claims Gemini did no real damage. [BBC // WSJ]

Risky Bulletin: Anthropic agents went hacking again

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

AI company Anthropic has disclosed a fourth incident where one of its AI agents escaped their test environment and hacked a real target.

The incident involved the Opus 4.6 model during a Capture The Flag (CTF) challenge, a common cybersecurity test.

Anthropic says the model broke its test environment by accident when it assigned conflicting IP addresses to different machines. The model realized its mistake and tried to terminate the test as a failure.

Srsly Risky Biz: America's Drivers Licence Breach is a National Security Disaster

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Last week, Krebs On Security broke the story of a newly launched dark web service calling itself Nexus that was selling access to identity documents, including 153 million drivers licences from US and Canadian citizens. This is a huge breach that will not only be used for run-of-the-mill cybercrime, but will also feed the intelligence machines of America's adversaries.

Nexus claimed, in a cybercrime forum post, that it had access to a major identity verification company and had spent more than a year "continuously" exfiltrating new data into a private database. Krebs On Security noted in a single day the number of licences in the database increased by nearly 400,000, suggesting regular ingestion of new data.

Krebs On Security was able to verify that the drivers licences held by the service were genuine. In addition to his own, it contained licences from nine of his friends and family members. Secretary of War Pete Hegseth, an assistant director at the FBI and other high-ranking US government officials also had licences in the mix.