Podcasts

News, analysis and commentary

Srsly Risky Biz: “Rogue AI” isn’t going anywhere

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

James Wilson
James Wilson

Technology Editor

Amberleigh Jack and James Wilson chat about OpenAI agents’ recent escapades into Australian government websites. OpenAI has promised to “rebuild trust with Australians” but we’re likely getting a glimpse into the new normal, here.

They also discuss how the ShinyHunters hacking group has found itself on law enforcement’s target list after breaching FBI systems. The group played some stupid games and they appear to be in the “stupid prizes” stage.

This episode is also available on YouTube

Srsly Risky Biz: “Rogue AI” isn’t going anywhere
0:00 / 16:17

ShinyHunters suspect arrested in the Netherlands

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A ShinyHunters suspect has been arrested in the Netherlands, Apple fixes an iOS zero-day found by Meta, recent Citrix zero-days see mass exploitation within hours and NVIDIA launches an AI sandboxing platform.

ShinyHunters suspect arrested in the Netherlands
0:00 / 7:40

Soap Box: HD Moore talks OT security, frontier fearmongering and more

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with industry legend HD Moore about how his company runZero wound up being used heavily to discover OT devices in enterprise networks.

They also talk about the vulnpocalypse and how frontier lab fearmongering is reminiscent of the collective freakout when HD released the Metasploit exploit framework back in 2003.

This episode is also available on YouTube.

Soap Box: HD Moore talks OT security, frontier fearmongering and more
0:00 / 34:01

Between Two Nerds: The AI crime machine

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about the rise of fully automated LLM-driven hacking campaigns among criminals and even state hacking groups. For those with the right risk appetite, a move fast and break things hacking approach using AI can pay off.

This episode is also available on YouTube.

Between Two Nerds: The AI crime machine
0:00 / 27:40

Risky Bulletin: Intel ends paid bug bounties

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Intel removes cash rewards from its bug bounty program, OpenAI agents probed dozens of organizations, Fraudsters scam €95 million from an Italian bank and Bitget is hacked for $350 million.

Risky Bulletin: Intel ends paid bug bounties
0:00 / 9:38

Sponsored: Robo-Burp is coming for your web apps

Presented by

James Wilson
James Wilson

Technology Editor

In this Risky Business sponsored interview James Wilson chats to Kieron Hughes and Andrzej Matykiewicz from PortSwigger about the company’s latest AI pen-testing product, Burp AT. The model has different levels of autonomy modes and is natively integrated with Burp Suite so once it finds vulnerabilities it can spin up intruder attacks, configure everything and brute-force the code.

The three also chat about the experiences of beta trial users, including one that found a vulnerability that disclosed reports from the company’s anonymous whistle blower platform.

Sponsored: Robo-Burp is coming for your web apps
0:00 / 21:31

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A major vulnerability has been found in the ancient TACACS+ networking protocol, Australia’s Prime Minister claims an OpenAI agent hacked the country’s Medicare website, OpenAI gives Ukraine access to its Daybreak cyber-defense program and the UK will establish an anti-disinformation center.

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol
0:00 / 11:02

Srsly Risky Biz: Bring on the AI lawsuits

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. Its a good move. Leaving the companies on the hook keeps the pressure on them to do better with their cyber security and testing controls.

They also discuss a Russian AI-powered cyberespionage campaign run by a group known as Midnight Blizzard. It used AI workflows to run the entire campaign so they got a lot more hacking done and accepted AI mistakes. This makes sense given that they want more intelligence from Ukrainian targets and don’t care at all about getting caught.

This episode is also available on YouTube.

Srsly Risky Biz: Bring on the AI lawsuits
0:00 / 14:55

Risky Business #854 -- We're Jevpilled

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

THE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14

On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including:

  • Google’s Gemini finally did some crimes
  • OpenAI admits more agents did silly things because “alignment”
  • US Treasury’s Scott Bessent rules out a liability waiver for the frontier labs, saying, roughly: “Lol. Lmao even.”
  • Jev is Silicon Valley’s “hot dog/not hotdog” app brought to life, and it will really improve security tooling
  • The FBI and Coast Guard boarded oil tankers after they were allegedly hacked
  • Much, much more…

This week’s show is brought to you by Thinkst Canary. Founder Haroon Meer joins Patrick to talk about Thinkst’s new deception tools that trick the AI agents that are targeting you. It’s actually hilarious how well deception tech works against hacking agents.

This episode is also available on YouTube

Risky Business #854 -- We're Jevpilled
0:00 / 54:49

Risky Bulletin: Team Cymru unmasks shady Chinese proxy network

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies.

Risky Bulletin: Team Cymru unmasks shady Chinese proxy network
0:00 / 8:58