Risky Business #801 -- AI models can hack well now and it's weirding us out

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. Google security engineering VP Heather Adkins drops by to talk about their AI bug hunter, and Risky Business producer Amberleigh Jack makes her main show debut.

This episode explores the rise of AI-powered bug hunting:

  • Google’s Project Zero and Deepmind team up to find and report 20 bugs to open source projects
  • The XBOW AI bug hunting platform sees success on HackerOne
  • Is an AI James Kettle on the horizon?

There’s also plenty of regular cybersecurity news to discuss:

  • On-prem Sharepoint’s codebase is maintained out of China… awkward!
  • China frets about the US backdooring its NVIDIA chips, how you like ‘dem apples, China?
  • SonicWall advises customers to turn off their VPNs
  • Hardware controlling Dell laptop fingerprint and card readers has nasty driver bugs
  • Russia uses its ISPs to in-the-middle embassy computers and backdoor ‘em.
  • The Russian government pushes VK’s Max messenger for everything

This week’s show is sponsored by device management platform Devicie. Head of Solutions Sean Ollerton talks through the impending Windows 10 apocalypse, as Microsoft ends mainstream support. He says Windows 11 isn’t as scary as people make out, but if the update isn’t on your radar now, time is running out.

Show Notes:

Google says its AI-based bug hunter found 20 security vulnerabilities | TechCrunch https://techcrunch.com/2025/08/04/google-says-its-ai-based-bug-hunter-found-20-security-vulnerabilities/

Is XBOW’s success the beginning of the end of human-led bug hunting? Not yet. | CyberScoop https://cyberscoop.com/is-xbows-success-the-beginning-of-the-end-of-human-led-bug-hunting-not-yet/

James Kettle on X: “There I am being careful to balance hyping my talk without going too far and then this gets published 😂 maybe the countdown timer is just too ominous! https://t.co/jEre6a9N7J” / X https://x.com/albinowax/status/1951722079302160845

Risky Bulletin: China with the accusations again - Risky Business Media https://risky.biz/risky-bulletin-china-with-the-accusations-again/

美情报机构频繁对我国防军工领域实施网络攻击窃密 https://mp.weixin.qq.com/s/MjIlXBYK0kK2ysU6a78BAg

SharePoint Exploit: Microsoft Used China-Based Engineers to Maintain the Software — ProPublica https://www.propublica.org/article/microsoft-sharepoint-hack-china-cybersecurity

China fears Nvidia chips could track, trace and shut down its AIs - Asia Times https://asiatimes.com/2025/08/china-fears-nvidia-chips-could-track-trace-and-shut-down-its-ais/

SonicWall urges customers to take VPN devices offline after ransomware incidents | The Record from Recorded Future News https://therecord.media/sonicwall-possible-zero-day-gen-7-firewalls-ssl-vpn

Gen 7 SonicWall Firewalls – SSLVPN Recent Threat Activity https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430

ReVault! When your SoC turns against you… https://blog.talosintelligence.com/revault-when-your-soc-turns-against-you/

Nearly 100,000 ChatGPT Conversations Were Searchable on Google https://www.404media.co/nearly-100-000-chatgpt-conversations-were-searchable-on-google/

Microsoft catches Russian hackers targeting foreign embassies - Ars Technica https://arstechnica.com/information-technology/2025/07/microsoft-catches-russian-hackers-targeting-foreign-embassies/

The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware | WIRED https://www.wired.com/story/russia-fsb-turla-secret-blizzard-apolloshadow-isp-cyberespionage/

Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats | Microsoft Security Blog https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/

Russia blocks popular US-made internet speed test tool over national security concerns | The Record from Recorded Future News https://therecord.media/russia-bans-speedtest-ookla