Risky Business (845): OpenAI's Skynet moment

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:

  • Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
  • US and China trade AI model ban threats
  • Iran has been using SS7 queries to locate and target US troops
  • Scattered Spider is having a hard time, not just because of Microsoft’s GDID
  • And much, much more!

This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.

Show Notes:

OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com https://openai.com/index/hugging-face-model-evaluation-security-incident

Security incident disclosure — July 2026 | Social Signals https://huggingface.co/blog/security-incident-july-2026

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action

Cheating behaviour in frontier model evaluations | AISI Work | Social Signals https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations

JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion

EXCLUSIVE: Beijing is looking at curbing overseas access to China’s top AI models, sources say | reuters.com https://www.reuters.com/world/beijing-is-looking-curbing-overseas-access-chinas-top-ai-models-sources-say-2026-07-07

https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi | https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi

Alibaba to ban employees from using Anthropic’s coding tool, source says | reuters.com https://www.reuters.com/world/china/alibaba-ban-claude-code-workplace-over-alleged-backdoor-risks-source-says-2026-07-03

Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says

Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code

Trump calls for new election security measures | NBC News Tech https://www.nbcnews.com/nightly-news/video/trump-calls-for-new-election-security-measures-266865733992

Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media https://therecord.media/scattered-spider-hackers-tfl-sentenced

Alleged longstanding member of Scattered Spider extradited to US | CyberScoop https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition

Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com https://www.zetter-zeroday.com/tracking-peter-stokes-and-the-com-allison-nixon-and-her-work-unmasking-cybercriminals

764 splinter group leader sentenced to 40 years in jail | cyberscoop.com https://cyberscoop.com/764-splinter-group-leader-sentenced-alexis-chavez

White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | cyberscoop.com https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse

Attackers vote themselves $20 million in BONK cryptocurrency | The Record https://therecord.media/attackers-vote-themselves-20-million-bonk-crypto

CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited

IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets

Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI | TechCrunch Security https://techcrunch.com/2026/07/13/apple-says-former-employee-exploited-rare-bug-to-download-confidential-files-after-leaving-for-openai

Risky Bulletin: Hacker wipes Romania’s entire land registry database - Risky Business Media | Social Signals https://risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database

Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september

On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security https://pushsecurity.com/resources/device-code-phishing