Risky Business (846): OpenAI built a fireplace out of wood

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:

  • Everyone signs the open weights open letter, except Anthropic… of course.
  • OpenAI had no idea it had hacked Hugging Face
  • Kimi K3 open weights released and they’re massive!
  • Why a more aggressive response is needed to cyber attacks on OT
  • And much, much more!

This week’s show is brought to you by SpecterOps. In this week’s sponsor interview Justin Kohler and Jared Atkinson talk about how SpecterOps’ Bloodhound now supports AWS attack paths. Run it against your AWS infra, but only if you have a strong stomach. The results will terrify you.

Show Notes:

Open Weights and American AI Leadership | Social Signals https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight

Our position on open-weights models | Social Signals https://www.anthropic.com/news/position-open-weights-models

Halvar Flake (@halvarflake) on X | X (formerly Twitter) https://x.com/halvarflake/status/2081975470761930916

White House accuses Chinese company of distilling Anthropic’s Fable | cyberscoop.com https://cyberscoop.com/white-house-accuses-moonshot-ai-anthropic-model-distillation

Jensen Huang (@JensenHuang) on X | X (formerly Twitter) https://x.com/JensenHuang/status/2081698060330250294

Its AI Agent Spent Days Hacking a Company, but Sources Say OpenAI Did Not Notice for a Week | reuters.com https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face | TechCrunch Security https://techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face

Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack | TechCrunch Security https://techcrunch.com/2026/07/26/hugging-face-ceo-calls-for-radical-transparency-after-unprecedented-openai-hack

Sens. Banks and Schiff Introduce Bill to Help American AI Companies Combat Chinese Espionage | https://www.banks.senate.gov/news/press-releases/sens-banks-and-schiff-introduce-bill-to-help-american-ai-companies-combat-chinese-espionage

AI Kill Switch Act would let Trump admin order shutdown of rogue AI systems | Ars Technica https://arstechnica.com/tech-policy/2026/07/ai-kill-switch-act-would-let-trump-admin-order-shutdown-of-rogue-ai-systems

Marco Rubio tells diplomats to play down talk of American tech “kill switch” | reuters.com https://www.reuters.com/legal/litigation/marco-rubio-tells-diplomats-play-down-talk-american-tech-kill-switch-2026-07-22

Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities | CyberScoop https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities

NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign | nsa.gov https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts | BleepingComputer https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts

LG to Ban Residential Proxies from Smart TV Apps | krebsonsecurity.com https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps

Despite multiple takedowns, botnets continue to grow | cyberscoop.com https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs

Upbound says hack caused $13 million in fraudulent Acima leases | BleepingComputer https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases

Fake Claude app promoted by Bing ads pushes SectopRAT malware | BleepingComputer https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin | BleepingComputer https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin

Clop ransomware targets Windchill, FlexPLM in data theft attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks

‘Wrench’ attacks against crypto holders appear to be on the rise | therecord.media https://therecord.media/wrench-attacks-against-cryptocurrency-holders

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face | wired.com https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face