Risky Business (849): Trump will unleash contractors on cybercriminals

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:

  • Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
  • OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
  • Anthropic’s models start a turf war when given the same task, surprising… nobody
  • We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
  • Much, much more

This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.

Show notes:

Trump signs memo authorizing private sector to launch cyberattacks https://www.washingtonpost.com/national-security/2026/08/14/trump-signs-memo-authorizing-private-sector-launch-cyberattacks

Trump taps cyber firms to go on offensive against criminals https://therecord.media/trump-cyber-crime-offensive

OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue https://www.wired.com/story/openai-overhauls-safety-protocols-after-its-ai-agents-went-rogue

Pacing model development in an era of cyber-critical capabilities https://openai.com/index/pacing-model-development-cyber-capabilities

Anthropic set AI agents loose on the same task. They started a turf war https://techcrunch.com/2026/08/13/anthropic-set-ai-agents-loose-on-the-same-task-they-started-a-turf-war

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan

Researchers find AI-powered hacking tools for sale in underground forums https://www.cybersecuritydive.com/news/ai-hacking-tools-sale-underground-forums/827807

Terabytes of credentials leaked in massive supply-chain attack https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack

Trivy, Not LiteLLM Behind the 2,500 Org Compromise https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise

Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes https://therecord.media/russia-wildberries-cyberattack-ukraine

‘Unprecedented’ number of Apple users received recent spyware alert, say investigators https://techcrunch.com/2026/08/17/unprecedented-number-of-apple-users-received-recent-spyware-alert-say-investigators

This Coin-Sized Device Can Hack a Boeing 737 https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals

Max severity SAP Commerce Cloud flaw now targeted in attacks https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks

Shell investigates ‘potential incident’ after Clop data theft claims https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims

Philips and GE investigating Clop ransomware data theft claims https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims

Uber Freight reportedly investigating after hacking group claims data breach https://techcrunch.com/2026/08/12/uber-freight-reportedly-investigating-after-hacking-group-claims-data-breach

Details emerge on BlackFile’s recent attacks on financial companies https://cyberscoop.com/blackfile-cyberattacks-financial-sector

After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug https://techcrunch.com/2026/08/12/after-microsoft-threatened-legal-action-a-security-researcher-publishes-a-new-windows-zero-day-bug

Kimwolf botnet rebuilt to survive takedowns, researchers say https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes

Hundreds of fake Chrome VPN extensions route traffic through a proxy https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy

Deepfake hiccup unmasks suspected digital certificate fraudster https://www.theregister.com/security/2026/08/11/deepfake-hiccup-unmasks-suspected-digital-certificate-fraudster/5285934

Vulnerability giving attackers full control of Macs is under active exploitation https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation

Critical VMware vCenter RCE flaw exploited for reverse SSH access https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access

See full show notes at https://risky.biz/RB849/