Risky Business (852): Cyber Command wants to buy shells

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:

  • ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits
  • The US government plans to pay private contractors to conduct military hacks
  • The US accuses China of distillation attacks, a.k.a. forbidden training
  • It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki
  • Much, much more…

This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace.

Show notes:

FBI Probes Service Selling 153M+ Drivers Licenses | Krebs on Security https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses

IDScan sued over alleged data breach affecting 153 million drivers | BleepingComputer https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers

Senate Considers Allowing Contractors to Conduct Military Hacks | bloomberg.com https://www.bloomberg.com/news/articles/2026-09-03/senate-considers-allowing-contractors-to-conduct-military-hacks

Feds accuse China of ‘systematic’ distillation of U.S. AI models | cyberscoop.com https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation

Dropbox accounts breached through Lenovo email verification flaw | BleepingComputer https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw

FBI raises alarm over deceptive phishing campaign targeting prominent people | cyberscoop.com https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign

Microsoft warns of TerminalFix attacks deploying reverse tunnels | BleepingComputer https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels

OpenAI agents discussed ways to escape their sandbox on public wiki | arstechnica.com https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki

OpenAI releases new model that it says triggered internal security measures | NBC News Tech https://www.nbcnews.com/tech/tech-news/openai-debuts-gpt-6-astra-security-measures-rcna595940

Trump may be forced to reveal secret rules feds use for AI safety testing | Social Signals https://arstechnica.com/tech-policy/2026/09/trump-may-be-forced-to-reveal-secret-rules-feds-use-for-ai-safety-testing

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited | therecord.media https://therecord.media/microsoft-patch-tuesday-september-2026

Security Incident – BGP Hijacking – Virtualizor | https://www.virtualizor.com/blog/security-incident-bgp-hijacking

Coder’s registry infrastructure compromised to push malicious modules | BleepingComputer https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules

Pegasus, NoviSpy variant spyware found on devices of Serbian activists | cyberscoop.com https://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists

European parliament members call for slowdown of Serbia’s EU entry over spyware use | CyberScoop https://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands

New pro-Ukraine hacker group targets Russian companies with custom ransomware | therecord.media https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia

US military disabled ad tracking on troops’ devices following reports of targeted attacks | TechCrunch Security https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges | BleepingComputer https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges

A hacker stole $340M in a crypto heist, then returned most of it | TechCrunch Security https://techcrunch.com/2026/09/08/a-hacker-stole-340m-in-a-crypto-heist-then-returned-most-of-it

‘White hat’ hackers take $47 million bounty after $320 million crypto theft | therecord.media https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward