Videos

News, analysis and product demos

Feature Interview: Nicholas Carlini, Anthropic

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this episode, Anthropic’s Nicholas Carlini joins Patrick Gray and James Wilson to talk about advancements in AI-driven vulnerability research and exploit development.

Nicholas’ talk at the recent [un]prompted conference demonstrated how Anthropic’s Opus 4.6 could find and exploit vulnerabilities in popular open source projects. In the short few weeks since then, Anthropic announced a new model that’s already identifying hundreds of bug fixes across critical software. Nicholas talks us through the work he does at Anthropic, what’s possible and the limitations with current frontier models, and where this goes from here.

Srsly Risky Biz: Musk snubs French authorities

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and James Wilson talk about the French criminal investigation into bias and illegal content on X. Elon Musk and former X CEO Linda Yaccarino didn’t appear for voluntary interviews scheduled this week, but refusing meetings won’t make X’s problems go away. European countries are concerned about X’s influence and regulators will be exploring all other options beyond criminal investigations.

They also discuss the fight to renew authorisation of Section 702 collection. It’s a valuable intelligence source, but in the past the FBI pointlessly overused it.

Risky Business (834): Vercel gets owned, Mozilla dumps hundreds of Mythos bugs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week’s cybersecurity news, including:

  • Vercel got owned, and there’s a few infostealer and compromised employee dots to connect
  • Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse
  • Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs?
  • The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing
  • And DDos attacks hit a couple of smaller-player socials

This week’s episode is sponsored by Permiso. Ian Ahl chats to Pat about the subtle signals Permiso uses to detect ShinyHunters-style activity in cloud and on-prem environments….

Between Two Nerds: AI as the mythical 10x hacker

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq take a deep dive into how a single hacker used OpenAI and Anthropic’s tools to help hack nine Mexican government organisations in quick time.

Srsly Risky Biz: Time to ban sale of precise geolocation data

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and Amberleigh Jack talk about a new Citizen Lab report into Webloc, a tool to identify and track mobile devices. It demonstrates how the collection and sale of mobile phone geolocation data presents privacy and national security risks.

They also discuss a deep-dive into how a single hacker was able to breach nine Mexican government agencies in just weeks using AI assistants. They enabled the attacker to move much faster.

Risky Business (833): The Great Mythos Freakout of 2026

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet
  • CISA adds a 2009 Excel bug to the KEV list, u wot?
  • Adobe also parties like it’s the 2000s, and fixes an Acrobat Reader bug
  • Disgraced former Trenchant exec Peter Williams’ sob story fails to resonate with … anyone
  • Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were “secured” by the password: 1234.

This week’s episode is sponsored by mobile network operator, Cape. Ajit Gokhale talks with James about the ways to get being a telco right when you’re starting from scratch and solving the security problems of 2026….

Between Two Nerds: How AI will upset state cyber competition

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq discuss how the rise of AI, which is very good at vulnerability and exploit development, will change the cyber security industry and competition between states.

Srsly Risky Biz: American diplomats to fight foreign propaganda... on X

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and Amberleigh Jack talk about the State Department taking to X to counter foreign propaganda. US Secretary of State Marco Rubio dismantled the State Department’s counter-propaganda office when he took charge, but it turns out that giving adversary states free reign online is a bad idea.

They also discuss how America’s lawful intercept systems are high value targets for Chinese hackers. It’s a big deal that part of the FBI’s lawful intercept system has been breached and it is high time that the security of these systems was reviewed.

Snake Oilers: Burp AI, Sondera and Truffle Security

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

  • Burp AI and DAST: The founder of PortSwigger and creator of legendary security software Burp Suite, Dafydd Stuttard, drops by to pitch listeners on Burp AI and Burp Suite DAST.

https://portswigger.net/

  • Sondera: Josh Devon talks about Sondera, a technology designed to intervene when AI models start doing the wrong thing by statefully tracking their trajectories. This isn’t a permissions suite for AI agents, it’s a way to stick agents in a harness and make sure they adhere to hard policy boundaries….

Risky Business (832): Anthropic unveils magical 0day computer God

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • Anthropic’s new Mythos model hunts bugs and chains exploits together so well that… you cant have it…
  • …Unless you’re one of their Project Glasswing partners
  • The world isn’t short on bugs, though. F5, Fortinet, Progress ShareFile, and TrueConf are all getting rekt by humans
  • GPU Rowhammering goes in the GPU, past the IOMMU and back into the host-side Nvidia driver
  • North Korea is spending serious time and money on its crypto hacking
  • Just when the US needs CISA most, they slash its budget some more!…