
Risky Bulletin
Regular cybersecurity news updates from the Risky Business team.
Episodes

Sponsored: Passkeys won’t stop authorisation phishing
In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer.
Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if th

Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs
The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great Firewall
Show notes

Srsly Risky Biz: Trump's private hacker memo is the right idea
Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disruption operations, but there simply isn’t enough government capacity. So it is time to bri

Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
Slovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.
Show notes
Risky Bulletin: Sl

Between Two Nerds: The eye of Sauron
In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.
This episode is also available on YouTube.
Show notes
Th

Risky Bulletin: The EU publishes its upcoming cybersecurity standards
The EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.
Show notes
Risky Bulletin: The EU publishes

Sponsored: What npm 12 fixes… and what it doesn’t
In this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what third-party code actually does before allowing it into their environments.

Risky Bulletin: US will let private companies carry out offensive cyber ops
The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.
Show notes
Risky Bu

Srsly Risky Biz: Data extortion is booming. Hooray!
Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.
They also discuss how the rise of AI makes it worth

Risky Bulletin: Russian hackers jump on the fake job interview train
Russian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams.
Show notes
Risky Bulletin: Russian hacker

Between Two Nerds: The cyber resistance!
In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals.
This epsiode is also available on YouTube.
Show notes
The Record on the Belarus Cyber Partisans

Risky Bulletin: Two law firms pay giant ransoms
Two American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!
Show notes
Risky Bulletin:

Sponsored: Island's expansion to SASE and enterprise AI
In this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI.
Show notes
About Michael Leland

Risky Bulletin: A Meta AI model also escaped a testing sandbox
A Meta AI model also escaped a testing sandbox, a cyberattack disrupts ports in North Carolina, the Philippines will establish a cybersecurity agency, and a Ransom Cartel admin gets 16 years in prison.
Show notes
Risky Bulletin: Meta's AI joins Anthropic

Srsly Risky Biz: Being a North Korean hacker is about to be less fun
Tom Uren and James Wilson talk about North Korea losing control over some of its hacker workforce. Expect some tightening of controls and oversight, and perhaps even a reduction in the country’s ransomware operations.
They also discuss escalating attacks on American water infrastructure. Although the impact of these attacks is relatively minor so far, the US governm

Risky Bulletin: Hacker breaches Hungary's State Treasury
A hacker breached Hungary’s State Treasury, Russia will mandate 40 apps on all smartphones next year, hackers steal Liechtenstein’s business database, and an AI agent got real CVEs for hallucinated vulnerability reports.
Show notes
Risky Bulletin: Hacker brea

Between Two Nerds: Hackers vs the state
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether hacker culture is inherently anti-authoritarian and how different states get their country’s hackers to work for the state.
This episode is also available on YouTube.
Show notes
D

Risky Bulletin: Anthropic models also did the hacky-hacky
Anthropic models also did the hacky-hacks, Coldcard was hacked for $70 million in Bitcoin, npm adds publish-time malware scanning, and Russia is behind the recent hotel WiFi hacks.
Show notes
Risky Bulletin: Russia is behind the recent hotel WiFi hacks

Sponsored: The intrusion signals hiding in plain sight
In this sponsored interview James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments.
Ian explains how ordinary-looking events such as a password reset, a new MFA device, unusual searches and a first-time AWS role assumption can combine to reveal an intrusion. Permiso’s platform connect

Risky Bulletin: Crime Stoppers puts bounty on INC ransomware group
A non-profit puts a $22,000 bounty on the INC ransomware group, hackers breach the UK Department for Education, Russia charges Telegram founder Pavel Durov, and the FCC bans foreign robots and power inverters.
Show notes
Risky Bulletin: Non-profit offers $22,

Srsly Risky Biz: Chipping away at Chinese AI risks
Tom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let’s not forget that America’s overriding goal is to remain ahead of China in the AI race. There are better ways to do that than overindexing on distillation.
They also discuss Iranian attacks on US cri

Risky Bulletin: Cyberattack disrupts Minnesota water utilities
A cyberattack has disrupted water utilities in more than 30 communities in Minnesota, Denmark tests a secondary banking system in case of a cyberattack, North Korea arrests bank hackers, and a new Chinese cyber contractor has been identified.
Show notes
Risky

Between Two Nerds: Cyber is people
In this edition of Between Two Nerds Tom Uren and The Grugq discuss how important people are to cyber power and whether the rise of AI is changing that.
This episode is also available on YouTube.
Show notes
Hugging Face incident

Risky Bulletin: A JSON RCE bug is about to rock the Java world
A JSON bug is about to rock the Java world, scam compounds continue in Myanmar despite the junta crackdown, and Google has a new APT naming scheme.
Show notes
Risky Bulletin: A JSON RCE bug is about to rock the Java world

Sponsored: How AI is putting pressure on EDR
In this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections.
LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by “burn

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and Google adds selfie video to its login options.
Show notes
Risky Bulletin: Western cyber agencies warn of Russian hacks of

Srsly Risky Biz: Knives are out for open-weight AI models
Tom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them.
They also talk about arrests of several members of the Scattered Spider juvenile cybercrime collective.
This episode is also available on YouTube

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach
Rogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.
Show notes

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine
In this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine.
This episode is also available on YouTube.
Show notes
Cyber Lessons from Russia's War i

Risky Bulletin: Hacker wipes Romania's entire land registry database
A hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress.
Show notes

Sponsored: Thinkst on building companies that don’t suck
In this Risky Business sponsor interview Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keepi

Srsly Risky Biz: Ransomware uses AI to amp up negotiations
Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations.
They also discuss the ever so many bugs being patched. This is good for organisations that patch, but it will

Between Two Nerds: Exploits are not cyber power
In this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency.
This episode is also available on YouTube.
Show notes

Risky Bulletin: NSA Tailored Access Operations is back
The NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor.
The Risky Bulletin newsletter and podcast will be on an editorial break until July 20.
Show notes

Sponsored: Why Sublime doesn’t toss AI at every email
In this Risky Business sponsored interview, Tom Uren chats with Sublime Security Product Manager AJ Williams about how the company targets its AI use. Rather than throwing its AI agents at everything, Sublime gives them the time-consuming email security tasks that humans don’t want to do.
Its ASA (Autonomous Security Analyst) agent investigates suspicious and user-r

Srsly Risky Biz: US Supreme Court undermines Section 702 intel
Tom Uren and James Wilson talk about a new US Supreme Court decision that puts the current EU-US data sharing agreement at risk. American intelligence collection efforts have been at the centre of legal challenges of these on-again off-again data transfer agreements, and if the current agreement were struck down it would cripple Section 702 collection from Europe.
T

Risky Bulletin: DHS IG investigates forced CISA reassignments
The DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels.
Show notes
Risky Bulletin: All new ca

Between Two Nerds: Why AI has not meant more hacks. Yet.
In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs.
This episode is also available on YouTube.
Show notes
Jerry Gamblin |

Risky Bulletin: EU official’s phone infected with Pegasus
A European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel.
Show notes
Risky Bulletin: Android dr

Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
FatFs bugs enable physical access attacks on industrial equipment, a clever password spraying attack bypasses M365 MFA, an AI agent is deploying ransomware in live attacks, and a webinar platform sues two security firms over bad IOCs.
Show notes
Risky Bulleti

Srsly Risky Biz: America won't beat the distillation ecosystem
Tom Uren and James Wilson talk about Chinese AI labs stealing the special sauce of American AI models in ‘distillation attacks’. These attacks are fed by a grey market in which Chinese consumers buy access to American models, where one of the byproducts is logs of user requests and responses. These make wonderful inputs into distillation attacks and the whole market

Risky Bulletin: Researcher drops giant cache of zero-days
An anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts geofence warrants, and security firm Huntress has denied accusations of a malicious insider.
Show notes
Risky Bulletin:

Between Two Nerds: Set cyberspace ablaze
In this edition of Between Two Nerds, Tom Uren and The Grugq discuss whether cyber organisations should actually be separated from Signals Intelligence organisations. The Grugq argues that having cyber expertise subordinate to intelligence collection means that many opportunities are never explored.
This episode is also available on YouTube.

Risky Bulletin: White House asks OpenAI to restrict GPT 5.6
The White House asks OpenAI to keep a tight grip on ChatGPT 5.6, the US Secret Service made some appalling OpSec mistakes, AMD has reintroduced a CPU security feature after consumer backlash, and an Iranian APT operator has been arrested in Montenegro.
Show notes

Sponsored: Corelight’s blueprint for AI-era defence
In this sponsored interview James Wilson chats with Corelight’s VP of Product Vijit Nair about defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance between proactive and reactive measures.
On the proactive side, you need modelling of assets and threats. On the reactive side you’ll need telemetry so

Risky Bulletin: Operation Endgame dismantles Amadey and StealerC
Law enforcement dismantles two more malware operations, Japan’s army used infected USB drives, Anthropic accuses Alibaba of distillation attacks, and Australia finds “digital dynamite” on critical networks.
Show notes
Risky Bulletin: Law enforcement agencies

Srsly Risky Biz: Open weight models make the Mythos debate moot
Tom Uren and James Wilson talk about the Five Eyes cyber security agencies warning about the arrival of AI-enabled cyber threats. The call-to-action is driven by the recognition that it is no longer possible to limit AI’s offensive cyber security capabilities to benign actors. The genie is out of the bottle, regardless of export controls on frontier models.
They als

Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing
The FortiBleed hacks are worse than a credentials leak, a new White House executive order sets out a hard 2031 post quantum cryptography deadline, Meta leaks employee keystroke data, and a third of Samsung and LG TVs act as proxies.
Show notes
Risky Bulletin:

Sponsored: Trail of Bits and OpenAI patch the planet
In this sponsored interview James Wilson chats with Trail of Bits founder and CEO Dan Guido about its newly announced partnership with OpenAI. Together, they’ve started a new initiative called “Patch the Planet” to support open source maintainers.
Being an open source maintainer is more difficult than ever. Just using frontier models to keep up with all the bug repo

Between Two Nerds: The PRC vs AI
In this edition of Between Two Nerds Tom Uren and The Grugq discuss the idea that the People’s Republic of China has mobilised its influence operations against the construction of US data centres and its build out of AI capacity.
This episode is also available on YouTube.
Show notes

Risky Bulletin: Klue breach impacts security firms
A data breach at business analytics platform Klue spreads to security firms, a hacker breaches Brazil’s national alert system, North Koreans are behind the Mastra supply chain attack, and a new, unfixable vulnerability has been found in Apple’s A12 and A13 chips.
Show notes

Risky Bulletin: Creds for 74,000 Fortinet devices leaked
A LOT of Fortinet creds have leaked online, Canada’s spy agency allowed to remove a botnet from Canadian devices, a supply chain attack hits the Mastra AI framework, and Europol disrupts SocGolish.
Show notes
Risky Bulletin: Canada’s spy agency allowed to rem

Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligence
Tom Uren and James Wilson talk about Anthropic rolling out its latest models only to have them effectively banned by the US government within days. Although the administration’s process for assessing new models is, ahem, amorphous, Anthropic is doing itself no favours by dismissing its concerns. The company needs to show some emotional intelligence and learn how to m

Risky Bulletin: China arrests Silver Fox cybercrime group suspects
66 members of the Silver Fox cybercrime group arrested in China, the EU will help Ukraine in the event of a major cyberattack, MS-ISAC loses 70% of its members after a DHS funding cut, and S-BOMs are still not widely adopted.
Show notes
Risky Bulletin: China

Between Two Nerds: Why NATO and cyber don't mix
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how NATO is set up to deter conventional conflict, and how that approach is fundamentally unsuited for ongoing, everyday cyber operations that are intended to confound adversaries.
This episode is also available on YouTube.
Show notes

Risky Bulletin: Arch Linux supply chain attack hits 1,900 packages
Almost 2,000 Arch Linux packages have been infected with malware in a supply chain attack, FISA surveillance powers expire for the first time since 2008, the FBI takes down a Chinese phishing service, and a major supply chain attack hits the WordPress ecosystem.
Show notes

Sponsored: Ent on using AI to track human behavior on the endpoint
In this Risky Business sponsored interview, Catalin Cimpanu talks with Brandon Dixon, co-founder and CTO of Ent AI, about the company’s innovative use of local LLMs to track user behavior on the endpoint, and add context to suspicious events to detect or prevent malicious activity.
Show notes

Risky Bulletin: CISA tightens patching rules amid bug deluge
CISA changes federal patching rules due to AI, a House Republican was hacked by Russia, ShinyHunters go on an Oracle hacking spree, and npm will block auto-run install scripts by default.
Show notes
Risky Bulletin: In the age of AI, CISA changes federal patch

Sponsored: Understanding CI/CD attack paths
In this sponsored episode, James Wilson chats with SpecterOps CTO Jared Atkinson about the central role that GitHub has played in recent supply chain compromises. GitHub is where code gets built, tested, and shipped to devices, cloud, and on-prem environments. Understanding the paths an attacker can use to get into GitHub, and where they can pivot to from there, is e

Srsly Risky Biz: Europe wants to wean itself off US tech
Tom Uren and James Wilson talk about the European Union’s digital sovereignty push. A divorce from US tech giants is on the cards, but building sovereign infrastructure and chip capacity will be hard. From an American perspective this is an entirely predicable own-goal. You can have internationally competitive tech giants or you can have an aggressive and coercive fo

Risky Bulletin: Nightmare Eclipse drops fresh 0day
Nightmare Eclipse drops a fresh zero day, Meta says NSO is targeting WhatsApp users again, hackers breach France’s Tchap secure messenger network, Putin disables some Kremlin security cameras, and Gmail be gone! Russia bans logins from foreign email addresses.
Show notes

Between Two Nerds: Nerds at NATO
In this edition of Between Two Nerds Tom Uren and The Grugq speak at the NATO CyCon conference on Cyber Conflict in Tallinn, Estonia. The pair discuss how cyber operations complement conventional military operations and the past, present and future of cyber conflict.
This episode is also available on YouTube.
Show n

Risky Bulletin: RubyGems adds dependency cooldowns to counter supply chain attacks
RubyGems adds dependency-cooldowns to counter supply chain attacks, AT&T and IBM are accused of hiding foreign hacks, Cisco warns of a new SD-WAN zero-day, and Google layoffs hit security teams.
Show notes
Risky Bulletin: RubyGems adds dependency cooldown

Risky Bulletin: EU unveils digital sovereignty plan
The EU unveils its digital sovereignty plan, an American law firm pays a $20 million ransom, authorities take down millions of email and social media scam accounts, and a new DoS bug can crash servers within seconds.
Show notes
Risky Bulletin: The EU debuts d

Srsly Risky Biz: NATO's cyber approach needs to change
Tom Uren and James Wilson talk about Tom’s trip to NATO’s Cyber Conflict conference. NATO countries want to bulk up their cyber efforts, and the pair discuss what that could look like.
They also look at the US military’s admission that commercial location data was used to target personnel involved in Epic Fury, the US war on Iran. This is not surprising at all, and

Risky Bulletin: FSB calls out Western spyware operation
Russia’s FSB calls out a Western spyware operation, high-profile Instagram accounts hijacked via Meta’s AI support agents, Red Hat npm packages were compromised in another supply chain attack, and ten percent of domains registered last year were malicious.
Show notes

Between Two Nerds: The intelligence cult
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the ways in which intelligence agencies are just like cults.
This episode is also available on YouTube
Show notes

Risky Bulletin: Recently patched PAN 0day exploited in the wild
A new Palo Alto Networks firewall bug is being exploited in the wild, Russia expands SORM surveillance, NIST is looking for new post quantum algorithms, and ENSOC launches in Europe.
Show notes
Risky Bulletin: Russia greatly expands SORM surveillance requirem

Sponsored: Inside CISA's disastrous secrets leak
In this sponsored interview Casey Ellis chats with Truffle Security’s founder and CEO Dylan Ayrey about the recent CISA secrets leak.
Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA’s org.
Dylan walks through why deleting the repo doesn’t fix anything, why mo

Risky Bulletin: Dutch police take down 17m device botnet
Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer is arrested for insider trading on Polymarket, and Gogs and the Casdoor IAM leave major bugs unpatched.
Show notes
Risky B

Risky Bulletin: Iran to reconnect to the Internet
Iran will reconnect to the Internet, a new vulnerability lets attackers bypass authentication on AI infrastructure, hackers breach Lithuania’s state registry, security firms take down the Glassworm botnet, and CERT India releases strict patching advice.
Show notes

Risky Bulletin: Mythos has found thousands of critical bugs
Anthropic says Mythos has found thousands of critical bugs, hackers leak documents from a Russian disinfo group, GitHub rolls out new npm security features, and Dutch police raid two bulletproof hosting providers.
Show notes
Risky Bulletin: Mythos has found t

Sponsored: Teaching AI agents the rules of the road
In this sponsored interview James Wilson chats with Sondera CEO Josh Devon about why guardrails and instruction files aren’t enough to keep AI agents from going haywire. EDR, DLP and other traditional controls can’t and won’t prevent agents from going rogue.
Josh explains Sondera’s “principle of least autonomy” for agents: let them do useful work, but put them in a

Risky Bulletin: Microsoft ends SMS MFA for personal accounts
Microsoft ends support for SMS MFA on personal accounts, GitHub was hacked via a malicious VS Code extension, CISA will let researchers submit new KEV entries, and an SMS blaster was detained at Eurovision.
Show notes
Risky Bulletin: Microsoft ends SMS MFA fo

Srsly Risky Biz: Politicians ditch Signal for homegrown apps
Tom Uren and James Wilson talk about moves from several European governments to ditch Signal and set up their own encrypted messaging systems for internal government use. These efforts are motivated by concerns about phishing and sovereignty, but the solutions being adopted are imperfect and will come with their own set of problems. Signal fills a space that can’t be

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs
Microsoft disrupts a malware-signing service used by ransomware gangs, a CISA contractor leaks sensitive GovCloud keys, vulnerability exploitation is now the dominant network entry vector, and Drupal readies security updates for a “highly critical” vulnerability.
Show notes

Between Two Nerds: Russia's hacker university
In this edition of Between Two Nerds Tom Uren and The Grugq look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russia’s cyber program and look

Risky Bulletin: Indonesia emerges as a new hub for cyber scams
Indonesia emerges as a new cyber scam hub, Grafana got hacked and held for ransom, the Fast16 malware subverted software used to simulate nuclear explosions, and a new Microsoft Exchange zero-day is under attack.
Show notes
Risky Bulletin: Indonesia emerges a

Sponsored: Push Security goes AI threat hunting in browser telemetry
In this sponsored interview James Wilson chats with Push Security’s Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform.
Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers.

Risky Bulletin: Shai-Hulud goes open-source
The source code for the Shai-Hulud worm has been released online, a dark web market admin was charged after a major OPSEC failure, France investigates an Israeli disinfo firm, and ‘Composer’ rushes to fix a GitHub token leak.
Show notes
Risky Bulletin: Shai-H
Recommended

English Vocabulary Help

این نقطه

Solved Murders - True Crime Stories

紐約鳥|New York Aperture

Doctor Zhivago Slow Read

Apple News In Conversation

The Young and Called Podcast .

Jubal Phone Pranks from The Jubal Show

پلی لیست | PlayList

English with Olivia | Slow Conversations & Vocabulary

Bible Tea

TED Talks Daily