惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
量子位
D
DataBreaches.Net
博客园 - 司徒正美
J
Java Code Geeks
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
B
Blog
The Cloudflare Blog
D
Docker
I
InfoQ
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
腾讯CDC
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
Vercel News
Vercel News
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
S
SegmentFault 最新的问题
GbyAI
GbyAI
有赞技术团队
有赞技术团队

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack Risky Biz Soap Box: Graph the planet!
Risky Business #820 -- Asian fraud kingpin will face Chin...
Adam Boileau · 2026-01-14 · via Risky Business

Risky Business Podcast

January 14, 2026

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

Risky Business returns for 2026! Patrick Gray and Adam Boileau talk through the week’s cybersecurity news, including:

  • Santa brings hackers MongoDB memory leaks for Christmas
  • Vercel pays out a million bucks to improve its React2Shell WAF defences
  • 39C3 delivers; the pink Power Ranger deletes nazis, while a catgirl ruins GnuPG
  • Cambodian scam compound kingpin gets extradited to China, and we don’t think it’ll go well for him
  • Krebs picks apart the Kimwolf botnet and residential proxy networks
  • So many healthcare data leaks that we have a roundup section

This week’s episode is sponsored by Airlock Digital. The founders of the application allow-listing vendor, David Cottingham and Daniel Schell, discuss Microsoft’s ClickOnce .NET app packaging, and how attackers have been abusing it to load code. Airlock hates it when you load code!

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!)

0:00 / 59:15

Logo

Show notes

US, Australia say ‘MongoBleed’ bug being exploited | The Record from Recorded Future News

Merry Christmas Day! Have a MongoDB security incident. | by Kevin Beaumont | Dec, 2025 | DoublePulsar

Inside Vercel’s sleep-deprived race to contain React2Shell | CyberScoop

gpg.fail

Hacktivist deletes white supremacist websites live onstage during hacker conference | TechCrunch

Chinese attackers exploiting zero-day to target Cisco email security products | The Record from Recorded Future News

Ni8mare  -  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) | Cyera Research Labs

ServiceNow patches critical AI platform flaw that could allow user impersonation | CyberScoop

Alleged cyber scam kingpin arrested, extradited to China | The Record from Recorded Future News

FCC IoT labeling program loses lead company after China probe | Cybersecurity Dive

Trump picks Lt. Gen. Joshua Rudd to lead NSA spy agency - The Washington Post

NSA cyber directorate gets new acting leadership | The Record from Recorded Future News

Dutch court sentences hacker who used port systems to smuggle cocaine to 7 years | The Record from Recorded Future News

ECLI:NL:GHAMS:2026:22, Amsterdam Court of Appeal, 23-003218-22

The Kimwolf Botnet is Stalking Your Local Network – Krebs on Security

Who Benefited from the Aisuru and Kimwolf Botnets? – Krebs on Security

Coupang recovers smashed laptop that alleged data leaker threw into river | The Record from Recorded Future News

Ransomware responders plead guilty to using ALPHV in attacks on US organizations | The Record from Recorded Future News

Nearly 480,000 impacted by Covenant Health data breach | The Record from Recorded Future News

Illinois health department exposed over 700,000 residents' personal data for years | TechCrunch

Tech provider for NHS England confirms data breach | TechCrunch

Hacker claiming to be behind ManageMyHealth breach: ‘I do it for the money and I’m in negotiations to get it’ - NZ Herald