惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
U
Unit 42
人人都是产品经理
人人都是产品经理
罗磊的独立博客
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
aimingoo的专栏
aimingoo的专栏
T
Tailwind CSS Blog
GbyAI
GbyAI
Blog — PlanetScale
Blog — PlanetScale
I
InfoQ
Last Week in AI
Last Week in AI
宝玉的分享
宝玉的分享
B
Blog RSS Feed
WordPress大学
WordPress大学
腾讯CDC
H
Help Net Security
博客园 - Franky
博客园 - 【当耐特】
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
B
Blog
Vercel News
Vercel News
博客园 - 司徒正美

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack Risky Biz Soap Box: Graph the planet!
Risky Business #831 -- The AI bugpocalypse begins
James Wilson · 2026-04-01 · via Risky Business

Risky Business Podcast

April 01, 2026

Presented by

James Wilson

James Wilson

Technology Editor

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package
  • TeamPCP appear to have ransacked Cisco’s source and cloud environments
  • AI is getting legitimately good at being told to “just go find some 0day in this”
  • Kaspersky says Coruna and Triangulation do share code lineage
  • Iranian hackers dump Kash Patel’s gmail spool
  • Oh, and of course there’s a Citrix Netscaler memory leak being exploited in the wild

This week’s episode is sponsored by Dropzone AI, who make automated AI SOC analysts. Head honcho Ed Wu explains how they’ve built pre-canned ‘hunt packs’ to lead the AI off into your environment to find weird, interesting and security relevant things.

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #831 -- The AI bugpocalypse begins

0:00 / 59:40

Logo

Show notes

Google links axios supply chain attack to North Korean group | The Record from Recorded Future News

Cisco source code stolen in Trivy-linked dev environment breach

chiefofautism on X: "someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo"

h0mbre on X: "Claude is somehow better at kernel exploitation than creating meal plans."

Vulnerability Research Is Cooked — Quarrelsome

MAD Bugs: vim vs emacs vs Claude - Calif

MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)

A Risky Biz Experiment: Hunting for iOS 0day with AI - Risky Business Media

Security leaders say the next two years are going to be 'insane' | CyberScoop

Coruna framework: an exploit kit and ties to Operation Triangulation | Securelist

Apple says no one using Lockdown Mode has been hacked with spyware | TechCrunch

Reverse engineering Apple’s silent security fixes - Calif

Jury finds Meta's platforms are harmful to children in 1st wave of social media addiction lawsuits | PBS News

Meta and YouTube found liable in social media addiction trial

Iranian hackers publish emails allegedly stolen from Kash Patel

Iran Us War: 'Legitimate targets': Iran issues warning to US tech firms including Google, Amazon, Microsoft, Nvidia - The Times of India

Drop Site on X: "IRGC: From now on, for every assassination, an American company will be destroyed"

OSINTtechnical on X: "Starlink shutdowns are forcing Russian troops even deeper into Ubiquiti’s ecosystem. "

Citrix NetScaler products confirmed to be under exploitation | Cybersecurity Dive

CISA tells federal agencies to patch Citrix NetScaler bug by Thursday | The Record from Recorded Future News

Using a VPN May Subject You to NSA Spying | WIRED

Post reporters called the White House. Their phones showed ‘Epstein Island.’ - The Washington Post