惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
博客园 - 司徒正美
D
DataBreaches.Net
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
腾讯CDC
博客园_首页
The Cloudflare Blog
S
SegmentFault 最新的问题
C
Check Point Blog
美团技术团队
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
T
The Blog of Author Tim Ferriss
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack
Risky Business #806 -- Apple's Memory Integrity Enforceme...
Adam Boileau · 2025-09-10 · via Risky Business

Risky Business Podcast

September 10, 2025

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Apple ruins exploit developers’ week with fresh memory corruption mitigations
  • Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack
  • Salesloft says its GitHub was the initial entry point for its compromise
  • Sitecore says people should “patch” its using-the-keymat-from-the-documentation “zero day”
  • Rogue certs for 1.1.1.1 appear to be just (stupid) testing
  • Jaguar Land Rover ransomware attackers are courting trouble

This week’s episode is sponsored by open source cloud security tool, Prowler. Founder Toni de la Fuente joins to discuss their new support for Microsoft 365. Time to point Prowler at your OneDrive and Sharepoint!

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal

0:00 / 51:42

Subscribe  

Logo

Prowler Logo

Brought to you by Prowler

Opensource cloud security tool

Show notes

Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research

Venezuela's president thinks American spies can't hack Huawei phones | TechCrunch

18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security

Software packages with more than 2 billion weekly downloads hit in supply-chain attack - Ars Technica

Salesloft platform integration restored after probe reveals monthslong GitHub account compromise | Cybersecurity Dive

CISA orders federal agencies to patch Sitecore zero-day following hacking reports | The Record from Recorded Future News

SAP warns of high-severity vulnerabilities in multiple products - Ars Technica

The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest. - Ars Technica

Cyberattack on Jaguar Land Rover threatens to hit British economic growth | The Record from Recorded Future News

Cyberattack forces Jaguar Land Rover to tell staff to stay at home | The Record from Recorded Future News

Bridgestone Americas continues probe as it looks to restore operations | Cybersecurity Dive

Qantas penalizes executives for July cyberattack | The Record from Recorded Future News

Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat' | The Record from Recorded Future News

GOP Cries Censorship Over Spam Filters That Work – Krebs on Security

Risky Bulletin: APT report? No, just a phishing test! - Risky Business Media

Post by @patrick.risky.biz — Bluesky