惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
H
Help Net Security
Jina AI
Jina AI
V
V2EX
G
Google Developers Blog
B
Blog
GbyAI
GbyAI
U
Unit 42
爱范儿
爱范儿
腾讯CDC
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
宝玉的分享
宝玉的分享
小众软件
小众软件
D
DataBreaches.Net
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
博客园 - 聂微东
The Cloudflare Blog
I
InfoQ
Microsoft Azure Blog
Microsoft Azure Blog
Hugging Face - Blog
Hugging Face - Blog
大猫的无限游戏
大猫的无限游戏

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack Risky Biz Soap Box: Graph the planet!
Risky Business #836 -- You can't patch the bugpocalypse
James Wilson · 2026-05-06 · via Risky Business

Risky Business Podcast

May 06, 2026

Presented by

James Wilson

James Wilson

Technology Editor

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including:

  • The US Government says we just have to patch faster, but…
  • Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn’t enough
  • James gets mad about lame AI Agent adoption advice from the US and Australian Governments
  • James Kettle and Niels Provos both showed us that any model can find 0day like Mythos
  • And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars

This week’s show is sponsored by SpecterOps. Their CTO, Jared Atkinson, chats to Pat about the big changes in the threat landscape, brought about by AI, that are causing a pivot away from detection and remediation, and toward prevention.

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #836 -- You can't patch the bugpocalypse

0:00 / 61:56

Logo

Show notes

Exclusive: US officials weigh cutting deadlines to fix digital flaws amid worries over AI-powered hacking, sources say | Reuters

British cyber agency warns of looming ‘patch wave’ as AI speeds flaw discovery | The Record from Recorded Future News

Federal agencies must patch cPanel bug by Sunday, CISA says | The Record from Recorded Future News

cPanel zero-day exploited for months before patch release (CVE-2026-41940) - Help Net Security

The most severe Linux threat to surface in years catches the world flat-footed - Ars Technica

New MOVEit vulnerabilities prompt urgent patch warning | Cybersecurity Dive

US and allies urge ‘careful adoption’ of AI agents | Cybersecurity Dive

careful_adoption_of_agentic_ai_services.pdf

User just tricked Grok and Bankrbot to send tokens with Morse code - Cryptopolitan

Finding Zero-Days with Any Model

(1872) Sponsored: James Kettle built an AI hacker - YouTube

Feature Interview: Nicholas Carlini, Anthropic - Risky Business Media

Trellix investigating breach of source code repository | Cybersecurity Dive

Popular DAEMON Tools software compromised | Securelist

Komari Red: The Monitoring Tool with a Built-in Reverse Shell | Huntress

Hackers earning millions from hijacked cargo, FBI says | The Record from Recorded Future News

Congress punts FISA renewal to June | The Record from Recorded Future News

Cops Use Apple Data And Car Bluetooth To Identify Crypto Robbery Suspect

Stewart Baker, outspoken voice on cybersecurity and national security law, dies at 78 | IAPP