惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
爱范儿
爱范儿
小众软件
小众软件
MyScale Blog
MyScale Blog
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
V
V2EX
量子位
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
C
Check Point Blog
月光博客
月光博客

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack
Risky Business #797 -- Stuxnet vs Massive Ordnance Penetr...
Adam Boileau · 2025-06-25 · via Risky Business

Risky Business Podcast

June 25, 2025

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • We roll our eyes over the “16 billion credentials” leak hitting mainstream news
  • Some interesting cyber angles emerge from the conflict in Iran
  • Opensource maintainer of libxml2 is fed up with this hacker crap
  • Shockingly, there are yet more ways to trick people into pasting commands into Windows
  • Veeam “patches” its backup software RCE like it’s 2002 … by breaking the public PoC

This week’s episode is sponsored by Internet-wide honeypot reconnaissance platform, Greynoise. Founder Andrew Morris joins to talk about their journey spotting Chinese ORB-builders hacking thousands of ASUS routers, and why they’re destined for the woodchipper.

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators

0:00 / 62:16

Logo

Show notes

No, the 16 billion credentials leak is not a new data breach

Canadian telecom hacked by suspected China state group - Ars Technica

Telecom giant Viasat breached by China's Salt Typhoon hackers

WarTranslated on X: "Iran’s jamming GPS in the Strait of Hormuz, messing with ~970 ships, per Windward. UKMTO confirms the interference. Faulty AIS coordinates are screwing up navigation in the Persian Gulf. The IRGC threatens to shut the strait down in hours. https://t.co/kdMJvshOGC" / X

Dmitri Alperovitch on X: "Chairman of the Joint Chiefs Gen. Dan Caine says @US_CYBERCOM supported this strike mission" / X

Top Pentagon spy pick rejected by White House - POLITICO

DHS warns of heightened cyber threat as US enters Iran conflict | Cybersecurity Dive

Exclusive: Early US intel assessment suggests strikes on Iran did not destroy nuclear sites, sources say

U.S. braces for Iran's response after overnight strikes on nuclear sites

Assessing the Damage to Iran’s Nuclear Program

Iran Hacks Tirana Municipality in Retaliation Over MEK - Tirana Times

Iran's government says it shut down internet to protect against cyberattacks | TechCrunch

Aflac discloses cyber intrusion linked to wider crime spree targeting insurance industry | Cybersecurity Dive

Tonga Ministry of Health hit with cyberattack affecting website, IT systems | The Record from Recorded Future News

Alleged Ryuk ransomware gang member arrested in Ukraine and extradited to US | The Record from Recorded Future News

Russia releases REvil members after convictions for payment card fraud | The Record from Recorded Future News

OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys - SpecterOps

Triaging security issues reported by third parties (#913) · Issue · GNOME/libxml2

README: Set expectations straight (35d04a08) · Commits · GNOME / libxml2 · GitLab

What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog

FileFix - A ClickFix Alternative | mr.d0x

Address bar shows hp.com. Browser displays scammers’ malicious text anyway. - Ars Technica

Researchers urge vigilance as Veeam releases patch to address critical flaw | Cybersecurity Dive

ASUSpicious Flaw - Millions of Users’ Information Exposed Since 2022 | MrBruh's Epic Blog

Perth dad who created ‘evil twin’ Wi-Fi did so to access pictures of women

GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers