惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
B
Blog RSS Feed
MyScale Blog
MyScale Blog
博客园_首页
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
小众软件
小众软件
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
Hugging Face - Blog
Hugging Face - Blog
The GitHub Blog
The GitHub Blog
D
Docker
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
F
Fortinet All Blogs
V
V2EX
Last Week in AI
Last Week in AI
Blog — PlanetScale
Blog — PlanetScale
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
雷峰网
雷峰网
博客园 - 叶小钗
月光博客
月光博客
J
Java Code Geeks
量子位
爱范儿
爱范儿
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
H
Help Net Security
酷 壳 – CoolShell
酷 壳 – CoolShell
腾讯CDC
Latest news
Latest news
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
美团技术团队
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
T
Troy Hunt's Blog
B
Blog
T
Tenable Blog
S
Schneier on Security
L
LangChain Blog
L
LINUX DO - 热门话题
博客园 - 司徒正美
I
InfoQ
P
Privacy International News Feed
P
Privacy & Cybersecurity Law Blog

Risky Business Media

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine Risky Bulletin: Hacker wipes Romania's entire land registry database Sponsored: Thinkst on building companies that don’t suck Srsly Risky Biz: Ransomware uses AI to amp up negotiations Fortibleed: The bleeding edge of AI cybercrime Between Two Nerds: Exploits are not cyber power What to do 'til the bugpocalypse gets here Risky Bulletin: NSA Tailored Access Operations is back Sponsored: Why Sublime doesn’t toss AI at every email Srsly Risky Biz: US Supreme Court undermines Section 702 intel Risky Bulletin: DHS IG investigates forced CISA reassignments Soap Box: Using threat hunting to drive detection Between Two Nerds: Why AI has not meant more hacks. Yet. Risky Bulletin: EU official’s phone infected with Pegasus Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices Srsly Risky Biz: America won't beat the distillation ecosystem Risky Bulletin: Researcher drops giant cache of zero-days Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban Mythos on your desk? Using local LLMs for code reviews Between Two Nerds: Set cyberspace ablaze Risky Bulletin: White House asks OpenAI to restrict GPT 5.6 Sponsored: Corelight’s blueprint for AI-era defence Risky Bulletin: Operation Endgame dismantles Amadey and StealerC Srsly Risky Biz: Open weight models make the Mythos debate moot Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing Risky Business #843 -- Fortibleed is kinda awesome, actually Pitching security startups to VCs in the AI era Sponsored: Trail of Bits and OpenAI patch the planet Between Two Nerds: The PRC vs AI Risky Bulletin: Klue breach impacts security firms How using open weight models can blow up in your face Risky Bulletin: Creds for 74,000 Fortinet devices leaked Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligence Risky Bulletin: China arrests Silver Fox cybercrime group suspects Risky Business #842 -- Anthropic needs an adult in the C suite The state of the art in AI model jailbreaks Between Two Nerds: Why NATO and cyber don't mix Risky Bulletin: Arch Linux supply chain attack hits 1,900 packages Sponsored: Ent on using AI to track human behavior on the endpoint Why NPM v12 won’t stop supply chain attacks Risky Bulletin: CISA tightens patching rules amid bug deluge Sponsored: Understanding CI/CD attack paths Srsly Risky Biz: Europe wants to wean itself off US tech Risky Bulletin: Nightmare Eclipse drops fresh 0day Risky Business #841 -- Microsoft gets owned and 0day'd Between Two Nerds: Nerds at NATO Risky Bulletin: RubyGems adds dependency cooldowns to counter supply chain attacks Everything is getting much worse, much faster Soap Box: Detection and response in the AI age Risky Bulletin: EU unveils digital sovereignty plan Srsly Risky Biz: NATO's cyber approach needs to change Risky Bulletin: FSB calls out Western spyware operation Risky Business #840 -- Microsoft walks back researcher threats Solo podcast: A deep dive on TeamPCP Between Two Nerds: The intelligence cult Risky Bulletin: Recently patched PAN 0day exploited in the wild Sponsored: Inside CISA's disastrous secrets leak Risky Bulletin: Dutch police take down 17m device botnet Risky Bulletin: Iran to reconnect to the Internet How to survive supply chain attacks Risky Bulletin: Mythos has found thousands of critical bugs Sponsored: Teaching AI agents the rules of the road Risky Bulletin: Microsoft ends SMS MFA for personal accounts How the CopyFail disclosure went sideways Risky Business #838 -- GitHub investigates possible breach
Risky Business #839 -- TeamPCP stole GitHub's internal repos
James Wilson · 2026-05-27 · via Risky Business Media

Risky Business Podcast

May 27, 2026

Presented by

James Wilson

James Wilson

Technology Editor

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • TeamPCP breached GitHub’s internal repos. Now what?
  • Some absolute plonker glued Coruna to a hijacked npm package
  • CISA is worried about about open source and wants third party submissions for KEV
  • AI infrastructure is “systemically” insecure
  • Much, much more

This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun!

This episode is also available on YouTube

Your browser does not support the audio element.

Risky Business #839 -- TeamPCP stole GitHub's internal repos

0:00 / 60:23

Subscribe  

Logo

Airlock Digital Logo

Brought to you by Airlock Digital

Allowlisting Software - Allowlist Made Simple

Show notes

GitHub confirms being hacked by TeamPCP, says customer data unaffected | therecord.media

Grafana Labs links GitHub environment breach to TanStack npm supply chain attack | Cybersecurity Dive

Coruna Respawned: Compromised art-template npm Package Leads... | Socket

CISA chief frets about open-source vulnerabilities, delayed security improvements | cyberscoop.com

Anthropic: Mythos finds more than 10,000 software flaws in first month | cyberscoop.com

Pardon MIE? | ironPeak Blog

CISA asks cybersecurity community to alert it to vulnerability exploitation | Cybersecurity Dive

Lawmakers Demand Answers as CISA Tries to Contain Data Leak | krebsonsecurity.com

Google publishes exploit code threatening millions of Chromium users | arstechnica.com

Millions of AI agents imperiled by critical vulnerability in open source package | arstechnica.com

Discord migrates all users to end-to-end encryption by default | The Record

Texas AG sues Meta over claims that WhatsApp doesn't provide end-to-end encryption | arstechnica.com

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada | krebsonsecurity.com

Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages | Cybersecurity Dive

FBI warns about fast-growing phishing kit targeting Microsoft 365 users | cyberscoop.com

Analyzing the rise in device code phishing attacks in 2026 | Push Security

Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses | TechCrunch Security

Kash Patel’s clothing brand website shut down after reports it was hacked | TechCrunch Security

Tulsi Gabbard resigns as US director of national intelligence | Social Signals

When Certificate Trust Fails: The DigiCert Code-Signing Incident and Microsoft Defender False Positive |