惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
量子位
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
B
Blog
U
Unit 42
C
Check Point Blog
I
InfoQ
aimingoo的专栏
aimingoo的专栏
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
云风的 BLOG
云风的 BLOG
宝玉的分享
宝玉的分享
爱范儿
爱范儿

Risky Business Media

Srsly Risky Biz: Trump's private hacker memo is the right idea Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras Risky Business #849 -- Trump will unleash contractors on cybercriminals Between Two Nerds: The eye of Sauron James Kettle on inventing new attack techniques with LLMs Risky Bulletin: The EU publishes its upcoming cybersecurity standards Sponsored: What npm 12 fixes… and what it doesn’t Risky Bulletin: US will let private companies carry out offensive cyber ops Soap Box: Zero Trust(ish) Networks Srsly Risky Biz: Data extortion is booming. Hooray! Risky Business #848 -- OpenAI comes clean Risky Bulletin: Russian hackers jump on the fake job interview train Between Two Nerds: The cyber resistance! Risky Bulletin: Two law firms pay giant ransoms Sponsored: Island's expansion to SASE and enterprise AI How private LLM inference actually works Risky Bulletin: A Meta AI model also escaped a testing sandbox Srsly Risky Biz: Being a North Korean hacker is about to be less fun Risky Bulletin: Hacker breaches Hungary's State Treasury Between Two Nerds: Hackers vs the state Risky Bulletin: Anthropic models also did the hacky-hacky Sponsored: The intrusion signals hiding in plain sight Risky Bulletin: Crime Stoppers puts bounty on INC ransomware group Srsly Risky Biz: Chipping away at Chinese AI risks Risky Bulletin: Cyberattack disrupts Minnesota water utilities Risky Business #846 -- OpenAI built a fireplace out of wood Benchmarks, borders and the true cost of AI regulation Between Two Nerds: Cyber is people Risky Bulletin: A JSON RCE bug is about to rock the Java world Sponsored: How AI is putting pressure on EDR
Risky Business #847 -- Oops! Claude's accidental hacking ...
James Wilson · 2026-08-05 · via Risky Business Media

Risky Business Podcast

August 05, 2026

Presented by

James Wilson

James Wilson

Technology Editor

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including:

  • Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny
  • The bugpocalypse is so chaotic, Microsoft can’t patch fast enough
  • A ColdCard wallet flaw led to millions in Bitcoin theft, but the back story behind the bug is bonkers
  • Iran hacks and disrupts water infrastructure in multiple American states
  • North Korea’s state-backed hackers turn criminal. Or their criminals turn into state-backed hackers. Or something. It’s all a bit confusing, actually.
  • Much, much more!

This week’s show is brought to you by Sondera. Co-founder Josh Devon joins Patrick and James to talk through some absolutely hilarious LLM horror stories.

This episode is also available on YouTube

Your browser does not support the audio element.

Risky Business #847 -- Oops! Claude's accidental hacking spree

0:00 / 68:22

Logo

Show notes

OpenAI says rogue agent behind Hugging Face hack broke into additional services | therecord.media

Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests | wired.com

Claude uploaded malware to PyPI in Anthropic's botched test | BleepingComputer

Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal | wired.com

Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets Truffle Security Co. |

Anthropic’s New AI Model Can Identify More Software Bugs Than Ever. Microsoft Is Struggling to Fix Them Fast Enough. | Social Signals

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting | wired.com

Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI | TechCrunch Security

Mythos uncovers crypto weaknesses that went unknown for years | arstechnica.com

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft | BleepingComputer

Chris Masterjohn (@ChrisMasterjohn) on X | X (formerly Twitter)

wale.moca 🐳 (@waleswoosh) on X | X (formerly Twitter)

U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities | washingtonpost.com

FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems | washingtonpost.com

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world | cyberscoop.com

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran | wired.com

Russia accuses Telegram founder of aiding terrorism, seeks international arrest | The Record

Laundry Bear’s webmail hackers had more in store after February, report says | therecord.media

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog

Phishing service spoofs RingCentral to steal Microsoft 365 accounts | BleepingComputer

North Korean hackers behind major open-source supply chain attacks, Amazon says | therecord.media

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn | The Record

North Korea arrests hackers accused of laundering stolen bank funds through crypto |

US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security | TechCrunch Security

Judge says Trump admin still lacks evidence for Anthropic 'supply chain risk' label | TechCrunch

Cyber Command plans Silicon Valley office to drive innovation | therecord.media

Apple is getting this wrong | OpenAI

Tech industry alliance proposes AI agent safety reporting program | Cybersecurity Dive

Massive ChainDrop npm supply-chain attack infects hundreds of packages | BleepingComputer

Massive supply-chain attack compromises 440 packages under four hours | cyberscoop.com