惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Last Week in AI
Last Week in AI
H
Help Net Security
博客园 - 叶小钗
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
腾讯CDC
MongoDB | Blog
MongoDB | Blog
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
A
About on SuperTechFans
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
Martin Fowler
Martin Fowler
月光博客
月光博客
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
Vercel News
Vercel News

Risky Bulletin

Between Two Nerds: The intelligence cult Risky Bulletin: Recently patched PAN 0day exploited in the wild Risky Bulletin: Dutch police take down 17m device botnet Risky Bulletin: Iran to reconnect to the Internet Risky Bulletin: Mythos has found thousands of critical bugs Sponsored: Teaching AI agents the rules of the road Risky Bulletin: Microsoft ends SMS MFA for personal accounts Srsly Risky Biz: Politicians ditch Signal for homegrown apps Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs Between Two Nerds: Russia's hacker university Risky Bulletin: Indonesia emerges as a new hub for cyber scams Sponsored: Push Security goes AI threat hunting in browser telemetry Risky Bulletin: Shai-Hulud goes open-source Srsly Risky Biz: The AI Regulation Knife Fight Risky Bulletin: Damaging worm rips through npm ecosystem Between Two Nerds: The AI-first crime gang Risky Bulletin: FCC relaxes foreign router security patch ban Sponsored: Knocknoc built a Greynoise integration Risky Bulletin: State sponsored group exploits Palo 0day Srsly Risky Biz: After Mythos, US government weighs AI regulation Risky Bulletin: Targeted supply chain attack hits DAEMON Tools Between Two Nerds: The wild wild west Risky Bulletin: DigiCert hacked with a malicious screensaver file Sponsored: James Kettle built an AI hacker Risky Bulletin: cPanel auth bypass exploited in wild Srsly Risky Biz: US Vows to Fight Distillation Attacks Risky Bulletin: Ukrainians hacked Russian satellite comms platform Between Two Nerds: Hackers from the future Risky Bulletin: New fingerprinting technique can track Tor users Sponsored: RunZero accidentally got good at OT
Sponsored: Inside CISA's disastrous secrets leak
Casey Ellis · 2026-06-01 · via Risky Bulletin

Risky Bulletin Podcast

June 01, 2026

Presented by

Casey Ellis

Casey Ellis

Founder, Bugcrowd

In this sponsored interview Casey Ellis chats with Truffle Security’s founder and CEO Dylan Ayrey about the recent CISA secrets leak.

Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA’s org.

Dylan walks through why deleting the repo doesn’t fix anything, why most cloud vendors won’t hard-revoke exposed keys (OpenAI and Slack will; AWS, Google and friends mostly won’t), why Hugging Face datasets now hold more secrets than GitHub itself, and what the next generation of multi-provider credential-harvesting supply chain worms is going to look like.

Your browser does not support the audio element.

Sponsored: Inside CISA's disastrous secrets leak

0:00 / 19:10

Logo