惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
B
Blog
博客园 - 三生石上(FineUI控件)
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
Vercel News
Vercel News
量子位
A
About on SuperTechFans
博客园 - 聂微东
WordPress大学
WordPress大学
D
DataBreaches.Net
The Cloudflare Blog
M
MIT News - Artificial intelligence
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
Docker
雷峰网
雷峰网
C
Check Point Blog
S
SegmentFault 最新的问题
U
Unit 42
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research

Risky Bulletin

Between Two Nerds: The intelligence cult Risky Bulletin: Recently patched PAN 0day exploited in the wild Risky Bulletin: Dutch police take down 17m device botnet Risky Bulletin: Iran to reconnect to the Internet Risky Bulletin: Mythos has found thousands of critical bugs Sponsored: Teaching AI agents the rules of the road Risky Bulletin: Microsoft ends SMS MFA for personal accounts Srsly Risky Biz: Politicians ditch Signal for homegrown apps Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs Between Two Nerds: Russia's hacker university Risky Bulletin: Indonesia emerges as a new hub for cyber scams Sponsored: Push Security goes AI threat hunting in browser telemetry Risky Bulletin: Shai-Hulud goes open-source Srsly Risky Biz: The AI Regulation Knife Fight Risky Bulletin: Damaging worm rips through npm ecosystem Between Two Nerds: The AI-first crime gang Risky Bulletin: FCC relaxes foreign router security patch ban Sponsored: Knocknoc built a Greynoise integration Risky Bulletin: State sponsored group exploits Palo 0day Srsly Risky Biz: After Mythos, US government weighs AI regulation Risky Bulletin: Targeted supply chain attack hits DAEMON Tools Between Two Nerds: The wild wild west Risky Bulletin: DigiCert hacked with a malicious screensaver file Sponsored: James Kettle built an AI hacker Risky Bulletin: cPanel auth bypass exploited in wild Srsly Risky Biz: US Vows to Fight Distillation Attacks Risky Bulletin: Ukrainians hacked Russian satellite comms platform Between Two Nerds: Hackers from the future Risky Bulletin: New fingerprinting technique can track Tor users Sponsored: RunZero accidentally got good at OT
Sponsored: Inside CISA's disastrous secrets leak
Casey Ellis · 2026-06-01 · via Risky Bulletin

Risky Bulletin Podcast

June 01, 2026

Presented by

Casey Ellis

Casey Ellis

Founder, Bugcrowd

In this sponsored interview Casey Ellis chats with Truffle Security’s founder and CEO Dylan Ayrey about the recent CISA secrets leak.

Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA’s org.

Dylan walks through why deleting the repo doesn’t fix anything, why most cloud vendors won’t hard-revoke exposed keys (OpenAI and Slack will; AWS, Google and friends mostly won’t), why Hugging Face datasets now hold more secrets than GitHub itself, and what the next generation of multi-provider credential-harvesting supply chain worms is going to look like.

Your browser does not support the audio element.

Sponsored: Inside CISA's disastrous secrets leak

0:00 / 19:10

Logo