惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
小众软件
小众软件
博客园 - 叶小钗
宝玉的分享
宝玉的分享
博客园_首页
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
B
Blog RSS Feed
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
U
Unit 42
F
Fortinet All Blogs
IT之家
IT之家
Y
Y Combinator Blog
Martin Fowler
Martin Fowler
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
Stack Overflow Blog
Stack Overflow Blog
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack Risky Biz Soap Box: Graph the planet!
Risky Business #820 -- Asian fraud kingpin will face Chin...
Adam Boileau · 2026-01-14 · via Risky Business

Risky Business Podcast

January 14, 2026

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

Risky Business returns for 2026! Patrick Gray and Adam Boileau talk through the week’s cybersecurity news, including:

  • Santa brings hackers MongoDB memory leaks for Christmas
  • Vercel pays out a million bucks to improve its React2Shell WAF defences
  • 39C3 delivers; the pink Power Ranger deletes nazis, while a catgirl ruins GnuPG
  • Cambodian scam compound kingpin gets extradited to China, and we don’t think it’ll go well for him
  • Krebs picks apart the Kimwolf botnet and residential proxy networks
  • So many healthcare data leaks that we have a roundup section

This week’s episode is sponsored by Airlock Digital. The founders of the application allow-listing vendor, David Cottingham and Daniel Schell, discuss Microsoft’s ClickOnce .NET app packaging, and how attackers have been abusing it to load code. Airlock hates it when you load code!

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!)

0:00 / 59:15

Logo

Show notes

US, Australia say ‘MongoBleed’ bug being exploited | The Record from Recorded Future News

Merry Christmas Day! Have a MongoDB security incident. | by Kevin Beaumont | Dec, 2025 | DoublePulsar

Inside Vercel’s sleep-deprived race to contain React2Shell | CyberScoop

gpg.fail

Hacktivist deletes white supremacist websites live onstage during hacker conference | TechCrunch

Chinese attackers exploiting zero-day to target Cisco email security products | The Record from Recorded Future News

Ni8mare  -  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) | Cyera Research Labs

ServiceNow patches critical AI platform flaw that could allow user impersonation | CyberScoop

Alleged cyber scam kingpin arrested, extradited to China | The Record from Recorded Future News

FCC IoT labeling program loses lead company after China probe | Cybersecurity Dive

Trump picks Lt. Gen. Joshua Rudd to lead NSA spy agency - The Washington Post

NSA cyber directorate gets new acting leadership | The Record from Recorded Future News

Dutch court sentences hacker who used port systems to smuggle cocaine to 7 years | The Record from Recorded Future News

ECLI:NL:GHAMS:2026:22, Amsterdam Court of Appeal, 23-003218-22

The Kimwolf Botnet is Stalking Your Local Network – Krebs on Security

Who Benefited from the Aisuru and Kimwolf Botnets? – Krebs on Security

Coupang recovers smashed laptop that alleged data leaker threw into river | The Record from Recorded Future News

Ransomware responders plead guilty to using ALPHV in attacks on US organizations | The Record from Recorded Future News

Nearly 480,000 impacted by Covenant Health data breach | The Record from Recorded Future News

Illinois health department exposed over 700,000 residents' personal data for years | TechCrunch

Tech provider for NHS England confirms data breach | TechCrunch

Hacker claiming to be behind ManageMyHealth breach: ‘I do it for the money and I’m in negotiations to get it’ - NZ Herald