惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
量子位
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
J
Java Code Geeks
B
Blog
V
V2EX
博客园 - 三生石上(FineUI控件)
Blog — PlanetScale
Blog — PlanetScale
aimingoo的专栏
aimingoo的专栏
Y
Y Combinator Blog
F
Fortinet All Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
A
About on SuperTechFans
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
H
Help Net Security
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
L
LangChain Blog

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack
Risky Business #784 -- GitHub supply chain attack steals ...
Adam Boileau · 2025-03-19 · via Risky Business

Risky Business Podcast

March 19, 2025

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Github Actions supply chain attack loots keys and secrets from 23k projects
  • Why a VC fund now owns a minority stake in Risky Business Media (!?!?)
  • China doxes Taiwanese military hackers
  • Microsoft thinks .lnk file whitespace trick isn’t worth patching but APTs sure love it
  • CISA delivers government efficiency by re-hiring fired staff… to put them on paid leave
  • …and Google acquires Wiz for $32bn

This week’s show is sponsored by Zero Networks, and they have sent along a happy customer to talk about their experience. Aaron Steinke is Head of Infrastructure at La Trobe Financial, an asset management firm in Australia. Aaron talks through bringing modern zero-trust goodness to the reality of a technology environment that’s been around 40 years.

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

0:00 / 56:58

Logo

Show notes

Risky Bulletin: GitHub supply chain attack prints everyone's secrets in build logs - Risky Business Media

China says Taiwan's military is behind PoisonIvy APT

China identifies Taiwanese hackers allegedly behind cyberattacks and espionage | The Record from Recorded Future News

Crypto exchange OKX shuts down tool used by North Korean hackers to launder stolen funds | The Record from Recorded Future News

Lazarus Group deceives developers with 6 new malicious npm packages | CyberScoop

Poisoned Windows shortcuts found to be a favorite of Chinese, Russian, N. Korean state hackers | The Record from Recorded Future News

'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in January | The Record from Recorded Future News

Black Basta uses brute-forcing tool to attack edge devices | Cybersecurity Dive

Alleged Russian LockBit developer extradited from Israel, appears in New Jersey court | The Record from Recorded Future News

CISA works to contact probationary employees for reinstatement after court order - Nextgov/FCW

‘People Are Scared’: Inside CISA as It Reels From Trump’s Purge | WIRED

The Wiretap: CISA Staff Are Cautiously Optimistic About Trump’s Pick For Director

White House instructs agencies to avoid firing cybersecurity staff, email says | Reuters

Signal no longer cooperating with Ukraine on Russian cyberthreats, official says | The Record from Recorded Future News

Telegram CEO Pavel Durov allowed to leave France amid investigation

Appellate court upholds sentence for former Uber cyber executive Joe Sullivan | The Record from Recorded Future News

Google buys cloud security provider Wiz for $32 billion | The Record from Recorded Future News

Pat Gray, Founder of Risky Business, Joins Decibel as Founder Advisor - Decibel