Risky Bulletin
Regular cybersecurity news updates from the Risky Business team...
ShinyHunters suspect arrested in the Netherlands
A ShinyHunters suspect has been arrested in the Netherlands, Apple fixes an iOS zero-day found by Meta, recent Citrix zero-days see mass exploitation within hours and NVIDIA launches an AI sandboxing platform.
Show notes
Risky Bulletin: Sanctions force CAs to revoke TLS certs in Iran, RussiaBetween Two Nerds: The AI crime machine
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the rise of fully automated LLM-driven hacking campaigns among criminals and even state hacking groups. For those with the right risk appetite, a move fast and break things hacking approach using AI can pay off.
This episode is also available on YouTube.
Show notes
Autonomous AI Agents are breaking into hundreds of Online Retailers A Single Operator, Two AI Platforms, Nine Government AgenciesRisky Bulletin: Intel ends paid bug bounties
Intel removes cash rewards from its bug bounty program, OpenAI agents probed dozens of organizations, Fraudsters scam €95 million from an Italian bank and Bitget is hacked for $350 million.
Show notes
Risky Bulletin: Intel ends paid bug bountiesSponsored: Robo-Burp is coming for your web apps
In this Risky Business sponsored interview James Wilson chats to Kieron Hughes and Andrzej Matykiewicz from PortSwigger about the company’s latest AI pen-testing product, Burp AT. The model has different levels of autonomy modes and is natively integrated with Burp Suite so once it finds vulnerabilities it can spin up intruder attacks, configure everything and brute-force the code.
The three also chat about the experiences of beta trial users, including one that found a vulnerability that disclosed reports from the company’s anonymous whistle blower platform.
Show notes
Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol
A major vulnerability has been found in the ancient TACACS+ networking protocol, Australia’s Prime Minister claims an OpenAI agent hacked the country’s Medicare website, OpenAI gives Ukraine access to its Daybreak cyber-defense program and the UK will establish an anti-disinformation center.
Show notes
Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocolSrsly Risky Biz: Bring on the AI lawsuits
Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. Its a good move. Leaving the companies on the hook keeps the pressure on them to do better with their cyber security and testing controls.
They also discuss a Russian AI-powered cyberespionage campaign run by a group known as Midnight Blizzard. It used AI workflows to run the entire campaign so they got a lot more hacking done and accepted AI mistakes. This makes sense given that they want more intelligence from Ukrainian targets and don’t care at...
Risky Bulletin: Team Cymru unmasks shady Chinese proxy network
A network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies.
Show notes
Risky Bulletin: Team Cymru unmasks shady Chinese proxy networkBetween Two Nerds: Real-time cyber defence
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether there is such a thing as real-time cyber defence. Will agentic AI save us from hacking AI?
This episode is also available on YouTube.
Show notes
Clem Delangue | XRisky Bulletin: Gemini finally did some crimes
Google’s Gemini hacked three companies, hackers claim a breach of Russia’s election commission, OpenAI was behind RubyGems’ May incident, and the Coast Guard and FBI board two ships to investigate cyberattacks.
Show notes
Risky Bulletin: Gemini hacked three companies tooSponsored: SpecterOps on the impact of AI agents on BloodHound
In this Risky Business sponsored interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin explains how Entra Agent ID can introduce new identity relationships and potential attack paths.
Show notes
Justin Kohler on LinkedIn SpecterOps, Introduction to BloodHoundRisky Bulletin: Anthropic agents went hacking again
Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.
Show notes
Risky Bulletin: Anthropic agents went hacking againSrsly Risky Biz: America's drivers licence breach is a national security disaster
Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.
They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough.
Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy.
This episode is also available on YouTube
Show notes
Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.
Show notes
Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandalBetween Two Nerds: Can AI defend critical infrastructure?
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line.
This episode is also available on YouTube.
Show notes
Heather Adkins X post Clem X post Secure connectivity principles for operational technology | NCSCRisky Bulletin: BEC campaign steals €35 million from French notaries
Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.
Show notes
Risky Bulletin: BEC campaign steals €35 million from French notariesSponsored: Authentik is rethinking PAM for AI agents
In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.
Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human.
They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access.
Show notes
Risky Bulletin: Russia tells data centers to deploy drone defenses
Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs.
Show notes
Risky Bulletin: Russia tells data centers to deploy drone defensesSrsly Risky Biz: China's botnets are worth disrupting
Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild.
They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal!
Finally, they discuss efforts to fix US water sector securi...
Risky Bulletin: BGP hijack delivers malicious Virtualizor updates
A BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness.
Show notes
Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updatesBetween Two Nerds: The perfect hacker
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals.
This episode is also available on YouTube.
Show notes
Bitdefender Labs report on SilkParasite OpenAI on the Hugging Face incidentRisky Bulletin: New powers for Dutch intelligence services
Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service.
Show notes
Risky Bulletin: Dutch intel services to get extensive new powersSponsored: Attackers need to be right more than once
In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown jewels”.
The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times.
Show notes
Risky Bulletin: Two TeamPCP members arrested in Australia
Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic.
Show notes
Risky Bulletin: Two TeamPCP members arrested in AustraliaSrsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting
Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution.
They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense.
This episode is also available on YouTube
Show notes
Risky Bulletin: Russia starts blocking DoH and DoT
Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common.
Show notes
Risky Bulletin: Russia starts blocking DoH and DoTBetween Two Nerds: Attribution is dead, long live attribution
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack.
This episode is also available on YouTube.
Show notes
Florian Roth X post Phrack issue 59, Defeating Forensic Analysis on Unix Phrack issue 62, Remote ExecRisky Bulletin: Expired credit cards can be used for malicious transactions
Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.
Show notes
Risky Bulletin: Expired cards can be used for new transactionsSponsored: Passkeys won’t stop authorisation phishing
In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer.
Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if their controls against these attacks actually work.
Show notes
Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs
The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great Firewall
Show notes
Risky Bulletin: Academics find source code overlaps between Geedge and China's Great FirewallSrsly Risky Biz: Trump's private hacker memo is the right idea
Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disruption operations, but there simply isn’t enough government capacity. So it is time to bring in the private sector.
They also discuss Ukraine’s combined cyber and kinetic strikes against Wildberries, the logistics company that is called the Amazon of Russia. These cyber operations didn’t amplify the effects of kinetic strikes, but it is great...
Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
Slovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.
Show notes
Risky Bulletin: Slovakia finds Russian backdoor in traffic speed camerasBetween Two Nerds: The eye of Sauron
In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.
This episode is also available on YouTube.
Show notes
The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber Defense Between Two Nerds: Exploits are not cyber powerRisky Bulletin: The EU publishes its upcoming cybersecurity standards
The EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.
Show notes
Risky Bulletin: The EU publishes its upcoming cybersecurity standardsSponsored: What npm 12 fixes… and what it doesn’t
In this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what third-party code actually does before allowing it into their environments.
Show notes
Risky Bulletin: US will let private companies carry out offensive cyber ops
The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.
Show notes
Risky Bulletin: White House lets private companies carry out offensive cyber opsSrsly Risky Biz: Data extortion is booming. Hooray!
Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.
They also discuss how the rise of AI makes it worth reinvigorating CISA’s Secure by Design initiative.
Show notes
Risky Bulletin: Russian hackers jump on the fake job interview train
Russian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams.
Show notes
Risky Bulletin: Russian hackers adopt the fake job interview tacticsBetween Two Nerds: The cyber resistance!
In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals.
This epsiode is also available on YouTube.
Show notes
The Record on the Belarus Cyber Partisans BTN6, How Ukraine could use its IT armyRisky Bulletin: Two law firms pay giant ransoms
Two American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!
Show notes
Risky Bulletin: Pwnie Awards 2026 winnersSponsored: Island's expansion to SASE and enterprise AI
In this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI.