Risky Business #837 -- GitHub Actions footgun claims TanStack

Presented by

James Wilson
James Wilson

Enterprise Technology Editor

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • Mini Shai-Hulud and the TanStack compromise using Github Actions
  • Instructure pays Canvas elearning platform data extortionists
  • More Linux privilege escalation 0days!
  • CISA helping critical infrastructure operators rearchitect their networks so they work offline

This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.

This episode is also available on Youtube.

Risky Business #837 -- GitHub Actions footgun claims TanStack
0:00 / 65:15

Show notes

‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack | CyberScoop

Hardening TanStack After the npm Compromise | TanStack Blog

Canvas Breach Disrupts Schools & Colleges Nationwide – Krebs on Security

Instructure pays ransom after Canvas incident as Congress announces investigation | The Record from Recorded Future News

When DNSSEC goes wrong: how we responded to the .de TLD outage

Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Google Cloud Blog

Mythos smythos! How to find 0day with lesser models - Risky Business Media

GitHub - V4bel/dirtyfrag · GitHub

retr0.zip

NVD - CVE-2026-42511

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoop

Ivanti customers confront yet another actively exploited zero-day | CyberScoop

Palo Alto warns of critical software bug used in firewall attacks | The Record from Recorded Future News

Where Have All the Complex Windows Malware and Their Analyses Gone?

Meet Rassvet, Russia’s Answer to Starlink | WIRED

DOJ says ransomware gang tapped into Russian government databases | TechCrunch

Iranian government hackers using Chaos ransomware as cover, researchers say | The Record from Recorded Future News

Foxconn confirms cyberattack impacting North American factories | The Record from Recorded Future News

New CISA initiative aims for critical infrastructure to operate offline during cyberattacks | The Record from Recorded Future News

‘HELLO BOSS’: Inside the Chinese Realtime Deepfake Software Powering Scams Around the World

How to Disable Google's Gemini in Chrome | WIRED

FCC pushes ban on security updates for foreign-made routers, drones to 2029 | The Record from Recorded Future News