Risky Business Podcast
July 22, 2026
Risky Business #845 -- OpenAI's Skynet moment
Presented by
Technology Editor
CEO and Publisher
On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
- Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
- US and China trade AI model ban threats
- Iran has been using SS7 queries to locate and target US troops
- Scattered Spider is having a hard time, not just because of Microsoft’s GDID
- And much, much more!
This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.
This episode is also available on YouTube.
Brought to you by Push Security
Browser-based detection and response
Show notes
OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com
Security incident disclosure — July 2026 | Social Signals
Cheating behaviour in frontier model evaluations | AISI Work | Social Signals
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals
Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica
https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi |
Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com
Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com
Trump calls for new election security measures | NBC News Tech
Alleged longstanding member of Scattered Spider extradited to US | CyberScoop
https://www.justice.gov/usao-ndil/media/1450651/dl?inline |
764 splinter group leader sentenced to 40 years in jail | cyberscoop.com
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | cyberscoop.com
Attackers vote themselves $20 million in BONK cryptocurrency | The Record
CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer
Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer
Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer
IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com
Pegasus Spyware European Parliament Pega Committee Member | The Record
Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security
Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer
On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security