Risky Business #846 -- OpenAI built a fireplace out of wood

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:

  • Everyone signs the open weights open letter, except Anthropic… of course.
  • OpenAI had no idea it had hacked Hugging Face
  • Kimi K3 open weights released and they’re massive!
  • Why a more aggressive response is needed to cyber attacks on OT
  • And much, much more!

This week’s show is brought to you by SpecterOps. In this week’s sponsor interview Justin Kohler and Jared Atkinson talk about how SpecterOps’ Bloodhound now supports AWS attack paths. Run it against your AWS infra, but only if you have a strong stomach. The results will terrify you.

This episode is also available on YouTube.

Risky Business #846 -- OpenAI built a fireplace out of wood
0:00 / 62:00

Show notes

Open Weights and American AI Leadership | Social Signals

Our position on open-weights models | Social Signals

Halvar Flake (@halvarflake) on X | X (formerly Twitter)

White House accuses Chinese company of distilling Anthropic’s Fable | cyberscoop.com

Jensen Huang (@JensenHuang) on X | X (formerly Twitter)

Its AI Agent Spent Days Hacking a Company, but Sources Say OpenAI Did Not Notice for a Week | reuters.com

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face | TechCrunch Security

Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack | TechCrunch Security

Sens. Banks and Schiff Introduce Bill to Help American AI Companies Combat Chinese Espionage |

AI Kill Switch Act would let Trump admin order shutdown of rogue AI systems | Ars Technica

Marco Rubio tells diplomats to play down talk of American tech "kill switch" | reuters.com

Federal agencies broaden alert on Iran-linked OT attacks | therecord.media

Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities | CyberScoop

NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign | nsa.gov

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts | BleepingComputer

Microsoft responds to LG monitors installing McAfee ads on Windows | Ars Technica

LG to Ban Residential Proxies from Smart TV Apps | krebsonsecurity.com

Despite multiple takedowns, botnets continue to grow | cyberscoop.com

Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill | therecord.media

Upbound says hack caused $13 million in fraudulent Acima leases | BleepingComputer

Fake Claude app promoted by Bing ads pushes SectopRAT malware | BleepingComputer

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin | BleepingComputer

Clop ransomware targets Windchill, FlexPLM in data theft attacks | BleepingComputer

'Wrench' attacks against crypto holders appear to be on the rise | therecord.media

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face | wired.com