Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #839 -- TeamPCP stole GitHub's internal repos

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • TeamPCP breached GitHub’s internal repos. Now what?
  • Some absolute plonker glued Coruna to a hijacked npm package
  • CISA is worried about about open source and wants third party submissions for KEV
  • AI infrastructure is “systemically” insecure
  • Much, much more

This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun!

This episode is also available on YouTube

Risky Business #839 -- TeamPCP stole GitHub's internal repos
0:00 / 60:23

Risky Business #838 -- GitHub investigates possible breach

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • GitHub announced a possible breach
  • CISA leaks important creds, keys in public repo
  • Awful vulnerability in Bitlocker renders it useless without a PIN
  • So. Many. Patches.
  • Polish Government urges officials to ditch Signal for mSzyfr
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy.

This episode is also available on YouTube.

Risky Business #838 -- GitHub investigates possible breach
0:00 / 62:49

Soap Box: Where does AI fit into cloud security?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

This episode is also available on Youtube.

Soap Box: Where does AI fit into cloud security?
0:00 / 33:37

Risky Business #837 -- GitHub Actions footgun claims TanStack

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • Mini Shai-Hulud and the TanStack compromise using Github Actions
  • Instructure pays Canvas elearning platform data extortionists
  • More Linux privilege escalation 0days!
  • CISA helping critical infrastructure operators rearchitect their networks so they work offline

This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.

Risky Business #837 -- GitHub Actions footgun claims TanStack
0:00 / 65:15

Risky Business #836 -- You can't patch the bugpocalypse

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including:

  • The US Government says we just have to patch faster, but…
  • Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn’t enough
  • James gets mad about lame AI Agent adoption advice from the US and Australian Governments
  • James Kettle and Niels Provos both showed us that any model can find 0day like Mythos
  • And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars

This week’s show is sponsored by SpecterOps. Their CTO, Jared Atkinson, chats to Pat about the big changes in the threat landscape, brought about by AI, that are causing a pivot away from detection and remediation, and toward prevention.

This episode is also available on Youtube.

Risky Business #836 -- You can't patch the bugpocalypse
0:00 / 61:56

Snake Oilers: Ent AI, Spacewalk and Mondoo

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

  • Ent AI: Co-founder Brandon Dixon pitched Ent, an intent-aware, AI-powered endpoint security control.

  • Spacewalk AI: Founders Chris Fuller and Tim Wenzlau pitch Spacewalk, an AI-powered incident response platform.

  • Mondoo: Co-founder Dominik Richter pitches Mondoo, an AI-powered “service as software” in the vulnerability management space.

This episode is also available on YouTube.

Snake Oilers: Ent AI, Spacewalk and Mondoo
0:00 / 43:59

Risky Business #835 -- Why the Fast16 malware is badass

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week’s cybersecurity news, including:

  • The US government is mad as hell about Chinese firms stealing American AI technology
  • Dmitri has an opinion or two about the US selling Nvidia chips to China
  • Speaking of Chinese AI, Kimi’s new 2.6 is very interesting
  • The US sanctions a Cambodian senator for earning mega bucks through scam compounds
  • And a ransomware family is promoting itself as being … quantum-safe?

This week’s show is sponsored by Trail of Bits. CEO and co-founder Dan Guido chats to Pat about how private inference works and Trail of Bits’ audit of WhatsApp’s private AI setup.

This episode is also available on Youtube.

Risky Business #835 -- Why the Fast16 malware is badass
0:00 / 66:28

Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

The Grugq
The Grugq

Independent Security Researcher

On this week’s show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week’s cybersecurity news, including:

  • Vercel got owned, and there’s a few infostealer and compromised employee dots to connect
  • Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse
  • Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs?
  • The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing
  • And DDos attacks hit a couple of smaller-player socials

This week’s episode is sponsored by Permiso. Ian Ahl chats to Pat about the subtle signals Permiso uses to detect ShinyHunters-style activity in cloud and on-prem environments.

This episode is also available on Youtube.

Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs
0:00 / 60:33

Risky Business #833 -- The Great Mythos Freakout of 2026

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet
  • CISA adds a 2009 Excel bug to the KEV list, u wot?
  • Adobe also parties like it’s the 2000s, and fixes an Acrobat Reader bug
  • Disgraced former Trenchant exec Peter Williams’ sob story fails to resonate with … anyone
  • Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were “secured” by the password: 1234.

This week’s episode is sponsored by mobile network operator, Cape. Ajit Gokhale talks with James about the ways to get being a telco right when you’re starting from scratch and solving the security problems of 2026.

This episode is also available on Youtube.

Risky Business #833 -- The Great Mythos Freakout of 2026
0:00 / 59:45

Snake Oilers: Burp AI, Sondera and Truffle Security

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

  • Burp AI and DAST: The founder of PortSwigger and creator of legendary security software Burp Suite, Dafydd Stuttard, drops by to pitch listeners on Burp AI and Burp Suite DAST.

  • Sondera: Josh Devon talks about Sondera, a technology designed to intervene when AI models start doing the wrong thing by statefully tracking their trajectories. This isn’t a permissions suite for AI agents, it’s a way to stick agents in a harness and make sure they adhere to hard policy boundaries.

  • Truffle Security: Dylan Ayrey, the founder of Truffle Security, joins Risky Business again to talk through the latest bells and whistles in Trufflehog, a security tool that searches for exposed secrets and validates them. The Truffle team has done a lot of work on the remediation part of their product over the last few years, and Dylan tells us all about it!

This episode is also available on YouTube

Snake Oilers: Burp AI, Sondera and Truffle Security
0:00 / 48:00