Risky Business Video
July 22, 2026
Risky Business (845): OpenAI's Skynet moment
Presented by
CEO and Publisher
Co-host at large
On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
- Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
- US and China trade AI model ban threats
- Iran has been using SS7 queries to locate and target US troops
- Scattered Spider is having a hard time, not just because of Microsoft’s GDID
- And much, much more!
This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.
Show Notes:
OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com https://openai.com/index/hugging-face-model-evaluation-security-incident
Security incident disclosure — July 2026 | Social Signals https://huggingface.co/blog/security-incident-july-2026
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action
Cheating behaviour in frontier model evaluations | AISI Work | Social Signals https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
EXCLUSIVE: Beijing is looking at curbing overseas access to China’s top AI models, sources say | reuters.com https://www.reuters.com/world/beijing-is-looking-curbing-overseas-access-chinas-top-ai-models-sources-say-2026-07-07
https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi | https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi
Alibaba to ban employees from using Anthropic’s coding tool, source says | reuters.com https://www.reuters.com/world/china/alibaba-ban-claude-code-workplace-over-alleged-backdoor-risks-source-says-2026-07-03
Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says
Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code
Trump calls for new election security measures | NBC News Tech https://www.nbcnews.com/nightly-news/video/trump-calls-for-new-election-security-measures-266865733992
Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media https://therecord.media/scattered-spider-hackers-tfl-sentenced
Alleged longstanding member of Scattered Spider extradited to US | CyberScoop https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com https://www.zetter-zeroday.com/tracking-peter-stokes-and-the-com-allison-nixon-and-her-work-unmasking-cybercriminals
764 splinter group leader sentenced to 40 years in jail | cyberscoop.com https://cyberscoop.com/764-splinter-group-leader-sentenced-alexis-chavez
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | cyberscoop.com https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse
Attackers vote themselves $20 million in BONK cryptocurrency | The Record https://therecord.media/attackers-vote-themselves-20-million-bonk-crypto
CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited
IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets
Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI | TechCrunch Security https://techcrunch.com/2026/07/13/apple-says-former-employee-exploited-rare-bug-to-download-confidential-files-after-leaving-for-openai
Risky Bulletin: Hacker wipes Romania’s entire land registry database - Risky Business Media | Social Signals https://risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database
Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september
On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security https://pushsecurity.com/resources/device-code-phishing