Risky Business (848): OpenAI comes clean

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

  • The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
  • Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
  • More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
  • It turns out TeamPCP has been around longer than we thought and predates the AI era
  • Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
  • Much, much more

This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.

Show notes:

How a simple request for AI to book a gym class exposed a major threat | Social Signals https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986

OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com https://www.wired.com/story/ok-well-there-are-even-more-ai-agent-hacking-incidents

OpenAI BlackHat talk re Hugging Face incident | https://www.youtube.com/watch?v=87DyyMV0kCY

Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media https://therecord.media/iran-cyberattacks-water-treatment

Cyberattack on North Carolina Ports ‘contained’ | therecord.media https://therecord.media/cyberattack-north-carolina-ports

Local governments in four states dealing with cyberattacks | The Record https://therecord.media/cyberattacks-ransomware-local-governments

Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska https://cert.pl/en/posts/2026/08/incident-follow-up-report-energy-sector-2025

Chinese telcos maintain deep US presence | The Record https://therecord.media/chinese-hackers-telecoms-house

State Department says Trump raised cyber scam compound issue with Xi | therecord.media https://therecord.media/trump-xi-southeast-asia-cyber-scam-compounds

Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop https://cyberscoop.com/teampcp-long-active-history-2020-oligo-security

A Security Pro Hacked North Korean Hackers. | wired.com https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun | https://risky.biz/srsly-risky-biz-being-a-north-korean-hacker-is-about-to-be-less-fun

Chrome adopts what may be the best protection yet against account takeovers | Ars Technica https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers

CSS:the bomb inside your inbox | PortSwigger Research https://portswigger.net/research/css-the-bomb-inside-your-inbox

Security update available for Metabase - Please upgrade now | Social Signals https://www.metabase.com/blog/security-update

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media https://therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka

British ‘Com’ member who abused more than 100 girls worldwide jailed for two years | therecord.media https://therecord.media/british-com-member-abuse-jailed-two-years

FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | TechCrunch Security https://techcrunch.com/2026/08/11/fbi-says-cybercriminals-are-hacking-into-victims-online-accounts-to-steal-their-intimate-pictures

AI is getting better at election facts, but voters shouldn’t rely on it | CyberScoop https://cyberscoop.com/ai-chatbots-2026-midterm-elections

The FTC wants to regulate AI for ideological bias | cyberscoop.com https://cyberscoop.com/ftc-regulating-ai-ideological-bias

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs

Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security https://techcrunch.com/2026/08/11/delta-investigating-after-someone-set-up-fake-wi-fi-network-mid-flight

mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub https://github.com/prowler-cloud/mcp-dashboard-demo/blob/main/prompt/prowler_dashboard_prompt.md