Risky Business Weekly (842): Anthropic needs an adult in the C suite

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • Anthropic’s Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security”
  • Why “guardrails” won’t keep the world safe from your AI doomsday machine
  • The FISA 702 statute expired, but the spying can (probably) continue!
  • NPM v12 delivers some protection against supply chain attacks, but not enough.
  • Microsoft has a series of bugs that prevent Windows Update from … updating
  • Much, much more!

This episode is also available on YouTube

Show notes:

Anthropic suspends new AI models after government directive | NBC News Tech https://www.nbcnews.com/tech/tech-news/anthropic-suspends-new-ai-models-fable-mythos-government-directive-rcna349901

How a 90-minute White House deadline sparked Silicon Valley’s biggest AI fight | washingtonpost.com https://www.washingtonpost.com/technology/2026/06/15/how-90-minute-white-house-deadline-sparked-silicon-valleys-biggest-ai-fight

David Shulman (@DavidShulmanFL) on X | X (formerly Twitter) https://x.com/davidshulmanfl/status/2065985589489344896?s=46&t=VLIuBKdOq3MvRk4IpV-_-A

Controversial FISA spying law expires tonight. The spying will continue. | Ars Technica https://arstechnica.com/tech-policy/2026/06/controversial-fisa-spying-law-expires-tonight-the-spying-will-continue

GitHub announces npm security changes to tackle supply-chain attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks

Why NPM v12 won’t stop supply chain attacks - Risky Business Media | Social Signals https://risky.biz/RBFEATURES26

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks

Microsoft patches Exchange Server zero-day exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-exchange-server-zero-day-exploited-in-attacks

Max severity Ivanti Sentry vulnerability now exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks

CISA warns of another cPanel plugin flaw exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw

Critical Fortinet FortiSandbox flaws now exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/critical-fortinet-fortisandbox-flaws-now-exploited-in-attacks

Path traversal flaw in AI dev platform Langflow exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks

Microsoft: Some Windows PCs fail to install latest monthly updates | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-some-upgraded-windows-pcs-fail-to-install-monthly-updates

Microsoft fixes BitLocker recovery bug on Windows Server 2025 | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-bug-on-windows-server-2025

New attack turned Microsoft 365 Copilot into 1-click data theft tool | BleepingComputer https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool

Over 73,000 French govt employees affected in Tchap messenger breach | BleepingComputer https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts

Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps | wired.com https://www.wired.com/story/signal-alums-release-encrypted-spaces-a-new-system-for-building-private-collaboration-apps

FBI disrupts massive AI-powered phishing service using a million URLs | BleepingComputer https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls

Cyberattack shuts down major Australian sugar mills, disrupting harvest | The Record https://therecord.media/cyberattack-shuts-down-major-australian-sugar-producer

Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcasts, Report Finds | wired.com https://www.wired.com/story/drug-sites-hijacked-spotifys-search-ranking-through-fake-podcasts-report-finds

It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests | 404.feed.press https://www.404media.co/it-is-trivially-easy-to-use-reddit-to-manipulate-ai-search-research-suggests

Who Runs the Ransomware Group ‘The Gentlemen?’ | krebsonsecurity.com https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen

:brdKnife: (@cR0w@infosec.exchange) | Infosec Exchange https://infosec.exchange/@cR0w/116732880369032945