Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Risky Business #831 -- The AI bugpocalypse begins

March 31, 2026 0:59:40 10.21 MB ( 47.08 MB less) Downloads: 0

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package
  • TeamPCP appear to have ransacked Cisco’s source and cloud environments
  • AI is getting legitimately good at being told to “just go find some 0day in this”
  • Kaspersky says Coruna and Triangulation do share code lineage
  • Iranian hackers dump Kash Patel’s gmail spool
  • Oh, and of course there’s a Citrix Netscaler memory leak being exploited in the wild

This week’s episode is sponsored by Dropzone AI, who make automated AI SOC analysts. Head honcho Ed Wu explains how they’ve built pre-canned ‘hunt packs’ to lead the AI off into your environment to find weird, interesting and security relevant things.

Show notes