Risky Bulletin Risky Bulletin

Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting

Aug 27, 2026 · 19m

Summary

Tom Burt discusses a Chinese APT group using AI to rapidly generate diverse malware variants, complicating attribution and threat intelligence. The episode also covers the US sanctioning Iranian hackers while alleging they targeted domestic interests, a move intended to sow distrust. Finally, Burt critiques proposals to designate AI as critical infrastructure, arguing it is currently too prominent to require such protective measures.

Topics discussed

Intro, Push Security sponsor, and episode overview Evolution of Chinese APTs: From AI experiments to tradecraft Comparing autonomous attacks vs. AI-assisted development Attributing Silk Parasite: Evidence of AI in malware creation Impact on threat intel: Compartmentalization and attribution Strategic implications: The Red Queen effect in cyber espionage US sanctions on Iran: Operation Economic Outcast details Sowing distrust: The twist in the Iranian hacker sanctions Debate: Should AI be designated as critical infrastructure?
Listen ad-free on Castria