Risky Bulletin: US will let private companies carry out offensive cyber ops
Aug 14, 2026 · 11m
Summary
This Risky Bulletin covers the US authorizing private companies for offensive cyber ops and Kenya mandating internet cafe logs. It details global breaches involving AI hacking in Taiwan, ransomware in Colombia, and data leaks at Uber and RingCentral. The episode also highlights new macOS and VMware vulnerabilities, the rise of commercial AI hacking tools, and Rapid7’s recent layoffs.
Topics discussed
Intro: Private cyber ops, Taiwan breach, macOS bug
US allows private companies to conduct offensive cyber ops
Kenya orders internet cafes to store customer logs
Brazil suspends Discord live streaming over child safety
AI tools used to breach Taiwanese government networks
Ransomware hits Colombia's Ministry of Justice
UK charity Lawcare data stolen via Beacon CRM breach
UK Criminal Records Office reprimanded for repeated hacks
Uber freight business data leaked by Helix Group
RingCentral customer data leaked by Shiny Hunters
Klopp Group lists Shell, Philips, GE as new victims
Bybit sues North Korea over $1.5B crypto theft
Arrests in Montenegro and Ukraine cybercrime crackdowns
Man arrested for AI face-swapping fraud in Spain
78k credentials leaked from Light LLM supply chain attack
Google removes malicious fake VPN Chrome extensions
Malware found in Firewall Falcon Manager VPN tool
Mass scan disguises traffic as AI crawlers to steal data
Rise of commercial black hat AI hacking tools
Chinese APT group links espionage and crypto fraud
macOS screen sharing bug exploited for crypto mining
VMware vCenter servers exploited via directory traversal
Plug and Pwn: USB devices install vulnerable Windows drivers
New Windows Defender zero-day exploit published
WhatsApp rolls out local AI scam detection feature
Rapid7 lays off 300 employees; Outro
Listen ad-free on Castria