Risky Bulletin Risky Bulletin

Risky Bulletin: US will let private companies carry out offensive cyber ops

Aug 14, 2026 · 11m

Summary

This Risky Bulletin covers the US authorizing private companies for offensive cyber ops and Kenya mandating internet cafe logs. It details global breaches involving AI hacking in Taiwan, ransomware in Colombia, and data leaks at Uber and RingCentral. The episode also highlights new macOS and VMware vulnerabilities, the rise of commercial AI hacking tools, and Rapid7’s recent layoffs.

Topics discussed

Intro: Private cyber ops, Taiwan breach, macOS bug US allows private companies to conduct offensive cyber ops Kenya orders internet cafes to store customer logs Brazil suspends Discord live streaming over child safety AI tools used to breach Taiwanese government networks Ransomware hits Colombia's Ministry of Justice UK charity Lawcare data stolen via Beacon CRM breach UK Criminal Records Office reprimanded for repeated hacks Uber freight business data leaked by Helix Group RingCentral customer data leaked by Shiny Hunters Klopp Group lists Shell, Philips, GE as new victims Bybit sues North Korea over $1.5B crypto theft Arrests in Montenegro and Ukraine cybercrime crackdowns Man arrested for AI face-swapping fraud in Spain 78k credentials leaked from Light LLM supply chain attack Google removes malicious fake VPN Chrome extensions Malware found in Firewall Falcon Manager VPN tool Mass scan disguises traffic as AI crawlers to steal data Rise of commercial black hat AI hacking tools Chinese APT group links espionage and crypto fraud macOS screen sharing bug exploited for crypto mining VMware vCenter servers exploited via directory traversal Plug and Pwn: USB devices install vulnerable Windows drivers New Windows Defender zero-day exploit published WhatsApp rolls out local AI scam detection feature Rapid7 lays off 300 employees; Outro
Listen ad-free on Castria