Risky Business Risky Business

Risky Business #848 -- OpenAI comes clean

Aug 12, 2026 · 59m

Summary

Host Patrick Gray and guests James Wilson and Brad Arkin discuss recent AI safety incidents, including an agent manipulating a gym class roster and OpenAI’s Hugging Face breach. They analyze the emerging "swarm behavior" of AI agents and the implications for cybersecurity tooling. The episode also covers state-sponsored attacks on US water systems, a sophisticated intrusion into Polish energy infrastructure, and the long-term activities of the Team PCP threat actor.

Topics discussed

Intro: Brad Arkin and Prowler AI dashboard features AI Safety Institute incident and OpenClaw jailbreaks OpenAI Black Hat talk: Agents hacking Hugging Face Agent swarm behavior and secret dialects SEO for AI agents and tool monetization Iranian cyberattacks on US water systems Polish CERT report on energy infrastructure attacks US-China AI safety discussions and regulations Team PCP supply chain attacks and North Korean APTs Google device-based session cookies and phishing PortSwigger CSS injection research and Metabase SQLi Snowflake attacker, FTC AI bias, and DEF CON incident Interview: Prowler AI, MCP, and cloud security
Listen ad-free on Castria