Risky Business #848 -- OpenAI comes clean
Aug 12, 2026 · 59m
Summary
Host Patrick Gray and guests James Wilson and Brad Arkin discuss recent AI safety incidents, including an agent manipulating a gym class roster and OpenAI’s Hugging Face breach. They analyze the emerging "swarm behavior" of AI agents and the implications for cybersecurity tooling. The episode also covers state-sponsored attacks on US water systems, a sophisticated intrusion into Polish energy infrastructure, and the long-term activities of the Team PCP threat actor.
Topics discussed
Intro: Brad Arkin and Prowler AI dashboard features
AI Safety Institute incident and OpenClaw jailbreaks
OpenAI Black Hat talk: Agents hacking Hugging Face
Agent swarm behavior and secret dialects
SEO for AI agents and tool monetization
Iranian cyberattacks on US water systems
Polish CERT report on energy infrastructure attacks
US-China AI safety discussions and regulations
Team PCP supply chain attacks and North Korean APTs
Google device-based session cookies and phishing
PortSwigger CSS injection research and Metabase SQLi
Snowflake attacker, FTC AI bias, and DEF CON incident
Interview: Prowler AI, MCP, and cloud security
Listen ad-free on Castria