Risky Business
Risky Business

Risky Business #826 -- A week of AI mishaps and skulduggery

25 February 2026 1:06:11 Risky Business Media

Listen to episode

About this episode

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

  • Low skill actors compromise 600 Fortinets with AI-generated playbooks
  • Anthropic calls out Chinese AI firms over model distillation
  • Meta’s director of AI safety tells her ClawdBot not to delete her mail… so of course it does
  • Peter Williams cops 7 years in jail for selling L3 Harris Trenchant’s exploits to Russia
  • Ivanti got hacked in 2021 via… bugs in Ivanti

This episode is sponsored by line-rate network capture system Corelight. CEO Brian Dye joins to discuss what AI can do for defenders, and what it can’t.

This episode is also available on Youtube.

            <h3 class="panel-title">Show notes</h3>
                <ul>

                    <li><a href="https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/">AI-augmented threat actor accesses FortiGate devices at scale</a></li>

                    <li><a href="https://x.com/uk_daniel_card/status/2025158197019849126?s=46&amp;t=VLIuBKdOq3MvRk4IpV-_-A">&quot;this reads to me like: they ran existing tools.... but with a cool dashboard :D&quot;</a></li>

                    <li><a href="https://cyberscoop.com/anthropic-accuses-chinese-labs-ai-distillation-cyber-risk/">Anthropic accuses Chinese labs of trying to illicitly take Claude’s capabilities | CyberScoop</a></li>

                    <li><a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks">Detecting and preventing distillation attacks</a></li>

                    <li><a href="https://apnews.com/article/anthropic-hegseth-ai-pentagon-military-3d86c9296fe953ec0591fcde6a613aba">Hegseth warns Anthropic to let the military use the company’s AI tech as it sees fit, AP sources say</a></li>

                    <li><a href="https://cyberscoop.com/anthropic-claude-code-security-automated-security-review/">Anthropic Rolls Out Embedded Security Scanning for Claude</a></li>

                    <li><a href="https://arstechnica.com/ai/2026/02/an-ai-coding-bot-took-down-amazon-web-services/">AWS's AI Coding Bot Kiro Caused a 13-Hour Outage</a></li>

                    <li><a href="https://www.microsoft.com/en-us/security/blog/2026/02/19/running-openclaw-safely-identity-isolation-runtime-risk/">Running OpenClaw safely: identity, isolation, and runtime risk</a></li>

                    <li><a href="https://risky.biz/RBFEATURES2/">Former Adobe, Cisco and Salesforce CISO talks AI pentesting</a></li>

                    <li><a href="https://risky.biz/RBFEATURES1/">History Repeats: Security in the AI Agent Era</a></li>

                    <li><a href="https://www.404media.co/meta-director-of-ai-safety-allows-ai-agent-to-accidentally-delete-her-inbox/">Meta Director of AI Safety Allows AI Agent to Accidentally Delete Her Inbox</a></li>

                    <li><a href="https://techcrunch.com/2026/02/18/microsoft-says-office-bug-exposed-customers-confidential-emails-to-copilot-ai/">Microsoft says Office bug exposed customers' confidential emails to Copilot AI | TechCrunch</a></li>

                    <li><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-copilot-data-controls-to-all-storage-locations/">The (tangential) fix: Microsoft adds Copilot data controls to all storage locations</a></li>

                    <li><a href="https://cyberscoop.com/l3harris-executive-peter-williams-sentenced-zero-day-exploits-russia/">Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker</a></li>

                    <li><a href="https://home.treasury.gov/news/press-releases/sb0404">Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools</a></li>

                    <li><a href="https://risky.biz/risky-bulletin-russia-starts-criminal-probe-of-telegram-founder-pavel-durov/">Risky Bulletin: Russia starts criminal probe of Telegram founder Pavel Durov</a></li>

                    <li><a href="https://therecord.media/ukraine-telegram-regulation-russia-sabotage-recruitment">Ukraine pushes tighter Telegram regulation, citing Russian recruitment of locals</a></li>

                    <li><a href="https://vmfunc.re/blog/persona">The watchers: how openai, the US government, and persona built an identity surveillance machine that files reports on you to the feds</a></li>

                    <li><a href="https://piunikaweb.com/2026/02/20/persona-denies-ice-dhs-ties-customer-email/">Persona emails customers saying they don’t work with ICE or DHS amid ‘surveillance’ claims</a></li>

                    <li><a href="https://www.akamai.com/blog/security-research/2026/feb/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis">Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513</a></li>

                    <li><a href="https://www.bloomberg.com/news/features/2026-02-19/vpn-used-by-us-government-failed-to-stop-china-state-sponsored-hackers">Ivanti hacked in 2021 via its own product</a></li>

                    <li><a href="https://therecord.media/fed-agencies-ordered-to-patch-dell-bug-after-exploitation-warning">Fed agencies ordered to patch Dell bug by Saturday after exploitation warning | The Record from Recorded Future News</a></li>

                    <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day">From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day</a></li>

                </ul>

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 Risky Business. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.