Sign in

James Wilson

@jameswilson.io
135 followers 34 following 60 posts

Reformed CTO turned Podcaster @ risky.biz

PostsRepliesMedia
James Wilson @jameswilson.io · 23/09/2026
Ransom payments end up in the wallets of drug and other crime gangs too. This changed my mind about ransom payment regulation. Geoff White (CyberHack, Conti Files, Lazarus Heist) and I sat down for a chat about just how ransomware gangs turn traceable bitcoin into cash. 🎧 risky.biz/RBFEATURES40/
risky.biz
How to launder illicit Bitcoin - Risky Business Media
In this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware [Read More]
043
James Wilson @jameswilson.io · 15/09/2026
How? How did Apple manage to make Siri *even worse* in watchOS / iOS 27.
100
James Wilson @jameswilson.io · 14/09/2026
I wanted to know how supply chain malware research is done. Who better to chat to about this than Paul McCarty from @opensourcemalware.bsky.social! We recorded an 85 minute deep dive into malware research techniques, tradecraft and risk mitigations. Enjoy! risky.biz/RBFEATURES39/
risky.biz
Hunting software supply chain malware - Risky Business Media
In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious p [Read More]
141
James Wilson @jameswilson.io · 08/09/2026
ICYMI: Trump's cyber memo is not a general licence for companies to hack back or a letter of marque. It creates a government-controlled program for vetted firms to surveil and disrupt foreign criminal groups. @bradarkin.bsky.social and I unpack what it could mean for CISOs. risky.biz/RBFEATURES38/
risky.biz
Who gets to hack the hackers? - Risky Business Media
In this podcast episode, Brad Arkin joins James Wilson to chat about the Trump administration's call to let private entities conduct cyber [Read More]
012
Reposted by James Wilson
Catalin Cimpanu @campuscodi.risky.biz · 07/09/2026
Hey look... I bought an N-able N-central server!
1111
James Wilson @jameswilson.io · 05/09/2026
Having the (awful) Music app open when double clicking an audio file is such a pain, but it worked. So instead I tried setting the "Always open in..." to QuickTime Player. But... now apparently that audio file that could open in Music could be malware. Another step closer to ditching macOS.
000
James Wilson @jameswilson.io · 28/08/2026
TeamPCP caused global software supply-chain chaos while leaving a trail of recycled handles, old forum records and passive DNS. Brian Krebs joined me to explain how he followed it to Perth, and what he learned from speaking with the group’s alleged leader. risky.biz/RBFEATURES37/
risky.biz
How Brian Krebs doxxed TeamPCP - Risky Business Media
In this podcast episode, James Wilson chats with Brian Krebs about the investigation that led him from recycled cybercrime handles and old [Read More]
172
James Wilson @jameswilson.io · 20/08/2026
If an AI finds a vulnerability or attack no human researcher had considered, is it still “just predicting tokens”? My latest Risky Business Features interview with @albinowax.bsky.social gets into AI, HTTP desync, novel security research, and why the expert still matters. risky.biz/RBFEATURES35/
risky.biz
James Kettle on inventing new attack techniques with LLMs - Risky Business Media
In this podcast episode, James Wilson chats with PortSwigger's Director of Research James Kettle about using an LLM to develop genuinely n [Read More]
011
Reposted by James Wilson
Activ8te @activ8te.bsky.social · 15/08/2026
I built Token Envy because “Claude Code feels slow today” was impossible to verify. It turns local session metadata into a private performance baseline and shareable card. Prompts stay on your machine. Try it: npx tokenenvy www.npmjs.com/package/toke... #TokenEnvy
122
James Wilson @jameswilson.io · 11/08/2026
ICYMI: I published a pod on private AI inference. Hosted LLMs that hide your chats from the provider. Trusted execution environments, GPU confidential computing, attestation, KV-cache side channels, and why “we don’t train on your data” is not the same as “we can’t see it.” risky.biz/RBFEATURES34/
risky.biz
How private LLM inference actually works - Risky Business Media
In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without t [Read More]
032
Reposted by James Wilson
Patrick Gray @patrick.risky.biz · 09/08/2026
This is the Cam Wilson story I spoke about on last Wednesday’s show… published today www.abc.net.au/news/2026-08...
abc.net.au
How a simple request for AI to book a gym class exposed a major threat
When Andrew asked his AI personal assistant to book him a spot in a gym class, he had no idea he would accidentally initiate an autonomous cyber attack.
3188
James Wilson @jameswilson.io · 08/08/2026
We’re putting more and more sensitive thinking into LLMs: code, credentials, product plans, deeply personal context... So who actually gets to see the prompt? I spoke with Tinfoil co-founder Tanya Verma about how Private LLM Inference works, and the social implications. risky.biz/RBFEATURES34/
risky.biz
How private LLM inference actually works - Risky Business Media
In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without t [Read More]
031
James Wilson @jameswilson.io · 29/07/2026
New solo pod from me delving into the real cost of having to switch from an open-weight LLM to a close-weight API. It's not an easy switch, especially for cybersecurity work. The trust boundary, privacy, capabilities, availability, and most of all model behaviour matters. 🎧 risky.biz/RBFEATURES33/
risky.biz
Benchmarks, borders and the true cost of AI regulation - Risky Business Media
The US government is flirting with the idea of regulating most open weight models out of existence. What would that mean for everyone who' [Read More]
121
James Wilson @jameswilson.io · 27/07/2026
Ah, there is it. Settings -> Notifications…
000
Reposted by James Wilson
Layer 8½ @mbrookspetersen.eurosky.social · 25/07/2026
Fittingly on that topic: Regarding Attacker-Defender asymmetry @ensarseker.bsky.social says to @jameswilson.io , that while attackers adopt AI very maturely and ar professionalizing their operations, defender can utilize AI to get even but: Many organisations are still learning to adopt AI. 🧵1/2
risky.biz
In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A smal [Read More]
121
James Wilson @jameswilson.io · 17/07/2026
FortiBleed is the antidote to vague “AI-powered attacker” talk. AI was wired into reconnaissance, credential processing, prioritisation, tooling, and workflow. They didn't prompt the agent, the agents prompted them. *That* is AI adoption for cyber. 🎧 New Podcast Episode: risky.biz/RBFEATURES32/
risky.biz
Fortibleed: The bleeding edge of AI cybercrime - Risky Business Media
In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A smal [Read More]
032
James Wilson @jameswilson.io · 02/07/2026
Uhh... my Mac just binned Codex and claimed it was malware. Where does one find a bit more info about... *why* this happened?!
130
James Wilson @jameswilson.io · 30/06/2026
Mythos on your desk. Source-local code reviews with frontier-like capabilities. Karsten Nohl and I talked for an hour about this in the latest Risky Business Features episode available now on YouTube and your favourite Podcast app. 🎧 risky.biz/RBFEATURES30/ 📺 www.youtube.com/watch?v=nhS5...
risky.biz
Mythos on your desk? Using local LLMs for code reviews - Risky Business Media
In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code [Read More]
041
James Wilson @jameswilson.io · 18/06/2026
Fable 5 made guardrails the load-bearing safety mechanism. It's the same model as Mythos 5. Public safety depends on external controls doing exactly what they claim to do. And they didn't. I unpack the whole saga here: risky.biz/RBFEATURES27/
risky.biz
The state of the art in AI model jailbreaks - Risky Business Media
In this solo podcast episode, James Wilson breaks down the current state of AI model jailbreaks.If you've somehow missed the story, last w [Read More]
030
James Wilson @jameswilson.io · 13/06/2026
I’d like to thank Trump personally for freeing up more capacity for the real OG, Claude 4.8. Thanks bud!
020
James Wilson @jameswilson.io · 13/06/2026
npm v12 won’t stop supply chain attacks. It’s a step forward, but the supply chain attacks and worms will continue. 🎧 risky.biz/RBFEATURES26/ Paul McCarty from @opensourcemalware.bsky.social joined me for this weeks Risky Business Features podcast to talk about npm and supply chain attacks.
risky.biz
Why NPM v12 won’t stop supply chain attacks - Risky Business Media
In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain att [Read More]
120
James Wilson @jameswilson.io · 06/06/2026
Vulnerabilities? Outages? Broken features? As long as it's in the name of AI innovation, KEEP GOING!! -- Seemingly most CEO's these days. So, what's a CISO to do? Hear from Brad Arkin (former CISO at Cisco, Adobe and Salesforce) on our latest Risky Business Features episode. risky.biz/RBFEATURES25/
risky.biz
Everything is getting much worse, much faster - Risky Business Media
In this podcast Brad Arkin joins James Wilson to talk about how the fear of being left behind in the AI era means enterprises are taking r [Read More]
171
James Wilson @jameswilson.io · 04/06/2026
New solo podcast on TeamPCP, trying to answer what we can learn about them from what they did and how they did it. This actor leaves so many unanswered questions (like... why?!).. but their arc from clumsy kubernetes crypto mining to supply-chain villains tell us a lot. risky.biz/RBFEATURES24/
risky.biz
Solo podcast: A deep dive on TeamPCP - Risky Business Media
In this solo episode, James Wilson takes a detailed look at TeamPCP. It started off by launching clumsy attacks against misconfigured Kube [Read More]
031
James Wilson @jameswilson.io · 26/05/2026
Supply chain compromise. You know it's going to happen to you. It's inevitable. So, here's how to survive it with advice from ex-Adobe/Cisco/Salesforce CISO, Brad Arkin: 🎧 risky.biz/RBFEATURES23/
risky.biz
How to survive supply chain attacks - Risky Business Media
In this podcast James Wilson chats with Brad Arkin about why software supply chain attacks have gone from rare, once-in-a-while disasters [Read More]
031
James Wilson @jameswilson.io · 24/05/2026
Uhhh... Apple... I'm, I'm already on Tahoe.
020
Reposted by James Wilson
Xint by Theori @xint-io.bsky.social · 22/05/2026
When @jameswilson.io reached out, he was upfront with his criticism for how we disclosed copy fail publicly. But we appreciated his willingness to listen and understand how AI has exposed risks in established disclosure protocals that had been dormant under the surface...
152
Reposted by James Wilson
Activ8te @activ8te.bsky.social · 08/05/2026
Really enjoyed the time with James at Risky Business. Between his James Kettle interview and mine: the models we have today can already do remarkable work; if you take the time to codify your expertise into scaffolding. And what that looks like with IronCurtain, and on what businesses need to do.
024
James Wilson @jameswilson.io · 08/05/2026
I'm sure we could've gone for 3 hours... but Niels and I reigned ourselves in after 90 minutes of talking through exactly how lesser models can find 0day all day... if you know how to orchestrate them in a way that turns your techniques into their state machines.
061
Reposted by James Wilson
Patrick Gray @patrick.risky.biz · 04/05/2026
If you would like to see a preview of @jameskettle.com's Blackhat talk "the HTTP terminator" then check out this interview my colleague @jameswilson.io recorded with him. Some pretty freaky stuff! VIDEO: www.youtube.com/watch?v=GdFG... AUDIO: risky.biz/RBNEWSSI126/
youtube.com
Sponsored: James Kettle built an AI hacker
YouTube video by Risky Business Media
2157
James Wilson @jameswilson.io · 28/04/2026
People kept saying LLMs won't find logic bugs, just memory corruption. Nicholas Carlini from Anthropic found a critical vulnerability in WolfSSL. Pure logic flaw. Missing hash function check = certificate forgery. CVSS 10. No memory corruption. Model found and exploited it. risky.biz/RBFEATURES16/
risky.biz
Feature Interview: Nicholas Carlini, Anthropic - Risky Business Media
In this episode, Anthropic’s Nicholas Carlini joins Patrick Gray and James Wilson to talk about advancements in AI-driven vulnerability re [Read More]
141
James Wilson @jameswilson.io · 20/04/2026
Mythos.. what does it really mean for a startup? Is it the end of secure software, a new SaaSpocalypse, time to give up integrating with enterprises? Yaniv Bernstein and I covered all this and more on today's Risky Business Features. risky.biz/RBFEATURES15/
021
James Wilson @jameswilson.io · 13/04/2026
Mythos and 0day: a hackers perspective. 🎧 risky.biz/RBFEATURES13/ … I wanted to hear what Anthropic’s #Mythos really means for someone who hacks for a living. Jamieson O’Reilly from DVULN and Aether AI join me for this chat. Enjoy!
risky.biz
Mythos and 0day: A hacker’s perspective - Risky Business Media
In this episode of Risky Business Features, James Wilson chats to professional hacker Jamieson O’Reilly about Anthropic’s Mythos and the i [Read More]
010
James Wilson @jameswilson.io · 08/04/2026
New episode with Geoff White (BBC Lazarus Heist, Cyber Hack podcast) on what actually happens after North Korea gets hired. Not the headline version. The full machine: deep fake interviews, 72-laptop farms, military units doing your tickets, a $30M bagman on a private jet. risky.biz/RBFEATURES12/
risky.biz
What happens after North Korea infiltrates? - Risky Business Media
In this episode, investigative journalist Geoff White joins James Wilson for a look into the complex machine that is North Korea’s IT work [Read More]
110
James Wilson @jameswilson.io · 04/04/2026
Sad claw.
000
Reposted by James Wilson
Catalin Cimpanu @campuscodi.risky.biz · 03/04/2026
-Russia will revoke licenses for unruly ISPs -Cyberattack disrupts access to newspaper archives across the US -Node.js pauses bug bounty program after funding lapse -Apple backports DarkSword patches -Hasbro has a data breach Podcast: risky.biz/RBNEWS546/ Newsletter: news.risky.biz/risky-bullet...
1117
James Wilson @jameswilson.io · 03/04/2026
Between seeing the epic supply chain attacks this week, and the internal pressure to move fast with AI adoption, I think all of us in senior tech leadership roles are going to have to bend on things that previously were an absolute hard no. risky.biz/RBFEATURES11/
risky.biz
Why CISOs need to be more flexible in the AI era - Risky Business Media
In this episode, James Wilson chats with Brad Arkin (former CISO of Adobe, Cisco and Salesforce) to talk about the mounting pressure that [Read More]
110
James Wilson @jameswilson.io · 03/04/2026
The long awaited next episode in How the World Got Owned! Part 1 of the 1990's. It's awesome. Enjoy!
023
James Wilson @jameswilson.io · 31/03/2026
This was a wild ride. Went into this with no expectations… came out of it understanding Coruna exploit kit even better than after my deep-dive episode… and a firm belief that an LLM could modernise these kits…
000
James Wilson @jameswilson.io · 28/03/2026
Between podcasts, baking some sourdough. Wood fired soy and linseed with a mix of rye and white flour.
Two homemade loaves of sourdough on a cooling rack
040
Reposted by James Wilson
Catalin Cimpanu @campuscodi.risky.biz · 25/03/2026
-The Intellexa CEO is pissed!!! -Google launches threat disruption unit -German police visit companies in the dead of night about software bugs -FTC bans all foreign-made routers -Firefox now has a built-in VPN Podcast: risky.biz/RBNEWS542/ Newsletter: news.risky.biz/risky-bullet...
1158
James Wilson @jameswilson.io · 24/03/2026
Risky Business Features: I ran an incident review of the Stryker cyberattack with Brad Arkin (former CISO at Cisco/Adobe/Salesforce). Brad's framework for how to run your own internal review is practical and actionable. Manage a device fleet, this is essential listening. risky.biz/RBFEATURES8
risky.biz
When disaster strykes - Risky Business Media
In this episode of Risky Business Features, James Wilson and Brad Arkin discuss the attack that devastated medtech company Stryker. It tur [Read More]
010
James Wilson @jameswilson.io · 19/03/2026
Model Context Protocol (MCP) is Dead. Killed by the shell. MCP showed us that LLM + Tools = real utility and productivity. Then AI Agents showed us they just want a shell. That has serious security implications. 🎧 risky.biz/RBFEATURES7/
520
Reposted by James Wilson
Patrick Gray @patrick.risky.biz · 18/03/2026
This week's show is up! Features @jameswilson.io, @metlstorm.risky.biz and yours truly talking through the week's news, from the Stryker breach to the latest research into "emergent cyber behaviours" in AI agents. Audio: risky.biz/RB829/ Video: www.youtube.com/watch?v=09js...
youtube.com
Risky Business (829): Sneaky lobsters: Why AI is the new insider threat
YouTube video by Risky Business Media
4166
Reposted by James Wilson
Patrick Gray @patrick.risky.biz · 06/03/2026
The L atest edition of Risky Business Features with James Wilson and former Adobe, Cisco and Salesforce CISO Brad Arkin is up: Being a Wartime CISO Support us by subscribing to our new Features feed! risky.biz/RBFEATURES4/
092
Reposted by James Wilson
Patrick Gray @patrick.risky.biz · 02/03/2026
We quietly launched this last week. It's early days and we only have a dozen or so vendors there so far, but the plan is to have pretty decent coverage of the industry after a while
1204
Reposted by James Wilson
Patrick Gray @patrick.risky.biz · 25/02/2026
I've read of today's Seriously Risky Business newsletter and it's absolutely terrific... it'll be out in a few hours. If you're not subscribed, get on it! (You can subscribe here: risky.biz/newsletters/)
risky.biz
Newsletters - Risky Business Media
Newsletters
0121
James Wilson @jameswilson.io · 20/02/2026
100,000 prompts to clone a frontier model on to a free open-weight model? Easy done, it turns out! I discussed this with Pat and Adam this week on Risky Biz. Link below! 📺 www.youtube.com/watch?v=kNVm... 🎧 risky.biz/RB825/
000
James Wilson @jameswilson.io · 18/02/2026
Stop saying "technical debt" to executives. Debt is loaded. Mortgages are leverage, credit cards are emergencies. You don't know which mental model they're applying. And the ask is always net-negative. Reframe it as a velocity tax. Full video: youtube.com/watch?v=pWwm-NYMsu0
youtube.com
"Technical Debt" Is Killing Your Credibility With Executives
YouTube video by Paved With Good Intentions
000
James Wilson @jameswilson.io · 12/02/2026
I dropped in to this week's Risky Business episode to talk about how the Anthriopic C Compiler is interesting, but a lot of the coverage has missed the point! It's about agents working together, not a new C Compiler. 🤦🏻‍♂️ risky.biz/RB824/
risky.biz
Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly - Risky Business Media
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:* Microsoft reshuffles security leaders [Read More]
000
James Wilson @jameswilson.io · 04/02/2026
Openclaw 🌶️ AI agent. Not a security problem if used carefully. Very easy to misconfigure. Blast radius disastrous. Clawhub 🌶️🌶️ package registry for skills (prompts). Malicious skills and download numbers faked. Moltbook 🌶️🌶️🌶️ Reddit for agents. Do not use this. risky.biz/RB823/ #moltbook #openclaw
risky.biz
Risky Business Media
News and commentary for cybersecurity and intelligence professionals
000