Risky Business

Risky Business #827 -- Iranian cyber threat actors are down but not out

30 snips
Mar 4, 2026
Sydney Maroney, Head of threat hunting at Nebulock and creator of an open-source Agentic Threat Hunting Framework, discusses AI-driven threat hunting and her framework. She covers agent design, session memory and documentation. She explains how AI speeds hunts while stressing verification and shows where to find the framework on GitHub.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Missile Strike Means Amazon May Have To Rebuild Entire Site

  • A missile hit an Amazon data center in Dubai, causing fire and sparking concerns about hardware integrity and supply-chain trust.
  • James Wilson explains Amazon's strict device-in/out policies force likely full rebuilds after physical breach.
INSIGHT

Leaked Triangulation Exploit Chain Sparked Criminal Use

  • The Triangulation iOS exploit toolkit leaked and is now used by criminals; hosts link this to an insider sale from L3Harris/Trenchant.
  • Patrick Gray argues Peter Williams likely sold the kit, undermining an NSA campaign and causing major harm.
INSIGHT

LLM Embeddings Make Cross‑Platform De‑Anonymization Trivial

  • LLMs can enable large-scale de‑anonymization by using embeddings to correlate writing styles across platforms.
  • James Wilson notes this approach scales where past techniques failed and used only public APIs, lowering the bar for abuse.
Get the Snipd Podcast app to discover more snips from this episode
Get the app