
Risky Business Risky Business #827 -- Iranian cyber threat actors are down but not out
30 snips
Mar 4, 2026 Sydney Maroney, Head of threat hunting at Nebulock and creator of an open-source Agentic Threat Hunting Framework, discusses AI-driven threat hunting and her framework. She covers agent design, session memory and documentation. She explains how AI speeds hunts while stressing verification and shows where to find the framework on GitHub.
AI Snips
Chapters
Transcript
Episode notes
Missile Strike Means Amazon May Have To Rebuild Entire Site
- A missile hit an Amazon data center in Dubai, causing fire and sparking concerns about hardware integrity and supply-chain trust.
- James Wilson explains Amazon's strict device-in/out policies force likely full rebuilds after physical breach.
Leaked Triangulation Exploit Chain Sparked Criminal Use
- The Triangulation iOS exploit toolkit leaked and is now used by criminals; hosts link this to an insider sale from L3Harris/Trenchant.
- Patrick Gray argues Peter Williams likely sold the kit, undermining an NSA campaign and causing major harm.
LLM Embeddings Make Cross‑Platform De‑Anonymization Trivial
- LLMs can enable large-scale de‑anonymization by using embeddings to correlate writing styles across platforms.
- James Wilson notes this approach scales where past techniques failed and used only public APIs, lowering the bar for abuse.
