Episode

Risky Business #839 -- TeamPCP stole GitHub's internal repos

Podcast
Risky Business
Published
May 27, 2026
Duration seconds
3623
Processing state
not_requested
Canonical source
https://risky.biz/RB839/
Audio
https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RB839.mp3
JSON
/v1/public/podcasts/risky-business-548735/episodes/risky-business-839-teampcp-stole-github-s-internal-repos
Markdown
/podcast/risky-business-548735/risky-business-839-teampcp-stole-github-s-internal-repos.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/risky-business-548735/episodes/risky-business-839-teampcp-stole-github-s-internal-repos/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/risky-business-548735/risky-business-839-teampcp-stole-github-s-internal-repos.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Much, much more This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun! This episode is also available on YouTube