# Risky Business #839 -- TeamPCP stole GitHub's internal repos Page: https://stenobird.com/podcast/risky-business-548735/risky-business-839-teampcp-stole-github-s-internal-repos Text version: https://stenobird.com/podcast/risky-business-548735/risky-business-839-teampcp-stole-github-s-internal-repos.md Podcast: [Risky Business](https://stenobird.com/podcast/risky-business-548735) Published: 2026-05-27T05:45:37+00:00 Episode link: https://risky.biz/RB839/ Audio file: https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RB839.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/risky-business-548735/episodes/risky-business-839-teampcp-stole-github-s-internal-repos Duration seconds: 3623 ## Resource On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Much, much more This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun! This episode is also available on YouTube ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/risky-business-548735/episodes/risky-business-839-teampcp-stole-github-s-internal-repos/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/risky-business-548735/risky-business-839-teampcp-stole-github-s-internal-repos.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.