
Risky Business Risky Business #816 -- Copilot Actions for Windows is extremely dicey
25 snips
Nov 26, 2025 H.D. Moore, a renowned security researcher and creator of Metasploit, joins to discuss RunZero's innovative tools. He elaborates on integrating RunZero with Bloodhound-style graph databases to enhance security analysis. H.D. also dives into the exciting future of AI in cybersecurity, touching on the challenges of varied deployment models. Additionally, he highlights how exposure management and user experience are shifting in product development, making security more effective and accessible.
AI Snips
Chapters
Transcript
Episode notes
Supply-Chain Risk From Deep Integrations
- Third-party integrations with deep API access create supply-chain risk across many customers.
- Patrick Gray and Adam Boileau note Salesforce spotted unusual API activity originating from Gainsight connectors.
Screenshots Don’t Always Mean Full Breach
- Insider screenshots and claims can inflate perceived breach impact quickly.
- Patrick Gray highlights CrowdStrike detected and fired an insider who leaked system screenshots.
APTs Exploit Legit Dev Tools
- APTs reuse legitimate developer tooling and tunnels to evade network controls.
- Adam Boileau describes APT31 abusing Microsoft dev tunnels and other tradecraft for persistence.
