James Wilson

@jameswilson.io

Reformed CTO turned Podcaster @ https://risky.biz/

New solo pod from me delving into the real cost of having to switch from an open-weight LLM to a close-weight API. It's not an easy switch, especially for cybersecurity work. The trust boundary, privacy, capabilities, availability, and most of all model behaviour matters. 🎧 risky.biz/RBFEATURES33/

Benchmarks, borders and the true cost of AI regulation - Risky Business Media

The US government is flirting with the idea of regulating most open weight models out of existence. What would that mean for everyone who' [Read More]

risky.biz

Fittingly on that topic: Regarding Attacker-Defender asymmetry @ensarseker.bsky.social says to @jameswilson.io , that while attackers adopt AI very maturely and ar professionalizing their operations, defender can utilize AI to get even but: Many organisations are still learning to adopt AI. 🧵1/2

In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A smal [Read More]

risky.biz

FortiBleed is the antidote to vague “AI-powered attacker” talk. AI was wired into reconnaissance, credential processing, prioritisation, tooling, and workflow. They didn't prompt the agent, the agents prompted them. *That* is AI adoption for cyber. 🎧 New Podcast Episode: risky.biz/RBFEATURES32/

Fortibleed: The bleeding edge of AI cybercrime - Risky Business Media

In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A smal [Read More]

risky.biz

Mythos on your desk. Source-local code reviews with frontier-like capabilities. Karsten Nohl and I talked for an hour about this in the latest Risky Business Features episode available now on YouTube and your favourite Podcast app. 🎧 risky.biz/RBFEATURES30/ 📺 www.youtube.com/watch?v=nhS5...

Mythos on your desk? Using local LLMs for code reviews - Risky Business Media

In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code [Read More]

risky.biz

Fable 5 made guardrails the load-bearing safety mechanism. It's the same model as Mythos 5. Public safety depends on external controls doing exactly what they claim to do. And they didn't. I unpack the whole saga here: risky.biz/RBFEATURES27/

The state of the art in AI model jailbreaks - Risky Business Media

In this solo podcast episode, James Wilson breaks down the current state of AI model jailbreaks.If you've somehow missed the story, last w [Read More]

risky.biz

npm v12 won’t stop supply chain attacks. It’s a step forward, but the supply chain attacks and worms will continue. 🎧 risky.biz/RBFEATURES26/ Paul McCarty from @opensourcemalware.bsky.social joined me for this weeks Risky Business Features podcast to talk about npm and supply chain attacks.

Why NPM v12 won’t stop supply chain attacks - Risky Business Media

In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain att [Read More]

risky.biz

Vulnerabilities? Outages? Broken features? As long as it's in the name of AI innovation, KEEP GOING!! -- Seemingly most CEO's these days. So, what's a CISO to do? Hear from Brad Arkin (former CISO at Cisco, Adobe and Salesforce) on our latest Risky Business Features episode. risky.biz/RBFEATURES25/

Everything is getting much worse, much faster - Risky Business Media

In this podcast Brad Arkin joins James Wilson to talk about how the fear of being left behind in the AI era means enterprises are taking r [Read More]

risky.biz

New solo podcast on TeamPCP, trying to answer what we can learn about them from what they did and how they did it. This actor leaves so many unanswered questions (like... why?!).. but their arc from clumsy kubernetes crypto mining to supply-chain villains tell us a lot. risky.biz/RBFEATURES24/

Solo podcast: A deep dive on TeamPCP - Risky Business Media

In this solo episode, James Wilson takes a detailed look at TeamPCP. It started off by launching clumsy attacks against misconfigured Kube [Read More]

risky.biz

Really enjoyed the time with James at Risky Business. Between his James Kettle interview and mine: the models we have today can already do remarkable work; if you take the time to codify your expertise into scaffolding. And what that looks like with IronCurtain, and on what businesses need to do.

Patrick Gray@patrick.risky.biz · 3mo ago

If listening to Niels Provos talk to my colleague @jameswilson.io for 90 minutes about orchestrating older LLMs to find 0day as effectively as Mythos can sounds like a good time to you, boy do I have some great news… VIDEO: youtu.be/ksWbjE9uQyk AUDIO: risky.biz/RBFEATURES19/

I'm sure we could've gone for 3 hours... but Niels and I reigned ourselves in after 90 minutes of talking through exactly how lesser models can find 0day all day... if you know how to orchestrate them in a way that turns your techniques into their state machines.

Patrick Gray@patrick.risky.biz · 3mo ago

If listening to Niels Provos talk to my colleague @jameswilson.io for 90 minutes about orchestrating older LLMs to find 0day as effectively as Mythos can sounds like a good time to you, boy do I have some great news… VIDEO: youtu.be/ksWbjE9uQyk AUDIO: risky.biz/RBFEATURES19/

People kept saying LLMs won't find logic bugs, just memory corruption. Nicholas Carlini from Anthropic found a critical vulnerability in WolfSSL. Pure logic flaw. Missing hash function check = certificate forgery. CVSS 10. No memory corruption. Model found and exploited it. risky.biz/RBFEATURES16/

Feature Interview: Nicholas Carlini, Anthropic - Risky Business Media

In this episode, Anthropic’s Nicholas Carlini joins Patrick Gray and James Wilson to talk about advancements in AI-driven vulnerability re [Read More]

risky.biz

Mythos and 0day: a hackers perspective. 🎧 risky.biz/RBFEATURES13/ … I wanted to hear what Anthropic’s #Mythos really means for someone who hacks for a living. Jamieson O’Reilly from DVULN and Aether AI join me for this chat. Enjoy!

Mythos and 0day: A hacker’s perspective - Risky Business Media

In this episode of Risky Business Features, James Wilson chats to professional hacker Jamieson O’Reilly about Anthropic’s Mythos and the i [Read More]

risky.biz

New episode with Geoff White (BBC Lazarus Heist, Cyber Hack podcast) on what actually happens after North Korea gets hired. Not the headline version. The full machine: deep fake interviews, 72-laptop farms, military units doing your tickets, a $30M bagman on a private jet. risky.biz/RBFEATURES12/

What happens after North Korea infiltrates? - Risky Business Media

In this episode, investigative journalist Geoff White joins James Wilson for a look into the complex machine that is North Korea’s IT work [Read More]

risky.biz

Between seeing the epic supply chain attacks this week, and the internal pressure to move fast with AI adoption, I think all of us in senior tech leadership roles are going to have to bend on things that previously were an absolute hard no. risky.biz/RBFEATURES11/

Why CISOs need to be more flexible in the AI era - Risky Business Media

In this episode, James Wilson chats with Brad Arkin (former CISO of Adobe, Cisco and Salesforce) to talk about the mounting pressure that [Read More]

risky.biz

This was a wild ride. Went into this with no expectations… came out of it understanding Coruna exploit kit even better than after my deep-dive episode… and a firm belief that an LLM could modernise these kits…

Patrick Gray@patrick.risky.biz · 4mo ago

Oh man... the RB team actually animated James Wilson's clanker cohost! This is a clip from the podcast @jameswilson.io did where he got his OpenClaw agent to use Claude to help him look for 0day in Webkit. risky.biz/RBFEATURES10/

Risky Business Features: I ran an incident review of the Stryker cyberattack with Brad Arkin (former CISO at Cisco/Adobe/Salesforce). Brad's framework for how to run your own internal review is practical and actionable. Manage a device fleet, this is essential listening. risky.biz/RBFEATURES8

When disaster strykes - Risky Business Media

In this episode of Risky Business Features, James Wilson and Brad Arkin discuss the attack that devastated medtech company Stryker. It tur [Read More]

risky.biz