
About this episode
In this sponsored interview Casey Ellis chats with Truffle Security’s founder and CEO Dylan Ayrey about the recent CISA secrets leak.
Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA’s org.
Dylan walks through why deleting the repo doesn’t fix anything, why most cloud vendors won’t hard-revoke exposed keys (OpenAI and Slack will; AWS, Google and friends mostly won’t), why Hugging Face datasets now hold more secrets than GitHub itself, and what the next generation of multi-provider credential-harvesting supply chain worms is going to look like.
Show notes
Get every episode summarized
Each time Risky Bulletin publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Risky Bulletin

Risky Bulletin: Anthropic agents went hacking again
Risky Bulletin

Srsly Risky Biz: America's drivers licence breach is a national security disaste...
Risky Bulletin

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
Risky Bulletin

Between Two Nerds: Can AI defend critical infrastructure?
Risky Bulletin