Mato
ShowsHow it worksAI talentsFree toolsPricing
Book a demo
ShowsHow it worksAI talentsFree toolsPricingSign in
Mato
Mato

The first generation of AI talents. Live AI media for brands, networks and creators.

ElevenLabs GrantsAWS ActivateGoogle for StartupsNVIDIA Inception Program

Product

  • How it works
  • AI talents
  • Documentation
  • The studio
  • Pricing
  • Embed player
  • Mato MCP
  • Mato Voice
  • Voice Studio
  • Changelog

Company

  • About
  • Vision
  • Partners
  • Affiliates
  • Blog
  • CustomersComing soon
  • CareersComing soon
  • Press kit
  • Contact

Resources

  • Investor overview
  • Free podcast tools
  • Free podcast transcription
  • Podcast ROI calculator
  • API docsComing soon
  • SecurityComing soon
  • StatusComing soon

© 2026 Mato. All rights reserved.

English · Multiple languages available

PrivacyTerms

Live Interview

And why does that matter?

This is how a Mato agent talks. Take the other seat: answer a few and feel it follow the thread.

Try it yourself

Podcast charts

Risky Business Features

Published by Risky Business Media

  • Technology

Join reformed CTO James Wilson as he dives deep on cybersecurity topics through an enterprise lens. From solo content and interviews with CISOs and researchers to vendor and startup deep dives, James does a bit of everything.

Listen on Apple Podcasts, opens in a new tabMake something like it

On the charts

3 chart placements

Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.

  1. Number 72TechnologyAustralia
  2. Number 109TechnologyUnited Kingdom
  3. Number 129TechnologyNorway

From the feed

Recent episodes

The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.

  1. Hunting software supply chain malware from Risky Business Features, opens in a new tab

    Sep 11, 20261 hr 15 min

    In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious packages, GitHub repositories and developer tools. Paul walks James through static analysis, deobfuscation and reconstructing multi-stage kill chains to identify what attackers are trying to steal. They also discuss how LLMs make malware development easier while introducing operational security mistakes. The pair examine DPRK tradecraft, blockchain-based payload delivery and what Paul calls Pollen Rider, which can reinfect developers through their own repositories. Show notes

  2. Who gets to hack the hackers? from Risky Business Features, opens in a new tab

    Sep 3, 202640 min

    In this podcast episode, Brad Arkin joins James Wilson to chat about the Trump administration’s call to let private entities conduct cyber operations against criminal groups. Brad’s firsthand experience responding to cyber incidents alongside US law enforcement gives him a unique perspective on how government and private sector relationships work, and how this program could improve the ability of both sides to tackle cybercrime. James and Brad also explore who might participate in these campaigns and whether the government will be able to effectively oversee them. Show notes

  3. How Brian Krebs doxxed TeamPCP from Risky Business Features, opens in a new tab

    Aug 28, 202629 min

    In this podcast episode, James Wilson chats with Brian Krebs about the investigation that led him from recycled cybercrime handles and old forum records to the true identity of TeamPCP’s alleged leader in Perth. TeamPCP is the hacker group that has gone berserk in the software supply chain over the last year or so, stealing credentials to compromise developers, their software packages, and their repositories. In this interview Brian talks about his Signal conversations with the group’s ringleader, the strange Cybercats community surrounding TeamPCP, and the passive DNS breakthrough that helped him unmask what he thinks are the ringleader’s true identities. Show notes Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

  4. James Kettle on inventing new attack techniques with LLMs from Risky Business Features, opens in a new tab

    Aug 17, 20261 hr 17 min

    In this podcast episode, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques. Kettle has built what he calls the HTTP Terminator, an autonomous research system that generates and tests tens of thousands of potentially new HTTP desync techniques. The Terminator, which makes use of Kettle’s own research methodology, has already come up with new desync methods that James hadn’t thought of before. Kettle and Wilson discuss how to develop and evaluate machine-generated ideas without drowning in false positives, and why the most powerful part of the process is the discovery cascade, where one unexpected result becomes the seed for another. The upshot is AI can conduct genuinely novel security research, but don’t expect to one-shot your way to an army of robot hackers. Show notes Can AI do novel security research? Meet the HTTP Terminator | PortSwigger Research HTTP/1.1 must die: the desync endgame

  5. How private LLM inference actually works from Risky Business Features, opens in a new tab

    Aug 7, 20261 hr 23 min

    In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without the inference provider seeing your prompts. Tanya talks James through how private inference works, from trusted execution environments and hardware attestation, to TLS termination and GPU isolation. Customers can verify the exact code and model processing their data, while Tinfoil and its infrastructure providers remain locked out. That’s clever engineering… but who really needs it? Is private inference only useful if you’re doing something bad, or will it become a privacy baseline like TLS? James and Tanya discuss the costs and trade-offs, and how open weights make private inference more transparent and trustworthy. Show notes

  6. Benchmarks, borders and the true cost of AI regulation from Risky Business Features, opens in a new tab

    Jul 28, 202639 min

    The US government is flirting with the idea of regulating most open weight models out of existence. What would that mean for everyone who’s currently using them? Policymakers who just look at the benchmarks and token costs might think frontier and open weight AI models are all interchangeable. That they can just banhammer them without causing any disruption. That’s far from the truth. In this solo podcast, James Wilson looks beyond the US vs China AI race rhetoric and instead games out what the real world consequences of the US government slapping bans on AI models could be. Show notes

  7. Fortibleed: The bleeding edge of AI cybercrime from Risky Business Features, opens in a new tab

    Jul 16, 202648 min

    In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A small investigation into a curiously open directory on an unknown server expanded into the discovery of an attack that targeted 400,000 Fortinet devices. As Ensar says, each time the SOCRadar team pulled a single thread, it led to a tapestry of AI-enabled cybercrime. They uncovered custom initial access, persistence and packet sniffing tools, as well as direct links to the INC and Lynx ransomware operations. Most interesting though is the use of AI to design, implement and operate all aspects of the campaign across a team of 20 individual actors. Operating more like a modern software company than a traditional cybercrime gang, Fortibleed serves as our first in-depth look at the future of cybercrime. Show notes SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations

  8. What to do 'til the bugpocalypse gets here from Risky Business Features, opens in a new tab

    Jul 10, 202644 min

    In this podcast episode Brad Arkin joins James Wilson to discuss how defenders can get ahead of the late-running bugpocalypse. While we’re confident the offensive cybersecurity capabilities of frontier and open-weight LLMs are real, attackers don’t yet seem able to fully utilise them. This creates a window of opportunity for defenders to tackle the threat. There are a few well-funded and seemingly overlapping industry efforts under way including Athena, Akrites, and Patch the Planet. But, as Brad says in this interview, there’s too much focus on fixing bugs and traditional vulnerability triage, and not enough on exploring how to make entire classes of vulnerabilities inert. Show notes

  9. Mythos on your desk? Using local LLMs for code reviews from Risky Business Features, opens in a new tab

    Jun 30, 20261 hr 11 min

    In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code reviews. In essence, Karsten created a hybrid code reviewing system where both cloud and local models are used to orchestrate, triage outputs, and write reports. In this system, only the local LLMs have source code access, with the cloud models used to manage the local models. In this “source-local” review technique, the source code never leaves the local endpoint, which is a requirement for some reviews. But funnily enough, Karsten was able to use this system to generate findings that were as impressive as when using frontier models directly. In a nutshell, Karsten proved it’s possible to use locally-hosted, open-weight models running on commodity hardware to produce findings comparable to those discovered by frontier cloud models. This episode is also available on YouTube . Show notes Beyond Fable: Can a Local LLM Replace Cloud AI for Security Code Reviews Mythos smythos! How to find 0day with lesser models

  10. Pitching security startups to VCs in the AI era from Risky Business Features, opens in a new tab

    Jun 23, 202635 min

    In this podcast Patrick Gray and James Wilson chat with Decibel Partners founder and Managing Partner Jon Sakoda to talk about pitching cybersecurity startups to VC firms in the AI age. Coding agents and large language models have made it easier than ever to create software products, but despite this, the bar for what interests an investor is still largely the same. Everyone can run the marathon, but it’s usually the same few folks who finish first. So tune in to hear Jon share with us his wisdom on when to start the conversation with investors, how to leverage the experience of the founder community, and what founders should watch out for. This episode is also available on YouTube Show notes

  11. How using open weight models can blow up in your face from Risky Business Features, opens in a new tab

    Jun 19, 202643 min

    In this podcast episode James Wilson and Brad Arkin talk about how to safely use open weight large language models in the enterprise. The cost of frontier models was already driving interest in freely available open weight models like DeepSeek, Kimi and Qwen. But now the US government is forcing Anthropic to pull its Fable and Mythors models from the market, the argument for having greater control over your own AI stack is stronger than ever. But as you’ll hear in this episode, the model itself is just one component of the complex tech stack you’ll need to spin up if you want local inference. There’s a lot of moving parts, each of which comes with its own supply chain risks. So whether you’re hosting these models on your own hardware or via a SaaS provider, there’s a lot to ponder! Show notes

  12. The state of the art in AI model jailbreaks from Risky Business Features, opens in a new tab

    Jun 16, 202652 min

    In this solo podcast episode, James Wilson breaks down the current state of AI model jailbreaks. If you’ve somehow missed the story, last week Anthropic released its Fable 5 and Mythos 5 models to the public. In the name of safety, both models were guardrailed up the wazoo, but that didn’t stop a bunch of jailbreakers from figuring out how to bypass at least some of their safety restrictions. In response to these guardrail bypasses the White House issued an export control directive on the models, citing national security concerns. But was the Trump administration right to do this? Do these jailbreaks represent a threat to the security of the USA, or was the export restriction overkill? Tune in to find out! Show notes Pliny the Elder on Fable 5 Jailbreak whoJumper's response to Pliny ConfusedPilot: Confused Deputy Risks in RAG-based LLMs

  13. Why NPM v12 won’t stop supply chain attacks from Risky Business Features, opens in a new tab

    Jun 12, 202638 min

    In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain attack mitigations coming in NPM v12. NPM disabling (by default) auto-run install scripts and dynamic dependencies is a positive step forward… but it’ll take years for this new version to be adopted, and these changes do nothing to prevent malicious packages being imported into projects. Further, Paul thinks disabling these features by default will introduce friction that will cause them to be re-enabled. When the choice is “this builds” and “this is less prone to malware”, the former will always win. Show notes

  14. Everything is getting much worse, much faster from Risky Business Features, opens in a new tab

    Jun 5, 202623 min

    In this podcast Brad Arkin joins James Wilson to talk about how the fear of being left behind in the AI era means enterprises are taking risks that would have been considered insane just a couple of years ago. Fears around outages or being hacked have been trumped by fears of being labelled an AI laggard. So where are we all going? Say hello to tech debt-riddled, vibe-coded apps, crazy dependencies on AI providers, and an emerging threat landscape that can’t be mitigated by a contemporary SOC. Sounds like fun, eh? Show notes

  15. Solo podcast: A deep dive on TeamPCP from Risky Business Features, opens in a new tab

    Jun 2, 20261 hr 4 min

    In this solo episode, James Wilson takes a detailed look at TeamPCP. It started off by launching clumsy attacks against misconfigured Kubernetes clusters in September 2025. But by February this year, TeamPCP had skilled up and was smashing global software supply chains in the highest profile attacks of 2026. TeamPCP upskilled and turned the software development ecosystem into its personal credential harvesting machine. Here’s how TeamPCP did it, and what we can learn from it. Show notes

  16. How to survive supply chain attacks from Risky Business Features, opens in a new tab

    May 25, 202636 min

    In this podcast James Wilson chats with Brad Arkin about why software supply chain attacks have gone from rare, once-in-a-while disasters to an operational problem affecting mainstream enterprises almost daily. AI has made attackers faster, and “vibe coding” means the number of environments pulling packages from the internet has gone to the moon. It also means legacy tooling that seeks out the bad packages and cleans them up isn’t enough. Package cooldown windows won’t fix this either. But all hope is not lost! Tune in to this podcast to find out how you can get a grip on the disaster de jour! Show notes

  17. How the CopyFail disclosure went sideways from Risky Business Features, opens in a new tab

    May 21, 202618 min

    In this episode, Theori’s Brian Pak and Andrew Wesie join James Wilson to discuss why the CopyFail exploit was publicly disclosed before Linux distributions had their patches ready. As you’ll hear in this episode, mistakes were made and lessons learned. It’s worth a podcast, too, because in our opinion this incident foreshadows the inevitable problems that open source software will face in the unfolding vulnpocalypse. Show notes

  18. NCSC’s Ollie Whitehouse on surviving the "bugpocalypse" from Risky Business Features, opens in a new tab

    May 18, 202629 min

    In this edition of Risky Business Features Ollie Whitehouse, the CTO of the UK’s National Cyber Security Centre, joins Patrick Gray and James Wilson to talk about why “patch faster” will only get organisations so far in the face of the AI “bugpocalypse”. As Ollie explains, organisations will need to reduce internet-facing attack surface and make better architecture decisions as 0day discovery speeds up. This episode is also available on YouTube . Show notes

  19. What a great agentic AI deployment plan looks like from Risky Business Features, opens in a new tab

    May 12, 202639 min

    In this podcast James Wilson and Brad Arkin workshop the advice they think the industry needs to hear when it comes to deploying agentic AI in the enterprise. Relegating agentic AI to non-sensitive and low-risk tasks doesn’t deliver value, and avoiding all risk stalls progress. James and Brad discuss the phases of AI adoption and contrast what a great plan looks like, versus an overly cautious one. Show notes

  20. Mythos smythos! How to find 0day with lesser models from Risky Business Features, opens in a new tab

    May 8, 20261 hr 27 min

    In this podcast James Wilson chats with Niels Provos about his research into using older AI models to successfully hunt for 0day vulnerabilities. Niels has had a long and prolific career in cybersecurity, having worked as a Distinguished Engineer at Google and then heading up security at Stripe. His interest in AI bug hunting was piqued recently when one of the Mythos 0day vulnerabilities that received lots of attention happened to be in code he wrote for the OpenBSD project 27 years ago. It got him thinking: Are these frontier models really that magical? Or could we replicate their findings with some clever orchestration instead of relying on the model’s smarts to find bugs with a single prompt? As it turns out, this was worth looking into. Niels’ orchestration framework, Iron Curtain, works extremely well. This episode is also available on YouTube Show notes Finding Zero-Days with Any Model Security Blueprints

Ranking source

Apple Podcasts rankings via the Mato Topic Intelligence Platform.

Observed September 20, 2026.

Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.

Pairs with

What to do with a chart

01ShowsThe shows Mato publishesEvery public Mato show, its episodes, and the Apple placements it holds.02AI talentPick the voice before the formatThe live roster of hosts, each with samples you can listen to before you commit.03How it worksFrom an idea to a published episodeWhat Mato does between the brief and the feed, step by step.

Steal the structure, not the show

Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.

Hear a Mato showCreate a show inspired by this