Risky Business Podcast
December 03, 2025
Risky Business #817 -- Less carnage than your usual Thanksgiving
Presented by
Technology Editor
CEO and Publisher
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. It’s a quiet week with Thanksgiving in the US, but there’s always some cyber to talk about:
- Airbus rolls out software updates after a cosmic ray bitflips an A320 into a dive
- Krebs tracks down a Scattered Lapsus$ Hunters teen through the usual poor opsec…
- … as Wired publishes an opsec guide for teens.
- Microsoft decides its login portal is worth a Content Security Policy
- South Korean online retailer data breach covers 65% of the country
This week’s episode is sponsored by Nebulock. Founder and CEO Damien Lewke joins to talk through their work bringing more SIgma threat detection rules to MacOS.
This episode is also available on Youtube.
Brought to you by Nebulock
Agentic Threat Hunting for Everyone
Show notes
Congress calls on Anthropic CEO to testify on Chinese Claude espionage campaign | CyberScoop
Post-mortem of Shai-Hulud attack on November 24th, 2025 - PostHog
Update: Shai-Hulud and the npm Ecosystem: Why CTEM Must Extend Beyond Your Walls | Armis
Glassworm's resurgence | Secure Annex
4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign | Koi Blog
Post by @spuxx.bsky.social — Bluesky
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’ – Krebs on Security
The WIRED Guide to Digital Opsec for Teens | WIRED
Reuters accused of hack attack | ZDNET
The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been ‘Performative’ | WIRED
Microsoft tightens cloud login process to prevent common attack | Cybersecurity Dive
NSA Contractor Groomed Teenage Girls On Reddit, DOJ Alleges