Podcasts

News, analysis and commentary

Srsly Risky Biz: Knives are out for open-weight AI models

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them.

They also talk about arrests of several members of the Scattered Spider juvenile cybercrime collective.

This episode is also available on YouTube

Srsly Risky Biz: Knives are out for open-weight AI models
0:00 / 24:36

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Rogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach
0:00 / 6:50

Risky Business #845 -- OpenAI's Skynet moment

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:

  • Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
  • US and China trade AI model ban threats
  • Iran has been using SS7 queries to locate and target US troops
  • Scattered Spider is having a hard time, not just because of Microsoft’s GDID
  • And much, much more!

This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.

This episode is also available on YouTube.

Risky Business #845 -- OpenAI's Skynet moment
0:00 / 69:31

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine.

This episode is also available on YouTube.

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine
0:00 / 27:04

Risky Bulletin: Hacker wipes Romania's entire land registry database

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress.

Risky Bulletin: Hacker wipes Romania's entire land registry database
0:00 / 9:03

Sponsored: Thinkst on building companies that don’t suck

Presented by

Casey Ellis
Casey Ellis

Founder, Bugcrowd

In this Risky Business sponsor interview Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs.

Sponsored: Thinkst on building companies that don’t suck
0:00 / 21:20

Srsly Risky Biz: Ransomware uses AI to amp up negotiations

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations.

They also discuss the ever so many bugs being patched. This is good for organisations that patch, but it will leave a very long tail of unpatched vulnerabilities.

This episode is also available on YouTube

Srsly Risky Biz: Ransomware uses AI to amp up negotiations
0:00 / 20:23

Fortibleed: The bleeding edge of AI cybercrime

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A small investigation into a curiously open directory on an unknown server expanded into the discovery of an attack that targeted 400,000 Fortinet devices.

As Ensar says, each time the SOCRadar team pulled a single thread, it led to a tapestry of AI-enabled cybercrime. They uncovered custom initial access, persistence and packet sniffing tools, as well as direct links to the INC and Lynx ransomware operations. Most interesting though is the use of AI to design, implement and operate all aspects of the campaign across a team of 20 individual actors. Operating more like a modern software company than a traditional cybercrime gang, Fortibleed serves as our first in-depth look at the future of cybercrime.

Fortibleed: The bleeding edge of AI cybercrime
0:00 / 48:03

Between Two Nerds: Exploits are not cyber power

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency.

This episode is also available on YouTube.

Between Two Nerds: Exploits are not cyber power
0:00 / 30:08

What to do 'til the bugpocalypse gets here

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode Brad Arkin joins James Wilson to discuss how defenders can get ahead of the late-running bugpocalypse. While we’re confident the offensive cybersecurity capabilities of frontier and open-weight LLMs are real, attackers don’t yet seem able to fully utilise them. This creates a window of opportunity for defenders to tackle the threat.

There are a few well-funded and seemingly overlapping industry efforts under way including Athena, Akrites, and Patch the Planet. But, as Brad says in this interview, there’s too much focus on fixing bugs and traditional vulnerability triage, and not enough on exploring how to make entire classes of vulnerabilities inert.

What to do 'til the bugpocalypse gets here
0:00 / 44:24