Podcasts

News, analysis and commentary

Risky Business #853 -- We're all gonna die, apparently

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including:

  • More tech guys penned more open letters and AI will destroy us all!
  • Another Wednesday, another congregation of OpenAI agents on wikis… yawn
  • OpenAI agents were behind the headscratching RubyGems hacking campaign in May
  • The FBI will disrupt more adversary operations, NSA is creating more mission centres, lawmakers want sanctions on hackers-for-hire… Release more hounds!
  • So many platforms, so many bugs, so many patches breaking other stuff
  • Much, much more…

This week’s show is brought to you by Airlock Digital. Its co-founders Daniel Schell and David Cottingham join Patrick to talk about how Airlock has integrated itself with Crowdstrike via its Falcon Foundry platform.

This episode is also available on YouTube

Risky Business #853 -- We're all gonna die, apparently
0:00 / 59:08

How to launder illicit Bitcoin

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware gangs get a payday.

The payment itself might be in the millions, but it’s difficult for gangs to convert their ill-gotten crypto gains into cash they can actually spend. Geoff explains the role of professional launderers and why cash-rich drug gangs are useful connections for crypto-rich cybercriminals.

They also dive into who operates these international laundering networks, other types of crime they enable, and whether this affects the argument of whether victims should be allowed to pay.

How to launder illicit Bitcoin
0:00 / 45:44

Hunting software supply chain malware

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious packages, GitHub repositories and developer tools.

Paul walks James through static analysis, deobfuscation and reconstructing multi-stage kill chains to identify what attackers are trying to steal. They also discuss how LLMs make malware development easier while introducing operational security mistakes.

The pair examine DPRK tradecraft, blockchain-based payload delivery and what Paul calls Pollen Rider, which can reinfect developers through their own repositories.

Hunting software supply chain malware
0:00 / 75:04

Risky Bulletin: Anthropic agents went hacking again

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.

Risky Bulletin: Anthropic agents went hacking again
0:00 / 10:20

Snake Oilers: watchTowr, XBOW and CoreView

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

  • watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do?
  • XBOW: The AI pentesting company pitches its approach
  • CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView!

This episode is also available on YouTube.

Snake Oilers: watchTowr, XBOW and CoreView
0:00 / 42:00

Srsly Risky Biz: America's drivers licence breach is a national security disaster

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.

They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough.

Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy.

This episode is also available on YouTube

Srsly Risky Biz: America's drivers licence breach is a national security disaster
0:00 / 24:44

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
0:00 / 7:58

Risky Business #852 -- Cyber Command wants to buy shells

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:

  • ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits
  • The US government plans to pay private contractors to conduct military hacks
  • The US accuses China of distillation attacks, a.k.a. forbidden training
  • It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki
  • Much, much more…

This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace.

This episode is also available on YouTube

Risky Business #852 -- Cyber Command wants to buy shells
0:00 / 63:29

Between Two Nerds: Can AI defend critical infrastructure?

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line.

This episode is also available on YouTube.

Between Two Nerds: Can AI defend critical infrastructure?
0:00 / 27:26

Risky Bulletin: BEC campaign steals €35 million from French notaries

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.

Risky Bulletin: BEC campaign steals €35 million from French notaries
0:00 / 8:27