Podcasts

News, analysis and commentary

Srsly Risky Biz: America's drivers licence breach is a national security disaster

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.

They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough.

Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy.

This episode is also available on YouTube

Srsly Risky Biz: America's drivers licence breach is a national security disaster
0:00 / 24:44

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
0:00 / 7:58

Risky Business #852 -- Cyber Command wants to buy shells

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:

  • ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits
  • The US government plans to pay private contractors to conduct military hacks
  • The US accuses China of distillation attacks, a.k.a. forbidden training
  • It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki
  • Much, much more…

This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace.

This episode is also available on YouTube

Risky Business #852 -- Cyber Command wants to buy shells
0:00 / 63:29

Between Two Nerds: Can AI defend critical infrastructure?

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line.

This episode is also available on YouTube.

Between Two Nerds: Can AI defend critical infrastructure?
0:00 / 27:26

Risky Bulletin: BEC campaign steals €35 million from French notaries

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.

Risky Bulletin: BEC campaign steals €35 million from French notaries
0:00 / 8:27

Sponsored: Authentik is rethinking PAM for AI agents

Presented by

James Wilson
James Wilson

Technology Editor

In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.

Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human.

They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access.

Sponsored: Authentik is rethinking PAM for AI agents
0:00 / 20:05

Risky Bulletin: Russia tells data centers to deploy drone defenses

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs.

Risky Bulletin: Russia tells data centers to deploy drone defenses
0:00 / 10:04

Who gets to hack the hackers?

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, Brad Arkin joins James Wilson to chat about the Trump administration’s call to let private entities conduct cyber operations against criminal groups.

Brad’s firsthand experience responding to cyber incidents alongside US law enforcement gives him a unique perspective on how government and private sector relationships work, and how this program could improve the ability of both sides to tackle cybercrime.

James and Brad also explore who might participate in these campaigns and whether the government will be able to effectively oversee them.

Who gets to hack the hackers?
0:00 / 40:46

Srsly Risky Biz: China's botnets are worth disrupting

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild.

They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal!

Finally, they discuss efforts to fix US water sector security. Sprinkling free tools on the problem will have limited impact.

This episode is also available on YouTube

Srsly Risky Biz: China's botnets are worth disrupting
0:00 / 22:15

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness.

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates
0:00 / 9:14