Podcasts

News, analysis and commentary

Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:

  • Iranian hackers take down a small-scale power generator in the UK
  • Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
  • Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
  • Prompt injection isn’t going away
  • LLMs are deceiving us meat sacks and it’s a worry
  • Much, much more…

This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.

This episode is also available on YouTube

Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
0:00 / 62:53

Between Two Nerds: Attribution is dead, long live attribution

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack.

This episode is also available on YouTube.

Between Two Nerds: Attribution is dead, long live attribution
0:00 / 32:58

Risky Bulletin: Expired credit cards can be used for malicious transactions

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.

Risky Bulletin: Expired credit cards can be used for malicious transactions
0:00 / 5:58

Sponsored: Passkeys won’t stop authorisation phishing

Presented by

James Wilson
James Wilson

Technology Editor

In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer.

Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if their controls against these attacks actually work.

Sponsored: Passkeys won’t stop authorisation phishing
0:00 / 20:05

Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great Firewall

Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs
0:00 / 6:08

Srsly Risky Biz: Trump's private hacker memo is the right idea

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disruption operations, but there simply isn’t enough government capacity. So it is time to bring in the private sector.

They also discuss Ukraine’s combined cyber and kinetic strikes against Wildberries, the logistics company that is called the Amazon of Russia. These cyber operations didn’t amplify the effects of kinetic strikes, but it is great propaganda to say that they did.

This episode is also available on YouTube

Srsly Risky Biz: Trump's private hacker memo is the right idea
0:00 / 31:07

Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Slovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.

Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
0:00 / 7:44

Risky Business #849 -- Trump will unleash contractors on cybercriminals

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:

Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing Anthropic’s models start a turf war when given the same task, surprising… nobody We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something. Much, much more

This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.

This episode is also available on YouTube

Risky Business #849 -- Trump will unleash contractors on cybercriminals
0:00 / 59:06

Between Two Nerds: The eye of Sauron

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.

This episode is also available on YouTube.

Between Two Nerds: The eye of Sauron
0:00 / 32:06

James Kettle on inventing new attack techniques with LLMs

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.

Kettle has built what he calls the HTTP Terminator, an autonomous research system that generates and tests tens of thousands of potentially new HTTP desync techniques. The Terminator, which makes use of Kettle’s own research methodology, has already come up with new desync methods that James hadn’t thought of before.

Kettle and Wilson discuss how to develop and evaluate machine-generated ideas without drowning in false positives, and why the most powerful part of the process is the discovery cascade, where one unexpected result becomes the seed for another.

The upshot is AI can conduct genuinely novel security research, but don’t expect to one-shot your way to an army of robot hackers.

James Kettle on inventing new attack techniques with LLMs
0:00 / 77:35