Podcasts

News, analysis and commentary

Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Slovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.

Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
0:00 / 7:44

Risky Business #849 -- Trump will unleash contractors on cybercriminals

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:

Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing Anthropic’s models start a turf war when given the same task, surprising… nobody We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something. Much, much more

This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.

This episode is also available on YouTube

Risky Business #849 -- Trump will unleash contractors on cybercriminals
0:00 / 59:06

Between Two Nerds: The eye of Sauron

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.

This episode is also available on YouTube.

Between Two Nerds: The eye of Sauron
0:00 / 32:06

James Kettle on inventing new attack techniques with LLMs

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.

Kettle has built what he calls the HTTP Terminator, an autonomous research system that generates and tests tens of thousands of potentially new HTTP desync techniques. The Terminator, which makes use of Kettle’s own research methodology, has already come up with new desync methods that James hadn’t thought of before.

Kettle and Wilson discuss how to develop and evaluate machine-generated ideas without drowning in false positives, and why the most powerful part of the process is the discovery cascade, where one unexpected result becomes the seed for another.

The upshot is AI can conduct genuinely novel security research, but don’t expect to one-shot your way to an army of robot hackers.

James Kettle on inventing new attack techniques with LLMs
0:00 / 77:35

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.

Risky Bulletin: The EU publishes its upcoming cybersecurity standards
0:00 / 8:37

Sponsored: What npm 12 fixes… and what it doesn’t

Presented by

Casey Ellis
Casey Ellis

Founder, Bugcrowd

In this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what third-party code actually does before allowing it into their environments.

Sponsored: What npm 12 fixes… and what it doesn’t
0:00 / 17:54

Risky Bulletin: US will let private companies carry out offensive cyber ops

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.

Risky Bulletin: US will let private companies carry out offensive cyber ops
0:00 / 11:07

Soap Box: Zero Trust(ish) Networks

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.

Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.

Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.

Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.

This episode is also available on YouTube

Soap Box: Zero Trust(ish) Networks
0:00 / 29:04

Srsly Risky Biz: Data extortion is booming. Hooray!

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.

They also discuss how the rise of AI makes it worth reinvigorating CISA’s Secure by Design initiative.

Srsly Risky Biz: Data extortion is booming. Hooray!
0:00 / 30:48

Risky Business #848 -- OpenAI comes clean

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

  • The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
  • Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
  • More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
  • It turns out TeamPCP has been around longer than we thought and predates the AI era
  • Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
  • Much, much more

This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.

This episode is also available on YouTube

Risky Business #848 -- OpenAI comes clean
0:00 / 59:47