Podcasts

News, analysis and commentary

Between Two Nerds: The perfect hacker

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals.

This episode is also available on YouTube.

Between Two Nerds: The perfect hacker
0:00 / 29:26

Risky Bulletin: New powers for Dutch intelligence services

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service.

Risky Bulletin: New powers for Dutch intelligence services
0:00 / 7:07

Sponsored: Attackers need to be right more than once

Presented by

James Wilson
James Wilson

Technology Editor

In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown jewels”.

The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times.

Sponsored: Attackers need to be right more than once
0:00 / 21:12

How Brian Krebs doxxed TeamPCP

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, James Wilson chats with Brian Krebs about the investigation that led him from recycled cybercrime handles and old forum records to the true identity of TeamPCP’s alleged leader in Perth.

TeamPCP is the hacker group that has gone berserk in the software supply chain over the last year or so, stealing credentials to compromise developers, their software packages, and their repositories.

In this interview Brian talks about his Signal conversations with the group’s ringleader, the strange Cybercats community surrounding TeamPCP, and the passive DNS breakthrough that helped him unmask what he thinks are the ringleader’s true identities.

How Brian Krebs doxxed TeamPCP
0:00 / 29:22

Risky Bulletin: Two TeamPCP members arrested in Australia

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic.

Risky Bulletin: Two TeamPCP members arrested in Australia
0:00 / 10:30

Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution.

They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense.

This episode is also available on YouTube

Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting
0:00 / 19:50

Risky Bulletin: Russia starts blocking DoH and DoT

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common.

Risky Bulletin: Russia starts blocking DoH and DoT
0:00 / 8:41

Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:

  • Iranian hackers take down a small-scale power generator in the UK
  • Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
  • Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
  • Prompt injection isn’t going away
  • LLMs are deceiving us meat sacks and it’s a worry
  • Much, much more…

This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.

This episode is also available on YouTube

Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
0:00 / 62:53

Between Two Nerds: Attribution is dead, long live attribution

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack.

This episode is also available on YouTube.

Between Two Nerds: Attribution is dead, long live attribution
0:00 / 32:58

Risky Bulletin: Expired credit cards can be used for malicious transactions

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.

Risky Bulletin: Expired credit cards can be used for malicious transactions
0:00 / 5:58