Podcasts

News, analysis and commentary

Risky Bulletin: Dutch police take down 17m device botnet

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer is arrested for insider trading on Polymarket, and Gogs and the Casdoor IAM leave major bugs unpatched.

Risky Bulletin: Dutch police take down 17m device botnet
0:00 / 8:45

Risky Bulletin: Iran to reconnect to the Internet

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Iran will reconnect to the Internet, a new vulnerability lets attackers bypass authentication on AI infrastructure, hackers breach Lithuania’s state registry, security firms take down the Glassworm botnet, and CERT India releases strict patching advice.

Risky Bulletin: Iran to reconnect to the Internet
0:00 / 6:14

Risky Business #839 -- TeamPCP stole GitHub's internal repos

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • TeamPCP breached GitHub’s internal repos. Now what?
  • Some absolute plonker glued Coruna to a hijacked npm package
  • CISA is worried about about open source and wants third party submissions for KEV
  • AI infrastructure is “systemically” insecure
  • Much, much more

This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun!

This episode is also available on YouTube

Risky Business #839 -- TeamPCP stole GitHub's internal repos
0:00 / 60:23

How to survive supply chain attacks

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast James Wilson chats with Brad Arkin about why software supply chain attacks have gone from rare, once-in-a-while disasters to an operational problem affecting mainstream enterprises almost daily.

AI has made attackers faster, and “vibe coding” means the number of environments pulling packages from the internet has gone to the moon. It also means legacy tooling that seeks out the bad packages and cleans them up isn’t enough. Package cooldown windows won’t fix this either.

But all hope is not lost! Tune in to this podcast to find out how you can get a grip on the disaster de jour!

How to survive supply chain attacks
0:00 / 36:51

Risky Bulletin: Mythos has found thousands of critical bugs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Anthropic says Mythos has found thousands of critical bugs, hackers leak documents from a Russian disinfo group, GitHub rolls out new npm security features, and Dutch police raid two bulletproof hosting providers.

Risky Bulletin: Mythos has found thousands of critical bugs
0:00 / 8:15

Sponsored: Teaching AI agents the rules of the road

Presented by

James Wilson
James Wilson

Technology Editor

In this sponsored interview James Wilson chats with Sondera CEO Josh Devon about why guardrails and instruction files aren’t enough to keep AI agents from going haywire. EDR, DLP and other traditional controls can’t and won’t prevent agents from going rogue.

Josh explains Sondera’s “principle of least autonomy” for agents: let them do useful work, but put them in a deterministic policy harness so they can’t leak secrets, abuse tools or wander off-task.

Sponsored: Teaching AI agents the rules of the road
0:00 / 26:54

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Microsoft ends support for SMS MFA on personal accounts, GitHub was hacked via a malicious VS Code extension, CISA will let researchers submit new KEV entries, and an SMS blaster was detained at Eurovision.

Risky Bulletin: Microsoft ends SMS MFA for personal accounts
0:00 / 9:00

How the CopyFail disclosure went sideways

Presented by

James Wilson
James Wilson

Technology Editor

In this episode, Theori’s Brian Pak and Andrew Wesie join James Wilson to discuss why the CopyFail exploit was publicly disclosed before Linux distributions had their patches ready. As you’ll hear in this episode, mistakes were made and lessons learned. It’s worth a podcast, too, because in our opinion this incident foreshadows the inevitable problems that open source software will face in the unfolding vulnpocalypse.

How the CopyFail disclosure went sideways
0:00 / 18:56

Srsly Risky Biz: Politicians ditch Signal for homegrown apps

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about moves from several European governments to ditch Signal and set up their own encrypted messaging systems for internal government use. These efforts are motivated by concerns about phishing and sovereignty, but the solutions being adopted are imperfect and will come with their own set of problems. Signal fills a space that can’t be filled with sovereign capability.

They also talk about Fast16 malware. We are only now learning about the second arm of a mid-2000s campaign to delay Iran’s nuclear weapons program that included the infamous Stuxnet worm.

This episode is also available on YouTube

Srsly Risky Biz: Politicians ditch Signal for homegrown apps
0:00 / 28:45

Risky Business #838 -- GitHub investigates possible breach

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • GitHub announced a possible breach
  • CISA leaks important creds, keys in public repo
  • Awful vulnerability in Bitlocker renders it useless without a PIN
  • So. Many. Patches.
  • Polish Government urges officials to ditch Signal for mSzyfr
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy.

This episode is also available on YouTube.

Risky Business #838 -- GitHub investigates possible breach
0:00 / 62:49