Podcasts

News, analysis and commentary

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A major vulnerability has been found in the ancient TACACS+ networking protocol, Australia’s Prime Minister claims an OpenAI agent hacked the country’s Medicare website, OpenAI gives Ukraine access to its Daybreak cyber-defense program and the UK will establish an anti-disinformation center.

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol
0:00 / 11:02

Srsly Risky Biz: Bring on the AI lawsuits

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. Its a good move. Leaving the companies on the hook keeps the pressure on them to do better with their cyber security and testing controls.

They also discuss a Russian AI-powered cyberespionage campaign run by a group known as Midnight Blizzard. It used AI workflows to run the entire campaign so they got a lot more hacking done and accepted AI mistakes. This makes sense given that they want more intelligence from Ukrainian targets and don’t care at all about getting caught.

This episode is also available on YouTube.

Srsly Risky Biz: Bring on the AI lawsuits
0:00 / 14:55

Risky Business #854 -- We're Jevpilled

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

THE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14

On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including:

  • Google’s Gemini finally did some crimes
  • OpenAI admits more agents did silly things because “alignment”
  • US Treasury’s Scott Bessent rules out a liability waiver for the frontier labs, saying, roughly: “Lol. Lmao even.”
  • Jev is Silicon Valley’s “hot dog/not hotdog” app brought to life, and it will really improve security tooling
  • The FBI and Coast Guard boarded oil tankers after they were allegedly hacked
  • Much, much more…

This week’s show is brought to you by Thinkst Canary. Founder Haroon Meer joins Patrick to talk about Thinkst’s new deception tools that trick the AI agents that are targeting you. It’s actually hilarious how well deception tech works against hacking agents.

This episode is also available on YouTube

Risky Business #854 -- We're Jevpilled
0:00 / 54:49

Risky Bulletin: Team Cymru unmasks shady Chinese proxy network

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies.

Risky Bulletin: Team Cymru unmasks shady Chinese proxy network
0:00 / 8:58

Between Two Nerds: Real-time cyber defence

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether there is such a thing as real-time cyber defence. Will agentic AI save us from hacking AI?

This episode is also available on YouTube.

Between Two Nerds: Real-time cyber defence
0:00 / 24:56

Risky Bulletin: Gemini finally did some crimes

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Google’s Gemini hacked three companies, hackers claim a breach of Russia’s election commission, OpenAI was behind RubyGems’ May incident, and the Coast Guard and FBI board two ships to investigate cyberattacks.

Risky Bulletin: Gemini finally did some crimes
0:00 / 9:21

Sponsored: SpecterOps on the impact of AI agents on BloodHound

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In this Risky Business sponsored interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin explains how Entra Agent ID can introduce new identity relationships and potential attack paths.

Sponsored: SpecterOps on the impact of AI agents on BloodHound
0:00 / 15:52

Risky Business #853 -- We're all gonna die, apparently

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including:

  • More tech guys penned more open letters and AI will destroy us all!
  • Another Wednesday, another congregation of OpenAI agents on wikis… yawn
  • OpenAI agents were behind the headscratching RubyGems hacking campaign in May
  • The FBI will disrupt more adversary operations, NSA is creating more mission centres, lawmakers want sanctions on hackers-for-hire… Release more hounds!
  • So many platforms, so many bugs, so many patches breaking other stuff
  • Much, much more…

This week’s show is brought to you by Airlock Digital. Its co-founders Daniel Schell and David Cottingham join Patrick to talk about how Airlock has integrated itself with Crowdstrike via its Falcon Foundry platform.

This episode is also available on YouTube

Risky Business #853 -- We're all gonna die, apparently
0:00 / 59:08

How to launder illicit Bitcoin

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware gangs get a payday.

The payment itself might be in the millions, but it’s difficult for gangs to convert their ill-gotten crypto gains into cash they can actually spend. Geoff explains the role of professional launderers and why cash-rich drug gangs are useful connections for crypto-rich cybercriminals.

They also dive into who operates these international laundering networks, other types of crime they enable, and whether this affects the argument of whether victims should be allowed to pay.

How to launder illicit Bitcoin
0:00 / 45:44

Hunting software supply chain malware

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious packages, GitHub repositories and developer tools.

Paul walks James through static analysis, deobfuscation and reconstructing multi-stage kill chains to identify what attackers are trying to steal. They also discuss how LLMs make malware development easier while introducing operational security mistakes.

The pair examine DPRK tradecraft, blockchain-based payload delivery and what Paul calls Pollen Rider, which can reinfect developers through their own repositories.

Hunting software supply chain malware
0:00 / 75:04