Podcasts

News, analysis and commentary

Risky Bulletin: APTeens go after Salesforce data

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A hacking group goes after Salesforce data, the FBI takes down the BidenCash carding forum, China offers rewards for Taiwanese military hackers, and high risk bugs are patched in enterprise software from HPE and Infoblox.

Risky Bulletin: APTeens go after Salesforce data
0:00 / 7:02

Srsly Risky Biz: Law Enforcement Is Finally Making Progress on Ransomware

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about how Operation Endgame, the multinational law enforcement effort to tackle ransomware is approaching the problem holisitically. It’s tackling the enablers of ransomware and although it won’t eliminate the crime, it’ll make it harder for criminals.

They also discuss the spyware app that helped to dismantle the Syrian regime, at least maybe a little bit, and how Russian military intelligence’s sabotage and assasination unit got into cyber operations.

This episode is also available on Youtube.

Srsly Risky Biz: Law Enforcement Is Finally Making Progress on Ransomware
0:00 / 18:43

Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Cyber firms agree to deconflict and cross-reference hacker group names
  • Russian nuclear facility blueprints gathered from public procurement websites
  • Someone audio deepfaked the White House Chief of Staff, but for the dumbest reasons
  • Germany identifies the Trickbot kingpin
  • Google spots China’s MSS using Calendar events for malware C2
  • Meta apps abuse localhost listeners to track web sessions.

This week’s episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss an open letter penned by JP Morgan Chase’s CISO that pleads with Software as a Service suppliers to try to suck less at security.

This episode is also available on Youtube.

Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242
0:00 / 58:22

Risky Bulletin: Syrian Army infected with spyware before regime collapse

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A spyware app infected the Syrian Army’s soldiers before the regime collapsed, NSO appeals its WhatsApp verdict, Chrome and Qual-comm patch zero-days, and an Emergency services information sharing group shuts down;

Risky Bulletin: Syrian Army infected with spyware before regime collapse
0:00 / 8:20

Between Two Nerds: NSA's thinking on information warfare

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq look at NSA’s take on information warfare, all the way back from 1997.

This episode is also available on Youtube.

Between Two Nerds: NSA's thinking on information warfare
0:00 / 31:08

Risky Bulletin: Law enforcement takes down AVCheck

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Law enforcement agencies take down A-V-Check, four US Senators urge for the reinstatement of the Cyber Safety Review Board, Germany identifies the leader of the TrickBot gang, and an AI-vibe-coding platform leaks user data and API keys.

Risky Bulletin: Law enforcement takes down AVCheck
0:00 / 6:16

Sponsored: HD Moore on why vuln scanners are awful and broken

Presented by

Casey Ellis
Casey Ellis

Founder, Bugcrowd

In this sponsored interview, Risky Business Media’s brand new interviewer Casey Ellis chats with runZero founder and CEO HD Moore about why vuln scanning tech is awful and broken. He also talks about how they’re trying to do something better by glueing their own discovery product to the nuclei open source vulnerability scanner.

Sponsored: HD Moore on why vuln scanners are awful and broken
0:00 / 15:21

Risky Bulletin: Windows Update will patch third party apps

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Windows Update will deliver third party app updates, a public database exposed Russia’s nuclear secrets, US banks ask the SEC to rescind cyber breach disclosure rule, and ConnectWise discloses an APT breach.

Risky Bulletin: Windows Update will patch third party apps
0:00 / 6:05

Srsly Risky Biz: Russia's cybercriminals and spies are officially in cahoots

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about Russian DanaBot malware developers making a tailored variant of their malware specifically for espionage. This fills in some of the blanks on the exact relationship between Russian criminals and the country’s intelligence services.

They also discuss a US Director of National Intelligence initiative to centralise the purchase of commercially acquired information. Although this information can be used maliciously, having a one-stop-shop should make it easier to check that it is being used responsibly.

This episode is also available on Youtube.

Srsly Risky Biz: Russia's cybercriminals and spies are officially in cahoots
0:00 / 16:27

Risky Business #793 -- Scattered Spider is hijacking MX records

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the week’s news, including:

  • EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes
  • The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed
  • Brian Krebs eats a 6.3Tbps DDoS … ‘cause that’s how you demo your packet cannon
  • Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers
  • Iranian behind 2019 Baltimore ransomware mysteriously appears in North Carolina and pleads guilty
  • CISA’s leadership is fleeing in droves, even though the US needs them more than ever.

This week’s episode is sponsored by Thinkst Canary. Long time friend of the show Haroon Meer joins and talks through where he feels the industry is at, having just returned home from the AI-fueled hype at this year’s RSA conference.

This episode is also available on Youtube.

Risky Business #793 -- Scattered Spider is hijacking MX records
0:00 / 64:52