Risky Business Podcast

Analysis and news podcasts published weekly

Wide World of Cyber: How state adversaries attack security vendors

Presented by

Alex Stamos
Alex Stamos

CISO, Sentinel One

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Wide World of Cyber podcast Patrick Gray talks to SentinelOne’s Steve Stone and Alex Stamos about how foreign adversaries are targeting security vendors, including them.

From North Korean IT workers to Chinese supply chain attacks, SentinelOne and its competitors are constantly fending off sophisticated hacking campaigns.

This edition of the Wide World of Cyber was recorded in front of a live audience in San Francisco, with Patrick attending via Zoom.

The Wide World of Cyber podcast series is a wholly sponsored co-production between SentinelOne and Risky Business Media.

This episode is also available on Youtube.

Wide World of Cyber: How state adversaries attack security vendors
0:00 / 52:42

Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • White House’s off-brand Israeli Signal fork logs cleartext messages with hard coded creds while getting hacked (twice). Just … Wow.
  • Ransomware attacks on UK retailers are linked, and Marks & Spencer has it extra bad
  • After six years dormant, a Magento eCommerce platform backdoor comes to life
  • The North Korean IT worker scam is truly webscale
  • NSO group owes Meta $168m for hacking WhatsApp

This week’s episode is sponsored by vulnerability management wranglers, Nucleus Security. Aaron Unterberger joins to talk through the complexities of tracking vulnerabilities in cloud components - left to the source, right to the deployments, and …sideways into the sidecars?

This week’s show also features an excerpt from Pat’s interview with Senator Mark Warner - Scoot back one in your podcast feed to check out the full chat, or find it on Youtube.

This episode is available on Youtube too.

Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate
0:00 / 56:12

BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this extended interview the Vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner, joins Risky Business host Patrick Gray to talk about:

  • The latest developments in the Signalgate scandal
  • Why America needs to be more aggressive in responding to Volt Typhoon
  • How tariffs are affecting American alliances
  • Why the Five Eyes alliance is sacrosanct

This episode is available on Youtube

BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs
0:00 / 49:44

Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • British retail stalwart Marks & Spencer gets cybered
  • South Korean telco sets out to replace all its subscriber SIMs after (we assume) it lost the keymat
  • It’s a good exploit week! Bugs in Apple Airplay, SAP webservers, Erlang SSH and CommVault backups
  • Juice jacking! No, really! Some researchers actually did it (so still not in the wild, then)
  • Anti-DOGE whistleblower sure sounds like he has a point

This week’s episode is sponsored by Knocknoc, who let you glue your firewalls to your single sign on. Knocknoc’s CEO Adam Pointon talks about the joy that having end-to-end IPv6 would bring for zero-trust access control. He also touches on people using Knocknoc inside their network to isolate critical systems.

Editors Note : Pat also gives Adam (Boileau) stick in the sponsor interview about the Risky Biz webserver not having IPv6 enabled, which fact-checking during the edit says is FAKE NEWS. Just uh, don’t look at how fresh that AAAA record in the DNS is, friends 😉

This episode is also available on Youtube.

Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful
0:00 / 62:31

Snake Oilers: LimaCharlie, Honeywell Cyber Insights, CobaltStrike and Outflank

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast, three sponsors come along to pitch their products:

This episode is also available on Youtube.

Snake Oilers: LimaCharlie, Honeywell Cyber Insights, CobaltStrike and Outflank
0:00 / 38:50

Snake Oilers: Pangea, Cosive and Sysdig

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of Snake Oilers three vendors pitch host Patrick Gray on their tech:

  • Pangea: Guardrails and security for AI agents and applications (https://pangea.cloud)

Worried about your AI apps going rogue, being mean to your customers or even disclosing sensitive information? Pangea exists to address these risks. Fascinating stuff.

  • Cosive: A threat intelligence company that can host your MISP server in AWS. CloudMISP! (https://www.cosive.com/capabilities/cloud-misp)

Are you running a MISP server on some old hardware under a desk in your SOC? There’s a better way! Cosive can run it for you on AWS so you can just use it instead of wrestling with maintaining it. They also do some CTI consulting to help you get better use out of MISP.

  • Sysdig: A Linux runtime security platform (https://sysdig.com/)

The modern Windows network is an all-singing, all-dancing, perfectly orchestrated, EDR-protected ballet. The modern Linux production environment… isn’t. Find out how Sysdig can help you get some visibility and control over your Linux fleet.

This episode is also available on Youtube.

Snake Oilers: Pangea, Cosive and Sysdig
0:00 / 47:45

Risky Business #788 -- Trump targets Chris Krebs, SentinelOne

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray talks to former NSA Cybersecurity Director Rob Joyce about Donald Trump’s unprecedented, unwarranted and completely bonkers political persecution of Chris Krebs and his employer SentinelOne.

They also talk through the week’s cybersecurity news, covering:

  • Mitre’s stewardship of the CVE database gets its funding DOGE’d
  • The US signs on to the Pall Mall anti-spyware agreement
  • China tries to play the nationstate cyber-attribution game, but comedically badly
  • Hackers run their malware inside the Windows sandbox, for security against EDR

This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins to talk through the increasing sprawl of the identity ecosystem.

This episode is also available on Youtube.

Risky Business #788 -- Trump targets Chris Krebs, SentinelOne
0:00 / 53:35

Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape

Presented by

Alex Stamos
Alex Stamos

CISO, Sentinel One

Chris Krebs
Chris Krebs

Chief Intelligence and Public Policy Officer, Sentinel One

Patrick Gray
Patrick Gray

CEO and Publisher

In this podcast, Patrick Gray chats with SentinelOne’s Chris Krebs and Alex Stamos about the huge changes afoot in the United States government and what they mean for the threat environment. From the director of NSA being fired to massive job cuts at CISA and huge foreign policy shifts, tomorrow’s threat environment is going to be very different to today’s. Tune in to hear analysis from two of the best in the business!

This episode is also available on Youtube.

Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape
0:00 / 43:29

Risky Business #787 -- Trump fires NSA director, CISA cuts inbound

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Oracle quietly cops to being hacked, but immediately pivots into pretending it didn’t matter
  • NSA and CyberCom leaders fired for not being MAGA enough
  • US Treasury had some dusty corners it hadn’t found China in yet, looked, found China in them
  • …which is a great time to discuss slashing CISA’s staffing
  • Ransomware crews and bullet proof hosting providers are getting rekt, and we love it
  • And Microsoft patches yet another logging 0-day being used in the wild.

This episode is sponsored by Yubico, makers of Yubikey hardware authentication tokens. Yubico’s Vice President of Solutions Architecture and Alliances Derek Hanson joins to discuss how the consumer-centric passkey ecosystem has become a real challenge for enterprises. And one that Yubico is actually really ideally positioned to solve.

This episode is also available on Youtube.

Risky Business #787 -- Trump fires NSA director, CISA cuts inbound
0:00 / 53:01

Risky Business #786 -- Oracle is lying

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Yes, Oracle Health and Oracle Cloud did get hacked
  • The fallout from Signalgate continues
  • North Korean IT workers pivot to Europe
  • Honeypot data suggests a storm is brewing for Palo Alto VPNs
  • Canadian Anon gets arrested for hacking Texas GOP

This week’s episode is sponsored by Trail of Bits. Tjaden Hess, a Principal Security Engineer at Trail of Bits who specialises in cryptography, joins the show this week to talk about what a responsible crypto-currency exchange cold wallet setup looks like, and … contrasts that with Bybit.

This episode is also available on Youtube.

Risky Business #786 -- Oracle is lying
0:00 / 55:14