Risky Business Podcast

Analysis and news podcasts published weekly

Soap Box: Detection and response in the AI age

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Edward Wu, founder of Dropzone, about what AI is doing to detection, response and the SOC more generally.

Dropzone makes AI agents that conduct alert investigations in your SOC, but will the SOC as we know it even exist in the future?

Ed has a deep expertise in SOC tech, having previously led AI/ML detection engineering at Extrahop. This interview is a fantastic look at what the future may bring for detection and response professionals.

This episode is also available on YouTube

Soap Box: Detection and response in the AI age
0:00 / 36:35

Risky Business #840 -- Microsoft walks back researcher threats

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution.

They cover:

  • Adversaries are tracking US troop locations with commercially available location data
  • A new Signal phishing campaign is going after message backups
  • 404 Media is suing ICE to get its spyware contract with REDLattice (lol)
  • Microsoft’s tone-deaf response to ‘never justifiable’ zero-day disclosures
  • Mini Shai-Hulud pops up again just as Glassworm gets shattered
  • Much, much more

This week’s episode is sponsored by Authentik, an open source identity platform that you can host yourself. In this week’s sponsor interview Authentik’s CEO Fletcher Heisler joins Patrick Gray to talk about how they’re keeping up with the bugpocalypse, and also the work they’re doing to support identities for AI agents.

This episode is also available on YouTube.

Risky Business #840 -- Microsoft walks back researcher threats
0:00 / 66:03

Risky Business #839 -- TeamPCP stole GitHub's internal repos

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

  • TeamPCP breached GitHub’s internal repos. Now what?
  • Some absolute plonker glued Coruna to a hijacked npm package
  • CISA is worried about about open source and wants third party submissions for KEV
  • AI infrastructure is “systemically” insecure
  • Much, much more

This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun!

This episode is also available on YouTube

Risky Business #839 -- TeamPCP stole GitHub's internal repos
0:00 / 60:23

Risky Business #838 -- GitHub investigates possible breach

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • GitHub announced a possible breach
  • CISA leaks important creds, keys in public repo
  • Awful vulnerability in Bitlocker renders it useless without a PIN
  • So. Many. Patches.
  • Polish Government urges officials to ditch Signal for mSzyfr
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy.

This episode is also available on YouTube.

Risky Business #838 -- GitHub investigates possible breach
0:00 / 62:49

Soap Box: Where does AI fit into cloud security?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

This episode is also available on Youtube.

Soap Box: Where does AI fit into cloud security?
0:00 / 33:37

Risky Business #837 -- GitHub Actions footgun claims TanStack

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • Mini Shai-Hulud and the TanStack compromise using Github Actions
  • Instructure pays Canvas elearning platform data extortionists
  • More Linux privilege escalation 0days!
  • CISA helping critical infrastructure operators rearchitect their networks so they work offline

This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.

Risky Business #837 -- GitHub Actions footgun claims TanStack
0:00 / 65:15

Risky Business #836 -- You can't patch the bugpocalypse

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including:

  • The US Government says we just have to patch faster, but…
  • Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn’t enough
  • James gets mad about lame AI Agent adoption advice from the US and Australian Governments
  • James Kettle and Niels Provos both showed us that any model can find 0day like Mythos
  • And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars

This week’s show is sponsored by SpecterOps. Their CTO, Jared Atkinson, chats to Pat about the big changes in the threat landscape, brought about by AI, that are causing a pivot away from detection and remediation, and toward prevention.

This episode is also available on Youtube.

Risky Business #836 -- You can't patch the bugpocalypse
0:00 / 61:56

Snake Oilers: Ent AI, Spacewalk and Mondoo

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

  • Ent AI: Co-founder Brandon Dixon pitched Ent, an intent-aware, AI-powered endpoint security control.

  • Spacewalk AI: Founders Chris Fuller and Tim Wenzlau pitch Spacewalk, an AI-powered incident response platform.

  • Mondoo: Co-founder Dominik Richter pitches Mondoo, an AI-powered “service as software” in the vulnerability management space.

This episode is also available on YouTube.

Snake Oilers: Ent AI, Spacewalk and Mondoo
0:00 / 43:59

Risky Business #835 -- Why the Fast16 malware is badass

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week’s cybersecurity news, including:

  • The US government is mad as hell about Chinese firms stealing American AI technology
  • Dmitri has an opinion or two about the US selling Nvidia chips to China
  • Speaking of Chinese AI, Kimi’s new 2.6 is very interesting
  • The US sanctions a Cambodian senator for earning mega bucks through scam compounds
  • And a ransomware family is promoting itself as being … quantum-safe?

This week’s show is sponsored by Trail of Bits. CEO and co-founder Dan Guido chats to Pat about how private inference works and Trail of Bits’ audit of WhatsApp’s private AI setup.

This episode is also available on Youtube.

Risky Business #835 -- Why the Fast16 malware is badass
0:00 / 66:28

Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

The Grugq
The Grugq

Independent Security Researcher

On this week’s show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week’s cybersecurity news, including:

  • Vercel got owned, and there’s a few infostealer and compromised employee dots to connect
  • Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse
  • Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs?
  • The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing
  • And DDos attacks hit a couple of smaller-player socials

This week’s episode is sponsored by Permiso. Ian Ahl chats to Pat about the subtle signals Permiso uses to detect ShinyHunters-style activity in cloud and on-prem environments.

This episode is also available on Youtube.

Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs
0:00 / 60:33