Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #647 -- Israel slashes cyber exports, Interpol takes down 1,000 crooks

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Israel slashes number of countries it will export cyber tools to
  • Interpol takes down 1,000 Internet fraudsters
  • Ransomware crews lying low?
  • When the tabloids do cyber the results are sometimes awesome
  • Much, much more…

This week’s sponsor interview is with Ryan Kalember of Proofpoint. He’s the EVP of Cybersecurity Strategy there and he’s joining me this week to talk about how investment activity in cybersecurity is basically leaving everyone who isn’t a mega enterprise behind.

Risky Business #647 -- Israel slashes cyber exports, Interpol takes down 1,000 crooks
0:00 / 58:48

Risky Business #646 -- Apple cracks the sads, sues NSO Group

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Apple sues NSO Group and it’s all a bit weird
  • Israel charges defence minister’s house cleaner with Iranian hacker collusion (really)
  • USA charges two Iranians over “Proud Boy” emails
  • Cyber insurers nope out of comprehensive coverage
  • Prodaft shells Conti, drops report like it’s a Normal Thing
  • Much, much more

This week’s show is sponsored by VMRay. We’ll be chatting with one of VMRay’s customers in this week’s sponsor interview. Jim Byrge works on the CSIRT team at Valvoline, and he’ll be along to talk about how they replaced their ageing, in-house developed SOAR platform with commercial tools. It was still harder than it should be in 2021, but they got there in the end.

Risky Business #646 -- Apple cracks the sads, sues NSO Group
0:00 / 57:42

Risky Biz Soap Box: DDoS crews will hit you creatively

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Risky Biz Soap Box podcast we chat with Sean Leach, the Chief Product Architect at Fastly, about the history and current status of the DDoS ecosystem. Despite never really making money for criminals, DDoS attacks are still a problem.

CDNs have soaked up a lot of the problem, so DDoS crews are getting creative. Do you know where you’re vulnerable?

Risky Biz Soap Box: DDoS crews will hit you creatively
0:00 / 41:18

Risky Business #645 -- How Israel used NSO to make friends in low places

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Watering hole attacks are getting much better
  • How Israel’s government used NSO to strengthen its diplomatic ties
  • Randori sat on some PAN 0day. This is fine.
  • Facebook outs state-backed ops
  • FBi has unfortunate incident with its mail boxes
  • Much, much more

This week’s sponsor interview is with HD Moore. He’s the founder of Rumble, the network asset discovery scanner, and he’s joining us to talk about some new tricks he’s added to the product, like integrations with cloud service APIs and external discovery products like Censys.

Risky Business #645 -- How Israel used NSO to make friends in low places
0:00 / 64:53

Risky Biz Soap Box: Linux is an infrastructure OS, act accordingly

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Soap Box podcast we’re chatting with Jake King. Jake is a co-founder of Cmd Security, a Linux Security startup that was recently acquired by Elastic.

Cmd’s technology basically started out as a control and visibility tool for Linux systems that could restrict user actions. But over time, the product evolved to be more detection and response oriented.

In this interview we talk to Jake about why Cmd wound up where it is, product wise, and what customers can expect now his company has been swept up by Elastic as a part of its broader push into XDR, or Extended Detection and Response.

Risky Biz Soap Box: Linux is an infrastructure OS, act accordingly
0:00 / 28:13

Risky Business #644 -- USA sanctions NSO Group, hits REvil

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • US sanctions NSO, Candiru, COSEINC and Positive Technologies
  • We wrap up the action in ransomware
  • Why exploit tournaments are boring in America and exciting in China
  • More malicious npm packages in the wild
  • Pentagon updates CMMC to 2.0
  • Much, much more

We’ll hear from Corelight’s CISO Bernard Brantley in this week’s sponsor interview. We’re talking about how attackers think in graphs and defenders think in lists.. Microsoft’s John Lambert wrote a post about that back in 2015, and Bernard joins the show this week to talk about why it’s just as relevant as ever. Stick around for that one.

Risky Business #644 -- USA sanctions NSO Group, hits REvil
0:00 / 62:54

Risky Business #643 -- Iranian fuel stations targeted, PNG ransomware a regional security risk

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Someone took down Iranian fuel stations
  • Papua New Guinea ransomware attack is pretty grim stuff
  • Russia’s SVR still going berserk in cloudtown
  • China Telecom America gets the boot
  • Much, much more

We’ll be hearing from Senetas CEO Andrew Wilson in this week’s sponsor interview. He’s joining us to talk about how the global semiconductor shortage is making him a very, very sad panda.

Risky Business #643 -- Iranian fuel stations targeted, PNG ransomware a regional security risk
0:00 / 73:03

Risky Biz Feature Interview: Mark Dowd on the 0day market and future of exceptional access

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

This feature podcast was made possible by the Hewlett Foundation’s Cyber Initiative. The foundation has given us grant funding to produce this podcast series, which is designed to educate policymakers in cybersecurity so they can make better decisions.

In this edition you’ll hear an interview I recorded with Mark Dowd.

Mark is a world-renowned security researcher who, some years ago, co-founded a company called Azimuth Security. As you’ll hear, the original plan was to provide security research and consulting services to vendors. But, pretty quickly, Azimuth became a serious player in offensive security, selling exploits and other tools to government agencies in the Five Eyes countries.

We recorded this interview touching on the history of Azimuth, what the public gets wrong when talking about 0day and surveillance, and were this whole thing could go – especially considering writing memory corruption exploits is getting so much harder.

Risky Biz Feature Interview: Mark Dowd on the 0day market and future of exceptional access
0:00 / 56:24

Risky Business #642 -- Brits, Dutch and Aussies embrace Hounds Doctrine

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • UK, Netherlands and Australia promise offensive response to big ticket ransomware
  • Wave of major cyber regulation and legislation in USA
  • Iran up in yer O365s, Russians in yer gmails
  • Submarine spy guy would have been fine, if he didn’t make one very big mistake
  • Much, much more

Jonathan Reiber is this week’s sponsor guest. He’s senior director of cybersecurity at AttackIQ and he’s joining us to talk through the US Government’s executive order on Zero Trust. Jonathan says it is actually born of a realisation the US government needs to do something differently, that the old approaches aren’t working.

Risky Business #642 -- Brits, Dutch and Aussies embrace Hounds Doctrine
0:00 / 59:08

Risky Business #641 -- Lawsuit: Ransomware contributed to baby's death

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Group-IB CEO arrested in Russia for treason
  • Lawsuit alleges ransomware contributed to hospitalised baby’s death
  • Nakasone outs self as hound release advocate
  • Syniverse owned, but we don’t know how badly
  • Why Google keyword warrants are awesome
  • Much, much more…

Nucleus co-founder Scott Kuffer is this week’s sponsor guest and the topic is actually a bit hilarious. They’ve found a killer use case that customers are clamouring for: Being able to map vulnerabilities to org groups within your enterprise so you can see who’s slacking off when it comes to patching.

Risky Business #641 -- Lawsuit: Ransomware contributed to baby's death
0:00 / 60:38