Videos

News, analysis and product demos

Soap Box: Red teaming AI systems with SpecterOps

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored Soap Box edition of the show, Patrick Gray and James Wilson talk about red teaming AI systems with Russel Van Tuyl, Vice President of Services at elite penetration testing firm SpecterOps.

SpecterOps is the company behind attack path enumeration tool Bloodhound and Bloodhound Enterprise, but they’re also a pentest and red teaming shop with world class expertise in popping shells on all sorts of interesting systems in all sorts of interesting places.

Srsly Risky Biz: Why get a warrant when you have Kash?

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and Amberleigh Jack talk about FBI Director Kash Patel admitting to Congress that the Bureau is buying American’s location data and using it to generate valuable intelligence. That’s concerning, because commercially available information can be used in tremendously invasive ways and the FBI can buy it without needing a warrant.

They also discuss the FCC’s surprising move to ban foreign-made consumer routers. It’s not about security, it is just about reshoring manufacturing.

And finally they discuss the Trump administration’s plan for unleashing the private sector.

Risky Business (830): LiteLLM and security scanner supply chains compromised

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They talk through:

  • TeamPCP’s supply chain attack on Github, and they threw in an anti-Iran wiper, because why not?!
  • Anthropic hooks up its models to just… use your whole computer
  • After Stryker’s Very Bad Day, CISA says maybe add some more controls around your Intune?
  • Another iOS exploit kit shows up in the cyber bargain-bin
  • The FTC decides to ban… all new home routers?! U wot m8?!
  • Supermicro founder was personally sanction-busting Nvidia GPUs into China?!

This week’s episode is sponsored by enterprise browser maker, Island. Chief Customer Officer Bradon Rogers joins Pat to explain how its customers are using Island to control the use of personal AI services in regulated industries. …

Between Two Nerds: Its raining iOS exploit kits!

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq discuss how Google just keeps on finding iOS exploit kits. Is iPhone security busted? And why are Russian state hackers after crypto?

Srsly Risky Biz: Successful war leaves Iran with one option, its cyber forces

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and Amberleigh Jack talk about how successfully achieving America’s war goals could force Iran to double down on cyber power. It’s resilient to bombing and is the cheapest, quickest way for the regime to get some wins post-war.

They also discuss Meta stepping back from end-to-end encryption on Instagram’s direct messages. There is a time and place for E2EE messages, so good riddance.

Finally, they discuss the one weird trick President Trump uses to make his smartphone conversations useless for foreign intelligence services.

Risky Business (829): Sneaky lobsters: Why AI is the new insider threat

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They discuss:

  • Iran’s Intune-based wiper attack on medical device maker Stryker
  • Qihoo 360’s AI publishes its own wildcard TLS cert private key
  • Instagram is canning its end-to-end encrypted messaging
  • What’s going on with mobile internet access in Moscow?
  • The Xbox One’s bootloader gets voltage glitched into submission
  • Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt files…)

This week’s episode is sponsored by browser-based detection and response company, Push Security. Researcher Dan Green and Field CTO Mark Orlando join Pat to talk through the InstallFix variant of the *Fix attack technique. …

Between Two Nerds: Unleashing Iran's hackers

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq discuss how bombing Iran changes incentives for Iranian hacker groups. Destroying other ways that Iran might project power could force it to double down on cyber capabilities.

Srsly Risky Biz: President Trump's best ever cyber strategy

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and Amberleigh Jack talk about the newly released Trump Cyber Strategy for America. The ideas in it are fine and occasionally even game-changing, but many of its goals have been undercut by the administration’s actions to date.

They also discuss the Coruna exploit kit, which is now known to have leaked from a US defence contractor. Exploits are so valuable that it is unrealistic to expect they can be kept secret.

Photo credit: Gage Skidmore, Flickr, licence: https://creativecommons.org/licenses/by-sa/2.0/deed.en

Risky Biz Soap Box: It took a decade, but allowlisting is cool again

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the Risky Business podcast Patrick Gray sits down with Airlock Digital co-founders Daniel Schell and David Cottingham to talk about the role AI models could play in managing enterprise allowlists.

They also talk about the durability of allowlisting as a control. After 12 years in business, the Airlock product hasn’t really changed all that much. That’s a good thing! It also means the Airlock team have been able to spend some time doing deep engineering instead of chasing the latest attacker TTPs and writing detection rules for them.

Risky Business (828): The Coruna exploits are truly exquisite

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

  • The Coruna exploits were L3 Harris, but it seems Triangulation… was not!
  • Iran’s cyber HQ hit by Israeli (kinetic) strikes
  • Trump’s cyber “strategy” is … well, all we’ve got is jokes cause there’s no serious content
  • NSA and CyberCom finally get a leader after Lt Gen Joshua Rudd gets Senate nod
  • DOGE (remember them?!) employee walked a social security database out on a USB stick

This episode is sponsored by open source cloud security scanner Prowler. Creator and CEO Toni de la Fuente talks to Pat about some of the enterprise features Prowler is growing, while remaining true to its open source roots. …