Special Edition: Chris Krebs, Alex Stamos and Patrick Gray

A conversation about tech supply chains and sovereignty...

In this special edition of the Risky Business podcast Patrick Gray chats with former Facebook CSO Alex Stamos and founding CISA director Chris Krebs about sovereignty and technology.

China and Russia are doing their level best to yeet American tech from their supply chains – hardware, software and cloud services. They’ll be rebuilding these supply chains – for government systems, at least – from components that they have complete visibility into, and control over.

Meanwhile, America’s government faces different supply chain challenges. It has a supply chain that won’t be weaponised against it by its adversaries, but it lacks the same sort of visibility and control that its adversaries will eventually achieve over their supply chains. So where does this leave the west? Where does it leave China and Russia?

Sponsored: Pushing back the frontiers of vulnerability research

Trail of Bits' Dan Guido on DARPA's AI cyber challenge

In this Risky Business News sponsored interview, Tom Uren talks to Dan Guido, the CEO of security research company Trail of Bits. Dan and Tom discuss DARPA’s upcoming AI cyber challenge, in which Trail of Bits will compete to solve very difficult bug discovery challenges. They also talk about Trail of Bits’ approach to making some of its own tools available to the community.

Risky Biz News: Authorities take down LabHost PhaaS

PLUS: Akira ransomware group made $42 million in a year; "highly profitable trader" found guilty at trial; Kubernetes clusters hacked via OpenMetadata bugs.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here.

Srsly Risky Biz: Why the compromise of open source projects is inevitable

PLUS: Microsoft dependency is a strategic risk

In this podcast Patrick Gray and Tom Uren talk about how open source software is inherently vulnerable to malicious ‘good samaritan’ attacks and what to do about it.

They also talk about a recent breach at data analytics company Sisense, how dependency on Microsoft is a strategic risk, and US Cyber Command’s view of the world.

Risky Business #745 – Tales from the PANageddon

PLUS: Why the Sisense breach is a BFD...

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • Palo Alto’s firewalls have a ../ bad day
  • Sisense’s bucket full of creds gets kicked over
  • United Healthcare draws the ire of congress
  • FISA 702 reauthorisation finally moves forward
  • Apple warns about “mercenary exploitation” but what’s the India link?
  • And much, much, more

This week’s sponsor is Panther, a platform that does detection as code on massive amounts of data. Panther’s founder Jack Naglieri is this week’s sponsor guest, and we spoke with him about some common detection-as-code approaches.

Risky Biz News: PuTTY crypto bug exposes private keys

PLUS: Cisco Duo discloses data breach; China tells telcos to ditch US chips; month-long brute-force campaign targets VPN devices.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Between Two Nerds: 0days in 2023

Looking at 0day through Google-coloured glasses

In this edition of Between Two Nerds Tom Uren and The Grugq look at Google’s review of 0days in 2023. They discuss what this kind of information tells us and how Google’s perspective influences the report.

Risky Biz News: Palo Alto Networks scrambles to push zero-day RCE patch

PLUS: FISA S702 reapproval passes through the House; Roku forcibly enables 2FA for all users after waves of credential-stuffing attacks; ex-Amazon engineer gets 3 years in prison for crypto-heist.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Sponsored: When standards drive innovation

Airlock Digital on how to make sure security standards work

In this Risky Business News sponsored interview, Tom Uren talks to Daniel Schell and David Cottingham, the CTO and CEO of Airlock Digital. They discuss the security standard that drove innovation and the genesis of Airlock Digital and also how to make sure that standards don’t become box-checking exercises.

Risky Biz News: CISA sounds alarm on Sisense breach

PLUS: Apple sends mercenary spyware notifications in 92 countries; US prepares a full Kasperksy ban; BatBadBut bug impacts multiple programming languages.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here

Srsly Risky Biz: States behaving badly

PLUS: The Big Tech bogeyman

In this podcast Patrick Gray and Tom Uren talk about how different states are transgressing what we want to be norms of online behaviour. They also look at the framing around new bipartisan privacy legislation and why vendors should have positive security obligations.

Risky Biz News: Ukraine suspends SBU cyber chief

PLUS: Multi-party approval comes to Google Workspace; Hacker dumps data of most Salvadorans; Ukrainian hackers wipe Russian cloud provider.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Business #744 -- Ransomware upstarts jostle in Lockbit's absence

PLUS: Why enterprise software security will never be truly secure...

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • Ransomware: down but not out
  • Zero day prices on the rise…
  • … and what it means for enterprise software
  • Geopolitical conflict comes to computers in Palau
  • Ukraine cyber chief Illia Vitiuk suspended
  • More x86 microarchitectural bad times
  • And much much more

Proofpoint’s chief strategy officer Ryan Kalember is this week’s sponsor guest. He takes aim at some recent vendor trends, like security companies describing themselves as “platforms”.

Sponsored: GreyNoise on last year's vulnerability exploitation trends

GreyNoise founder Andrew Morris explains how the company's Sift AI works under the hood.

In this Risky Business News sponsor interview, Catalin Cimpanu talks with GreyNoise founder Andrew Morris about last year’s vulnerability exploitation trends, how the company’s AI system works, and Catalin makes a fool of himself because he can’t pronounce ‘abnormalities.’

Snake Oilers: Kodex, ClearVector and Censys

Hear three pitches from three vendors!

In this edition of Snake Oilers you’ll hear pitches from three companies:

  • Kodex: Makes a platform companies can use to interact with law enforcement (Solves the law enforcement impersonator problem, among others.)
  • ClearVector: Cloud security startup from former FireEye/Mandiant SVP/CTO John Laliberte
  • Censys: Scans the entire internet, identifies assets you didn’t know were yours, helps you track attacker infrastructure like C2

Risky Biz News: Ukraine wants Sandworm hackers tried at The Hague

PLUS: Google fixes two Pixel zero-days used to unlock devices; Progress Software delivers another ten out of ten bug; and Windows 10 ESU prices are out!

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.