Srsly Risky Biz: How the SEC's new cyber disclosure rules are shaking out

PLUS: How private sector involvement is key for the CSRB

In this podcast Patrick Gray and Tom Uren talk about how the SEC’s new disclosure rules that mean companies have four days to report cyber security incidents once they’ve formally decided that they are material. So far, companies are very much erring on the side of caution.

They also look at the criticism of the CSRB’s board composition. Tom thinks these critiques are misguided. The cyber security landscape is so fractured that if the board were made up of faceless bureaucrats it would get very limited traction.

Risky Biz News: SVR hackers also breached HPE

PLUS: New Chinese APT caught performing AitM attacks; Ukraine hacktivists wipe Russian satellite imagery processing center; major RCE bug patched in Jenkins.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #733 -- Say cheese, motherf---er

Australia sanctions and doxxes the Medibank hacker, publishes webcam trophy shots...

In this week’s show Patrick Gray and Adam Boileau discuss the week’s security news.

  • Microsoft honks its clown car horn
  • Australia’s hounds, released, catch their man
  • The beginning of the end for Scattered Spider
  • SEC was SIM swapped but had MFA off any way
  • Ivanti learns a lesson…
  • … while Progress does not
  • and much more

DHS undersecretary for policy and Cyber Safety Review Board head Rob Silvers is this week’s feature guest. He joins the show to talk about how the CSRB handles possible conflicts of interests from board members with industry day jobs.

In this week’s sponsor interview Resourcely’s founder Travis McPeak talks about why we need to help developers with “paved roads” instead of relying on dashboard products to tell us when things have gone wrong.

Risky Biz News: SVR hackers breach Microsoft

PLUS: Chinese APT secretly exploited VMWare zero-day for months; BreachForums admin sentenced; and Zloader returns

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Srsly Risky Biz: The PRC doesn't care about stealth, just access

PLUS: A mild win for geolocation privacy

In this podcast Adam Boileau and Tom Uren talk about how although the PRC has pivoted to quieter living-off-the-land approaches, they don’t really care about stealth. They just want long-term access. So this means noisily digging in to networks and targeting end-of-life devices.

They also look at the FTC’s settlement against geolocation data broker Outlogic. It’s a win, but it’s built on shaky foundations.

Risky Business #732 — We are CRUSHED

PLUS: China snoops on Pooh meme Airdroppers

On this week’s SURPRISE edition, Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Their disappointment over last week’s SEC Twitter hack
  • China rainbow-tables Airdrop
  • Enterprise bugs galore…
  • … and why patching fast is hard when there isn’t even a patch yet
  • UEFI flaws get trad-BIOS-era vendor response
  • and much, much more…

This week’s show is unsponsored, we’re just here for the fun of it.

Srsly Risky Biz: Russia's cyber war fantasy

PLUS: Predatory Sparrow strikes again

In this podcast Adam Boileau and Tom Uren talk about how cyber operations are being used in conflicts in both Ukraine and the Middle East. Some of these operations make sense but others seem pointless or even counterproductive.

Risky Biz News: Ransomware wrecks Paraguay's largest telco

PLUS: Stuxnet saboteur identified after 15 years; China cracks Apple's AirDrop; and ransomware keys recovered when developer arrested in the Netherlands

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #731 -- SEC Twitter hack moves Bitcoin price

PLUS: Kaspersky admires Triangulation hackers' fine work

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • SEC Twitter account hack moves bitcoin price
  • Kaspersky admires Triangulation hackers’ fine work
  • Telcos hacked all over
  • Israel hacks Iranian gasoline pumps again
  • Iran up in Albania, Sudan, Egypt and Tanzania
  • and much, much more…

This week’s show is brought to you by Nucleus Security. Co-founder Scott Kuffer joins us to talk about why patch management is more nuanced than just “patch fast!”