Risky Business #733 -- Say cheese, motherf---er

Australia sanctions and doxxes the Medibank hacker, publishes webcam trophy shots...

In this week’s show Patrick Gray and Adam Boileau discuss the week’s security news.

  • Microsoft honks its clown car horn
  • Australia’s hounds, released, catch their man
  • The beginning of the end for Scattered Spider
  • SEC was SIM swapped but had MFA off any way
  • Ivanti learns a lesson…
  • … while Progress does not
  • and much more

DHS undersecretary for policy and Cyber Safety Review Board head Rob Silvers is this week’s feature guest. He joins the show to talk about how the CSRB handles possible conflicts of interests from board members with industry day jobs.

In this week’s sponsor interview Resourcely’s founder Travis McPeak talks about why we need to help developers with “paved roads” instead of relying on dashboard products to tell us when things have gone wrong.

Risky Biz News: SVR hackers breach Microsoft

PLUS: Chinese APT secretly exploited VMWare zero-day for months; BreachForums admin sentenced; and Zloader returns

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Srsly Risky Biz: The PRC doesn't care about stealth, just access

PLUS: A mild win for geolocation privacy

In this podcast Adam Boileau and Tom Uren talk about how although the PRC has pivoted to quieter living-off-the-land approaches, they don’t really care about stealth. They just want long-term access. So this means noisily digging in to networks and targeting end-of-life devices.

They also look at the FTC’s settlement against geolocation data broker Outlogic. It’s a win, but it’s built on shaky foundations.

Risky Business #732 — We are CRUSHED

PLUS: China snoops on Pooh meme Airdroppers

On this week’s SURPRISE edition, Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Their disappointment over last week’s SEC Twitter hack
  • China rainbow-tables Airdrop
  • Enterprise bugs galore…
  • … and why patching fast is hard when there isn’t even a patch yet
  • UEFI flaws get trad-BIOS-era vendor response
  • and much, much more…

This week’s show is unsponsored, we’re just here for the fun of it.

Srsly Risky Biz: Russia's cyber war fantasy

PLUS: Predatory Sparrow strikes again

In this podcast Adam Boileau and Tom Uren talk about how cyber operations are being used in conflicts in both Ukraine and the Middle East. Some of these operations make sense but others seem pointless or even counterproductive.

Risky Biz News: Ransomware wrecks Paraguay's largest telco

PLUS: Stuxnet saboteur identified after 15 years; China cracks Apple's AirDrop; and ransomware keys recovered when developer arrested in the Netherlands

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #731 -- SEC Twitter hack moves Bitcoin price

PLUS: Kaspersky admires Triangulation hackers' fine work

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • SEC Twitter account hack moves bitcoin price
  • Kaspersky admires Triangulation hackers’ fine work
  • Telcos hacked all over
  • Israel hacks Iranian gasoline pumps again
  • Iran up in Albania, Sudan, Egypt and Tanzania
  • and much, much more…

This week’s show is brought to you by Nucleus Security. Co-founder Scott Kuffer joins us to talk about why patch management is more nuanced than just “patch fast!”

Risky Biz News: Merck settles NotPetya lawsuit

PLUS: Turkish APT group Sea Turtle returns; Pompompurin re-arrested after breaking parole; and $1.8 billion worth of crypto was stolen in 2023.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #730 -- Apple, Facebook go all in on e2ee

PLUS: A look back at 2023...

In this week’s edition of the show Patrick Gray and guest co-host Dmitri Alperovitch discuss:

  • Major telco in Ukraine taken down by Russia
  • Apple and Facebook go all in on e2ee
  • Why 702 reauthorisation is looking a bit sketchy
  • The USG wants your push notifications
  • The year in review, plus some predictions for 2024

This week’s show is brought to you by Thinkst Canary. Haroon Meer, Thinkst’s founder, is this week’s sponsor guest. He joins us to talk about APT groups pivoting to living-off-the-land techniques.

Risky Biz Soap Box: Why enterprise browsers are good, actually

Seems crazy. Isn't.

In this Soap Box edition of the Risky Business podcast Patrick Gray talks to Island’s Bradon Rogers about security-focussed, enterprise browsers.

You can use Island to do stuff like grant third parties access to corporate applications on unmanaged devices in a not insane way – that’s a huge pain point for a lot of CISOs, and something that is bringing a lot of new customers through Island’s doors. Obviously for devices you do manage, you can roll Island out as your default enterprise browser. There are a lot of security benefits to doing that.