Risky Business #774 -- Cleo file transfer appliances under widespread attack

PLUS: Snowflake kills username and password-based auth…

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Cleo file transfer products have a remote code exec, here we go again!
  • Snowflake phases out password-based auth
  • Chinese Sophos-exploit-dev company gets sanctioned
  • Romania’s election gets rolled back after Tiktok changed the outcome
  • AMD’s encrypted VM tech bamboozled by RAM with one extra address bit
  • Some cool OpenWRT research
  • And much, much more.

This week’s episode is sponsored by Thinkst, who love sneaky canary token traps. Jacob Torrey previews an upcoming Blackhat talk filled with interesting operating system tricks you can use to trigger canaries in your environment. You wont believe the third trick! Attackers hate him!

This episode is also available on Youtube.

Risky Biz News: Improperly patched Cleo bug exploited in the wild

PLUS: US sanctions Chinese APT exploit supplier; Romania's largest electricity provider hit by ransomware; OpenWrt fixes firmware contamination attack.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Biz News: Members of US Congress targeted by phishing op

PLUS: FCC proposes new telco cyber rules following Salt Typhoon hacks; major phishing gang detained in Belgium and the Netherlands; new DaMAgeCard attack exploits SD Express standard.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered

PLUS: Cybersecurity in energy critical infrastructure

In this interview Patrick Gray talks to Yubico’s COO and President Jerrod Chong about a new Yubikey feature: pre-registration.

You can now ship pre-registered Yubikeys to your staff so you don’t need to rely on your staff to enrol them. They’ve achieved this with really slick Okta and Entra ID integrations.

Jerrod also talks about a recent trip to Singapore and concerns he has about the cybersecurity of critical infrastructure in the energy sector.

Sponsored: Proofpoint on the rise of ClickFix attacks

Selena Larson talks about the recent AitM phishing and ClickFix trends.

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Proofpoint senior threat intelligence analyst Selena Larson about the rise of Attacker-in-the-Middle phishing and ClickFix social engineering campaigns.

Srsly Risky Biz: Why hack and leak is still a big deal

PLUS: Crimephone evolution

In this podcast Tom Uren and Adam Boileau talk about the continued importance of hack and leak operations. They didn’t really affect the recent US presidential election, but they are still a powerful tool for vested interests to influence public policy.

They also discuss the police bust of MATRIX, yet another encrypted messenger that is marketed to criminals and designed to resist police surveillance. The crimephone landscape is splintering due to the constant drumbeat of police success.

This episode is also available on Youtube.

Risky Business #773 -- Cybercriminals are dropping like flies in Russia

PLUS: Would you buy shares in Microsoft's cybersecurity business?

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • The FTC decides its time to take another look at Microsoft
  • Exxon’s opponents targeted by hackers
  • Russian hackers keep getting sentenced and it confuses us
  • The Feds recommend Signal, because throwing hackers out of telcos ain’t gonna happen
  • A South Korean set-top-box manufacturer shipped a DDoS client for corpo-combat
  • And much, much more.

This week’s sponsor interview with Vijit Nair from Corelight. We talk to him about doing detection in cloud environments, and how the varied nature of cloud systems makes the old ways - network monitoring - useful in new and interesting ways.

If you’re in Sydney, Pat is recording a live episode of the Wide World of Cyber with Chris Krebs on 5 December. There might still be tickets left!

This episode is also available on Youtube.

Risky Biz News: Poland arrests former spy chief in Pegasus scandal

PLUS: Hydra dark web market admin gets life in prison; Europol takes down MATRIX crypto-comms platform; Japanese crypto exchange shuts down after major hack.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Biz News: Russia arrests WazaWaka

PLUS: Police arrest tech company CEO for building DDoS function; hackers steal $17 million from Uganda's central bank; Windows Server 2012 zero-day awaits patch.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Sponsored: Push Security on its new stolen credentials detection feature

Jacques Louw also talks AitM phishing and MFA adoption.

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Jacques Louw, co-founder and chief product officer at Push Security, on the company’s new stolen credentials detection feature, how AitM phishing can be spotted in the browser, and how Push deals with customers needing help with MFA.

Srsly Risky Biz: Australian government to shut down AN0M evidence appeals

PLUS: Trump won't save Microsoft from nation-state cyberattacks

In this podcast Tom Uren and Patrick Gray talk about the Australian Government’s extraordinary legislation that will retrospectively ensure that warrants used for the An0m crimephone sting operation are valid.

They also discuss a sterling CISA red team report and the naiveté of Microsoft’s Vice Chair and President Brad Smith.

This episode is also available on Youtube.

Risky Business #772 -- Salt Typhoon is truly a national security disaster

PLUS: The bad old days return with Blue Yonder ransomware attack...

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • A ransomware attack has crippled US supply chain software provider Blue Yonder
  • Russian spies hack nearby wifi to get to their targets, but that doesn’t seem surprising?
  • Salt Typhoon’s attacks on telcos are hard to solve and big on impact
  • China’s surveillance state workers sell their access at home
  • Palo Alto is bad and should feel bad
  • And much, much more.

In this week’s sponsor interview Patrick Gray chats with Matt Muller from Tines about Gartner’s “spicy take” that the SOAR category is dead. SOAR is dead! Long live SOAR!

This episode is also available on Youtube.

Risky Biz News: Banshee Stealer shuts down after source code leak

PLUS: Geico fined over 2020 security breach, a new pro-Kremlin group emerges out of India; Russian group behind Firefox and Windows zero-days.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Between Two Nerds: Why attribution matters

And why it drives competition between sophisticated actors

In this edition of Between Two Nerds Tom Uren and The Grugq talk about different views on attribution and why it still matters for sophisticated state-backed groups.

Risky Biz News: Four PR firms are behind a Chinese propaganda network

PLUS: US telcos learned of Salt Typhoon breaches from Microsoft; Russian hackers pull off a crazy WiFi attack; hacktivists leak data from Andrew Tate's website.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Sponsored: Breaking the deadlock between IT and security teams

Stairwell's Mike Wiacek on how to win friends and influence (IT) people

In this Risky Business News sponsored interview, Tom Uren talks to Mike Wiacek, CEO and founder of Stairwell, about the occasionally dysfunctional relationship between IT and security teams. Mike talks about how security vendors need to reach out to turn IT teams into allies.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: