Sponsored: Tines CEO Eoin Hinchy on burnout in SOC teams

It's a real thing...

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Tines co-founder and CEO Eoin Hinchy about how organisations can maximise the potential of their security teams during an economic downturn, with a concentration on why human error and burnout caused by excessive workloads on security teams can be a risk.

Risky Biz News: Microsoft botches Azure bug fix

PLUS: Salesforce zero-day abused in Facebook phishing campaigns; and a Tesla jailbreak revealed at BlackHat.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: On Microsoft, Wyden's Bark May Have Some Bite

PLUS: Slamming the FBI's back door shut with 702 reform...

In this podcast Patrick Gray and Tom Uren talk about how Microsoft’s lackadaisical cloud product security is attracting the ire of important politicians.

They also examine a presidential advisory board report into Section 702 collection and discuss why oversight in intelligence collection is important.

Risky Business #715 -- Pressure mounts on Microsoft to explain itself

Y U NO HSM, MS? Y?

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Ron Wyden’s “please explain” letter to Microsoft
  • Chinese APT crews prepositioning to disrupt US military logistics
  • China claims US hacked its seismology sensors
  • Ivanti/MobileIron exploitation going vertical
  • Much, much more

This week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO, is this week’s sponsor guest. He’s joined by Eric Foster, Stairwell’s VP of Business Development.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: SEC adopts new cybersecurity rules

PLUS: Former Group-IB CEO gets 14 years in prison for treason; 41 zero-days exploited in the wild last year; and new DDoS attack types spotted.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Feature interview: Australia's Cyber Security Minister Clare O'Neil

Clare O'Neil and Ciaran Martin talk to Patrick Gray about cyber strategy and releasing the hounds…

In this interview Patrick Gray speaks to Australia’s Home Affairs and Cyber Security Minister Clare O’Neil and NCSC founding director Ciaran Martin about the government’s upcoming cybersecurity strategy, releasing the hounds and more.

Srsly Risky Biz: In Beijing, the Fourth Amendment is Still For Sale

PLUS: Ransomware is up, down and sideways...

In this podcast Patrick Gray and Tom Uren talk about draft US legislation that aims to stop law enforcement from circumventing the Fourth Amendment by simply buying data on US citizens. It’s a good move, but the overall data ecosystem needs broader reform.

They also discuss new reports into the ransomware ecosystem. There is both good news and bad news, but data gaps still make it difficult for policymakers to have a good handle on how to respond.

Risky Biz News: Norwegian government hacked with MobileIron zero-day

PLUS: TETRA encrypted radio traffic can be decrypted; Apple patches another Triangulation zero-day; and the Zenbleed vulnerability leaks passwords and encryption keys from AMD Zen CPUs.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Business #714 -- Microsoft vs Wiz: pistols at dawn

They're both wrong, but it's fun to watch...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The dust-up between Microsoft and Wiz
  • MobileIron/Ivanti 0day hoses Norwegian government agencies
  • That’ll do TETRA, that’ll do…
  • Microsoft finally agrees to offer decent logging without price gouging
  • Much, much more

This week’s show is brought to you by Resoucely. Travis McPeak, Resourcely’s co-founder and CEO, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: Ransomware victims stop paying up

PLUS: Tens of thousands of Citrix devices still unpatched against recent zero-day; and Target reveals its EasySweep card skimmer detector.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Biz Soap Box: BEC actors embrace LLMs to attack Japan

Now the hype has died off, let's look at how attackers and defenders are using AI…

This Soap Box edition of the podcast is sponsored by Proofpoint.

Proofpoint offers email security and DLP products and services, and they’re probably best known for being the biggest email security company on the planet.

That means they process a LOT of emails in the hopes of throttling the number of malicious emails that organisations have to deal with, whether that’s malware, phishing or BEC.

So, with that in mind, what role could large language models play in email security?

Now that the initial ChatGPT hype has died off a little, we spoke with Proofpoint’s VP of cybersecurity strategy Ryan Kalember about large language models and how they’re going to help defenders and attackers alike.