Risky Business #773 -- Cybercriminals are dropping like flies in Russia

PLUS: Would you buy shares in Microsoft's cybersecurity business?

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • The FTC decides its time to take another look at Microsoft
  • Exxon’s opponents targeted by hackers
  • Russian hackers keep getting sentenced and it confuses us
  • The Feds recommend Signal, because throwing hackers out of telcos ain’t gonna happen
  • A South Korean set-top-box manufacturer shipped a DDoS client for corpo-combat
  • And much, much more.

This week’s sponsor interview with Vijit Nair from Corelight. We talk to him about doing detection in cloud environments, and how the varied nature of cloud systems makes the old ways - network monitoring - useful in new and interesting ways.

If you’re in Sydney, Pat is recording a live episode of the Wide World of Cyber with Chris Krebs on 5 December. There might still be tickets left!

This episode is also available on Youtube.

Risky Biz News: Poland arrests former spy chief in Pegasus scandal

PLUS: Hydra dark web market admin gets life in prison; Europol takes down MATRIX crypto-comms platform; Japanese crypto exchange shuts down after major hack.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Biz News: Russia arrests WazaWaka

PLUS: Police arrest tech company CEO for building DDoS function; hackers steal $17 million from Uganda's central bank; Windows Server 2012 zero-day awaits patch.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Sponsored: Push Security on its new stolen credentials detection feature

Jacques Louw also talks AitM phishing and MFA adoption.

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Jacques Louw, co-founder and chief product officer at Push Security, on the company’s new stolen credentials detection feature, how AitM phishing can be spotted in the browser, and how Push deals with customers needing help with MFA.

Srsly Risky Biz: Australian government to shut down AN0M evidence appeals

PLUS: Trump won't save Microsoft from nation-state cyberattacks

In this podcast Tom Uren and Patrick Gray talk about the Australian Government’s extraordinary legislation that will retrospectively ensure that warrants used for the An0m crimephone sting operation are valid.

They also discuss a sterling CISA red team report and the naiveté of Microsoft’s Vice Chair and President Brad Smith.

This episode is also available on Youtube.

Risky Business #772 -- Salt Typhoon is truly a national security disaster

PLUS: The bad old days return with Blue Yonder ransomware attack...

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • A ransomware attack has crippled US supply chain software provider Blue Yonder
  • Russian spies hack nearby wifi to get to their targets, but that doesn’t seem surprising?
  • Salt Typhoon’s attacks on telcos are hard to solve and big on impact
  • China’s surveillance state workers sell their access at home
  • Palo Alto is bad and should feel bad
  • And much, much more.

In this week’s sponsor interview Patrick Gray chats with Matt Muller from Tines about Gartner’s “spicy take” that the SOAR category is dead. SOAR is dead! Long live SOAR!

This episode is also available on Youtube.

Risky Biz News: Banshee Stealer shuts down after source code leak

PLUS: Geico fined over 2020 security breach, a new pro-Kremlin group emerges out of India; Russian group behind Firefox and Windows zero-days.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Between Two Nerds: Why attribution matters

And why it drives competition between sophisticated actors

In this edition of Between Two Nerds Tom Uren and The Grugq talk about different views on attribution and why it still matters for sophisticated state-backed groups.

Risky Biz News: Four PR firms are behind a Chinese propaganda network

PLUS: US telcos learned of Salt Typhoon breaches from Microsoft; Russian hackers pull off a crazy WiFi attack; hacktivists leak data from Andrew Tate's website.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Sponsored: Breaking the deadlock between IT and security teams

Stairwell's Mike Wiacek on how to win friends and influence (IT) people

In this Risky Business News sponsored interview, Tom Uren talks to Mike Wiacek, CEO and founder of Stairwell, about the occasionally dysfunctional relationship between IT and security teams. Mike talks about how security vendors need to reach out to turn IT teams into allies.

Risky Biz News: US charges five Scattered Spider members

PLUS: Apple fixes macOS zero-days; T-Mobile finally stops a breach; US takes down PopeyeTools carding portal.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: The PLA's cyber operations go dark

PLUS: Market forces in the bug bounty market

In this podcast Tom Uren and Patrick Gray talk about what the People’s Liberation Army cyber operators have been up to. They used to be China’s most visible cyber operators but have since disappeared.

They also discuss the shift towards widespread exploitation of 0days, particularly in enterprise perimeter devices.

This episode is also available on Youtube.

Risky Business #771 -- Palo Alto's firewall 0days are very, very stupid

PLUS: Microsoft teases some plausibly good post-Crowdstrike ideas...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Microsoft introduces some sensible sounding post-Crowdstrike changes
  • Palo Alto patches hella-stupid bugs in its firewall management webapp
  • CISA head Jen Easterly to depart as Trump arrives
  • AI grandma tarpits phone scammers in family-tech-support hell
  • Academic research supports your gut-reaction; phishing training doesn’t work
  • And much, much more.

This week’s episode is sponsored by Greynoise. The always excitable Andrew Morris joins to remind us that the edge-device vulnerabilities Pat and Adam complain about on the show are in fact actually even worse than we make them out to be. Andrew also tells us about a zero-day Greynoise’ AI system truffle-pigged out of their data set.

This episode is also available on Youtube.

Between Two Nerds: Cyber weapons

What they are and why talking about them makes no sense

In this edition of Between Two Nerds Tom Uren and The Grugq talk about what cyber weapons really are and why use of the term is counterproductive.

They reference Defining Offensive Cyber Capabilities, a paper authored by Tom.

Risky Biz News: MSS now dominates China's cyber activity

PLUS: Prolific teenage swatter pleads guilty; Microsoft adds spoofing warning to Exchange; major breach at another data aggregator.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: How Trump will drive covert operations

PLUS: Canada's confusing TikTok ban

In this podcast Tom Uren and Patrick Gray talk about what to expect from President Trump’s second term. Trump is an activist president who believes in using state power, so intelligence agencies will be pushed to conduct more audacious or even outrageous covert operations.

They also discuss concerns about a new UN cybercrime treaty that is set for a vote at the General Assembly and the Canadian government’s curious decision to force the closure of TikTok’s local offices.

This episode is also available on Youtube.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: