Srsly Risky Biz: Why election interference is inevitable

PLUS: ChatGPT in harassment campaigns

In this podcast Patrick Grey and Tom Uren talk about whether election interference will take place in the Taiwanese, US and Russian elections that are all taking place in 2024. They also look at a ChatGPT-powered online harassment campaign.

Risky Business #729 -- Why patching faster won't save us

PLUS: Why the ownCloud bug won't cause a MOVEit-scale disaster...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Iran-linked attacks on US water infrastructure
  • Why the ownCloud bug isn’t the end of the world
  • The D-Link 0day that… never existed?
  • In defence of Okta
  • Much, much more

This week’s show is brought to you by Proofpoint. Ryan Kalember, Proofpoint’s EVP of Cybersecurity Strategy, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: US government agencies officially suck at logging

PLUS: Windows 10 gets three years of paid security updates; Andariel steals South Korea's laser weapons secrets; and there are still 23,000 backdoored Cisco IOS XE devices online.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: Living off the land is the new normal

PLUS: Why more service providers are critical than you think...

In this podcast Patrick Grey and Tom Uren talk about how threat actors abusing legitimate tools (aka living off the land) is the new normal. Everyone is doing it, from activists to cybercriminals to nation states. It’s a worry because defender’s standard practices really aren’t set up to detect and deal with that kind of behaviour.

They also discuss how cyber incidents in the US and UK amongst providers of key real estate services are disrupting house sales.

Risky Business #728 -- The Citrixbleed ransomware disaster

PLUS: Why we secretly stan DPRK APTs...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The Citrixbleed ransomware crisis
  • Why the FBI hasn’t arrested Scattered Spider members
  • DPRK is in your supply chains
  • Microsoft has a brainwave and buys a HSM
  • When civil war meets pig butchering
  • Much, much more

This week’s show is brought to you by Airlock Digital. David Cottingham and Daniel Schell are this week’s sponsor guests.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: Chipmaker NXT hacked by Chinese APT group

PLUS: Russians issue arrest warrant for Facebook executive; EU holds election cybersecurity exercise; and three cryptocurrency exchanges lose a total of $161 million.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: Death by a thousand cuts

PLUS: Ransomware's latest troll

In this podcast Adam Boileau and Tom Uren talk the rise of the Indian hack-for-hire industry. It doesn’t get the same attention that high-profile iPhone ‘zero-click’ hacking does, but its a global scourge that undermines legal processes.

They also discuss the AlphV ransomware group reporting a company to the SEC for not disclosing a breach that it caused.

Risky Biz News: Fastly to block domain fronting in 2024

PLUS: Windows Hello authentication bypassed; Pegasus spyware found in Serbia; and 21 Chinese anti-censorship tools disappeared overnight.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.

You can find the newsletter version of this podcast here.