Risky Business #601 -- Everyone's messing with TrickBot

PLUS: Why the "ethics in OST" debate is moot...

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • Yep, it was Cyber Command
  • Also Microsoft, Symantec, Lumen and others
  • Norwegian parliament hack pinned on Russia
  • We finally talk about “ethics in OST”
  • More

Snake Oilers 12 Part 1: An incident management platform for the SOC and auditing for your SaaS accounts

PLUS: Trend Micro pitches XDR as a concept...

In this (wholly sponsored) edition of the Snake Oilers podcast, three vendors will drop by to pitch their sweet, sweet snake oil:

  • Vaughan Shanks pitches the Cydarm SOC incident management platform
  • Adrian Kitto introduces Detexian, a platform that audits SaaS accounts
  • Eric Skinner from Trend Micro talks about XDR

Risky Business #600 -- Who's messing with TrickBot?

PLUS: Treasury issues final warning over sanctioned ransomware crews...

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • The UHS ransomware attack
  • Someone is messing with TrickBot: Did the USA release the hounds?
  • US Treasury issues final warning on sanctioned ransomware crews
  • Azerbaijan and Armenia going at it
  • Fancy Bear owns US government department

Ransomware attack cripples 250 US hospitals

The Risky Biz newsletter for October 6, 2020...

This week alone, ransomware attacks have crippled several hundred US hospitals and inconvenienced scientists working on COVID-19 vaccines and treatments. The lines have been crossed so many times now: do lawmakers really need to wait until an attack changes patient outcomes before the hounds are released?

Risky Biz special guest: Former Australian Prime Minister Malcolm Turnbull

Ex-PM talks about Huawei, 2016 US campaign hack-and-leak, disinformation and more...

In this podcast you’ll hear an interview with former Australian prime minister Malcolm Turnbull. He joins Risky Business to talk through a bunch of issues from Huawei’s exclusion from Australia’s NBN and 5G builds, to political accountability and leadership in cybersecurity.

Risky Business #599 -- You get domain admin! And YOU get domain admin!

EVERYONE gets domain admin!!!

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • Russia, China, Iran having a red hot go at US political orgs
  • Crowdstrike drops report, telcos having a bad time
  • MSS owning US government with dumb bugs
  • DoJ indicts Iranian script kiddie because reasons
  • Proposed TikTok-Oracle deal barely makes sense
  • The mother of all Microsoft auth bugs, wow
  • Much, much more…

GRU eyes US election

The Risky Biz newsletter for September 15, 2020...

Microsoft has outed attempts by GRU attackers to hack into the Office365 accounts of political campaigns.

Risky Business #598 -- China closing the "cyber gap" with USA

PLUS: Operation Warp Speed efforts to ensure COVID research data integrity, availability...

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • Why integrity and availability are key to developing a COVID vaccine
  • China closing the “cyber gap” with USA
  • ASPI publishes research on TikTok, WeChat censorship
  • Belarusian “news app” was tracking activists
  • Julian Assange back in court to fight extradition
  • Much, much more

Risky Biz Soap Box: Canary's Royal origin story

Haroon Meer, this is your life...

This is a sponsored podcast.

Today we’re chatting with a very special guest, Haroon Meer.

Haroon is the founder of Thinkst Canary. Some call it a deception company, but he doesn’t, as you’ll hear. He says Canary is a detection company and the distinction is important.

Risky Business #597 -- Alex Stamos talks news, Pompeo's "clean networks" initiative

PLUS: Why Electron apps are a security trashfire...

On this week’s show Patrick and Alex discuss the week’s security news, including:

  • NZ stock exchange felled by DDoS attack
  • DNI cancels in-person election security briefings for Democats
  • Russians didn’t hack Michigan voter data
  • Sendgrid having a bad time of its own making
  • US to doxes historical DPRK crypto laundering infrastructure, processes

The US exposes how the DPRK cashes out from cybercrime

The Risky Biz newsletter for September 1, 2020...

The US Government has stepped up its campaign to expose North Korea’s state-backed cybercrime operations, this week doxxing malware the DPRK uses to cash out attacks on banks and the techniques it uses to launder funds stolen from cryptocurrency exchanges.

Former Uber CSO charged with obstruction of justice

The Risky Biz newsletter for August 25, 2020...

A criminal complaint filed against Uber’s former chief security officer this week was an extraordinary event because Uber’s response to its 2016 breach was anything but ordinary. There are nonetheless some hard lessons in it for every CSO.

Risky Business #595 -- NSA and FBI document GRU's Linux malware for them

PLUS: All the week's security news...

On this week’s show Patrick, Adam and Sherrod DeGrippo discuss the week’s security news, including:

  • NSA and FBI doxx GRU malware. Lol.
  • Malicious Azure app snags SANS staffer
  • Oracle to acquire TikTok?
  • Trump weighs Snowden pardon
  • Much, much more

This week’s show is brought to you by Airlock Digital. They make allowlist/safelist software that is actually manageable at scale! David Cottingham, an Airlock co-founder, joins the show this week to talk through a few product updates.