Risky Business Podcast
March 12, 2025
Risky Business #783 -- Evil webcam ransomwares entire Windows network
Presented by

Technology Editor

CEO and Publisher
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news with special guest Rob Joyce, a Former Special Assistant to the US President and Director of Cybersecurity for NSA.
They talk through:
- A realistic bluetooth-proximity phishing attack against Passkeys
- A very patient ransomware actor encrypts an entire enterprise with a puny linux webcam processor
- The ESP32 backdoor that is neither a door nor at the back
- The X DDoS that Elon said was Ukraine is claimed by pro-Palestinian hacktivists
- Years later, LastPass hackers are still emptying crypto-wallets
- …and it turns out North Korea nailed {Safe}Wallet with a malicious docker image. Nice!
Rob Joyce recently testified to the US House Select Committee on the Chinese Communist Party, and he explains why DOGE kicking probationary employees to the curb is “devastating” for the national security staff pipeline.
This week’s episode is sponsored by SpecterOps, makers of the Bloodhound identity attack path mapping tool. Chief Product Officer Justin Kohler and Principal Security Researcher Lee Chagolla-Christensen discuss their pragmatic approach to disabling NTLM authentication in Active Directory using Bloodhound’s insight.
This episode is also available on Youtube.

Brought to you by SpecterOps
Know Your Adversary
Show notes
CVE-2024-9956 - PassKey Account Takeover in All Mobile Browsers | Tobia Righi - Security Researcher
Feds Link $150M Cyberheist to 2022 LastPass Hacks – Krebs on Security
Camera off: Akira deploys ransomware via webcam
Alleged Co-Founder of Garantex Arrested in India – Krebs on Security
37K+ VMware ESXi instances vulnerable to critical zero-day | Cybersecurity Dive
Apple patches 0-day exploited in “extremely sophisticated attack” - Ars Technica
What Really Happened With the DDoS Attacks That Took Down X | WIRED
Eleven11bot estimates revised downward as researchers point to Mirai variant | Cybersecurity Dive
Safe.eth on X: "Investigation Updates and Community Call to Action" / X
How to verify Safe{Wallet} transactions on a hardware wallet | Safe{Wallet} Help Center and Support.
U.S. pauses intelligence sharing with Ukraine used to target Russian forces - The Washington Post