<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xml:base="https://risky.biz/feeds/videos/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Risky Business Videos</title>
    <description>Video posts from Risky Business Media.</description>
    <link>https://risky.biz/</link>
    <copyright>Copyright Risky Business Media 2007-2026</copyright>
    <language>en</language>
    <atom:link href="https://risky.biz/feeds/videos/" rel="self" type="application/rss+xml" />
    <pubDate>Fri, 01 May 2026 15:23:13 +1000</pubDate>
    <lastBuildDate>Fri, 01 May 2026 15:23:13 +1000</lastBuildDate>
    <generator>Jekyll v4.2.2</generator>

    
    

    
    
      <item>
        <title>Snake Oilers: Ent AI, Spacewalk and Mondoo</title>
        <pubDate>Fri, 01 May 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/snake-oilers-ent-ai-spacewalk-and-mondoo/</link>
        <guid isPermaLink="true">https://risky.biz/video/snake-oilers-ent-ai-spacewalk-and-mondoo/</guid>
        <description><![CDATA[
          
            In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

* Ent AI: Co-founder Brandon Dixon pitched Ent, an intent-aware, AI-powered endpoint security control. [https://ent.ai](https://ent.ai)

* Spacewalk AI: Founders Chris Fuller and Tim Wenzlau pitch Spacewalk, an AI-powered incident response platform. [https://www.spacewalk.ai](https://www.spacewalk.ai)

* Mondoo: Co-founder Dominik Richter pitches Mondoo, an AI-powered "service as software" in the vulnerability management space. [https://mondoo.com](https://mondoo.com)
          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: US Vows to Fight Distillation Attacks</title>
        <pubDate>Thu, 30 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-us-vows-to-fight-distillation-attacks/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-us-vows-to-fight-distillation-attacks/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the US government stepping in to fight 'distillation attacks' by Chinese AI labs. These are methods used to steal the special sauce of frontier AI models simply by asking questions.

They also discuss the wide-spread shift amongst Chinese threat actors to using botnets for all aspects of their operations. It's a problem for defenders, but also a disruption opportunity for authorities.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (835): Why the Fast16 malware is badass</title>
        <pubDate>Wed, 29 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-835-why-the-fast16-malware-is-badass/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-835-why-the-fast16-malware-is-badass/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week’s cybersecurity news, including:

* The US government is mad as hell about Chinese firms stealing American AI technology 
* Dmitri has an opinion or two about the US selling Nvidia chips to China
* Speaking of Chinese AI, Kimi’s new 2.6 is very interesting
* The US sanctions a Cambodian senator for earning mega bucks through scam compounds
* And a ransomware family is promoting itself as being … quantum-safe?

This week’s show is sponsored by Trail of Bits. CEO and co-founder Dan Guido chats to Pat about how private inference works and Trail of Bits' audit of WhatsApp's private AI setup....
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Hackers from the future</title>
        <pubDate>Mon, 27 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-hackers-from-the-future/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-hackers-from-the-future/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss what the North Korean hack of Drift can tell us about the future of hacking.


          
        ]]></description>
      </item>
    
      <item>
        <title>Feature Interview: Nicholas Carlini, Anthropic</title>
        <pubDate>Fri, 24 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/feature-interview-nicholas-carlini-anthropic/</link>
        <guid isPermaLink="true">https://risky.biz/video/feature-interview-nicholas-carlini-anthropic/</guid>
        <description><![CDATA[
          
            In this episode, Anthropic’s Nicholas Carlini joins Patrick Gray and James Wilson to talk about advancements in AI-driven vulnerability research and exploit development. 

Nicholas’ talk at the recent [un]prompted conference demonstrated how Anthropic’s Opus 4.6 could find and exploit vulnerabilities in popular open source projects. In the short few weeks since then, Anthropic announced a new model that's already identifying hundreds of bug fixes across critical software. Nicholas talks us through the work he does at Anthropic, what’s possible and the limitations with current frontier models, and where this goes from here.
          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Musk snubs French authorities</title>
        <pubDate>Thu, 23 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-musk-snubs-french-authorities/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-musk-snubs-french-authorities/</guid>
        <description><![CDATA[
          
            Tom Uren and James Wilson talk about the French criminal investigation into bias and illegal content on X. Elon Musk and former X CEO Linda Yaccarino didn't appear for voluntary interviews scheduled this week, but refusing meetings won't make X's problems go away. European countries are concerned about X's influence and regulators will be exploring all other options beyond criminal investigations.

They also discuss the fight to renew authorisation of Section 702 collection. It's a valuable intelligence source, but in the past the FBI pointlessly overused it.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (834): Vercel gets owned, Mozilla dumps hundreds of Mythos bugs</title>
        <pubDate>Wed, 22 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-834-vercel-gets-owned-mozilla-dumps-hundreds-of-mythos-bugs/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-834-vercel-gets-owned-mozilla-dumps-hundreds-of-mythos-bugs/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week’s cybersecurity news, including:

* Vercel got owned, and there’s a few infostealer and compromised employee dots to connect
* Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse
* Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs?
* The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing
* And DDos attacks hit a couple of smaller-player socials

This week's episode is sponsored by Permiso. Ian Ahl chats to Pat about the subtle signals Permiso uses to detect ShinyHunters-style activity in cloud and on-prem environments....
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: AI as the mythical 10x hacker</title>
        <pubDate>Mon, 20 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-ai-as-the-mythical-10x-hacker/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-ai-as-the-mythical-10x-hacker/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq take a deep dive into how a single hacker used OpenAI and Anthropic's tools to help hack nine Mexican government organisations in quick time. 


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Time to ban sale of precise geolocation data</title>
        <pubDate>Thu, 16 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-time-to-ban-sale-of-precise-geolocation-data/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-time-to-ban-sale-of-precise-geolocation-data/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about a new Citizen Lab report into Webloc, a tool to identify and track mobile devices. It demonstrates how the collection and sale of mobile phone geolocation data presents privacy and national security risks.

They also discuss a deep-dive into how a single hacker was able to breach nine Mexican government agencies in just weeks using AI assistants. They enabled the attacker to move much faster.


          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (833): The Great Mythos Freakout of 2026</title>
        <pubDate>Wed, 15 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-833-the-great-mythos-freakout-of-2026/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-833-the-great-mythos-freakout-of-2026/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

* Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet
* CISA adds a 2009 Excel bug to the KEV list, u wot?
* Adobe also parties like it’s the 2000s, and fixes an Acrobat Reader bug
* Disgraced former Trenchant exec Peter Williams’ sob story fails to resonate with … anyone
* Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were "secured" by the password: 1234. 

This week's episode is sponsored by mobile network operator, Cape. Ajit Gokhale talks with James about the ways to get being a telco right when you're starting from scratch and solving the security problems of 2026....
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: How AI will upset state cyber competition</title>
        <pubDate>Mon, 13 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-how-ai-will-upset-state-cyber-competition/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-how-ai-will-upset-state-cyber-competition/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss how the rise of AI, which is very good at vulnerability and exploit development, will change the cyber security industry and competition between states. 


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: American diplomats to fight foreign propaganda... on X</title>
        <pubDate>Thu, 09 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-american-diplomats-to-fight-foreign-propaganda-on-x/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-american-diplomats-to-fight-foreign-propaganda-on-x/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the State Department taking to X to counter foreign propaganda. US Secretary of State Marco Rubio dismantled the State Department's counter-propaganda office when he took charge, but it turns out that giving adversary states free reign online is a bad idea.

They also discuss how America's lawful intercept systems are high value targets for Chinese hackers. It's a big deal that part of the FBI's lawful intercept system has been breached and it is high time that the security of these systems was reviewed.
          
        ]]></description>
      </item>
    
      <item>
        <title>Snake Oilers: Burp AI, Sondera and Truffle Security</title>
        <pubDate>Thu, 09 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/snake-oilers-burp-ai-sondera-and-truffle-security/</link>
        <guid isPermaLink="true">https://risky.biz/video/snake-oilers-burp-ai-sondera-and-truffle-security/</guid>
        <description><![CDATA[
          
            In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

* Burp AI and DAST: The founder of PortSwigger and creator of legendary security software Burp Suite, Dafydd Stuttard, drops by to pitch listeners on Burp AI and Burp Suite DAST.

[https://portswigger.net/](https://portswigger.net/)

* Sondera: Josh Devon talks about Sondera, a technology designed to intervene when AI models start doing the wrong thing by statefully tracking their trajectories. This isn't a permissions suite for AI agents, it's a way to stick agents in a harness and make sure they adhere to hard policy boundaries....
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (832): Anthropic unveils magical 0day computer God</title>
        <pubDate>Wed, 08 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-832-anthropic-unveils-magical-0day-computer-god/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-832-anthropic-unveils-magical-0day-computer-god/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

* Anthropic's new Mythos model hunts bugs and chains exploits together so well that… you cant have it…
* …Unless you’re one of their Project Glasswing partners
* The world isn’t short on bugs, though. F5, Fortinet, Progress ShareFile, and TrueConf are all getting rekt by humans
* GPU Rowhammering goes in the GPU, past the IOMMU and back into the host-side Nvidia driver
* North Korea is spending serious time and money on its crypto hacking 
* Just when the US needs CISA most, they slash its budget some more!...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Make cyber, not war</title>
        <pubDate>Mon, 06 Apr 2026 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-make-cyber-not-war/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-make-cyber-not-war/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss how Iran's cyber forces have been used during the ongoing war so far.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: America&apos;s next top (cyber) model</title>
        <pubDate>Thu, 02 Apr 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-americas-next-top-cyber-model/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-americas-next-top-cyber-model/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about how incredibly good AI models have gotten at finding and exploiting vulnerabilities. That will upend the cyber security industry and it has implications for state cyber organisations such as NSA and Cyber Command.

They also discuss how broadband wireless communications links are critical in the war in Ukraine. After losing access to Starlink, Russian forces are doubling down on using equipment from American company Ubiquiti.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (831): The AI bugpocalypse begins</title>
        <pubDate>Wed, 01 Apr 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-831-the-ai-bugpocalypse-begins/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-831-the-ai-bugpocalypse-begins/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

* Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package
* TeamPCP appear to have ransacked Cisco's source and cloud environments
* AI is getting legitimately good at being told to "just go find some 0day in this"
* Kaspersky says Coruna and Triangulation do share code lineage
* Iranian hackers dump Kash Patel's gmail spool
* Oh, and of course there's a Citrix Netscaler memory leak being exploited in the wild

This week's episode is sponsored by Dropzone AI, who make automated AI SOC analysts. Head honcho Ed Wu explains how they've built pre-canned 'hunt packs' to lead the AI off into your environment to find weird, interesting and security relevant things. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: More secure but less safe</title>
        <pubDate>Mon, 30 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-more-secure-but-less-safe/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-more-secure-but-less-safe/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about hacking and scams. While hacking is disappearing as a threat for most people, it is a new golden age for scammers. Even Tom has been scammed!



          
        ]]></description>
      </item>
    
      <item>
        <title>Soap Box: Red teaming AI systems with SpecterOps</title>
        <pubDate>Fri, 27 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/soap-box-red-teaming-ai-systems-with-specterops/</link>
        <guid isPermaLink="true">https://risky.biz/video/soap-box-red-teaming-ai-systems-with-specterops/</guid>
        <description><![CDATA[
          
            In this sponsored Soap Box edition of the show, Patrick Gray and James Wilson talk about red teaming AI systems with Russel Van Tuyl, Vice President of Services at elite penetration testing firm SpecterOps.

SpecterOps is the company behind attack path enumeration tool Bloodhound and Bloodhound Enterprise, but they're also a pentest and red teaming shop with world class expertise in popping shells on all sorts of interesting systems in all sorts of interesting places.
          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Why get a warrant when you have Kash?</title>
        <pubDate>Thu, 26 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-why-get-a-warrant-when-you-have-kash/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-why-get-a-warrant-when-you-have-kash/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about FBI Director Kash Patel admitting to Congress that the Bureau is buying American's location data and using it to generate valuable intelligence. That's concerning, because commercially available information can be used in tremendously invasive ways and the FBI can buy it without needing a warrant.

They also discuss the FCC's surprising move to ban foreign-made consumer routers. It's not about security, it is just about reshoring manufacturing.

And finally they discuss the Trump administration's plan for unleashing the private sector.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (830): LiteLLM and security scanner supply chains compromised</title>
        <pubDate>Wed, 25 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-830-litellm-and-security-scanner-supply-chains-compromised/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-830-litellm-and-security-scanner-supply-chains-compromised/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They talk through:

* TeamPCP's supply chain attack on Github, and they threw in an anti-Iran wiper, because why not?!
* Anthropic hooks up its models to just… use your whole computer
* After Stryker's Very Bad Day, CISA says maybe add some more controls around your Intune?
* Another iOS exploit kit shows up in the cyber bargain-bin
* The FTC decides to ban… all new home routers?! U wot m8?!
* Supermicro founder was personally sanction-busting Nvidia GPUs into China?!

This week's episode is sponsored by enterprise browser maker, Island. Chief Customer Officer Bradon Rogers joins Pat to explain how its customers are using Island to control the use of personal AI services in regulated industries. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Its raining iOS exploit kits!</title>
        <pubDate>Mon, 23 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-its-raining-ios-exploit-kits/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-its-raining-ios-exploit-kits/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss how Google just keeps on finding iOS exploit kits. Is iPhone security busted? And why are Russian state hackers after crypto?



          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Successful war leaves Iran with one option, its cyber forces</title>
        <pubDate>Thu, 19 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-successful-war-leaves-iran-with-one-option-its-cyber-forces/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-successful-war-leaves-iran-with-one-option-its-cyber-forces/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about how successfully achieving America's war goals could force Iran to double down on cyber power. It's resilient to bombing and is the cheapest, quickest way for the regime to get some wins post-war.

They also discuss Meta stepping back from end-to-end encryption on Instagram's direct messages. There is a time and place for E2EE messages, so good riddance.

Finally, they discuss the one weird trick President Trump uses to make his smartphone conversations useless for foreign intelligence services.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (829): Sneaky lobsters: Why AI is the new insider threat</title>
        <pubDate>Wed, 18 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-829-sneaky-lobsters-why-ai-is-the-new-insider-threat/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-829-sneaky-lobsters-why-ai-is-the-new-insider-threat/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They discuss:

* Iran's Intune-based wiper attack on medical device maker Stryker
* Qihoo 360's AI publishes its own wildcard TLS cert private key
* Instagram is canning its end-to-end encrypted messaging
* What's going on with mobile internet access in Moscow?
* The Xbox One's bootloader gets voltage glitched into submission
* Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt files…)

This week's episode is sponsored by browser-based detection and response company,  Push Security. Researcher Dan Green and Field CTO Mark Orlando join Pat to talk through the InstallFix variant of the *Fix attack technique. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Unleashing Iran&apos;s hackers</title>
        <pubDate>Mon, 16 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-unleashing-irans-hackers/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-unleashing-irans-hackers/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss how bombing Iran changes incentives for Iranian hacker groups. Destroying other ways that Iran might project power could force it to double down on cyber capabilities.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: President Trump&apos;s best ever cyber strategy</title>
        <pubDate>Thu, 12 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-president-trumps-best-ever-cyber-strategy/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-president-trumps-best-ever-cyber-strategy/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the newly released Trump Cyber Strategy for America. The ideas in it are fine and occasionally even game-changing, but many of its goals have been undercut by the administration's actions to date.

They also discuss the Coruna exploit kit, which is now known to have leaked from a US defence contractor. Exploits are so valuable that it is unrealistic to expect they can be kept secret.

Photo credit: Gage Skidmore, Flickr, licence: [https://creativecommons.org/licenses/by-sa/2.0/deed.en](https://creativecommons.org/licenses/by-sa/2.0/deed.en)
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Biz Soap Box: It took a decade, but allowlisting is cool again</title>
        <pubDate>Thu, 12 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-biz-soap-box-it-took-a-decade-but-allowlisting-is-cool-again/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-biz-soap-box-it-took-a-decade-but-allowlisting-is-cool-again/</guid>
        <description><![CDATA[
          
            In this Soap Box edition of the Risky Business podcast Patrick Gray sits down with Airlock Digital co-founders Daniel Schell and David Cottingham to talk about the role AI models could play in managing enterprise allowlists. 

They also talk about the durability of allowlisting as a control. After 12 years in business, the Airlock product hasn't really changed all that much. That's a good thing! It also means the Airlock team have been able to spend some time doing deep engineering instead of chasing the latest attacker TTPs and writing detection rules for them.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (828): The Coruna exploits are truly exquisite</title>
        <pubDate>Wed, 11 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-828-the-coruna-exploits-are-truly-exquisite/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-828-the-coruna-exploits-are-truly-exquisite/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

* The Coruna exploits were L3 Harris, but it seems Triangulation… was not!
* Iran's cyber HQ hit by Israeli (kinetic) strikes
* Trump's cyber “strategy” is … well, all we've got is jokes cause there's no serious content
* NSA and CyberCom finally get a leader after Lt Gen Joshua Rudd gets Senate nod
* DOGE (remember them?!) employee walked a social security database out on a USB stick

This episode is sponsored by open source cloud security scanner Prowler. Creator and CEO Toni de la Fuente talks to Pat about some of the enterprise features Prowler is growing, while remaining true to its open source roots. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: An internet blackout won&apos;t stop NSA in Iran</title>
        <pubDate>Mon, 09 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-an-internet-blackout-wont-stop-nsa-in-iran/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-an-internet-blackout-wont-stop-nsa-in-iran/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about why an internet shutdown won't stop US cyber operations in Iran. 


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: The four hour cyber war on Iran</title>
        <pubDate>Thu, 05 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-the-four-hour-cyber-war-on-iran/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-the-four-hour-cyber-war-on-iran/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about how cyber operations were used in the first hours of the US-Israeli attack on Iran. They were instrumental in the attack on Iranian Supreme Leader Ali Khamenei, but they didn't last long. The Iranian regime implemented an internet blackout within four hours of the first bombs.

They also discuss how threat actors are using AI. It's not game-changing so far, but it is very much altering the balance between attack and defence.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (827): Iranian cyber threat actors are down but not out</title>
        <pubDate>Wed, 04 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-827-iranian-cyber-threat-actors-are-down-but-not-out/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-827-iranian-cyber-threat-actors-are-down-but-not-out/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

* The US-Israeli attack on Iran had a whole lot of cyber. It's clearly in the playbook now!
* The NSA Triangulation / L3 Harris Trenchant iOS exploit kit is on the loose, and being used by Chinese crypto scammers
* So long Maddhu Gottumukkala, but CISA's annus horribilis continues
* Adam "humbug" Boileau complains about the Airsnitch wifi attack just being three ethernets in a trenchcoat
* ASD's Cisco SD-WAN threat hunting guide is clearly borne of … experience

This week's episode is sponsored by AI threat hunting platform Nebulock. Sydney Marrone joins to talk about how useful AI models are on the hunt, and her work building out an open source framework and maturity model. It's methodology agnostic, so you can adapt it for your environment, and the github link is in the show notes! ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: How cyber ops in Ukraine have evolved</title>
        <pubDate>Mon, 02 Mar 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-how-cyber-ops-in-ukraine-have-evolved/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-how-cyber-ops-in-ukraine-have-evolved/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq how the use of cyber operations in the war in Ukraine has evolved over time.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Is Claude too woke for war?</title>
        <pubDate>Thu, 26 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-is-claude-too-woke-for-war/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-is-claude-too-woke-for-war/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the argy-bargy between the Pentagon and AI company Anthropic. US Defense Secretary Pete Hegseth is demanding that all safeguards are lifted from Claude, while Anthropic CEO Dario Amodei is insisting on protections against mass surveillance of Americans and use in lethal autonomous weapons.

They also discuss the return of Volt Typhoon, the Chinese hacker group prepositioning in critical infrastructure for sabotage in the event of a conflict over Taiwan. The group is still around, even though the US government declared victory against it last July.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (826): A week of AI mishaps and skulduggery</title>
        <pubDate>Wed, 25 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-826-a-week-of-ai-mishaps-and-skulduggery/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-826-a-week-of-ai-mishaps-and-skulduggery/</guid>
        <description><![CDATA[
          
            On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

* Low skill actors compromise 600 Fortinets with AI-generated playbooks
* Anthropic calls out Chinese AI firms over model distillation 
* Meta's director of AI safety tells her ClawdBot not to delete her mail… so of course it does
* Peter Williams cops 7 years in jail for selling L3 Harris Trenchant's  exploits to Russia
* Ivanti got hacked in 2021 via… bugs in Ivanti

This episode is sponsored by line-rate network capture system Corelight. CEO Brian Dye joins to discuss what AI can do for defenders, and what it can't. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: How NSA will use AI</title>
        <pubDate>Mon, 23 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-how-nsa-will-use-ai/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-how-nsa-will-use-ai/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about how 'professional' Five Eyes cyber espionage agencies like NSA will use AI. These agencies place a premium on stealth and won't yolo AI


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Cyber bullets can&apos;t replace political will</title>
        <pubDate>Thu, 19 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-cyber-bullets-cant-replace-political-will/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-cyber-bullets-cant-replace-political-will/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about a groundswell of calls from European officials to build cyber capabilities to strike back against adversaries. There are good reasons that countries should have their own cyber capabilities, but if you don't have the political will to strike back, having a magic cyber weapon doesn't really make a difference.

They also talk about 'distillation attacks'. They are a way that AI developers can steal the secret sauce of advanced models just by asking questions. It looks like American companies need government assistance if the US wants to keep its AI lead.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Biz Soap Box: The lethal trifecta of AI risks</title>
        <pubDate>Thu, 19 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-biz-soap-box-the-lethal-trifecta-of-ai-risks/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-biz-soap-box-the-lethal-trifecta-of-ai-risks/</guid>
        <description><![CDATA[
          
            There's a lethal trifecta of AI risks: access to private data, exposure to untrusted content, and external communication. In this conversation, Risky Business host Patrick Gray chats with Josh Devon, the co-founder of Sondera, about how to best address these risks.


There is no magic solution to this problem. AI models mix code and data, are non-deterministic, and are crawling around all over your enterprise data and APIs as you read this. 


But in this sponsored interview, Josh outlines how we can start to wrap our hands around the problem.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (825): Palo Alto Networks blames it on the boogie</title>
        <pubDate>Wed, 18 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-825-palo-alto-networks-blames-it-on-the-boogie/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-825-palo-alto-networks-blames-it-on-the-boogie/</guid>
        <description><![CDATA[
          
            On this week's show, Patrick Gray, Adam Boileau and James WIlson discuss the week's cybersecurity news. They cover:

* Palo Alto threat researchers want to attribute to China, but its management says shush
* An increasing proportion of ransomware is data extortion. Is this good?
* Cambodia says it’s going to dismantle scam compounds
* CISA sufferers through yet another shutdown
* Google Gemini's training secrets are being systematically harvested to improve other LLMs
* Academics assess SaaS password managers’ resilience against a malicious server

This episode is sponsored by SSO-firewall integration vendor Knocknoc. Chief exec Adam Pointon joins to talk about the latest in defences… which is to say Knocknoc for Solaris/Sparc and HPUX on PA-RISC?! Okay also that other little known OS… Windows. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Buying the magic weapon</title>
        <pubDate>Mon, 16 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-buying-the-magic-weapon/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-buying-the-magic-weapon/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss whether middle powers should be investing in military cyber capabilities.  


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Microsoft forgoes its secure future</title>
        <pubDate>Thu, 12 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-microsoft-forgoes-its-secure-future/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-microsoft-forgoes-its-secure-future/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about Microsoft CEO Satya Nadella's messaging around personnel changes at the top of its security organisation. These signal a focus on selling security products rather than on making secure products.

They also discuss Expedition Cloud, a Chinese cyber range that replicated the critical infrastructure of neighbouring countries, apparently to develop and fine-tune cyber disruption operations.

Finally, they talk about what we've learnt about the role of cyber operations in the US bombing of Iranian nuclear facilities. It was far bigger than we previously thought.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (824): Microsoft&apos;s Secure Future is looking a bit wobbly</title>
        <pubDate>Wed, 11 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-824-microsofts-secure-future-is-looking-a-bit-wobbly/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-824-microsofts-secure-future-is-looking-a-bit-wobbly/</guid>
        <description><![CDATA[
          
            On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* Microsoft reshuffles security leadership. It doesn't spark joy.
* Russia is hacking the Winter Olympics. Again. But y tho?
* China-linked groups are keeping busy, hacking telcos in Norway, Singapore and dozens of others
* Campaigns underway targeting Ivanti, BeyondTrust and SolarWinds products
* An unknown hero blocks 23/tcp on the US internet backbone
* And James Wilson pops into talk about Claude's go at a C compiler

This episode is sponsored by Ent.AI, an AI startup that isn't quite ready to tell us all what they're doing. But nevertheless, founder Brandon Dixon joins to discuss AI's role in security. Where does language-based understanding take us that previous methods couldn't?...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Why we are doomed to insecurity</title>
        <pubDate>Mon, 09 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-why-we-are-doomed-to-insecurity/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-why-we-are-doomed-to-insecurity/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about why the world is destined to be perpetually insecure. 


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Google&apos;s cyber disruption unit kicks its first goal</title>
        <pubDate>Thu, 05 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-googles-cyber-disruption-unit-kicks-its-first-goal/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-googles-cyber-disruption-unit-kicks-its-first-goal/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about Google's cyber disruption unit taking aim at the IPIDEA residential proxy network. The network was a cybercrime enabler that was used by hundreds of threat actors for crime and espionage. More of this kind of disruption please.

They also discuss SpaceX's rapid action to stop the Russian military using Starlink terminals to guide drones deep into Ukrainian territory.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (823): Humans impersonate clawdbots impersonating humans</title>
        <pubDate>Wed, 04 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-823-humans-impersonate-clawdbots-impersonating-humans/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-823-humans-impersonate-clawdbots-impersonating-humans/</guid>
        <description><![CDATA[
          
            Patrick Gray and Adam Boileau are joined by the newest guy on the Risky Business Media team, James WIlson. They discuss the week's cybersecurity news, including: 

* Notepad++ update supply chain attack has been attributed to China
* The AI agent future is even more stupid than expected; behold the OpenClaw/Clawdbot/Moltbook mess
* The Epstein files claim he had a personal hacker?
* Microsoft is finally getting ready to (think about starting to begin to) disable NTLM by default
* The usual bugs in the usual things! Ivanti, Fortinet, and Solarwinds. Again. 
* Telco hides a free trip in its privacy policy, someone actually reads it and wins!...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: The internal logic of Russian power grid attacks</title>
        <pubDate>Mon, 02 Feb 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-the-internal-logic-of-russian-power-grid-attacks/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-the-internal-logic-of-russian-power-grid-attacks/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss the recent Russian attack on Polish electricity infrastructure.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Punish the wicked and reward the righteous</title>
        <pubDate>Thu, 29 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-punish-the-wicked-and-reward-the-righteous/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-punish-the-wicked-and-reward-the-righteous/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the Pall Mall Process, an international effort to reign in abusive spyware. Tom thinks the US has already stumbled into a viable carrots and sticks style strategy that will shape the industry more than coming up with standards will.

The pair also discuss news that Chinese Salt Typhoon hackers compromised the calls of senior UK officials in Downing Street. The UK has extensive telecommunications security regulations and the incident makes us wonder what that legislation is actually good for.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (822): France will ditch American tech over security risks</title>
        <pubDate>Wed, 28 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-822-france-will-ditch-american-tech-over-security-risks/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-822-france-will-ditch-american-tech-over-security-risks/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. They discuss:

* La France is tres sérieux about ditching US productivity software
* China's Salt Typhoon was snooping on Downing Street
* Trump wields the mighty DISCOMBOBULATOR
* ESET says the Polish power grid wiper was Russia's GRU Sandworm crew
* US cyber institutions CISA and NIST are struggling
* Voice phishing for MFA bypass is getting even more polished

This episode is sponsored by Sublime Security. Brian Baskin is one of the team behind Sublime's 2026 Email Threat Research report. He joins to talk through what they see of attackers' use of AI, as well as the other trends of the year....
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Getting pinged and the fog of war</title>
        <pubDate>Tue, 27 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-getting-pinged-and-the-fog-of-war/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-getting-pinged-and-the-fog-of-war/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss how getting pinged hurts state hackers by introducing uncertainty. Publishing technical reports on the hack can actually improve the situation by removing uncertainty  about how  attackers were detected.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: You can&apos;t block space internet</title>
        <pubDate>Thu, 22 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-you-cant-block-space-internet/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-you-cant-block-space-internet/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the rise of technologies that can undermine internet blackouts such as Starlink and its relatively new direct-to-cell service. Authoritarian internet shutdowns and disasters happen often enough that governments should think about how to take advantage of these new technologies rather than just reacting when crises arise.

They also discuss the nomination of General Joshua Rudd as head of NSA and US Cyber Command.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (821): Wiz researchers could have owned every AWS customer</title>
        <pubDate>Wed, 21 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-821-wiz-researchers-could-have-owned-every-aws-customer/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-821-wiz-researchers-could-have-owned-every-aws-customer/</guid>
        <description><![CDATA[
          
            In this week's show, Patrick Gray and Adam Boileau discuss the week's cybersecurity news, joined by a special guest. BBC World Cyber Correspondent Joe Tidy is a long time listener and he pops in for a ride-along in the news segment plus a chat about his new book. 

This week news includes: 
* Did the US cyber Venezuela's power grid, or do they just want us to think they coulda?
* US govt might boycott the RSAC Conference 'cause Jen Easterly being CEO makes them mad
* MS Patch Tuesday fixes CVSS5.5 bug and … stops you shutting down
* Wiz pulls off cloud stunt hack that ends with control of everyone's AWS console...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Why the West sucks at Information Warfare</title>
        <pubDate>Mon, 19 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-why-the-west-sucks-at-information-warfare/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-why-the-west-sucks-at-information-warfare/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about what information warfare even is, revisit a 30-year-old paper and examine why Western governments struggle with the concept.  



          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: China Fights Scam Compounds … For China</title>
        <pubDate>Thu, 15 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-china-fights-scam-compounds-for-china/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-china-fights-scam-compounds-for-china/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the Chinese government's reactive approach to tackling scam compounds. It's driven by bad news on domestic media and therefore focusses on the compounds that are targeting Chinese citizens. Rather than eliminating the industry, that may instead be shaping the industry to focus on other countries and particularly Americans.

They also discuss the role of disruptive cyber operations in the US's raid to capture Venezuelan President Nicolás Maduro.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (820): Asian fraud kingpin will face Chinese justice (pew pew!)</title>
        <pubDate>Wed, 14 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-820-asian-fraud-kingpin-will-face-chinese-justice-pew-pew/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-820-asian-fraud-kingpin-will-face-chinese-justice-pew-pew/</guid>
        <description><![CDATA[
          
            Risky Business returns for 2026! Patrick Gray and Adam Boileau talk through the week's cybersecurity news, including:
 
* Santa brings hackers MongoDB memory leaks for Christmas
* Vercel pays out a million bucks to improve its React2Shell WAF defences
* 39C3 delivers; the pink Power Ranger deletes nazis, while a catgirl ruins GnuPG
* Cambodian scam compound kingpin gets extradited to China, and we don't think it'll go well for him
* Krebs picks apart the Kimwolf botnet and residential proxy networks
* So many healthcare data leaks that we have a roundup section

This week's episode is sponsored by Airlock Digital. The founders of the application allow-listing vendor, David Cottingham and Daniel Schell, discuss Microsoft's ClickOnce .NET app packaging, and how attackers have been abusing it to load code. Airlock hates it when you load code!...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Lights out!</title>
        <pubDate>Mon, 12 Jan 2026 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-lights-out/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-lights-out/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq about the role of cyber operations in the US capture of Venezuela's president Nicolas Maduro. 



          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Like Huawei, but for electricity</title>
        <pubDate>Thu, 18 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-like-huawei-but-for-electricity/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-like-huawei-but-for-electricity/</guid>
        <description><![CDATA[
          
            Tom Uren and Patrick Gray talk about America's increasing dependence on Chinese manufacturers for electrical sector equipment. This doesn't seem like a good idea when China is hacking electric utilities for sabotage and PLA researchers are dreaming up ways to attack the grid.

They also discuss the possibility that the US was responsible for a cyber attack on Venezuela's state oil company and how Russian state-backed hacktivism is so dumb.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (819): Venezuela (credibly?!) blames USA for wiper attack</title>
        <pubDate>Wed, 17 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-819-venezuela-credibly-blames-usa-for-wiper-attack/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-819-venezuela-credibly-blames-usa-for-wiper-attack/</guid>
        <description><![CDATA[
          
            In the final show of 2025, Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: 

* React2Shell attacks continue, surprising no one
* The unholy combination of OAuth consent phishing, social engineering and Azure CLI
* Venezuela's state oil firm gets ransomware'd, blames US… but what if it really is a US cyber op?!
* Russian junk-hacktivist gets indicted for cybering critical… err...  a car wash and a fountain
* Microsoft finally turns RC4 off by default in Active Directory Kerberos
* Traefik's TLS verify=on … turns it off, whoopsie 🤡

This week's episode is sponsored by Sublime Security, makers of an email filtering solution that's up for  dealing with modern problems. Founder and CEO Josh Kamdjou joins to talk about calendar invite phishing, and the extra steps they've had to take to reach into people's calendars and fix the mess. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Three Nerds: The evolution of Iranian cyber espionage</title>
        <pubDate>Mon, 15 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-three-nerds-the-evolution-of-iranian-cyber-espionage/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-three-nerds-the-evolution-of-iranian-cyber-espionage/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk to Hamid Kashfi, CEO and founder of DarkCell, about the Iranian cyber espionage scene.

Kashfi talks about how the regime once forced people to hack and crushed the domestic security research scene. He describes how and why the government has changed its approach and is now reaping the rewards of improved Iranian capabilities.


          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Biz Soap Box: Graph the planet!</title>
        <pubDate>Thu, 11 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-biz-soap-box-graph-the-planet/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-biz-soap-box-graph-the-planet/</guid>
        <description><![CDATA[
          
            In this sponsored Soap Box edition of the Risky Business podcast, Patrick Gray chats with Jared Atkinson, CTO of SpecterOps, about BloodHound OpenGraph. 

OpenGraph enumerates attack paths across platforms and services, not just your primary directories. 

A compromised GitHub account to on-prem AD compromise attack path? It's a thing, and OpenGraph will find it.

Cross-platform attack path enumeration! So good!
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (818): React2Shell is a fun one</title>
        <pubDate>Wed, 10 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-818-react2shell-is-a-fun-one/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-818-react2shell-is-a-fun-one/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* There's a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?
* China is out popping shells with it
* Linux adds support for PCIe bus encryption
* Amnesty International says Intellexa can just TeamViewer into its customers' surveillance systems
* ...and a Belgian murder suspect complains that GrapheneOS's duress wipe feature failed him?

This week's episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll's Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board? ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: When cyber campaigns cross a line</title>
        <pubDate>Thu, 04 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-when-cyber-campaigns-cross-a-line/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-when-cyber-campaigns-cross-a-line/</guid>
        <description><![CDATA[
          
            Tom Uren and Patrick Gray discuss a new report proposing a framework for deciding when cyber operations raise red flags. It suggests seven red flags and could help clarify thinking about how to respond to different operations.

They also discuss Anthropic testifying to Congress and Iran using cyber intelligence to target missile strikes including by sharing it with Houthi rebels who fired at a specific ship.

And finally, we are not reassured by China's white paper about being a good cyber citizen.


          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (817): Less carnage than your usual Thanksgiving</title>
        <pubDate>Wed, 03 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-817-less-carnage-than-your-usual-thanksgiving/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-817-less-carnage-than-your-usual-thanksgiving/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. It's a quiet week with Thanksgiving in the US, but there's always some cyber to talk about:

* Airbus rolls out software updates after a cosmic ray bitflips an A320 into a dive
* Krebs tracks down a Scattered Lapsus$ Hunters teen through the usual poor opsec...
* ... as Wired publishes an opsec guide for teens. 
* Microsoft decides its login portal is worth a Content Security Policy
* South Korean online retailer data breach covers 65% of the country

This week's episode is sponsored by Nebulock. Founder and CEO Damien Lewke joins to talk through their work bringing more SIgma threat detection rules to MacOS. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Beating back state espionage</title>
        <pubDate>Mon, 01 Dec 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-beating-back-state-espionage/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-beating-back-state-espionage/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq wonder whether it is possible to deter states from cyber espionage with doxxing and other disruption measures.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: DeepSeek and Musk&apos;s Grok both toe the party line</title>
        <pubDate>Thu, 27 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-deepseek-and-musks-grok-both-toe-the-party-line/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-deepseek-and-musks-grok-both-toe-the-party-line/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about new research that shows the Chinese-made DeepSeek-R1 AI model produces insecure code when  prompts include topics that the Chinese Communist Party dislikes. It's interesting research, but the CCP doesn't have a monopoly on imposing AI bias.

They also discuss the complete doxxing of the Iranian cyber espionage group known as APT35 or Charming Kitten.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (816): Copilot Actions for Windows is extremely dicey</title>
        <pubDate>Wed, 26 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-816-copilot-actions-for-windows-is-extremely-dicey/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-816-copilot-actions-for-windows-is-extremely-dicey/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* Salesforce partner Gainsight has customer data stolen
* Crowdstrike fires insider who gave hackers screenshots of internal systems
* Australian Parliament turns off wifi and bluetooth in fear of of visiting Chinese bigwigs
* Shai-Hulud npm/Github worm is back, and rm -rf'ier than ever
* SEC gives up on Solarwinds lawsuit
* Dog eats cryptographer's key material

This week's episode is sponsored by runZero. HD Moore pops in to talk about how they’re integrating runZero with Bloodhound-style graph databases. He also discusses uses for driving runZero's tools with an AI, plus the complexities of shipping AI when the company has a variety of deployment models....
          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: AI-Powered espionage will favor China</title>
        <pubDate>Thu, 20 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-ai-powered-espionage-will-favor-china/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-ai-powered-espionage-will-favor-china/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about Anthropic's discovery of an "AI-orchestrated" cyber espionage campaign. To Tom, it feels a research project, but it's pretty clear it will be really useful for threat actors that aren't focussed on specific high-priority targets. Think ransomware, Chinese intellectual property theft and North Korean hackers. But it won't be so good for Western intelligence agencies.

They also discuss Google's legal disruption of the China-based Lighthouse phishing as a service operation. Surprisingly, it seems to be working!

Finally, they talk about why the memory safe Rust language has been a triple win for Android.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Biz Soap Box: Greynoise knows when bad bugs are coming</title>
        <pubDate>Thu, 20 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-biz-soap-box-greynoise-knows-when-bad-bugs-are-coming/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-biz-soap-box-greynoise-knows-when-bad-bugs-are-coming/</guid>
        <description><![CDATA[
          
            In this sponsored Soap Box edition of the podcast, Andrew Morris joins Patrick Gray to talk about how Greynoise can often get a 90 day heads up on serious vulnerabilities. Whether it's malicious actors doing reconnaissance or the affected vendors trying to understand the scope of the problem, it seems that mass scanning activity lines up pretty nicely with typical 90-day disclosure timelines.

A fascinating chat with Andrew, as always.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (815): Anthropic&apos;s AI APT report is a big deal</title>
        <pubDate>Wed, 19 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-815-anthropics-ai-apt-report-is-a-big-deal/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-815-anthropics-ai-apt-report-is-a-big-deal/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* Anthropic says a Chinese APT orchestrated attacks using its AI
* It’s a day ending in -y, so of course there are shamefully bad Fortinet exploits in the wild
* Turns out slashing CISA was a bad idea, now it’s time for a hiring spree
* Researchers brute force entire phone number space against Whatsapp contact discovery API
* DOJ figures out how to make SpaceX turn off scam compounds’ Starlink service

This week's episode is sponsored by Mastercard. Senior Vice President of Mastercard Cybersecurity Urooj Burney joins to talk about how the roles of fraud and cyber teams in the financial sector are starting to converge. Mastercard also recently acquired Recorded Future, and Urooj talks about how they aim to integrate cyber threat intelligence into the financial world. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Russia&apos;s cyber war on wheat</title>
        <pubDate>Mon, 17 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-russias-cyber-war-on-wheat/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-russias-cyber-war-on-wheat/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about the strategic "logic" of Russian wiper attacks on the Ukrainian grain sector.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Meta&apos;s fraud profit scandal</title>
        <pubDate>Thu, 13 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-metas-fraud-profit-scandal/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-metas-fraud-profit-scandal/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about a new Reuters' report that reveals how Meta is knowingly raking in cash from scam advertisements. It's around $16 billion worth, and in documents Meta calculates that it outweighs the costs of possible regulatory action.

They also discuss recent state-backed supply chain attacks that have, so far, remained targeted and responsible. Finally they look at the UK's decision to stop sharing intelligence with the US about suspected drug boats in the Caribbean.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (814): It&apos;s a bad time to be a scam compound operator</title>
        <pubDate>Wed, 12 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-814-its-a-bad-time-to-be-a-scam-compound-operator/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-814-its-a-bad-time-to-be-a-scam-compound-operator/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* The KK Park scam compound in Myanmar gets blasted with actual dynamite
* China sentences more scammers TO DEATH
* While Singapore is opting to lash them with the cane
* Chinese security firm KnownSec leaks a bunch of documents
* Necromancy continues on NSO Group, with a Trump associate in charge
* OWASP freshens up the Top 10, you won't believe what's number three!

This week's episode is sponsored by Thinkst Canary. Big bird Haroon Meer joins and, as usual, makes a good point. If you're going to trust a vendor to do something risky like put a box on your network, they have an obligation to explain how they make that safe. Thinkst has a /security page that does exactly that. So why do we let Palo Alto and Fortinet get away with "trust me, bro"?...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Why AI in malware is lame</title>
        <pubDate>Mon, 10 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-why-ai-in-malware-is-lame/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-why-ai-in-malware-is-lame/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss how cyber criminals and even state actors are being dumb about using AI.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: The cyber regime change pipe dream</title>
        <pubDate>Thu, 06 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-the-cyber-regime-change-pipe-dream/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-the-cyber-regime-change-pipe-dream/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about aggressive US cyber operations targeting the Venezuelan government in President Trump's first term. These were narrowly successful in that they achieved their immediate operational goals, but they didn't achieve Trump's broader policy goal of ousting Venezuelan leader Nicolás Maduro.

They also talk about why the adtech ecosystem is a national security problem all round the world and how cybercriminals are collaborating with organised crime to steal cargo from logistics companies.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (813): FFmpeg has a point</title>
        <pubDate>Wed, 05 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-813-ffmpeg-has-a-point/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-813-ffmpeg-has-a-point/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
 
* We love some good vulnerability reporting drama, this time FFmpeg's got beef with Google
* OpenAI announces its Aardvark bug-gobbling system
* Two US ransomware responders get arrested for… ransomware 
* Memento (nee HackingTeam) CEO says: Sì, those are totally our tools getting snapped in Russia
* Hackers help freight theft gangs steal shipments to resell
* A second Jabber Zeus mastermind gets his comeuppance 15 years on

This week's episode is sponsored by Nucleus Security, who make a vulnerability information management system. Co-founder Scott Kuffer says that approaches for triaging vulnerabilities have started to fall apart, given there are just. So. Many. And they're all important!...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: Lost in transmission</title>
        <pubDate>Mon, 03 Nov 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-lost-in-transmission/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-lost-in-transmission/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss the futility of using aggressive cyber operations to send messages between states.  


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Peter Williams, Ex-ASD, Pleads Guilty to Selling Eight Exploits to Russia</title>
        <pubDate>Thu, 30 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-peter-williams-ex-asd-pleads-guilty-to-selling-eight-exploits-to-russia/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-peter-williams-ex-asd-pleads-guilty-to-selling-eight-exploits-to-russia/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about Peter Williams, the general manager of vulnerability research firm Trenchant, who has pleaded guilty to selling exploits to the Russian 0day broker Operation Zero. It's a terrible look, but it doesn't mean the private sector can't be trusted to develop exploits.

They also discuss a new report's recommendations to empower the Office of the National Cyber Director. It's a good idea, but it won't make up for the cuts in funding and personnel across the Trump administration's cyber portfolio.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (812): Alleged Trenchant exploit mole is ex-ASD</title>
        <pubDate>Wed, 29 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-812-alleged-trenchant-exploit-mole-is-ex-asd/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-812-alleged-trenchant-exploit-mole-is-ex-asd/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* L3Harris Trenchant boss accused of selling exploits to Russia once worked at the Australian Signals Directorate
* Microsoft WSUS bug being exploited in the wild
* Dan Kaminsky DNS cache poisoning comes back because of a bad PRNG
* SpaceX finally starts disabling Starlink terminals used by scammers
* Garbage HP update deletes certificates that authed Windows systems to Entra

This week's episode is sponsored by automation company Tines. Field CISO Matt Muller joins to discuss how Tines has embraced LLMs and the agentic-AI future into their workflow automation. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: NSA gets its mojo back!</title>
        <pubDate>Mon, 27 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-nsa-gets-its-mojo-back/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-nsa-gets-its-mojo-back/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq dissect a recent Chinese CERT report that the NSA had hacked China's national time keeping service.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Hacking for Godot</title>
        <pubDate>Thu, 23 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-hacking-for-godot/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-hacking-for-godot/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about how America can better use its private sector to scale up offensive cyber activities, including espionage and disruption operations. Involving it to tackle ransomware and cryptocurrency scammers makes a lot of sense.

They also talk about how the ransomware ecosystem is splintering, and one operator's relatively quick journey from being an affiliate to a platform operator.

Show Notes:

From Chaos to Capability: Building the US Market for Offensive Cyber  [https://sergeybratus.gitlab.io/papers/DartmouthCyberRoundtable2025.pdf](https://sergeybratus.gitlab.io/papers/DartmouthCyberRoundtable2025.pdf)...
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (811): F5 is the tip of the crap software iceberg</title>
        <pubDate>Wed, 22 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-811-f5-is-the-tip-of-the-crap-software-iceberg/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-811-f5-is-the-tip-of-the-crap-software-iceberg/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* China has been rummaging in F5's networks for a couple of years
* Meanwhile China tries to deflect by accusing the NSA of hacking its national timing system
* Salesforce hackers use their stolen data trove to dox NSA, ICE employees
* Crypto stealing, proxy-deploying, blockchain-C2-ing VS Code worm charms us with its chutzpah
* Adam gets humbled by new Linux-capabilities backdoor trick
* Microsoft ignores its own guidance on avoiding BinaryFormatter, gets WSUS owned. 

This episode is sponsored by Push Security. Co-founder and Chief Product Officer Jacques Louw joins to talk through how Push traced a LinkedIn phishing campaign targeting CEOs, and the new logging capabilities that proved critical to understanding it....
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Three Nerds: India, the sleeping cyber superpower</title>
        <pubDate>Mon, 20 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-three-nerds-india-the-sleeping-cyber-superpower/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-three-nerds-india-the-sleeping-cyber-superpower/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk to Joe Devanny, senior lecturer from King's College London, all about India's missing cyber power. It has the ingredients to become a cyber superpower, but so far, hasn't shown the motivation.   


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Small beer surveillance firms escape crackdown, for now</title>
        <pubDate>Thu, 16 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-small-beer-surveillance-firms-escape-crackdown-for-now/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-small-beer-surveillance-firms-escape-crackdown-for-now/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about First Wap, a Jakarta-based company that is selling surveillance-as-a-service. The good news is that it appears that government and media attention has had an impact on high-profile spyware vendors like NSO Group. The bad news is that these smaller players are flying under the radar and aren't afraid of selling to sketchy customers.

They also talk about how the Chinese government has harnessed the power of its exploit development community with hacking contests.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Biz Soap Box: Why Mastercard is scaling its cybersecurity business</title>
        <pubDate>Thu, 16 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-biz-soap-box-why-mastercard-is-scaling-its-cybersecurity-business/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-biz-soap-box-why-mastercard-is-scaling-its-cybersecurity-business/</guid>
        <description><![CDATA[
          
            In this sponsored Soap Box edition of the Risky Business podcast, host Patrick Gray chats with Mastercard's Executive Vice President and Head of Security Solutions, Johan Gerber, about how the card brand thinks about cybersecurity and why it's aggressively investing in the space.

After listening to this interview you'll understand why the credit card company spent $2.65b on threat intelligence vendor Recorded Future!
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (810): Data extortion attacks have a silver lining</title>
        <pubDate>Wed, 15 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-810-data-extortion-attacks-have-a-silver-lining/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-810-data-extortion-attacks-have-a-silver-lining/</guid>
        <description><![CDATA[
          
            In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* FBI intervenes in Scattered Spider Salesforce leaksite
* Clop loots Oracle E-Biz deployments
* Plus so much more data extortion.. At least it’s not ransomware … we     guess?
* The US still can't decide who's gonna be in charge of NSA & Cybercom
* Cambodian scam compounds get sanctioned and $15b in crypto is seized
* NSO gets sold for pocket-lint-grade money
* Bugs! Redis CVSS 10, Ivanti, Crowdstrike and… Internet Explorer?! zeroday?! In the wild?!!!?

This week's episode is sponsored by Stairwell. Founder Mike Wiacek talks about how Stairwell brings VirusTotal-like visibility to private files, and about integrating the insights that brings into your SOC workflow. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: The Keyser Soze of Scattered Spider</title>
        <pubDate>Mon, 13 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-the-keyser-soze-of-scattered-spider/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-the-keyser-soze-of-scattered-spider/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about how different cybercriminal groups are looking for insiders to provide network access.


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Clop is a big fish, but not worth hunting</title>
        <pubDate>Thu, 09 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-clop-is-a-big-fish-but-not-worth-hunting/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-clop-is-a-big-fish-but-not-worth-hunting/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the Clop ransomware gang. It is interesting because the group has arrived at a strategy that rinses a whole lot of enterprises at once and comes with a decent pay day. But it's actually the least damaging kind of ransomware. Tom wonders why can't more gangs be like Clop?

They also discuss the US government having second thoughts about ignoring foreign influence operations. Its adversaries run them all the time, so perhaps just sticking its head in the sand isn't the best strategy.
          
        ]]></description>
      </item>
    
      <item>
        <title>Snake Oilers: Realm Security, Horizon3 and Persona</title>
        <pubDate>Tue, 07 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/snake-oilers-realm-security-horizon3-and-persona/</link>
        <guid isPermaLink="true">https://risky.biz/video/snake-oilers-realm-security-horizon3-and-persona/</guid>
        <description><![CDATA[
          
            In this edition of the Snake Oilers podcasts, three vendors pop in to pitch you all on their wares:

* Realm Security: A security focussed, AI-first data pipeline platform [https://realm.security/](https://realm.security/)
* Horizon3: AI hackers! Pentesting robots!! They're coming fer yur jerbs! [https://horizon3.ai/](https://horizon3.ai/)
* Persona: Verify customer and staff identities with live capture [https://withpersona.com/](https://withpersona.com/)
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: What drives 0day mass exploitation</title>
        <pubDate>Mon, 06 Oct 2025 00:00:00 +1100</pubDate>
        <link>https://risky.biz/video/between-two-nerds-what-drives-0day-mass-exploitation/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-what-drives-0day-mass-exploitation/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about the 0day mass exploitation of SharePoint and Exchange. This type of widespread hacking appears to be increasingly common... but is it? 


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: The cyberespionage gig economy</title>
        <pubDate>Thu, 02 Oct 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-the-cyberespionage-gig-economy/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-the-cyberespionage-gig-economy/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about different ways foreign intelligence services are finding to recruit local proxies. These methods could be too risky for Western intelligence agencies, but for some state's services they just make sense.

They also discuss a report into DOGE and how speed was prioritised over robust governance.
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business (809): Hackers try to pay a journalist for access to the BBC</title>
        <pubDate>Wed, 01 Oct 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-809-hackers-try-to-pay-a-journalist-for-access-to-the-bbc/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-809-hackers-try-to-pay-a-journalist-for-access-to-the-bbc/</guid>
        <description><![CDATA[
          
            On this week’s show Patrick Gray is on holiday so Amberleigh Jack and Adam Boileau hijack the studio to discuss the week’s cybersecurity news, including:

* Hackers learn that trying to coerce a journalist just makes for … a great story?
* A man in his 40s gets arrested over the European airport chaos. Yep, we’re surprised, too
* Adam fanboys over Watchtowr Labs while bemoaning Fortra
* Academics pick apart Tile trackers and find them lacking
* CISA tells agencies to patch their damn Cisco gear

 Show Notes: 

'You'll never need to work again': Criminals offer reporter money to hack BBC
[https://www.bbc.com/news/articles/c3w5n903447o](https://www.bbc.com/news/articles/c3w5n903447o)...
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: The power of cyber</title>
        <pubDate>Mon, 29 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-the-power-of-cyber/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-the-power-of-cyber/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq discuss the power of cyber. 



          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: The kids aren&apos;t alright</title>
        <pubDate>Thu, 25 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-the-kids-arent-alright/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-the-kids-arent-alright/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about how the funnel that turns kids into cyber criminals has evolved over the last decade. Cybercrime's reach has broadened, it is more lucrative and more violent.

They also talk about new thinking about deterring America's cyber adversaries.


          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (808): Insane megabug in Entra left all tenants exposed</title>
        <pubDate>Wed, 24 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-808-insane-megabug-in-entra-left-all-tenants-exposed/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-808-insane-megabug-in-entra-left-all-tenants-exposed/</guid>
        <description><![CDATA[
          
            On this week’s show Patrick Gray and special guest Rob Joyce discuss the week’s cybersecurity news, including:

* Secret Service raids a SIM farm in New York
* MI6 launches a dark web portal
* Are the 2023 Scattered Spider kids finally getting their comeuppance?
* Production halt continues for Jaguar Land Rover
* GitHub tightens its security after Shai-Hulud worm

This week's episode is sponsored by Sublime Security. In this week's sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI in an email security platform.
 ...
          
        ]]></description>
      </item>
    
      <item>
        <title>DEMO: Sublime Security demos its agentic AI powered email security platform</title>
        <pubDate>Wed, 24 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/demo-sublime-security-demos-its-agentic-ai-powered-email-security-platform/</link>
        <guid isPermaLink="true">https://risky.biz/video/demo-sublime-security-demos-its-agentic-ai-powered-email-security-platform/</guid>
        <description><![CDATA[
          
            In this sponsored product demo Sublime Security co-founder and CEO Josh Kamdjou joins Risky Business podcast host Patrick Gray to show off the company's email security platform, including its latest agentic AI bells and whistles.
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: How the US can win the cyber war</title>
        <pubDate>Mon, 22 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-how-the-us-can-win-the-cyber-war/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-how-the-us-can-win-the-cyber-war/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq look at a new Center for Strategic and International Studies report A Playbook for Winning the Cyber War


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: US investment in spyware skyrockets</title>
        <pubDate>Thu, 18 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-us-investment-in-spyware-skyrockets/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-us-investment-in-spyware-skyrockets/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about why it is good news that US investment in spyware vendors has skyrocketed.

They also discuss the in-principle agreement for TikTok to remain in the US. It's a win-win: a win for China and a win for TikTok, but not so much a win for US national security.
          
        ]]></description>
      </item>
    
      <item>
        <title>Demo: Vulnerability scanning and management with runZero</title>
        <pubDate>Thu, 18 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/demo-vulnerability-scanning-and-management-with-runzero/</link>
        <guid isPermaLink="true">https://risky.biz/video/demo-vulnerability-scanning-and-management-with-runzero/</guid>
        <description><![CDATA[
          
            In this product demo Patrick Gray hosts Ali Cheikh while he shows off how you can use runZero to scan for and manage vulnerabilities in your environment. 

Thanks to the recent integration of the Nuclei vulnerability scanner, runZero is no longer just an asset discovery tool.

Check out runZero at: [https://runzero.com](https://runzero.com)
          
        ]]></description>
      </item>
    
      <item>
        <title>Risky Business Weekly (807): Shai-Hulud npm worm wreaks old-school havoc</title>
        <pubDate>Wed, 17 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/risky-business-weekly-807-shai-hulud-npm-worm-wreaks-old-school-havoc/</link>
        <guid isPermaLink="true">https://risky.biz/video/risky-business-weekly-807-shai-hulud-npm-worm-wreaks-old-school-havoc/</guid>
        <description><![CDATA[
          
            On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

* Shai-Hulud worm propagates via npm and steals credentials
* Jaguar Land Rover attack may put smaller suppliers out of business
* Leaked data emerges from the vendor behind the Great Firewall of China
* Vastaamo hacker walks free while appeal is underway
* Why is a senator so mad about Kerberos?

This week's episode is sponsored by Knocknoc. Chief exec Adam Pointon joins to talk through the surprising number of customers that are using Knocknoc's identity-to-firewall glue to protect internal services and networks. ...
          
        ]]></description>
      </item>
    
      <item>
        <title>Soap Box: runZero shakes up vulnerability management</title>
        <pubDate>Mon, 15 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/soap-box-runzero-shakes-up-vulnerability-management/</link>
        <guid isPermaLink="true">https://risky.biz/video/soap-box-runzero-shakes-up-vulnerability-management/</guid>
        <description><![CDATA[
          
            In this sponsored Soap Box edition of the Risky Business podcast, industry legend HD Moore joins the show to talk about runZero's major push into vulnerability management.

With its new Nuclei integration, runZero is now able to get a very accurate picture of what's vulnerable in your environment, without spraying highly privileged credentials at attackers on your network. 

It can also integrate with your EDR platform, and other data sources, to give you powerful visibility into the true state of things on your network and in your cloud.
          
        ]]></description>
      </item>
    
      <item>
        <title>Between Two Nerds: The limits of cyber power</title>
        <pubDate>Mon, 15 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/between-two-nerds-the-limits-of-cyber-power/</link>
        <guid isPermaLink="true">https://risky.biz/video/between-two-nerds-the-limits-of-cyber-power/</guid>
        <description><![CDATA[
          
            In this edition of Between Two Nerds Tom Uren and The Grugq talk about the limits of a state's cyber power.   


          
        ]]></description>
      </item>
    
      <item>
        <title>Srsly Risky Biz: Exploiting authorisation sprawl is the new black</title>
        <pubDate>Thu, 11 Sep 2025 00:00:00 +1000</pubDate>
        <link>https://risky.biz/video/srsly-risky-biz-exploiting-authorisation-sprawl-is-the-new-black/</link>
        <guid isPermaLink="true">https://risky.biz/video/srsly-risky-biz-exploiting-authorisation-sprawl-is-the-new-black/</guid>
        <description><![CDATA[
          
            Tom Uren and Amberleigh Jack talk about the Salesloft Drift incident. It is a great example of the sprawling impact that the breach of a single service provider can have. We expect these single-compromise-large-blast-radius attacks will become the new norm.

They also talk about Apple's Memory Integrity Enforcement, which promises to be a big step forward for memory safety on Apple devices.
          
        ]]></description>
      </item>
    
  </channel>
</rss>
