Snake Oilers: Sublime Security, VulnCheck and Devicie

Tune your email detections, get vuln intel and manage your devices!

In this edition of Snake Oilers you’ll hear product pitches from:

  • Sublime Security: e-mail security for people who want to tune their detections
  • VulnCheck: Provides vulnerability intelligence to governments, large enterprises and vendors
  • Devicie: Manage your devices with Intune without pulling your hair out

Risky Business #722 -- Microsoft embraces Zero Trust... Authentication?

How Redmond leaked 38TB with a bad URL...

On this week’s show Patrick Gray, Adam Boileau and Lina Lau discuss the week’s security news. They cover:

  • Microsoft’s 38TB oopsie
  • MGM’s Okta compromised, was this what Okta was warning us about?
  • Why we need a cyber knife fight
  • Google Authenticator sync abused in the wild
  • Much, much more

This week’s show is brought to you by Push Security. Co-founder Adam Bateman is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: North Korea steals $54 million from CoinEx

PLUS: US wants governments to commit to not paying ransoms; Caesars paid a $15 million ransom; and Meduza's publisher infected with Pegasus spyware.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: Microsoft's security culture sucks

PLUS: The UK govt will cooperate with... itself?

In this edition of Seriously Risky Biz guest host Adam Boileau talks with Tom Uren about what Microsoft’s recent breach by a Chinese-based threat actor tells us about the company’s security culture. There were several serious governance failures that allowed this incident to happen.

They also look at a new UK government effort to reassure companies that they won’t be punished (as much) for seeking help from the NCSC.

Risky Biz News: Won't someone think of the... casinos?!

MGM Resorts downed in cyber incident; Adobe, Google, Mozilla, and Microsoft patch zero-days; and Microsoft Teams is spreading ransomware.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Risky Business #721 -- Why Storm-0558's Microsoft hack should have failed

It was great hacking, but it just shouldn't have worked...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • How Storm-0558 stole Microsoft’s signing key
  • Cisco 0day being used by ransomware crews
  • We were right about Elon stumbling into the Ukraine war
  • Someone’s amazing image library 0day just got crushed
  • Much, much more!

This week’s show is brought to you by Nucleus Security. Co-founder Scott Kuffer is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Sponsored: Red Canary's Gerry Johansen on IR readiness

IR drills and tabletops are just as important as IR playbooks...

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Red Canary Principal Readiness Engineer Gerry Johansen about the need to prepare IR plans in advance and why that’s just as important as the IR playbook itself.

Risky Biz News: Ransomware gangs using Cisco 0day

PLUS: FBI links Stake crypto-heist to North Korea; Ukrainian hacktivists unmask Russia's Cuban mercenary recruiting scheme.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Snake Oilers: ConductorOne, Bloodhound Enterprise and Zero Networks

Three vendors fighting the good fight...

In this edition of Snake Oilers you’ll hear product pitches from:

  • ConductorOne: PAM, account cycle management and access auditing for cloud and SaaS accounts
  • Bloodhound Enterprise: Enumerate attack paths in your environment and shut them down
  • Zero Networks: Agentless: heavily automated microsegmentation and a VPN product that won’t get you insta-owned

Risky Biz News: Microsoft explains how it lost its signing key

PLUS: Apple patches zero-days used to install NSO’s Pegasus spyware; China bans iPhones for government work; and US and UK dox and sanction 11 more Trickbot/Conti members

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: Why "pig butchering" is even worse than you think

A new UN report lays out the human trafficking nexus...

In this podcast Patrick Gray and Tom Uren talk about a new UN report that says that hundreds of thousands of innocent people are being forced into working in online crypto and romance scams.

They also look at new age verification laws that aim to make it more difficult for children to see pornography. It’s a complex topic, but Australia’s eSafety office has done excellent work on it.

Risky Biz News: China cracks down on Southeast Asian scam call centers

PLUS: MinIO servers exploited to breach cloud infrastructure; Paraguay's National Police hacked; crypto-gambling site Stake loses $41 million in crypto-heist.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Risky Business #720 -- How cloud identity provider federation features can get you mega-owned

The attacks against Okta customers aren't actually novel and you should understand them...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Why everyone should pay attention to some recent attacks on Okta customers
  • Why third party comms apps are risky af
  • Why are Russian espionage opps using Tor for C2?
  • Surveillance firms abuse Fiji Telco Digicel’s SS7 access
  • Much, much more!

This week’s show is brought to you by Gigamon. Mark Jow, Gigamon’s EMEA Technical Director is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: Okta Super Administrator accounts targeted

PLUS: LogicMonitor customers get ransomwared; NIST publishes CI/CD security framework; and Microsoft retires WordPad.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: The UK snoopers' charter won't stop security patches

PLUS: A detailed look at China's Barracuda campaign…

In this podcast Patrick Gray and Tom Uren about proposed changes to the UK’s Investigatory Powers Act. Some pundits are saying the changes will clear the way for the government to prevent tech companies from rolling out security patches. They’re wrong.

They also look at a new Mandiant report that dives deeper into a recent Chinese group’s campaign that compromised Barracuda Email Security Gateways. The report provides a wonderful overview of the campaign.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: