Risky Business #716 -- This ain't your grandma's cloud

How complexity is biting Azure on its big, blue ass...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Tenable gives Microsoft a spray over Azure bug fix delay, quality
  • Lateral movement fun via Azure Active Directory Cross-Tenant Synchronization
  • Ransomware targets hospitals, special needs schools
  • Japan’s cybersecurity has some catching up to do
  • Much, much more

This week’s show is brought to you by Corelight. Brian Dye, Corelight’s CEO, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: Sandworm hackers target Ukraine's military systems

PLUS: DHS links pro-PRC info-op to Chinese municipal government; Russia cracks down on "gray" SIM cards; and Curve Finance hacker returns most of the stolen funds.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Sponsored: Tines CEO Eoin Hinchy on burnout in SOC teams

It's a real thing...

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Tines co-founder and CEO Eoin Hinchy about how organisations can maximise the potential of their security teams during an economic downturn, with a concentration on why human error and burnout caused by excessive workloads on security teams can be a risk.

Risky Biz News: Microsoft botches Azure bug fix

PLUS: Salesforce zero-day abused in Facebook phishing campaigns; and a Tesla jailbreak revealed at BlackHat.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.

You can find the newsletter version of this podcast here.

Srsly Risky Biz: On Microsoft, Wyden's Bark May Have Some Bite

PLUS: Slamming the FBI's back door shut with 702 reform...

In this podcast Patrick Gray and Tom Uren talk about how Microsoft’s lackadaisical cloud product security is attracting the ire of important politicians.

They also examine a presidential advisory board report into Section 702 collection and discuss why oversight in intelligence collection is important.

Risky Business #715 -- Pressure mounts on Microsoft to explain itself

Y U NO HSM, MS? Y?

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Ron Wyden’s “please explain” letter to Microsoft
  • Chinese APT crews prepositioning to disrupt US military logistics
  • China claims US hacked its seismology sensors
  • Ivanti/MobileIron exploitation going vertical
  • Much, much more

This week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO, is this week’s sponsor guest. He’s joined by Eric Foster, Stairwell’s VP of Business Development.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: SEC adopts new cybersecurity rules

PLUS: Former Group-IB CEO gets 14 years in prison for treason; 41 zero-days exploited in the wild last year; and new DDoS attack types spotted.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Feature interview: Australia's Cyber Security Minister Clare O'Neil

Clare O'Neil and Ciaran Martin talk to Patrick Gray about cyber strategy and releasing the hounds…

In this interview Patrick Gray speaks to Australia’s Home Affairs and Cyber Security Minister Clare O’Neil and NCSC founding director Ciaran Martin about the government’s upcoming cybersecurity strategy, releasing the hounds and more.

Srsly Risky Biz: In Beijing, the Fourth Amendment is Still For Sale

PLUS: Ransomware is up, down and sideways...

In this podcast Patrick Gray and Tom Uren talk about draft US legislation that aims to stop law enforcement from circumventing the Fourth Amendment by simply buying data on US citizens. It’s a good move, but the overall data ecosystem needs broader reform.

They also discuss new reports into the ransomware ecosystem. There is both good news and bad news, but data gaps still make it difficult for policymakers to have a good handle on how to respond.

Risky Biz News: Norwegian government hacked with MobileIron zero-day

PLUS: TETRA encrypted radio traffic can be decrypted; Apple patches another Triangulation zero-day; and the Zenbleed vulnerability leaks passwords and encryption keys from AMD Zen CPUs.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.

Risky Business #714 -- Microsoft vs Wiz: pistols at dawn

They're both wrong, but it's fun to watch...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The dust-up between Microsoft and Wiz
  • MobileIron/Ivanti 0day hoses Norwegian government agencies
  • That’ll do TETRA, that’ll do…
  • Microsoft finally agrees to offer decent logging without price gouging
  • Much, much more

This week’s show is brought to you by Resoucely. Travis McPeak, Resourcely’s co-founder and CEO, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Biz News: Ransomware victims stop paying up

PLUS: Tens of thousands of Citrix devices still unpatched against recent zero-day; and Target reveals its EasySweep card skimmer detector.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast here.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: