Risky Business #692 -- Google search results spew malware, phishing sites

The search giant's ads and organic results have become dangerous...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Google’s search results have become a malware-riddled sh*tshow
  • Ransomware payment values dropped by 40% YoY in 2022
  • Kraken takes over Solaris the old school way
  • Grand Theft Auto RCE is wreaking havoc
  • ManageEngine customers are all getting owned
  • So you know, pretty much business as usual

This week’s show is brought to you by Kroll.

Jim Hung co-leads the special projects and applied research team at Kroll and joins us to talk about the big changes happening in the incident response discipline.

Between Two Nerds: When Operations Get Burnt

How do adversaries deal with operational failure and why do they make the choices they do?

In this edition of Between Two Nerds Tom Uren and The Grugq look at operations being ‘burnt’ from the adversary’s point of view. What do they do when an operation is burnt? What are the factors that go into the decisions that they make?

Srsly Risky Biz: LockBit ripe for disruption, Russians throw kitchen sink at Ukraine

PLUS: French general sounds alarm on US hunt forward operations...

In this podcast Patrick Gray talks to Tom Uren about security researcher Jon DiMaggio infiltrating the LockBit ransomware group. DiMaggio’s report shows that there are numerous disruption operations.

They also cover a new Ukrainian report about Russia’s combined cyber, conventional and military operations. It doesn’t look like the Russians are deftly coordinating these different attacks to maximum effect so much as using a kitchen sink approach.

Finally, they look at a French general’s warning to other European countries that the US might use Cyber Command hunt forward operations as an intelligence gathering operation. We don’t think this is at all likely, but the general has hit on a fear that other countries will have.

Risky Business #691 -- LockBit and "Pablo Escobar syndrome"

Why LockBit's Royal Mail caper could backfire…

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Royal Mail attack was LockBit and GCHQ will probably “bust some heads”
  • CircleCI’s incident report and the problem with malwared endpoints in the Zero Trust age
  • Cloudflare backs Mastodon
  • Paul Nakasone: NSA did some great stuff! It was really good!
  • Cisco won’t patch SMB routers sold in 2020
  • Much, much more

This week’s show is brought to you by Material Security. Material co-founder Ryan Noon and Snowflake’s head of cybersecurity strategy Omer Singer are this week’s sponsor guests.

Risky Biz News: Pro-Russian hacktivists offer cryptocurrency for DDoS attacks against Ukraine and western targets

PLUS: Bangladesh government bought loads of Israeli surveillance tools; npm libraries delete user files; malware found preinstalled on T95 Android TV boxes...

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Srsly Risky Biz: Carnegie Report Takes Wind Out of Cyber War's Sails

PLUS: The Bad Times Keep Rolling for NSO Group...

In this podcast Patrick Gray talks to Tom Uren about a new Carnegie report that does a really good job examining the interplay of disruptive cyber operations and conventional military action in Russia’s invasion of Ukraine.

They also examine the trajectory of NSO Group. The US Supreme Court has decided that WhatsApp’s court case against the firm can continue, but the political environment has changed so drastically we don’t think the court case will make much difference in the end.

Risky Biz News: Windows 7 reaches end-of-support

PLUS: SugarCRM zero-day used to compromise roughly 10% of all internet-accessible servers; smart ship management platform taken down after hack; Raspberry Robin botnet loses 30% of C2 servers in partial takedown.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #690 -- 2023 will be a rough year for critical online services

Recent attacks against Okta, CircleCI, Slack and Lastpass have set the tone for the year ahead...

On this week’s show Patrick Gray and Adam Boileau discuss the news we missed while on break. Because it’s the first show of the year, we split the discussion into themes:

  • Attacks against critical online services like Okta, CircleCI, Slack and Lastpass will increase in volume
  • All the latest global intrigue, from NSO being noped by the US Supreme Court to DDoS attacks in Serbia, Turla’s latest campaign, supply chain attacks against Ukraine, why Russia has been more active than we realised and much more
  • A ransomware wrap, a discussion about the rise of data extortion and why it’s unlikely to remain a huge problem
  • Why automotive security research will actually be interesting this year
  • PLUS: A bunch of random news!

This week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he joins us to talk about something they’ve developed – a zero knowledge proof of exploit technique. Very interesting stuff!

Srsly Risky Biz: The Access Debate is Now the Child Safety Debate

Our last podcast for 2022... see you all next year!

In this podcast Patrick Gray talks to Tom Uren about Apple’s latest move to roll out end-to-end encrypted iCloud backups and how that plays into the lawful access debate. Pending legislation in the US, UK and EU is all about mitigating online harms and countering child exploitation, so they think the policy debate has moved on from lawful access. There are lots of measures that companies could take in this space that don’t compromise end-to-end encryption, and legislators are going to force companies to do more. They also look at the next move for North Korean hackers. They’ve had an absolute field day pillaging cryptocurrency ventures. What will their next move be as the “Crypto Winter” arrives?

You can find the newsletter post this podcast is based on here.

Risky Business #689 -- FBI baulks at Apple's iCloud encryption push

PLUS: Microsoft signs malicious drivers, Japan to release the Shiba Inus…

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Apple to introduce user-encrypted backups, FBI is sad
  • Twitter ices e2ee plans for DMs
  • RackSpace is getting sued over its hosted Exchange ransomware incident
  • Dodgy driving: Microsoft signs some shady stuff
  • Japan to change laws, release the Shibas
  • A look at the US NDAA
  • Much, much more

This week’s show is sponsored by Obsidian Security. Obsidian co-founder Ben Johnson joins the show this week to talk through SaaS configuration security and visibility/monitoring.

Between Two Nerds: The US has it all wrong on cyber

How the "Cyber Grand Strategy" makes sense for everyone, except America...

In this edition of Between Two Nerds Tom Uren and The Grugq find that for most countries use of cyber capabilities makes sense. Except for the US. They are in a different position and the development of cyberspace as a domain of strategic competition is a net loss for them.

Risky Biz News: Disgruntled member doxes and extorts URSNIF gang

PLUS: PyPI and npm packages deploy ransomware; Japan wants to carry out preemptive cyber-attacks; Pwn2Own Toronto hacking contest results...

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and presented by Patrick Gray, who’s filling in for Claire Aird.

You can find the newsletter version of this podcast click here.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: