Srsly Risky Biz: Army. Navy. Air Force. Cyber Force?

PLUS: UK's National Health Service gets its own cyber strategy

In this podcast Patrick Gray talks to Tom Uren about the a thought bubble floated by military cyber professionals that the US armed forces needs a US Cyber Force. The justification is a bit light on and Tom doesn’t really think the proposal makes sense.

They also discuss US Cyber Command’s “Hunt Forward” operations. In these operations partner countries invite CYBERCOM in to hunt for adversary activity. Access to networks is touchy stuff, though, so CYBERCOM spends a lot of time and effort in diplomatic efforts convincing potential partner agencies. We think these types of activities are great but in some parts of the world — think Asia — a warmer and fuzzier branding might be the go.

Risky Business #701 -- Why infosec is wrong about TikTok

PLUS: White House drops executive order on spyware...

NOTE: Patrick’s audio is a bit degraded in a few parts of this episode. It’s still clear enough, but if you hear some degradation in parts then yes, it’s us, not you.

On this week’s show Patrick Gray, Adam Boileau and Tom Uren discuss the week’s security news. They cover:

  • The Biden White House’s executive order on spyware
  • Why the infosec community writ large is wrong on TikTok
  • Clop campaign: it’s time to ditch your file transfer gateways
  • Major Android app booted from store because it was full of 0day privesc exploits lol
  • More detail on the BreachForums admin arrest
  • Much, much more

This week’s show is brought to you by runZero. HD Moore, co-founder of runZero, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick, Adam and Tom on Mastodon if that’s your thing.

Between Two Nerds: The Real Problem with TikTok

Many of the dangers of TikTok are overstated, but it is still a real problem...

In this edition of Between Two Nerds Tom Uren and The Grugq look at what the real problems with TikTok are. Many people are focussing on risks we think are irrelevant or overblown, but it is a massively influential app under Chinese Communist Party control.

Risky Biz News: BreachForums shuts down for good

PLUS: Kremlin staff told to dump their iPhones; Greece spied on Meta employee; cybersecurity spending to reach $219 billion this year.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #700 -- Yevgeny Prigozhin's empire gets owned

...and the details are incredible...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news in front of a live audience at AISA’s CyberCon in Canberra.

They cover:

  • Yevgeny Prigozhin’s entire enterprise got majorly owned
  • Kremlin bans iPhones among President’s staff
  • A look at those Android handset baseband bugs (woof)
  • A discussion of the acropalypse issue
  • Why you need to sort out your egress filtering in light of the latest Outlook bug
  • Shanna Daly joins us on stage to talk about why the infosec industry sucks
  • Plus much much more

This week’s show is sponsored by Stairwell. Mike Wiacek, Stairwell’s founder, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Between Two Nerds: The Balance between Offence and Defence

There are good reasons network defenders should be dominant... so why do attackers still succeed?

In this edition of Between Two Nerds Tom Uren and The Grugq look at the natural advantages that network defenders have. Despite this “home ground advantage” hackers still have a great deal of success and Tom and The Grugq look at what does work in favour of attackers.

Risky Biz News: Horror show 0days hit Samsung smartphones

PLUS: FBI investigates TikTok for spying on journalists; BreachForum admin arrested in the US; aCropalypse vulnerability can recover cropped and redacted screenshots.

Description: A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Srsly Risky Biz: The RESTRICT Act Is Not About TikTok

PLUS: When good laws meet bad governments...

In this podcast Patrick Gray talks to Tom Uren about the RESTRICT Act, proposed US legislation that tries to deal with the problems posed by technologies from foreign adversaries. RESTRICT gives the US government powers to deal with companies like Kaspersky, Huawei and now TikTok on an ongoing basis, rather than muddling through in an ad hoc way each time a problem company pops up. It also requires that the Secretary of Commerce come up with processes and procedures to deal with and mitigate these types of threats, rather than the current whack-a-mole approach.

They also discuss a draft Cambodian cyber security law and experts’ concerns that it could be abused by the Cambodian government to maintain its grip on power. This law has many similarities to Australian critical infrastructure law and Tom and Pat discuss the reasons behind the law in Australia. There’s a straight line between a serious ransomware incident in Australia and the resulting law, but still, Cambodia’s government remains authoritarian.

Finally, they look at a Carnegie report on Chinese manipulation of international standards setting organisations. It’s a good report and explains what is going on — Chinese manipulation does happen occasionally, but it is “largely unsuccessful”.

Risky Biz News: CISA establishes ransomware warning pilot program

PLUS: Euler Finance hacked for $197 million; the UK government creates new security agency to defend against state-sponsored threats; Patch Tuesday comes with three zero-day fixes.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Business #699 -- BYOD risks ramp up

Threat actors are really enjoying home networks and BYOD these days…

Threat actors are really enjoying home networks and BYOD these days…

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why our LastPass/DPRK hunch weakened
  • CISA launches ransomware warning program
  • Is the Ring data extortion real?
  • White House flags cloud service security regulation
  • Pig Butchering overtakes BEC as top cybercrime earner
  • Much more!

Between Two Nerds: Cyber Powers and Talent Pipelines

How different countries develop their cyber workforces...

In this edition of Between Two Nerds Tom Uren and The Grugq look at how different countries take different approaches to talent identification and recruitment. How much of a difference does it make? And why do countries have these different approaches?

Risky Biz Soap Box: Six degrees of Domain Admin

Why your Active Directory is a mess and how you can fix it with Bloodhound...

Today’s soap box is an absolute cracker. We’re talking to Andy Robbins, the principal product architect at SpecterOps and one of the three original creators of the original open source version of Bloodhound.

If you don’t know what Bloodhound is, it’s a tool that grabs Active Directory information and turns it into a navigable graph. So if you’re an attacker you land on a network, enumerate directory information, and then map out a path to domain admin.

Bloodhound has been extremely popular with red teamers for years – to the point that it’s just a standard tool in the red team toolkit. But the team behind Bloodhound is now turning their attention to making Bloodhound a defensive tool as well as an offensive tool.

Risky Biz News: Hackers steal data on US House members

PLUS: Google and Meta sue South Korea's privacy agency; Chinese hackers backdoor SonicWall devices; Google discontinues Chrome Cleanup Tool.

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Srsly Risky Biz: Grandpa Biden, Cyber President

PLUS: The iCloud backup from hell...

In this podcast Patrick Gray talks to Tom Uren about the recently released US National Cyber Security Strategy. Tom really likes it because it sets out how the US will “win” by reshaping who is liable when crapware hits the fan. It’s got other stuff in it too…

Tom and Pat also discuss the story of an MSS agent being busted when trying to steal intellectual property from the aviation industry. He used the same iphone for both his personal life and his spying and his iCloud backups were an intelligence bonanza. These backups not only had messages to potential recruits, they also had had audio of meetings he’d recorded where he was discussing his approach to espionage.

Finally, we talk about the security risks that arise from the use of Chinese ship-to-shore cranes at ports. Apparently these are chock full of sensors and could be spying on port logistics.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: