Risky Biz News: Greece tries to downplay its spyware scandal

PLUS: Cuba ransomware gang claims Montenegro attack; hacktivists release Lukashenko's passport scan as NFT; and Google launches bug bounty program for its FOSS projects.

A short podcast updating listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Risky Business #676 -- Okta, Authy users among Twilio hack targets

There's a one time password supply chain, and it got owned pretty hard...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The Twilio breach was actually a big deal
  • How a Belarusian Cyber Partisans hack burned a GRU illegal
  • Who wants 25m hashed passwords from Russia?
  • An NFT we can get behind
  • How attackers are using game anti-cheat drivers to defeat EDR
  • Much, much more

This week’s sponsor interview is with Mike Benjamin, the VP of security research at Fastly. He pops in to argue that your red team needs to actually consider how your apps will cope with bot-driven attacks.

Risky Biz News: Cybercrime groups got bored of RU/UA hacktivism

PLUS: In other news: Authy users affected by Twilio hack; Tykelab linked to SS7 attacks; and Moldova, Montenegro, and Slovenia deal with cyber-attacks.

A short podcast updating listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Risky Business #675 -- The problem with Mudge's whistleblowing complaint

Twitter's security is a trashfire, but Mudge's complaint has issues...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A deep look at Mudge’s sensational whistleblower complaint against Twitter
  • Brazilian Federal Police raid Lapsus$ crew
  • NSO CEO to stand down (again), 100 staff to be let go
  • Signal users impacted in Twilio incident
  • Tornado Cash OFACs around and finds out
  • Much, much more

This week’s show is brought to you by Greynoise. Its founder, Andrew Morris, joins the show with a stinging critique of the wider threat intelligence industry. Don’t miss that one.

RBTALKS3: Vitali Kremez on the impending downfall of the RaaS ecosystem

PLUS: Ransomware gangs are slowly moving to corporate hack-steal-extort-or-leak schemes, with no encryption involved.

Vitali Kremez, CEO of Advanced Intelligence, talks to Risky Business about the impending downfall of the Ransomware-as-a-Service ecosystem, as major ransomware gangs are slowly moving to corporate hack-steal-extort-or-leak schemes, with no encryption involved.

Risky Biz News: Bitcoin ATMs hacked

PLUS: VIASAT hack impacted French emergency services; LockBit gang gets DDOSed; and NSO CEO resigns (again).

A short podcast updating listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Risky Biz News: CyberCom faces staffing issues

PLUS: Estonia reports record DDoS attacks; Brazil police conduct raids in Lapsus$ investigation; and Ryuk money launderer arrested.

A short podcast updating listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Risky Biz Soap Box: Okta's Brett Winterford on session cookie theft and mitigations

PLUS: Why "continuous authentication" isn't just an empty marketing phrase…

In this edition of the Soap Box podcast Okta’s APAC CISO and former Risky Biz editor Brett Winterford talks about how attackers are getting much better at swiping session cookies via realtime phishing and malware.

He also talks about some mitigation strategies to combat this threat and introduces the concept of continuous authentication.

Risky Biz News: FIRST releases TLP v2.0

PLUS: Hacktivists leak LatAm mining data; GitHub users attacked with phony repos; and academics find new eavesdropping method via fiber optics cables.

A short podcast updating listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Risky Business #674 -- "Free money" exploit spawns $150m blockchain feeding frenzy

It's the modern equivalent of the townsfolk raiding the crashed armoured car...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Taiwan tensions fail to conjure the cyber apocalypse
  • Crypto bridge exploit results in $150m feeding frenzy
  • Chainalysis evidence to be challenged in court
  • Post-quantum NIST candidate algorithm gets smoked
  • DSIRF’s Russia links
  • Much, much more

This week’s sponsor interview is with Jerrod Chong from Yubico. He’s joining the show to talk about why consumer-focussed implementations of Webauthn like Apple’s Passkeys aren’t a great enterprise solution.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: