Podcasts

News, analysis and commentary

Risky Bulletin: US will let private companies carry out offensive cyber ops

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.

Risky Bulletin: US will let private companies carry out offensive cyber ops
0:00 / 11:07

Soap Box: Zero Trust(ish) Networks

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.

Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.

Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.

Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.

This episode is also available on YouTube

Soap Box: Zero Trust(ish) Networks
0:00 / 29:04

Srsly Risky Biz: Data extortion is booming. Hooray!

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.

They also discuss how the rise of AI makes it worth reinvigorating CISA’s Secure by Design initiative.

Srsly Risky Biz: Data extortion is booming. Hooray!
0:00 / 30:48

Risky Business #848 -- OpenAI comes clean

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

  • The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
  • Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
  • More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
  • It turns out TeamPCP has been around longer than we thought and predates the AI era
  • Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
  • Much, much more

This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.

This episode is also available on YouTube

Risky Business #848 -- OpenAI comes clean
0:00 / 59:47

Risky Bulletin: Russian hackers jump on the fake job interview train

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Russian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams.

Risky Bulletin: Russian hackers jump on the fake job interview train
0:00 / 9:12

Between Two Nerds: The cyber resistance!

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals.

This epsiode is also available on YouTube.

Between Two Nerds: The cyber resistance!
0:00 / 29:53

Risky Bulletin: Two law firms pay giant ransoms

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Two American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!

Risky Bulletin: Two law firms pay giant ransoms
0:00 / 8:26

Sponsored: Island's expansion to SASE and enterprise AI

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI.

Sponsored: Island's expansion to SASE and enterprise AI
0:00 / 16:59

How private LLM inference actually works

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without the inference provider seeing your prompts.

Tanya talks James through how private inference works, from trusted execution environments and hardware attestation, to TLS termination and GPU isolation. Customers can verify the exact code and model processing their data, while Tinfoil and its infrastructure providers remain locked out.

That’s clever engineering… but who really needs it? Is private inference only useful if you’re doing something bad, or will it become a privacy baseline like TLS? James and Tanya discuss the costs and trade-offs, and how open weights make private inference more transparent and trustworthy.

How private LLM inference actually works
0:00 / 83:49

Risky Bulletin: A Meta AI model also escaped a testing sandbox

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A Meta AI model also escaped a testing sandbox, a cyberattack disrupts ports in North Carolina, the Philippines will establish a cybersecurity agency, and a Ransom Cartel admin gets 16 years in prison.

Risky Bulletin: A Meta AI model also escaped a testing sandbox
0:00 / 7:07