Podcasts

News, analysis and commentary

Hunting software supply chain malware

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious packages, GitHub repositories and developer tools.

Paul walks James through static analysis, deobfuscation and reconstructing multi-stage kill chains to identify what attackers are trying to steal. They also discuss how LLMs make malware development easier while introducing operational security mistakes.

The pair examine DPRK tradecraft, blockchain-based payload delivery and what Paul calls Pollen Rider, which can reinfect developers through their own repositories.

Hunting software supply chain malware
0:00 / 75:04

Risky Bulletin: Anthropic agents went hacking again

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.

Risky Bulletin: Anthropic agents went hacking again
0:00 / 10:20

Snake Oilers: watchTowr, XBOW and CoreView

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

  • watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do?
  • XBOW: The AI pentesting company pitches its approach
  • CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView!

This episode is also available on YouTube.

Snake Oilers: watchTowr, XBOW and CoreView
0:00 / 42:00

Srsly Risky Biz: America's drivers licence breach is a national security disaster

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.

They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough.

Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy.

This episode is also available on YouTube

Srsly Risky Biz: America's drivers licence breach is a national security disaster
0:00 / 24:44

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
0:00 / 7:58

Risky Business #852 -- Cyber Command wants to buy shells

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:

  • ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits
  • The US government plans to pay private contractors to conduct military hacks
  • The US accuses China of distillation attacks, a.k.a. forbidden training
  • It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki
  • Much, much more…

This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace.

This episode is also available on YouTube

Risky Business #852 -- Cyber Command wants to buy shells
0:00 / 63:29

Between Two Nerds: Can AI defend critical infrastructure?

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line.

This episode is also available on YouTube.

Between Two Nerds: Can AI defend critical infrastructure?
0:00 / 27:26

Risky Bulletin: BEC campaign steals €35 million from French notaries

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.

Risky Bulletin: BEC campaign steals €35 million from French notaries
0:00 / 8:27

Sponsored: Authentik is rethinking PAM for AI agents

Presented by

James Wilson
James Wilson

Technology Editor

In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.

Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human.

They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access.

Sponsored: Authentik is rethinking PAM for AI agents
0:00 / 20:05

Risky Bulletin: Russia tells data centers to deploy drone defenses

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs.

Risky Bulletin: Russia tells data centers to deploy drone defenses
0:00 / 10:04