Podcasts

News, analysis and commentary

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Microsoft ends support for SMS MFA on personal accounts, GitHub was hacked via a malicious VS Code extension, CISA will let researchers submit new KEV entries, and an SMS blaster was detained at Eurovision.

Risky Bulletin: Microsoft ends SMS MFA for personal accounts
0:00 / 9:00

How the CopyFail disclosure went sideways

Presented by

James Wilson
James Wilson

Technology Editor

In this episode, Theori’s Brian Pak and Andrew Wesie join James Wilson to discuss why the CopyFail exploit was publicly disclosed before Linux distributions had their patches ready. As you’ll hear in this episode, mistakes were made and lessons learned. It’s worth a podcast, too, because in our opinion this incident foreshadows the inevitable problems that open source software will face in the unfolding vulnpocalypse.

How the CopyFail disclosure went sideways
0:00 / 18:56

Srsly Risky Biz: Politicians ditch Signal for homegrown apps

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about moves from several European governments to ditch Signal and set up their own encrypted messaging systems for internal government use. These efforts are motivated by concerns about phishing and sovereignty, but the solutions being adopted are imperfect and will come with their own set of problems. Signal fills a space that can’t be filled with sovereign capability.

They also talk about Fast16 malware. We are only now learning about the second arm of a mid-2000s campaign to delay Iran’s nuclear weapons program that included the infamous Stuxnet worm.

This episode is also available on YouTube

Srsly Risky Biz: Politicians ditch Signal for homegrown apps
0:00 / 28:45

Risky Business #838 -- GitHub investigates possible breach

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • GitHub announced a possible breach
  • CISA leaks important creds, keys in public repo
  • Awful vulnerability in Bitlocker renders it useless without a PIN
  • So. Many. Patches.
  • Polish Government urges officials to ditch Signal for mSzyfr
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy.

This episode is also available on YouTube.

Risky Business #838 -- GitHub investigates possible breach
0:00 / 62:49

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Microsoft disrupts a malware-signing service used by ransomware gangs, a CISA contractor leaks sensitive GovCloud keys, vulnerability exploitation is now the dominant network entry vector, and Drupal readies security updates for a “highly critical” vulnerability.

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs
0:00 / 8:50

Between Two Nerds: Russia's hacker university

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russia’s cyber program and look at what Western intelligence agencies do instead.

This episode is also available on YouTube.

Between Two Nerds: Russia's hacker university
0:00 / 29:22

NCSC’s Ollie Whitehouse on surviving the "bugpocalypse"

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of Risky Business Features Ollie Whitehouse, the CTO of the UK’s National Cyber Security Centre, joins Patrick Gray and James Wilson to talk about why “patch faster” will only get organisations so far in the face of the AI “bugpocalypse”.

As Ollie explains, organisations will need to reduce internet-facing attack surface and make better architecture decisions as 0day discovery speeds up.

This episode is also available on YouTube.

NCSC’s Ollie Whitehouse on surviving the "bugpocalypse"
0:00 / 29:25

Risky Bulletin: Indonesia emerges as a new hub for cyber scams

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Indonesia emerges as a new cyber scam hub, Grafana got hacked and held for ransom, the Fast16 malware subverted software used to simulate nuclear explosions, and a new Microsoft Exchange zero-day is under attack.

Risky Bulletin: Indonesia emerges as a new hub for cyber scams
0:00 / 10:10

Sponsored: Push Security goes AI threat hunting in browser telemetry

Presented by

James Wilson
James Wilson

Technology Editor

In this sponsored interview James Wilson chats with Push Security’s Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform.

Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers.

Sponsored: Push Security goes AI threat hunting in browser telemetry
0:00 / 14:01

Soap Box: Where does AI fit into cloud security?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

This episode is also available on Youtube.

Soap Box: Where does AI fit into cloud security?
0:00 / 33:37