Podcasts

News, analysis and commentary

Soap Box: Where does AI fit into cloud security?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

This episode is also available on Youtube.

Soap Box: Where does AI fit into cloud security?
0:00 / 33:37

Risky Bulletin: Shai-Hulud goes open-source

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The source code for the Shai-Hulud worm has been released online, a dark web market admin was charged after a major OPSEC failure, France investigates an Israeli disinfo firm, and ‘Composer’ rushes to fix a GitHub token leak.

Risky Bulletin: Shai-Hulud goes open-source
0:00 / 8:50

Srsly Risky Biz: The AI Regulation Knife Fight

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about the argy bargy within the Trump administration about AI regulation. They cover who is fighting, what is at stake and what the real areas of concern are.

They also cover low earth orbit satellite constellations. Russia’s building one, the EU has plans and China is building two. They are the new must-have accessory for any country with global ambitions.

This episode is also available on YouTube

Srsly Risky Biz: The AI Regulation Knife Fight
0:00 / 23:34

Risky Bulletin: Damaging worm rips through npm ecosystem

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and another major supply chain attack on npm (yawn).

Risky Bulletin: Damaging worm rips through npm ecosystem
0:00 / 7:49

Risky Business #837 -- GitHub Actions footgun claims TanStack

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • Mini Shai-Hulud and the TanStack compromise using Github Actions
  • Instructure pays Canvas elearning platform data extortionists
  • More Linux privilege escalation 0days!
  • CISA helping critical infrastructure operators rearchitect their networks so they work offline

This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.

Risky Business #837 -- GitHub Actions footgun claims TanStack
0:00 / 65:15

What a great agentic AI deployment plan looks like

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast James Wilson and Brad Arkin workshop the advice they think the industry needs to hear when it comes to deploying agentic AI in the enterprise.

Relegating agentic AI to non-sensitive and low-risk tasks doesn’t deliver value, and avoiding all risk stalls progress. James and Brad discuss the phases of AI adoption and contrast what a great plan looks like, versus an overly cautious one.

What a great agentic AI deployment plan looks like
0:00 / 39:59

Between Two Nerds: The AI-first crime gang

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss why it makes even more sense for criminal organisations to adopt AI as compared to regular businesses.

This episode is also available on YouTube.

Between Two Nerds: The AI-first crime gang
0:00 / 25:57

Risky Bulletin: FCC relaxes foreign router security patch ban

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The FCC relaxes its foreign router ban to allow for security updates, the ShinyHunters group disrupts schools across the globe, a 21-year-old remote code execution bug turns up in FreeBSD, and another Linux privilege escalation bug was disclosed… without a patch.

Risky Bulletin: FCC relaxes foreign router security patch ban
0:00 / 10:56

Sponsored: Knocknoc built a Greynoise integration

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored interview Patrick Gray chats with Knocknoc CEO Adam Pointon about their Greynoise integration.

Knocknoc allowlists network connections from users’ IPs after they’ve been through an SSO challenge. It’s great for protecting vulnerable or risky assets that your org has to connect to the internet. But what happens when one of your users tries to authenticate from a bad IP? You probably don’t want to add that one to your allowlist!

Thanks to Knocknoc’s new Greynoise integration, you don’t have to!

Sponsored: Knocknoc built a Greynoise integration
0:00 / 10:22

Mythos smythos! How to find 0day with lesser models

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast James Wilson chats with Niels Provos about his research into using older AI models to successfully hunt for 0day vulnerabilities. Niels has had a long and prolific career in cybersecurity, having worked as a Distinguished Engineer at Google and then heading up security at Stripe.

His interest in AI bug hunting was piqued recently when one of the Mythos 0day vulnerabilities that received lots of attention happened to be in code he wrote for the OpenBSD project 27 years ago.

It got him thinking: Are these frontier models really that magical? Or could we replicate their findings with some clever orchestration instead of relying on the model’s smarts to find bugs with a single prompt?

As it turns out, this was worth looking into. Niels’ orchestration framework, Iron Curtain, works extremely well.

This episode is also available on YouTube

Mythos smythos! How to find 0day with lesser models
0:00 / 87:53