Podcasts

News, analysis and commentary

Risky Bulletin: Russia's Signal phishing nets thousands of accounts

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Russian intelligence services compromised thousands of Signal accounts, the Trivy vulnerability scanner is abused in a supply chain attack, Oracle issues an out-of-band patch for its Fusion Middleware, and the FBI takes down the Aisuru and Kimwolf botnets.

Risky Bulletin: Russia's Signal phishing nets thousands of accounts
0:00 / 7:01

When disaster strykes

Presented by

James Wilson
James Wilson

Enterprise Technology Editor

In this episode of Risky Business Features, James Wilson and Brad Arkin discuss the attack that devastated medtech company Stryker. It turns out the attackers used Microsoft’s inTune to wipe the company’s devices, but what else could they have weaponised?

This podcast basically turned into an incident review of the Stryker incident. Enjoy!

When disaster strykes
0:00 / 40:00

Sponsored: What is Extended Identity Access Management?

Presented by

Casey Ellis
Casey Ellis

Founder, Bugcrowd

In this Risky Business sponsored interview, Casey Ellis chats to Fletcher Heisler, founder and CEO of open source identity provider, Authentik. They chat about Extended Identity Access Management (XIAM), the company’s new acronym that has been seven years in the making.

Sponsored: What is Extended Identity Access Management?
0:00 / 10:39

Risky Bulletin: Second iOS hacking framework found in the wild

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A second iOS hacking framework has been found in the wild, Belgium launches its own government communications app, AWS kills S3 bucketsquatting and a cyberattack cripples car breathalyzers.

Risky Bulletin: Second iOS hacking framework found in the wild
0:00 / 7:01

Srsly Risky Biz: Successful war leaves Iran with one option, its cyber forces

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Amberleigh Jack talk about how successfully achieving America’s war goals could force Iran to double down on cyber power. It’s resilient to bombing and is the cheapest, quickest way for the regime to get some wins post-war.

They also discuss Meta stepping back from end-to-end encryption on Instagram’s direct messages. There is a time and place for E2EE messages, so good riddance.

Finally, they discuss the one weird trick President Trump uses to make his smartphone conversations useless for foreign intelligence services.

This episode is also available on Youtube.

Srsly Risky Biz: Successful war leaves Iran with one option, its cyber forces
0:00 / 19:11

MCP is Dead

Presented by

James Wilson
James Wilson

Enterprise Technology Editor

James Wilson delivers his take on the state of the Model Context Protocol (MCP) in this solo episode of Risky Business Features. Despite MCP being the technology that made Large Language Models useful and AI Agents possible, the models have shown us they want to use something else instead. They want to use the shell directly, and that is going to have serious cybersecurity consequences.

MCP is Dead
0:00 / 36:42

Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat

Presented by

James Wilson
James Wilson

Enterprise Technology Editor

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They discuss:

  • Iran’s Intune-based wiper attack on medical device maker Stryker
  • Qihoo 360’s AI publishes its own wildcard TLS cert private key
  • Instagram is canning its end-to-end encrypted messaging
  • What’s going on with mobile internet access in Moscow?
  • The Xbox One’s bootloader gets voltage glitched into submission
  • Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt files…)

This week’s episode is sponsored by browser-based detection and response company, Push Security. Researcher Dan Green and Field CTO Mark Orlando join Pat to talk through the InstallFix variant of the *Fix attack technique.

This episode is also available on Youtube.

Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat
0:00 / 63:45

Risky Bulletin: EU finally imposes more cyber sanctions

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The EU imposes cyber sanctions, an Iranian cyber chief was killed by US-Israeli strikes, the UK fixes a major bug in its company registry, and a US man phishes celebrity athletes while on home detention… for phishing.

Risky Bulletin: EU finally imposes more cyber sanctions
0:00 / 6:27

Between Two Nerds: Unleashing Iran's hackers

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss how bombing Iran changes incentives for Iranian hacker groups. Destroying other ways that Iran might project power could force it to double down on cyber capabilities.

This episode is also available on Youtube.

Between Two Nerds: Unleashing Iran's hackers
0:00 / 27:41

Risky Bulletin: Meta disrupts Mexican cartels

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Meta suspends Mexican cartel accounts, multiple vulnerabilities have been found in Linux AppArmour, Instagram will disable support for end-to-end encrypted messaging and a supply chain attack hits AppsFlyer.

Risky Bulletin: Meta disrupts Mexican cartels
0:00 / 6:12