Podcasts

News, analysis and commentary

Sanctions abound, but the hacks keep coming

Presented by

Brett Winterford
Brett Winterford

In the same week the EU imposed sanctions against Russian, Chinese and North Korean actors, hacking crews from all three countries were implicated in new mischief.

Risky Biz Soap Box: Yubico Chief Solutions Officer Jerrod Chong

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Soap Box is the wholly sponsored podcast series we do here at Risky.Biz. That means everyone you hear on this podcast paid to be here. In this podcast you’re going to hear my latest interview with Jerrod Chong, Yubico’s Chief Solutions Officer.

Hardware security keys like Yubikeys have come a long way, even over the last couple of years. The biggest change is that the support for hardware keys is borderline ubiquitous now. FIDO2 support is in all the major browsers. You can even use Yubikeys with Google apps on an iPhone. The plumbing is here, it’s arrived.

Risky Biz Soap Box: Yubico Chief Solutions Officer Jerrod Chong
0:00 / 37:24

Risky Business #592 -- We're back. Did we miss anything?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • Two Chinese nationals charged with freelancing for MSS
  • Russia, China hacking COVID-19 research
  • The world dodged a bullet on the Windows DNS bug
  • Twitter blue tick pwnapalooza
  • Much, much more.
Risky Business #592 -- We're back. Did we miss anything?
0:00 / 66:12

Chinese campaign a sad indictment of infosec

Presented by

Brett Winterford
Brett Winterford

Who needs custom malware and 0day when wins come this easy?

The enterprise apps are revolting too

Presented by

Brett Winterford
Brett Winterford

If it’s any consolation, the most capable infosec teams in the world are having just as much trouble dealing with the current onslaught of high severity vulnerabilities as you are.

What even is Winnti?

Presented by

Daniel Gordon
Daniel Gordon

Winnti is all at once a malware family, a group, and several groups with wildly diverging motivations. We’re at the point where we may as well scrap the name and start again.

Risky Biz Soap Box: Facebook, under the hood

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Normally these Soap Box podcasts – which are wholly sponsored – feature vendors trying to sell you stuff. But this time we’re doing something different: an interview with two of Facebook’s most senior engineers.

Risky Biz Soap Box: Facebook, under the hood
0:00 / 49:25

Risky Business #591 -- EncroChat user experience includes getting owned, going to prison

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick and Adam discuss the week’s security news, including:

  • The latest on the EncroChat hack-related arrests
  • Details about the fresh F5 and Citrix bugs
  • Natanz go boom
  • Paying Wastedlocker ransoms violates Treasury sanctions
  • North Korea embraces Magecart (lol)
  • Much, much more…
Risky Business #591 -- EncroChat user experience includes getting owned, going to prison
0:00 / 56:20

The network devices are revolting

Presented by

Brett Winterford
Brett Winterford

A critical, trivially exploitable vulnerability in the management interface of F5’s Big-IP devices is the latest in a string of nasty bugs in networking equipment critical to enterprise computing.

Like last year’s Citrix NetScaler and Pulse Secure vulnerabilities, this one is going to hurt.

Risky Biz Soap Box: No magic wand for business email compromise (BEC)

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

This edition of the Soap Box podcast is brought to you by Proofpoint.

Today’s guest is Proofpoint’s EVP of Cybersecurity Strategy, Ryan Kalember, and the topic is business email compromise, or BEC.

BEC is a big deal, generating billions of dollars in losses every year across basically all industry verticals and levels of government. Until recently, there haven’t been many technical controls that help to mitigate it.

Risky Biz Soap Box: No magic wand for business email compromise (BEC)
0:00 / 44:37