Podcasts

News, analysis and commentary

Risky Bulletin: Windows Update will patch third party apps

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Windows Update will deliver third party app updates, a public database exposed Russia’s nuclear secrets, US banks ask the SEC to rescind cyber breach disclosure rule, and ConnectWise discloses an APT breach.

Risky Bulletin: Windows Update will patch third party apps
0:00 / 6:05

Srsly Risky Biz: Russia's cybercriminals and spies are officially in cahoots

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about Russian DanaBot malware developers making a tailored variant of their malware specifically for espionage. This fills in some of the blanks on the exact relationship between Russian criminals and the country’s intelligence services.

They also discuss a US Director of National Intelligence initiative to centralise the purchase of commercially acquired information. Although this information can be used maliciously, having a one-stop-shop should make it easier to check that it is being used responsibly.

This episode is also available on Youtube.

Srsly Risky Biz: Russia's cybercriminals and spies are officially in cahoots
0:00 / 16:27

Risky Business #793 -- Scattered Spider is hijacking MX records

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the week’s news, including:

  • EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes
  • The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed
  • Brian Krebs eats a 6.3Tbps DDoS … ‘cause that’s how you demo your packet cannon
  • Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers
  • Iranian behind 2019 Baltimore ransomware mysteriously appears in North Carolina and pleads guilty
  • CISA’s leadership is fleeing in droves, even though the US needs them more than ever.

This week’s episode is sponsored by Thinkst Canary. Long time friend of the show Haroon Meer joins and talks through where he feels the industry is at, having just returned home from the AI-fueled hype at this year’s RSA conference.

This episode is also available on Youtube.

Risky Business #793 -- Scattered Spider is hijacking MX records
0:00 / 64:52

Risky Bulletin: Dutch intelligence discovers a new Russian APT

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Dutch intelligence discovers a new Russian APT, a ransomware attack hits the maker of MATLAB, 20 arrested in Nigeria over hacking exam results, and an Iranian pleads guilty for the Robbinhood ransomware attacks.

Risky Bulletin: Dutch intelligence discovers a new Russian APT
0:00 / 5:27

Between Two Nerds: Cyber's hard problems

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about cyber’s ‘hard problems’ and why they are intractable.

This episode is also available on Youtube.

Between Two Nerds: Cyber's hard problems
0:00 / 26:19

Risky Bulletin: Major CISA leadership exodus underway

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A major exodus of leadership is underway at CISA, the US government will audit NIST over its vulnerability backlog; an ancient and mysterious APT has been linked to Spain’s government, and the SVG image format is great for phishing.

Risky Bulletin: Major CISA leadership exodus underway
0:00 / 4:51

Sponsored: Sublime Security on the spam/email bomb problem

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Bobby Filar, Head of Machine Learning at Sublime Security. Bobby takes us through the rising problem of spam bombing, or email bombing, a technique threat actors are increasingly using for initial access into corporate environments.

Sponsored: Sublime Security on the spam/email bomb problem
0:00 / 22:55

Risky Bulletin: DanaBot and Lumma Stealer taken down

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Law enforcement takes down the DanaBot and Lumma Stealer malware operations, the US government wants a centralized data broker platform, Turkey dismantles a Chinese IMSI catcher spy ring, and Russia hacked border cameras to track Ukrainian military aid.

Risky Bulletin: DanaBot and Lumma Stealer taken down
0:00 / 7:33

Srsly Risky Biz: Telegram is cooperating with authorities, for now

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about how Telegram took down the two largest ever criminal marketplaces recently. They used Telegram for all their communications and had collectively sold over USD$30 billion in illicit products. The pair discuss why Telegram is now cooperating with authorities after historically being reluctant and whether this assistance will continue.

They also discuss how Meta is awash with scam advertisements and how Chinese mobile app encryption is suspiciously awful.

This episode is also available on Youtube.

Srsly Risky Biz: Telegram is cooperating with authorities, for now
0:00 / 20:27

Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • TeleMessage memory dumps show up on DDoSecrets
  • Coinbase contractor bribed to hand over user data
  • Telegram does seem to be actually cooperating with law enforcement
  • Britain’s legal aid service gets 15 years worth of applicant data stolen
  • Shocking no one, Ivanti were weaseling when they blamed latest bugs on a third party library

This week’s episode is sponsored by Prowler, who make an open source cloud security tool. Founder and original project developer Toni de la Fuente joins to talk through the flexibility that open tooling brings. Prowler is also adding support for SaaS platforms like M365, and of course, an AI assistant to help you write checks!

This episode is also available on Youtube.

Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now
0:00 / 53:01