Podcasts

News, analysis and commentary

Sponsored: Sublime Security on trends and the rise of SVG abuse

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Josh Kamdjou, co-founder and CEO of Sublime Security. Josh goes over recent trends in email badness, such as the increase in QR code abuse and the rise of SVG smuggling.

Sponsored: Sublime Security on trends and the rise of SVG abuse
0:00 / 14:12

Risky Bulletin: Hacktivists claim cyber-sabotage of 116 Iranian ships

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Hacktivists sabotage over 100 Iranian ships, Iran calls out China for hacking, six new Paragon customers come to light, and North Korea creates a new cyber unit.

Risky Bulletin: Hacktivists claim cyber-sabotage of 116 Iranian ships
0:00 / 6:23

Srsly Risky Biz: China's MSS gets personal

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray discuss how China’s Ministry of State Security is increasingly doxxing and threatening Taiwanese APT operators. In some ways this mirrors the US strategy of naming and shaming Chinese cyber operators in indictments that contain lots of supporting information. But although MSS statements are filled with propaganda rather than technical detail, naming Taiwanese military hackers has some bite.

They also discuss Russia’s ‘shadow war’ sabotage campaign across Europe. The Russian campaign mostly relies on traditional sabotage and finding local proxies to throw bombs. But it does make sense for Western governments to respond with destructive cyber operations.

This episode is also available on Youtube.

Srsly Risky Biz: China's MSS gets personal
0:00 / 19:10

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Github Actions supply chain attack loots keys and secrets from 23k projects
  • Why a VC fund now owns a minority stake in Risky Business Media (!?!?)
  • China doxes Taiwanese military hackers
  • Microsoft thinks .lnk file whitespace trick isn’t worth patching but APTs sure love it
  • CISA delivers government efficiency by re-hiring fired staff… to put them on paid leave
  • …and Google acquires Wiz for $32bn

This week’s show is sponsored by Zero Networks, and they have sent along a happy customer to talk about their experience. Aaron Steinke is Head of Infrastructure at La Trobe Financial, an asset management firm in Australia. Aaron talks through bringing modern zero-trust goodness to the reality of a technology environment that’s been around 40 years.

This episode is also available on Youtube.

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
0:00 / 56:58

Risky Bulletin: Google buys Wiz for $32 billion

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Google buys Wiz for $32 billion, China attributes the Poison Ivy APT group to the Taiwanese Military, APT groups abuse a Windows zero-day and a judge tells CISA to reinstate fired workers.

Risky Bulletin: Google buys Wiz for $32 billion
0:00 / 5:44

Between Two Nerds: Sowing discord by being nice!

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq talk about how offensive cyber operations could do so much more than just ‘deny, disrupt, degrade and destroy’. Grugq thinks this thinking is rooted in military culture and he wonders why cyber operations are always so mean.

This episode is also available on Youtube.

Between Two Nerds: Sowing discord by being nice!
0:00 / 27:00

Risky Bulletin: GitHub supply chain attack leaks secrets

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Patrick Gray
Patrick Gray

CEO and Publisher

A GitHub supply chain attack leaks secrets, the White House tells federal agencies to stop firing cyber staff, Germany exempts cybersecurity from debt limits, and the RCS standard adds support for end-to-end encryption.

Risky Bulletin: GitHub supply chain attack leaks secrets
0:00 / 8:28

Sponsored: Using carrots and sticks to get more secure software

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

In this Risky Bulletin sponsor interview Matt Muller, field CISO of Tines, explains how governments are using carrots and sticks to improve the security of enterprise software. Matt discusses CISA’s ‘Secure by Design’ pledge and the UK NCSC’s effort to quantify ‘unforgivable bugs’

Sponsored: Using carrots and sticks to get more secure software
0:00 / 13:15

Risky Bulletin: FBI says online file converters are nasty

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The FBI warns of online file converters that distribute malware, China backdoors Juniper router, a wave of ransomware hits Taiwan, and North Korean spyware slips into the Play Store.

Risky Bulletin: FBI says online file converters are nasty
0:00 / 6:45

Srsly Risky Biz: Outside America, Musk's X is a foreign influence threat

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray discuss how X is actively engaging in political interference outside the US. The risks mirror those of TikTok. American legislators moved against TikTok because it could potentially be a powerful tool for the Chinese government to interfere with American political discourse. X is a realised threat, not a potential one, so we expect that foreign governments will start to consider a ban.

They also explore why mass firing of probationary employees in NSA and intelligence agencies is particularly damaging.

This episode is also available on Youtube.

Srsly Risky Biz: Outside America, Musk's X is a foreign influence threat
0:00 / 15:23