Podcasts

News, analysis and commentary

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Microsoft disrupts a malware-signing service used by ransomware gangs, a CISA contractor leaks sensitive GovCloud keys, vulnerability exploitation is now the dominant network entry vector, and Drupal readies security updates for a “highly critical” vulnerability.

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs
0:00 / 8:50

Between Two Nerds: Russia's hacker university

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russia’s cyber program and look at what Western intelligence agencies do instead.

This episode is also available on YouTube.

Between Two Nerds: Russia's hacker university
0:00 / 29:22

NCSC’s Ollie Whitehouse on surviving the "bugpocalypse"

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of Risky Business Features Ollie Whitehouse, the CTO of the UK’s National Cyber Security Centre, joins Patrick Gray and James Wilson to talk about why “patch faster” will only get organisations so far in the face of the AI “bugpocalypse”.

As Ollie explains, organisations will need to reduce internet-facing attack surface and make better architecture decisions as 0day discovery speeds up.

This episode is also available on YouTube.

NCSC’s Ollie Whitehouse on surviving the "bugpocalypse"
0:00 / 29:25

Risky Bulletin: Indonesia emerges as a new hub for cyber scams

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Indonesia emerges as a new cyber scam hub, Grafana got hacked and held for ransom, the Fast16 malware subverted software used to simulate nuclear explosions, and a new Microsoft Exchange zero-day is under attack.

Risky Bulletin: Indonesia emerges as a new hub for cyber scams
0:00 / 10:10

Sponsored: Push Security goes AI threat hunting in browser telemetry

Presented by

James Wilson
James Wilson

Technology Editor

In this sponsored interview James Wilson chats with Push Security’s Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform.

Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers.

Sponsored: Push Security goes AI threat hunting in browser telemetry
0:00 / 14:01

Soap Box: Where does AI fit into cloud security?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

This episode is also available on Youtube.

Soap Box: Where does AI fit into cloud security?
0:00 / 33:37

Risky Bulletin: Shai-Hulud goes open-source

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

The source code for the Shai-Hulud worm has been released online, a dark web market admin was charged after a major OPSEC failure, France investigates an Israeli disinfo firm, and ‘Composer’ rushes to fix a GitHub token leak.

Risky Bulletin: Shai-Hulud goes open-source
0:00 / 8:50

Srsly Risky Biz: The AI Regulation Knife Fight

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about the argy bargy within the Trump administration about AI regulation. They cover who is fighting, what is at stake and what the real areas of concern are.

They also cover low earth orbit satellite constellations. Russia’s building one, the EU has plans and China is building two. They are the new must-have accessory for any country with global ambitions.

This episode is also available on YouTube

Srsly Risky Biz: The AI Regulation Knife Fight
0:00 / 23:34

Risky Bulletin: Damaging worm rips through npm ecosystem

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and another major supply chain attack on npm (yawn).

Risky Bulletin: Damaging worm rips through npm ecosystem
0:00 / 7:49

Risky Business #837 -- GitHub Actions footgun claims TanStack

Presented by

James Wilson
James Wilson

Technology Editor

Adam Boileau
Adam Boileau

Co-host at large

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

  • Mini Shai-Hulud and the TanStack compromise using Github Actions
  • Instructure pays Canvas elearning platform data extortionists
  • More Linux privilege escalation 0days!
  • CISA helping critical infrastructure operators rearchitect their networks so they work offline

This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.

Risky Business #837 -- GitHub Actions footgun claims TanStack
0:00 / 65:15