Podcasts

News, analysis and commentary

Risky Bulletin: eScan antivirus distributes backdoor in latest supply chain attack

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Catalin Cimpanu
Catalin Cimpanu

News Editor

Hackers breach eScan antivirus and distribute a backdoor, Google takes down the IPIDEA proxy botnet, most GDPR fines remain uncollected, and the Poland wiper attack hit 30 locations.

Risky Bulletin: eScan antivirus distributes backdoor in latest supply chain attack
0:00 / 7:01

Srsly Risky Biz: Punish the wicked and reward the righteous

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Amberleigh Jack talk about the Pall Mall Process, an international effort to reign in abusive spyware. Tom thinks the US has already stumbled into a viable carrots and sticks style strategy that will shape the industry more than coming up with standards will.

The pair also discuss news that Chinese Salt Typhoon hackers compromised the calls of senior UK officials in Downing Street. The UK has extensive telecommunications security regulations and the incident makes us wonder what that legislation is actually good for.

This episode is also available on Youtube.

Srsly Risky Biz: Punish the wicked and reward the righteous
0:00 / 17:17

Risky Business #822 -- France will ditch American tech over security risks

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. They discuss:

  • La France is tres sérieux about ditching US productivity software
  • China’s Salt Typhoon was snooping on Downing Street
  • Trump wields the mighty DISCOMBOBULATOR
  • ESET says the Polish power grid wiper was Russia’s GRU Sandworm crew
  • US cyber institutions CISA and NIST are struggling
  • Voice phishing for MFA bypass is getting even more polished

This episode is sponsored by Sublime Security. Brian Baskin is one of the team behind Sublime’s 2026 Email Threat Research report. He joins to talk through what they see of attackers’ use of AI, as well as the other trends of the year.

This episode is also available on Youtube.

Risky Business #822 -- France will ditch American tech over security risks
0:00 / 64:05

Risky Bulletin: Cyberattack cripples cars across Russia

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Catalin Cimpanu
Catalin Cimpanu

News Editor

A cyberattack has crippled cars in Russia, Microsoft patches an Office zero-day, WhatsApp rolls out an account lockdown feature, and a handful of Chrome extensions steal ChatGPT auth tokens.

Risky Bulletin: Cyberattack cripples cars across Russia
0:00 / 7:43

Between Two Nerds: Getting pinged and the fog of war

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss how getting pinged hurts state hackers by introducing uncertainty. Publishing technical reports on the hack can actually improve the situation by removing uncertainty about how attackers were detected.

This episode is also available on Youtube.

Between Two Nerds: Getting pinged and the fog of war
0:00 / 30:02

Sponsored: Push Security on ConsentFix attacks

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Luke Jennings, VP of Research & Development at Push Security, about ConsentFix. It’s a new form of email-based social engineering attack used in the wild, an evolution of the ClickFix attack that goes after your identity.

Sponsored: Push Security on ConsentFix attacks
0:00 / 13:06

Risky Bulletin: Russia deployed wipers on Poland's energy grid

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Catalin Cimpanu
Catalin Cimpanu

News Editor

Russia deployed wipers against Poland’s energy grid, Microsoft shared BitLocker keys with the FBI, Romania dismantles a murder-for-hire portal, and the EU creates a new anti-spyware group.

Risky Bulletin: Russia deployed wipers on Poland's energy grid
0:00 / 6:34

Risky Bulletin: Improperly patched bug exploited again in Fortinet firewalls

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Catalin Cimpanu
Catalin Cimpanu

News Editor

A poorly patched bug is being exploited in Fortinet firewalls, hackers go after security testing environments, Jordanian police used Cellebrite against activists, and new Cisco and SmarterMail zero-days.

Risky Bulletin: Improperly patched bug exploited again in Fortinet firewalls
0:00 / 6:39

Srsly Risky Biz: You can't block space internet

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Amberleigh Jack talk about the rise of technologies that can undermine internet blackouts such as Starlink and its relatively new direct-to-cell service. Authoritarian internet shutdowns and disasters happen often enough that governments should think about how to take advantage of these new technologies rather than just reacting when crises arise.

They also discuss the nomination of General Joshua Rudd as head of NSA and US Cyber Command.

This episode is also available on Youtube.

Srsly Risky Biz: You can't block space internet
0:00 / 19:47

Risky Business #821 -- Wiz researchers could have owned every AWS customer

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, joined by a special guest. BBC World Cyber Correspondent Joe Tidy is a long time listener and he pops in for a ride-along in the news segment plus a chat about his new book.

This week news includes:

  • Did the US cyber Venezuela’s power grid, or do they just want us to think they coulda?
  • US govt might boycott the RSAC Conference ‘cause Jen Easterly being CEO makes them mad
  • MS Patch Tuesday fixes CVSS5.5 bug and … stops you shutting down
  • Wiz pulls off cloud stunt hack that ends with control of everyone’s AWS console
  • Millions of Bluetooth devices that use Google’s Fast Pairing will pair with anyone, any time
  • GNU inet-tools’ telnetd parties like it’s 2007, and brings -f root unauthed remote login back

Thinkst is this week’s sponsor, and long time friend of the show Haroon Meer joins. As always they’re polishing their Canary tokens - adding breadcrumbs to lead you to them - but they’re also a bunch of giant nerds who now run South Africa’s Computer Olympiad.

This episode is also available on Youtube.

Risky Business #821 -- Wiz researchers could have owned every AWS customer
0:00 / 64:46