Podcasts

News, analysis and commentary

Risky Biz News: Google Authenticator can now sync data to Google accounts

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Biz News: Google Authenticator can now sync data to Google accounts
0:00 / 0:00

Risky Business #703 -- Russia whines about its tech dependence on China

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The supply chain attack in the supply chain attack
  • Russia has a China dependency problem
  • Recent research into TLS resumption flaws
  • Google and Intel team up on hardware hacking
  • DHS will hack enterprise kit
  • Much, much more

This week’s show is brought to you by Corelight. Brian Dye, Corelight’s CEO, is this week’s sponsor guest. He’s talking about the (actually sensible) ChatGPT-driven features Corelight has built into its NDR platform.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Business #703 -- Russia whines about its tech dependence on China
0:00 / 0:00

Between Two Nerds: Cyber Deterrence

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq discuss whether cyber operations are any good at deterrence. Tom thinks that attributes of the domain mean that it is just no good for deterrence. The Grugq, however, thinks that it can be, although perhaps not in a state vs state context.

Between Two Nerds: Cyber Deterrence
0:00 / 0:00

Risky Biz News: CISA will rescue abandoned open source security tool

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Biz News: CISA will rescue abandoned open source security tool
0:00 / 0:00

Risky Biz News: 3CX was a supply chain attack in a supply chain attack

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Biz News: 3CX was a supply chain attack in a supply chain attack
0:00 / 0:00

Snake Oilers: Socket, Teleport and Mandiant's Purple Team

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Socket.dev, a software supply chain product that currently deploys as a GitHub addon
  • Teleport, a company that makes a secure access gateway/single sign on product for engineers to securely access infrastructure
  • Mandiant joins us to pitch its Purple Team engagement product

Enjoy!

Snake Oilers: Socket, Teleport and Mandiant's Purple Team
0:00 / 0:00

Srsly Risky Biz: After Viasat, Space Systems Get Scrutiny

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Patrick Gray
Patrick Gray

CEO and Publisher

In this podcast Patrick Gray talks to Tom Uren about a report by CSC 2.0 that recommends the US government designate space systems as critical infrastructure. Lots of satellites systems are already covered under other critical infrastructure sectors such as communication or defence, but Tom agrees that there are some good reasons to carve out a space-specific critical infrastructure sector.

They also talk about the US State Department working on developing a portfolio of cyber diplomacy “offerings”, ranging from disaster relief funding, to technical capacity building, through to policy-level cyber education. This seems like a great idea.

Srsly Risky Biz: After Viasat, Space Systems Get Scrutiny
0:00 / 0:00

Risky Biz News: Apple's Lockdown Mode wins against iOS zero-day

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.

You can find the newsletter version of this podcast click here.

Risky Biz News: Apple's Lockdown Mode wins against iOS zero-day
0:00 / 0:00

Risky Business #702 -- 3CX: It's like SolarWinds, but stupider

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Why 3CX was the dumbest supply chain attack we’ve seen
  • Why Wiz’s AzureAD research was a showstopper that didn’t get the attention it deserved
  • How attackers are burning down cloud infrastructure
  • The latest from the world of spyware
  • Much, much more

This week’s show is brought to you by Nucleus Security. Chris Hughes from Aquia is this week’s sponsor guest. He appeared at Nucleus Security’s invitation.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Business #702 -- 3CX: It's like SolarWinds, but stupider
0:00 / 0:00

Between Two Nerds: The NCF's Practical Guide to Offensive Cyber Operations

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq discuss the UK’s National Cyber Force’s recently published “Responsible Cyber Power in Practice” document. The Grugq thinks he’s been plagiarised, while Tom wonders whether the NCF’s “doctrine of cognitive effects” highlights the limits of cyber operations. It’s a good document and will be influential in shaping how people discuss offensive operations (those that disrupt, degrade, destroy etc).

Between Two Nerds: The NCF's Practical Guide to Offensive Cyber Operations
0:00 / 0:00