Podcasts

News, analysis and commentary

Risky Business #629 -- Kaseya 0day was utter trash

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss recent security news, including:

  • Our take on the REvil attack against Kaseya customers
  • Microsoft’s print spooler bug is a real worry
  • Reports the RNC breached by Russia’s SVR
  • NSA snaps GRU brute forcing efforts
  • Much, much more

This week’s show is brought to you by Material Security, a very interesting startup that has a completely different take on what email security actually is. Material’s co-founder Ryan Noon will be along in this week’s sponsor interview to talk about the cool stuff they’re doing on the analytics side.

Risky Business #629 -- Kaseya 0day was utter trash
0:00 / 0:00

Risky Business #628 -- Microsoft is not your friend

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss recent security news, including:

  • Microsoft reluctantly and belatedly discloses breach
  • Chinese APT suspected of Air India breach
  • JBS paid $11m even though they successfully restored systems
  • cl0p money launderer arrests
  • Ransomware news roundup
  • The latest research and MORE

This week’s show is brought to you by Greynoise. Its founder and CEO, Andrew Morris, joins us this week to talk through some of the work he’s been doing to extend Greynoise’s use cases. It’s a great chat, that one.

Risky Business #628 -- Microsoft is not your friend
0:00 / 0:00

Risky Biz Soap Box: EclecticIQ's CEO Joep Gommers on operationalising threat intelligence

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Aaaaand we’re back on deck! We’re kicking things off this week with this interview with Joep Gommers, the CEO and founder of EclecticIQ. And FYI, in case you didn’t know, these Soap Box podcasts are wholly sponsored.

If your job involves handling threat intel, then I think you’ll really enjoy this conversation. It touches on a bunch of stuff. The first part of this is talking through what EclecticIQ actually offers, currently, then we talk more broadly about operationalising threat intelligence, and finally we talk about EclecticIQ’s new stuff – which include introducing XDR tooling.

Risky Biz Soap Box: EclecticIQ's CEO Joep Gommers on operationalising threat intelligence
0:00 / 0:00

Risky Biz Soap Box: Banks to embrace Yubikeys for customers

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

As regular listeners know, the soap box podcasts we publish here at Risky.Biz are wholly sponsored. That means everyone you hear in one of these podcasts, paid to be here.

And this edition of Soap Box has become an annual thing – it’s our once-yearly catch up with Jerrod Chong, the chief solutions officer of Yubico, makers of the Yubikey and YubiHSM.

Yubikey is an infosec darling, really, because they’re in the unique position of having a product that’s popular with security professionals like CISOs while also being popular with security-conscious consumers. Businesses get value out of Yubikeys, but so do normal people, thanks to key support being baked into services like Facebook and Google.

As you’re about to hear, there’s a whole new category of use about to open up – Bank of America is launching FIDO2 U2F support for its customers. That’s a big deal – the more FIDO2 keys we get out there the better.

Risky Biz Soap Box: Banks to embrace Yubikeys for customers
0:00 / 0:00

Risky Business #627 -- USG claws back Colonial pipeline ransom money

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • US Government claws back Colonial ransom bitcoin. We don’t think the FBI acted alone.
  • Meet an0m, the cute little app for planning crimes that drinks milkshakes.
  • Ransomware stuff, duh.
  • Trickbot developer arrested in Florida
  • Supreme court upends CFAA “exceed authorised access” element
  • Much, much more

This week’s show is brought to you by Datadog. Michael Yamnitsky will be along in this week’s sponsor interview to talk about cloud security posture management. DataDog is launching a product in that space, so we’ll be hearing about the types of issues CSPM products can help to unearth.

Risky Business #627 -- USG claws back Colonial pipeline ransom money
0:00 / 0:00

Risky Business #626 -- Russian ransomware beef simmers

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Ransomware attack threatens Australian and US beef supply
  • Talos dubs Russian ransomware crews “privateers”
  • NYTimes writes another bad story
  • More Fortinet pwnage
  • Belgian government rolls Hafnium IR and finds, well, something else
  • Google unveils new rowhammer techniques
  • Much, much more

Haroon Meer of Thinkst Canary is this week’s sponsor guest. Thinkst is spinning up a labs division, but they’ll be doing something different to the same-old bug hunting. That’s a quality conversation.

Risky Business #626 -- Russian ransomware beef simmers
0:00 / 0:00

Risky Business #625 -- Iranians wipe some machines, Israelis kaboom some

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The latest news on the health system ransomware crisis in Ireland
  • TSA to force pipeline operators to disclose attacks they probably aren’t detecting anyway
  • Colonial paying ransom angers US congresspeople who really haven’t thought this through
  • Iran targets Israeli systems with new wipers
  • Israel targets Hamas systems with guided munitions that go bang
  • Much, much more

This week’s sponsor guest is Ryan Kalember, EVP of Cybersecurity Strategy at Proofpoint. He joins us to talk about how compromised o365 accounts are powering all sorts of threat actors right now – from ransomware operators to BEC crews and APT units, everyone loves a popped mailbox.

Risky Business #625 -- Iranians wipe some machines, Israelis kaboom some
0:00 / 0:00

Risky Biz Feature Podcast: The politics of cybersecurity

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this podcast we’ll be hearing from an Australian politician, Tim Watts. He’s a member of our federal parliament and serves as our shadow minister for communications and cybersecurity. For our overseas listeners, the “shadow” part of his title is there because he’s a member of the opposition party, so he’s not in government. But, of course, if the Labor party wins the next election he’ll be our communications and cybersecurity minister.

Anyway, Tim is a bit of an anomaly in politics because he has a genuine, nerd-like interest in the field we so love. Tim and I chat pretty regularly, and I can say that yes, 100%, his interest in this field is genuine and he has a firm grasp on the issues that matter.

I thought now would be a great time to run an interview on the politics of infosec. While it’s true that policymakers spend time thinking about this stuff, cybersecurity hasn’t yet crossed over into being what they call a “retail politics” issue. But thanks to the Colonial pipeline ransomware incident, that might be about to change.

Risky Biz Feature Podcast: The politics of cybersecurity
0:00 / 0:00

Risky Business #624 -- Ransomware farce continues

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The aftermath of the Colonial ransomware attack
  • Biden signs cybersecurity EO
  • DarkSide crew hounded off the Internet. For now.
  • Ransomware campaigns continue, hitting health, insurance targets globally
  • IIS PoC released
  • Rapid7 discloses Codecov-related source code breach
  • Much, much more

This week’s show is brought to you by AttackIQ. Its VP of Product Mark Bagley and Senior Director of Cybersecurity Strategy and Policy Jonathan Reiber are this week’s sponsor guests.

Risky Business #624 -- Ransomware farce continues
0:00 / 0:00

Risky Biz Snake Oilers: Google pitches BeyondCorp for Enterprise

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

As regular listeners would know, Snake OIlers is a wholly sponsored podcast series we do here at Risky Biz HQ where vendors give us money so they can come on and pitch their products to you, our dear, dear listeners.

And we have three vendors along today to pitch you:

  • Google Cloud Security is in the top slot pitching their Zero Trust product suite BeyondCorp Zero Trust for Enterprise.

  • Devicie, an Australian startup, that developed a solution that makes Microsoft Intune useable.

  • Trend Micro joins the show to talk about its latest XDR features

Risky Biz Snake Oilers: Google pitches BeyondCorp for Enterprise
0:00 / 0:00