Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #813 -- FFmpeg has a point

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • We love some good vulnerability reporting drama, this time FFmpeg’s got beef with Google
  • OpenAI announces its Aardvark bug-gobbling system
  • Two US ransomware responders get arrested for… ransomware
  • Memento (nee HackingTeam) CEO says: Sì, those are totally our tools getting snapped in Russia
  • Hackers help freight theft gangs steal shipments to resell
  • A second Jabber Zeus mastermind gets his comeuppance 15 years on

This week’s episode is sponsored by Nucleus Security, who make a vulnerability information management system. Co-founder Scott Kuffer says that approaches for triaging vulnerabilities have started to fall apart, given there are just. So. Many. And they’re all important!

This episode is also available on Youtube.

Risky Business #813 -- FFmpeg has a point
0:00 / 65:08

Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • L3Harris Trenchant boss accused of selling exploits to Russia once worked at the Australian Signals Directorate
  • Microsoft WSUS bug being exploited in the wild
  • Dan Kaminsky DNS cache poisoning comes back because of a bad PRNG
  • SpaceX finally starts disabling Starlink terminals used by scammers
  • Garbage HP update deletes certificates that authed Windows systems to Entra

This week’s episode is sponsored by automation company Tines. Field CISO Matt Muller joins to discuss how Tines has embraced LLMs and the agentic-AI future into their workflow automation.

This episode is also available on Youtube.

Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD
0:00 / 66:14

Risky Business #811 -- F5 is the tip of the crap software iceberg

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • China has been rummaging in F5’s networks for a couple of years
  • Meanwhile China tries to deflect by accusing the NSA of hacking its national timing system
  • Salesforce hackers use their stolen data trove to dox NSA, ICE employees
  • Crypto stealing, proxy-deploying, blockchain-C2-ing VS Code worm charms us with its chutzpah
  • Adam gets humbled by new Linux-capabilities backdoor trick
  • Microsoft ignores its own guidance on avoiding BinaryFormatter, gets WSUS owned.

This episode is sponsored by Push Security. Co-founder and Chief Product Officer Jacques Louw joins to talk through how Push traced a LinkedIn phishing campaign targeting CEOs, and the new logging capabilities that proved critical to understanding it.

This episode is also available on Youtube.

Risky Business #811 -- F5 is the tip of the crap software iceberg
0:00 / 51:51

Wide World of Cyber: A deep dive on the F5 hack

Presented by

Chris Krebs
Chris Krebs

Funemployed

Alex Stamos
Alex Stamos

Funemployed

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Wide World of Cyber podcast Patrick Gray talks to Chris Krebs and Alex Stamos about the F5 incident. They talk about what happened, whether it’s a big deal, and why private equity ownership of mid-tier cybersecurity companies is often a red flag.

Wide World of Cyber: A deep dive on the F5 hack
0:00 / 39:11

Risky Biz Soap Box: Why Mastercard is scaling its cybersecurity business

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored Soap Box edition of the Risky Business podcast, host Patrick Gray chats with Mastercard’s Executive Vice President and Head of Security Solutions, Johan Gerber, about how the card brand thinks about cybersecurity and why it’s aggressively investing in the space.

After listening to this interview you’ll understand why the credit card company spent $2.65b on threat intelligence vendor Recorded Future!

This episode is also available on Youtube.

Risky Biz Soap Box: Why Mastercard is scaling its cybersecurity business
0:00 / 30:49

Risky Business #810 -- Data extortion attacks have a silver lining

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • FBI intervenes in Scattered Spider Salesforce leaksite
  • Clop loots Oracle E-Biz deployments
  • Plus so much more data extortion.. At least it’s not ransomware … we guess?
  • The US still can’t decide who’s gonna be in charge of NSA & Cybercom
  • Cambodian scam compounds get sanctioned and $15b in crypto is seized
  • NSO gets sold for pocket-lint-grade money
  • Bugs! Redis CVSS 10, Ivanti, Crowdstrike and… Internet Explorer?! zeroday?! In the wild?!!!?

This week’s episode is sponsored by Stairwell. Founder Mike Wiacek talks about how Stairwell brings VirusTotal-like visibility to private files, and about integrating the insights that brings into your SOC workflow.

This episode is also available on Youtube.

Risky Business #810 -- Data extortion attacks have a silver lining
0:00 / 63:12

Snake Oilers: Realm Security, Horizon3 and Persona

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcast, three vendors pop in to pitch you all on their wares:

  • Realm Security: A security focussed, AI-first data pipeline platform
  • Horizon3: AI hackers! Pentesting robots!! They’re coming fer yur jerbs!
  • Persona: Verify customer and staff identities with live capture

This episode is also available on Youtube.

Snake Oilers: Realm Security, Horizon3 and Persona
0:00 / 45:40

Risky Business #809 -- Hackers try to pay a journalist for access to the BBC

Presented by

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray is on holiday so Amberleigh Jack and Adam Boileau hijack the studio to discuss the week’s cybersecurity news, including:

  • Hackers learn that trying to coerce a journalist just makes for … a great story?
  • A man in his 40s gets arrested over the European airport chaos. Yep, we’re surprised, too.
  • Adam fanboys over Watchtowr Labs while bemoaning Fortra.
  • Academics pick apart Tile trackers and find them lacking
  • CISA tells agencies to patch their damn Cisco gear

This episode is also available on YouTube.

Risky Business #809 -- Hackers try to pay a journalist for access to the BBC
0:00 / 39:28

Risky Business #808 -- Insane megabug in Entra left all tenants exposed

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and special guest Rob Joyce discuss the week’s cybersecurity news, including:

  • Secret Service raids a SIM farm in New York
  • MI6 launches a dark web portal
  • Are the 2023 Scattered Spider kids finally getting their comeuppance?
  • Production halt continues for Jaguar Land Rover
  • GitHub tightens its security after Shai-Hulud worm

This week’s episode is sponsored by Sublime Security. In this week’s sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI in an email security platform.

This episode is also available on YouTube

Risky Business #808 -- Insane megabug in Entra left all tenants exposed
0:00 / 52:37

Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Shai-Hulud worm propagates via npm and steals credentials
  • Jaguar Land Rover attack may put smaller suppliers out of business
  • Leaked data emerges from the vendor behind the Great Firewall of China
  • Vastaamo hacker walks free while appeal is underway
  • Why is a senator so mad about Kerberos?

This week’s episode is sponsored by Knocknoc. Chief exec Adam Pointon joins to talk through the surprising number of customers that are using Knocknoc’s identity-to-firewall glue to protect internal services and networks.

This week’s episode is also available on Youtube.

Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc
0:00 / 53:19