Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #778 -- Musk's child soldiers seize control of FedGov IT systems

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • DeepSeek leaves an unauthed database on the internet
  • Russia hacked UK prime minister’s personal mail
  • Australia sanctions a Telegram group… which is more sensible than it sounds
  • Medical device backdoor turns out to be just poorly thought out upgrade feature
  • Google abuses weak hashing to patch AMD CPU microcode
  • And much, much more.

This week’s episode is sponsored by email security boffins Sublime. Their co-founder and CEO Josh Kamdjou joins to talk about how attackers’ abuse of legitimate services like Docusign is a challenge for email security vendors.

Risky Business #778 -- Musk's child soldiers seize control of FedGov IT systems
0:00 / 56:28

Risky Business #777 -- It's SonicWall's turn

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

Coming to you from the same room in Risky Business headquarters Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. They talk through:

  • Sonicwall firewalls hand out remote code exec like candy
  • Mastercard make a slapstick-grade mistake with their DNS
  • The data breach at PowerSchool and other niche SaaS providers
  • Academic research proposes taking down Europe’s power grid
  • Apple CPUs get a new speculative execution side channel
  • And much, much more.

This week’s episode is sponsored by Push Security, who make an identity security product that runs inside browsers. Luke Jennings joins to discuss some of the pitfalls of federated authentication, like attackers using unexpected identity providers to log in to your apps.

This episode is also available on Youtube.

Risky Business #777 -- It's SonicWall's turn
0:00 / 51:26

Risky Business #776 -- Trump will flex American cyber muscles

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

Risky Business returns for its 19th year! Patrick Gray and Adam Boileau discuss the week’s cybersecurity news and there is a whole bunch of it. They discuss:

  • The incoming Trump administration guts the CSRB
  • Biden’s last cyber Executive Order has sensible things in it
  • China’s breach of the US Treasury gets our reluctant admiration
  • Ross Ulbricht - the Dread Pirate Roberts of Silk Road fame - gets his Trump pardon
  • New year, same shameful comedy Forti- and Ivanti- bugs
  • US soldier behind the Snowflake hacks faces charges after a solid Krebs-ing
  • And much, much (much! after a month off) more.

This week’s episode is sponsored by Sandfly Security, who make a Linux EDR solution. Founder Craig Rowland joins to talk about how the Linux ecosystem struggles with its lack of standardised approaches to detection and response. If you’ve got a telco full of unix, and people are asking how much Salt Typhoon you’ve got in there… Sandfly’s tools are probably what you’re looking for.

If you like your Business like us… - Risky - then we’re hiring! We’re looking for someone to help with audio and video production for our work, manage our socials, and if you’re also into the Cybers… even better. Position is remote, with a preference for timezones amenable to Australia/NZ. Drop us a line: editorial at risky.biz.

Risky Business #776 -- Trump will flex American cyber muscles
0:00 / 63:53

Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored Soap Box edition of the show Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes.

This is largely a conversation about compliance, but it’s actually interesting and fun. These are words we never thought we’d type!

Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser
0:00 / 26:40

Risky Business #775 -- Cl0p is back, SEC hack disclosures disappoint

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • The SEC’s cyber incident reporting isn’t very exciting after all
  • China Telecom on the way to being thrown out of the US
  • The NSA/Cybercom might get two separate hats
  • The Cl0p ransomware crew are back and taking responsibility for the Cleo hacks
  • (Yet another) File upload bug in Struts makes Java admins weep
  • And much, much more.

This episode is sponsored by SpecterOps, who run a pretty top notch offsec/pentest team when they’re not busy making the Bloodhound Enterprise identity attack path enumeration software. SpecterOps’ Robby Winchester joins to talk about how pentest has changed, and how their customers get value from their testing.

This episode is also available Youtube.

Risky Business #775 -- Cl0p is back, SEC hack disclosures disappoint
0:00 / 61:06

Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Wild World of Cyber podcast Patrick Gray sits down with SentinelOne’s Chief Intelligence and Public Policy Officer Chris Krebs to talk all about Chinese cyber operations.

They look at the Salt Typhoon and Volt Typhoon campaigns, the last 20 years of Chinese operations, and the evolution of the cyber roles of China’s Ministry of State Security and People’s Liberation Army.

It’s a very dense hour of conversation!

This podcast was recorded in front of an audience at the Museum of Contemporary Art in Sydney.

This episode is also available on Youtube.

Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations
0:00 / 50:04

Risky Business #774 -- Cleo file transfer appliances under widespread attack

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Cleo file transfer products have a remote code exec, here we go again!
  • Snowflake phases out password-based auth
  • Chinese Sophos-exploit-dev company gets sanctioned
  • Romania’s election gets rolled back after Tiktok changed the outcome
  • AMD’s encrypted VM tech bamboozled by RAM with one extra address bit
  • Some cool OpenWRT research
  • And much, much more.

This week’s episode is sponsored by Thinkst, who love sneaky canary token traps. Jacob Torrey previews an upcoming Blackhat talk filled with interesting operating system tricks you can use to trigger canaries in your environment. You wont believe the third trick! Attackers hate him!

This episode is also available on Youtube.

Risky Business #774 -- Cleo file transfer appliances under widespread attack
0:00 / 62:28

Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this interview Patrick Gray talks to Yubico’s COO and President Jerrod Chong about a new Yubikey feature: pre-registration.

You can now ship pre-registered Yubikeys to your staff so you don’t need to rely on your staff to enrol them. They’ve achieved this with really slick Okta and Entra ID integrations.

Jerrod also talks about a recent trip to Singapore and concerns he has about the cybersecurity of critical infrastructure in the energy sector.

Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered
0:00 / 29:56

Risky Business #773 -- Cybercriminals are dropping like flies in Russia

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • The FTC decides its time to take another look at Microsoft
  • Exxon’s opponents targeted by hackers
  • Russian hackers keep getting sentenced and it confuses us
  • The Feds recommend Signal, because throwing hackers out of telcos ain’t gonna happen
  • A South Korean set-top-box manufacturer shipped a DDoS client for corpo-combat
  • And much, much more.

This week’s sponsor interview with Vijit Nair from Corelight. We talk to him about doing detection in cloud environments, and how the varied nature of cloud systems makes the old ways - network monitoring - useful in new and interesting ways.

If you’re in Sydney, Pat is recording a live episode of the Wide World of Cyber with Chris Krebs on 5 December. There might still be tickets left!

This episode is also available on Youtube.

Risky Business #773 -- Cybercriminals are dropping like flies in Russia
0:00 / 57:02

Risky Business #772 -- Salt Typhoon is truly a national security disaster

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • A ransomware attack has crippled US supply chain software provider Blue Yonder
  • Russian spies hack nearby wifi to get to their targets, but that doesn’t seem surprising?
  • Salt Typhoon’s attacks on telcos are hard to solve and big on impact
  • China’s surveillance state workers sell their access at home
  • Palo Alto is bad and should feel bad
  • And much, much more.

In this week’s sponsor interview Patrick Gray chats with Matt Muller from Tines about Gartner’s “spicy take” that the SOAR category is dead. SOAR is dead! Long live SOAR!

This episode is also available on Youtube.

Risky Business #772 -- Salt Typhoon is truly a national security disaster
0:00 / 61:05