Risky Business Features Podcast

Analysis and news podcasts published weekly

Bug count sounds impressive... but means little

Presented by

James Wilson
James Wilson

Technology Editor

In this solo Risky Business Features episode, James Wilson explains why “number of bugs” fixed in any given update is a misleading metric. We’ve seen up to 1,000 individual bug fixes in a single update recently, but that doesn’t give defenders the full picture they need to manage risks.

Not all bugs are equally exploitable, so the industry needs to catch up to the bugpocalypse with more transparency. And maybe an entirely different approach to patching.

Bug count sounds impressive... but means little
0:00 / 45:58

How to launder illicit Bitcoin

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware gangs get a payday.

The payment itself might be in the millions, but it’s difficult for gangs to convert their ill-gotten crypto gains into cash they can actually spend. Geoff explains the role of professional launderers and why cash-rich drug gangs are useful connections for crypto-rich cybercriminals.

They also dive into who operates these international laundering networks, other types of crime they enable, and whether this affects the argument of whether victims should be allowed to pay.

How to launder illicit Bitcoin
0:00 / 45:44

Hunting software supply chain malware

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious packages, GitHub repositories and developer tools.

Paul walks James through static analysis, deobfuscation and reconstructing multi-stage kill chains to identify what attackers are trying to steal. They also discuss how LLMs make malware development easier while introducing operational security mistakes.

The pair examine DPRK tradecraft, blockchain-based payload delivery and what Paul calls Pollen Rider, which can reinfect developers through their own repositories.

Hunting software supply chain malware
0:00 / 75:04

Who gets to hack the hackers?

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, Brad Arkin joins James Wilson to chat about the Trump administration’s call to let private entities conduct cyber operations against criminal groups.

Brad’s firsthand experience responding to cyber incidents alongside US law enforcement gives him a unique perspective on how government and private sector relationships work, and how this program could improve the ability of both sides to tackle cybercrime.

James and Brad also explore who might participate in these campaigns and whether the government will be able to effectively oversee them.

Who gets to hack the hackers?
0:00 / 40:46

How Brian Krebs doxxed TeamPCP

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, James Wilson chats with Brian Krebs about the investigation that led him from recycled cybercrime handles and old forum records to the true identity of TeamPCP’s alleged leader in Perth.

TeamPCP is the hacker group that has gone berserk in the software supply chain over the last year or so, stealing credentials to compromise developers, their software packages, and their repositories.

In this interview Brian talks about his Signal conversations with the group’s ringleader, the strange Cybercats community surrounding TeamPCP, and the passive DNS breakthrough that helped him unmask what he thinks are the ringleader’s true identities.

How Brian Krebs doxxed TeamPCP
0:00 / 29:22

James Kettle on inventing new attack techniques with LLMs

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.

Kettle has built what he calls the HTTP Terminator, an autonomous research system that generates and tests tens of thousands of potentially new HTTP desync techniques. The Terminator, which makes use of Kettle’s own research methodology, has already come up with new desync methods that James hadn’t thought of before.

Kettle and Wilson discuss how to develop and evaluate machine-generated ideas without drowning in false positives, and why the most powerful part of the process is the discovery cascade, where one unexpected result becomes the seed for another.

The upshot is AI can conduct genuinely novel security research, but don’t expect to one-shot your way to an army of robot hackers.

James Kettle on inventing new attack techniques with LLMs
0:00 / 77:35

How private LLM inference actually works

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without the inference provider seeing your prompts.

Tanya talks James through how private inference works, from trusted execution environments and hardware attestation, to TLS termination and GPU isolation. Customers can verify the exact code and model processing their data, while Tinfoil and its infrastructure providers remain locked out.

That’s clever engineering… but who really needs it? Is private inference only useful if you’re doing something bad, or will it become a privacy baseline like TLS? James and Tanya discuss the costs and trade-offs, and how open weights make private inference more transparent and trustworthy.

How private LLM inference actually works
0:00 / 83:49

Benchmarks, borders and the true cost of AI regulation

Presented by

James Wilson
James Wilson

Technology Editor

The US government is flirting with the idea of regulating most open weight models out of existence. What would that mean for everyone who’s currently using them?

Policymakers who just look at the benchmarks and token costs might think frontier and open weight AI models are all interchangeable. That they can just banhammer them without causing any disruption. That’s far from the truth.

In this solo podcast, James Wilson looks beyond the US vs China AI race rhetoric and instead games out what the real world consequences of the US government slapping bans on AI models could be.

Benchmarks, borders and the true cost of AI regulation
0:00 / 39:23

Fortibleed: The bleeding edge of AI cybercrime

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A small investigation into a curiously open directory on an unknown server expanded into the discovery of an attack that targeted 400,000 Fortinet devices.

As Ensar says, each time the SOCRadar team pulled a single thread, it led to a tapestry of AI-enabled cybercrime. They uncovered custom initial access, persistence and packet sniffing tools, as well as direct links to the INC and Lynx ransomware operations. Most interesting though is the use of AI to design, implement and operate all aspects of the campaign across a team of 20 individual actors. Operating more like a modern software company than a traditional cybercrime gang, Fortibleed serves as our first in-depth look at the future of cybercrime.

Fortibleed: The bleeding edge of AI cybercrime
0:00 / 48:03

What to do 'til the bugpocalypse gets here

Presented by

James Wilson
James Wilson

Technology Editor

In this podcast episode Brad Arkin joins James Wilson to discuss how defenders can get ahead of the late-running bugpocalypse. While we’re confident the offensive cybersecurity capabilities of frontier and open-weight LLMs are real, attackers don’t yet seem able to fully utilise them. This creates a window of opportunity for defenders to tackle the threat.

There are a few well-funded and seemingly overlapping industry efforts under way including Athena, Akrites, and Patch the Planet. But, as Brad says in this interview, there’s too much focus on fixing bugs and traditional vulnerability triage, and not enough on exploring how to make entire classes of vulnerabilities inert.

What to do 'til the bugpocalypse gets here
0:00 / 44:24