Risky Bulletin Podcast feed

Daily podcasts featuring news bulletins and discussion shows...

Between Two Nerds: Cyber is people

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss how important people are to cyber power and whether the rise of AI is changing that.

This episode is also available on YouTube.

Between Two Nerds: Cyber is people
0:00 / 30:12

Risky Bulletin: A JSON RCE bug is about to rock the Java world

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A JSON bug is about to rock the Java world, scam compounds continue in Myanmar despite the junta crackdown, and Google has a new APT naming scheme.

Risky Bulletin: A JSON RCE bug is about to rock the Java world
0:00 / 6:59

Sponsored: How AI is putting pressure on EDR

Presented by

James Wilson
James Wilson

Technology Editor

In this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections.

LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by “burning tokens”. The takeaway is that defenders increasingly need to assume attackers have visibility into how their endpoint security products work.

Sponsored: How AI is putting pressure on EDR
0:00 / 17:58

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and Google adds selfie video to its login options.

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
0:00 / 8:44

Srsly Risky Biz: Knives are out for open-weight AI models

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them.

They also talk about arrests of several members of the Scattered Spider juvenile cybercrime collective.

This episode is also available on YouTube

Srsly Risky Biz: Knives are out for open-weight AI models
0:00 / 24:36

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Rogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach
0:00 / 6:50

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine.

This episode is also available on YouTube.

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine
0:00 / 27:04

Risky Bulletin: Hacker wipes Romania's entire land registry database

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

A hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress.

Risky Bulletin: Hacker wipes Romania's entire land registry database
0:00 / 9:03

Sponsored: Thinkst on building companies that don’t suck

Presented by

Casey Ellis
Casey Ellis

Founder, Bugcrowd

In this Risky Business sponsor interview Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs.

Sponsored: Thinkst on building companies that don’t suck
0:00 / 21:20

Srsly Risky Biz: Ransomware uses AI to amp up negotiations

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations.

They also discuss the ever so many bugs being patched. This is good for organisations that patch, but it will leave a very long tail of unpatched vulnerabilities.

This episode is also available on YouTube

Srsly Risky Biz: Ransomware uses AI to amp up negotiations
0:00 / 20:23