Risky Bulletin Podcast feed

Daily podcasts featuring news bulletins and discussion shows...

Risky Bulletin: Dutch police take down 17m device botnet

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer is arrested for insider trading on Polymarket, and Gogs and the Casdoor IAM leave major bugs unpatched.

Risky Bulletin: Dutch police take down 17m device botnet
0:00 / 8:45

Risky Bulletin: Iran to reconnect to the Internet

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Iran will reconnect to the Internet, a new vulnerability lets attackers bypass authentication on AI infrastructure, hackers breach Lithuania’s state registry, security firms take down the Glassworm botnet, and CERT India releases strict patching advice.

Risky Bulletin: Iran to reconnect to the Internet
0:00 / 6:14

Risky Bulletin: Mythos has found thousands of critical bugs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Anthropic says Mythos has found thousands of critical bugs, hackers leak documents from a Russian disinfo group, GitHub rolls out new npm security features, and Dutch police raid two bulletproof hosting providers.

Risky Bulletin: Mythos has found thousands of critical bugs
0:00 / 8:15

Sponsored: Teaching AI agents the rules of the road

Presented by

James Wilson
James Wilson

Technology Editor

In this sponsored interview James Wilson chats with Sondera CEO Josh Devon about why guardrails and instruction files aren’t enough to keep AI agents from going haywire. EDR, DLP and other traditional controls can’t and won’t prevent agents from going rogue.

Josh explains Sondera’s “principle of least autonomy” for agents: let them do useful work, but put them in a deterministic policy harness so they can’t leak secrets, abuse tools or wander off-task.

Sponsored: Teaching AI agents the rules of the road
0:00 / 26:54

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Microsoft ends support for SMS MFA on personal accounts, GitHub was hacked via a malicious VS Code extension, CISA will let researchers submit new KEV entries, and an SMS blaster was detained at Eurovision.

Risky Bulletin: Microsoft ends SMS MFA for personal accounts
0:00 / 9:00

Srsly Risky Biz: Politicians ditch Signal for homegrown apps

Presented by

James Wilson
James Wilson

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and James Wilson talk about moves from several European governments to ditch Signal and set up their own encrypted messaging systems for internal government use. These efforts are motivated by concerns about phishing and sovereignty, but the solutions being adopted are imperfect and will come with their own set of problems. Signal fills a space that can’t be filled with sovereign capability.

They also talk about Fast16 malware. We are only now learning about the second arm of a mid-2000s campaign to delay Iran’s nuclear weapons program that included the infamous Stuxnet worm.

This episode is also available on YouTube

Srsly Risky Biz: Politicians ditch Signal for homegrown apps
0:00 / 28:45

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Microsoft disrupts a malware-signing service used by ransomware gangs, a CISA contractor leaks sensitive GovCloud keys, vulnerability exploitation is now the dominant network entry vector, and Drupal readies security updates for a “highly critical” vulnerability.

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs
0:00 / 8:50

Between Two Nerds: Russia's hacker university

Presented by

The Grugq
The Grugq

Independent Security Researcher

Tom Uren
Tom Uren

Policy & Intelligence

In this edition of Between Two Nerds Tom Uren and The Grugq look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russia’s cyber program and look at what Western intelligence agencies do instead.

This episode is also available on YouTube.

Between Two Nerds: Russia's hacker university
0:00 / 29:22

Risky Bulletin: Indonesia emerges as a new hub for cyber scams

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Claire Aird
Claire Aird

Newsreader

Indonesia emerges as a new cyber scam hub, Grafana got hacked and held for ransom, the Fast16 malware subverted software used to simulate nuclear explosions, and a new Microsoft Exchange zero-day is under attack.

Risky Bulletin: Indonesia emerges as a new hub for cyber scams
0:00 / 10:10

Sponsored: Push Security goes AI threat hunting in browser telemetry

Presented by

James Wilson
James Wilson

Technology Editor

In this sponsored interview James Wilson chats with Push Security’s Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform.

Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers.

Sponsored: Push Security goes AI threat hunting in browser telemetry
0:00 / 14:01