Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #693 -- Hive takedown is the beginning, not the end

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A look at the Hive takedown
  • UK’s Royal Mail still struggling
  • GitHub’s code signing certificates stolen
  • TSA misses the point on no-fly list theft
  • Much, much more

This week’s show is brought to you by Remediant, which is now a part of Netwrix.

Tim Keeler is co-founder of Remediant and joins us to talk about how the PAM market – and the tech that makes it up – is changing.

Risky Business #693 -- Hive takedown is the beginning, not the end
0:00 / 0:00

Risky Biz Soap Box: Tools alone won't solve your vuln management problems

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the show Nucleus Security’s Scott Kuffer discusses Stakeholder-Specific Vulnerability Categorization (SSVC) and why tools alone can’t fix a dysfunctional vulnerability management program.

Risky Biz Soap Box: Tools alone won't solve your vuln management problems
0:00 / 0:00

Risky Business #692 -- Google search results spew malware, phishing sites

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Google’s search results have become a malware-riddled sh*tshow
  • Ransomware payment values dropped by 40% YoY in 2022
  • Kraken takes over Solaris the old school way
  • Grand Theft Auto RCE is wreaking havoc
  • ManageEngine customers are all getting owned
  • So you know, pretty much business as usual

This week’s show is brought to you by Kroll.

Jim Hung co-leads the special projects and applied research team at Kroll and joins us to talk about the big changes happening in the incident response discipline.

Risky Business #692 -- Google search results spew malware, phishing sites
0:00 / 0:00

Risky Business #691 -- LockBit and "Pablo Escobar syndrome"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Royal Mail attack was LockBit and GCHQ will probably “bust some heads”
  • CircleCI’s incident report and the problem with malwared endpoints in the Zero Trust age
  • Cloudflare backs Mastodon
  • Paul Nakasone: NSA did some great stuff! It was really good!
  • Cisco won’t patch SMB routers sold in 2020
  • Much, much more

This week’s show is brought to you by Material Security. Material co-founder Ryan Noon and Snowflake’s head of cybersecurity strategy Omer Singer are this week’s sponsor guests.

Risky Business #691 -- LockBit and "Pablo Escobar syndrome"
0:00 / 0:00

Risky Business #690 -- 2023 will be a rough year for critical online services

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the news we missed while on break. Because it’s the first show of the year, we split the discussion into themes:

  • Attacks against critical online services like Okta, CircleCI, Slack and Lastpass will increase in volume
  • All the latest global intrigue, from NSO being noped by the US Supreme Court to DDoS attacks in Serbia, Turla’s latest campaign, supply chain attacks against Ukraine, why Russia has been more active than we realised and much more
  • A ransomware wrap, a discussion about the rise of data extortion and why it’s unlikely to remain a huge problem
  • Why automotive security research will actually be interesting this year
  • PLUS: A bunch of random news!

This week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he joins us to talk about something they’ve developed – a zero knowledge proof of exploit technique. Very interesting stuff!

Risky Business #690 -- 2023 will be a rough year for critical online services
0:00 / 0:00

Risky Business #689 -- FBI baulks at Apple's iCloud encryption push

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Apple to introduce user-encrypted backups, FBI is sad
  • Twitter ices e2ee plans for DMs
  • RackSpace is getting sued over its hosted Exchange ransomware incident
  • Dodgy driving: Microsoft signs some shady stuff
  • Japan to change laws, release the Shibas
  • A look at the US NDAA
  • Much, much more

This week’s show is sponsored by Obsidian Security. Obsidian co-founder Ben Johnson joins the show this week to talk through SaaS configuration security and visibility/monitoring.

Risky Business #689 -- FBI baulks at Apple's iCloud encryption push
0:00 / 0:00

Risky Biz Soap Box: Attack Path Management is the New Hotness

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored podcast Patrick Gray and Ryan Kalember talk about Proofpoint’s acquisition of Illusive, a company that started off in the “deception” space and then moved towards doing attack path analysis and management.

Risky Biz Soap Box: Attack Path Management is the New Hotness
0:00 / 0:00

Risky Business #688 -- APT41 pickpockets Uncle Sam

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Samsung, LG Android signing keys pinched
  • LastPass gets owned again
  • APT41 steal covid relief money
  • Amnesty International hacked in Canada
  • Much, much more

This week’s show is brought to you by Airlock Digital. Its CEO and CTO join host Patrick Gray this week to talk about admin to kernel as a security boundary, and the limitations of kernel driver blocklists.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Business #688 -- APT41 pickpockets Uncle Sam
0:00 / 0:00

Risky Business #687 -- Shady deeds in sunny places: Ransomware smashes Vanuatu, Guadeloupe

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • UK, USA ban Chinese security cameras
  • What is the Boa webserver and why is it everywhere?
  • Vanuatu, Guadeloupe smashed by ransomware
  • REvil back with more dumps despite ASD attention
  • Much, much more

This week’s sponsor guest is Jake King from Elastic Security, who joins us to talk through the company’s most recent threat report. There’s a link to the report in our show notes.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Risky Business #687 -- Shady deeds in sunny places: Ransomware smashes Vanuatu, Guadeloupe
0:00 / 0:00

Risky Business #686 -- White House to move on spyware industry

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Half of all UK COBRA meetings are ransomware related
  • Ransomware biggest risk to US port security
  • White House to move on spyware industry
  • EU to launch its own Starlink equivalent
  • Much, much more

AttackIQ’s Jonathan Reiber will be joining us in this week’s sponsor interview to talk about how companies and their boards are really moving towards outcomes-based security programs.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #686 -- White House to move on spyware industry
0:00 / 0:00