Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #681 -- It's Exchangehog Day

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • More Exchange 0days cause more havoc
  • A look at some earlier Exchange hack incidents
  • How the CIA got its agents killed with its truly awful online opsec
  • Ex NSA staffer arrested for espionage
  • Much, much more

This week’s show is brought to you by Proofpoint. Ryan Kalember, Proofpoint’s EVP of cybersecurity strategy, joins the show this week to talk about some overlooked detection opportunities – some simple stuff you can look for in your environment that should raise gigantic flashing red flags.

Risky Business #681 -- It's Exchangehog Day
0:00 / 52:07

Risky Biz Soap Box: Why Microsoft's Smart Application Control is very strange

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box podcast Patrick Gray interviews Airlock Digital CTO Daniel Schell and CEO David Cottingham about Microsoft’s new Smart Application Control feature, why controlling browser extensions via endpoint instrumentation is really hard and why PAM solutions don’t actually do allowlisting, even if they claim they do.

Risky Biz Soap Box: Why Microsoft's Smart Application Control is very strange
0:00 / 28:05

Risky Business #680 -- Uber, Rockstar Games hacker arrested

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Lapsus$’s Teapot arrested by UK police
  • Optus hacker issues grovelling apology after feeling AFP and ASD heat
  • Ukraine claims Russia is planning massive attacks on its infrastructure
  • RSOCKS bot herder begs for extradition to USA
  • Russians scammed when seeking military service exemptions
  • Much, much more

This week’s show is sponsored by Votiro. Ravi Srinivasan, Votiro’s CEO, joins the show this week to talk about how people are using content disarm and reconstruction.

Risky Business #680 -- Uber, Rockstar Games hacker arrested
0:00 / 51:21

Risky Business #679 -- A look at Uber's very bad week

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A look at how Uber got owned so hard
  • Why cleartext cookie storage in Microsoft Teams’ Electron-based app is actually a big deal
  • Russian official: Starlink is a legitimate military target
  • Wagner mercs get doxxed
  • Kiwi Farms having a bad time
  • Much, much more

In this week’s sponsor interview we’ll be chatting to Nucleus’s CEO Steve Carter about CISA’s KEV list. He has feelings about the KEV list – they’re mostly positive, but he also has a few reasonable gripes and he joins me to talk about them.

Risky Business #679 -- A look at Uber's very bad week
0:00 / 58:21

Risky Biz Soap Box: Haroon Meer on "sensitive command tokens"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Soap Box podcast Patrick Gray talks to Haroon Meer about Thinkst Canary’s new sensitive command token. It’s a great way to detect intruders on your Windows systems. Haroon also talks about how to use canaries strategically.

Risky Biz Soap Box: Haroon Meer on "sensitive command tokens"
0:00 / 30:59

Risky Business #678 -- Iranians Gone Wild

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Albania suffers under another crippling Iranian attack
  • Iran’s APT42 using clever, multi-persona phishing
  • State Department cyber snitching program paying off
  • Former NSA director Gen. Keith Alexander sued over alleged IronNet pump and dump
  • Mudge fronts US Senate Judiciary Committee
  • Much, much more…

This week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO is this week’s sponsor guest and he talks about why they’ve pushed their Inception platform beyond YARA hunting. You can see a demo of Inception on our YouTube product demo page.

Risky Business #678 -- Iranians Gone Wild
0:00 / 51:11

Risky Business #677 -- A day late and a dollar short: China doxxes NSA op

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • China’s super spies figure out Rob Joyce ran TAO ops
  • FBI, French authorities fly to Montenegro to investigate ransomware attack
  • NEWSFLASH: Cloudflare are still a bunch of Nazi cuddlers
  • SIM swap drama spills into real world shootings, firebombings
  • Yandex Taxi hack clogs Moscow streets
  • The TikTok breach that wasn’t
  • Project Raven veterans get wings clipped
  • Why recent BGP hijacks are getting a bit concerning
  • Much, much more

This week’s show is brought to you by Corelight, the company that maintains Zeek. Corleight’s Federal CTO Jean Schaffer joins us in this week’s sponsor interview to talk about whether or not the White House’s executive order on Zero Trust is actually changing anything.

Risky Business #677 -- A day late and a dollar short: China doxxes NSA op
0:00 / 58:43

Risky Business #676 -- Okta, Authy users among Twilio hack targets

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The Twilio breach was actually a big deal
  • How a Belarusian Cyber Partisans hack burned a GRU illegal
  • Who wants 25m hashed passwords from Russia?
  • An NFT we can get behind
  • How attackers are using game anti-cheat drivers to defeat EDR
  • Much, much more

This week’s sponsor interview is with Mike Benjamin, the VP of security research at Fastly. He pops in to argue that your red team needs to actually consider how your apps will cope with bot-driven attacks.

Risky Business #676 -- Okta, Authy users among Twilio hack targets
0:00 / 55:17

Risky Business #675 -- The problem with Mudge's whistleblowing complaint

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A deep look at Mudge’s sensational whistleblower complaint against Twitter
  • Brazilian Federal Police raid Lapsus$ crew
  • NSO CEO to stand down (again), 100 staff to be let go
  • Signal users impacted in Twilio incident
  • Tornado Cash OFACs around and finds out
  • Much, much more

This week’s show is brought to you by Greynoise. Its founder, Andrew Morris, joins the show with a stinging critique of the wider threat intelligence industry. Don’t miss that one.

Risky Business #675 -- The problem with Mudge's whistleblowing complaint
0:00 / 65:45

Risky Biz Soap Box: Okta's Brett Winterford on session cookie theft and mitigations

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Soap Box podcast Okta’s APAC CISO and former Risky Biz editor Brett Winterford talks about how attackers are getting much better at swiping session cookies via realtime phishing and malware.

He also talks about some mitigation strategies to combat this threat and introduces the concept of continuous authentication.

Risky Biz Soap Box: Okta's Brett Winterford on session cookie theft and mitigations
0:00 / 40:58