Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #674 -- "Free money" exploit spawns $150m blockchain feeding frenzy

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Taiwan tensions fail to conjure the cyber apocalypse
  • Crypto bridge exploit results in $150m feeding frenzy
  • Chainalysis evidence to be challenged in court
  • Post-quantum NIST candidate algorithm gets smoked
  • DSIRF’s Russia links
  • Much, much more

This week’s sponsor interview is with Jerrod Chong from Yubico. He’s joining the show to talk about why consumer-focussed implementations of Webauthn like Apple’s Passkeys aren’t a great enterprise solution.

Risky Business #674 -- "Free money" exploit spawns $150m blockchain feeding frenzy
0:00 / 46:27

Risky Business #673 -- When throwing computers into a woodchipper is standard IR

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why Entrust being ransomwared is good news
  • UEFI bootkits turn hardware into landfill
  • Microsoft resumes macro blocking rollout
  • Pat and Adam talk about why plugging your IDP into legacy apps is a dreadful idea
  • Much, much more

This week’s sponsor guest is Paul “The Voice” Lanzi of Remediant. He’s popping along to talk about the emergence of a new product category – Identity Threat Detection and Response, or ITDR.

Risky Business #673 -- When throwing computers into a woodchipper is standard IR
0:00 / 58:15

Risky Business #672 -- "Expected behaviour" is in the eye of the beholder

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A look at the DHS Cyber Safety Review Board’s Log4j report
  • Joshua Schulte no longer the “alleged” Vault7 leaker
  • Chinese APT crews targeted US political journalists before Jan 6
  • Ransomware gangs make leak sites searchable
  • Why recovering plaintext passwords from Okta is expected behaviour
  • US Government seizes North Korean ransomware payment
  • Much, much more

This week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he’ll tell us about work Trail of Bits did for DARPA on investigating blockchain security fundamentals.

Risky Business #672 -- "Expected behaviour" is in the eye of the beholder
0:00 / 53:32

Risky Business #671 -- The case for an American-owned NSO Group

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and guest cohost Dmitri Alperovitch discuss the week’s security news, including:

  • Why an American defence contractor acquiring NSO Group would be a nonproliferation win
  • A look at Microsoft’s botched macro measures
  • iPhone’s Lockdown Mode
  • Ukraine goes big on Yubikeys
  • Aerojet Rocketdyne pays millions over poor security controls, CISO whistleblower gets bag of cash
  • Much, much more

This week’s show is sponsored by Proofpoint. Ryan Kalember, Proofpoint’s Executive Vice President of Cybersecurity Strategy, joins us in this week’s sponsor interview to talk about changes he’s observed in the criminal ecosystem.

Risky Business #671 -- The case for an American-owned NSO Group
0:00 / 58:00

Risky Biz Soap Box: Running a global vulnerability management program

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Today’s soap box is brought to you by Nucleus Security.

Nucleus makes a platform that ingests vulnerability scan information from all your vuln scanning tech so that you can do things like assign different vulnerabilities to different teams to manage and remediate. Send these ones to infrastructure, send these ones to app teams, send everything up and down this stack to this department etc.

If you want to see Nucleus in action I have recorded a demo and it’s on our YouTube product demos page, I’ve linked through to it in the show notes for this podcast.

Our guest in this episode is Scott Kuffer, co-founder of Nucleus, and the topic is running a vulnerability management program in a very large enterprise.

Risky Biz Soap Box: Running a global vulnerability management program
0:00 / 35:28

Risky Business #670 -- China's world record data breach

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and guest cohost Mark Piper discuss the week’s security news, including:

  • A billion records leaked in China
  • China to develop desktop operating system
  • HackerOne fires insider for stealing hackers’ work and bounties
  • FSB officer charged with stealing hacker’s bitcoin
  • Why Microsoft is wrong on Russia and Ukraine
  • Much, much more

Red Canary’s Adam Mashinchi and Brian Donohue will be along in this week’s sponsor interview to talk about Atomic Red Team, the open source adversary emulation framework they help to maintain.

Risky Business #670 -- China's world record data breach
0:00 / 63:06

Risky Business #669 -- Finally, an ICS attack that made stuff explode!

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Activists who are totally not Israeli military hackers make Iranian steel mills firebally
  • Chinese APT crews use ransomware to muddy attribution
  • Attackers are now ransoming cloud access
  • Chinese APTs using building control systems for persistence and stealth
  • USA, UK and NZ govts issue PowerShell advice
  • Much, much more

This week’s show is brought to you by Material Security. JJ Agha, CISO at Compass, joins the show to talk about how he’s using it to make phishing triage and automation less traumatic.

Risky Business #669 -- Finally, an ICS attack that made stuff explode!
0:00 / 67:15

Risky Biz Soap Box: HD Moore on taking Rumble to the cloud

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Today’s Soap Box guest is an industry legend – Metasploit creator HD Moore. He’s here to tell us more about what’s happening with his latest creation, Rumble Network Discovery.

Risky Biz Soap Box: HD Moore on taking Rumble to the cloud
0:00 / 27:04

Risky Business #668 -- Microsoft is hiding its Azure security problems

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Paige Thompson guilty of Capital One hack
  • Microsoft is hiding serious Azure security issues
  • New Australian government lobbying for Julian Assange
  • How to ransomware documents in the cloud
  • Microsoft stops Windows 10/11 downloads in Russia
  • Belarusian cyber partisans obtain spy agency’s audio recordings
  • Much, much more

This week’s edition of the show is brought to you by Gigamon. Josh Day, Gigamon’s Director of applied threat research team, will be along in this week’s sponsor interview to talk about detecting badness on your network in encrypted traffic.

Risky Business #668 -- Microsoft is hiding its Azure security problems
0:00 / 64:53

Risky Business #667 -- "Shields Up" for cyber's forever war

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • “Shields Up” advice is now provably meaningless
  • Russia to ditch offshore comms apps like WhatsApp
  • Evil Corp’s Lockbit sanctions evasion attempt backfires
  • Binance is a cesspit of shady financial dealings
  • Apple’s passkey release foreshadows FIDO mass adoption
  • Much, much more

This week’s sponsor interview is about Elastic’s teardown on some really interesting APT linux malware called BPFdoor. Jake King and Colson Wilhoit joined the show for that interview.

Risky Business #667 -- "Shields Up" for cyber's forever war
0:00 / 58:53