Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #683 -- OpenSSL bug is a fizzer, ASD responds to Medibank hack

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Twitter bluechecks face phishing barrage
  • Australian government goes berserk on Medibank hack response
  • Former WSJ journalist sues law firm over email hack and info op that got him fired
  • OpenSSL bug lands with a whimper
  • Apple macOS Ventura update breaks security tools
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Marco Slaviero, Thinkst’s head of engineering, joins us this week to talk through the company’s latest release, codenamed Quokka.

Risky Business #683 -- OpenSSL bug is a fizzer, ASD responds to Medibank hack
0:00 / 62:51

Snake Oilers: Truffle Security, KSOC and Snyk

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Truffle Security talks secrets discovery
  • KSOC builds Kubernetes security tools
  • Snyk has a new product to better secure Infrastructure as Code
Snake Oilers: Truffle Security, KSOC and Snyk
0:00 / 38:25

Snake Oilers: Tines, Code42 and Kroll

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Tines, the no code security automation solution that people are going absolutely nuts over
  • Code42, the insider threat detection solution maker
  • Kroll talks about its MDR offering
Snake Oilers: Tines, Code42 and Kroll
0:00 / 37:59

Risky Business #682 -- Starlink goes dark on Ukraine's front line

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including:

  • Why former Uber CISO Joe Sullivan’s guilty verdict shouldn’t worry you
  • United States puts chipmaking restrictions on China, APT activity is coming
  • Elon blinks and Starlink goes dark on Ukraine’s front line
  • Master cyber criminal arrested in Australia
  • Much, much more

This week’s show is brought to you by runZero, the asset inventory and network visibility solution. runZero’s founding CTO and industry legend HD Moore is this week’s sponsor guest.

Risky Business #682 -- Starlink goes dark on Ukraine's front line
0:00 / 67:37

Risky Business #681 -- It's Exchangehog Day

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • More Exchange 0days cause more havoc
  • A look at some earlier Exchange hack incidents
  • How the CIA got its agents killed with its truly awful online opsec
  • Ex NSA staffer arrested for espionage
  • Much, much more

This week’s show is brought to you by Proofpoint. Ryan Kalember, Proofpoint’s EVP of cybersecurity strategy, joins the show this week to talk about some overlooked detection opportunities – some simple stuff you can look for in your environment that should raise gigantic flashing red flags.

Risky Business #681 -- It's Exchangehog Day
0:00 / 52:07

Risky Biz Soap Box: Why Microsoft's Smart Application Control is very strange

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box podcast Patrick Gray interviews Airlock Digital CTO Daniel Schell and CEO David Cottingham about Microsoft’s new Smart Application Control feature, why controlling browser extensions via endpoint instrumentation is really hard and why PAM solutions don’t actually do allowlisting, even if they claim they do.

Risky Biz Soap Box: Why Microsoft's Smart Application Control is very strange
0:00 / 28:05

Risky Business #680 -- Uber, Rockstar Games hacker arrested

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Lapsus$’s Teapot arrested by UK police
  • Optus hacker issues grovelling apology after feeling AFP and ASD heat
  • Ukraine claims Russia is planning massive attacks on its infrastructure
  • RSOCKS bot herder begs for extradition to USA
  • Russians scammed when seeking military service exemptions
  • Much, much more

This week’s show is sponsored by Votiro. Ravi Srinivasan, Votiro’s CEO, joins the show this week to talk about how people are using content disarm and reconstruction.

Risky Business #680 -- Uber, Rockstar Games hacker arrested
0:00 / 51:21

Risky Business #679 -- A look at Uber's very bad week

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A look at how Uber got owned so hard
  • Why cleartext cookie storage in Microsoft Teams’ Electron-based app is actually a big deal
  • Russian official: Starlink is a legitimate military target
  • Wagner mercs get doxxed
  • Kiwi Farms having a bad time
  • Much, much more

In this week’s sponsor interview we’ll be chatting to Nucleus’s CEO Steve Carter about CISA’s KEV list. He has feelings about the KEV list – they’re mostly positive, but he also has a few reasonable gripes and he joins me to talk about them.

Risky Business #679 -- A look at Uber's very bad week
0:00 / 58:21

Risky Biz Soap Box: Haroon Meer on "sensitive command tokens"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Soap Box podcast Patrick Gray talks to Haroon Meer about Thinkst Canary’s new sensitive command token. It’s a great way to detect intruders on your Windows systems. Haroon also talks about how to use canaries strategically.

Risky Biz Soap Box: Haroon Meer on "sensitive command tokens"
0:00 / 30:59

Risky Business #678 -- Iranians Gone Wild

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Albania suffers under another crippling Iranian attack
  • Iran’s APT42 using clever, multi-persona phishing
  • State Department cyber snitching program paying off
  • Former NSA director Gen. Keith Alexander sued over alleged IronNet pump and dump
  • Mudge fronts US Senate Judiciary Committee
  • Much, much more…

This week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO is this week’s sponsor guest and he talks about why they’ve pushed their Inception platform beyond YARA hunting. You can see a demo of Inception on our YouTube product demo page.

Risky Business #678 -- Iranians Gone Wild
0:00 / 51:11