Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #658 -- Germany sounds alarm on Kaspersky software

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Germany issues stark warning to Kaspersky users
  • Ukraine SATCOM hack keeps getting more interesting
  • Russia to spin up its own CA, but it’s not what it seems
  • Why the ransomware threat could get worse, then better
  • Much, much more

This week’s show is brought to you by Fastly. Kelly Shortridge, Fastly’s Senior Principal Product Technologist, joins the show this week to tell us what modern security actually looks like. Kelly is always fascinating so we were thrilled she was in the sponsor chair this week.

Risky Business #658 -- Germany sounds alarm on Kaspersky software
0:00 / 0:00

Risky Business #657 -- Belarus targets refugee data

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray, Brian Krebs and Adam Boileau discuss the week’s security news, including:

  • The Contileaks latest
  • Belarus targeted refugee data. Was it behind the ICRC hack?
  • How APT41 hacked America’s livestock
  • SATCOM hack in Ukraine may bode ill for Musk
  • Much, much more

Material Security’s co-founder Ryan Noon is this week’s sponsor guest. He joins the show to talk about a few things, how the building blocks for a whole new generation of security tooling – like large-scale data crunching tech – is now just available off the shelf. He also talks us through an integration Material has done with a groovy new SOAR platform called Tines.

Risky Business #657 -- Belarus targets refugee data
0:00 / 0:00

Risky Business #656 – We expected a cyberwar but got an infowar

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray, Dmitri Alperovitch and Adam Boileau discuss the week’s security news, including:

  • We expected a cyberwar but got an information war
  • People with SDR kits are doing SIGINT in Ukraine
  • Conti has imploded and it’s hilarious
  • Much, much more

This week’s show is brought to you by Proofpoint. Sherrod DeGrippo, Proofpoint’s Vice President of Threat Research and Detection is this week’s sponsor guest. She joins us to talk about how there isn’t really any magic advice she can dispense to protect customers from Russian attacks.

There are some show notes below, but they’re not exhaustive.

Risky Business #656 – We expected a cyberwar but got an infowar
0:00 / 0:00

Risky Biz Soap Box: US Government will embrace "phishing resistant MFA"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

These Soap Box editions of the show are entirely sponsored – that means everyone you hear in one of these episodes paid to be here.

In this edition we’re talking to Yubico’s Chief Solutions Officer Jerrod Chong. We do one of these Soap Box podcasts with Jerrod every year. Yubico, of course, is the maker of the Yubikey hardware security device.

In this chat with Jerrod we cover a few things – like the zero trust executive order, hardware-backed web transactions and how the industry leading the charge on security keys right now is actually the cryptocurrency space.

Risky Biz Soap Box: US Government will embrace "phishing resistant MFA"
0:00 / 0:00

Risky Business #655 -- USG: Expect Russian cyber drama

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Ukraine sanctions may lead to Russia going “cyber feral”
  • Brian Krebs links Red Cross breach to Iranian actor
  • APT10 uses cred stuffing as misdirection
  • Report: Global logistics behemoth Expeditors ransomwared
  • NFT thefts still hilarious
  • Inside the epic KlaySwap hack
  • Much, much more

In this week’s sponsor interview Thinkst Canary’s Marco Slaviero talks about some work they’ve done on introducing a “Safety Net” against AWS token enumeration edge cases. That’s a very interesting interview.

Risky Business #655 -- USG: Expect Russian cyber drama
0:00 / 0:00

Risky Biz Feature: "Everyone has a plan until they get punched in the face"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

There is no weekly news show this week. Instead, we’re running this feature interview with Michael Montoya, the CISO of Equinix. This isn’t a sponsored interview or anything like that, this podcast was prepared with support from the Hewlett Foundation’s Cyber Initiative.

Equinix has 9,000 staff and operates 220 data centres globally. Its annual revenue is in the order of USD$6bn. In September 2020 it was attacked by criminals who deployed the Netwalker ransomware on its corporate network. The attackers demanded a USD$4.5m ransom payment for service restoration and to keep the data they stole from the company private.

This interview has taken a while to organise, but when I first found out Michael was open to the idea of talking through the incident I jumped at it. It’s extremely rare for CISOs to be made available to talk about events like this, but it’s something that should happen more often. We can learn a lot by dissecting these types of incidents publicly. Enjoy!

Risky Biz Feature: "Everyone has a plan until they get punched in the face"
0:00 / 0:00

Risky Business #654 -- FBI arrests deeply annoying cryptocurrency influencers

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A spate of ransomware attacks on European energy and transport
  • Russian authorities extend cybercrime crackdown
  • Irritating influencers arrested for laundering 2016 Bitfinex hack proceeds
  • IRS abandons ID.me trial
  • Microsoft disables macros by default, disables MSIX protocol handler
  • Much, much more

This week’s show is brought to you by ExtraHop.

Extrahop’s Ted Driggs is this week’s sponsor guest – he was on the show about a year ago talking about how we should really start thinking about putting together software bills of behaviours as well as bills of material. Ted is back to tell us how that effort is progressing. As you’ll hear, a lot of the behavioural data on software already exists, but it’s being hoarded by different vendors.

Risky Business #654 -- FBI arrests deeply annoying cryptocurrency influencers
0:00 / 0:00

Risky Biz Soap Box: The state of malicious mass scanning with Andrew Morris

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

These soap box podcasts are wholly sponsored – that means everyone you hear in one of these editions paid to be here. Today’s guest is Andrew Morris, the founder and CEO of Greynoise.

Greynoise is one of those companies that has a brief that sounds simple but is actually quite hard to execute on. They detect malicious mass scanning on the Internet so their customers can plug that data into their SOC to see if the IP they just got an alert on is something targeting them or something targeting the whole internet.

You don’t even need to be a customer to get some use out of Greynoise. If you want to know about an IP you’ve seen an alert for just head over to greynoise.io and drop it into the search box – magic awaits.

Greynoise makes its money by selling API access to its service, basically, and its customers mostly use it for SIEM enrichment. But as you’ll hear, Andrew says the company is looking at moving toward actually blocking this type of mass scanning from hitting customer environments, and is even looking at working with telcos to scrub the most egregious stuff from the internet entirely. His rationale is actually pretty simple – he wants to narrow the aperture through which mass scanning can fit through. He wants to make it harder.

But this interview isn’t just about what Greynoise doing, it’s also about the current state of mass scanning.

Risky Biz Soap Box: The state of malicious mass scanning with Andrew Morris
0:00 / 0:00

Risky Business #653 -- REvil arrests: Sometimes a banana is just a banana

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray, Tom Uren and Joe Slowik discuss the week’s security news, including:

  • Why China’s Olympics app is probably not spyware
  • New DDoS record set at 3.47Tbps
  • USG goes all in on Zero Trust
  • Dmitry Medvedev makes all the right noises on ransomware cooperation
  • Iranian APT crew dabbles in ransomware
  • German fuel distribution ransomwared
  • The latest on NSO
  • Much, much more

This week’s show is brought to you by Google Cloud. Anton Chuvakin, the head of security solution strategy at Google Cloud will be along in this week’s sponsor interview to talk about why SIEM vendors – including Google Cloud – are gobbling up SOAR platforms in acquisitions.

Links to everything that we discussed are below and you can follow Patrick, Tom or Joeon Twitter if that’s your thing.

Risky Business #653 -- REvil arrests: Sometimes a banana is just a banana
0:00 / 0:00

Risky Business #652 -- Cyber Partisans take down Belarusian rail systems

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Belarusian Cyber Partisans ransom train network
  • A look at developments in Ukraine
  • Merck wins NotPetya insurance lawsuit
  • US VC firm in talks to acquire NSO Group
  • Much, much more

This week’s show is brought to you by Trail of Bits, the security engineering firm. Dan Guido joins us this week week to talk about zkdocs, a bunch of documentation Trail of Bits put together to provide guidance on how to implement some of these newfangled concepts – like zero knowledge proofs – that are popular in blockchain and cryptoland.

Risky Business #652 -- Cyber Partisans take down Belarusian rail systems
0:00 / 0:00