Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #769 -- Sophos drops implants on Chinese exploit devs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Sophos drops implants on Chinese firewall exploit devs
  • Microsoft workshops better just-in-time Windows admin privileges
  • Snowflake hacker arrested in Canada
  • Okta has a fun, but not very impactful auth-bypass bug
  • Russians bring dumb-but-smart RDP client attacks
  • And much, much more.

Special guest Sophos CISO Ross McKerchar joined us to talk about its “hacking back” campaign. The full interview is available on Youtube for those who want to really live vicariously through Sophos doing what every vendor probably wants to do.

This week’s episode is sponsored by attack surface mapping vendor runZero. Founder and CEO HD Moore joins to talk about marrying up the outside and inside views of your network.

You can also watch this episode on Youtube

Risky Business #769 -- Sophos drops implants on Chinese exploit devs
0:00 / 0:00

Risky Business #768 -- CSRB will investigate China's Wiretap Hacks

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • CSRB to investigate China’s telco-wiretapping hacks
  • Euro law enforcement takes down the Redline infostealer
  • Someone steals Fed crypto… and then tries to quietly sneak it back in
  • Russia sentences REvil guys to … jail? Really?
  • Apple private cloud compute gets a proper bug bounty program
  • And much, much more.

This week’s episode is sponsored by Material Security, who help navigate the mess of cloud productivity data security. Daniel Ayala - Chief Security and Trust Officer at Dotmatics - is a Material customer, and joins Pat and Material Security’s Rajan Kapoor to talk about how to wrangle securing data that ends up in corporate cloud email and file stores.

This episode is also available on Youtube.

Risky Business #768 -- CSRB will investigate China's Wiretap Hacks
0:00 / 0:00

Risky Biz Soap Box: Thinkst Canary's decade of deception

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the podcast Patrick Gray chats with Thinkst Canary founder Haroon Meer about his “decade of deception”, including:

  • A history of Thinkst Canary including a recap of what they actually do
  • A look at why they’re still really the only major player in the deception game
  • A look at what companies like Microsoft are doing with deception
  • Why security startups should have conference booths
Risky Biz Soap Box: Thinkst Canary's decade of deception
0:00 / 0:00

Risky Business #767 – SEC fines Check Point, Mimecast, Avaya and Unisys over hacks

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • SEC fines tech firms for downplaying the Solarwinds hacks
  • Anonymous Sudan still looks and quacks like a Russian duck
  • Apple proposes max 10 day TLS certificate life
  • Oopsie! Microsoft loses a bunch of cloud logs
  • Veeam and Fortinet are bad and should feel bad
  • North Koreans are good (at hacking)
  • And much, much more.

This week’s episode is sponsored by Proofpoint. Chief Strategy Officer Ryan Kalember joins to talk about their work keeping up with prolific threat actor SocGholish.

This episode is also available on Youtube.

Risky Business #767 – SEC fines Check Point, Mimecast, Avaya and Unisys over hacks
0:00 / 0:00

Risky Business #766 – China hacks America's lawful intercept systems

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s infosec news, including:

  • Chinese spooks all up in western telco lawful intercept
  • Jerks ruin the Internet Archive’s day
  • Microsoft drops a great report with a bad chart
  • The feds make their own crypto currency and get it pumped
  • Forti-, Palo- and Ivanti-fail
  • And much, much more.

This week’s episode is sponsored by detection-as-code vendor Panther. Casey Hill, Panther’s Director Product Management joins to discuss why the old “just bung it all in a data lake and… ???… “ approach hasn’t worked out, and what smart teams do to handle their logs.

This episode is also available on [Youtube].(https://youtu.be/86zy6DcwtbE)

Risky Business #766 – China hacks America's lawful intercept systems
0:00 / 0:00

Snake Oilers: Sandfly Security, Permiso and Wiz

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of Snake Oilers we hear pitches from three security vendors:

  • Sandfly Security: An agentless Linux security platform that actually sounds very cool
  • Permiso: An identity security platform founded by ex FireEye folks
  • Wiz: The cloud security giant is getting in on code security scanning

You can watch this edition of Snake Oilers on YouTube here.

Snake Oilers: Sandfly Security, Permiso and Wiz
0:00 / 0:00

Risky Business #765 -- The Kaspersky switcheroo

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

Patrick Gray and Adam Boileau discuss the week’s infosec news with everyone’s favourite ex-NSA big-brain, Rob Joyce. They talk through:

  • Musk and Durov bow to government pressure
  • Tiktok rushes to ban authoritarian propagandists
  • The US doesn’t want Chinese software in its cars
  • Kaspersky replaces itself with an AV no one has ever heard of
  • Aussie police chalk up another crimephone takedown
  • Press Win-R Ctrl-V to prove you’re human
  • And much, much more.

This week’s show is brought to you by Stairwell, and Stairwell’s founder Mike Wiacek will be along to talk about how people are using their platform to hunt down detection resistant malware.

A video version of this episode is also available on Youtube.

Risky Business #765 -- The Kaspersky switcheroo
0:00 / 0:00

Risky Business #764 -- Mossad expands into telecommunications services

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray and Adam Boileau discuss the weeks security news, including:

  • Hezbollah’s attempts to avoid SIGINT with pagers ends in explosions
  • The US shines many bright lights on RT’s disinfo role
  • Australia counters Chinese bullying in the Pacific
  • Valid accounts are the most prevalent entry point, says CISA’s data
  • Ivanti and Fortinet vie for worst vendor of the week
  • Krebs writes up the shift towards charging The Com with terrorism
  • And much, much more…

This week’s episode is sponsored by Push Security, who bring security visibility to where it needs to be these days – the browser. Luke Jennings joins this week’s show to discuss how phish-kit crews are driving the arms race forward, and how detection has to adapt and go where the users are.

This episode is also available on Youtube.

Risky Business #764 -- Mossad expands into telecommunications services
0:00 / 0:00

Risky Business #763 – Microsoft un-patches critical bug

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show, Patrick Gray and Adam Boileau discuss the weeks security news, including:

  • Russia’s disinformation peddlers face multifaceted sternness from the DoJ
  • Telegram is now law enforcement’s bestest new pal, all of a sudden
  • Iran’s banking industry arranges a payment plan for a ransom
  • Columbia investigates how it sent private jets full of cash to pay for Pegasus
  • Microsoft innovates with Un-Patch Tuesday
  • And much, much more.

This week’s sponsor is Kroll Cyber, and one of their incident responders Paul Wells joins to discuss that one weird trick that actually helps - preparing for an incident before hand, rather than learning all those hard lessons in the middle of a crisis.

This week’s episode is also available on Youtube.

Risky Business #763 – Microsoft un-patches critical bug
0:00 / 0:00

Snake Oilers: Authentik, Dropzone and SlashID

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of Snake Oilers Patrick Gray gets pitches from three cybersecurity companies:

  • Authentik, an open source identity provider that a lot of large organisations are deploying on prem as an alternative to cloud-based IDPs
  • Dropzone AI, an LLM-based agent that can do the work of a Tier 1 SOC analyst
  • SlashID, an identity security company that can crunch your logs to find attackers

You can watch this edition of Snake Oilers on YouTube here.

Snake Oilers: Authentik, Dropzone and SlashID
0:00 / 0:00