Risky Business Podcast

Analysis and news podcasts published weekly

Risky Biz Soap Box: Banks to embrace Yubikeys for customers

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

As regular listeners know, the soap box podcasts we publish here at Risky.Biz are wholly sponsored. That means everyone you hear in one of these podcasts, paid to be here.

And this edition of Soap Box has become an annual thing – it’s our once-yearly catch up with Jerrod Chong, the chief solutions officer of Yubico, makers of the Yubikey and YubiHSM.

Yubikey is an infosec darling, really, because they’re in the unique position of having a product that’s popular with security professionals like CISOs while also being popular with security-conscious consumers. Businesses get value out of Yubikeys, but so do normal people, thanks to key support being baked into services like Facebook and Google.

As you’re about to hear, there’s a whole new category of use about to open up – Bank of America is launching FIDO2 U2F support for its customers. That’s a big deal – the more FIDO2 keys we get out there the better.

Risky Biz Soap Box: Banks to embrace Yubikeys for customers
0:00 / 27:40

Risky Business #627 -- USG claws back Colonial pipeline ransom money

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • US Government claws back Colonial ransom bitcoin. We don’t think the FBI acted alone.
  • Meet an0m, the cute little app for planning crimes that drinks milkshakes.
  • Ransomware stuff, duh.
  • Trickbot developer arrested in Florida
  • Supreme court upends CFAA “exceed authorised access” element
  • Much, much more

This week’s show is brought to you by Datadog. Michael Yamnitsky will be along in this week’s sponsor interview to talk about cloud security posture management. DataDog is launching a product in that space, so we’ll be hearing about the types of issues CSPM products can help to unearth.

Risky Business #627 -- USG claws back Colonial pipeline ransom money
0:00 / 56:08

Risky Business #626 -- Russian ransomware beef simmers

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Ransomware attack threatens Australian and US beef supply
  • Talos dubs Russian ransomware crews “privateers”
  • NYTimes writes another bad story
  • More Fortinet pwnage
  • Belgian government rolls Hafnium IR and finds, well, something else
  • Google unveils new rowhammer techniques
  • Much, much more

Haroon Meer of Thinkst Canary is this week’s sponsor guest. Thinkst is spinning up a labs division, but they’ll be doing something different to the same-old bug hunting. That’s a quality conversation.

Risky Business #626 -- Russian ransomware beef simmers
0:00 / 59:33

Risky Business #625 -- Iranians wipe some machines, Israelis kaboom some

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The latest news on the health system ransomware crisis in Ireland
  • TSA to force pipeline operators to disclose attacks they probably aren’t detecting anyway
  • Colonial paying ransom angers US congresspeople who really haven’t thought this through
  • Iran targets Israeli systems with new wipers
  • Israel targets Hamas systems with guided munitions that go bang
  • Much, much more

This week’s sponsor guest is Ryan Kalember, EVP of Cybersecurity Strategy at Proofpoint. He joins us to talk about how compromised o365 accounts are powering all sorts of threat actors right now – from ransomware operators to BEC crews and APT units, everyone loves a popped mailbox.

Risky Business #625 -- Iranians wipe some machines, Israelis kaboom some
0:00 / 59:31

Risky Biz Feature Podcast: The politics of cybersecurity

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this podcast we’ll be hearing from an Australian politician, Tim Watts. He’s a member of our federal parliament and serves as our shadow minister for communications and cybersecurity. For our overseas listeners, the “shadow” part of his title is there because he’s a member of the opposition party, so he’s not in government. But, of course, if the Labor party wins the next election he’ll be our communications and cybersecurity minister.

Anyway, Tim is a bit of an anomaly in politics because he has a genuine, nerd-like interest in the field we so love. Tim and I chat pretty regularly, and I can say that yes, 100%, his interest in this field is genuine and he has a firm grasp on the issues that matter.

I thought now would be a great time to run an interview on the politics of infosec. While it’s true that policymakers spend time thinking about this stuff, cybersecurity hasn’t yet crossed over into being what they call a “retail politics” issue. But thanks to the Colonial pipeline ransomware incident, that might be about to change.

Risky Biz Feature Podcast: The politics of cybersecurity
0:00 / 31:44

Risky Business #624 -- Ransomware farce continues

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The aftermath of the Colonial ransomware attack
  • Biden signs cybersecurity EO
  • DarkSide crew hounded off the Internet. For now.
  • Ransomware campaigns continue, hitting health, insurance targets globally
  • IIS PoC released
  • Rapid7 discloses Codecov-related source code breach
  • Much, much more

This week’s show is brought to you by AttackIQ. Its VP of Product Mark Bagley and Senior Director of Cybersecurity Strategy and Policy Jonathan Reiber are this week’s sponsor guests.

Risky Business #624 -- Ransomware farce continues
0:00 / 54:24

Risky Biz Snake Oilers: Google pitches BeyondCorp for Enterprise

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

As regular listeners would know, Snake OIlers is a wholly sponsored podcast series we do here at Risky Biz HQ where vendors give us money so they can come on and pitch their products to you, our dear, dear listeners.

And we have three vendors along today to pitch you:

  • Google Cloud Security is in the top slot pitching their Zero Trust product suite BeyondCorp Zero Trust for Enterprise.

  • Devicie, an Australian startup, that developed a solution that makes Microsoft Intune useable.

  • Trend Micro joins the show to talk about its latest XDR features

Risky Biz Snake Oilers: Google pitches BeyondCorp for Enterprise
0:00 / 42:58

Risky Business #623 -- Ransomware threatens US energy security

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray, Adam Boileau and Chris Krebs discuss the week’s security news, including:

  • An analysis of the Colonial pipeline ransomware attack
  • More ransomware news
  • UK and US expose APT29’s preferred exploits (again)
  • IntrusionTruth drops a new post
  • 128m Apple devices were hit by XCodeGhost
  • Much, much more

This week’s sponsor interview is with Aaron Parecki, a Senior Security Architect at Okta. He’s also been a spec editor and member of the oath working group at IETF for nearly 11 years, so he knows a thing or two about OAuth. He’ll be joining me after the week’s news to talk through the latest OAuth guidance the IETF is going to release.

Risky Business #623 -- Ransomware threatens US energy security
0:00 / 63:22

Risky Business #622 -- GitHub weighs exploit ban

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • GitHub weighs banning exploits
  • Ransomware galore
  • Belgian government crippled in DDoS attack
  • Intrusion Truth Twitter account suspended
  • More Pulsesecure victims identified
  • Much, much more

This week’s show is brought to you by ExtraHop networks, and they’ll pop along in this week’s sponsor interview to float a really, really good idea. The Biden administration EO on cybersecurity will mandate software is shipped with a so-called software bill of materials so customers will actually know what’s in their supply chain. Ben Higgins and Ted Driggs from Extrahop will join us today to argue they should also supply a bill of behaviours; data in a standardised form that will tell you things like what domains and IPs the software will connect to.

Risky Business #622 -- GitHub weighs exploit ban
0:00 / 63:07

Risky Business #621 -- Ultra professional criminal attackers ascendant

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • USA imposes sanctions over SolarWinds campaign
  • Enterprise border devices being attacked everywhere by all and sundry
  • Malvertising is coming back
  • Ultra professional criminal attackers are ascendant
  • All the latest ransomware, supply chain and other infosec news

This week’s sponsor interview is with Brian Dye, CEO of Corelight. We speak to him about what he’s calling “Open NDR”. A lot of the big SOCs have settled on their preferred ways of sharing threat information, and Brian drops by to talk all about those trends.

Risky Business #621 -- Ultra professional criminal attackers ascendant
0:00 / 69:28