Risky Business Podcast

Analysis and news podcasts published weekly

Risky Business #541 -- NSO Group makes global headlines. What next?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick and Adam talk through all the week’s security news, including:

  • NSO Group WhatsApp vuln coverage goes nuclear
  • Activists targeted by NSO malware in hiding in west after CIA tipoffs
  • Cisco Trust Anchor drags on sea floor
  • Linux kernel bugs likely overhyped
  • Adobe patches insane number of CVEs
  • Microsoft patches rumoured GCHQ VEP’d RDP bug
  • New hardware bugs affect Intel processors
  • SHA-1 collisions become much more practical
  • Major US anti-virus firms owned hard

This week’s sponsor interview with Ryan Kalember of Proofpoint. Ryan is a listener, and when he heard Adam talking about how password rotations actually result in crappy passwords, it hit a nerve with him. He says Proofpoint, via its CASBY product, is seeing a lot of targeted credential stuffing campaigns cycling through variations of passwords that have appeared in dumps.

Apparently the bad guys are hip to what a typical password rotation variation looks like and they’re using this knowledge to better direct their cred stuffing attempts.

Links to everything are below, and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #541 -- NSO Group makes global headlines. What next?
0:00 / 64:26

Risky Business #540 -- In depth: Hamas cyber unit destroyed in air strike

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • IDF takes out Hamas cyber HQ (Features commentary from Bobby Chesney and Klon Kitchen)
  • NYTimes mangles Symantec’s “Buckeye” research
  • Lots of dark web arrests
  • SAP exploits not all they’re cracked up to be
  • Magecart-style attacks spread to other platforms
  • Tech-led crackdown on Chinese-muslims intensifies
  • Japan to create “defensive malware”

This week’s sponsor interview is with Duo Security advisory CSO Richard Archdeacon and we’ll be talking about zero trust networks. Richard isn’t so worried about every vendor under the sun claiming to be a zero trust tech company. He doesn’t think that’s going to derail the move to zero trust architectures because the move towards them is too strong.

Links to everything are below, and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #540 -- In depth: Hamas cyber unit destroyed in air strike
0:00 / 56:44

Snake Oilers 9 part 2: Rapid7 talks SOAR, Trend Micro on its API-based email security play

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

This isn’t the regular weekly risky biz news and current affairs show, this is the special podcast series we do here at Risky Biz HQ where we take that dirty, dirty vendor cash and let security companies tell the audience all about what they do. Think of it as show and tell for security vendors!

In this edition we’ve got three more vendors vying for your hard-earned bread. We’ll be hearing from Rapid7 on their InsightConnect product, that one used to be known as Komand. What can you automate and orchestrate with it? How does it work? Who’s using it? What are they doing with it?

Then we’ll be hearing from Trend Micro about their O365 mail security product, and this one is legit interesting for one very simple reason – the deployment method. Most of the mail security firms basically make you route your mail through them.

In this case what Trend has done is create a mail security product that just fiddles with your mailboxes through the Microsoft O365 API. They have literally set up a demo account for an enterprise over a beer at a bar. So yeah, I suspect we’ll be seeing more mail security products deploying this way… and because it’s show and tell, Trend will be along to talk about some of the bells and whistles that come with that product.

Then finally we’ll be hearing from Cybermerc. This is a group based out of Canberra in Australia. They’ve done a lot of enterprise deception hybrid hardware/consulting, that’s something they’ve gotten very good at. They also do a lot of cyber cyber training, but now they’re trying to market a managed service towards small to medium businesses – those with 50 to a few hundred seats. A managed honeypot, some internal vuln scans, and a partridge in a pear tree!

Snake Oilers 9 part 2: Rapid7 talks SOAR, Trend Micro on its API-based email security play
0:00 / 37:47

Risky Business #539 -- Docker Hub owned, Cloudflare, Bloomberg under fire

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Docker Hub owned
  • That Confluence bug we were talking about a couple of weeks ago got wormified
  • Oracle WebLogic users also having a bad time
  • Cloudflare faces investor pressure over providing services to Nazis
  • Slack warns investors of possible nation-state attacks against it
  • Norsk Hydro puts dollar value on ransomware incident
  • Bloomberg publishes another ridiculous security story
  • Much, much more!

This week’s sponsor interview is with Casey Ellis, the CTO and co-founder of Bugcrowd.

As most of you are probably aware, Bugcrowd announced its so-called “next generation penetration testing” product last year, a move followed some months later by its competitor HackerOne. With others in the bounty space already offering these types of penetration testing packages, it looks like these efforts are here to stay.

But where do crowdsourced penetration tests sit in the wider penetration testing market? Are they coming after the Insomnia and Atredis Partners type firms? The NCCs? The shonky nessus-scan “penetration testers”? Well, not surprisingly Casey argues that this is a new sub-niche in the market and he makes a pretty compelling case to support that argument.

Links to everything are below, and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #539 -- Docker Hub owned, Cloudflare, Bloomberg under fire
0:00 / 52:15

Risky Business #538 -- Marcus Hutchins is a milkshake duck, Iranian APTs doxxed and more

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Marcus Hutchins faces his milkshake duck moment
  • Iranian APT crew gets Shadowbrokersed
  • DNS interference campaign is actually two large-scale actors
  • UK to use some Huawei components in 5G build
  • French Government launches comms app for politicians, it doesn’t go well
  • More detail on CCleaner/ASUS crew
  • Carbanak source found on VT (lol)
  • Wall Street Market exit scams
  • BEC costing US firms $1.3bn PA
  • Much MOAR!

This week’s show is brought to you by Signal Sciences, their CEO Andrew Peterson will be along in this week’s sponsor interview to have a bit of a chat about how a lot of traditional enterprises are running serious business web app shops these days.

Links to everything are below, and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #538 -- Marcus Hutchins is a milkshake duck, Iranian APTs doxxed and more
0:00 / 54:37

Snake Oilers 9 part 1: The best Snake Oilers edition we've ever run

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

On this edition of Snake Oilers you’ll be hearing from three vendors offering what I believe to be excellent security technology. I haven’t personally used this tech, but conceptually everything featured in this edition is The Good Stuff. You’ll see. Or hear. You know what I mean.

First up we’ll be hearing from CMD, they make killer software for Linux that lets you lock down account actions. Not permissions, actions. Do all the default and service accounts you have to run on your Linux fleet terrify you? Well, this is a solution for that. There’s a visibility component there, too.

Then we’ll be hearing from AlphaSOC. When we last spoke to them they were just doing domain-based analytics, but they’ve expanded their tech and now offer IP-based and http request-based analytics. You can deploy AlphaSOC as a Splunk app or hook up to their API any other way you want. They’re offering free trials, but even when you’re on the paid service it’s actually pretty affordable.

The brain behind AlphaSOC is Chris McNab who used to run incident response at NCC Group. He’s seen how the planes crash into the mountains and he has created a product that performs eminently sensible analysis on your traffic and metadata to alert you to badness.

Then finally we’ll be hearing from Nucleus. This is a new company and if your job is managing vulnerabilities and vuln scanners in your org then straight up, just skip to the Nucleus interview immediately. They’ve created a web app that normalises vulnerability scanning information. It’ll take the outputs from Snyk, Rapid7, Checkmarx, Netsparker, OpenVAS, Twistlock, Fortify, Burp Suite, Nessus, Qualys, Acunetix AND others.

It ingests all of this data, normalises it, then plumbs these alerts through to the right people through a multitude of different ticketing systems. If your’e stuck in the 7th layer of Sharepoint or Spreadsheet vulnerability management hell, this is a solution to your problems. You will weep salty tears of joy when you hear this one. Free trials of Nucleus are also available.

Links to the companies featured are below!

Snake Oilers 9 part 1: The best Snake Oilers edition we've ever run
0:00 / 47:30

Risky Business #537 -- Assange arrested, WordPress ecosystem on fire

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Adam Boileau and Patrick Gray discuss the week’s security news:

  • Julian Assange arrested, likely to be extradited to the USA
  • Krebs: Breach at outsourcing firm Wipro
  • WordPress 0day drama causing serious headaches
  • Silk Road 2’s “DPR2” sent to slammer
  • More from Kaspersky SAS

This week’s show is brought to you by Thinkst Canary! Thinkst founder Haroon Meer will be along in this week’s show to talk about the effect venture capital is having on the security ecosystem. He thinks VC money often makes weak ideas look strong, and in a market where it’s quite difficult to make informed purchasing decisions, that’s not a good thing.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #537 -- Assange arrested, WordPress ecosystem on fire
0:00 / 58:17

Risky Business #536 -- Mar-a-Lago arrest, ASUS supply chain attack and more

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week’s show Patrick Gray and Adam Boileau recap all the infosec news of the last three weeks, including:

  • Chinese woman arrested at Mar-a-Lago being very shady
  • The ASUS supply chain attack
  • Flame-related malware lived on longer than expected
  • boostrap-sass Ruby gem backdoored
  • Latest on Norsk Hydro and other victims of the same crew
  • More trouble at Toyota
  • Huawei spanked by UK oversight panel
  • Exodus govvie malware affects Android and iOS
  • Plus much, much more

This week’s sponsor interview is with Kumud Kalia, the Chief Information and Technology Officer of Cylance. They actually dropped a really interesting product announcement at RSA a few weeks back and Kumud will be along later on to tell us about that. The tl;dr it’s an agent that models endpoint behaviour so when someone - or something - else starts using that endpoint to do things that don’t fit the user profile, action can be taken.

It’s the type of tech concept that normally belongs in academic papers, not in actual products people can actually buy. That’s an interesting chat.

Links to everything are below, and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #536 -- Mar-a-Lago arrest, ASUS supply chain attack and more
0:00 / 58:57

Risky Biz Soap Box: All about WebAuthn with Duo Security

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

This is a wholly sponsored podcast brought to you by Duo Security.

WebAuthn is a new multifactor authentication standard for the web that is all rooted in very smart encryption tech. Some of you would already be using similar authentication standards in apps without even thinking about it, like doing biometric authentication in your banking apps. You want to log in via your app and it scans your face to auth you, that sort of thing. WebAuthn makes those types of authentication actions available to users through the browser.

It’s now an official W3C standard supported by most browsers. It’s the future of auth on the Web.

Duo Security has been involved a little bit with the standards process and in this edition of the Soap Box podcast you’re going to hear a nearly hour long conversation between myself, Nick Steele and James Barclay who are Duo’s resident Webauthn dudes at Duo Labs.

I hope you enjoy this conversation.

Risky Biz Soap Box: All about WebAuthn with Duo Security
0:00 / 51:31

Risky Business #535 -- Stop giving Cloudflare money

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

In this week’s show Patrick Gray and Alex Stamos discuss the week’s news, as well as discussing the rise of white supremacist communities and propaganda on the Internet and what can be done about it.


  • Norsk Hydro ransomwared
  • Huawei ban gets more and more political
  • APT40 hitting USA hard
  • Cyber Command’s Euro road-trip
  • Kremlin interference in EU elections extremely likely
  • US Senators seek information on breaches targeting them
  • Cloudflare won’t pull service from 8chan in wake of NZ attack
  • Beto O’Rourke was cDc member
  • New Mirari variant
  • 150 million Android devices hosed by new malware
  • Much, much more

This week’s show is brought to you by Chronicle Security! We’ll be joined by Chronicle co-founders Shapor Naghibzadeh and Mike Wiacek. They had a tremendously successful launch at RSA and they’re going to pop in to tell us about some near future plans they have for their Backstory product.

Links to everything are below, and you can follow Patrick or Alex on Twitter if that’s your thing.

Risky Business #535 -- Stop giving Cloudflare money
0:00 / 72:05