Risky Business (809): Hackers try to pay a journalist for access to the BBC

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray is on holiday so Amberleigh Jack and Adam Boileau hijack the studio to discuss the week’s cybersecurity news, including:

  • Hackers learn that trying to coerce a journalist just makes for … a great story?
  • A man in his 40s gets arrested over the European airport chaos. Yep, we’re surprised, too
  • Adam fanboys over Watchtowr Labs while bemoaning Fortra
  • Academics pick apart Tile trackers and find them lacking
  • CISA tells agencies to patch their damn Cisco gear

Show Notes:

‘You’ll never need to work again’: Criminals offer reporter money to hack BBC https://www.bbc.com/news/articles/c3w5n903447o

Government to guarantee £1.5bn Jaguar Land Rover loan after cyber shutdown https://www.bbc.com/news/articles/cgl15ykerlro

Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms – Krebs on Security https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/

UK authorities arrest man in connection with cyberattack against aviation vendor | Cybersecurity Dive https://www.cybersecuritydive.com/news/uk-arrest-cyberattack-aviation/761008/

Chinese scammer pleads guilty after UK seizes nearly $7 billion in bitcoin https://therecord.media/chinese-scammer-guilty-seizure-uk

Cyberattack on Japanese beer giant Asahi limits shipping, call center operations | The Record from Recorded Future News https://therecord.media/asahi-japan-cyberattack-limits-shipping-call-centers

Afghanistan plunged into nationwide internet blackout, disrupting air travel, medical care | The Record from Recorded Future News https://therecord.media/afghanistan-plunged-into-nationwide-internet-blackout

Tile trackers are a stalker’s dream, say Georgia Tech researchers https://www.theregister.com/2025/09/30/tile_trackers_unencrypted_info/

Intel and AMD trusted enclaves, the backbone of network security, fall to physical attacks - Ars Technica https://arstechnica.com/security/2025/09/intel-and-amd-trusted-enclaves-the-backbone-of-network-security-fall-to-physical-attacks/

Supermicro server motherboards can be infected with unremovable malware - Ars Technica https://arstechnica.com/security/2025/09/supermicro-server-motherboards-can-be-infected-with-unremovable-malware/

China-linked hackers use ‘BRICKSTORM’ backdoor to steal IP | The Record from Recorded Future News https://therecord.media/china-linked-hackers-brickstorm-backdoor-ip

Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign

Federal agencies given one day to patch exploited Cisco firewall bugs | The Record from Recorded Future News https://therecord.media/cisco-asa-firewall-bugs-cisa-federal-agencies-warning

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte

Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035) https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/

It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/