Videos

News, analysis and product demos

Srsly Risky Biz: Outside America, Musk's X is a foreign influence threat

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray discuss how X is actively engaging in political interference outside the US. The risks mirror those of TikTok. American legislators moved against TikTok because it could potentially be a powerful tool for the Chinese government to interfere with American political discourse. X is a realised threat, not a potential one, so we expect that foreign governments will start to consider a ban.

They also explore why mass firing of probationary employees in NSA and intelligence agencies is particularly damaging.

This episode is sponsored by https://greynoise.io.

Risky Business Weekly (783): Evil webcam ransomwares entire Windows network

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news with special guest Rob Joyce, a Former Special Assistant to the US President and Director of Cybersecurity for NSA.

They talk through:

  • A realistic bluetooth-proximity phishing attack against Passkeys
  • A very patient ransomware actor encrypts an entire enterprise with a puny linux webcam processor
  • The ESP32 backdoor that is neither a door nor at the back
  • The X DDoS that Elon said was Ukraine is claimed by pro-Palestinian hacktivists
  • Years later, LastPass hackers are still emptying crypto-wallets
  • …and it turns out North Korea nailed {Safe}Wallet with a malicious docker image. Nice!…

Between Two Nerds: Mind control powers

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq talk about what Europe should do given that US security guarantees are evaporating. Should Europe grow its cyber capabilities, what it would get out of it and how should it go about doing it?

Srsly Risky Biz: Starlink an internet lifeline for pig butchering compounds

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

In this podcast Tom Uren and Patrick Gray discuss how Starlink is providing an internet lifeline for scam compounds that have had their internet access cut by Thai authorities. Starlink has a very poor track record dealing with unauthorised use, but it is time for the company to develop the processes to keep on top of these problems.

They also discuss how President Trump’s actions that favour Russia will make Five Eyes partners take stock, particularly when it comes to HUMINT intelligence sharing.

Finally they examine the did-it-happen-or-not stand-down of US Cyber Command’s Russian operations.

Risky Business Weekly (782): Are the USA and Russia cyber friends now?

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Did the US decide to stop caring about Russian cyber, or not?
  • Adam stans hard for North Korea’s massive ByBit crypto-theft
  • Cellebrite firing Serbia is an example of the system working
  • Starlink keeps scam compounds in Myanmar running
  • Biggest DDoS botnet yet pushes over 6Tbps

This week’s episode is sponsored by network visibility company Corelight. Vincent Stoffer, field CTO at Corelight joins to talk through where eyes on your network can spot attackers like Salt and Volt Typhoon.

Between Two Nerds: The NSA's hacking magic?

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq take a deep dive into incident response reports from Chinese cybersecurity firms that attribute the hack of one of the country’s top seven defence universities to the US National Security Agency. These reports were collated and translated into English by the security researcher known as inversecos (https://x.com/inversecos))

Srsly Risky Biz: Canada's expulsion from Five Eyes would be a disaster

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Patrick Gray talk about the White House apparently considering kicking Canada out of the Five Eyes intelligence alliance to apply pressure on the country. It’s a terrible idea and even thinking about it undermines the strength of the alliance.

They also discuss Sweden’s proposed legislation that would order apps like WhatsApp and Signal to store messages so they could be provided under warrant to authorities. The story is a vignette of the ongoing encryption debate, but we think apps like Signal will leave the country rather than comply.

Finally, they talk about how the illicit …

Risky Business Weekly (781): How Bybit oopsied $1.4bn

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • North Korea pulls off a 1.5 billion dollar crypto heist
  • Apple pulls Advanced Data Protection from the UK
  • Black Basta ransomware gang’s internal chats leak
  • Russians snoop on Signal with QR codes
  • And Myanmar ships thousands of freed scam compound workers to Thailand

Regular guest Lina Lau joins to discuss her work reading Chinese incident response reports on WeChat, and how that has people thinking that… she outed the NSA?

This week’s episode is sponsored by Airlock Digital, and allow-listing tragics Daniel Schell and David Cottingham are along with an amusing tale of using Windows’ own allow-listing software to block EDR from loading. …

Product demo: Prowler, the free and open source cloud security platform

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this sponsored product demo, Prowler founder and CEO Toni de la Fuente walks Risky Business host Patrick Gray through the company’s open source cloud security platform.

Toni demonstrates how Prowler can identify and remediate security issues across AWS, Azure, GCP and Kubernetes. There’s a pointy-clicky GUI interface and a CLI, and both come in handy in different ways.

The Prowler platform is completely free and open source, but there is a hosted version you can pay for if you don’t want to run it yourself.

Find the Prowler company at https://prowler.com and the GitHub page at https://github.com/prowler-cloud

Between Two Nerds: Hacking's First Principles

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq examine the fundamental principles of network exploitation as described in Matthew Monte’s ‘Network Attacks and Exploitation: A Framework’ book.