Videos

News, analysis and product demos

Risky Business (849): Trump will unleash contractors on cybercriminals

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:

  • Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
  • OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
  • Anthropic’s models start a turf war when given the same task, surprising… nobody
  • We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
  • Much, much more

This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper….

James Kettle on inventing new attack techniques with LLMs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this episode, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.

Kettle has built what he calls the HTTP Terminator, an autonomous research system that generates and tests tens of thousands of potentially new HTTP desync techniques. The Terminator, which makes use of Kettle’s own research methodology, has already come up with new desync methods that James hadn’t thought of before.

Kettle and Wilson discuss how to develop and evaluate machine-generated ideas without drowning in false positives, and why the most powerful part of the process is the discovery cascade, where one unexpected result becomes the seed for another….

Between Two Nerds: The eye of Sauron

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.

Soap Box: Zero Trust(ish) Networks

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.

Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.

Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.

Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.

Srsly Risky Biz: Data extortion is booming. Hooray!

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up.

They also discuss how the rise of AI makes it worth reinvigorating CISA’s Secure by Design initiative.

Risky Business (848): OpenAI comes clean

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

  • The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
  • Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
  • More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
  • It turns out TeamPCP has been around longer than we thought and predates the AI era
  • Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways…

Between Two Nerds: The cyber resistance!

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals.

Srsly Risky Biz: Being a North Korean hacker is about to be less fun

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and James Wilson talk about North Korea losing control over some of its hacker workforce. Expect some tightening of controls and oversight, and perhaps even a reduction in the country’s ransomware operations.

They also discuss escalating attacks on American water infrastructure. Although the impact of these attacks is relatively minor so far, the US government has been slow to respond from a political perspective.

Between Two Nerds: Hackers vs the state

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether hacker culture is inherently anti-authoritarian and how different states get their country’s hackers to work for the state.

Srsly Risky Biz: Chipping away at Chinese AI risks

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Amberleigh Jack
Amberleigh Jack

Producer and Editor

Tom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let’s not forget that America’s overriding goal is to remain ahead of China in the AI race. There are better ways to do that than overindexing on distillation.

They also discuss Iranian attacks on US critical infrastructure. Given that the war in Iran is unpopular, incidents that make headlines without causing serious impact are perfectly calibrated.