Videos

News, analysis and product demos

Srsly Risky Biz: Exploiting authorisation sprawl is the new black

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Amberleigh Jack talk about the Salesloft Drift incident. It is a great example of the sprawling impact that the breach of a single service provider can have. We expect these single-compromise-large-blast-radius attacks will become the new norm.

They also talk about Apple’s Memory Integrity Enforcement, which promises to be a big step forward for memory safety on Apple devices.

Risky Business Weekly (806): Apple's Memory Integrity Enforcement is a big deal

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Apple ruins exploit developers’ week with fresh memory corruption mitigations
  • Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack
  • Salesloft says its GitHub was the initial entry point for its compromise
  • Sitecore says people should “patch” its using-the-keymat-from-the-documentation “zero day”
  • Rogue certs for 1.1.1.1 appear to be just (stupid) testing
  • Jaguar Land Rover ransomware attackers are courting trouble

This week’s episode is sponsored by open source cloud security tool, Prowler. Founder Toni de la Fuente joins to discuss their new support for Microsoft 365. Time to point Prowler at your OneDrive and Sharepoint!…

Snake Oilers: Nebulock, Vali Cyber and Cape

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this edition of the Snake Oilers podcasts, three vendors pop in to pitch you all on their wares:

Damien Lewke from Nebulock joins the show to talk about how its agentic AI platform can surface attacker activity out of all those “low” and “informational” findings your detection team doesn’t have time to look at.

Austin Gadient from Vali Cyber stops by to talk about ZeroLock, its hypervisor security product. It’s marketed as a counter-ransomware control but is just a generally useful security platform for virtualised environments….

Between Two Nerds: The death of the exploit

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq talk about the trend toward outrageously complicated exploits and what it means for hacking and cyber espionage.

Srsly Risky Biz: Google sharpens its cyber knife

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Amberleigh Jack talk about Google starting a cyber disruption unit. It’s a sign of the times but could also point the way forward for policymakers looking to involve the private sector in government-endorsed efforts to strike back in cyberspace.

They also talk about cyber security authorities from 13 different countries pegging Salt Typhoon to three Chinese companies. That’s a lot of countries, but Tom wonders whether attribution is just viewed as a cost of doing business for the Chinese government.

And it turns out that Apple’s dispute with the UK government about encrypted iCloud data has not yet been resolved, despite media reports to the contrary.

Risky Business Weekly (805): On the Salesloft Drift breach and "OAuth soup"

Presented by

Adam Boileau
Adam Boileau

Technology Editor

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • The Salesloft breach and why OAuth soup is a problem
  • The Salt Typhoon telco hackers turn out to be Chinese private sector, but state-directed
  • Google says it will stand up a “disruption unit”
  • Microsoft writes up a ransomware gang that’s all-in on the cloud future
  • Aussie firm hot-mics its work-from-home employees’ laptops
  • Youtube scam baiters help the feds take down a fraud ring

This episode is sponsored by Dropzone.AI. Founder and CEO Edward Wu joins the show to talk about how AI driven SOC tools can help smaller organisations claw their way above the “security poverty line”. A dedicated monitoring team, threat hunting and alert triage, in a company that only has a couple of part time infosec people? Yes please!…

Between Two Nerds: How threat actors are using AI to run wild

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Grugq
The Grugq

Independent Security Researcher

In this edition of Between Two Nerds Tom Uren and The Grugq talk about how cyber threat actors are using AI tools to fill in resource and skills gaps that they have.

Srsly Risky Biz: America wants to hack the planet

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

Tom Uren and Amberleigh Jack talk about proposed legislation that would allow the President to license private sector hackers to go after cybercrime groups. The bill won’t pass, but letting hackers loose on industrial-scale scam farms actually makes sense.

They also talk about Microsoft’s blind spot regarding China. It has trusted China-based engineers with sensitive work, and is now only just realising that China’s security interests are not compatible with Microsoft’s.

Risky Business Weekly (804): Phrack's DPRK hacker is probably a Chinese APT guy

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Australia expels Iranian ambassador
  • Hackers sabotage Iranian shipping satcoms
  • APT hacker got doxxed in Phrack. Kind of. They’re probably Chinese, not DPRK?
  • Trail of Bits uses image-downscaling to sneak prompts into Google Gemini
  • The Com’s King Bob gets ten years in the slammer
  • It’s a day that ends in -y, so of course there’s a new Citrix Netscaler RCE being used in the wild.

This week’s episode is brought to you by Corelight. Chief Strategy Officer Greg Bell talks through how they’ve been implementing AI for sifting through your network data. A model-context-protocol server that can rummage in all those packet logs for you while you keep investigating? Yes please. …

Wide World of Cyber: Microsoft's China Entanglement

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Alex Stamos
Alex Stamos

CISO, Sentinel One

Chris Krebs
Chris Krebs

Chief Intelligence and Public Policy Officer, Sentinel One

The Wide World of Cyber podcast is back! In this episode host Patrick Gray chats with Alex Stamos and Chris Krebs about Microsoft’s entanglement in China.

Redmond has been using Chinese engineers to do everything from remotely support US DoD private cloud systems to maintain the on premise version of the SharePoint code base. It’s all blown up in the press over the last month, but how did we get here? Did Microsoft make these decisions to save money? Or was it more about getting access to the Chinese market? And how can we all make the world’s most important software company stop doing things like this? Tune in to the Wide World of Cyber podcast to find out!