Videos

News, analysis and product demos

Srsly Risky Biz: Don't bring a banana to a knife fight

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

In this podcast Tom Uren and Patrick Gray talk about the Snowflake hack after the person allegedly responsible was arrested in Canada. Telegram is involved at all sorts of levels and Tom wonders if this crime would have occurred if Telegram didn’t exist.

They also discuss the impact of the Chinese hack of US telcos and Sophos’ five-year cyber knife fight with Chinese APT crews.

Risky Business Weekly (769): Sophos pwns Chinese APTs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s weekly Risky Business cybersecurity podcast Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Sophos drops implants on Chinese firewall exploit devs
  • Microsoft workshops better just-in-time Windows admin privileges
  • Snowflake hacker arrested in Canada
  • Okta has a fun, but not very impactful auth-bypass bug
  • Russians bring dumb-but-smart RDP client attacks
  • And much, much more.

Special guest Sophos CISO Ross McKerchar joined us to talk about its “hacking back” campaign. The full interview is available on Youtube (https://www.youtube.com/watch?v=QDh5-ZL3nis)) for those who want to really live vicariously through Sophos doing what every vendor probably wants to do. …

Risky Business Weekly: Chinese APT Wiretaps the US Presidential Race (768)

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

NOTE: This is the news segment from this week’s podcast but the sponsor interview will only appear in the audio version due to a technical problem with that interview’s video recording. This is the same news segment though!

In this edition of the weekly Risky Business cybersecurity podcast Patrick Gray and Adam Boileau talk through:

  • A Chinese APT wiretaps the Trump and Harris campaigns
  • Operation Magnus snares infostealer operators and customers
  • Crypto thieves return stolen funds to US government wallets
  • Did Israel hack Iranian air defence?
  • Delta finally sues CrowdStrike
  • Much, much more…

Risky Biz Soap Box: Thinkst Canary's decade of deception

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the podcast Patrick Gray chats with Thinkst Canary founder Haroon Meer about his “decade of deception”, including:

  • A history of Thinkst Canary including a recap of what they actually do
  • A look at why they’re still really the only major player in the deception game
  • A look at what companies like Microsoft are doing with deception
  • Why security startups should have conference booths

Find them at https://canary.tools/

Srsly Risky Biz: EU lobs software liability hand grenade

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

In this podcast Tom Uren, Patrick Gray and Adam Boileau talk about an EU directive that will make vendors liable for software defects. The directive sets a very high bar but is also limited in scope. It only applies to individuals and doesn’t cover professional use so it is a very practical way to start changing expectations about liability.

They also talk about Session Messenger app which has decamped from Australia and set up a foundation in Switzerland. The encrypted and metadata-resistant app is catnip for criminals, so we expect that it is on a collision course with state power.

Product Demo: Securing M365 and Google Workspace with Material Security

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this product demo, Material Security’s co-founder and CEO Abhishek Agrawal shows how the company’s platform works with M365 and Google Workspace. It can be used to find and automatically fix existing vulnerabilities, find new threats, and protect data even after a compromise has occurred.

Risky Business Weekly (767): Why North Korea's hacks are, sadly, GOATED

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • The SEC fines tech firms for downplaying the Solarwinds hacks
  • Anonymous Sudan still looks and quacks like a Russian duck
  • Apple proposes max 10 day TLS certificate life
  • Oopsie! Microsoft loses a bunch of cloud logs
  • Veeam and Fortinet are bad and should feel bad
  • North Koreans are good (at hacking)
  • And much, much more.

This week’s episode is sponsored by Proofpoint. Chief Strategy Officer Ryan Kalember joins to talk about their work keeping up with prolific threat actor SocGholish. …

Srsly Risky Biz: When thuggery is your cyber talent pipeline

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Tom Uren
Tom Uren

Policy & Intelligence

In this podcast Tom Uren and Patrick Gray talk about the evolving relationship between Russian intelligence services and the country’s cybercriminals. The GRU’s sabotage unit, for example, has been recruiting crooks to build a destructive cyber capability. Tom suspects that GRU thugs are not so good at hands-on-keyboard operations, but excellent at coercing weedy cybercriminals to hack for the state.

They also talk about OpenAI’s report into malicious actor’s use of its models, and how Australia’s proposed cyber security law looks pretty sensible.

Risky Business Weekly: China hacks America's lawful intercept systems (episode 766)

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Chinese spooks all up in western telco lawful intercept
  • Jerks ruin the Internet Archive’s day
  • Microsoft drops a great report with a bad chart
  • The feds make their own crypto currency and get it pumped
  • Forti-, Palo- and Ivanti-fail
  • And much, much more

This week’s episode is sponsored by detection-as-code vendor Panther. Casey Hill, Panther’s Director Product Management joins to discuss why the old “just bung it all in a data lake and… ???… “ approach hasn’t worked out, and what smart teams do to handle their logs. …