Risky Bulletin - podcast cover

Risky Bulletin

risky.bizrisky.biz
Regular cybersecurity news updates from the Risky Business team...
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Risky Bulletin: EU scraps Chat Control vote

The EU scraps its upcoming vote on Chat Control, Ukraine establishes a Cyber Force, CISA workers are reassigned to immigration enforcement, and two teens are arrested over the UK nursery hacks. Show notes Risky Bulletin: EU scraps Chat Control vote

Oct 10, 20257 min

Srsly Risky Biz: Clop is a big fish, but not worth hunting

Tom Uren and Amberleigh Jack talk about the Clop ransomware gang. It is interesting because the group has arrived at a strategy that rinses a whole lot of enterprises at once and comes with a decent pay day, But it’s actually the least damaging kind of ransomware. Tom wonders why can’t more gangs be like Clop? They also discuss the US government having second thoughts about ignoring foreign influence operations. Its adversaries run them all the time, so perhaps just sticking its head in the sand...

Oct 09, 202517 min

Risky Bulletin: Redis vulnerability impacts all versions released in the last 13 years

Redis patches a remote code execution vulnerability, Oracle out-of-band-fixes a zero-day used in a recent extortion campaign, Medusa ransomware group was behind a recent Fortra zero-day, and India fixes a tax filing system flaw; Show notes Risky Bulletin: Redis vulnerability impacts all versions released in the last 13 years...

Oct 07, 20256 min

Between Two Nerds: What drives 0day mass exploitation

In this edition of Between Two Nerds Tom Uren and The Grugq talk about the 0day mass exploitation of SharePoint and Exchange. This type of widespread hacking appears to be increasingly common… but is it? This episode is also available on YouTube . Show notes X post | Brian in Pittsburgh...

Oct 06, 202525 min

Sponsored: Corelight on where will NDRs go next

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Ashish Malpani, Head of Product Marketing at Corelight. The discussion looks at how NDRs might evolve, such as expanding to protect inter-cloud networks and complementing EDRs. Show notes Corelight

Oct 05, 202512 min

Risky Bulletin: Scam compound operators sentenced to death in China

China sentences 11 scam compound operators to death, the UK makes another request for Apple user data, an Iranian APT gets doxxed again, and Microsoft launches a Security Store. Show notes Risky Bulletin: Scam compound operators sentenced to death in China...

Oct 03, 20257 min

Srsly Risky Biz: The cyberespionage gig economy

Tom Uren and Amberleigh Jack talk about different ways foreign intelligence services are finding to recruit local proxies. These methods could be too risky for Western intelligence agencies, but for some state’s services they just make sense. They also discuss a report into DOGE and how speed was prioritised over robust governance. This episode is also available on Youtube . Show notes...

Oct 02, 202518 min

Risky Bulletin: Router APIs abused to send SMS spam

A Cybercrime group abuses routers to send SMS spam, CISA announces a new collaboration model for state governments, South Korea raises its cyber threat level after a data center fire, and Tile tracking devices expose their location. Show notes Risky Bulletin: Router APIs abused to send SMS spam waves...

Oct 01, 20256 min

Between Two Nerds: The power of cyber

In this edition of Between Two Nerds Tom Uren and The Grugq discuss the power of cyber. This episode is also available on Youtube . Show notes Narrow windows of opportunity: the limited utility of cyber operations in war RUSI's UK cyber effects network RUSI call for abstracts The fate of nations BTN discussion UK National Cyber Force's Responsible Cyber Power in Practice Sponsor interview on the importance of resilient IdPs...

Sep 29, 202528 min

Risky Bulletin: UK to bail out Jaguar Land Rover

The UK will bail out Jaguar Land Rover following its cyberattack, hackers try to extort a ransom using childrens’ photos, Dutch police arrest two teens over sniffing WiFi for Russian spies, and a recent GoAnywhere MFT bug is being exploited. Show notes Risky Bulletin: UK to bail out Jaguar Land Rover...

Sep 29, 20255 min

Sponsored: Why identity is critical

In this sponsored interview, Authentik CEO Fletcher Heisler talks to Tom Uren about how identity providers (IdP) are fundamental to everything an organisation does. He explains how organisations are making themselves resilient by managing their redundancy and failover options. Show notes

Sep 28, 202513 min

Risky Bulletin: EU users to get free Windows 10 extended security updates

European users will get free Windows 10 extended security updates, Cisco patches three zero-days, Microsoft drops an Israeli intel surveillance contract and a UK man is arrested for the EU airport disruptions. Show notes Risky Bulletin: EU users to get free Windows 10 extended security updates...

Sep 26, 20258 min

Srsly Risky Biz: The kids aren't alright

Tom Uren and Amberleigh Jack talk about how the funnel that turns kids into cyber criminals has evolved over the last decade. Cybercrime’s reach has broadened, it is more lucrative and more violent. They also talk about new thinking about deterring America’s cyber adversaries. This episode is also available on YouTube Show notes CSIS's Playbook for Winning the Cyber War Bloomberg reporting on Scattered Spider...

Sep 25, 202516 min

Risky Bulletin: US raids SIM farm in New York

The US Secret Service raids a SIM farm in New York, EU airport disruptions were caused by ransomware, thieves steal gold nuggets from a French museum after a cyberattack and SonicWall releases a firmware update to remove SMA rootkits. Show notes Risky Bulletin: US raids SIM farm in New York...

Sep 24, 20257 min

Between Two Nerds: How the US can win the cyber war

In this edition of Between Two Nerds Tom Uren and The Grugq look at a new Center for Strategic and International Studies report: A Playbook for Winning the Cyber War. This episode is also available on YouTube . Show notes CSIS Playbook...

Sep 22, 202531 min

Risky Bulletin: Cyberattack disrupts airports across Europe

A cyberattack disrupts European airports, a Scattered Spider member turns himself in to US authorities, the Pentagon hires a new cyber policy leader and two Russian APTs work together for the first time. Show notes Risky Bulletin: Cyberattack disrupts airports across Europe...

Sep 22, 20257 min

Sponsored: SpecterOps on identities at rest and identities in transit

In this Risky Business News sponsor interview, Catalin Cimpanu talks with Jared Atkinson, CTO at SpecterOps. They discuss how SpecterOps is using classifying identities under two categories, identities at rest and identities in transit, what they are and how they should be treated differently. Show notes Shifting the Paradigm: Managing Identities at Rest vs. Identities in Transit BloodHound OpenGraph...

Sep 21, 202519 min

Risky Bulletin: Pentagon has more than 70,000 cyber personnel

America’s Government Accountability Office says the Pentagon employs more than 70,000 cyber personnel, hackers steal SonicWall firewall configs, DeepSeek returns insecure code for groups China doesn’t like, and two Scattered Spider members arrested in the UK. Show notes Risky Bulletin: Pentagon has +70K cyber staff, and a lot of overlap...

Sep 19, 20257 min

Srsly Risky Biz: US investment in spyware skyrockets

Tom Uren and Amberleigh Jack talk about why it is good news that US investment in spyware vendors has skyrocketed. They also discuss the in-principle agreement for TikTok to remain in the US. It’s a win-win: a win for China and a win for TikTok, but not so much a win for US national security. This episode is also available on YouTube . Show notes...

Sep 18, 202516 min

Risky Bulletin: Android switches to risk-based security updates

Android will only issue monthly updates for high-risk vulnerabilities, a self-replicating attack hits the npm registry, BreachForums’ admin resentenced on appeal, and hackers breach Gucci’s parent company. Show notes Risky Bulletin: AI chatbot disinformation doubles in a year...

Sep 16, 20257 min

Between Two Nerds: The limits of cyber power

In this edition of Between Two Nerds Tom Uren and The Grugq talk about the limits of a state’s cyber power. This episode is also available on YouTube Show notes Dave Aitel's CyberSecPolitics post on cyber power metrics Lawfare Post BTN 117, The fate of nations BTN 120, Should US spies steal Chinese commercial secrets...

Sep 15, 202531 min

Risky Bulletin: DC sues crypto ATM operator for profiting from scams

The US sues a crypto ATM operator for profiting from scams, SMS blasters make their way into Switzerland, the US and Portugal tussle over the extradition of the RaidForums admin, and Samsung patches a zero-day in its phones. Show notes Risky Bulletin: US largest crypto ATM operator sued for profiting from scams...

Sep 15, 20257 min

Sponsored: The challenge of managing browser extensions

In this sponsored interview, Casey Ellis chats to David Cottingham and Daniel Schell from Airlock Digital. They discuss the challenge of browser extension management for enterprises, why it’s a priority and how Airlock can help. Show notes

Sep 14, 202520 min

Risky Bulletin: Apple notifies French users of spyware attacks

Apple notifies French users of spyware attacks, China will increase fines for data breaches Google pays $1.6mil for cloud bugs at a hackathon event, and no more hacked free laundry for Dutch students Show notes Risky Bulletin: Most UK school hacks are caused by their own students...

Sep 12, 20257 min

Srsly Risky Biz: Exploiting authorisation sprawl is the new black

Tom Uren and Amberleigh Jack talk about the Salesloft Drift incident. It is a great example of the sprawling impact that the breach of a single service provider can have. We expect these single-compromise-large-blast-radius attacks will become the new norm. They also talk about Apple’s Memory Integrity Enforcement, which promises to be a big step forward for memory safety on Apple devices. This episode is also available on Youtube . Show notes...

Sep 11, 202518 min

Risky Bulletin: White House to keep CyberCom and NSA dual role

The White House will keep the CyberCom and NSA dual-hat leadership arrangement, the US charges a major ransomware figure, Apple ships a memory safety protection feature and yet another supply chain attack hits the npm world. Show notes Risky Bulletin: US charges major ransomware figure...

Sep 10, 20259 min

Between Two Nerds: The death of the exploit

In this edition of Between Two Nerds Tom Uren and The Grugq talk about the trend toward outrageously complicated exploits and what it means for hacking and cyber espionage. This episode is also available on YouTube Show notes

Sep 08, 202526 min

Risky Bulletin: New APT group turns out to be a phishing test

A new APT group turns out to be a phishing test, Qantas cuts executives’ bonuses after a recent breach, Anthropic stops selling AI tools to Chinese firms, and Nepal blocks 26 social media sites. Show notes Risky Bulletin: APT report? No, just a phishing test!...

Sep 08, 20258 min

Sponsored: Why prompt injection is an intractable problem

In this sponsored interview Casey Ellis chats with Keith Hoodlet from Trail of Bits. Keith is Trail of Bits’ director of engineering for AI, machine learning and application security and he joined Casey to talk about why prompt injection attack techniques that target AI are an unsolvable problem. Show notes

Sep 07, 202517 min
For the best experience, listen in Metacast app for iOS or Android