
Risky Business
227 FOLLOWERS
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Risky Business
6d ago
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news with special guest Rob Joyce, a Former Special Assistant to the US President and Director of Cybersecurity for NSA.
They talk through:
A realistic bluetooth-proximity phishing attack against Passkeys
A very patient ransomware actor encrypts an entire enterprise with a puny linux webcam processor
The ESP32 backdoor that is neither a door nor at the back
The X DDoS that Elon said was Ukraine is claimed by pro-Palestinian hacktivists
Years later, LastPass hackers are still emptying crypto-wallets
…and it turn ..read more
Risky Business
2w ago
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Did the US decide to stop caring about Russian cyber, or not?
Adam stans hard for North Korea’s massive ByBit crypto-theft
Cellebrite firing Serbia is an example of the system working
Starlink keeps scam compounds in Myanmar running
Biggest DDoS botnet yet pushes over 6Tbps
This week’s episode is sponsored by network visibility company Corelight. Vincent Stoffer, field CTO at Corelight joins to talk through where eyes on your network can spot attackers like Salt and Volt Typhoon.
This episode is also ava ..read more
Risky Business
2w ago
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
North Korea pulls off a 1.5 billion dollar crypto heist
Apple pulls Advanced Data Protection from the UK
Black Basta ransomware gang’s internal chats leak
Russians snoop on Signal with QR codes
And Myanmar ships thousands of freed scam compound workers to Thailand
Regular guest Lina Lau joins to discuss her work reading Chinese incident response reports on WeChat, and how that has people thinking that … she outed the NSA?
This week’s episode is sponsored by Airlock Digital, and allow-listing tragics Dani ..read more
Risky Business
3w ago
In this episode of the Wide World of Cyber podcast Risky Business host Patrick Gray chats with SentinelOne’s Chris Krebs and Alex Stamos about AI, DeepSeek, and regulation.
From its bad transport security to its Chinese ownership and the economic implications of China “entering the chat”, everyone’s freaking out over this new model. But should they be?
Pat, Alex and Chris dissect the model’s significance, the politics of it all and how AI regulation in Europe, the US and China will shape the future of LLMs.
This episode is also available on Youtube.
Show notes ..read more
Risky Business
1M ago
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
Australian spooks scrubbed Medibank data off Zservers bulletproof hosting
Why device code phishing is the latest trick in confusing poor users about cloud authentication
Cloudflare gets blocked in Spain, but only on weekends and because of… football?
Palo Alto has yet another dumb bug
Adam gushes about Qualys’ latest OpenSSH vulns
Enterprise browser maker Island is this week’s sponsor and Chief Customer Officer Braden Rogers joins the show to talk about how the adoption of AI everywhere is cau ..read more
Risky Business
1M ago
In this SoapBox edition of the show Patrick Gray chats to Fletcher Heisler, the CEO of open-source identity provider Authentik.
The whole idea of Authentik is you can take control of an essential IT and security function: identity. Because Authentik is open source it’s extremely flexible, and if you’re running it yourself, you get to decide where your IDP should sit in your architecture. You can run it on prem if you’re an emergency call centre or you’re operating an airgapped network, or you can spin it up in your cloud environment if you’re a typical enterprise.
Fletcher talks through the re ..read more
Risky Business
1M ago
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
Musk’s DOGE kid has a history with The Com
Paragon fires Italy as a spyware customer
Thailand cuts power to scam compounds…
… and arrests Phobos/8Base Russian cybercrims
The CyberCX DFIR report shows non-U2F MFA is well and truly over
And much, much more.
This week’s episode is sponsored by Dropzone.AI. They make an AI SOC analysis platform that relieves your analysts of the necessary but tedious work, so they can focus on the value of human insight. Dropzone’s founder and CEO Edward Wu joins ..read more
Risky Business
1M ago
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
DeepSeek leaves an unauthed database on the internet
Russia hacked UK prime minister’s personal mail
Australia sanctions a Telegram group… which is more sensible than it sounds
Medical device backdoor turns out to be just poorly thought out upgrade feature
Google abuses weak hashing to patch AMD CPU microcode
And much, much more.
This week’s episode is sponsored by email security boffins Sublime. Their co-founder and CEO Josh Kamdjou joins to talk about how attackers’ abuse of legitimate servi ..read more
Risky Business
1M ago
Coming to you from the same room in Risky Business headquarters Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. They talk through:
Sonicwall firewalls hand out remote code exec like candy
Mastercard make a slapstick-grade mistake with their DNS
The data breach at PowerSchool and other niche SaaS providers
Academic research proposes taking down Europe’s power grid
Apple CPUs get a new speculative execution side channel
And much, much more.
This week’s episode is sponsored by Push Security, who make an identity security product that runs inside browsers. Luke Jennings join ..read more
Risky Business
1M ago
Risky Business returns for its 19th year! Patrick Gray and Adam Boileau discuss the week’s cybersecurity news and there is a whole bunch of it. They discuss:
The incoming Trump administration guts the CSRB
Biden’s last cyber Executive Order has sensible things in it
China’s breach of the US Treasury gets our reluctant admiration
Ross Ulbricht - the Dread Pirate Roberts of Silk Road fame - gets his Trump pardon
New year, same shameful comedy Forti- and Ivanti- bugs
US soldier behind the Snowflake hacks faces charges after a solid Krebs-ing
And much, much (much! after a month off) more.
This w ..read more