Snake Oilers: Burp AI, Sondera and Truffle Security

Published: 04/09/2026 16:33:35
Snake Oilers: Burp AI, Sondera and Truffle Security Episode Details
In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: Burp AI and DAST: The founder of PortSwigger and creator of legendary security software Burp Suite, Dafydd Stuttard, drops by to pitch listeners on Burp AI and Burp Suite DAST. Sondera: Josh Devon talks about Sondera, a technology designed to intervene when AI models start doing the wrong thing by statefully tracking their trajectories. This isnât a permissions suite for AI agents, itâs a way to stick agents in a harness
Risky Business #832 -- Anthropic unveils magical 0day computer God

Published: 04/07/2026 23:59:38
Risky Business #832 -- Anthropic unveils magical 0day computer God Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James Wilson discuss the weekâs cybersecurity news. They cover: Anthropicâs new Mythos model hunts bugs and chains exploits together so well that⦠you cant have it⦠â¦Unless youâre one of their Project Glasswing partners The world isnât short on bugs, though. F5, Fortinet, Progress ShareFile, and TrueConf are all getting rekt by humans GPU Rowhammering goes in the GPU, past the IOMMU and back into the host-side Nvidia driver North Korea is spending serious time and money on its crypto hacking
How the World Got Owned Episode 2: The 1990s, Part One

Published: 04/02/2026 19:35:55
How the World Got Owned Episode 2: The 1990s, Part One Episode Details
In this special documentary episode, Patrick Gray and Amberleigh Jack take a look back at hacking throughout the 1990s, from the feel-good vibes of the early hacking communities to the antics of young hackers who wound up on the run from the FBI. Part one features recollections from: Jeff Moss (The Dark Tangent), DefCon and Black Hat founder Chris Wysopal (Weld Pond), L0pht member, co-founder, @Stake Kevin Poulsen (Dark Dante), 1990s hacker turned journalist Elias Levy (Aleph One), author of Smashing the Stack for Fun and Profit, Phrack, 1996 How
Risky Business #831 -- The AI bugpocalypse begins

Published: 03/31/2026 22:50:51
Risky Business #831 -- The AI bugpocalypse begins Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James Wilson discuss the weekâs cybersecurity news. They cover: Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package TeamPCP appear to have ransacked Ciscoâs source and cloud environments AI is getting legitimately good at being told to âjust go find some 0day in thisâ Kaspersky says Coruna and Triangulation do share code lineage Iranian hackers dump Kash Patelâs gmail spool Oh, and of course thereâs a Citrix Netscaler memory leak being exploited in the wild This weekâs episode
Soap Box: Red teaming AI systems with SpecterOps

Published: 03/26/2026 20:07:14
Soap Box: Red teaming AI systems with SpecterOps Episode Details
In this sponsored Soap Box edition of the show, Patrick Gray and James Wilson talk about red teaming AI systems with Russel Van Tuyl, Vice President of Services at elite penetration testing firm SpecterOps. SpecterOps is the company behind attack path enumeration tool Bloodhound and Bloodhound Enterprise, but theyâre also a pentest and red teaming shop with world class expertise in popping shells on all sorts of interesting systems in all sorts of interesting places. This episode is also available on Youtube.
Risky Business #830 -- LiteLLM and security scanner supply chains compromised

Published: 03/24/2026 23:13:36
Risky Business #830 -- LiteLLM and security scanner supply chains compromised Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James WIlson discuss the weekâs cybersecurity news. They talk through: TeamPCPâs supply chain attack on Github, and they threw in an anti-Iran wiper, because why not?! Anthropic hooks up its models to just⦠use your whole computer After Strykerâs Very Bad Day, CISA says maybe add some more controls around your Intune? Another iOS exploit kit shows up in the cyber bargain-bin The FTC decides to ban⦠all new home routers?! U wot m8?! Supermicro founder was personally sanction-busting Nvidia GPUs
Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat

Published: 03/17/2026 22:39:30
Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James WIlson discuss the weekâs cybersecurity news. They discuss: Iranâs Intune-based wiper attack on medical device maker Stryker Qihoo 360âs AI publishes its own wildcard TLS cert private key Instagram is canning its end-to-end encrypted messaging Whatâs going on with mobile internet access in Moscow? The Xbox Oneâs bootloader gets voltage glitched into submission Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt filesâ¦) This weekâs episode is sponsored by browser-based detection and response
Risky Biz Soap Box: It took a decade, but allowlisting is cool again

Published: 03/12/2026 18:12:14
Risky Biz Soap Box: It took a decade, but allowlisting is cool again Episode Details
In this Soap Box edition of the Risky Business podcast Patrick Gray sits down with Airlock Digital co-founders Daniel Schell and David Cottingham to talk about the role AI models could play in managing enterprise allowlists. They also talk about the durability of allowlisting as a control. After 12 years in business, the Airlock product hasnât really changed all that much. Thatâs a good thing! It also means the Airlock team have been able to spend some time doing deep engineering instead of chasing the latest attacker TTPs and writing
Risky Business #828 -- The Coruna exploits are truly exquisite

Published: 03/10/2026 23:31:39
Risky Business #828 -- The Coruna exploits are truly exquisite Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James WIlson discuss the weekâs cybersecurity news. They cover: The Coruna exploits were L3 Harris, but it seems Triangulation⦠was not! Iranâs cyber HQ hit by Israeli (kinetic) strikes Trumpâs cyber âstrategyâ is ⦠well, all weâve got is jokes cause thereâs no serious content NSA and CyberCom finally get a leader after Lt Gen Joshua Rudd gets Senate nod DOGE (remember them?!) employee walked a social security database out on a USB stick This episode is sponsored by open source
Risky Business #827 -- Iranian cyber threat actors are down but not out

Published: 03/03/2026 22:29:15
Risky Business #827 -- Iranian cyber threat actors are down but not out Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James WIlson discuss the weekâs cybersecurity news. They cover: The US-Israeli attack on Iran had a whole lot of cyber. Itâs clearly in the playbook now! The NSA Triangulation / L3 Harris Trenchant iOS exploit kit is on the loose, and being used by Chinese crypto scammers So long Maddhu Gottumukkala, but CISAâs annus horribilis continues Adam âhumbugâ Boileau complains about the Airsnitch wifi attack just being three ethernets in a trenchcoat ASDâs Cisco SD-WAN threat hunting guide is clearly borne
Risky Business #826 -- A week of AI mishaps and skulduggery

Published: 02/24/2026 21:49:29
Risky Business #826 -- A week of AI mishaps and skulduggery Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James WIlson discuss the weekâs cybersecurity news. They cover: Low skill actors compromise 600 Fortinets with AI-generated playbooks Anthropic calls out Chinese AI firms over model distillation Metaâs director of AI safety tells her ClawdBot not to delete her mail⦠so of course it does Peter Williams cops 7 years in jail for selling L3 Harris Trenchantâs exploits to Russia Ivanti got hacked in 2021 via⦠bugs in Ivanti This episode is sponsored by line-rate network capture system Corelight. CEO Brian
Risky Biz Soap Box: The lethal trifecta of AI risks

Published: 02/19/2026 17:33:55
Risky Biz Soap Box: The lethal trifecta of AI risks Episode Details
Thereâs a lethal trifecta of AI risks: access to private data, exposure to untrusted content, and external communication. In this conversation, Risky Business host Patrick Gray chats with Josh Devon, the co-founder of Sondera, about how to best address these risks. There is no magic solution to this problem. AI models mix code and data, are non-deterministic, and are crawling around all over your enterprise data and APIs as you read this. But in this sponsored interview, Josh outlines how we can start to wrap our hands around the problem.
Risky Business #825 -- Palo Alto Networks blames it on the boogie

Published: 02/17/2026 21:49:36
Risky Business #825 -- Palo Alto Networks blames it on the boogie Episode Details
On this weekâs show, Patrick Gray, Adam Boileau and James WIlson discuss the weekâs cybersecurity news. They cover: Palo Alto threat researchers want to attribute to China, but management says shush An increasing proportion of ransomware is data extortion. Is this good? Cambodia says itâs going to dismantle scam compounds CISA sufferers through yet another shutdown Google Geminiâs training secrets are being systematically harvested to improve other LLMs Academics assess SaaS password managersâ resilience against a malicious server This episode is sponsored by SSO-firewall integration vendor Knocknoc. Chief exec Adam
Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly

Published: 02/10/2026 21:50:13
Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Microsoft reshuffles security leadership. It doesnât spark joy. Russia is hacking the Winter Olympics. Again. But y tho? China-linked groups are keeping busy, hacking telcos in Norway, Singapore and dozens of others Campaigns underway targeting Ivanti, BeyondTrust and SolarWinds products An unknown hero blocks 23/tcp on the US internet backbone And James Wilson pops into talk about Claudeâs go at a C compiler This weekâs episode is sponsored by Ent.AI, an AI startup that isnât
Risky Business #823 -- Humans impersonate clawdbots impersonating humans

Published: 02/03/2026 21:13:54
Risky Business #823 -- Humans impersonate clawdbots impersonating humans Episode Details
Patrick Gray and Adam Boileau are joined by the newest guy on the Risky Business Media team, James WIlson. They discuss the weekâs cybersecurity news, including: Notepad++ update supply chain attack has been attributed to China The AI agent future is even more stupid than expected; behold the OpenClaw/Clawdbot/Moltbook mess The Epstein files claim he had a personal hacker? Microsoft is finally getting ready to (think about starting to begin to) disable NTLM by default The usual bugs in the usual things! Ivanti, Fortinet, and Solarwinds. Again. Telco hides a
Risky Business #822 -- France will ditch American tech over security risks

Published: 01/27/2026 21:35:47
Risky Business #822 -- France will ditch American tech over security risks Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news. They discuss: La France is tres sérieux about ditching US productivity software Chinaâs Salt Typhoon was snooping on Downing Street Trump wields the mighty DISCOMBOBULATOR ESET says the Polish power grid wiper was Russiaâs GRU Sandworm crew US cyber institutions CISA and NIST are struggling Voice phishing for MFA bypass is getting even more polished This episode is sponsored by Sublime Security. Brian Baskin is one of the team behind Sublimeâs 2026 Email Threat Research report.
Risky Business #821 -- Wiz researchers could have owned every AWS customer

Published: 01/20/2026 22:28:42
Risky Business #821 -- Wiz researchers could have owned every AWS customer Episode Details
In this weekâs show, Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, joined by a special guest. BBC World Cyber Correspondent Joe Tidy is a long time listener and he pops in for a ride-along in the news segment plus a chat about his new book. This week news includes: Did the US cyber Venezuelaâs power grid, or do they just want us to think they coulda? US govt might boycott the RSAC Conference âcause Jen Easterly being CEO makes them mad MS Patch Tuesday fixes CVSS5.5 bug
Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!)

Published: 01/13/2026 19:42:29
Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) Episode Details
Risky Business returns for 2026! Patrick Gray and Adam Boileau talk through the weekâs cybersecurity news, including: Santa brings hackers MongoDB memory leaks for Christmas Vercel pays out a million bucks to improve its React2Shell WAF defences 39C3 delivers; the pink Power Ranger deletes nazis, while a catgirl ruins GnuPG Cambodian scam compound kingpin gets extradited to China, and we donât think itâll go well for him Krebs picks apart the Kimwolf botnet and residential proxy networks So many healthcare data leaks that we have a roundup section This weekâs
How the World Got Owned Episode 1: The 1980s

Published: 01/06/2026 14:00:00
How the World Got Owned Episode 1: The 1980s Episode Details
In this special documentary episode, Patrick Gray and Amberleigh Jack take a historical dive into hacking in the 1980s. Through the words of those that were there, they discuss life on the ARPANET, the 414s hacking group, the Morris Worm, the vibe inside the NSA and a parallel hunt for German hackers happening at a similar time to Cliff Stollâs famous Cuckooâs Egg story. This podcast features the memories of: Jon Callas, former principal software engineer at Digital Equipment Corporation Mark Rasch, Morris Worm prosecutor Timothy Winslow, former 414 hacker
Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack

Published: 12/16/2025 20:13:10
Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack Episode Details
In the final show of 2025, Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: React2Shell attacks continue, surprising no one The unholy combination of OAuth consent phishing, social engineering and Azure CLI Venezuelaâs state oil firm gets ransomwareâd, blames US⦠but what if it really is a US cyber op?! Russian junk-hacktivist gets indicted for cybering critical⦠err⦠a car wash and a fountain Microsoft finally turns RC4 off by default in Active Directory Kerberos Traefikâs TLS verify=on ⦠turns it off, whoopsie 𤡠This weekâs episode
Risky Biz Soap Box: Graph the planet!

Published: 12/11/2025 13:26:18
Risky Biz Soap Box: Graph the planet! Episode Details
In this sponsored Soap Box edition of the Risky Business podcast, Patrick Gray chats with Jared Atkinson, CTO of SpecterOps, about BloodHound OpenGraph. OpenGraph enumerates attack paths across platforms and services, not just your primary directories. A compromised GitHub account to on-prem AD compromise attack path? Itâs a thing, and OpenGraph will find it. Cross-platform attack path enumeration! So good! This episode is also available on Youtube.
Risky Business #818 -- React2Shell is a fun one

Published: 12/09/2025 20:33:11
Risky Business #818 -- React2Shell is a fun one Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Thereâs a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate? China is out popping shells with it Linux adds support for PCIe bus encryption Amnesty International says Intellexa can just TeamViewer into its customersâ surveillance systems â¦and a Belgian murder suspect complains that GrapheneOSâs duress wipe feature failed him? This weekâs episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Krollâs Cyber and Data Resilience
Risky Business #817 -- Less carnage than your usual Thanksgiving

Published: 12/02/2025 20:38:27
Risky Business #817 -- Less carnage than your usual Thanksgiving Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news. Itâs a quiet week with Thanksgiving in the US, but thereâs always some cyber to talk about: Airbus rolls out software updates after a cosmic ray bitflips an A320 into a dive Krebs tracks down a Scattered Lapsus$ Hunters teen through the usual poor opsec⦠⦠as Wired publishes an opsec guide for teens. Microsoft decides its login portal is worth a Content Security Policy South Korean online retailer data breach covers 65% of the country
Risky Business #816 -- Copilot Actions for Windows is extremely dicey

Published: 11/25/2025 21:34:45
Risky Business #816 -- Copilot Actions for Windows is extremely dicey Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Salesforce partner Gainsight has customer data stolen Crowdstrike fires insider who gave hackers screenshots of internal systems Australian Parliament turns off wifi and bluetooth in fear of of visiting Chinese bigwigs Shai-Hulud npm/Github worm is back, and rm -rfâier than ever SEC gives up on Solarwinds lawsuit Dog eats cryptographerâs key material This weekâs episode is sponsored by runZero. HD Moore pops in to talk about how theyâre integrating runZero with Bloodhound-style graph databases. He
Risky Biz Soap Box: Greynoise knows when bad bugs are coming

Published: 11/20/2025 13:20:20
Risky Biz Soap Box: Greynoise knows when bad bugs are coming Episode Details
In this sponsored Soap Box edition of the podcast, Andrew Morris joins Patrick Gray to talk about how Greynoise can often get a 90 day heads up on serious vulnerabilities. Whether itâs malicious actors doing reconnaissance or the affected vendors trying to understand the scope of the problem, it seems that mass scanning activity lines up pretty nicely with typical 90-day disclosure timelines. A fascinating chat with Andrew, as always. This episode is also available on Youtube.
Risky Business #815 -- Anthropic's AI APT report is a big deal

Published: 11/18/2025 19:43:19
Risky Business #815 -- Anthropic's AI APT report is a big deal Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Anthropic says a Chinese APT orchestrated attacks using its AI Itâs a day ending in -y, so of course there are shamefully bad Fortinet exploits in the wild Turns out slashing CISA was a bad idea, now itâs time for a hiring spree Researchers brute force entire phone number space against Whatsapp contact discovery API DOJ figures out how to make SpaceX turn off scam compoundsâ Starlink service This weekâs episode is sponsored by Mastercard.
Risky Business #814 -- It's a bad time to be a scam compound operator

Published: 11/11/2025 20:48:11
Risky Business #814 -- It's a bad time to be a scam compound operator Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: The KK Park scam compound in Myanmar gets blasted with actual dynamite China sentences more scammers TO DEATH While Singapore is opting to lash them with the cane Chinese security firm KnownSec leaks a bunch of documents Necromancy continues on NSO Group, with a Trump associate in charge OWASP freshens up the Top 10, you wonât believe whatâs number three! This weekâs episode is sponsored by Thinkst Canary. Big bird Haroon Meer joins and, as
Risky Business #813 -- FFmpeg has a point

Published: 11/04/2025 21:29:28
Risky Business #813 -- FFmpeg has a point Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: We love some good vulnerability reporting drama, this time FFmpegâs got beef with Google OpenAI announces its Aardvark bug-gobbling system Two US ransomware responders get arrested for⦠ransomware Memento (nee HackingTeam) CEO says: Sì, those are totally our tools getting snapped in Russia Hackers help freight theft gangs steal shipments to resell A second Jabber Zeus mastermind gets his comeuppance 15 years on This weekâs episode is sponsored by Nucleus Security, who make a vulnerability
Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD

Published: 10/28/2025 22:30:38
Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: L3Harris Trenchant boss accused of selling exploits to Russia once worked at the Australian Signals Directorate Microsoft WSUS bug being exploited in the wild Dan Kaminsky DNS cache poisoning comes back because of a bad PRNG SpaceX finally starts disabling Starlink terminals used by scammers Garbage HP update deletes certificates that authed Windows systems to Entra This weekâs episode is sponsored by automation company Tines. Field CISO Matt Muller joins to discuss how Tines has
Risky Business #811 -- F5 is the tip of the crap software iceberg

Published: 10/21/2025 22:05:21
Risky Business #811 -- F5 is the tip of the crap software iceberg Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: China has been rummaging in F5âs networks for a couple of years Meanwhile China tries to deflect by accusing the NSA of hacking its national timing system Salesforce hackers use their stolen data trove to dox NSA, ICE employees Crypto stealing, proxy-deploying, blockchain-C2-ing VS Code worm charms us with its chutzpah Adam gets humbled by new Linux-capabilities backdoor trick Microsoft ignores its own guidance on avoiding BinaryFormatter, gets WSUS owned. This episode is sponsored by
Wide World of Cyber: A deep dive on the F5 hack

Published: 10/20/2025 21:28:13
Wide World of Cyber: A deep dive on the F5 hack Episode Details
In this edition of the Wide World of Cyber podcast Patrick Gray talks to Chris Krebs and Alex Stamos about the F5 incident. They talk about what happened, whether itâs a big deal, and why private equity ownership of mid-tier cybersecurity companies is often a red flag.
Risky Biz Soap Box: Why Mastercard is scaling its cybersecurity business

Published: 10/16/2025 18:12:05
Risky Biz Soap Box: Why Mastercard is scaling its cybersecurity business Episode Details
In this sponsored Soap Box edition of the Risky Business podcast, host Patrick Gray chats with Mastercardâs Executive Vice President and Head of Security Solutions, Johan Gerber, about how the card brand thinks about cybersecurity and why itâs aggressively investing in the space. After listening to this interview youâll understand why the credit card company spent $2.65b on threat intelligence vendor Recorded Future! This episode is also available on Youtube.
Risky Business #810 -- Data extortion attacks have a silver lining

Published: 10/15/2025 00:30:14
Risky Business #810 -- Data extortion attacks have a silver lining Episode Details
In this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: FBI intervenes in Scattered Spider Salesforce leaksite Clop loots Oracle E-Biz deployments Plus so much more data extortion.. At least itâs not ransomware ⦠we guess? The US still canât decide whoâs gonna be in charge of NSA & Cybercom Cambodian scam compounds get sanctioned and $15b in crypto is seized NSO gets sold for pocket-lint-grade money Bugs! Redis CVSS 10, Ivanti, Crowdstrike and⦠Internet Explorer?! zeroday?! In the wild?!!!? This weekâs episode is sponsored
Snake Oilers: Realm Security, Horizon3 and Persona

Published: 10/07/2025 16:50:04
Snake Oilers: Realm Security, Horizon3 and Persona Episode Details
In this edition of the Snake Oilers podcast, three vendors pop in to pitch you all on their wares: Realm Security: A security focussed, AI-first data pipeline platform Horizon3: AI hackers! Pentesting robots!! Theyâre coming fer yur jerbs! Persona: Verify customer and staff identities with live capture This episode is also available on Youtube.
Risky Business #809 -- Hackers try to pay a journalist for access to the BBC

Published: 10/01/2025 02:01:41
Risky Business #809 -- Hackers try to pay a journalist for access to the BBC Episode Details
On this weekâs show Patrick Gray is on holiday so Amberleigh Jack and Adam Boileau hijack the studio to discuss the weekâs cybersecurity news, including: Hackers learn that trying to coerce a journalist just makes for ⦠a great story? A man in his 40s gets arrested over the European airport chaos. Yep, weâre surprised, too. Adam fanboys over Watchtowr Labs while bemoaning Fortra. Academics pick apart Tile trackers and find them lacking CISA tells agencies to patch their damn Cisco gear This episode is also available on YouTube.
Risky Business #808 -- Insane megabug in Entra left all tenants exposed

Published: 09/23/2025 22:03:14
Risky Business #808 -- Insane megabug in Entra left all tenants exposed Episode Details
On this weekâs show Patrick Gray and special guest Rob Joyce discuss the weekâs cybersecurity news, including: Secret Service raids a SIM farm in New York MI6 launches a dark web portal Are the 2023 Scattered Spider kids finally getting their comeuppance? Production halt continues for Jaguar Land Rover GitHub tightens its security after Shai-Hulud worm This weekâs episode is sponsored by Sublime Security. In this weekâs sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI
Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc

Published: 09/16/2025 22:01:40
Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Shai-Hulud worm propagates via npm and steals credentials Jaguar Land Rover attack may put smaller suppliers out of business Leaked data emerges from the vendor behind the Great Firewall of China Vastaamo hacker walks free while appeal is underway Why is a senator so mad about Kerberos? This weekâs episode is sponsored by Knocknoc. Chief exec Adam Pointon joins to talk through the surprising number of customers that are using Knocknocâs identity-to-firewall glue to protect
Risky Biz Soap Box: runZero shakes up vulnerability management

Published: 09/14/2025 19:01:43
Risky Biz Soap Box: runZero shakes up vulnerability management Episode Details
In this sponsored Soap Box edition of the Risky Business podcast, industry legend HD Moore joins the show to talk about runZeroâs major push into vulnerability management. With its new Nuclei integration, runZero is now able to get a very accurate picture of whatâs vulnerable in your environment, without spraying highly privileged credentials at attackers on your network. It can also integrate with your EDR platform, and other data sources, to give you powerful visibility into the true state of things on your network and in your cloud. This episode
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal

Published: 09/09/2025 23:54:02
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Apple ruins exploit developersâ week with fresh memory corruption mitigations Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack Salesloft says its GitHub was the initial entry point for its compromise Sitecore says people should âpatchâ its using-the-keymat-from-the-documentation âzero dayâ Rogue certs for 1.1.1.1 appear to be just (stupid) testing Jaguar Land Rover ransomware attackers are courting trouble This weekâs episode is sponsored by open source cloud security tool, Prowler.
Snake Oilers: Nebulock, Vali Cyber and Cape

Published: 09/07/2025 23:20:48
Snake Oilers: Nebulock, Vali Cyber and Cape Episode Details
In this edition of the Snake Oilers podcasts, three vendors pop in to pitch you all on their wares: Automated, AI-powered threat hunting with Nebulock Damien Lewke from Nebulock joins the show to talk about how its agentic AI platform can surface attacker activity out of all those âlowâ and âinformationalâ findings your detection team doesnât have time to look at. Runtime security for hypervisors from Vali Cyber Austin Gadient from Vali Cyber stops by to talk about ZeroLock, its hypervisor security product. Itâs marketed as a counter-ransomware control but
Risky Business #805 -- On the Salesloft Drift breach and "OAuth soup"

Published: 09/02/2025 22:56:55
Risky Business #805 -- On the Salesloft Drift breach and "OAuth soup" Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: The Salesloft breach and why OAuth soup is a problem The Salt Typhoon telco hackers turn out to be Chinese private sector, but state-directed Google says it will stand up a âdisruption unitâ Microsoft writes up a ransomware gang thatâs all-in on the cloud future Aussie firm hot-mics its work-from-home employeesâ laptops Youtube scam baiters help the feds take down a fraud ring This episode is sponsored by Dropzone.AI. Founder and CEO Edward Wu joins
Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy

Published: 08/27/2025 00:02:20
Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Australia expels Iranian ambassador Hackers sabotage Iranian shipping satcoms APT hacker got doxxed in Phrack. Kind of. Theyâre probably Chinese, not DPRK? Trail of Bits uses image-downscaling to sneak prompts into Google Gemini The Comâs King Bob gets ten years in the slammer Itâs a day that ends in -y, so of course thereâs a new Citrix Netscaler RCE being used in the wild. This weekâs episode is brought to you by Corelight. Chief Strategy
Wide World of Cyber: Microsoft's China Entanglement

Published: 08/24/2025 23:24:29
Wide World of Cyber: Microsoft's China Entanglement Episode Details
The Wide World of Cyber podcast is back! In this episode host Patrick Gray chats with Alex Stamos and Chris Krebs about Microsoftâs entanglement in China. Redmond has been using Chinese engineers to do everything from remotely support US DoD private cloud systems to maintain the on premise version of the SharePoint code base. Itâs all blown up in the press over the last month, but how did we get here? Did Microsoft make these decisions to save money? Or was it more about getting access to the Chinese market?
Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs

Published: 08/19/2025 23:34:58
Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Oracleâs long term CSO departs, and weâre not that sad about it Canadaâs House of Commons gets popped through a Microsoft bug Russia degrades voice calls via Whatsapp and Telegram to push people towards Max South-East Asian scam compounds are also behind child sextortion Reports that the UK has backed down on Apple crypto are⦠strange Oh and of course thereâs a Fortinet bug! Thereâs always a Fortinet bug! This weekâs episode is sponsored by
Risky Biz Soap Box: How to measure vulnerability reachability

Published: 08/14/2025 18:06:39
Risky Biz Soap Box: How to measure vulnerability reachability Episode Details
In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications. Itâs great to know thereâs a CVE in a library youâre using, but itâs even better if you can say whether or not that vulnerability actually impacts your application. They also talk about how Socket started out as a way to discover malicious packages in software projects, but these days itâs playing the CVE game as well. This episode is also available
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds

Published: 08/13/2025 00:51:34
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: CISA warns about the path from on-prem Exchange to the cloud Microsoft awards a crisp zero dollar bill for a report about what a mess its internal Entra-authed apps are Everyone and their dog seems to have a shell in US Federal Court information systems Google pays $250k for a Chrome sandbox escape Attackers use javascript in adult SVG files to ⦠farm facebook likes?! SonicWall says users arenât getting hacked with an 0day⦠this
Risky Business #801 -- AI models can hack well now and it's weirding us out

Published: 08/06/2025 00:24:55
Risky Business #801 -- AI models can hack well now and it's weirding us out Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news. Google security engineering VP Heather Adkins drops by to talk about their AI bug hunter, and Risky Business producer Amberleigh Jack makes her main show debut. This episode explores the rise of AI-powered bug hunting: Googleâs Project Zero and Deepmind team up to find and report 20 bugs to open source projects The XBOW AI bug hunting platform sees success on HackerOne Is an AI James Kettle on the horizon? Thereâs also plenty of regular cybersecurity
Soap Box: Why AI can't fix bad security products

Published: 07/31/2025 22:37:33
Soap Box: Why AI can't fix bad security products Episode Details
In this Soap Box edition of the show Patrick Gray chats with the CEO of email security company Sublime Security, Josh Kamdjou. They talk about where AI is useful, where it isnât, and why AI canât save vendors from their bad product design choices. This episode is also available on Youtube.
Risky Business #800 â The SharePoint bug may have leaked from Microsoft MAPP

Published: 07/29/2025 23:49:20
Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Did the SharePoint bug leak out of the Microsoft MAPP program? Expel retracts its FIDO bypass writeup The mess surrounding the women-only dating-safety app Tea gets worse Broadcom customers struggle to get patches for VMWare hypervisor escapes Aeroflot gets hacked by the Cyber Partisans, disrupting flights This weekâs episode is sponsored by Push Security. Daniel Cuthbert joins and explains how having telemetry about identity from inside the browser is a key pillar for investigating intrusions in
Risky Business #799 -- Everyone's Sharepoint gets shelled

Published: 07/23/2025 00:53:42
Risky Business #799 -- Everyone's Sharepoint gets shelled Episode Details
Risky Biz returns after two weeks off, and there sure is cybersecurity news to catch up on. Patrick Gray and Adam Boileau discuss: Microsoft tried to make outsourcing the Pentagonâs cloud maintenance to China okay (it was not) She shells Sharepoint by the sea-shore (by âsheâ we mean âChinaâ) Four (alleged) Scattered Spider members arrested (and bailed) in the UK Hackers spend $2700 to buy creds for a Brazilian payment system, steal $100M Fortinet has SQLI in the auth header, Citrix mem leak is weaponised, HP hardcodes creds and Sonicwalls
Risky Biz Soap Box: Prowler, the open cloud security platform

Published: 07/14/2025 15:15:09
Risky Biz Soap Box: Prowler, the open cloud security platform Episode Details
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, founder of open source multi-cloud security product Prowler. Toni explains how Prowler came to be, and how its journey followed his own learning about the cloud. The pair also discuss Prowlerâs successful transition from an open-source project into a community, and now a growing business with an as-a-service platform. This episode is also available on Youtube.
Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses

Published: 07/01/2025 23:54:27
Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Australian airline Qantas looks like it got a Scattered Spider-ing Microsoft works towards blunting the next CrowdStrike disaster Changes are coming for Microsoftâs default enterprise app consenting setup Synology downplays hardcoded passwords for its M365 cloud backup agent The next Citrix Netscaler memory disclosure looks nasty Drug cartels used technical surveillance to find, fix and finish FBI informants and witnesses This weekâs episode is sponsored by RAD Security. Co-founder Jimmy Mesta joins to talk through how
Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators

Published: 06/24/2025 23:48:25
Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: We roll our eyes over the â16 billion credentialsâ leak hitting mainstream news Some interesting cyber angles emerge from the conflict in Iran Opensource maintainer of libxml2 is fed up with this hacker crap Shockingly, there are yet more ways to trick people into pasting commands into Windows Veeam âpatchesâ its backup software RCE like itâs 2002 ⦠by breaking the public PoC This weekâs episode is sponsored by Internet-wide honeypot reconnaissance platform, Greynoise. Founder Andrew
Risky Business #796 -- With special guest co-host Chris Krebs

Published: 06/17/2025 23:43:47
Risky Business #796 -- With special guest co-host Chris Krebs Episode Details
On this weekâs show Patrick Gray and Adam Boileau are joined by special guest Chris Krebs to discuss the weekâs cybersecurity news. They talk through: Israeli âhacktivistsâ take out an Iranian state-owned bank Scattered-spider and friends pivot into attacking insurers Securing identities in a cloud-first world keeps us awake at night Microsoft takes the âaasâ out of SaaS for Europe, leaving us with just software! An AI prompt injection into M365 exfils corporate data This weekâs episode is sponsored by Krollâs Cyber practice. Kroll Cyber Associate Managing Director George Glass
Soap Box: AI has entered the SOC, and it ain't going anywhere

Published: 06/15/2025 20:40:56
Soap Box: AI has entered the SOC, and it ain't going anywhere Episode Details
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Dropzone AI founder Ed Wu about the role of LLMs in the SOC. The debate about whether AI agents are going to wind up in the SOC is over, theyâve already arrived. But what are they good for? What are they NOT good for? And where else will we see AI popping up in security? This episode is also available on Youtube.
Risky Business #795 -- How The Com is hacking Salesforce tenants

Published: 06/10/2025 23:57:30
Risky Business #795 -- How The Com is hacking Salesforce tenants Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: New York Times gets a little stolen Russian FSB data as a treat iVerify spots possible evidence of iOS exploitation against the Harris-Walz campaign Researcher figures out a trick to get Google account holdersâ full names and phone numbers Major US food distributor gets ransomwared The Comâs social engineering of Salesforce app authorisations is a harbinger of our future problems Australian Navy forgets New Zealand has computers, zaps Kiwis with their giant radar. This weekâs episode
Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242

Published: 06/03/2025 23:56:13
Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242 Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Cyber firms agree to deconflict and cross-reference hacker group names Russian nuclear facility blueprints gathered from public procurement websites Someone audio deepfaked the White House Chief of Staff, but for the dumbest reasons Germany identifies the Trickbot kingpin Google spots Chinaâs MSS using Calendar events for malware C2 Meta apps abuse localhost listeners to track web sessions. This weekâs episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss
Risky Business #793 -- Scattered Spider is hijacking MX records

Published: 05/27/2025 23:56:57
Risky Business #793 -- Scattered Spider is hijacking MX records Episode Details
In this weekâs edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the weekâs news, including: EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed Brian Krebs eats a 6.3Tbps DDoS ⦠âcause thatâs how you demo your packet cannon Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers Iranian behind 2019 Baltimore ransomware mysteriously appears in
Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now

Published: 05/20/2025 23:21:26
Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: TeleMessage memory dumps show up on DDoSecrets Coinbase contractor bribed to hand over user data Telegram does seem to be actually cooperating with law enforcement Britainâs legal aid service gets 15 years worth of applicant data stolen Shocking no one, Ivanti were weaseling when they blamed latest bugs on a third party library This weekâs episode is sponsored by Prowler, who make an open source cloud security tool. Founder and original project developer Toni de la
Risky Biz Soap Box: Push Security's browser-first twist on identity security

Published: 05/15/2025 18:33:43
Risky Biz Soap Box: Push Security's browser-first twist on identity security Episode Details
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security. Push has built an identity security platform that collects identity information and events from your usersâ browsers. It can detect phish kits and shut down phishing attempts, protect SSO credentials, and find shadow/personal account that a user has spun up. Itâs extremely difficult to bypass. Thatâs because when youâre in the browser it doesnât matter how a phishing link arrives, or how a threat actor has concealed it
Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys

Published: 05/13/2025 23:47:37
Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Struggling to find that pesky passwords.xlsx in Sharepoint? Copilot has your back! The ransomware ecosystem is finding life a bit tough lately SAP Netweaver bug being used by Chinese APT crew Academics keep just keep finding CPU side-channel attacks And of course⦠bugs! Asus, Ivanti, Fortinet⦠and a Nissan LEAF? This weekâs episode is sponsored by Resourcely, who will soothe your Terraform pains. Founder and CEO Tracis McPeak joins to talk about how to get from
Wide World of Cyber: How state adversaries attack security vendors

Published: 05/08/2025 19:28:56
Wide World of Cyber: How state adversaries attack security vendors Episode Details
In this edition of the Wide World of Cyber podcast Patrick Gray talks to SentinelOneâs Steve Stone and Alex Stamos about how foreign adversaries are targeting security vendors, including them. From North Korean IT workers to Chinese supply chain attacks, SentinelOne and its competitors are constantly fending off sophisticated hacking campaigns. This edition of the Wide World of Cyber was recorded in front of a live audience in San Francisco, with Patrick attending via Zoom. The Wide World of Cyber podcast series is a wholly sponsored co-production between SentinelOne and
Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate

Published: 05/06/2025 23:55:44
Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: White Houseâs off-brand Israeli Signal fork logs cleartext messages with hard coded creds while getting hacked (twice). Just ⦠Wow. Ransomware attacks on UK retailers are linked, and Marks & Spencer has it extra bad After six years dormant, a Magento eCommerce platform backdoor comes to life The North Korean IT worker scam is truly webscale NSO group owes Meta $168m for hacking WhatsApp This weekâs episode is sponsored by vulnerability management wranglers, Nucleus Security. Aaron
BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs

Published: 05/06/2025 00:03:06
BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs Episode Details
In this extended interview the Vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner, joins Risky Business host Patrick Gray to talk about: The latest developments in the Signalgate scandal Why America needs to be more aggressive in responding to Volt Typhoon How tariffs are affecting American alliances Why the Five Eyes alliance is sacrosanct This episode is available on Youtube
Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful

Published: 04/30/2025 00:30:32
Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: British retail stalwart Marks & Spencer gets cybered South Korean telco sets out to replace all its subscriber SIMs after (we assume) it lost the keymat Itâs a good exploit week! Bugs in Apple Airplay, SAP webservers, Erlang SSH and CommVault backups Juice jacking! No, really! Some researchers actually did it (so still not in the wild, then) Anti-DOGE whistleblower sure sounds like he has a point This weekâs episode is sponsored by Knocknoc, who let
Snake Oilers: LimaCharlie, Honeywell Cyber Insights, CobaltStrike and Outflank

Published: 04/27/2025 23:44:34
Snake Oilers: LimaCharlie, Honeywell Cyber Insights, CobaltStrike and Outflank Episode Details
In this edition of the Snake Oilers podcast, three sponsors come along to pitch their products: LimaCharlie: A public cloud for SecOps Honeywell Cyber Insights: An OT security/discovery solution Fortraâs CobaltStrike and Outflank: Security tooling for red teamers This episode is also available on Youtube.
Snake Oilers: Pangea, Cosive and Sysdig

Published: 04/17/2025 00:15:58
Snake Oilers: Pangea, Cosive and Sysdig Episode Details
In this edition of Snake Oilers three vendors pitch host Patrick Gray on their tech: Pangea: Guardrails and security for AI agents and applications (https://pangea.cloud) Worried about your AI apps going rogue, being mean to your customers or even disclosing sensitive information? Pangea exists to address these risks. Fascinating stuff. Cosive: A threat intelligence company that can host your MISP server in AWS. CloudMISP! (https://www.cosive.com/snakeoilers) Are you running a MISP server on some old hardware under a desk in your SOC? Thereâs a better way! Cosive can run it for
Risky Business #788 -- Trump targets Chris Krebs, SentinelOne

Published: 04/15/2025 23:34:04
Risky Business #788 -- Trump targets Chris Krebs, SentinelOne Episode Details
On this weekâs show Patrick Gray talks to former NSA Cybersecurity Director Rob Joyce about Donald Trumpâs unprecedented, unwarranted and completely bonkers political persecution of Chris Krebs and his employer SentinelOne. They also talk through the weekâs cybersecurity news, covering: Mitreâs stewardship of the CVE database gets its funding DOGEâd The US signs on to the Pall Mall anti-spyware agreement China tries to play the nationstate cyber-attribution game, but comedically badly Hackers run their malware inside the Windows sandbox, for security against EDR This weekâs episode is sponsored by open
Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape

Published: 04/10/2025 00:03:10
Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape Episode Details
In this podcast, Patrick Gray chats with SentinelOneâs Chris Krebs and Alex Stamos about the huge changes afoot in the United States government and what they mean for the threat environment. From the director of NSA being fired to massive job cuts at CISA and huge foreign policy shifts, tomorrowâs threat environment is going to be very different to todayâs. Tune in to hear analysis from two of the best in the business! This episode is also available on Youtube.
Risky Business #787 -- Trump fires NSA director, CISA cuts inbound

Published: 04/09/2025 00:30:07
Risky Business #787 -- Trump fires NSA director, CISA cuts inbound Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Oracle quietly cops to being hacked, but immediately pivots into pretending it didnât matter NSA and CyberCom leaders fired for not being MAGA enough US Treasury had some dusty corners it hadnât found China in yet, looked, found China in them â¦which is a great time to discuss slashing CISAâs staffing Ransomware crews and bullet proof hosting providers are getting rekt, and we love it And Microsoft patches yet another logging 0-day being used in the
Risky Business #786 -- Oracle is lying

Published: 04/01/2025 22:40:25
Risky Business #786 -- Oracle is lying Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Yes, Oracle Health and Oracle Cloud did get hacked The fallout from Signalgate continues North Korean IT workers pivot to Europe Honeypot data suggests a storm is brewing for Palo Alto VPNs Canadian Anon gets arrested for hacking Texas GOP This weekâs episode is sponsored by Trail of Bits. Tjaden Hess, a Principal Security Engineer at Trail of Bits who specialises in cryptography, joins the show this week to talk about what a responsible crypto-currency exchange
Soap Box: Knocknoc glues your SSO to your firewalls for Just-in-Time network access

Published: 03/26/2025 18:48:45
Soap Box: Knocknoc glues your SSO to your firewalls for Just-in-Time network access Episode Details
In this Soap Box edition of Risky Business host Patrick Gray talks to Knocknoc CEO Adam Pointon about how to easily rein in attack surface by glueing your single sign-on service to your network controls. Do your Palo Alto and Fortinet devices really need to be discoverable by ransomware crews? Does your file transfer appliance need to be open to the whole world? What about your SSH and RDP? Your Citrix? Your (gasp) Exchange Online servers?? You can do a lot with IP allowlisting and simple Identity Aware Proxies (IAPs)
Risky Business #785 -- Signal-gate is actually as bad as it looks

Published: 03/25/2025 22:41:49
Risky Business #785 -- Signal-gate is actually as bad as it looks Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Yes, the Trump admin really did just add a journo to their Yemen-attack-planning Signal group The Github actions hack is smaller than we thought, but was targeting crypto Remote code exec in Kubernetes, ouch Oracle denies its cloud got owned, but that sure does look like customer keymat Taiwanese hardware maker Clevo packs its private keys into bios update zip US Treasury un-sanctions Tornado Cash, party time in Pyongyang? This weekâs episode is sponsored by runZero.
Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

Published: 03/18/2025 22:58:07
Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Github Actions supply chain attack loots keys and secrets from 23k projects Why a VC fund now owns a minority stake in Risky Business Media (!?!?) China doxes Taiwanese military hackers Microsoft thinks .lnk file whitespace trick isnât worth patching but APTs sure love it CISA delivers government efficiency by re-hiring fired staff⦠to put them on paid leave â¦and Google acquires Wiz for $32bn This weekâs show is sponsored by Zero Networks, and they have
Risky Business #783 -- Evil webcam ransomwares entire Windows network

Published: 03/11/2025 23:30:32
Risky Business #783 -- Evil webcam ransomwares entire Windows network Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news with special guest Rob Joyce, a Former Special Assistant to the US President and Director of Cybersecurity for NSA. They talk through: A realistic bluetooth-proximity phishing attack against Passkeys A very patient ransomware actor encrypts an entire enterprise with a puny linux webcam processor The ESP32 backdoor that is neither a door nor at the back The X DDoS that Elon said was Ukraine is claimed by pro-Palestinian hacktivists Years later, LastPass hackers are still emptying
Risky Business #782 -- Are the USA and Russia cyber friends now?

Published: 03/04/2025 21:25:31
Risky Business #782 -- Are the USA and Russia cyber friends now? Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: Did the US decide to stop caring about Russian cyber, or not? Adam stans hard for North Koreaâs massive ByBit crypto-theft Cellebrite firing Serbia is an example of the system working Starlink keeps scam compounds in Myanmar running Biggest DDoS botnet yet pushes over 6Tbps This weekâs episode is sponsored by network visibility company Corelight. Vincent Stoffer, field CTO at Corelight joins to talk through where eyes on your network can spot attackers like Salt and
Risky Business #781 -- How Bybit oopsied $1.4bn

Published: 02/25/2025 22:20:33
Risky Business #781 -- How Bybit oopsied $1.4bn Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news: North Korea pulls off a 1.5 billion dollar crypto heist Apple pulls Advanced Data Protection from the UK Black Basta ransomware gangâs internal chats leak Russians snoop on Signal with QR codes And Myanmar ships thousands of freed scam compound workers to Thailand Regular guest Lina Lau joins to discuss her work reading Chinese incident response reports on WeChat, and how that has people thinking that ⦠she outed the NSA? This weekâs episode is sponsored
Wide World of Cyber: DeepSeek lobs an AI hand grenade

Published: 02/20/2025 20:31:15
Wide World of Cyber: DeepSeek lobs an AI hand grenade Episode Details
In this episode of the Wide World of Cyber podcast Risky Business host Patrick Gray chats with SentinelOneâs Chris Krebs and Alex Stamos about AI, DeepSeek, and regulation. From its bad transport security to its Chinese ownership and the economic implications of China âentering the chatâ, everyoneâs freaking out over this new model. But should they be? Pat, Alex and Chris dissect the modelâs significance, the politics of it all and how AI regulation in Europe, the US and China will shape the future of LLMs. This episode is also
Risky Business #780 -- ASD torched Zservers data while admins were drunk

Published: 02/18/2025 21:39:53
Risky Business #780 -- ASD torched Zservers data while admins were drunk Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Australian spooks scrubbed Medibank data off Zservers bulletproof hosting Why device code phishing is the latest trick in confusing poor users about cloud authentication Cloudflare gets blocked in Spain, but only on weekends and because of⦠football? Palo Alto has yet another dumb bug Adam gushes about Qualysâ latest OpenSSH vulns Enterprise browser maker Island is this weekâs sponsor and Chief Customer Officer Bradon Rogers joins the show to talk about how the adoption of
Risky Biz Soap Box: Run your own open source IDP with Authentik

Published: 02/13/2025 18:24:24
Risky Biz Soap Box: Run your own open source IDP with Authentik Episode Details
In this SoapBox edition of the show Patrick Gray chats to Fletcher Heisler, the CEO of open-source identity provider Authentik. The whole idea of Authentik is you can take control of an essential IT and security function: identity. Because Authentik is open source itâs extremely flexible, and if youâre running it yourself, you get to decide where your IDP should sit in your architecture. You can run it on prem if youâre an emergency call centre or youâre operating an airgapped network, or you can spin it up in your
Risky Business #779 -- DOGE staffer linked to The Com

Published: 02/11/2025 21:18:48
Risky Business #779 -- DOGE staffer linked to The Com Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Muskâs DOGE kid has a history with The Com Paragon fires Italy as a spyware customer Thailand cuts power to scam compounds⦠⦠and arrests Phobos/8Base Russian cybercrims The CyberCX DFIR report shows non-U2F MFA is well and truly over And much, much more. This weekâs episode is sponsored by Dropzone.AI. They make an AI SOC analysis platform that relieves your analysts of the necessary but tedious work, so they can focus on the value
Risky Business #778 -- Musk's child soldiers seize control of FedGov IT systems

Published: 02/04/2025 21:24:50
Risky Business #778 -- Musk's child soldiers seize control of FedGov IT systems Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: DeepSeek leaves an unauthed database on the internet Russia hacked UK prime ministerâs personal mail Australia sanctions a Telegram group⦠which is more sensible than it sounds Medical device backdoor turns out to be just poorly thought out upgrade feature Google abuses weak hashing to patch AMD CPU microcode And much, much more. This weekâs episode is sponsored by email security boffins Sublime. Their co-founder and CEO Josh Kamdjou joins to talk about how attackersâ
Risky Business #777 -- It's SonicWall's turn

Published: 01/28/2025 21:29:48
Risky Business #777 -- It's SonicWall's turn Episode Details
Coming to you from the same room in Risky Business headquarters Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news. They talk through: Sonicwall firewalls hand out remote code exec like candy Mastercard make a slapstick-grade mistake with their DNS The data breach at PowerSchool and other niche SaaS providers Academic research proposes taking down Europeâs power grid Apple CPUs get a new speculative execution side channel And much, much more. This weekâs episode is sponsored by Push Security, who make an identity security product that runs inside browsers.
Risky Business #776 -- Trump will flex American cyber muscles

Published: 01/21/2025 21:18:15
Risky Business #776 -- Trump will flex American cyber muscles Episode Details
Risky Business returns for its 19th year! Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news and there is a whole bunch of it. They discuss: The incoming Trump administration guts the CSRB Bidenâs last cyber Executive Order has sensible things in it Chinaâs breach of the US Treasury gets our reluctant admiration Ross Ulbricht - the Dread Pirate Roberts of Silk Road fame - gets his Trump pardon New year, same shameful comedy Forti- and Ivanti- bugs US soldier behind the Snowflake hacks faces charges after a solid
Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser

Published: 12/19/2024 21:16:53
Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser Episode Details
In this sponsored Soap Box edition of the show Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes. This is largely a conversation about compliance, but itâs actually interesting and fun. These are words we never thought weâd type! You can find Island at https://island.io/ This episode is also available on Youtube.
Risky Business #775 -- Cl0p is back, SEC hack disclosures disappoint

Published: 12/17/2024 19:37:09
Risky Business #775 -- Cl0p is back, SEC hack disclosures disappoint Episode Details
On this weekâs show, Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: The SECâs cyber incident reporting isnât very exciting after all China Telecom on the way to being thrown out of the US The NSA/Cybercom might get two separate hats The Cl0p ransomware crew are back and taking responsibility for the Cleo hacks (Yet another) File upload bug in Struts makes Java admins weep And much, much more. This episode is sponsored by SpecterOps, who run a pretty top notch offsec/pentest team when theyâre not busy
Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations

Published: 12/12/2024 21:56:26
Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations Episode Details
In this edition of the Wild World of Cyber podcast Patrick Gray sits down with SentinelOneâs Chief Intelligence and Public Policy Officer Chris Krebs to talk all about Chinese cyber operations. They look at the Salt Typhoon and Volt Typhoon campaigns, the last 20 years of Chinese operations, and the evolution of the cyber roles of Chinaâs Ministry of State Security and Peopleâs Liberation Army. Itâs a very dense hour of conversation! This podcast was recorded in front of an audience at the Museum of Contemporary Art in Sydney. This
Risky Business #774 -- Cleo file transfer appliances under widespread attack

Published: 12/10/2024 21:08:26
Risky Business #774 -- Cleo file transfer appliances under widespread attack Episode Details
On this weekâs show, Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Cleo file transfer products have a remote code exec, here we go again! Snowflake phases out password-based auth Chinese Sophos-exploit-dev company gets sanctioned Romaniaâs election gets rolled back after Tiktok changed the outcome AMDâs encrypted VM tech bamboozled by RAM with one extra address bit Some cool OpenWRT research And much, much more. This weekâs episode is sponsored by Thinkst, who love sneaky canary token traps. Jacob Torrey previews an upcoming Blackhat talk filled with
Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered

Published: 12/08/2024 16:49:27
Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered Episode Details
In this interview Patrick Gray talks to Yubicoâs COO and President Jerrod Chong about a new Yubikey feature: pre-registration. You can now ship pre-registered Yubikeys to your staff so you donât need to rely on your staff to enrol them. Theyâve achieved this with really slick Okta and Entra ID integrations. Jerrod also talks about a recent trip to Singapore and concerns he has about the cybersecurity of critical infrastructure in the energy sector.
Risky Business #773 -- Cybercriminals are dropping like flies in Russia

Published: 12/03/2024 19:54:12
Risky Business #773 -- Cybercriminals are dropping like flies in Russia Episode Details
On this weekâs show, Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: The FTC decides its time to take another look at Microsoft Exxonâs opponents targeted by hackers Russian hackers keep getting sentenced and it confuses us The Feds recommend Signal, because throwing hackers out of telcos ainât gonna happen A South Korean set-top-box manufacturer shipped a DDoS client for corpo-combat And much, much more. This weekâs sponsor interview with Vijit Nair from Corelight. We talk to him about doing detection in cloud environments, and how the
Risky Business #772 -- Salt Typhoon is truly a national security disaster

Published: 11/26/2024 21:02:05
Risky Business #772 -- Salt Typhoon is truly a national security disaster Episode Details
On this weekâs show, Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: A ransomware attack has crippled US supply chain software provider Blue Yonder Russian spies hack nearby wifi to get to their targets, but that doesnât seem surprising? Salt Typhoonâs attacks on telcos are hard to solve and big on impact Chinaâs surveillance state workers sell their access at home Palo Alto is bad and should feel bad And much, much more. In this weekâs sponsor interview Patrick Gray chats with Matt Muller from Tines about
Risky Business #771 -- Palo Alto's firewall 0days are very, very stupid

Published: 11/19/2024 21:31:18
Risky Business #771 -- Palo Alto's firewall 0days are very, very stupid Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Microsoft introduces some sensible sounding post-Crowdstrike changes Palo Alto patches hella-stupid bugs in its firewall management webapp CISA head Jen Easterly to depart as Trump arrives AI grandma tarpits phone scammers in family-tech-support hell Academic research supports your gut-reaction; phishing training doesnât work And much, much more. This weekâs episode is sponsored by Greynoise. The always excitable Andrew Morris joins to remind us that the edge-device vulnerabilities Pat and Adam complain about on the show
Risky Business #770 -- A Russian IR guy discovers extremely cool spookware

Published: 11/12/2024 22:31:56
Risky Business #770 -- A Russian IR guy discovers extremely cool spookware Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Apple frustrates law enforcement with iOS auto-reboot CISA says most KEV vulnerabilities in 2023 were first used as zero days Russians roll incident response on some sweet Linux spookware Regular users can create mailboxes in M365? Tor tracks down the source of its joe-job abuse complaints And much, much more. This weekâs feature guest is former FBI agent Chris Tarbell, who arrested Silk Road operator Ross Ulbricht way back in 2013. As suggestions swirl that
Risky Biz Soap Box: Why black box email security is dead

Published: 11/10/2024 20:14:53
Risky Biz Soap Box: Why black box email security is dead Episode Details
In this edition of the Risky Business Soap Box weâre talking all about email security with Sublime Security co-founder Josh Kamdjou. Email security is one of the oldest product categories in security, but as youâll hear, Josh thinks the incumbents are just doing it wrong. He joins Risky Business host Patrick Gray for this interview about Sublimeâs origin story and its new approach to email security.
Risky Business #769 -- Sophos drops implants on Chinese exploit devs

Published: 11/05/2024 22:47:43
Risky Business #769 -- Sophos drops implants on Chinese exploit devs Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: Sophos drops implants on Chinese firewall exploit devs Microsoft workshops better just-in-time Windows admin privileges Snowflake hacker arrested in Canada Okta has a fun, but not very impactful auth-bypass bug Russians bring dumb-but-smart RDP client attacks And much, much more. Special guest Sophos CISO Ross McKerchar joined us to talk about its âhacking backâ campaign. The full interview is available on Youtube for those who want to really live vicariously through Sophos doing what every
Risky Business #768 -- CSRB will investigate China's Wiretap Hacks

Published: 10/29/2024 22:32:59
Risky Business #768 -- CSRB will investigate China's Wiretap Hacks Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: CSRB to investigate Chinaâs telco-wiretapping hacks Euro law enforcement takes down the Redline infostealer Someone steals Fed crypto⦠and then tries to quietly sneak it back in Russia sentences REvil guys to ⦠jail? Really? Apple private cloud compute gets a proper bug bounty program And much, much more. This weekâs episode is sponsored by Material Security, who help navigate the mess of cloud productivity data security. Daniel Ayala - Chief Security and Trust Officer
Risky Biz Soap Box: Thinkst Canary's decade of deception

Published: 10/27/2024 21:36:08
Risky Biz Soap Box: Thinkst Canary's decade of deception Episode Details
In this Soap Box edition of the podcast Patrick Gray chats with Thinkst Canary founder Haroon Meer about his âdecade of deceptionâ, including: A history of Thinkst Canary including a recap of what they actually do A look at why theyâre still really the only major player in the deception game A look at what companies like Microsoft are doing with deception Why security startups should have conference booths
Risky Business #767 â SEC fines Check Point, Mimecast, Avaya and Unisys over hacks

Published: 10/22/2024 21:40:07
Risky Business #767 – SEC fines Check Point, Mimecast, Avaya and Unisys over hacks Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs cybersecurity news, including: SEC fines tech firms for downplaying the Solarwinds hacks Anonymous Sudan still looks and quacks like a Russian duck Apple proposes max 10 day TLS certificate life Oopsie! Microsoft loses a bunch of cloud logs Veeam and Fortinet are bad and should feel bad North Koreans are good (at hacking) And much, much more. This weekâs episode is sponsored by Proofpoint. Chief Strategy Officer Ryan Kalember joins to talk about their work keeping up with
Risky Business #766 â China hacks America's lawful intercept systems

Published: 10/15/2024 22:14:25
Risky Business #766 – China hacks America's lawful intercept systems Episode Details
On this weekâs show Patrick Gray and Adam Boileau discuss the weekâs infosec news, including: Chinese spooks all up in western telco lawful intercept Jerks ruin the Internet Archiveâs day Microsoft drops a great report with a bad chart The feds make their own crypto currency and get it pumped Forti-, Palo- and Ivanti-fail And much, much more. This weekâs episode is sponsored by detection-as-code vendor Panther. Casey Hill, Pantherâs Director Product Management joins to discuss why the old âjust bung it all in a data lake and⦠???⦠â
Snake Oilers: Sandfly Security, Permiso and Wiz

Published: 10/01/2024 18:40:57
Snake Oilers: Sandfly Security, Permiso and Wiz Episode Details
In this edition of Snake Oilers we hear pitches from three security vendors: Sandfly Security: An agentless Linux security platform that actually sounds very cool Permiso: An identity security platform founded by ex FireEye folks Wiz: The cloud security giant is getting in on code security scanning You can watch this edition of Snake Oilers on YouTube here.
