
Risky Bulletin (risky.biz)
Explorez tous les épisodes de Risky Bulletin
Date | Titre | Durée | |
---|---|---|---|
11 Nov 2024 | Between Two Nerds: How Telegram creates cybercriminals | 00:28:11 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how ungoverned spaces on Telegram result in increasingly toxic and antisocial communities. | |||
18 Nov 2024 | Between Two Nerds: Cyber weapons | 00:32:09 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about what cyber weapons really are and why use of the term is counterproductive. They reference Defining Offensive Cyber Capabilities, a paper authored by Tom. Show notes | |||
25 Nov 2024 | Between Two Nerds: Why attribution matters | 00:22:56 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about different views on attribution and why it still matters for sophisticated state-backed groups. | |||
02 Dec 2024 | Between Two Nerds: The kid to criminal pipeline | 00:24:17 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how the opportunities for hackers have changed and how that has altered the pipelines that turn kids into criminals. Show notes | |||
09 Dec 2024 | Between Two Nerds: Why the US is so uptight about cyber operations | 00:30:05 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how states have very different approaches to controlling cyber operations. At the very beginning they refer to this Microsoft Threat Intelligence post. Show notes | |||
16 Dec 2024 | Between Two Nerds: The evolution of Russia's cyber operations in Ukraine | 00:29:28 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the evolution of Russian cyber operations during its invasion of Ukraine. This episode is also available on Youtube. Show notes | |||
26 Aug 2024 | Between Two Nerds: Phishing is easy, phishing is difficult | 00:26:20 | |
In this edition of Between Two Nerds Tom Uren and The Grugq discuss the opportunities in phishing and why it is both easy and difficult. | |||
03 Sep 2024 | Between Three Nerds: How the MSS became a cyber juggernaut | 00:39:51 | |
In this edition of Between Three Nerds Tom Uren and The Grugq talk to Alex Joske, author of a book about how the Chinese Ministry of State Security (MSS) has shaped Western perceptions of China. They discuss the MSS’s position in the Chinese bureaucracy, its increasing role in cyber espionage, its use of contractors and the PRC’s vulnerability disclosure laws. Show notes | |||
09 Sep 2024 | Between Two Nerds: Verify, but don't trust | 00:28:35 | |
In this edition of Between Two Nerds Tom Uren and The Grugq dissect an FBI advisory about North Korean groups targeting cryptocurrency firms with social engineering. | |||
23 Sep 2024 | Between Two Nerds: Setting Europe ablaze with cyber criminals | 00:28:26 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about new reports saying that Russia is creating new cyber groups made up of cyber criminals. | |||
30 Sep 2024 | Between Two Nerds: Cyber forces in Southeast Asia | 00:26:04 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about various Southeast Asian countries investing in cyber forces, the drivers behind these decisions and what kind of actions make sense. | |||
07 Oct 2024 | Between Two Nerds: The rise of cyber persistence | 00:22:08 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about ‘cyber persistence theory’. They cover what it is, why it is increasingly popular amongst America’s allies, why we think the theory is right and also cover some critiques of the theory. They refer to the article in CyberScoop ‘America’s allies are shifting: Cyberspace is about persistence, not deterrence’ in CyberScoop. Show notes | |||
14 Oct 2024 | Between Two Nerds: How criminals are using deepfakes | 00:25:41 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how criminals are using deepfakes… but it is not the end of the world. Show notes | |||
21 Oct 2024 | Between Two Nerds: Measuring cyber power | 00:31:43 | |
In this edition of Between Two Nerds Tom Uren and The Grugq talk about a new attempt to measure cyber power, the International Institute for Strategic Studies Cyber Power Matrix. Show notes | |||
04 Nov 2024 | Between Two Nerds: The grand strategy of ransomware | 00:28:31 | |
In this edition of Between Two Nerds Tom Uren and The Grugq discuss what the Russian state gains and loses from hosting a ransomware ecosystem. | |||
21 Aug 2024 | Risky Biz News: Mandatory MFA comes to Azure admins in October | 00:08:20 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
23 Aug 2024 | Risky Biz News: Fraud tactics evolve with NFC card cloning malware | 00:06:53 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
26 Aug 2024 | Risky Biz News: Telegram founder Pavel Durov detained in France | 00:06:11 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
28 Aug 2024 | Risky Biz News: Volt Typhoon returns with a new zero-day | 00:06:45 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
30 Aug 2024 | Risky Biz News: Iranian APT moonlights as access broker and ransomware helper | 00:10:05 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
02 Sep 2024 | Risky Biz News: US charges swatters who terrorized government officials | 00:08:15 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
04 Sep 2024 | Risky Biz News: China ramps up US election disinformation | 00:04:50 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey. You can find the newsletter version of this podcast here. Show notes | |||
06 Sep 2024 | Risky Biz News: Doppelganger gets a kick in the butt from Uncle Sam | 00:11:11 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
09 Sep 2024 | Risky Biz News: Two security enhancements coming to Windows | 00:09:24 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
11 Sep 2024 | Risky Biz News: UK NCA "on its knees" and bleeding staff | 00:08:07 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
13 Sep 2024 | Risky Biz News: Vo1d infects 1.3 million Android TV boxes | 00:11:13 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
16 Sep 2024 | Risky Biz News: US says RT moved into cyber and intelligence-gathering territory | 00:07:28 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
18 Sep 2024 | Risky Biz News: US Treasury piles more sanctions on Intellexa | 00:08:33 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
20 Sep 2024 | Risky Biz News: A flurry of law enforcement takedowns | 00:08:07 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
23 Sep 2024 | Risky Biz News: Stealer devs bypass Chrome's new cookie protection | 00:07:27 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
25 Sep 2024 | Risky Biz News: China says Taiwan's military is behind a hacktivist group | 00:08:01 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
27 Sep 2024 | Risky Biz News: Three years later, US charges Joker's Stash carding forum admin | 00:08:36 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
30 Sep 2024 | Risky Biz News: Attackers are on the hunt for the new UNIX CUPS RCE | 00:09:34 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
02 Oct 2024 | Risky Biz News: New EvilCorp sanctions and LockBit arrests | 00:08:42 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
04 Oct 2024 | Risky Biz News: Russia arrests Cryptex founder a week after US sanctions | 00:07:47 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
06 Oct 2024 | Risky Biz News: China wiretaps US wiretapping system | 00:06:09 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
09 Oct 2024 | Risky Biz News: EU adopts new sanctions framework to cover Russia's cyber warfare and disinformation | 00:07:20 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
11 Oct 2024 | Risky Biz News: Dutch government to physically replace tens of thousands of hackable traffic lights | 00:08:52 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
14 Oct 2024 | Risky Biz News: Verizon call logs breached | 00:09:44 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
16 Oct 2024 | Risky Biz News: China says the US is framing other countries for espionage operations | 00:07:24 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
18 Oct 2024 | Risky Biz News: Anonymous Sudan's Russia Links Are (Still) Obvious | 00:09:20 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
21 Oct 2024 | Risky Biz News: The EU will make vendors liable for bugs | 00:06:51 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
23 Oct 2024 | Risky Biz News: Apple wants a 45 day limit on TLS certificates | 00:08:32 | |
This episode previously referred to a 10 day limit, but we read the wrong bit of a table. This has been corrected in the title to 45 days, but the podcast audio still refers to the incorrect 10 day maximum age. Sorry! A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
25 Oct 2024 | Risky Biz News: Fortinet bungles another zero-day disclosure | 00:08:48 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
27 Oct 2024 | Risky Biz News: Russia sends REvil gang members to prison | 00:10:29 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
29 Oct 2024 | Risky Biz News: Two arrests in Operation Magnus | 00:04:59 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
01 Nov 2024 | Risky Biz News: Sophos doxes Chinese exploit development centers | 00:10:45 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
04 Nov 2024 | Risky Biz News: 1,000 detained in scam compound raid | 00:08:25 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
06 Nov 2024 | Risky Biz News: Big changes coming to Windows 11 admin accounts | 00:06:45 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
07 Nov 2024 | Risky Biz News: Russia blocks Cloudflare ECH connections | 00:06:33 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
11 Nov 2024 | Risky Biz News: iPhones are auto-rebooting to defeat law enforcement | 00:09:52 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
12 Nov 2024 | Risky Biz News: Most of 2023's top exploited vulnerabilities were initially zero-days | 00:06:44 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
15 Nov 2024 | Risky Biz News: MSS now dominates China's cyber activity | 00:09:26 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
18 Nov 2024 | Risky Biz News: Unpatched zero-day in Palo Alto Networks is in the wild | 00:11:23 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
20 Nov 2024 | Risky Biz News: Remote fix feature for unbootable PCs coming to Windows | 00:07:39 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
22 Nov 2024 | Risky Biz News: US charges five Scattered Spider members | 00:08:25 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
24 Nov 2024 | Risky Biz News: Four PR firms are behind a Chinese propaganda network | 00:07:59 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
27 Nov 2024 | Risky Biz News: Banshee Stealer shuts down after source code leak | 00:07:15 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
29 Nov 2024 | Risky Biz News: Microsoft’s thanksgiving treat: an FTC investigation | 00:07:29 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
02 Dec 2024 | Risky Biz News: Russia arrests WazaWaka | 00:05:12 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
04 Dec 2024 | Risky Biz News: Poland arrests former spy chief in Pegasus scandal | 00:08:39 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
05 Dec 2024 | Risky Biz News: Salt Typhoon's telco hacking spree keeps getting bigger | 00:07:41 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
08 Dec 2024 | Risky Biz News: Members of US Congress targeted by phishing op | 00:06:01 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
11 Dec 2024 | Risky Biz News: Improperly patched Cleo bug exploited in the wild | 00:09:42 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. You can find the newsletter version of this podcast here. Show notes | |||
13 Dec 2024 | Risky Bulletin: Germany's BSI sinkhole BADBOX malware | 00:08:52 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. Show notes | |||
16 Dec 2024 | Risky Bulletin: Secret ransomware campaign targeted DrayTek routers for a year | 00:07:42 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. Show notes | |||
18 Dec 2024 | Risky Bulletin: Cl0p returns | 00:07:38 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. Show notes | |||
19 Dec 2024 | Risky Bulletin: Russia designates Recorded Future an "undesirable organization" | 00:07:14 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. Show notes | |||
19 Jan 2025 | Risky Bulletin: Biden's last cyber executive order | 00:06:06 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. Show notes | |||
21 Jan 2025 | Risky Bulletin: Trump guts the Cyber Safety Review Board | 00:04:14 | |
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird. Show notes | |||
25 Aug 2024 | Sponsored: How Thinkst has survived with a hacker-like mentality at its core | 00:17:38 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Haroon Meer, Founder and CEO at Thinkst, about the company’s evolution over the past 15 years, its focus on hacker-like internal culture, and the UK NCSC’s new deception network. Show notes | |||
01 Sep 2024 | Sponsored: GreyNoise launches private preview of Plasma sensors | 00:22:47 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Andrew Morris, founder of security firm GreyNoise. Andrew introduces Plasma, a new GreyNoise product that can allow customers to deploy custom GreyNoise sensors anywhere they want—on perimeters, on internal networks, on DMZs, or anywhere else. Show notes | |||
08 Sep 2024 | Sponsored: Sublime Security on generative AI attacks in the wild | 00:16:03 | |
In this Risky Business News sponsored interview, Tom Uren talks to Josh Kamdjou, founder and CEO of Sublime Security, about the spectrum of attacks that are taking advantage of generative AI. These range from taking basic attacks with a pinch of AI pixie dust to more complex attacks where AI is used to construct message threads with multiple personas. Josh also talks about how different AI models can be used to identify these attacks even when they are novel. | |||
22 Sep 2024 | Sponsored: Resourcely on some of the hard truths about security teams | 00:12:50 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Resourcely co-founder and CEO Travis McPeak about some of the hard and uncomfortable truths about the role of security teams inside a company. Show notes | |||
29 Sep 2024 | Sponsored: What NSA gets wrong about microsegmentation | 00:14:42 | |
In this Risky Business News sponsored interview, Tom Uren talks to Benny Lakunishok, CEO and cofounder of ZeroNetworks, about network microsegmentation, why it is important, how to do it, and what the NSA gets wrong about it. | |||
06 Oct 2024 | Sponsored: Airlock Digital on what else should be disabled in Windows | 00:20:40 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Airlock Digital founders Daniel Schell and David Cottingham about other things Microsoft can do to secure and harden Windows. Show notes | |||
13 Oct 2024 | Sponsored: Trail of Bits on post-quantum cryptography | 00:14:29 | |
In this Risky Business News sponsored interview, Tom Uren talks to Dan Guido, CEO of Trail of Bits, about post-quantum cryptography. The pair dive into what it is, why it is needed now and how organisations are dealing with its adoption. | |||
20 Oct 2024 | Sponsored: How serious attackers drive MFA adoption | 00:11:59 | |
In this Risky Business News sponsored interview, Tom Uren talks to Brett Winterford, Okta’s APAC Chief Security Officer. Brett has mined Okta’s data and finds strong evidence that organisations invest in phishing-resistant authentication methods once they know they’ve been targeted by groups that excel at social engineering (such as Scattered Spider). Brett discussed this research at Okta’s conference, Oktane, which was held in Las Vegas on 15 to 17 October 2024. | |||
03 Nov 2024 | Sponsored: Nucleus Security on partners and integrations | 00:16:59 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Adam Dudley, Senior Director for Strategic Initiatives & Alliances at Nucleus Security, on how the company works with partners and customers to constantly improve its service. Adam also touches on how executives are now inquiring about vulnerability management more than low-level practitioners. Show notes | |||
24 Nov 2024 | Sponsored: Breaking the deadlock between IT and security teams | 00:13:50 | |
In this Risky Business News sponsored interview, Tom Uren talks to Mike Wiacek, CEO and founder of Stairwell, about the occasionally dysfunctional relationship between IT and security teams. Mike talks about how security vendors need to reach out to turn IT teams into allies. | |||
01 Dec 2024 | Sponsored: Push Security on its new stolen credentials detection feature | 00:21:09 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Jacques Louw, co-founder and chief product officer at Push Security, on the company’s new stolen credentials detection feature, how AitM phishing can be spotted in the browser, and how Push deals with customers needing help with MFA. | |||
08 Dec 2024 | Sponsored: Proofpoint on the rise of ClickFix attacks | 00:13:16 | |
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Proofpoint senior threat intelligence analyst Selena Larson about the rise of Attacker-in-the-Middle phishing and ClickFix social engineering campaigns. Show notes | |||
19 Jan 2025 | Sponsored: The tidal wave of cloud technical debt | 00:11:59 | |
In this Risky Bulletin sponsor interview, Travis McPeak, the CEO and founder of Resourcely, explains that companies are now realising they have a ton of cloud-related technical debt because of the success of cloud posture management products. Travis talks about different approaches he has seen to tackle rampant cloud misconfigurations. Show notes | |||
20 Dec 2024 | RBTALKS5: How Pfizer uses AI to detect insider risk | 00:22:30 | |
Brian A. Coleman, Senior Director for Insider Risk, Information Security, and Digital Forensics at Pfizer, talks to us about how his security team is experimenting with AI to improve their insider risk detection systems. The system Brian and his team put together can detect sensitive information or documents handled by unauthorized accounts, but can also spot documents moving around and ending up where they shouldn’t be - either by accident, malice, or as a result of a security breach. Show notes | |||
07 Nov 2024 | Srsly Risky Biz: How Telegram makes criminal enterprise easy | 00:16:17 | |
In this podcast Tom Uren and Patrick Gray talk about the Snowflake hack after the person allegedly responsible was arrested in Canada. Telegram is involved at all sorts of levels and Tom wonders if this crime would have occurred if Telegram didn’t exist. They also discuss the impact of the Chinese hack of US telcos and Sophos’ five-year cyber knife fight with Chinese APT crews. This episode is also available on Youtube. | |||
14 Nov 2024 | Srsly Risky Biz: How Trump will drive covert operations | 00:17:00 | |
In this podcast Tom Uren and Patrick Gray talk about what to expect from President Trump’s second term. Trump is an activist president who believes in using state power, so intelligence agencies will be pushed to conduct more audacious or even outrageous covert operations. They also discuss concerns about a new UN cybercrime treaty that is set for a vote at the General Assembly and the Canadian government’s curious decision to force the closure of TikTok’s local offices. This episode is also available on Youtube. | |||
21 Nov 2024 | Srsly Risky Biz: The PLA's cyber operations go dark | 00:14:54 | |
In this podcast Tom Uren and Patrick Gray talk about what the People’s Liberation Army cyber operators have been up to. They used to be China’s most visible cyber operators but have since disappeared. They also discuss the shift towards widespread exploitation of 0days, particularly in enterprise perimeter devices. This episode is also available on Youtube. | |||
28 Nov 2024 | Srsly Risky Biz: Australian government to shut down AN0M evidence appeals | 00:17:12 | |
In this podcast Tom Uren and Patrick Gray talk about the Australian Government’s extraordinary legislation that will retrospectively ensure that warrants used for the An0m crimephone sting operation are valid. They also discuss a sterling CISA red team report and the naiveté of Microsoft’s Vice Chair and President Brad Smith. This episode is also available on Youtube. | |||
05 Dec 2024 | Srsly Risky Biz: Why hack and leak is still a big deal | 00:21:41 | |
In this podcast Tom Uren and Adam Boileau talk about the continued importance of hack and leak operations. They didn’t really affect the recent US presidential election, but they are still a powerful tool for vested interests to influence public policy. They also discuss the police bust of MATRIX, yet another encrypted messenger that is marketed to criminals and designed to resist police surveillance. The crimephone landscape is splintering due to the constant drumbeat of police success. This episode is also available on Youtube. | |||
12 Dec 2024 | Srsly Risky Biz: FCC demands telcos improve security | 00:17:20 | |
In this podcast Tom Uren and Patrick Gray talk about the US Federal Communications Commission effort to get US telcos to lift their security game and compares it to UK and Australian efforts. The US is very late to the game, and improving security is a huge job. They also talk about Chinese cyber actors continuing to pointlessly sow chaos and how an influence campaign in Romania is an absolute disaster for TikTok. This episode is also available on Youtube. | |||
19 Dec 2024 | Srsly Risky Biz: Why two hats are better than two heads | 00:19:48 | |
In this podcast Tom Uren and Patrick Gray talk about the likelihood that the incoming Trump administration will end the ‘dual-hat’ arrangement where a single officer leads both US Cyber Command and the National Security Agency. This would result in Cyber Command outranking NSA and could prioritise cyber disruption operations over intelligence collection. That would be a bad outcome. They also talk about how changes to SEC disclosure rules have led to an outpouring of corporate drivel and how WhatsApp became an everything app. This episode is also availble on Youtube. Show notes | |||
22 Aug 2024 | Australia's National ID System Will Be Awful... And Then Great | 00:18:17 | |
In this podcast Tom Uren and Patrick Gray discuss an Australian government effort to bridge the gap between online and real identity across the whole economy. It addresses a real need, but Tom doesn’t think it will go smoothly. They also discuss ongoing Chinese cyber espionage focussed on Russian targets. They may have a ‘no limits’ friendship, but spying between allies is remarkably common. This episode is also available on Youtube. | |||
29 Aug 2024 | Srsly Risky Biz: Telegram's CEO released on bail, can't leave France | 00:17:12 | |
In this podcast Tom Uren and Patrick Gray talk about Telegram’s founder and CEO Pavel Durov being bailed. They dive into the backstory behind the charges he’s facing and what it all might mean for other messaging platforms. They also discuss a very handy list of straightforward ways to detect North Korean’s trying to sneak into remote work jobs. | |||
05 Sep 2024 | Srsly Risky Biz: Using Exploits to Steal Exploits Is as Old as Time | 00:14:56 | |
In this podcast Tom Uren and Patrick Gray discuss Russia’s use of exploits from commercial spyware vendors. Bought through a front, or stolen with other bugs? The also discuss Iran’s counter-intelligence innovations - if you apply for a job thats very clearly an Israeli front, then perhaps you’re not that trustworthy after all? This episode is also available on Youtube. | |||
12 Sep 2024 | Srsly Risky Biz: The three I's in Spyware | 00:17:54 | |
In this podcast Tom Uren and Patrick Gray talk about the structure of the spyware ecosystem. It’s concentrated, with lots of vendors in India, Israel and Italy. And its a small pool of talent, with many companies being founded by just a few individuals. They also talk about the US government’s actions against Russia’s disinformation ecosystem. The US very clearly linked different ‘layers’ of that ecosystem directly to the Russian government. Employing influencers via cutouts also shows how Russian disinformation has responded as social media platforms have countered interference efforts. This episode is also available on Youtube. | |||
26 Sep 2024 | Srsly Risky Biz: Neutering Volt Typhoon to deter China | 00:14:28 | |
In this podcast Tom Uren and Patrick Gray talk about the possibility of deterring Volt Typhoon, the Chinese group that is compromising US critical infrastructure to enable future disruption operations in the event of a conflict with US. Tom thinks it is not possible to deter Volt Typhoon, but things might work the other way. If the US can neuter Volt Typhoon and take away the PRC’s magic cyber bullet, it could make conflict less likely. They also discuss the lessons for all companies in Microsoft’s security turnaround and how X and Telegram have folded in the face of government pressure. The video version of this episode is also available on Youtube. | |||
03 Oct 2024 | Srsly Risky Biz: Tackling election interference at warp speed | 00:20:17 | |
In this podcast Tom Uren and Adam Boileau talk about how the US government’s response to Iranian election interference is proceeding at light speed. This allows other actors such as Meta to make decisions relating to interference with certainty. They also discuss how Russian cybercrime group Evil Corp’s relationship with Russian intelligence was built on the founder’s marriage. This episode is also available on Youtube. | |||
10 Oct 2024 | Srsly Risky Biz: How Telegram turbocharges organised crime | 00:22:42 | |
In this podcast Tom Uren and Adam Boileau talk a new UN report that spells out the role Telegram plays as a massive enabler for transnational organised crime. They also discuss China’s hacking of US telcos to possibly target of lawful intercept equipment and a remarkably entertaining account of North Korean IT workers being employed by over a dozen cryptocurrency firms. This episode is also available on Youtube. Show notes | |||
17 Oct 2024 | Srsly Risky Biz: When thuggery is your cyber talent pipeline | 00:22:47 | |
In this podcast Tom Uren and Patrick Gray talk about the evolving relationship between Russian intelligence services and the country’s cybercriminals. The GRU’s sabotage unit, for example, has been recruiting crooks to build a destructive cyber capability. Tom suspects that GRU thugs are not so good at hands-on-keyboard operations, but excellent at coercing weedy cybercriminals to hack for the state. They also talk about OpenAI’s report into malicious actor’s use of its models, and how Australia’s proposed cyber security law looks pretty sensible. Show notes | |||
24 Oct 2024 | Srsly Risky Biz: EU lobs software liability hand grenade | 00:19:47 | |
In this podcast Tom Uren, Patrick Gray and Adam Boileau talk about an EU directive that will make vendors liable for software defects. The directive sets a very high bar but is also limited in scope. It only applies to individuals and doesn’t cover professional use so it is a very practical way to start changing expectations about liability. They also talk about Session Messenger app which has decamped from Australia and set up a foundation in Switzerland. The encrypted and metadata-resistant app is catnip for criminals, so we expect that it is on a collision course with state power. This episode is also available on Youtube. |