Regular cybersecurity news updates from the Risky Business team...
Risky Biz News: Ivanti finally releases zero-day patches
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
2/2/2024 • 0
Srsly Risky Biz: US data dumpster fire singes NSA
In this podcast Patrick Gray and Tom Uren talk about how the NSA suffered collateral damage from the US’s lax data privacy environment.
They also discuss how to respond to aggressive adversaries, how the current SEC cyber security disclosure regime is pointless and finally admit they occasionally get things wrong.
2/1/2024 • 0
Risky Biz News: Brazilian police arrest Grandoreiro malware gang
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/31/2024 • 0
Between Two Nerds: Rethinking mobile phones on the battlefield
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how the war in Ukraine is showing how useful mobile devices are in war. Using them is risky, but those risks need to be managed.
They refer to this report which examines location tracking in the battlefield.
1/30/2024 • 0
Risky Biz News: DOJ and FTC tell companies to stop deleting chats
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/29/2024 • 0
REPOSTED: Sponsored: Talking with Island on how enterprise browsers could replace some technology stacks
NOTE: We initially published the wrong mp3 for this episode. It has been corrected!
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Bradon Rogers, Chief Customer Officer at enterprise browser Island, on how a modern enterprise browser solution like Island can be used to replace, complement, or enhance some enterprise security tools or technology stacks.
1/29/2024 • 0
Srsly Risky Biz: How the SEC's new cyber disclosure rules are shaking out
In this podcast Patrick Gray and Tom Uren talk about how the SEC’s new disclosure rules that mean companies have four days to report cyber security incidents once they’ve formally decided that they are material. So far, companies are very much erring on the side of caution.
They also look at the criticism of the CSRB’s board composition. Tom thinks these critiques are misguided. The cyber security landscape is so fractured that if the board were made up of faceless bureaucrats it would get very limited traction.
1/26/2024 • 0
Between Two Nerds: Why data brokers aren't causing widespread harms
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how having so much data available about Americans feels creepy, yet there is little visible harm to individuals. But there are still reasons to be worried.
1/25/2024 • 0
Risky Biz News: SVR hackers also breached HPE
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/25/2024 • 0
Risky Biz News: AU, UK, US sanction Russian behind Medibank ransomware attack
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/24/2024 • 0
Sponsored: Why finding and responding threats isn't enough and we need to contain them as well
In this Risky Business News sponsor interview Tom Uren talks to Ivan Dwyer of Material Security about how it makes sense to view office productivity suites as an organisation’s critical infrastructure.
1/22/2024 • 0
Risky Biz News: SVR hackers breach Microsoft
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/22/2024 • 0
Risky Biz News: Congress considers making CSRB permanent
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/19/2024 • 0
Srsly Risky Biz: The PRC doesn't care about stealth, just access
In this podcast Adam Boileau and Tom Uren talk about how although the PRC has pivoted to quieter living-off-the-land approaches, they don’t really care about stealth. They just want long-term access. So this means noisily digging in to networks and targeting end-of-life devices.
They also look at the FTC’s settlement against geolocation data broker Outlogic. It’s a win, but it’s built on shaky foundations.
1/18/2024 • 0
Risky Biz News: Ivanti Connect Secure zero-days suffer mass exploitation
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/17/2024 • 0
Between Two Nerds: Stuxnet, the inevitable game changer
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how Stuxnet was an ‘inevitability gamechanger’, how much we now know about the operation and how much the Dutch government should have known at the time.
1/16/2024 • 0
Risky Biz News: Chinese APT hacks a third of Cisco RV320/325 routers
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/15/2024 • 0
Sponsored: How the rise of cloud has changed the SIEM game
In this Risky Business News sponsor interview Tom Uren talks to Ken Westin, Field CISO at Panther about how the rise of cloud and hybrid IT architectures requires a new type of SIEM.
1/14/2024 • 0
Risky Biz News: Chinese APT exploits two Pulse Secure zero-days
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/12/2024 • 0
Srsly Risky Biz: Russia's cyber war fantasy
In this podcast Adam Boileau and Tom Uren talk about how cyber operations are being used in conflicts in both Ukraine and the Middle East. Some of these operations make sense but others seem pointless or even counterproductive.
1/11/2024 • 0
Risky Biz News: Ransomware wrecks Paraguay's largest telco
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/10/2024 • 0
Between Three Nerds: Martijn Grooten on how Infosec has changed
In this edition of Between Two Nerds Tom Uren and The Grugq talk with infosec and anti-virus veteran Martijn Grooten about how the infosec industry has changed over the years.
1/9/2024 • 0
Sponsored: When you have to run that Chinese government tax software
In this Risky Business News sponsor interview Tom Uren talks to Chris St Myers, Stairwell’s head of threat research, about managing the risk from software you absolutely must use.
Show notes
Stairwell's Inception Platform
1/8/2024 • 0
Risky Biz News: Merck settles NotPetya lawsuit
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast click here.
1/8/2024 • 0
Risky Biz News: UK summons Russian ambassador over hacking campaigns
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
12/8/2023 • 0
Srsly Risky Biz: Why election interference is inevitable
In this podcast Patrick Grey and Tom Uren talk about whether election interference will take place in the Taiwanese, US and Russian elections that are all taking place in 2024.
They also look at a ChatGPT-powered online harassment campaign.
12/7/2023 • 0
Between Two Nerds: Revisiting Ukraine's IT Army
In this edition of Between Two Nerds Tom Uren and The Grugq talk about recent hints that the Ukrainian government has figured out how to make use of the IT Army
12/5/2023 • 0
Risky Biz News: US government agencies officially suck at logging
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
12/5/2023 • 0
Risky Biz News: US Government sounds alarm on water plant hacks
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
12/4/2023 • 0
Risky Biz News: Black Basta group made $107 million from ransom payments
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
12/1/2023 • 0
Srsly Risky Biz: Living off the land is the new normal
In this podcast Patrick Grey and Tom Uren talk about how threat actors abusing legitimate tools (aka living off the land) is the new normal. Everyone is doing it, from activists to cybercriminals to nation states. It’s a worry because defender’s standard practices really aren’t set up to detect and deal with that kind of behaviour.
They also discuss how cyber incidents in the US and UK amongst providers of key real estate services are disrupting house sales.
11/30/2023 • 0
Risky Biz News: Ransomware cripples hospitals in six US states
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/29/2023 • 0
Between Two Nerds: The evolution of Russian electricity attacks
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the latest Russian cyber attacks on the Ukrainian energy grid.
11/28/2023 • 0
Risky Biz News: Chipmaker NXT hacked by Chinese APT group
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/27/2023 • 0
Sponsored: Corelight's Brian Dye on how network data is the connective tissue of incident response
In this Risky Business News sponsor interview Tom Uren talks to Brian Dye, CEO of Corelight about the value of data from NDR tools when it comes to longer term incident response.
11/26/2023 • 0
Srsly Risky Biz: Death by a thousand cuts
In this podcast Adam Boileau and Tom Uren talk the rise of the Indian hack-for-hire industry. It doesn’t get the same attention that high-profile iPhone ‘zero-click’ hacking does, but its a global scourge that undermines legal processes.
They also discuss the AlphV ransomware group reporting a company to the SEC for not disclosing a breach that it caused.
11/23/2023 • 0
Risky Biz News: Fastly to block domain fronting in 2024
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/23/2023 • 0
Risky Biz News: Tor Project removes 1k relays linked to cryptocurrency scheme
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/22/2023 • 0
Between Two Nerds: How marketing has changed the cyber security landscape
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how being more open about cyber security threats is great for marketing and has also forced cyber security companies to pick sides and make value judgements.
11/21/2023 • 0
Risky Biz News: DIALStranger vulnerabilities disclosed after four years
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/20/2023 • 0
Sponsored: Everything you wanted to know about Passkeys but were too afraid to ask
In this Risky Business News sponsor interview Tom Uren talks to Derek Hanson, Yubico’s VP of Solutions Architecture and Alliances about the state of authentication and what Passkeys are all about.
11/20/2023 • 0
Risky Biz News: FCC adopts SIM-swapping and port-out protections
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/17/2023 • 0
Srsly Risky Biz: LockBit's disastrous success
In this podcast Adam Boileau and Tom Uren talk about two very significant cyber incidents. In the first, LockBit attacked the US arm of China’s biggest bank and the disruption left the bank owing USD$9bn at the end of the day. The other disrupted 40% of Australia’s port traffic.
They also examine the reasons why it makes sense for banks to do more regarding fraud.
11/16/2023 • 0
Risky Biz News: Russia hacked 22 Danish critical infrastructure companies
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/15/2023 • 0
Between Two Nerds: The Rules of War in cyberspace
In this edition of Between Two Nerds Tom Uren and The Grugq talk about International Humanitarian Law aka the Rules of War in cyberspace. These rules don’t really make sense in cyberspace, but despite that we think talking about them (and other norms of behaviour) is still worthwhile
11/14/2023 • 0
Sponsored: Ryan Mahoney on how Gigamon lets you have your cake and eat it too
In this Risky Business News sponsor interview Tom Uren talks to Ryan Mahoney, Product Director at Gigamon. The TLS 1.3 encryption standard makes passive network monitoring inside your network difficult without break and inspect contortions. But Gigamon has what they call a “precryption” solution!
11/13/2023 • 0
Risky Biz News: Malay officials take down BulletProftLink
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/13/2023 • 0
Risky Biz News: Clop is coming for your SysAid servers
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
In this podcast Adam Boileau and Tom Uren talk about Microsoft’s Secure Future Initiative. It’s been likened to the company’s 2002 Trustworthy Computing initiative, but compared to that it is a massive disappointment.
They also discuss how the European-wide police operation against EncroChat unravelled when a UK intelligence analyst warned her friends with criminal links that the service had been compromised.
11/9/2023 • 0
Risky Biz News: Microsoft makes MFA mandatory for cloud admin portals
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/8/2023 • 0
Between Two Nerds: The Morris Worm
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the internet-melting 1988 Morris Worm and how cyber security has changed since then.
11/7/2023 • 0
Risky Biz News: US sanctions Russian woman for laundering Ryuk gang money
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/6/2023 • 0
Sponsored: runZero's Huxley Barbee on finding the unknown unknowns
In this Risky Business News sponsor interview Tom Uren talks to Huxley Barbee, Security Evangelist at runZero finding the unknown unknowns and what even is a security evangelist anyway.
11/6/2023 • 0
Risky Biz News: Microsoft goes through a second Trustworthy Computing moment
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/3/2023 • 0
Srsly Risky Biz: When good cyber security leads to violence
In this podcast host Adam Boileau and Tom Uren talk about the confluence of hacking and real-world violence.
They also discuss the SEC’s decision to charge SolarWinds and its CISO for not being transparent enough about SolarWinds’ real cybersecurity risks. Unfortunately, almost all companies have cyber security problems but disclose them only in very generic ways.
11/2/2023 • 0
Risky Biz News: SEC charges SolarWinds and its CISO
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
11/1/2023 • 0
Between Two Nerds: What is really at stake with cyber security
In this edition of Between Two Nerds Tom Uren and The Grugq discuss what is really at stake when it comes to cyber security.
10/31/2023 • 0
Risky Biz News: Ransomware gangs pounce on CitrixBleed vulnerability
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/30/2023 • 0
Sponsored: Talking with Nucleus Security about vulnerability threat intelligence
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Patrick Garrity, VP of Marketing and security researcher at Nucleus Security, on the rise and evolution of vulnerability threat intel and how CISA KEV’s new ransomware section will be a game changer.
Show notes
Misconfigurations and Weaknesses Known to be Used in Ransomware Campaigns
CISA Releases New Resources Identifying Known Exploited Vulnerabilities and Misconfigurations Linked to Ransomware
10/29/2023 • 0
Risky Biz News: First Kazakhstan-based APT discovered, tries to disguise itself as Azerbaijan
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/27/2023 • 0
Srsly Risky Biz: Ransomware's soft underbelly
In this podcast guest host Adam Boileau and Tom Uren talk about the recent Ukrainian hacktivist group’s hack and burn attack on a ransomware gang. This makes us think there are definitely opportunities for Western cyber outfits.
They also discuss why companies should think about human rights when they make contingency plans for crises like war.
10/26/2023 • 0
Risky Biz News: 1Password joins the list of Okta victims
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/25/2023 • 0
The Between Two Nerds Halloween Special
In this edition of Between Two Nerds Tom Uren and The Grugq discuss “spooky effects” aka when agencies play silly buggers with target computers.
10/24/2023 • 0
Sponsored: It's better for everyone when DevOps have tools that are secure-by-default
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Resourcely CEO Travis McPeak about the modern DevOps ecosystem and how just giving developers tools with security baked in keeps everyone safe and happy, and how that’s easier than expecting your software engineers to become cybersecurity experts overnight.
10/23/2023 • 0
Risky Biz News: Cisco IOS XE hackers hide their tracks as patches come out
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/23/2023 • 0
Risky Biz News: Two ransomware gang websites go puff!
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/20/2023 • 0
Srsly Risky Biz: CISA to vendors — fix your products
In this podcast guest host Patrick Gray and Tom Uren talk about a CISA and NSA advisory that lists the 10 most common network misconfigurations they. It’s 101-level stuff and is particularly sobering because CISA and NSA don’t look at run of the mill networks, they look at important ones. CISA thinks part of the problem is vendors that make insecure-by-default products.
They also talk about a new Five Eyes security intelligence leader summit that warns of PRC intellectual property theft.
10/19/2023 • 0
Risky Biz News: 30k+ Cisco devices compromised with IOS XE zero-day
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/18/2023 • 0
Between Two Nerds: Effects operations during war and peace
In this edition of Between Two Nerds Tom Uren and The Grugq discuss how changing circumstances change the risk/reward balance and change whether effects operations are worthwhile.
10/16/2023 • 0
Risky Biz News: Israel warns citizens of security camera hack risk
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu.
You can find the newsletter version of this podcast here.
10/16/2023 • 0
Sponsored: Airlock Digital's co-founders on securing PowerShell
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Airlock Digital founders Daniel Schell and David Cottingham about the recent Microsoft Digital Defense Report and the problems that come with trying to properly secure PowerShell.
Show notes
Microsoft Digital Defense Report 2023 (MDDR) | Microsoft Security Insider
Resources for deprecated features in the Windows client - What's new in Windows | Microsoft Learn
The evolution of Windows authentication | Windows IT Pro Blog
Is Securing PowerShell a Lost Cause? - by Allan Liska
10/15/2023 • 0
Risky Biz News: Microsoft takes NTLM behind the shed
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
10/13/2023 • 0
Srsly Risky Biz: The EU needs to grow a political spine on spyware
In this podcast guest host Patrick Gray and Tom Uren talk about research that discovered that EU-based spyware was being used to target EU and US officials. Will that encourage EU governments to take action against spyware?
They also discuss Belgian concerns that the PRC will take advantage of a Chinese logistics firm with a hub in Liège for espionage.
Finally, they discuss whether hacktivists will follow International Humanitarian Law (IHL or the Rules of Law) rules about hactivism in wartime. Almost certainly not, but Tom still thinks its worth talking about and promoting responsible behaviour.
10/12/2023 • 0
Risky Biz News: Microsoft kills VBScript
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
10/11/2023 • 0
Between Two Nerds: BEC and ransomware, a match made in hell
In this edition of Between Two Nerds Tom Uren and The Grugq examine the opportunities that ransomware gangs and business email compromise/romance scammers have to collaborate.
10/10/2023 • 0
Risky Biz News: Human-operated ransomware attacks double in a year
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
10/9/2023 • 0
Sponsored: PAM vs teenagers... FIGHT!
In this Risky Business News sponsor interview Tom Uren asks Martin Cannard, VP of Product Strategy at Netwrix, how privileged access management can help defend organisations. ‘Advanced Persistent Teenagers’ regularly use social engineering techniques to compromise highly privileged accounts, but that doesn’t mean it’s instantly game over for defenders.
10/8/2023 • 0
Risky Biz News: Ransomware dwell times plummet
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
10/6/2023 • 0
Srsly Risky Biz: NSA wants to protect America's AI edge
In this podcast Patrick Gray and Tom Uren talk about the NSA’s creation of a new AI Security Center. One of it’s roles is to help protect AI intellectual property and so maintain the US’s AI advantage.
They also look at a new Mandiant report that looks at vulnerabilities that are exploited in the wild. This research finds a shift away from the top three vendors (Microsoft, Apple and Google) and there are rich pickings for threat actors at the network edge.
10/5/2023 • 0
Risky Biz News: Ransomware gangs hit TeamCity and WS_FTP servers
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
10/4/2023 • 0
Between Two Nerds: Have offensive cyber operations against ransomware groups failed?
In this edition of Between Two Nerds Tom Uren and The Grugq examine whether offensive cyber operations against ransomware groups have succeeded or failed. And how would we even know?
10/3/2023 • 0
Risky Biz Sponsor Interview: The e-crime ecosystem is changing
In this Risky Business News sponsor interview Tom Uren talks to Selena Larson, Senior Threat Intelligence Analyst at Proofpoint, about the state of play in the cybercrime ecosystem. People and organisations are getting better at protecting themselves from scams and compromises, but criminals will use every possible avenue to reach people and scam them.
10/2/2023 • 0
Risky Biz News: Critical Exim bugs remains unpatched
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
10/2/2023 • 0
Risky Biz News: More in-the-wild 0day for Firefox, Chrome
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/29/2023 • 0
Srsly Risky Biz: The cyber-yoofs must be stopped!
In this edition of Seriously Risky Business Patrick Gray and Tom Uren talk about the possibility of diverting youths from a life of serious cybercrime. It’ll be tough.
They also talk about a Ukrainian government report into changes in Russian cyber activity.
9/28/2023 • 0
Risky Biz News: CISA publishes HBOM framework
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/27/2023 • 0
Risky Biz News: China admits NSA hacked Huawei
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/25/2023 • 0
Between Two Nerds: Why the UK and US Cyber Strategies are Mirror Images
In this edition of Between Two Nerds Tom Uren and The Grugq examine how US and UK strategies to use cyber power differ but are in some ways mirror images of each other.
9/25/2023 • 0
Sponsored: Stairwell's Silas Cutler on the Akira leak and attacker infrastructure
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Stairwell Principal Reverse Engineer Silas Cutler about Akira’s recent server leak and attacker infrastructure.
9/24/2023 • 0
Risky Biz News: North Korea steals $54 million from CoinEx
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
In this edition of Seriously Risky Biz guest host Adam Boileau talks with Tom Uren about what Microsoft’s recent breach by a Chinese-based threat actor tells us about the company’s security culture. There were several serious governance failures that allowed this incident to happen.
They also look at a new UK government effort to reassure companies that they won’t be punished (as much) for seeking help from the NCSC.
9/14/2023 • 0
Risky Biz News: Won't someone think of the... casinos?!
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/13/2023 • 0
Between Two Nerds: How AI can turbocharge cyber scams
In this edition of Between Two Nerds Tom Uren and The Grugq examine how AI can help cyber criminals and scammers.
9/12/2023 • 0
Risky Biz News: Ransomware gangs using Cisco 0day
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/11/2023 • 0
Sponsored: Red Canary's Gerry Johansen on IR readiness
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Red Canary Principal Readiness Engineer Gerry Johansen about the need to prepare IR plans in advance and why that’s just as important as the IR playbook itself.
9/11/2023 • 0
Risky Biz News: Microsoft explains how it lost its signing key
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/8/2023 • 0
Srsly Risky Biz: Why "pig butchering" is even worse than you think
In this podcast Patrick Gray and Tom Uren talk about a new UN report that says that hundreds of thousands of innocent people are being forced into working in online crypto and romance scams.
They also look at new age verification laws that aim to make it more difficult for children to see pornography. It’s a complex topic, but Australia’s eSafety office has done excellent work on it.
9/7/2023 • 0
Risky Biz News: China cracks down on Southeast Asian scam call centers
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/6/2023 • 0
Between Two Nerds: When states are at the mercy of tech company policy
In this edition of Between Two Nerds Tom Uren and The Grugq look at how companies often make unilateral decisions that constrain states’ behaviour, for better and worse.
9/5/2023 • 0
Risky Biz News: Okta Super Administrator accounts targeted
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/4/2023 • 0
Risky Biz Sponsor Interview: Why Island raised over $250m to build an enterprise browser
In this Risky Business News sponsor interview Tom Uren talks to Mike Fey, CEO and co-founder of Island about the idea of an ‘enterprise browser’. Tom and Mike discuss what an enterprise browser actually is, what problems it solves, and why browsers focussed on business requirements haven’t been a product category until now.
9/4/2023 • 0
Risky Biz News: Chinese APT sneaks trojaned Signal app into Play Store
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
9/1/2023 • 0
Srsly Risky Biz: The UK snoopers' charter won't stop security patches
In this podcast Patrick Gray and Tom Uren about proposed changes to the UK’s Investigatory Powers Act. Some pundits are saying the changes will clear the way for the government to prevent tech companies from rolling out security patches. They’re wrong.
They also look at a new Mandiant report that dives deeper into a recent Chinese group’s campaign that compromised Barracuda Email Security Gateways. The report provides a wonderful overview of the campaign.
8/31/2023 • 0
Risky Biz News: FBI nukes Qakbot botnet
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/30/2023 • 0
Between Two Nerds: Know thyself
In this edition of Between Two Nerds Tom Uren and The Grugq look at how asset inventory tools aren’t a substitute for knowing what a business values.
8/29/2023 • 0
Risky Biz News: Kroll SIM-swapped in attack targeting crypto platforms
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/28/2023 • 0
Srsly Risky Biz: Why did Russia deploy hackers to war zones?
In this podcast Patrick Gray and Tom Uren talk about how Ukraine has countered Russia’s cyber operations.
They also look at various initiatives the US government is taking to secure open source software and ask whether it is getting serious about FOSS.
8/25/2023 • 0
Risky Biz News: WinRAR zero-day used to hack stock and crypto traders
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/25/2023 • 0
Risky Biz News: South Korea investigates Chinese "spy chips"
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/23/2023 • 0
Between Two Nerds: Hacking CCTV cameras for fun and profit
In this edition of Between Two Nerds, Tom Uren and The Grugq examine the history of CCTV hacking and what different groups get out of these hacks.
8/22/2023 • 0
Risky Biz News: Foreign intelligence services are targeting the US space sector
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/21/2023 • 0
Risky Biz Sponsor Interview: Using AI to do security research
In this Risky Business News sponsor interview Tom Uren talks to Dan Guido, CEO of Trail of Bits, about AI. Dan thinks AI technologies will be a “game changer”. But he also thinks the conversation around AI is not very sophisticated just yet.
8/21/2023 • 0
Risky Biz News: PowerShell's official package repo is a supply chain mess
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/18/2023 • 0
Risky Biz News: Lockbit is posting fictitious leaks, is close to implosion
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/16/2023 • 0
Between Two Nerds: The juice jacking mass delusion
In this edition of Between Two Nerds Tom Uren and The Grugq look at why ‘juice jacking’ is a forever fear even though its not a real-world threat.
8/15/2023 • 0
Risky Biz Sponsor Interview with Jacob Torrey of Thinkst Labs
In this Risky Business News sponsor interview Tom Uren talks to Jacob Torrey, Thinkst’s Head of Labs. Jacob produces ThinkstScapes, a brilliant quarterly summary of the most interesting security research from around the world.
In this interview Jacob talks about his favourite research of this issue, why Thinkst invests the time and effort in producing ThinkstScapes and also talks about Thinkst Citation, a companion product that contains information about nearly 70,000 security talks going all the way back to 1993.
8/14/2023 • 0
Risky Biz News: CSRB to investigate Microsoft hack
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/14/2023 • 0
Risky Biz News: Russia blocks OpenVPN and WireGuard VPN protocols
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/11/2023 • 0
Srsly Risky Biz: Why Russia's Plan to Hide Spy Data Will Fail
In this podcast Patrick Gray and Tom Uren talk about how the Russian government is planning to alter databases to hide their spies from open source investigations. It’s a nice try, but we don’t think it will work.
They also look at contrasting stories that illustrate how law enforcement agencies can facial recognition technology responsibly, but can also royally screw things up.
8/10/2023 • 0
Risky Biz News: Sandworm hackers target Ukraine's military systems
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/9/2023 • 0
Between Two Nerds: China's Changing Cyber Espionage Playbook
In this edition of Between Two Nerds Tom Uren and The Grugq ask whether Chinese operations are becoming stealthier and why? Is it a top-down directive to be careful? Or do the operations themselves require more stealth?
8/8/2023 • 0
Sponsored: Tines CEO Eoin Hinchy on burnout in SOC teams
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Tines co-founder and CEO Eoin Hinchy about how organisations can maximise the potential of their security teams during an economic downturn, with a concentration on why human error and burnout caused by excessive workloads on security teams can be a risk.
8/7/2023 • 0
Risky Biz News: Ransomware attack cripples hospitals across five US states
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/7/2023 • 0
Risky Biz News: Microsoft botches Azure bug fix
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/4/2023 • 0
Srsly Risky Biz: On Microsoft, Wyden's Bark May Have Some Bite
In this podcast Patrick Gray and Tom Uren talk about how Microsoft’s lackadaisical cloud product security is attracting the ire of important politicians.
They also examine a presidential advisory board report into Section 702 collection and discuss why oversight in intelligence collection is important.
8/3/2023 • 0
Risky Biz News: "American" cloud provider is allegedly an Iranian bulletproof host
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
8/2/2023 • 0
Between Two Nerds: The Rights and Wrongs of IP Theft
In this edition of Between Two Nerds Tom Uren and The Grugq look at the arguments against intellectual property theft and why there isn’t universal agreement that it should be prohibited.
8/1/2023 • 0
Risky Biz News: Calls to investigate Microsoft over SolarWinds, Storm-0558
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
7/31/2023 • 0
Sponsored: Andrew Morris on the future of GreyNoise's honeypot network
In this Risky Business News sponsor interview, Catalin Cimpanu talks with GreyNoise founder and CEO Andrew Morris about the company’s vast network of honeypots, and how they’re preparing to take it to the next phase.
7/31/2023 • 0
Risky Biz News: SEC adopts new cybersecurity rules
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/28/2023 • 0
Srsly Risky Biz: In Beijing, the Fourth Amendment is Still For Sale
In this podcast Patrick Gray and Tom Uren talk about draft US legislation that aims to stop law enforcement from circumventing the Fourth Amendment by simply buying data on US citizens. It’s a good move, but the overall data ecosystem needs broader reform.
They also discuss new reports into the ransomware ecosystem. There is both good news and bad news, but data gaps still make it difficult for policymakers to have a good handle on how to respond.
7/27/2023 • 0
Risky Biz News: Norwegian government hacked with MobileIron zero-day
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/26/2023 • 0
Between Two Nerds: When iPhones aren't good enough
In this edition of Between Two Nerds Tom Uren and The Grugq look at when it makes sense for governments to invest in building their own secure phone
7/25/2023 • 0
Sponsored: Everything you want to know about BYO vulnerable driver attacks but are afraid to ask
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Airlock Digital founders Daniel Schell and David Cottingham about vulnerable drivers, BYOVD attacks, and the problem with driver-based attacks.
7/24/2023 • 0
Risky Biz News: Ransomware victims stop paying up
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/23/2023 • 0
Risky Biz News: Microsoft capitulates on cloud security logs
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/21/2023 • 0
Srsly Risky Biz: Time for Cloud Transparency
In this podcast Patrick Gray and Tom Uren talk about recent breaches of JumpCloud and Microsoft cloud services. It’s great they disclosed these incidents voluntarily, but cloud companies are so important that detailed postmortems shouldn’t be voluntary.
They also discuss the Biden administration’s cyber security strategy implementation plan and the opportunity to collect email destined for the US military by typo-squatting on the ‘.ml’ domain.
7/20/2023 • 0
Risky Biz News: A Citrix 0day RCE is being actively exploited
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/19/2023 • 0
Between Two Nerds: Shaping ransomware group behaviour
In this edition of Between Two Nerds Tom Uren and The Grugq look at the idea of actively shaping ransomware group behaviour to get the type of behaviour we’d prefer.
7/18/2023 • 0
Risky Biz News: JumpCloud compromised by APT group
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
7/17/2023 • 0
Risky Biz News: Microsoft likely compromised in US Government hack
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Kaitlyn Sawrey.
You can find the newsletter version of this podcast here.
7/14/2023 • 0
Srsly Risky Biz: WeChat's Privacy Policy Is Useless
In this podcast Patrick Gray and Tom Uren talk about Citizen Lab’s analysis of WeChat’s behaviour and its privacy policy. That report misses the point: WeChat is an integral part of the PRC’s architecture of censorship and repression, and the Chinese government isn’t constrained by WeChat’s privacy policy.
They also discuss a new report that proposes a human-centred framework for assessing client-side Child Sexual Abuse Material (CSAM) detection technologies. It’s a step forward because it makes clearer the tradeoffs that are being made when these technologies are suggested.
7/13/2023 • 0
Risky Biz News: Microsoft nukes 100 malicious drivers
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/12/2023 • 0
Risky Biz News: Mastodon plugs a horror-show bug
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/10/2023 • 0
Risky Biz Sponsor Interview with Scott Hanson from Kroll on Detection-as-Code
In this Risky Business News sponsor interview, Catalin Cimpanu talks with Scott Hanson, Head of Global Security Operations at Kroll, on how the company has adopted Detection-as-Code for its approach to writing, managing, and rolling out detection rules for its customers.
7/10/2023 • 0
Risky Biz News: Ransomware cripples Japan's largest cargo port
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/7/2023 • 0
Srsly Risky Biz: The Russia vs US Extradition Tug of War
In this podcast Patrick Gray and Tom Uren talk about the regular extradition battles that occur between the US and Russia whenever a Russian cybercriminal is arrested in a third country. It’s less about protecting cybercriminals and more about Russia trying to poke the USA in the eye.
They also discuss recent Ukrainian hacktivist operations that have been extremely successful, but also don’t seem to have had any really meaningful impact.
7/6/2023 • 0
Between Two Nerds: Should journalists be protected against spyware?
In this edition of Between Two Nerds Tom Uren and The Grugq look at the EU’s proposed media freedom act and how one of its goals is to protect journalists from spyware.
7/4/2023 • 0
Risky Biz News: $922 million worth of crypto stolen in H1 2023
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/4/2023 • 0
Sponsor Interview: RunZero adds passive scanning for OT networks
In this Risky Business News sponsor interview Tom Uren talks to RunZero’s CEO Chris Kirsch about how RunZero has evolved from an IT network active scanning product to one that can now discover assets on OT and cloud environments using both active and passive scanning approaches.
7/3/2023 • 0
Risky Biz News: Prigozhin's troll farms in limbo after Wagner mutiny
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
7/3/2023 • 0
Risky Biz News: Philippine authorities free 2,700 "cybercrime slaves"
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/30/2023 • 0
Srsly Risky Biz: The SEC Gets Personal
In this podcast Patrick Gray and Tom Uren talk about the US Securities Exchange Commission warning SolarWinds executives that it is planning to bring enforcement actions against them. This is a big deal and really signifies that the SEC wants companies to be much more open about cybersecurity incident disclosures.
They also discuss the outcomes from a European law enforcement operation against the EncroChat ‘crimephone’. It was an absolutely stunning success, but what does it mean for the future of the access debate?
Show notes
The boom, the bust and the adjust | by Maor Shwartz | Jun, 2023 | Medium
6/29/2023 • 0
Risky Biz News: LetMeSpy gets hacked
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/28/2023 • 0
Risky Biz News: SEC moves on SolarWinds executives
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/26/2023 • 0
Risky Biz News: Apple patches "Triangulation" zero-days
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/23/2023 • 0
Srsly Risky Biz: Why China's Barracuda Hacks Are Just Plain Rude
In this podcast Patrick Gray and Tom Uren talk about the PRC’s campaign compromising Barracuda Email Security Gateways. It doesn’t quite break international “norms”, but it is definitely on the nose.
They also discuss Albania’s police raid of an Iranian opposition refugee camp which is said to be hosting a hacking cell that targeted Iran’s government.
6/22/2023 • 0
Risky Biz News: Albania raids Iranian MEK camp for running a "hacker center"
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/21/2023 • 0
Between Two Nerds: Go Big or Go Home
In this edition of Between Two Nerds Tom Uren and The Grugq look at three different state operations that have recently been outed and what these operations tell us about how these states are behaving.
6/20/2023 • 0
Risky Biz News: Microsoft admits it got DDoSed by Anonymous Sudan
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/19/2023 • 0
Risky Biz News: Russian LockBit affiliate arrested in… the US?
A short podcast updating listeners on the security news of the last few days, as prepared by Catalin Cimpanu and read by Claire Aird.
You can find the newsletter version of this podcast here.
6/16/2023 • 0
Srsly Risky Biz: IC Reform Wanted, Decent Privacy Laws Needed
In this podcast Patrick Gray and Tom Uren talk about a new report examining how the US intelligence communities uses data it buys. It finds that data you can buy now rivals or exceeds what intelligence agencies can collect, but the IC overall doesn’t treat the data with the sensitivity and care that it deserves. Fixing IC policy is one thing, but that won’t help at all with foreign adversaries or even local US law enforcement. US needs good data privacy law that cleans up the whole field.
They also look at new research that examines how lawyers’ incentives to protect clients mean that incident response is hamstrung when it comes to discovering root causes and learning lessons.