Skip to content
Artwork for Risky Bulletin
NewsTech NewsTechnology

Risky Bulletin

Risky Business Media

Regular cybersecurity news updates from the Risky Business team...

Play
  • 136 episodes
  • Avg 16 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • September 11 · 10 min

    Risky Bulletin: Anthropic agents went hacking again

    Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff. Show notes Risky Bulletin: Anthropic agents went hacking again

  • September 10 · 24 min

    Srsly Risky Biz: America's drivers licence breach is a national security disaster

    Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences. They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough. Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy. This episode is also available on YouTube Show notes

  • September 9 · 7 min

    Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

    Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty. Show notes Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

  • September 7 · 27 min

    Between Two Nerds: Can AI defend critical infrastructure?

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line. This episode is also available on YouTube. Show notes Heather Adkins X post Clem X post Secure connectivity principles for operational technology | NCSC

  • September 7 · 8 min

    Risky Bulletin: BEC campaign steals €35 million from French notaries

    Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin. Show notes Risky Bulletin: BEC campaign steals €35 million from French notaries

  • September 6 · 20 min

    Sponsored: Authentik is rethinking PAM for AI agents

    In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human. They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access. Show notes

  • September 4 · 10 min

    Risky Bulletin: Russia tells data centers to deploy drone defenses

    Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs. Show notes Risky Bulletin: Russia tells data centers to deploy drone defenses

  • September 3 · 22 min

    Srsly Risky Biz: China's botnets are worth disrupting

    Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal! Finally, they discuss efforts to fix US water sector security. Sprinkling free tools on the problem will have limited impact. This episode is also available on YouTube Show notes

  • September 2 · 9 min

    Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

    A BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness. Show notes Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates

  • August 31 · 29 min

    Between Two Nerds: The perfect hacker

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals. This episode is also available on YouTube. Show notes Bitdefender Labs report on SilkParasite OpenAI on the Hugging Face incident

  • August 31 · 7 min

    Risky Bulletin: New powers for Dutch intelligence services

    Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service. Show notes Risky Bulletin: Dutch intel services to get extensive new powers

  • August 30 · 21 min

    Sponsored: Attackers need to be right more than once

    In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown jewels”. The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times. Show notes

  • August 28 · 10 min

    Risky Bulletin: Two TeamPCP members arrested in Australia

    Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic. Show notes Risky Bulletin: Two TeamPCP members arrested in Australia

  • August 27 · 19 min

    Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting

    Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense. This episode is also available on YouTube Show notes

  • August 26 · 8 min

    Risky Bulletin: Russia starts blocking DoH and DoT

    Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common. Show notes Risky Bulletin: Russia starts blocking DoH and DoT

  • August 24 · 32 min

    Between Two Nerds: Attribution is dead, long live attribution

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available on YouTube. Show notes Florian Roth X post Phrack issue 59, Defeating Forensic Analysis on Unix Phrack issue 62, Remote Exec

  • August 24 · 5 min

    Risky Bulletin: Expired credit cards can be used for malicious transactions

    Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars. Show notes Risky Bulletin: Expired cards can be used for new transactions

  • August 23 · 20 min

    Sponsored: Passkeys won’t stop authorisation phishing

    In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if their controls against these attacks actually work. Show notes

  • August 21 · 6 min

    Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs

    The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great Firewall Show notes Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

  • August 20 · 31 min

    Srsly Risky Biz: Trump's private hacker memo is the right idea

    Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disruption operations, but there simply isn’t enough government capacity. So it is time to bring in the private sector. They also discuss Ukraine’s combined cyber and kinetic strikes against Wildberries, the logistics company that is called the Amazon of Russia. These cyber operations didn’t amplify the effects of kinetic strikes, but it is great propaganda to say that they did. This episode is also available on YouTube Show notes

Showing 1–20 of 136 episodes