Risky Business

Auteur(s): Patrick Gray
  • Résumé

  • Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
    Copyright 2007-2025 Patrick Gray
    Voir plus Voir moins
Épisodes
  • Risky Business #780 -- ASD torched Zservers data while admins were drunk
    Feb 19 2025

    On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

    • Australian spooks scrubbed Medibank data off Zservers bulletproof hosting
    • Why device code phishing is the latest trick in confusing poor users about cloud authentication
    • Cloudflare gets blocked in Spain, but only on weekends and because of… football?
    • Palo Alto has yet another dumb bug
    • Adam gushes about Qualys’ latest OpenSSH vulns

    Enterprise browser maker Island is this week’s sponsor and Chief Customer Office Braden Rogers joins the show to talk about how the adoption of AI everywhere is causing headaches.

    This episode is also available on Youtube.

    Show notes
    • Five Russians went out drinking. When they got back, Australia had struck
    • Dutch police say they took down 127 servers used by sanctioned hosting service | The Record from Recorded Future News
    • Further cyber sanctions in response to Medibank Private cyberattack | Defence Ministers
    • What is device code phishing, and why are Russian spies so successful at it? - Ars Technica
    • Anyone Can Push Updates to the DOGE.gov Website
    • Piracy Crisis: Cloudflare Says LaLiga Knew Dangers, Blocked IP Address Anyway (Update) * TorrentFreak
    • Palo Alto Networks warns firewall vulnerability is under active exploitation | Cybersecurity Dive
    • Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466 | Qualys Security Blog
    • China’s Salt Typhoon hackers targeting Cisco devices used by telcos, universities | The Record from Recorded Future News
    • RedMike Exploits Unpatched Cisco Devices in Global Telecommunications Campaign
    • A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks | WIRED
    • How Phished Data Turns into Apple & Google Wallets – Krebs on Security
    • New hack uses prompt injection to corrupt Gemini’s long-term memory
    • Arizona woman pleads guilty to running laptop farm for N. Korean IT workers, faces 9-year sentence | The Record from Recorded Future News
    • US reportedly releases Russian cybercrime figure Alexander Vinnik in prisoner swap | The Record from Recorded Future News
    • EXCLUSIVE: A Russia-linked Telegram network is inciting terrorism and is behind hate crimes in the UK – HOPE not hate
    • Remembering David Jorm - fundraising for Mental Health research
    Voir plus Voir moins
    1 h et 1 min
  • Risky Biz Soap Box: Run your own open source IDP with Authentik
    Feb 14 2025

    In this SoapBox edition of the show Patrick Gray chats to Fletcher Heisler, the CEO of open-source identity provider Authentik.

    The whole idea of Authentik is you can take control of an essential IT and security function: identity. Because Authentik is open source it’s extremely flexible, and if you’re running it yourself, you get to decide where your IDP should sit in your architecture. You can run it on prem if you’re an emergency call centre or you’re operating an airgapped network, or you can spin it up in your cloud environment if you’re a typical enterprise.

    Fletcher talks through the reasons Authentik users are decoupling themselves from the major SaaS Identity Providers, and the flexibility that comes from being able to assemble exactly what you need.

    This episode is also available on Youtube.

    Show notes
      Voir plus Voir moins
      38 min
    • Risky Business #779 -- DOGE staffer linked to The Com
      Feb 12 2025
      On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: Musk’s DOGE kid has a history with The ComParagon fires Italy as a spyware customerThailand cuts power to scam compounds…… and arrests Phobos/8Base Russian cybercrimsThe CyberCX DFIR report shows non-U2F MFA is well and truly overAnd much, much more. This week’s episode is sponsored by Dropzone.AI. They make an AI SOC analysis platform that relieves your analysts of the necessary but tedious work, so they can focus on the value of human insight. Dropzone’s founder and CEO Edward Wu joins to talk about how they approach the problem. This episode is also available on Youtube. Show notes Teen on Musk’s DOGE Team Graduated from ‘The Com’ – Krebs on SecurityACLU Warns DOGE’s ‘Unchecked’ Access Could Violate Federal Law | WIREDLawsuit accuses Trump administration of violating federal information security law | The Record from Recorded Future NewsThe Recruitment Effort That Helped Build Elon Musk’s DOGE Army | WIREDStates prepare privacy lawsuit against DOGE over access to federal data | The Record from Recorded Future NewsUnion groups sue Treasury over giving DOGE access to sensitive data | The Record from Recorded Future NewsStudent group sues Education Department over reported DOGE access to financial aid databases | The Record from Recorded Future NewsHackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts | The Record from Recorded Future NewsDeepSeek iOS app sends data unencrypted to ByteDance-controlled servers - Ars TechnicaDeepSeek Is a Win for Chinese Hackers - Risky BusinessOwner of spyware used in alleged WhatsApp breach ends contract with Italy | WhatsApp | The GuardianAnother person targeted by Paragon spyware comes forward | TechCrunchApple fixes security flaw allowing third-party access to locked devices | The Record from Recorded Future NewsU.S. sanctions bulletproof hosting provider for supplying LockBit infrastructure | CyberScoopThailand cuts power supply to Myanmar scam hubs | The Record from Recorded Future News8Base ransomware site taken down as Thai authorities arrest 4 connected to operation | The Record from Recorded Future NewsTwo Russian nationals arrested in takedown of Phobos ransomware infrastructure | The Record from Recorded Future NewsThe Company Man: Binance exec detained in Nigeria breaks his silence | The Record from Recorded Future NewsDeloitte pays $5M in connection with breach of Rhode Island benefits site | Cybersecurity DiveDFIR - Threat Report 2025 | CyberCXRequest a Demo | Dropzone AI
      Voir plus Voir moins
      59 min

    Ce que les auditeurs disent de Risky Business

    Moyenne des évaluations de clients

    Évaluations – Cliquez sur les onglets pour changer la source des évaluations.