…
continue reading
1
Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser
26:40
26:40
Spill senere
Spill senere
Lister
Lik
Likt
26:40
In this sponsored Soap Box edition of the show Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes. This is largely a conversation about compliance, but it’s actually interesting and fun. These are words we …
…
continue reading
1
Risky Business #775 -- Cl0p is back, SEC hack disclosures disappoint
1:01:06
1:01:06
Spill senere
Spill senere
Lister
Lik
Likt
1:01:06
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: The SEC’s cyber incident reporting isn’t very exciting after all China Telecom on the way to being thrown out of the US The NSA/Cybercom might get two separate hats The Cl0p ransomware crew are back and taking responsibility for the Cleo hacks (Yet …
…
continue reading
1
Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations
50:04
50:04
Spill senere
Spill senere
Lister
Lik
Likt
50:04
In this edition of the Wild World of Cyber podcast Patrick Gray sits down with SentinelOne’s Chief Intelligence and Public Policy Officer Chris Krebs to talk all about Chinese cyber operations. They look at the Salt Typhoon and Volt Typhoon campaigns, the last 20 years of Chinese operations, and the evolution of the cyber roles of China’s Ministry …
…
continue reading
1
Risky Business #774 -- Cleo file transfer appliances under widespread attack
1:02:28
1:02:28
Spill senere
Spill senere
Lister
Lik
Likt
1:02:28
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: Cleo file transfer products have a remote code exec, here we go again! Snowflake phases out password-based auth Chinese Sophos-exploit-dev company gets sanctioned Romania’s election gets rolled back after Tiktok changed the outcome AMD’s encrypted V…
…
continue reading
1
Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered
29:56
29:56
Spill senere
Spill senere
Lister
Lik
Likt
29:56
In this interview Patrick Gray talks to Yubico’s COO and President Jerrod Chong about a new Yubikey feature: pre-registration. You can now ship pre-registered Yubikeys to your staff so you don’t need to rely on your staff to enrol them. They’ve achieved this with really slick Okta and Entra ID integrations. Jerrod also talks about a recent trip to …
…
continue reading
1
Risky Business #773 -- Cybercriminals are dropping like flies in Russia
57:02
57:02
Spill senere
Spill senere
Lister
Lik
Likt
57:02
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: The FTC decides its time to take another look at Microsoft Exxon’s opponents targeted by hackers Russian hackers keep getting sentenced and it confuses us The Feds recommend Signal, because throwing hackers out of telcos ain’t gonna happen A South K…
…
continue reading
1
Risky Business #772 -- Salt Typhoon is truly a national security disaster
1:01:05
1:01:05
Spill senere
Spill senere
Lister
Lik
Likt
1:01:05
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: A ransomware attack has crippled US supply chain software provider Blue Yonder Russian spies hack nearby wifi to get to their targets, but that doesn’t seem surprising? Salt Typhoon’s attacks on telcos are hard to solve and big on impact China’s sur…
…
continue reading
1
Risky Business #771 -- Palo Alto's firewall 0days are very, very stupid
1:01:12
1:01:12
Spill senere
Spill senere
Lister
Lik
Likt
1:01:12
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: Microsoft introduces some sensible sounding post-Crowdstrike changes Palo Alto patches hella-stupid bugs in its firewall management webapp CISA head Jen Easterly to depart as Trump arrives AI grandma tarpits phone scammers in family-tech-support hell…
…
continue reading
1
Risky Business #770 -- A Russian IR guy discovers extremely cool spookware
1:03:29
1:03:29
Spill senere
Spill senere
Lister
Lik
Likt
1:03:29
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: Apple frustrates law enforcement with iOS auto-reboot CISA says most KEV vulnerabilities in 2023 were first used as zero days Russians roll incident response on some sweet Linux spookware Regular users can create mailboxes in M365? Tor tracks down th…
…
continue reading
1
Risky Biz Soap Box: Why black box email security is dead
36:12
36:12
Spill senere
Spill senere
Lister
Lik
Likt
36:12
In this edition of the Risky Business Soap Box we’re talking all about email security with Sublime Security co-founder Josh Kamdjou. Email security is one of the oldest product categories in security, but as you’ll hear, Josh thinks the incumbents are just doing it wrong. He joins Risky Business host Patrick Gray for this interview about Sublime’s …
…
continue reading
1
Risky Business #769 -- Sophos drops implants on Chinese exploit devs
56:51
56:51
Spill senere
Spill senere
Lister
Lik
Likt
56:51
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: Sophos drops implants on Chinese firewall exploit devs Microsoft workshops better just-in-time Windows admin privileges Snowflake hacker arrested in Canada Okta has a fun, but not very impactful auth-bypass bug Russians bring dumb-but-smart RDP clien…
…
continue reading
1
Risky Business #768 -- CSRB will investigate China's Wiretap Hacks
51:37
51:37
Spill senere
Spill senere
Lister
Lik
Likt
51:37
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: CSRB to investigate China’s telco-wiretapping hacks Euro law enforcement takes down the Redline infostealer Someone steals Fed crypto… and then tries to quietly sneak it back in Russia sentences REvil guys to … jail? Really? Apple private cloud compu…
…
continue reading
1
Risky Biz Soap Box: Thinkst Canary's decade of deception
37:56
37:56
Spill senere
Spill senere
Lister
Lik
Likt
37:56
In this Soap Box edition of the podcast Patrick Gray chats with Thinkst Canary founder Haroon Meer about his “decade of deception”, including: A history of Thinkst Canary including a recap of what they actually do A look at why they’re still really the only major player in the deception game A look at what companies like Microsoft are doing with de…
…
continue reading
1
Risky Business #767 – SEC fines Check Point, Mimecast, Avaya and Unisys over hacks
1:02:21
1:02:21
Spill senere
Spill senere
Lister
Lik
Likt
1:02:21
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: SEC fines tech firms for downplaying the Solarwinds hacks Anonymous Sudan still looks and quacks like a Russian duck Apple proposes max 10 day TLS certificate life Oopsie! Microsoft loses a bunch of cloud logs Veeam and Fortinet are bad and should fe…
…
continue reading
1
Risky Business #766 – China hacks America's lawful intercept systems
53:57
53:57
Spill senere
Spill senere
Lister
Lik
Likt
53:57
On this week’s show Patrick Gray and Adam Boileau discuss the week’s infosec news, including: Chinese spooks all up in western telco lawful intercept Jerks ruin the Internet Archive’s day Microsoft drops a great report with a bad chart The feds make their own crypto currency and get it pumped Forti-, Palo- and Ivanti-fail And much, much more. This …
…
continue reading
1
Snake Oilers: Sandfly Security, Permiso and Wiz
40:22
40:22
Spill senere
Spill senere
Lister
Lik
Likt
40:22
In this edition of Snake Oilers we hear pitches from three security vendors: Sandfly Security: An agentless Linux security platform that actually sounds very cool Permiso: An identity security platform founded by ex FireEye folks Wiz: The cloud security giant is getting in on code security scanning You can watch this edition of Snake Oilers on YouT…
…
continue reading
1
Risky Business #765 -- The Kaspersky switcheroo
1:05:41
1:05:41
Spill senere
Spill senere
Lister
Lik
Likt
1:05:41
Patrick Gray and Adam Boileau discuss the week’s infosec news with everyone’s favourite ex-NSA big-brain, Rob Joyce. They talk through: Musk and Durov bow to government pressure Tiktok rushes to ban authoritarian propagandists The US doesn’t want Chinese software in its cars Kaspersky replaces itself with an AV no one has ever heard of Aussie polic…
…
continue reading
1
Risky Business #764 -- Mossad expands into telecommunications services
1:02:56
1:02:56
Spill senere
Spill senere
Lister
Lik
Likt
1:02:56
On this week’s show, Patrick Gray and Adam Boileau discuss the weeks security news, including: Hezbollah’s attempts to avoid SIGINT with pagers ends in explosions The US shines many bright lights on RT’s disinfo role Australia counters Chinese bullying in the Pacific Valid accounts are the most prevalent entry point, says CISA’s data Ivanti and For…
…
continue reading
1
Risky Business #763 – Microsoft un-patches critical bug
51:49
51:49
Spill senere
Spill senere
Lister
Lik
Likt
51:49
On this week’s show, Patrick Gray and Adam Boileau discuss the weeks security news, including: Russia’s disinformation peddlers face multifaceted sternness from the DoJ Telegram is now law enforcement’s bestest new pal, all of a sudden Iran’s banking industry arranges a payment plan for a ransom Columbia investigates how it sent private jets full o…
…
continue reading
1
Snake Oilers: Authentik, Dropzone and SlashID
38:03
38:03
Spill senere
Spill senere
Lister
Lik
Likt
38:03
In this edition of Snake Oilers Patrick Gray gets pitches from three cybersecurity companies: Authentik, an open source identity provider that a lot of large organisations are deploying on prem as an alternative to cloud-based IDPs Dropzone AI, an LLM-based agent that can do the work of a Tier 1 SOC analyst SlashID, an identity security company tha…
…
continue reading
1
Risky Business #762 -- Brazil nukes X, Iranian APTs deploy ransomware
1:04:46
1:04:46
Spill senere
Spill senere
Lister
Lik
Likt
1:04:46
On this week’s show, Patrick Gray and Adam Boileau discuss the weeks security news, including: Brazil’s supreme court bans X-formerly-Twitter, Iranian cyber teams cooperate with ransomware crews While North Koreans wield chrome-windows 0-day Yubikey cloning attack is impressive, but doesn’t have us binning our keys quite yet The White House is comi…
…
continue reading
1
Risky Business #761 – Telegram v frogs. Fight!
1:04:32
1:04:32
Spill senere
Spill senere
Lister
Lik
Likt
1:04:32
On this week’s show, Patrick Gray and Adam Boileau discusses the week’s security news, including: Telegram founder’s arrest in France Volt Typhoon 0days some SD-WAN gear Russia frets about Ukraine all up in Kursk’s webcams Cybercriminals social engineer payment card NFC relay attacks in the wild The slow burn of Active Directory name collisions And…
…
continue reading
1
Feature interview: ASIO Director General Mike Burgess on encryption and access
29:49
29:49
Spill senere
Spill senere
Lister
Lik
Likt
29:49
Mike Burgess is the director general of ASIO. But the thing about Mike is he’s actually a cybersecurity guy. He joined ASD, Australia’s NSA, back in 1995 when it was still the Defence Signals Directorate. He was there for 18 years before he bounced out to the private sector for a while to work as the CISO for Australia’s largest telco, Telstra. In …
…
continue reading
1
Risky Business #760 – Microsoft to make MFA mandatory
1:04:44
1:04:44
Spill senere
Spill senere
Lister
Lik
Likt
1:04:44
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news including: Microsoft did a good thing! Soon all Azure admins will require MFA The three billion row National Public Data breach mess, courtesy Florida Man US govt confirms that it was Iran that hacked the Trump campaign Is TP-Link the next Huawei, or just not very g…
…
continue reading
1
Wide World of Cyber: 2024 election interference, the media and Iran's hack and leak
36:23
36:23
Spill senere
Spill senere
Lister
Lik
Likt
36:23
In this conversation Risky Business host Patrick Gray speaks with SentinelOne’s Chris Krebs and Alex Stamos about what sort of cyber enabled interference we can expect in the 2024 US presidential race. Alex was the CISO at Facebook during the 2016 election, and Chris Krebs was responsible for US election security as the director of CISA in 2020. Wa…
…
continue reading
1
Risky Business #759 – Why Iran's hack and leak will amount to naught
1:04:35
1:04:35
Spill senere
Spill senere
Lister
Lik
Likt
1:04:35
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news and recap the best research presented at Black Hat and DEF CON in Las Vegas last week. They cover: Iran tries an election hack’n’leak like its still 2016 Crowdstrike takes home the Pwnie for Epic Fail at DEF CON UK healthcare SaaS faces six million pound fine for la…
…
continue reading
1
Soap Box: Making security tech more people friendly
34:35
34:35
Spill senere
Spill senere
Lister
Lik
Likt
34:35
In this sponsored Soap Box edition of the show we talk to Proofpoint’s Chief Strategy Officer Ryan Kalember about making security tech more people centric. We often talk about how we can use signals from users to drive some of our security tech. But what about using our security tech to drive user behaviour? Ryan thinks there are some opportunities…
…
continue reading
1
Risky Business #758 – Crowdstrike's postmortem underwhelms
52:57
52:57
Spill senere
Spill senere
Lister
Lik
Likt
52:57
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including: Crowdstrike talks loud in its postmortem, but says very little Digicert fears the CA-Browser Forum, gets lawsuit from a customer Dmitri Alperovitch joins the show to talk about the Russian prisoner swap Cloudflare continues to harbour scum and villainy P…
…
continue reading
1
Risky Business #757 – The ClownStrike cleanup continues
1:00:49
1:00:49
Spill senere
Spill senere
Lister
Lik
Likt
1:00:49
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including: The insurance industry’s reaction to CrowdStrike’s mess Google’s Workspace email validation flaw and its consequences for OAuth’d applications Is the VMWare ESX group membership feature a CVE or an FYI? Secureboot continues to under-deliver North Korea’s…
…
continue reading
1
Wide World of Cyber: Why we should show CrowdStrike no mercy
44:40
44:40
Spill senere
Spill senere
Lister
Lik
Likt
44:40
In this episode of Wide World of Cyber, Risky Business host Patrick Gray discusses the recent CrowdStrike incident and its implications for security software that operates in kernel space with Chris Krebs and Alex Stamos of SentinelOne, a CrowdStrike Competitor. The conversation also delves into Microsoft’s role in this whole disaster and the poten…
…
continue reading
1
Risky Business #756 -- Move fast and break everything
58:52
58:52
Spill senere
Spill senere
Lister
Lik
Likt
58:52
The Risky Biz main show returns from a break to the traditional internet-melting mess that happens whenever Patrick Gray takes a holiday. Pat and Adam Boileau talk through the week’s security news, including: Oh Crowdstrike, no, oh no, honey, no AT&T stored call records on Snowflake and you’ll never guess what happened next Squarespace buys Google …
…
continue reading
1
Risky Biz Soap Box: Mike Wiacek on lazy mode threat hunting
31:20
31:20
Spill senere
Spill senere
Lister
Lik
Likt
31:20
This Soap Box edition of the show is with Mike Wiacek, the CEO and Founder of Stairwell. Stairwell is a platform that creates something similar to an NDR, but for file analysis instead of network traffic. The idea is you get a copy of every unique file in your environment to the Stairwell platform, via a file forwarding agent. You get an inventory …
…
continue reading
1
Wide World of Cyber: State directed cybercrime
39:41
39:41
Spill senere
Spill senere
Lister
Lik
Likt
39:41
In this podcast Alex Stamos, Chris Krebs and Patrick Gray discuss the relationship between cybercrime and the state, which is often more complicated than it should be. While the US Government and its allies fight the scourge of ransomware, other governments are using it to either raise revenue or irritate their foes. North Korea sees ransomware as …
…
continue reading
1
Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!
59:19
59:19
Spill senere
Spill senere
Lister
Lik
Likt
59:19
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including: Widely used polyfill javascript gets hijacked by its new owners MacOS supply chain disaster bullet dodged That OpenSSH remote code exec OH MY <3 Entrust gets its CA business kicked to the kerb by Google South Korean telco intentionally viruses 600k custo…
…
continue reading
1
Risky Biz Soap Box: Why AI shouldn't really change your security controls
35:29
35:29
Spill senere
Spill senere
Lister
Lik
Likt
35:29
This is a sponsored Soap Box edition of the Risky Business podcast. Abhishek Agrawal is the CEO and co-founder of Material Security, an email security company that locks down cloud email archives. Attackers have been raiding mailspools since hacking has existed, and with those mailspools now in the cloud with services like o365 and Google Workspace…
…
continue reading
1
Risky Business #754 -- Assange pleads guilty to espionage, walks free
57:00
57:00
Spill senere
Spill senere
Lister
Lik
Likt
57:00
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including: Julian Assange finally cuts a deal, pleads guilty, and goes free USA to ban Kaspersky - even updates Car dealer SaaS provider CDK contemplates paying a ransom Intolerable healthcare ransomware attacks continue We revisit Windows proximity bugs via wifi a…
…
continue reading
1
Risky Business #753 – Congress and vuln researchers maul Microsoft
1:03:37
1:03:37
Spill senere
Spill senere
Lister
Lik
Likt
1:03:37
On this week’s retreat special, the entire Risky Business team is together in a tropical paradise for the first time. The team takes a break from the infinity pool to discuss the week’s security news: Microsoft recalls Recall, but why did it have to be such a mess And a Windows kernel wifi code-exec, really? Passkeys and identity are hard Scattered…
…
continue reading
1
Risky Business #752 -- Apple announcements thrill and terrify at the same time
1:04:07
1:04:07
Spill senere
Spill senere
Lister
Lik
Likt
1:04:07
On this week’s show Patrick Gray and Adam Boileau are joined by long-time NSA boffin Rob Joyce. Now Rob’s left the government service, he’s hobnobbing with us pundits, talking through the week’s news: Apple announces a big leap for confidential cloud computing into the mass market While at the same time, letting you just mosey around your iPhone fr…
…
continue reading
1
Risky Business #751 -- Snowflake, operation Endgame and Microsoft's looming FTC problem
1:04:01
1:04:01
Spill senere
Spill senere
Lister
Lik
Likt
1:04:01
On this week’s show Patrick Gray and Mark Piper discuss the week’s security news, including: What on earth happened at Snowflake? A look at operation Endgame Check Point’s hilarious adventures with dot dot slash Report says the FTC is looking at Microsoft’s security product bundling More ransomware hits Russia Much, much more 404 Media co-founder J…
…
continue reading
1
Risky Business #750 -- Why Microsoft's Recall is an attacker's best friend
1:01:33
1:01:33
Spill senere
Spill senere
Lister
Lik
Likt
1:01:33
On this week’s show Patrick and Adam discuss the week’s security news, including: Russian delivery company gets ransomware-wiper’d A supply-chain attack targets video software used in US courts Checkpoint firewalls get hacked, details as clear as mud Microsoft Recall delights hackers Aussie telco Optus gets told its IR report isn’t legal advice Cyb…
…
continue reading
1
Risky Business #749 -- Google answer to Microsoft's insecurity? Buy Google stuff!
54:05
54:05
Spill senere
Spill senere
Lister
Lik
Likt
54:05
This week’s episode was recorded in front of a live audience at AusCERT’s 2024 conference. Pat and Adam talked through: Google starts using security as a marketing tool against Microsoft, along with steep discounts Microsoft announces a creepy desktop recording AI UK govt proposes ransom payment controls Arizona woman runs a laptop farm for North K…
…
continue reading
1
Wide World of Cyber: Krebs and Stamos on How AI Will Change Cybersecurity
44:52
44:52
Spill senere
Spill senere
Lister
Lik
Likt
44:52
In this podcast SentinelOne’s Chief Trust officer Alex Stamos and its Chief Intelligence and Public Policy Officer Chris Krebs join Patrick Gray to talk all about AI. It’s been a year and a half since ChatGPT landed and freaked everyone out. Since then, AI has really entrenched itself as the next big thing. It’s popping up everywhere, and the use c…
…
continue reading
1
Risky Business #748 -- New cyber rules for US healthcare are coming
1:02:33
1:02:33
Spill senere
Spill senere
Lister
Lik
Likt
1:02:33
This week Patrick Gray and Adam Boileau along special guest Lina Lau discuss the week’s news, including: The ongoing Ascension healthcare disruption, and Whether its reasonable for healthcare orgs to be pushing back Platforming cybercriminals for interviews Own the libs by… not using E2EE messaging? CISA’s secure by design, we want to believe! The …
…
continue reading
1
Risky Business #747 -- Lockbit Leader Has A Very Bad Day
55:11
55:11
Spill senere
Spill senere
Lister
Lik
Likt
55:11
Patrick dials in from RSA in San Francisco to discuss the week’s security news with Adam, including: The west doxxes LockbitSupp, who must now hide his hundred million dollars Revil hacker behind Kasaya breach gets 14 years Microsoft makes some positive sounding* noises on security A fun flaw in nearly all VPN clients Gitlab admins continue their n…
…
continue reading
1
Risky Business #746 – Microsoft takes your security seriously*
1:03:12
1:03:12
Spill senere
Spill senere
Lister
Lik
Likt
1:03:12
On this week’s show Patrick and Adam discuss the week’s security news, including: Microsoft reassures* us that they take security very seriously* Cisco ASA firewalls get sneakily backdoored, but no one’s quite sure how Change Healthcare was 1FA Citrix all along The FTC, FCC and other government sticks get waved at tech Lizard Squad Finn who hacked …
…
continue reading
1
Snake Oilers: Push Security, Knocknoc and iVerify
42:06
42:06
Spill senere
Spill senere
Lister
Lik
Likt
42:06
In this edition of Snake Oilers we’ll be hearing from: Push Security: A browser plugin-based security company that combats identity-based attacks. (Much more compelling that it sounds in this description.) Knocknoc: The tool Risky Business uses to protect our own applications and services. (Restrict network/port access to users who are authenticate…
…
continue reading
1
Special Edition: Chris Krebs, Alex Stamos and Patrick Gray
45:26
45:26
Spill senere
Spill senere
Lister
Lik
Likt
45:26
In this special edition of the Risky Business podcast Patrick Gray chats with former Facebook CSO Alex Stamos and founding CISA director Chris Krebs about sovereignty and technology. China and Russia are doing their level best to yeet American tech from their supply chains – hardware, software and cloud services. They’ll be rebuilding these supply …
…
continue reading
1
Risky Business #745 – Tales from the PANageddon
58:10
58:10
Spill senere
Spill senere
Lister
Lik
Likt
58:10
On this week’s show Patrick and Adam discuss the week’s security news, including: Palo Alto’s firewalls have a ../ bad day Sisense’s bucket full of creds gets kicked over United Healthcare draws the ire of congress FISA 702 reauthorisation finally moves forward Apple warns about “mercenary exploitation” but what’s the India link? And much, much, mo…
…
continue reading
On this week’s show Patrick and Adam discuss the week’s security news, including: Ransomware: down but not out Zero day prices on the rise… … and what it means for enterprise software Geopolitical conflict comes to computers in Palau Ukraine cyber chief Illia Vitiuk suspended More x86 microarchitectural bad times And much much more Proofpoint’s chi…
…
continue reading
1
Snake Oilers: Kodex, ClearVector and Censys
42:03
42:03
Spill senere
Spill senere
Lister
Lik
Likt
42:03
In this edition of Snake Oilers you’ll hear pitches from three companies: Kodex: Makes a platform companies can use to interact with law enforcement (Solves the law enforcement impersonator problem, among others.) ClearVector: Cloud security startup from former FireEye/Mandiant SVP/CTO John Laliberte Censys: Scans the entire internet, identifies as…
…
continue reading