Skip to content
Artwork for Risky Bulletin
NewsTech NewsTechnology

Risky Bulletin

Risky Business Media

Regular cybersecurity news updates from the Risky Business team...

Play
  • 142 episodes
  • Avg 16 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Today · 11 min

    Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol

    A major vulnerability has been found in the ancient TACACS+ networking protocol, Australia’s Prime Minister claims an OpenAI agent hacked the country’s Medicare website, OpenAI gives Ukraine access to its Daybreak cyber-defense program and the UK will establish an anti-disinformation center. Show notes Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol

  • Yesterday · 14 min

    Srsly Risky Biz: Bring on the AI lawsuits

    Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. Its a good move. Leaving the companies on the hook keeps the pressure on them to do better with their cyber security and testing controls. They also discuss a Russian AI-powered cyberespionage campaign run by a group known as Midnight Blizzard. It used AI workflows to run the entire campaign so they got a lot more hacking done and accepted AI mistakes. This makes sense given that they want more intelligence from Ukrainian targets and don’t care at all about getting caught. This episode is also available on YouTube. Show notes

  • Wednesday · 8 min

    Risky Bulletin: Team Cymru unmasks shady Chinese proxy network

    A network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies. Show notes Risky Bulletin: Team Cymru unmasks shady Chinese proxy network

  • Monday · 24 min

    Between Two Nerds: Real-time cyber defence

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether there is such a thing as real-time cyber defence. Will agentic AI save us from hacking AI? This episode is also available on YouTube. Show notes Clem Delangue | X

  • Monday · 9 min

    Risky Bulletin: Gemini finally did some crimes

    Google’s Gemini hacked three companies, hackers claim a breach of Russia’s election commission, OpenAI was behind RubyGems’ May incident, and the Coast Guard and FBI board two ships to investigate cyberattacks. Show notes Risky Bulletin: Gemini hacked three companies too

  • Sunday · 15 min

    Sponsored: SpecterOps on the impact of AI agents on BloodHound

    In this Risky Business sponsored interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin explains how Entra Agent ID can introduce new identity relationships and potential attack paths. Show notes Justin Kohler on LinkedIn SpecterOps, Introduction to BloodHound

  • September 11 · 10 min

    Risky Bulletin: Anthropic agents went hacking again

    Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff. Show notes Risky Bulletin: Anthropic agents went hacking again

  • September 10 · 24 min

    Srsly Risky Biz: America's drivers licence breach is a national security disaster

    Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences. They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough. Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy. This episode is also available on YouTube Show notes

  • September 9 · 7 min

    Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

    Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty. Show notes Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

  • September 7 · 27 min

    Between Two Nerds: Can AI defend critical infrastructure?

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line. This episode is also available on YouTube. Show notes Heather Adkins X post Clem X post Secure connectivity principles for operational technology | NCSC

  • September 7 · 8 min

    Risky Bulletin: BEC campaign steals €35 million from French notaries

    Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin. Show notes Risky Bulletin: BEC campaign steals €35 million from French notaries

  • September 6 · 20 min

    Sponsored: Authentik is rethinking PAM for AI agents

    In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human. They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access. Show notes

  • September 4 · 10 min

    Risky Bulletin: Russia tells data centers to deploy drone defenses

    Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs. Show notes Risky Bulletin: Russia tells data centers to deploy drone defenses

  • September 3 · 22 min

    Srsly Risky Biz: China's botnets are worth disrupting

    Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal! Finally, they discuss efforts to fix US water sector security. Sprinkling free tools on the problem will have limited impact. This episode is also available on YouTube Show notes

  • September 2 · 9 min

    Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

    A BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness. Show notes Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates

  • August 31 · 29 min

    Between Two Nerds: The perfect hacker

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals. This episode is also available on YouTube. Show notes Bitdefender Labs report on SilkParasite OpenAI on the Hugging Face incident

  • August 31 · 7 min

    Risky Bulletin: New powers for Dutch intelligence services

    Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service. Show notes Risky Bulletin: Dutch intel services to get extensive new powers

  • August 30 · 21 min

    Sponsored: Attackers need to be right more than once

    In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown jewels”. The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times. Show notes

  • August 28 · 10 min

    Risky Bulletin: Two TeamPCP members arrested in Australia

    Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic. Show notes Risky Bulletin: Two TeamPCP members arrested in Australia

  • August 27 · 19 min

    Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting

    Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense. This episode is also available on YouTube Show notes

Showing 1–20 of 142 episodes