Timeline
Every post and feed across this instance
-
Snake Oilers: Realm Security, Horizon3 and Persona
In this edition of the Snake Oilers podcast, three vendors pop in to pitch you all on their wares:
- Realm Security: A security focussed, AI-first data pipeline platform
- Horizon3: AI hackers! Pentesting robots!! They’re coming fer yur jerbs!
- Persona: Verify customer and staff identities with live capture
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #788 -- Trump targets Chris Krebs, SentinelOne
On this week’s show Patrick Gray talks to former NSA Cybersecurity Director Rob Joyce about Donald Trump’s unprecedented, unwarranted and completely bonkers political persecution of Chris Krebs and his employer SentinelOne.
They also talk through the week’s cybersecurity news, covering:
- Mitre’s stewardship of the CVE database gets its funding DOGE’d
- The US signs on to the Pall Mall anti-spyware agreement
- China tries to play the nationstate cyber-attribution game, but comedically badly
- Hackers run their malware inside the Windows sandbox, for security against EDR
This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins to talk through the increasing sprawl of the identity ecosystem.
This episode is also available on Youtube.
Show notes
- Cybersecurity industry falls silent as Trump turns ire on SentinelOne | Reuters
- U.S. cyber defenders shaken by Trump's attack on their former boss
- Trump Revenge Tour Targets Cyber Leaders, Elections – Krebs on Security
- Wyden to block Trump's CISA nominee until agency releases report on telecoms’ ‘negligent cybersecurity’ | The Record from Recorded Future News
- Gabbard sets up DOGE-style team to cut costs, uncover intel ‘weaponization’
- MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty
- US to sign Pall Mall pact aimed at countering spyware abuses | The Record from Recorded Future News
- Court document reveals locations of WhatsApp victims targeted by NSO spyware | TechCrunch
- Spyware Maker NSO Group Is Paving a Path Back Into Trump’s America | WIRED
- NCSC shares technical details of spyware targeting Uyghur, Tibetan and Taiwanese groups | The Record from Recorded Future News
- Risky Bulletin: Chinese APT abuses Windows Sandbox to go invisible on infected hosts
- China escalates cyber fight with U.S., names alleged NSA hackers
- Researcher uncovers dozens of sketchy Chrome extensions with 4 million installs - Ars Technica
- China-based SMS Phishing Triad Pivots to Banks – Krebs on Security
- Risky Bulletin: CA/B Forum approves 47-days TLS certs
- Ransomware in het mkb: Cybercriminelen verhogen losgeld bij cyberverzekering
- 4chan Is Down Following What Looks to Be a Major Hack Spurred By Meme War
dts.podtrac.com -
Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Australia expels Iranian ambassador
- Hackers sabotage Iranian shipping satcoms
- APT hacker got doxxed in Phrack. Kind of. They’re probably Chinese, not DPRK?
- Trail of Bits uses image-downscaling to sneak prompts into Google Gemini
- The Com’s King Bob gets ten years in the slammer
- It’s a day that ends in -y, so of course there’s a new Citrix Netscaler RCE being used in the wild.
This week’s episode is brought to you by Corelight. Chief Strategy Officer Greg Bell talks through how they’ve been implementing AI for sifting through your network data. A model-context-protocol server that can rummage in all those packet logs for you while you keep investigating? Yes please.
This episode is also available on Youtube.
Show notes
- Embassy staff flee Canberra in dead of night | news.com.au — Australia’s leading news site for latest headlines
- Swedish security service says Iran uses criminal networks in Sweden | Reuters
- Risky Bulletin: Hackers sabotage Iranian ships at sea, again - Risky Business Media
- Microsoft scales back Chinese access to cyber early warning system | Reuters
- Microsoft Didn’t Disclose Key Details to U.S. Officials of China-Based Engineers, Record Shows — ProPublica
- .:: Phrack Magazine ::.
- Uncovering the Chinese Proxy Service Used in APT Campaigns
- Weaponizing image scaling against production AI systems -The Trail of Bits Blog
- FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations | Cybersecurity Dive
- CrowdStrike warns of uptick in Silk Typhoon attacks this summer | CyberScoop
- Kevin Beaumont: "There’s a bunch of new Netscal…" - Cyberplace
- US charges Oregon man in vast botnet-for-hire operation | Cybersecurity Dive
- South Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities | The Record from Recorded Future News
- SIM-Swapper, Scattered Spider Hacker Gets 10 Years – Krebs on Security
- Chinese national who sabotaged Ohio company’s systems handed four-year jail stint | The Record from Recorded Future News
- Nevada state offices close after wide-ranging 'network security incident' | Reuters
- DSLRoot, Proxies, and the Threat of ‘Legal Botnets’ – Krebs on Security
- Russia weighs Google Meet ban as part of foreign tech crackdown | The Record from Recorded Future News
- Kremlin-Mandated Messaging App Max Is Designed To Spy On Users
- Иеромонах РПЦ Макарий призвал помолиться за мессенджер MAX
dts.podtrac.com -
How the World Got Owned Episode 1: The 1980s
In this special documentary episode, Patrick Gray and Amberleigh Jack take a historical dive into hacking in the 1980s. Through the words of those that were there, they discuss life on the ARPANET, the 414s hacking group, the Morris Worm, the vibe inside the NSA and a parallel hunt for German hackers happening at a similar time to Cliff Stoll’s famous Cuckoo’s Egg story.
This podcast features the memories of:
- Jon Callas, former principal software engineer at Digital Equipment Corporation
- Mark Rasch, Morris Worm prosecutor
- Timothy Winslow, former 414 hacker
- Greg Chartrand, author of Cracking the Cuckoos Egg and
- Tony Sager, former NSA
How the World Got Owned is produced in partnership with SentinelOne.
Show notes
- 1988 Federal sentencing guidelines manual
- Computer Intruder is put on probation and fined $10,000 | The New York Times
- Computer Intruder is found guilty | The New York Times
- United States of America, Appellee, v. Robert Tappan Morris, Defendant-appellant, 928 F.2d 504 (2d Cir. 1991)
- The Cuckoo’s Egg: Tracking a Spy Through the Maze of Computer Espionage | Clifford Stoll
- Cracking the Cuckoo’s Egg: The Untold Story of tracking and finding Karl Koch aka Hagbard of the Chaos Computer Club | Greg Chartrand
- Computer Buffs Tapped NASA Files | The New York Times
- Young Computer Bandits Byte off More than They Could Chew | The Washington Post
- ‘Hacker’ is used by Mainstream Media, September 5, 1983 | EDN
- Neal Patrick to testify before congressional committee
- Wargames official trailer, 1983
- CBS News Segment on Robert Morris Computer Hacker
- The Fall of the Berlin Wall | Sky News
- I Hacked a Nuclear Facility in the 1980’s. You’re Welcome | CNN
dts.podtrac.com -
Wide World of Cyber: How state adversaries attack security vendors
In this edition of the Wide World of Cyber podcast Patrick Gray talks to SentinelOne’s Steve Stone and Alex Stamos about how foreign adversaries are targeting security vendors, including them.
From North Korean IT workers to Chinese supply chain attacks, SentinelOne and its competitors are constantly fending off sophisticated hacking campaigns.
This edition of the Wide World of Cyber was recorded in front of a live audience in San Francisco, with Patrick attending via Zoom.
The Wide World of Cyber podcast series is a wholly sponsored co-production between SentinelOne and Risky Business Media.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #795 -- How The Com is hacking Salesforce tenants
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- New York Times gets a little stolen Russian FSB data as a treat
- iVerify spots possible evidence of iOS exploitation against the Harris-Walz campaign
- Researcher figures out a trick to get Google account holders’ full names and phone numbers
- Major US food distributor gets ransomwared
- The Com’s social engineering of Salesforce app authorisations is a harbinger of our future problems
- Australian Navy forgets New Zealand has computers, zaps Kiwis with their giant radar.
This week’s episode is sponsored by identity provider Okta. Long-time friend of the show Alex Tilley is Okta’s Global Threat Research Coordinator, and he joins to discuss how organisations can use both human and technical signals to spot North Koreans in their midst.
This episode is also available on Youtube.
Show notes
- How The Times Obtained Secret Russian Intelligence Documents - The New York Times
- Ukraine's military intelligence claims cyberattack on Russian strategic bomber maker | The Record from Recorded Future News
- Harris-Walz campaign may have been targeted by iPhone hackers, cybersecurity firm says
- iVerify Uncovers Evidence of Zero-Click Mobile Exploitation in the U.S.
- Spyware maker cuts ties with Italy after government refused audit into hack of journalist’s phone | The Record from Recorded Future News
- Italian lawmakers say Italy used spyware to target phones of immigration activists, but not against journalist | TechCrunch
- Android chipmaker Qualcomm fixes three zero-days exploited by hackers | TechCrunch
- Cellebrite to acquire mobile testing firm Corellium in $200 million deal | CyberScoop
- Apple Gave Governments Data on Thousands of Push Notifications
- A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
- Bruteforcing the phone number of any Google user
- Acreed infostealer poised to replace Lumma after global crackdown | The Record from Recorded Future News
- BidenCash darknet forum taken down by US, Dutch law enforcement | The Record from Recorded Future News
- NHS calls for 1 million blood donors as UK stocks remain low following cyberattack | The Record from Recorded Future News
- Major food wholesaler says cyberattack impacting distribution systems | The Record from Recorded Future News
- Kettering Health confirms attack by Interlock ransomware group as health record system is restored | The Record from Recorded Future News
- Hackers abuse malicious version of Salesforce tool for data theft, extortion | Cybersecurity Dive
- shubs on X: "IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue: https://t.co/X3dkMz9gwK" / X
- Ross Ulbricht Got a $31 Million Donation From a Dark Web Dealer, Crypto Tracers Suspect | WIRED
- Australian navy ship causes radio and internet outages to parts of New Zealand
dts.podtrac.com -
Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- We roll our eyes over the “16 billion credentials” leak hitting mainstream news
- Some interesting cyber angles emerge from the conflict in Iran
- Opensource maintainer of libxml2 is fed up with this hacker crap
- Shockingly, there are yet more ways to trick people into pasting commands into Windows
- Veeam “patches” its backup software RCE like it’s 2002 … by breaking the public PoC
This week’s episode is sponsored by Internet-wide honeypot reconnaissance platform, Greynoise. Founder Andrew Morris joins to talk about their journey spotting Chinese ORB-builders hacking thousands of ASUS routers, and why they’re destined for the woodchipper.
This episode is also available on Youtube.
Show notes
- No, the 16 billion credentials leak is not a new data breach
- Canadian telecom hacked by suspected China state group - Ars Technica
- Telecom giant Viasat breached by China's Salt Typhoon hackers
- WarTranslated on X: "Iran’s jamming GPS in the Strait of Hormuz, messing with ~970 ships, per Windward. UKMTO confirms the interference. Faulty AIS coordinates are screwing up navigation in the Persian Gulf. The IRGC threatens to shut the strait down in hours. https://t.co/kdMJvshOGC" / X
- Dmitri Alperovitch on X: "Chairman of the Joint Chiefs Gen. Dan Caine says @US_CYBERCOM supported this strike mission" / X
- Top Pentagon spy pick rejected by White House - POLITICO
- DHS warns of heightened cyber threat as US enters Iran conflict | Cybersecurity Dive
- Exclusive: Early US intel assessment suggests strikes on Iran did not destroy nuclear sites, sources say
- U.S. braces for Iran's response after overnight strikes on nuclear sites
- Assessing the Damage to Iran’s Nuclear Program
- Iran Hacks Tirana Municipality in Retaliation Over MEK - Tirana Times
- Iran's government says it shut down internet to protect against cyberattacks | TechCrunch
- Aflac discloses cyber intrusion linked to wider crime spree targeting insurance industry | Cybersecurity Dive
- Tonga Ministry of Health hit with cyberattack affecting website, IT systems | The Record from Recorded Future News
- Alleged Ryuk ransomware gang member arrested in Ukraine and extradited to US | The Record from Recorded Future News
- Russia releases REvil members after convictions for payment card fraud | The Record from Recorded Future News
- OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys - SpecterOps
- Triaging security issues reported by third parties (#913) · Issue · GNOME/libxml2
- README: Set expectations straight (35d04a08) · Commits · GNOME / libxml2 · GitLab
- What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog
- FileFix - A ClickFix Alternative | mr.d0x
- Address bar shows hp.com. Browser displays scammers’ malicious text anyway. - Ars Technica
- Researchers urge vigilance as Veeam releases patch to address critical flaw | Cybersecurity Dive
- ASUSpicious Flaw - Millions of Users’ Information Exposed Since 2022 | MrBruh's Epic Blog
- Perth dad who created ‘evil twin’ Wi-Fi did so to access pictures of women
- GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
dts.podtrac.com -
Soap Box: AI has entered the SOC, and it ain't going anywhere
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Dropzone AI founder Ed Wu about the role of LLMs in the SOC.
The debate about whether AI agents are going to wind up in the SOC is over, they’ve already arrived. But what are they good for? What are they NOT good for? And where else will we see AI popping up in security?
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape
In this podcast, Patrick Gray chats with SentinelOne’s Chris Krebs and Alex Stamos about the huge changes afoot in the United States government and what they mean for the threat environment. From the director of NSA being fired to massive job cuts at CISA and huge foreign policy shifts, tomorrow’s threat environment is going to be very different to today’s. Tune in to hear analysis from two of the best in the business!
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Struggling to find that pesky passwords.xlsx in Sharepoint? Copilot has your back!
- The ransomware ecosystem is finding life a bit tough lately
- SAP Netweaver bug being used by Chinese APT crew
- Academics keep just keep finding CPU side-channel attacks
- And of course… bugs! Asus, Ivanti, Fortinet… and a Nissan LEAF?
This week’s episode is sponsored by Resourcely, who will soothe your Terraform pains. Founder and CEO Tracis McPeak joins to talk about how to get from a very red dashboard full of cloud problems to a workable future.
This episode is also available on Youtube.
Show notes
- Exploiting Copilot AI for SharePoint | Pen Test Partners
- MrBruh's Epic Blog
- Ransomware group Lockbit appears to have been hacked, analysts say | Reuters
- "CONTI LEAK: Video they tried to bury! 6+ Conti members on a private jet. TARGET’s birthday — $10M bounty on his head. Filmed by TARGET himself. Original erased — we kept a copy."
- Mysterious hackers who targeted Marks and Spencer's computer systems hint at political allegiance as they warn other tech criminals not to attack former Soviet states
- The organizational structure of ransomware groups is evolving rapidly.
- SAP NetWeaver exploitation enters second wave of threat activity
- China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures
- DOGE software engineer’s computer infected by info-stealing malware
- Hackers hijack Japanese financial accounts to conduct nearly $2 billion in trades
- FBI and Dutch police seize and shut down botnet of hacked routers
- Poland arrests four in global DDoS-for-hire takedown
- School districts hit with extortion attempts after PowerSchool breach
- EU launches vulnerability database to tackle cybersecurity threats
- Training Solo - vusec
- Branch Privilege Injection: Exploiting Branch Predictor Race Conditions – Computer Security Group
- Remote Exploitation of Nissan Leaf: Controlling Critical Body Elements from the Internet
- PSIRT | FortiGuard Labs
- EPMM Security Update | Ivanti
dts.podtrac.com -
Risky Business #782 -- Are the USA and Russia cyber friends now?
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Did the US decide to stop caring about Russian cyber, or not?
- Adam stans hard for North Korea’s massive ByBit crypto-theft
- Cellebrite firing Serbia is an example of the system working
- Starlink keeps scam compounds in Myanmar running
- Biggest DDoS botnet yet pushes over 6Tbps
This week’s episode is sponsored by network visibility company Corelight. Vincent Stoffer, field CTO at Corelight joins to talk through where eyes on your network can spot attackers like Salt and Volt Typhoon.
This episode is also available on Youtube.
Show notes
- Sygnia Preliminary Bybit Investigation Report
- Verichains Bybit Incident Investigation Preliminary Report
- North Koreans finish initial laundering stage after more than $1 billion stolen from Bybit | The Record from Recorded Future News
- Risky Bulletin: Trump administration stops treating Russian hackers as a threat - Risky Business
- Did Trump Admin Order U.S. Cyber Command and CISA to Stand Down on Russia? (Story updated)
- Russia to redeploy resources freed up by end of war in Ukraine, warns Finnish intelligence | The Record from Recorded Future News
- FBI urges crypto community to avoid laundering funds from Bybit hack | The Record from Recorded Future News
- Risky Bulletin: Cellebrite bans bad boy Serbia - Risky Business
- Belgium probes suspected Chinese hack of state security service | The Record from Recorded Future News
- Gabbard: UK demand to Apple for backdoor access is 'grave concern' to US | The Record from Recorded Future News
- Elon Musk’s Starlink Is Keeping Modern Slavery Compounds Online | WIRED
- U.S. Soldier Charged in AT&T Hack Searched “Can Hacking Be Treason” – Krebs on Security
- Google Password Manager finally syncs to iOS—here’s how - Ars Technica
- Gmail Security Alert: Google To Ditch SMS Codes For Billions Of Users
- Massive Iran-linked botnet launches DDoS attacks against telecom, gaming platforms | Cybersecurity Dive
- Microsoft-signed driver used in ransomware attacks | Cybersecurity Dive
- London member of ‘Com’ network convicted of making indecent images of children | The Record from Recorded Future News
- Volt Typhoon & Salt Typhoon Attackers Are Evading EDR: What Can You Do? | Corelight
dts.podtrac.com -
Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- White House’s off-brand Israeli Signal fork logs cleartext messages with hard coded creds while getting hacked (twice). Just … Wow.
- Ransomware attacks on UK retailers are linked, and Marks & Spencer has it extra bad
- After six years dormant, a Magento eCommerce platform backdoor comes to life
- The North Korean IT worker scam is truly webscale
- NSO group owes Meta $168m for hacking WhatsApp
This week’s episode is sponsored by vulnerability management wranglers, Nucleus Security. Aaron Unterberger joins to talk through the complexities of tracking vulnerabilities in cloud components - left to the source, right to the deployments, and …sideways into the sidecars?
This week’s show also features an excerpt from Pat’s interview with Senator Mark Warner - Scoot back one in your podcast feed to check out the full chat, or find it on Youtube.
This episode is available on Youtube too.
Show notes
- Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages
- Despite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logs
- The Signal Clone the Trump Admin Uses Was Hacked
- App used by Mike Waltz suspends services after hacking claims
- Senator Demands Investigation into Trump Admin Signal Clone After 404 Media Investigation
- MG on X: "Looks like TeleMessage was probably procured and rolled out under Biden. There are public records for it. https://t.co/XCuZpi8PL3" / X
- Harrods becomes latest retailer to announce attempted cyberattack | The Record from Recorded Future News
- Co-op DragonForce cyber attack includes customer data, firm admits
- Co-op cyber attack: Staff told to keep cameras on in meetings
- Hundreds of e-commerce sites hacked in supply-chain attack - Ars Technica
- Microsoft’s new “passwordless by default” is great but comes at a cost - Ars Technica
- Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. - Ars Technica
- North Korean operatives have infiltrated hundreds of Fortune 500 companies | CyberScoop
- US wants to cut off key player in Southeast Asian cybercrime industry | The Record from Recorded Future News
- Myanmar militia leader sanctioned by US over cyber scam connections | The Record from Recorded Future News
- Trump proposes major cut to CISA’s budget, citing false ‘censorship’ claims | Cybersecurity Dive
- NSA to cut up to 2,000 civilian roles as part of intel community downsizing | The Record from Recorded Future News
- NSO Group owes $168M in damages to WhatsApp over spyware infections, jury says | CyberScoop
dts.podtrac.com -
Snake Oilers: Pangea, Cosive and Sysdig
In this edition of Snake Oilers three vendors pitch host Patrick Gray on their tech:
- Pangea: Guardrails and security for AI agents and applications (https://pangea.cloud)
Worried about your AI apps going rogue, being mean to your customers or even disclosing sensitive information? Pangea exists to address these risks. Fascinating stuff.
- Cosive: A threat intelligence company that can host your MISP server in AWS. CloudMISP! (https://www.cosive.com/snakeoilers)
Are you running a MISP server on some old hardware under a desk in your SOC? There’s a better way! Cosive can run it for you on AWS so you can just use it instead of wrestling with maintaining it. They also do some CTI consulting to help you get better use out of MISP.
- Sysdig: A Linux runtime security platform (https://sysdig.com/)
The modern Windows network is an all-singing, all-dancing, perfectly orchestrated, EDR-protected ballet. The modern Linux production environment… isn’t. Find out how Sysdig can help you get some visibility and control over your Linux fleet.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Soap Box: Why AI can't fix bad security products
In this Soap Box edition of the show Patrick Gray chats with the CEO of email security company Sublime Security, Josh Kamdjou. They talk about where AI is useful, where it isn’t, and why AI can’t save vendors from their bad product design choices.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #831 -- The AI bugpocalypse begins
On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
- Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package
- TeamPCP appear to have ransacked Cisco’s source and cloud environments
- AI is getting legitimately good at being told to “just go find some 0day in this”
- Kaspersky says Coruna and Triangulation do share code lineage
- Iranian hackers dump Kash Patel’s gmail spool
- Oh, and of course there’s a Citrix Netscaler memory leak being exploited in the wild
This week’s episode is sponsored by Dropzone AI, who make automated AI SOC analysts. Head honcho Ed Wu explains how they’ve built pre-canned ‘hunt packs’ to lead the AI off into your environment to find weird, interesting and security relevant things.
This episode is also available on Youtube.
Show notes
- Google links axios supply chain attack to North Korean group | The Record from Recorded Future News
- Cisco source code stolen in Trivy-linked dev environment breach
- chiefofautism on X: "someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo"
- h0mbre on X: "Claude is somehow better at kernel exploitation than creating meal plans."
- Vulnerability Research Is Cooked — Quarrelsome
- MAD Bugs: vim vs emacs vs Claude - Calif
- MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
- A Risky Biz Experiment: Hunting for iOS 0day with AI - Risky Business Media
- Security leaders say the next two years are going to be 'insane' | CyberScoop
- Coruna framework: an exploit kit and ties to Operation Triangulation | Securelist
- Apple says no one using Lockdown Mode has been hacked with spyware | TechCrunch
- Reverse engineering Apple’s silent security fixes - Calif
- Jury finds Meta's platforms are harmful to children in 1st wave of social media addiction lawsuits | PBS News
- Meta and YouTube found liable in social media addiction trial
- Iranian hackers publish emails allegedly stolen from Kash Patel
- Iran Us War: 'Legitimate targets': Iran issues warning to US tech firms including Google, Amazon, Microsoft, Nvidia - The Times of India
- Drop Site on X: "IRGC: From now on, for every assassination, an American company will be destroyed"
- OSINTtechnical on X: "Starlink shutdowns are forcing Russian troops even deeper into Ubiquiti’s ecosystem. "
- Citrix NetScaler products confirmed to be under exploitation | Cybersecurity Dive
- CISA tells federal agencies to patch Citrix NetScaler bug by Thursday | The Record from Recorded Future News
- Using a VPN May Subject You to NSA Spying | WIRED
- Post reporters called the White House. Their phones showed ‘Epstein Island.’ - The Washington Post
dts.podtrac.com -
Risky Biz Soap Box: runZero shakes up vulnerability management
In this sponsored Soap Box edition of the Risky Business podcast, industry legend HD Moore joins the show to talk about runZero’s major push into vulnerability management.
With its new Nuclei integration, runZero is now able to get a very accurate picture of what’s vulnerable in your environment, without spraying highly privileged credentials at attackers on your network.
It can also integrate with your EDR platform, and other data sources, to give you powerful visibility into the true state of things on your network and in your cloud.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #796 -- With special guest co-host Chris Krebs
On this week’s show Patrick Gray and Adam Boileau are joined by special guest Chris Krebs to discuss the week’s cybersecurity news. They talk through:
- Israeli “hacktivists” take out an Iranian state-owned bank
- Scattered-spider and friends pivot into attacking insurers
- Securing identities in a cloud-first world keeps us awake at night
- Microsoft takes the “aas” out of SaaS for Europe, leaving us with just software!
- An AI prompt injection into M365 exfils corporate data
This week’s episode is sponsored by Kroll’s Cyber practice. Kroll Cyber Associate Managing Director George Glass is based in London and talks through his experiences helping organisations in the UK deal with the Scattered Spider attacks.
This episode is also available on Youtube.
Show notes
- Iran’s Bank Sepah disrupted by cyberattack claimed by pro-Israel hacktivist group | CyberScoop
- Iran orders officials to ditch connected devices
- Heightened Cyberthreat Amidst Israel-Iran Conflict
- Threat group linked to UK, US retail attacks now targeting insurance industry | Cybersecurity Dive
- Coming to Apple OSes: A seamless, secure way to import and export passkeys - Ars Technica
- Cyberattack on Washington Post Compromises Email Accounts of Journalists
- Hackers impersonating US government compromise email account of prominent Russia researcher | The Record from Recorded Future News
- A good one to talk to Chris about:
- Breaking down ‘EchoLeak’, the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
- CISA warns of supply chain risks as ransomware attacks exploit SimpleHelp flaws | Cybersecurity Dive
- Whole Foods supplier making progress on restoration after cyberattack left shelves empty | The Record from Recorded Future News
- Ransomware attack on ticketing platform upends South Korean entertainment industry | The Record from Recorded Future News
- Advisory: Cybersecurity incident
dts.podtrac.com -
Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Cyber firms agree to deconflict and cross-reference hacker group names
- Russian nuclear facility blueprints gathered from public procurement websites
- Someone audio deepfaked the White House Chief of Staff, but for the dumbest reasons
- Germany identifies the Trickbot kingpin
- Google spots China’s MSS using Calendar events for malware C2
- Meta apps abuse localhost listeners to track web sessions.
This week’s episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss an open letter penned by JP Morgan Chase’s CISO that pleads with Software as a Service suppliers to try to suck less at security.
This episode is also available on Youtube.
Show notes
- 'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames | Reuters
- Ukraine's Massive Drone Attack Was Powered by Open Source Software
- Massive security breach: Russian nuclear facilities exposed online
- How a Spyware App Compromised Assad’s Army - New Lines Magazine
- Exclusive | Federal Authorities Probe Effort to Impersonate White House Chief of Staff Susie Wiles - WSJ
- Malaysian home minister’s WhatsApp hacked, used to scam contacts | The Record from Recorded Future News
- U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on Security
- Top counter antivirus service disrupted in global takedown | CyberScoop
- Cops in Germany Claim They’ve ID’d the Mysterious Trickbot Ransomware Kingpin | WIRED
- Australian ransomware victims now must tell the government if they pay up | The Record from Recorded Future News
- Google: China-backed hackers hiding malware in calendar events | Cybersecurity Dive
- Coinbase breach linked to customer data leak in India, sources say | Reuters
- US military IT specialist arrested for allegedly trying to leak secrets to foreign government | The Record from Recorded Future News
- NSO appeals WhatsApp decision, says it can’t pay $168 million in ‘unlawful’ damages | The Record from Recorded Future News
- ConnectWise says nation-state attack targeted multiple ScreenConnect customers | The Record from Recorded Future News
- Google Online Security Blog: Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store
- Meta and Yandex are de-anonymizing Android users’ web browsing identifiers - Ars Technica
- An Open Letter to Third-Party Suppliers
dts.podtrac.com -
Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Oracle’s long term CSO departs, and we’re not that sad about it
- Canada’s House of Commons gets popped through a Microsoft bug
- Russia degrades voice calls via Whatsapp and Telegram to push people towards Max
- South-East Asian scam compounds are also behind child sextortion
- Reports that the UK has backed down on Apple crypto are… strange
- Oh and of course there’s a Fortinet bug! There’s always a Fortinet bug!
This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins the show this week, and explains the journey of implementing SSO backed login on Windows, Mac and Linux. You’ll never guess which one was a few lines of PAM config, and which was a multi-month engineering project!
This episode is also available on Youtube.
Show notes
- Is Oracle facing headwinds? After layoffs, its 4-decade veteran Chief Security Officer Mary Ann Davidson departs
- Oracle CSO blasted over anti-security research rant - iTnews
- New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts | The Record from Recorded Future News
- Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme – Krebs on Security
- How we found TeaOnHer spilling users' driver's licenses in less than 10 minutes | TechCrunch
- UK has backed down on demand to access US Apple user data, spy chief says
- DNI Tulsi Gabbard on X: "As a result, the UK has agreed to drop its mandate for"
- Hackers target Workday in social engineering attack
- Russia curbs WhatsApp, Telegram calls to counter cybercrime | The Record from Recorded Future News
- Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability | The Record from Recorded Future News
- Norway police believe pro-Russian hackers were behind April dam sabotage | The Record from Recorded Future News
- US agencies, international allies issue guidance on OT asset inventorying | Cybersecurity Dive
- FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970)
- U.S. State Dept - Near Eastern Affairs on X: "He did not claim diplomatic immunity and was released by a state judge"
- 493 Cases of Sextortion Against Children Linked to Notorious Scam Compounds | WIRED
- .:: Phrack Magazine ::.
- Accenture to buy Australian cyber security firm CyberCX - iTnews
dts.podtrac.com -
Wide World of Cyber: Microsoft's China Entanglement
The Wide World of Cyber podcast is back! In this episode host Patrick Gray chats with Alex Stamos and Chris Krebs about Microsoft’s entanglement in China.
Redmond has been using Chinese engineers to do everything from remotely support US DoD private cloud systems to maintain the on premise version of the SharePoint code base. It’s all blown up in the press over the last month, but how did we get here? Did Microsoft make these decisions to save money? Or was it more about getting access to the Chinese market? And how can we all make the world’s most important software company stop doing things like this? Tune in to the Wide World of Cyber podcast to find out!
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Microsoft reshuffles security leadership. It doesn’t spark joy.
- Russia is hacking the Winter Olympics. Again. But y tho?
- China-linked groups are keeping busy, hacking telcos in Norway, Singapore and dozens of others
- Campaigns underway targeting Ivanti, BeyondTrust and SolarWinds products
- An unknown hero blocks 23/tcp on the US internet backbone
- And James Wilson pops into talk about Claude’s go at a C compiler
This week’s episode is sponsored by Ent.AI, an AI startup that isn’t quite ready to tell us all what they’re doing. But nevertheless, founder Brandon Dixon joins to discuss AI’s role in security. Where does language-based understanding take us that previous methods couldn’t?
This episode is also available on Youtube.
Show notes
- Updates in two of our core priorities - The Official Microsoft Blog
- Strengthening Windows trust and security through User Transparency and Consent | Windows Experience Blog
- Microsoft prepares to refresh Secure Boot’s digital certificate | Cybersecurity Dive
- Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilities | CyberScoop
- Microsoft releases urgent Office patch. Russian-state hackers pounce. - Ars Technica
- Italy blames Russia-linked hackers for cyberattacks ahead of Winter Olympics | The Record from Recorded Future News
- Researchers uncover vast cyberespionage operation targeting dozens of governments worldwide | The Record from Recorded Future News
- Germany warns of state-linked phishing campaign targeting journalists, government officials | The Record from Recorded Future News
- Norwegian intelligence discloses country hit by Salt Typhoon campaign | The Record from Recorded Future News
- Singapore says China-linked hackers targeted telecom providers in major spying campaign | The Record from Recorded Future News
- Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector | Cyber Security Agency of Singapore
- How Intel and Google Collaborate to Strengthen Intel® TDX
- Strengthening the Foundation: A Joint Security Review of Intel TDX 1.5 - Google Bug Hunters
- Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399) | Huntress
- EU, Dutch government announce hacks following Ivanti zero-days | The Record from Recorded Future News
- North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam | The Record from Recorded Future News
- BeyondTrust warns of critical RCE flaw in remote support software
- Rapid7 Analysis of CVE-2026-1731
- Building a C compiler with a team of parallel Claudes \ Anthropic
- (1) Post by @ryiron.bsky.social — Bluesky
- What AI Security Research Looks Like When It Works | AISLE
- South Korean crypto exchange races to recover $40bn of bitcoin sent to customers by mistake | South Korea | The Guardian
- White House to meet with GOP lawmakers on FISA Section 702 renewal | The Record from Recorded Future News
dts.podtrac.com -
Risky Business #810 -- Data extortion attacks have a silver lining
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- FBI intervenes in Scattered Spider Salesforce leaksite
- Clop loots Oracle E-Biz deployments
- Plus so much more data extortion.. At least it’s not ransomware … we guess?
- The US still can’t decide who’s gonna be in charge of NSA & Cybercom
- Cambodian scam compounds get sanctioned and $15b in crypto is seized
- NSO gets sold for pocket-lint-grade money
- Bugs! Redis CVSS 10, Ivanti, Crowdstrike and… Internet Explorer?! zeroday?! In the wild?!!!?
This week’s episode is sponsored by Stairwell. Founder Mike Wiacek talks about how Stairwell brings VirusTotal-like visibility to private files, and about integrating the insights that brings into your SOC workflow.
This episode is also available on Youtube.
Show notes
- FBI takedown banner appears on BreachForums site as Scattered Spider promotes leak | The Record from Recorded Future News
- Dozens of Oracle customers impacted by Clop data theft for extortion campaign | CyberScoop
- Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882)
- Clop is a Big Fish, But Not Worth Hunting - Risky Business Media
- ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security
- The company Discord blamed for its recent breach says it wasn't hacked
- Qantas confirms cybercriminals released stolen customer data | The Record from Recorded Future News
- Red Hat confirms breach of GitLab instance, which stored company’s consulting data | CyberScoop
- Risky Bulletin: Microsoft revamps Edge's "IE Mode" after zero-day attacks - Risky Business Media
- Teenagers arrested in England over cyberattack on nursery chain Kido | The Record from Recorded Future News
- Acting US Cyber Command, NSA chief won’t be nominated for the job, sources say | The Record from Recorded Future News
- Layoffs, reassignments further deplete CISA | Cybersecurity Dive
- Trump’s scandalous directive to AG Pam Bondi reached the public by accident
- Feds sanction Cambodian conglomerate over cyber scams, seize $15 billion from chairman | The Record from Recorded Future News
- US Congress committee investigating Musk-owned Starlink over Myanmar scam centres | Myanmar | The Guardian
- Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data | WIRED
- Netherlands invokes special powers against Chinese-owned semiconductor company Nexperia | The Record from Recorded Future News
- Spyware maker NSO Group confirms acquisition by US investors | TechCrunch
- Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits | WIRED
- Wiz Finds Critical Redis RCE Vulnerability: CVE‑2025‑49844 | Wiz Blog
- SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal | CyberScoop
- SonicWall SSLVPN devices compromised using valid credentials | Cybersecurity Dive
- Issues Affecting CrowdStrike Falcon Sensor for Windows
- ZDI Drops 13 Unpatched Ivanti Endpoint Manager Vulnerabilities - SecurityWeek
- Jaguar Land Rover launches phased restart at factories after cyber-attack | Jaguar Land Rover | The Guardian
- Windows 10 support ends today — here's who's affected and what you need to do
dts.podtrac.com -
Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Did the SharePoint bug leak out of the Microsoft MAPP program?
- Expel retracts its FIDO bypass writeup
- The mess surrounding the women-only dating-safety app Tea gets worse
- Broadcom customers struggle to get patches for VMWare hypervisor escapes
- Aeroflot gets hacked by the Cyber Partisans, disrupting flights
This week’s episode is sponsored by Push Security. Daniel Cuthbert joins and explains how having telemetry about identity from inside the browser is a key pillar for investigating intrusions in the browser-centric future.
This episode is also available on Youtube.
Show notes
- Microsoft Probing Whether Cyber Alert Tipped Off Chinese Hackers
- Microsoft says Warlock ransomware deployed in SharePoint attacks as governments scramble | The Record from Recorded Future News
- What we know about the Microsoft SharePoint attacks | Cybersecurity Dive
- An important update (and apology) on our PoisonSeed blog
- Tea User Files Class Action After Women’s Safety App Exposes Data
- A Second Tea Breach Reveals Users’ DMs About Abortions and Cheating
- Top Lawyer for National Security Agency Is Fired
- From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944
- VMware prevents some perpetual license holders from downloading patches
- Pro-Ukrainian hackers take credit for attack that snarls Russian flight travel - Ars Technica
- КИБЕРУДАР ПО АЭРОФЛОТУ РФ!v
- Treasury sanctions North Koreans involved in IT-worker schemes | Cybersecurity Dive
- Minnesota governor activates National Guard amid St. Paul cyberattack | StateScoop
- Outage was result of cyberattack, Post Luxembourg says
- Clorox files $380 million suit blaming Cognizant for 2023 cyberattack | Cybersecurity Dive
- Cisco network access security platform vulnerabilities under active exploitation | CyberScoop
- Arizona woman sentenced to 8.5 years for running North Korean laptop farm | The Record from Recorded Future News
- Cybercrime forum Leak Zone publicly exposed its users' IP addresses | TechCrunch
dts.podtrac.com -
Risky Business #799 -- Everyone's Sharepoint gets shelled
Risky Biz returns after two weeks off, and there sure is cybersecurity news to catch up on. Patrick Gray and Adam Boileau discuss:
- Microsoft tried to make outsourcing the Pentagon’s cloud maintenance to China okay (it was not)
- She shells Sharepoint by the sea-shore (by ‘she’ we mean ‘China’)
- Four (alleged) Scattered Spider members arrested (and bailed) in the UK
- Hackers spend $2700 to buy creds for a Brazilian payment system, steal $100M
- Fortinet has SQLI in the auth header, Citrix mem leak is weaponised, HP hardcodes creds and Sonicwalls get user-moderootkits. Just security vendor things!
This week’s episode is sponsored by Airlock Digital. CEO David Cottingham talks through what it takes to build a mature, resilient management platform for a security critical system.
This episode is also available on Youtube.
Show notes
- Update on DOD’s cloud services
- Microsoft to stop using engineers in China for tech support of US military, Hegseth orders review
- A Little-Known Microsoft Program Could Expose the Defense Department to Chinese Hackers
- While DOD policy bans unauthorized apps like TikTok from being on employees phones over national security risks
- Microsoft Fix Targets Attacks on SharePoint Zero-Day – Krebs on Security
- National Guard was hacked by China's 'Salt Typhoon' group, DHS says
- Suspected contractor for China’s Hafnium group arrested in in Italy | Cybersecurity Dive
- Singapore accuses Chinese state-backed hackers of attacking critical infrastructure networks | The Record from Recorded Future News
- UK Arrests Four in ‘Scattered Spider’ Ransom Group – Krebs on Security
- Four people bailed after arrests over cyber attacks on M&S, Co-op and Harrods
- Brazilian police arrest IT worker over $100 million cyber theft | The Record from Recorded Future News
- At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds | WIRED
- Hacker returns cryptocurrency stolen from GMX exchange after $5 million bounty payment | The Record
- Indian crypto exchange CoinDCX says $44 million stolen from reserves | The Record
- Chainalysis: $2.17 billion in crypto stolen in first half of 2025, driven by North Korean hacks | The Record
- PoisonSeed bypassing FIDO keys to ‘fetch’ user accounts
- Risky Bulletin: Browser extensions hijacked for web scraping botnet
- A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors
- A surveillance vendor was caught exploiting a new SS7 attack to track people's phone locations | TechCrunch
- Ukrainian hackers wipe databases at Russia's Gazprom in major cyberattack, intelligence source says
- File transfer company CrushFTP warns of zero-day exploit seen in the wild | The Record
- HPE warns of hardcoded passwords in Aruba access points
- Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
- Researchers, CISA confirm active exploitation of critical Citrix Netscaler flaw | Cybersecurity Dive
- Google finds custom backdoor being installed on SonicWall network devices - Ars Technica
- Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years
dts.podtrac.com -
Risky Business #818 -- React2Shell is a fun one
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- There’s a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?
- China is out popping shells with it
- Linux adds support for PCIe bus encryption
- Amnesty International says Intellexa can just TeamViewer into its customers’ surveillance systems
- …and a Belgian murder suspect complains that GrapheneOS’s duress wipe feature failed him?
This week’s episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll’s Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board?
This episode is also available on Youtube.
Show notes
- Risky Bulletin: APTs go after the React2Shell vulnerability within hours - Risky Business Media
- Guillermo Rauch on X: "React2Shell" / X
- React2Shell-CVE-2025-55182-original-poc/README.md at main · lachlan2k/React2Shell-CVE-2025-55182-original-poc · GitHub
- Hydrogen: Shopify’s headless commerce framework
- Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSS | The Record from Recorded Future News
- Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
- Three hacking groups, two vulnerabilities and all eyes on China | The Record from Recorded Future News
- Risky Bulletin: Linux adds PCIe encryption to help secure cloud servers
- Sean Plankey nomination to lead CISA appears to be over after Thursday vote | CyberScoop
- 🕳 on X: "This guy is complaining that GrapheneOS “failed him”. Showing a Belgian 🇧🇪 police request for an interrogation regarding premeditated murder (as a suspect)." / X
- Sanctioned spyware maker Intellexa had direct access to government espionage victims, researchers say | TechCrunch
- To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
- Is ransomware finally on the decline? Treasury data offers cautious hope | CyberScoop
- UK cyber agency warns LLMs will always be vulnerable to prompt injection | CyberScoop
- In comedy of errors, men accused of wiping gov databases turned to an AI tool - Ars Technica
dts.podtrac.com -
Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Australian airline Qantas looks like it got a Scattered Spider-ing
- Microsoft works towards blunting the next CrowdStrike disaster
- Changes are coming for Microsoft’s default enterprise app consenting setup
- Synology downplays hardcoded passwords for its M365 cloud backup agent
- The next Citrix Netscaler memory disclosure looks nasty
- Drug cartels used technical surveillance to find, fix and finish FBI informants and witnesses
This week’s episode is sponsored by RAD Security. Co-founder Jimmy Mesta joins to talk through how they use AI automation to assess the security posture of sprawling cloud environments.
This episode is also available on Youtube.
Show notes
- Qantas hit by cyber attack, leaving 6 million customer records at risk of data breach
- Scattered Spider appears to pivot toward aviation sector | Cybersecurity Dive
- Microsoft to make Windows more resilient following 2024 IT outage | Cybersecurity Dive
- (384) The Ultimate Guide to App Consent in Microsoft Entra - YouTube
- When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365" / modzero
- AT&T deploys new account lock feature to counter SIM swapping | CyberScoop
- Iran-linked hackers threaten to release Trump aides' emails | Reuters
- US government warns of new Iran-linked cyber threats on critical infrastructure | Cybersecurity Dive
- Actively exploited vulnerability gives extraordinary control over server fleets - Ars Technica
- Critical vulnerability in Citrix Netscaler raises specter of exploitation wave | Cybersecurity Dive
- Identities of More Than 80 Americans Stolen for North Korean IT Worker Scams | WIRED
- Cloudflare confirms Russia restricting access to services amid free internet crackdown | The Record from Recorded Future News
- Mexican drug cartel used hacker to track FBI official, then killed potential FBI informants, government audit says | CNN Politics
- Audit of the FBI's Efforts to Mitigate the Effects of Ubiquitous Technical Surveillance - Redacted Report
- NATO members aim for spending 5% of GDP on defense, with 1.5% eligible for cyber | The Record from Recorded Future News
- US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations | CyberScoop
- US, French authorities confirm arrest of BreachForums hackers | TechCrunch
- Spanish police arrest five over $542 million crypto investment scheme | The Record from Recorded Future News
- Scam compounds labeled a 'living nightmare' as Cambodian government accused of turning a blind eye | The Record from Recorded Future News
dts.podtrac.com -
Risky Biz Soap Box: Prowler, the open cloud security platform
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, founder of open source multi-cloud security product Prowler.
Toni explains how Prowler came to be, and how its journey followed his own learning about the cloud. The pair also discuss Prowler’s successful transition from an open-source project into a community, and now a growing business with an as-a-service platform.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs
In this extended interview the Vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner, joins Risky Business host Patrick Gray to talk about:
- The latest developments in the Signalgate scandal
- Why America needs to be more aggressive in responding to Volt Typhoon
- How tariffs are affecting American alliances
- Why the Five Eyes alliance is sacrosanct
This episode is available on Youtube
Show notes
dts.podtrac.com -
Risky Business #809 -- Hackers try to pay a journalist for access to the BBC
On this week’s show Patrick Gray is on holiday so Amberleigh Jack and Adam Boileau hijack the studio to discuss the week’s cybersecurity news, including:
- Hackers learn that trying to coerce a journalist just makes for … a great story?
- A man in his 40s gets arrested over the European airport chaos. Yep, we’re surprised, too.
- Adam fanboys over Watchtowr Labs while bemoaning Fortra.
- Academics pick apart Tile trackers and find them lacking
- CISA tells agencies to patch their damn Cisco gear
This episode is also available on YouTube.
Show notes
- 'You'll never need to work again': Criminals offer reporter money to hack BBC
- Government to guarantee £1.5bn Jaguar Land Rover loan after cyber shutdown
- Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms – Krebs on Security
- UK authorities arrest man in connection with cyberattack against aviation vendor | Cybersecurity Dive
- Chinese scammer pleads guilty after UK seizes nearly $7 billion in bitcoin
- Cyberattack on Japanese beer giant Asahi limits shipping, call center operations | The Record from Recorded Future News
- Afghanistan plunged into nationwide internet blackout, disrupting air travel, medical care | The Record from Recorded Future News
- Tile trackers are a stalker's dream, say Georgia Tech researchers
- Intel and AMD trusted enclaves, the backbone of network security, fall to physical attacks - Ars Technica
- Supermicro server motherboards can be infected with unremovable malware - Ars Technica
- China-linked hackers use ‘BRICKSTORM’ backdoor to steal IP | The Record from Recorded Future News
- Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
- Federal agencies given one day to patch exploited Cisco firewall bugs | The Record from Recorded Future News
- Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
- Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035)
- It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2
dts.podtrac.com -
Risky Biz Soap Box: Push Security's browser-first twist on identity security
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.
Push has built an identity security platform that collects identity information and events from your users’ browsers. It can detect phish kits and shut down phishing attempts, protect SSO credentials, and find shadow/personal account that a user has spun up.
It’s extremely difficult to bypass. That’s because when you’re in the browser it doesn’t matter how a phishing link arrives, or how a threat actor has concealed it from your detection stack – if the user sees it, Push sees it.
There are solutions for protecting your users SSO credentials, like passkeys. But what about all the SaaS in your environment? Even if it’s enrolled into your SSO, are you sure that’s how your users are authenticating to it? What about the automation platforms your developers and admins use? What about data platforms like Snowflake? Are your using setting up passkeys for those accounts? How would you know, and what problems can it cause if those accounts are vulnerable?
This is a fun one!
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #825 -- Palo Alto Networks blames it on the boogie
On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:
- Palo Alto threat researchers want to attribute to China, but management says shush
- An increasing proportion of ransomware is data extortion. Is this good?
- Cambodia says it’s going to dismantle scam compounds
- CISA sufferers through yet another shutdown
- Google Gemini’s training secrets are being systematically harvested to improve other LLMs
- Academics assess SaaS password managers’ resilience against a malicious server
This episode is sponsored by SSO-firewall integration vendor Knocknoc. Chief exec Adam Pointon joins to talk about the latest in defences… which is to say Knocknoc for Solaris/Sparc and HPUX on PA-RISC?! Okay also that other little known OS… Windows.
This episode is also available on Youtube.
Show notes
- Data-only extortion grows as ransomware gangs seek better profits | Cybersecurity Dive
- Arctic Wolf Threat Report 2026
- Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say
- Risky Bulletin: Cambodia promises to dismantle scam networks by April - Risky Business Media
- Age of the ‘scam state’: how an illicit, multibillion-dollar industry has taken root in south-east Asia | Cybercrime | The Guardian
- Critical flaw in BeyondTrust Remote Support sees early signs of exploitation | Cybersecurity Dive
- CISA Navigates DHS Shutdown With Reduced Staff - SecurityWeek
- Kimwolf Botnet Swamps Anonymity Network I2P – Krebs on Security
- BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign — Elastic Security Labs
- Over 500,000 VKontakte accounts hijacked through malicious Chrome extensions | The Record from Recorded Future News
- Password managers' promise that they can't see your vaults isn't always true - Ars Technica
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers
- Google finds state-sponsored hackers use AI at 'all stages' of attack cycle | CyberScoop
- Google: Gemini hit with 100,000+ prompts in cloning attempt
- Proofpoint acquires Acuvity to tackle the security risks of agentic AI | CyberScoop
- Cisco Redefines Security for the Agentic Era with AI Defense Expansion and AI-Aware SASE
- Sophos Acquires Arco Cyber to Bring CISO-Level, Agentic AI-Powered Expertise to Every Organization
- Dave Kennedy on X: "Regarding this, there was a couple questions on does the pacemaker continue to advertise - most BLE implantable devices go into a sleep type mode. In this case, we are lucky - it does not. We know based on law enforcement answers that she is using a more modern pacemaker with" / X
- Clash Report on X: "BIG: Dutch Defence Minister Gijs Tuinman hints that software independence is possible for F-35 jets. He literally said you can “jailbreak” an F-35. When asked if Europe can modify it without US approval: “That’s not the point… we’ll see whether the Americans will show https://t.co/f11cGvtYsO" / X
- Dutch police arrest man who refused to delete confidential files shared by mistake | The Record from Recorded Future News
dts.podtrac.com -
Risky Biz Soap Box: The lethal trifecta of AI risks
There’s a lethal trifecta of AI risks: access to private data, exposure to untrusted content, and external communication. In this conversation, Risky Business host Patrick Gray chats with Josh Devon, the co-founder of Sondera, about how to best address these risks.
There is no magic solution to this problem. AI models mix code and data, are non-deterministic, and are crawling around all over your enterprise data and APIs as you read this.
But in this sponsored interview, Josh outlines how we can start to wrap our hands around the problem.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #814 -- It's a bad time to be a scam compound operator
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- The KK Park scam compound in Myanmar gets blasted with actual dynamite
- China sentences more scammers TO DEATH
- While Singapore is opting to lash them with the cane
- Chinese security firm KnownSec leaks a bunch of documents
- Necromancy continues on NSO Group, with a Trump associate in charge
- OWASP freshens up the Top 10, you won’t believe what’s number three!
This week’s episode is sponsored by Thinkst Canary. Big bird Haroon Meer joins and, as usual, makes a good point. If you’re going to trust a vendor to do something risky like put a box on your network, they have an obligation to explain how they make that safe. Thinkst has a /security page that does exactly that. So why do we let Palo Alto and Fortinet get away with “trust me, bro”?
This episode is also available on Youtube.
Show notes
- Myanmar Junta Dynamites Scam Hub in PR Move as Global Pressure Grows
- China sentences 5 Myanmar scam kingpins to death | The Record from Recorded Future News
- Law passed for scammers, mules to be caned after victims in Singapore lose almost $4b since 2020 | The Straits Times
- KnownSec breach: What we know so far. - NetAskari
- Risky Bulletin: Another Chinese security firm has its data leaked
- Inside Congress Live
- The Government Shutdown Is a Ticking Cybersecurity Time Bomb | WIRED
- Former Trump official named NSO Group executive chairman | The Record from Recorded Future News
- Short-term renewal of cyber information sharing law appears in bill to end shutdown | The Record from Recorded Future News
- Jaguar Land Rover hack hurt the U.K.'s GDP, Bank of England says
- Monetary Policy Report - November 2025 | Bank of England
- SonicWall says state-linked actor behind attacks against cloud backup service | Cybersecurity Dive
- Japanese media giant Nikkei reports Slack breach exposing employee and partner records | The Record from Recorded Future News
- "Intel sues former employee for allegedly stealing confidential data" Post by @campuscodi.risky.biz — Bluesky
- Introduction - OWASP Top 10:2025 RC1
dts.podtrac.com -
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- CISA warns about the path from on-prem Exchange to the cloud
- Microsoft awards a crisp zero dollar bill for a report about what a mess its internal Entra-authed apps are
- Everyone and their dog seems to have a shell in US Federal Court information systems
- Google pays $250k for a Chrome sandbox escape
- Attackers use javascript in adult SVG files to … farm facebook likes?!
- SonicWall says users aren’t getting hacked with an 0day… this time.
This week’s episode is sponsored by SpecterOps. Chief product officer Justin Kohler talks about how the flagship Bloodhound tool has evolved to map attack paths anywhere. Bring your own applications, directories and systems into the graph, and join the identity attacks together.
This episode is also available on Youtube.
Show notes
- CISA, Microsoft issue alerts on ‘high-severity’ Exchange vulnerability | The Record from Recorded Future News
- Advanced Active Directory to Entra ID lateral movement techniques
- Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications
- Cartels may be able to target witnesses after major court hack
- Federal judiciary tightens digital security as it deals with ‘escalated cyberattacks’ | The Record from Recorded Future News
- Citrix NetScaler flaws lead to critical infrastructure breaches | Cybersecurity Dive
- DARPA touts value of AI-powered vulnerability detection as it announces competition winners | Cybersecurity Dive
- Buttercup is now open-source!
- HTTP/1.1 must die: the desync endgame
- US confirms takedown of BlackSuit ransomware gang that racked up $370 million in ransoms | The Record from Recorded Future News
- North Korean cyber-espionage group ScarCruft adds ransomware in recent attack | The Record from Recorded Future News
- Adult sites are stashing exploit code inside racy .svg files - Ars Technica
- Google pays 250k for Chromium sandbox escape
- SonicWall says recent attack wave involved previously disclosed flaw, not zero-day | Cybersecurity Dive
- Two groups exploit WinRAR flaws in separate cyber-espionage campaigns | The Record from Recorded Future News
- Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge | The Record from Recorded Future News
- Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home | WIRED
- Malware in Open VSX: These Vibes Are Off
- How attackers are using Active Directory Federation Services to phish with legit office.com links
- Introducing our guide to phishing detection evasion techniques
- The State of Attack Path Management
dts.podtrac.com -
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Apple ruins exploit developers’ week with fresh memory corruption mitigations
- Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack
- Salesloft says its GitHub was the initial entry point for its compromise
- Sitecore says people should “patch” its using-the-keymat-from-the-documentation “zero day”
- Rogue certs for 1.1.1.1 appear to be just (stupid) testing
- Jaguar Land Rover ransomware attackers are courting trouble
This week’s episode is sponsored by open source cloud security tool, Prowler. Founder Toni de la Fuente joins to discuss their new support for Microsoft 365. Time to point Prowler at your OneDrive and Sharepoint!
This episode is also available on Youtube.
Show notes
- Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
- Venezuela's president thinks American spies can't hack Huawei phones | TechCrunch
- 18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security
- Software packages with more than 2 billion weekly downloads hit in supply-chain attack - Ars Technica
- Salesloft platform integration restored after probe reveals monthslong GitHub account compromise | Cybersecurity Dive
- CISA orders federal agencies to patch Sitecore zero-day following hacking reports | The Record from Recorded Future News
- SAP warns of high-severity vulnerabilities in multiple products - Ars Technica
- The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest. - Ars Technica
- Cyberattack on Jaguar Land Rover threatens to hit British economic growth | The Record from Recorded Future News
- Cyberattack forces Jaguar Land Rover to tell staff to stay at home | The Record from Recorded Future News
- Bridgestone Americas continues probe as it looks to restore operations | Cybersecurity Dive
- Qantas penalizes executives for July cyberattack | The Record from Recorded Future News
- Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat' | The Record from Recorded Future News
- GOP Cries Censorship Over Spam Filters That Work – Krebs on Security
- Risky Bulletin: APT report? No, just a phishing test! - Risky Business Media
- Post by @patrick.risky.biz — Bluesky
dts.podtrac.com -
Risky Business #827 -- Iranian cyber threat actors are down but not out
On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:
- The US-Israeli attack on Iran had a whole lot of cyber. It’s clearly in the playbook now!
- The NSA Triangulation / L3 Harris Trenchant iOS exploit kit is on the loose, and being used by Chinese crypto scammers
- So long Maddhu Gottumukkala, but CISA’s annus horribilis continues
- Adam “humbug” Boileau complains about the Airsnitch wifi attack just being three ethernets in a trenchcoat
- ASD’s Cisco SD-WAN threat hunting guide is clearly borne of … experience
This week’s episode is sponsored by AI threat hunting platform Nebulock. Sydney Marrone joins to talk about how useful AI models are on the hunt, and her work building out an open source framework and maturity model. It’s methodology agnostic, so you can adapt it for your environment, and the github link is in the show notes!
This episode is also available on Youtube.
Show notes
- Inside the plan to kill Ali Khamenei
- Hacked traffic cams and hijacked TVs: How cyber operations supported the war against Iran | TechCrunch
- Matthew Prince 🌥 on X: "Counter to what some cyber vendors are saying, there’s been a dramatic drop in Iranian cyber operations. Likely as the operators are sheltering. They may pick back up, but right now there’s a noticeable lull." / X
- Cyber Command disrupted Iranian comms, sensors, top general says | The Record from Recorded Future News
- Iranian Hackers Use Elon Musk’s Starlink To Stay Online
- Exclusive | U.S. Smuggled Thousands of Starlink Terminals Into Iran After Protest Crackdown - WSJ
- Attacks on GPS Spike Amid US and Israeli War on Iran | WIRED
- Amazon Data Centers on Fire After Iranian Missile Strikes on Dubai
- A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals | WIRED
- Canceled contracts, a failed polygraph and personal disputes: Inside the turbulent tenure of Noem’s former cyber czar - POLITICO
- CISA CIO Robert Costello exits agency | CyberScoop
- OpenAI alters deal with Pentagon as critics sound alarm over surveillance
- Inside Anthropic’s Killer-Robot Dispute With the Pentagon - The Atlantic
- Read the full transcript of our interview with Anthropic CEO Dario Amodei - CBS News
- CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements
- Large-Scale Online Deanonymization with LLMs
- Hackers Weaponize Claude Code in Mexican Government Cyberattack - SecurityWeek
- New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises - Ars Technica
- CISA orders agencies to patch Cisco devices now under attack | Cybersecurity Dive
- CISCO SD-WAN THREAT HUNT GUIDE
- ClawJacked attack let malicious websites hijack OpenClaw to steal data
- Area Man Accidentally Hacks 6,700 Camera-Enabled Robot Vacuums | WIRED
- Intellexa founder, three others sentenced to 8 years in prison over Greek spyware scandal | The Record from Recorded Future News
- Moscow man accused of posing as FSB officer to extort Conti ransomware gang | The Record from Recorded Future News
- Farewell, Felix · The Recurity Lablog
- Atmos Sphere 2026 | Atmos
- The Agentic Threat Hunting Framework | Nebulock blog
- GitHub - Nebulock-Inc/agentic-threat-hunting-framework: ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy. · GitHub
dts.podtrac.com -
Risky Biz Soap Box: Greynoise knows when bad bugs are coming
In this sponsored Soap Box edition of the podcast, Andrew Morris joins Patrick Gray to talk about how Greynoise can often get a 90 day heads up on serious vulnerabilities. Whether it’s malicious actors doing reconnaissance or the affected vendors trying to understand the scope of the problem, it seems that mass scanning activity lines up pretty nicely with typical 90-day disclosure timelines.
A fascinating chat with Andrew, as always.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #815 -- Anthropic's AI APT report is a big deal
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Anthropic says a Chinese APT orchestrated attacks using its AI
- It’s a day ending in -y, so of course there are shamefully bad Fortinet exploits in the wild
- Turns out slashing CISA was a bad idea, now it’s time for a hiring spree
- Researchers brute force entire phone number space against Whatsapp contact discovery API
- DOJ figures out how to make SpaceX turn off scam compounds’ Starlink service
This week’s episode is sponsored by Mastercard. Senior Vice President of Mastercard Cybersecurity Urooj Burney joins to talk about how the roles of fraud and cyber teams in the financial sector are starting to converge. Mastercard also recently acquired Recorded Future, and Urooj talks about how they aim to integrate cyber threat intelligence into the financial world.
This episode is also available on Youtube.
Show notes
- Full report: Disrupting the first reported AI-orchestrated cyber espionage campaign
- Researchers question Anthropic claim that AI-assisted attack was 90% autonomous - Ars Technica
- China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work | CyberScoop
- Amazon discovers APT exploiting Cisco and Citrix zero-days | AWS Security Blog
- CISA gives federal agencies one week to patch exploited Fortinet bug | The Record from Recorded Future News
- PSIRT | FortiGuard Labs
- CISA, eyeing China, plans hiring spree to rebuild its depleted ranks | Cybersecurity Dive
- This Is the Platform Google Claims Is Behind a 'Staggering’ Scam Text Operation | WIRED
- A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers | WIRED
- DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound | WIRED
- Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million | The Record from Recorded Future News
- Cyberattack leaves Jaguar Land Rover short of £680 million | The Record from Recorded Future News
- FBI: Akira gang has received nearly $250 million in ransoms | The Record from Recorded Future News
- Operation Endgame: Police reveal takedowns of three key cybercrime tools | The Record from Recorded Future News
- Inside a Wild Bitcoin Heist: Five-Star Hotels, Cash-Stuffed Envelopes, and Vanishing Funds | WIRED
dts.podtrac.com -
Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat
On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They discuss:
- Iran’s Intune-based wiper attack on medical device maker Stryker
- Qihoo 360’s AI publishes its own wildcard TLS cert private key
- Instagram is canning its end-to-end encrypted messaging
- What’s going on with mobile internet access in Moscow?
- The Xbox One’s bootloader gets voltage glitched into submission
- Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt files…)
This week’s episode is sponsored by browser-based detection and response company, Push Security. Researcher Dan Green and Field CTO Mark Orlando join Pat to talk through the InstallFix variant of the *Fix attack technique.
This episode is also available on Youtube.
Show notes
- Iranian Hacktivists Strike Medical Device Maker Stryker in "Severe" Attack that Wiped Systems
- Stryker says it's restoring systems after pro-Iran hackers wiped thousands of employee devices | TechCrunch
- Stryker attack raises concerns about role of device management tool | Cybersecurity Dive
- Stryker tells SEC that timeline for recovery from cyberattack unknown | The Record from Recorded Future News
- How ‘Handala’ Became the Face of Iran’s Hacker Counterattacks | WIRED
- U.S Strikes Killed Iranian Cyber Chiefs, But The Hacks Continued
- Risky Business Features: Being a Wartime CISO
- Supply-chain attack using invisible code hits GitHub and other repositories - Ars Technica
- China's biggest cybersecurity company, Qihoo 360 just leaked their own wildcard SSL private key
- Emergent Cyber Behavior: When AI Agents Become Offensive Threat Actors - Irregular
- Risky Business Features: MCP is Dead
- Measuring AI Agents’ Progress on Multi-Step Cyber Attack Scenarios
- Measuring AI Agents' Progress on Multi-Step Cyber Attack Scenarios
- What is end-to-end encryption on Instagram | Instagram Help Center
- US Lawmakers Move to Kill the FBI’s Warrantless Wiretap Access | WIRED
- Website "whitelists" launched in Moscow | Forbes.ru
- Exclusive: Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show | Reuters
- Feds say another DigitalMint negotiator ran ransomware attacks and helped extort $75 million | CyberScoop
- Researchers disclose vulnerabilities in IP KVMs from four manufacturers - Ars Technica
- RE//verse 2026: Hacking the Xbox One by Markus 'doom' Gaasedelen - YouTube
- CrackArmor: Multiple vulnerabilities in AppArmor
dts.podtrac.com -
Risky Business #811 -- F5 is the tip of the crap software iceberg
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- China has been rummaging in F5’s networks for a couple of years
- Meanwhile China tries to deflect by accusing the NSA of hacking its national timing system
- Salesforce hackers use their stolen data trove to dox NSA, ICE employees
- Crypto stealing, proxy-deploying, blockchain-C2-ing VS Code worm charms us with its chutzpah
- Adam gets humbled by new Linux-capabilities backdoor trick
- Microsoft ignores its own guidance on avoiding BinaryFormatter, gets WSUS owned.
This episode is sponsored by Push Security. Co-founder and Chief Product Officer Jacques Louw joins to talk through how Push traced a LinkedIn phishing campaign targeting CEOs, and the new logging capabilities that proved critical to understanding it.
This episode is also available on Youtube.
Show notes
- Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks | WIRED
- Breach at US-based cybersecurity provider F5 blamed on China, sources say | Reuters
- Network security devices endanger orgs with ’90s era flaws | CSO Online
- China claims it caught US attempting cyberattack on national time center | The Record from Recorded Future News
- Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials
- Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials
- ICE amps up its surveillance powers, targeting immigrants and antifa - The Washington Post
- John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
- US court orders spyware company NSO to stop targeting WhatsApp, reduces damages | Reuters
- Apple alerts exploit developer that his iPhone was targeted with government spyware | TechCrunch
- A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones | WIRED
- GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace | Koi Blog
- European police bust network selling thousands of phone numbers to scammers | The Record from Recorded Future News
- Stephan Berger on X: "We recently took over an APT investigation from another forensic company. While reviewing analysis reports from the other company, we discovered that the attackers had been active in the network for months and had deployed multiple backdoors. One way they could regain root" / X
- Linux Capabilities Revisited | dfir.ch
- CVE-2025-59287 WSUS Remote Code Execution | HawkTrace
- TARmageddon (CVE-2025-62518): RCE Vulnerability Highlights the Challenges of Open Source Abandonware | Edera Blog
- Browser threat detection & response | Push Security | Push Security
- How Push stopped a high risk LinkedIn spear-phishing attack
dts.podtrac.com -
Left-Handed People Can’t Use a Fountain Pen
Apparently left-handed people can't use a fountain pen as the left hand smudges the ink as they write. I call bullshit on that. I'm left-handed, and I use a fountain pen just fine - even with an "overhand" grip.
I read this post from Neal Stephenson a few days ago (thanks to Sal for sharing it), where Neal - a professional, left-handed writer who writes his books with a pen and paper - shares some of his experience and advice on writing with a fountain pen.
I've been back using fountain pens for a few months now and it's going great, but as Neal says - it's all about the paper. I use a decent quality notepad for writing my notes, with either a £30 Lamy Safari fountain pen, or a ~£100 Kaweco AL Sport. Both work great and I'm yet to find myself with pen on my hand. Here's an example of me writing in my notebook, using both my Lamy and Kaweco.
As you can see, I have an overhand grip where my hand swipes across the ink as I write, but the ink is dry by the time my hand gets there. Both these pens have a medium nib too.
So if you're left-handed and think you can't use a fountain pen, you can! You just need some decent paper.
Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️
You can reply to this post by email, or leave a comment.
-
This AI notetaker won't sell surveillance to your boss
Granola CEO Chris Pedregal on invisible AI bots, the coming fight over who sees your transcripts, and why he turns down the companies that ask for them -
5. Le vivant comme terrain d’exploration avec Kim Verbeke
Kim Verbeke, conversation autour du vivant et des rêves !
Dans ce nouvel épisode, Kim Verbeke, créatrice d’objets vivants en céramique nous dévoile les dessous d’un métier passion dont les horaires se calent sur les variations successives de températures, de séchage et de périodes de rush.
Ce métier, c’est aussi laisser vivre ces créations dans les cuisines de chefs, de famille, de gens pour qui ces objets ont une âme. Et qui mesure toute la valeur de cet artisanat.
Avec Kim, j’ai découvert la petite fille qui jouait déjà les mains dans la boue au Burundi, la passionnée de nature, d’exploration et de vivant. Cette connexion à notre planète dont on se prend de passion, elle nous revèle bien des secrets sur nous-mêmes… Ce centrage, cet ancrage, élément essentiel dont Kim nous transmet l’importance.
Aussi, on a parlé de solitude choisie et nécéssaire, de choix de coeur plutôt que de raison, d’intuition, de notre ventre qui nous dirige vers certains choix plutôt que d’autres, de rêves d’éducation, de couple, d’amour.
Je vous invite à écouter cet épisode avec une âme d’enfant qui plonge les mains dans la terre, notre Terre.
Bonne écoute
-------------------
Liens pour retrouver Kim :
https://www.instagram.com/kimverbeke/
Lien vers l’épisode Métamorphose - Réaliser nos rêves pour faire advenir la révolution bleue : https://www.metamorphosepodcast.com/podcast/serie-ouvrir-nos-coeurs-ep-5-composer-nos-vies-comme-la-plus
The Awkward Yeti : https://www.instagram.com/theawkwardyeti/
BD coeur/cerveau : https://www.editions-delcourt.fr/bd/series/serie-coeur-et-cerveau/album-coeur-et-cerveau
Liens de Bombo : www.instagram.com/bombopodcast/
-------------------
➡️ Rejoignez la communauté sur Instagram.
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music ..
Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière et Christophe Gérard.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
10. Vague d'engagements positifs avec Noémie De Clercq
Dans ce nouvel épisode de Bombo, j’ai invité Noémie à mon micro 🎤 Noémie De Clercq est une militante dans ses valeurs et les incarne pleinement. La durabilité, elle la propage dans la food avec son entreprise Mingle qui accompagne les acteurs de l’alimentation. Ses combats sont tant politique que social, sociétal car au delà de la food, Noémie s’engage pour le féminisme, la grossophobie, l’inclusivité…
De ses multicasquettes de nombreux projets sont nés et clôturés, d’autres prennent ancrage, perdurent et se propagent.
📖 Comme la revue Manifeast, recueil d’acteurs durables suivant une charte précise et juste. 🔎 Elle nous donne accès à ces critères pour des choix individuels éclairés. Avec Noémie, on a fait le tour de sa vie.
Je vous invite à prendre part à cette douce vague afin de plonger ensemble dans une mer d’espoir.
Bonne écoute et bel été ☀️
Liens externes :
Suivre Noémie et Mingle Food : https://www.instagram.com/mingle.food/
Site web de Mingle Food : https://www.minglefood.be
Commander Manifeast 📖 : https://www.minglefood.be/manifeast
Découvrir Nomad Coworking 💻 : https://www.nomad-community.be
Suivre Bombo 🍋 : https://www.instagram.com/bombopodcast/
-------------------
➡️ Rejoignez la communauté sur Instagram.
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music .. Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
9. Reportage avec Mélanie Guisset qui sème les opportunités comme des haricots magiques
Dans ce nouvel épisode de Bombo, j’ai invité Mélanie Guisset, l’influenceuse potager sous le nom de Melting Green. Ancienne psychologue dans les unités spéciales de La Police, c’est après le covid et trois enfants qu’un virement de carrière a dû opérer. Son élan à frapper aux portes, sa ténacité, sa joie et son sourire ont convertit des milliers d’abonnés et lui ont ouvert les portes de la radio et ensuite de la télé.
De petite fille pipelette « allo, j’écoute » à psychologue à chroniqueuse, Mélanie a toujours aimer semer des graines, que ce soit dans la tête de ses patients, de ses auditeurs ou encore dans les consciences. Aujourd’hui, Mélanie s’émerveille de ses récoltes abondantes alors qu’elle n’a jamais su tenir un basilic. Et encourage tous les motivés à avoir la main verte. De grands-parents fermiers à son potager, un monde s’est déroulé entre temps mais rien n’était laissé au hasard.
J’ai découvert une femme généreuse, engagée et rayonnante dont l’énergie vous pousse à l’accompagner dans ses danses de la joie et à vous dépasser.
Je vous invite à nous rejoindre dans cette danse de mots et de rires que l’on a partagé.
Bonne écoute.
Liens externes :
Suivre Mélanie - https://www.instagram.com/melting.green?igsh=MTlpZDdseWUxaXZ6cg==
Suivre Bombo : www.instagram.com/bombopodcast/
-------------------
➡️ Rejoignez la communauté sur Instagram.
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music .. Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
6. Plats, pinceaux et ton piquant : l’univers décalé de Marion, illustratrice belge
Dans cet épisode, Marion Demeulenaere, française, devenue belge de coeur, nous amène à considérer l’illustration comme terrain de fouille et d’exploration infini empreint d’une ironie vintage et colorée. Elle encre son amour pour les lettres, les dessins, l’humour belge, les petits mijotés et autres joyeusetés culinaires familiales.
Avec une sincérité désarmante, Marion nous confie ses défis, ses inspirations et ses aspirations futures, tout en évoquant l'importance de suivre son cœur et son intuition dans chaque création. Préparez-vous à être inspiré par son approche joyeuse et passionnée de l’art et de la cuisine.
Avec Marion, on a fait les gourmandes et on a parlé de bons petits plats. Ceux de sa famille et de son enfance, ceux qu’elles concoctent avec amour pour ces convives et ceux sur le pouce.
Ce language culinaire que témoignent certaines personnes comme un vrai language d’amour. Comme rassembler autour d’une table avec un menu bien choisi, de bons produits, du partage, de la transmission et des sujets piquants d’honnêteté, c’est un de ses languages. Comme celui de bâtir un collectif pour briser les tabous, se serrer les coudes et créer sa tribu, le collectif “Ton Piquant”.
Je vous invite à vous laisser emporter par la magie de son univers gourmand et plein d’humour.
Bonne écoute
Liens de mon invité.e
Site de Marion : https://mariondemeulenaere.com/
Instagram de Marion : https://www.instagram.com/mariondemeulenaere
Atelier Ton piquant : http://tonpiquant.be/
Liens externes
Moirés : https://www.instagram.com/moires.brussels/
Les Gastrosophes : https://www.facebook.com/lesgastrosophes/
Camille Toussaint : https://www.instagram.com/cam.toussaint/
Lien de Bombo : www.instagram.com/bombopodcast/
-------------------
➡️ Rejoignez la communauté sur Instagram.
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music ..
Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière et Christophe Gérard.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
3. Trajectoire non balisée avec Véronique Socié, fromagère et passeuse d’histoires
Véronique Socié, fromagère jurassienne expatriée à Bruxelles. Entourée de chèvres, de montagne jusqu'à Bruxelles dans une zone touristique à La Fruitière.
Dans cet épisode, Véro nous démontre que vivre plusieurs vies en une est possible. Gardienne d’enfants, de chèvres, d’ânes, de savoirs, de refuge et aujourd’hui de fromages, cette hôtesse hors pair, remplit sa vie de valeurs fortes et de doux combats. La nature, sa ressource principale lui a donné l’élan nécessaire à la quitter mais jamais bien longtemps. Cette connexion forte, Véro la nourrit et la transmet au travers de son métier, au plus proche des paysans et des gens de la Terre. Notre terre si riche, si vivante dont un petit bout se goûte et se sent dans chaque fromage dont Véro est la passeuse. Passeuse de savoirs, d’histoires, de valeurs et de goût.
Véro m’a raconté son enfance, la petite Véro jouant la sauveuse de lion en Afrique, sa vie avec ses grands-mères matriarches d’une infinie patience avec elle, son Jura, sa nature, de son alimentation et de ses joues remplies, de sa première expérience gastronomique chez Berlin et de ce qui la conduite ici à Bruxelles, à ouvrir La Fruitière avec son fils, Léo.
Je vous souhaite de recevoir les mots de Véro comme elle vous nourrirrait de ses histoires.
Bonne écoute !
Liens externes :
La Fruitière : https://lafruitiere.brussels/
https://www.instagram.com/lafruitierebrussels/
Rue du Marché au Charbon 99-103 à Bruxelles
Liens de Bombo : www.instagram.com/bombopodcast/
-------------------
➡️ Rejoignez la communauté sur Instagram.
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music ..
Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière et Christophe Gérard.
Photographe : Maurine Toussaint.
http://www.maurinetoussaint.com/
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
29. La quête de sa vérité au rythme de ses propres saisons avec Coraline Brodkom
Dans ce nouvel épisode de Bombo, j’ai invité Coco, boosteuse d'entrepreneures et porteuses de projets. Plongez dans notre conversation avec Coraline Brodkom, où l’écriture devient fil rouge, la communauté un refuge, et la vérité un cap. Elle raconte sa résilience, ses échecs transformés en tremplins, et sa manière d’entreprendre au rythme de ses saisons intérieures. Un épisode qui inspire à bâtir une vie alignée — douce, libre et profondément humaine. Je vous invite dans cet épisode à écrire 3 prochaines actions folles ou moins folles qui vous combleraient.
Pourquoi écouter cet épisode avec Coco :
Découvrir son parcours marqué par la résilience après la perte de sa maman.
Comprendre comment l’écriture a toujours été son fil rouge.
Explorer sa vision de la communauté, de l’amitié et des liens du cœur.
S’inspirer de sa façon de créer une vie alignée avec ses propres rythmes.
Retenir ses apprentissages d’échecs transformés en bénédictions.
Plonger dans sa quête de vérité et de beauté au quotidien.
Liens externes :
Site de Coco - Boosteke : https://www.boosteke.com
S’inscrire à la tribu Boost : https://tally.so/r/3j978Q
Suivre Coco sur Instagram : https://www.instagram.com/boosteke/
-------------------
➡️ Rejoignez la communauté Bombo Podcast sur Instagram : https://www.instagram.com/bombopodcast/
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music .. Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
25. Dans le sac d'une créatrice audacieuse et engagée : Emmanuelle Adam
Dans ce nouvel épisode de Bombo, j’ai invité Emmanuelle Adam, fondatrice de la marque de maroquinerie bruxelloise Lilu. Plus que créer des sacs de cuir précieux, elle nous partage sa vision de la mode : symbole de différenciation, d’audace et d’engagement. Son regard sur le monde, le féminisme, l’artisanat et l’entreprenariat, …
Je vous invite à vivre cette discussion comme un questionnement sur vos engagements quotidiens.
Raisons d’écouter cet épisode avec Emmanuelle :
Une vision engagée de la mode : Emmanuelle défend l’artisanat local, la qualité et la durabilité, bien loin du fast fashion.
Un parcours inspirant : Elle raconte son chemin de styliste à entrepreneure avec sincérité et humilité.
Un univers sensible et puissant : Entre cuir, transmission et bienveillance, elle crée bien plus que des sacs.
Engagement, féminisme, entraide, audace... un podcast qui résonne profondément.
Un regard lucide sur le monde : Elle évoque avec force les dérives actuelles, les défis des femmes, et l’importance d’agir.
Emmanuelle parle vrai, avec douceur et conviction – un moment précieux à écouter.
Liens externes :
Lilu Boutique, Rue du Bailli 9 à Ixelles, Bruxelles
Site de Lilu Bag : https://lilu.be
Instagram de Lilu : https://www.instagram.com/lilu_bag/
Extrait "C'est du Belge" RTBF : https://auvio.rtbf.be/media/c-est-du-belge-les-sacs-lilu-un-savoir-faire-belge-2994874
-------------------
➡️ Rejoignez la communauté Bombo Podcast sur Instagram : https://www.instagram.com/bombopodcast/
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music .. Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co -
11. Du contenant au contenu avec Ben Lahaye
Dans ce nouvel épisode de Bombo, j’ai retrouvé Ben de l’atelier de céramique qui porte le nom de Ben et Bib’s son mari, Bibenbou. Les mains dans la terre, depuis ses études d’architecture, ce sont les premières commandes d’amis restaurateurs qui ont fait se professionnaliser cette pratique pour Ben.
Au fil des ans, Ben a créer un lien fort entre le corps, l’esprit et son environnement. C’est cette démarche qu’elle met au centre de ses activités aujourd’hui et de sa vie. Avec Bib’s, derrière les fourneaux et Ben derrière son tour, ils créent cette communion et ouvrent des espaces d’expérimentation.
Faire alliance avec son corps en le nourrissant selon son profil, c’est ce que Ben prône dans ses stages contenant/contenu que j’ai pu expérimenter l’année dernière. Véritable révélation et coup de coeur. Si bien, que je me suis formée au profilage et arpente encore les tours de Ben.
Ensemble, on a remonté le temps. Petite fille, toujours dehors, Ben revit ses moments festifs en famille. On a aussi parlé de son rapport à l’alimentation comme alicament, de sa pratique avec des chefs étoilés, du contenant et du contenu dans nos assiettes, de nature, du contact à la terre qui apaise.
Je vous invite à ouvrir la porte de cet univers singulier que Ben a créé et joignez vous à la fête du bon et du beau.
Lien externes :
Suivre Bibenbou : https://bibenbou.be & www.instagram.com/bibenbou/
Suivre Maya Dedecker - formation en profilage alimentaire : www.mayadedecker.be
Suivre Bombo : www.instagram.com/bombopodcast/
-------------------
➡️ Rejoignez la communauté Bombo Podcast sur Instagram : https://www.instagram.com/bombopodcast/
Bombo est disponible gratuitement sur toutes les plateformes : Apple Podcasts, Spotify, Deezer, PodcastAddict, Amazon Music .. Si vous avez aimé cet épisode, laissez moi des étoiles ⭐ et abonnez-vous pour ne rater aucun nouvel épisode.
Bombo, le podcast, donne la parole à des passionnés, des rêveurs, des artistes afin de créer, questionner et propager la joie ! Le propos de mes invité.e.s n’a pas la valeur d’expertise mais est le reflet de leur vécu, leur liberté et leur intimité.
-------------------
Bombo est une émission créée par Frédérique Scarnière
Générique : Frédérique Scarnière sur une musique composée par Christophe Gérard.
Montage et mixage : Frédérique Scarnière.
Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.
audio.ausha.co