Timeline
Every post and feed across this instance
-
Risky Business #821 -- Wiz researchers could have owned every AWS customer
In this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, joined by a special guest. BBC World Cyber Correspondent Joe Tidy is a long time listener and he pops in for a ride-along in the news segment plus a chat about his new book.
This week news includes:
- Did the US cyber Venezuela’s power grid, or do they just want us to think they coulda?
- US govt might boycott the RSAC Conference ‘cause Jen Easterly being CEO makes them mad
- MS Patch Tuesday fixes CVSS5.5 bug and … stops you shutting down
- Wiz pulls off cloud stunt hack that ends with control of everyone’s AWS console
- Millions of Bluetooth devices that use Google’s Fast Pairing will pair with anyone, any time
- GNU inet-tools’ telnetd parties like it’s 2007, and brings -f root unauthed remote login back
Thinkst is this week’s sponsor, and long time friend of the show Haroon Meer joins. As always they’re polishing their Canary tokens - adding breadcrumbs to lead you to them - but they’re also a bunch of giant nerds who now run South Africa’s Computer Olympiad.
This episode is also available on Youtube.
Show notes
- Cyberattack in Venezuela Demonstrated Precision of U.S. Capabilities - The New York Times
- Why I’m withholding certainty that “precise” US cyber-op disrupted Venezuelan electricity - Ars Technica
- Layered Ambiguity: US Cyber Capabilities in the Raid to Extract Maduro from Venezuela | Royal United Services Institute
- Former CISA Director Jen Easterly Will Lead RSAC Conference | WIRED
- Trump officials consider skipping premier cyber conference after Biden-era cyber leader named CEO - Nextgov/FCW
- Federal agencies ordered to patch Microsoft Desktop Windows Manager bug | The Record from Recorded Future News
- Windows 11 shutdown bug forces Microsoft into damage control • The Register
- CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog
- Critical flaw in AWS Console risked compromise of build environment | Cybersecurity Dive
- Never-before-seen Linux malware is “far more advanced than typical” - Ars Technica
- VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun - Check Point Research
- Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking | WIRED
- Critical flaw in Fortinet FortiSIEM targeted in exploitation threat | Cybersecurity Dive
- CVE-2025-64155: 3 Years of Remotely Rooting the FortiSIEM
- A single click mounted a covert, multistage attack against Copilot - Ars Technica
- Police raid homes of alleged Black Basta hackers, hunt suspected Russian ringleader | The Record from Recorded Future News
- Jordanian initial access broker pleads guilty to helping target 50 companies | The Record from Recorded Future News
- Supreme Court hacker posted stolen government data on Instagram | TechCrunch
- oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
- How crypto criminals stole $700 million from people - often using age-old tricks
- Ctrl + Alt + Chaos: How Teenage Hackers Hijack the Internet
dts.podtrac.com -
Risky Business #826 -- A week of AI mishaps and skulduggery
On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:
- Low skill actors compromise 600 Fortinets with AI-generated playbooks
- Anthropic calls out Chinese AI firms over model distillation
- Meta’s director of AI safety tells her ClawdBot not to delete her mail… so of course it does
- Peter Williams cops 7 years in jail for selling L3 Harris Trenchant’s exploits to Russia
- Ivanti got hacked in 2021 via… bugs in Ivanti
This episode is sponsored by line-rate network capture system Corelight. CEO Brian Dye joins to discuss what AI can do for defenders, and what it can’t.
This episode is also available on Youtube.
Show notes
- AI-augmented threat actor accesses FortiGate devices at scale
- "this reads to me like: they ran existing tools.... but with a cool dashboard :D"
- Anthropic accuses Chinese labs of trying to illicitly take Claude’s capabilities | CyberScoop
- Detecting and preventing distillation attacks
- Hegseth warns Anthropic to let the military use the company’s AI tech as it sees fit, AP sources say
- Anthropic Rolls Out Embedded Security Scanning for Claude
- AWS's AI Coding Bot Kiro Caused a 13-Hour Outage
- Running OpenClaw safely: identity, isolation, and runtime risk
- Former Adobe, Cisco and Salesforce CISO talks AI pentesting
- History Repeats: Security in the AI Agent Era
- Meta Director of AI Safety Allows AI Agent to Accidentally Delete Her Inbox
- Microsoft says Office bug exposed customers' confidential emails to Copilot AI | TechCrunch
- The (tangential) fix: Microsoft adds Copilot data controls to all storage locations
- Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker
- Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools
- Risky Bulletin: Russia starts criminal probe of Telegram founder Pavel Durov
- Ukraine pushes tighter Telegram regulation, citing Russian recruitment of locals
- The watchers: how openai, the US government, and persona built an identity surveillance machine that files reports on you to the feds
- Persona emails customers saying they don’t work with ICE or DHS amid ‘surveillance’ claims
- Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513
- Ivanti hacked in 2021 via its own product
- Fed agencies ordered to patch Dell bug by Saturday after exploitation warning | The Record from Recorded Future News
- From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
dts.podtrac.com -
Risky Business #786 -- Oracle is lying
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Yes, Oracle Health and Oracle Cloud did get hacked
- The fallout from Signalgate continues
- North Korean IT workers pivot to Europe
- Honeypot data suggests a storm is brewing for Palo Alto VPNs
- Canadian Anon gets arrested for hacking Texas GOP
This week’s episode is sponsored by Trail of Bits. Tjaden Hess, a Principal Security Engineer at Trail of Bits who specialises in cryptography, joins the show this week to talk about what a responsible crypto-currency exchange cold wallet setup looks like, and … contrasts that with Bybit.
This episode is also available on Youtube.
Show notes
- Oracle Health breach compromises patient data at US hospitals
- FBI probes Oracle hack tied to healthcare extortion: Report - Becker's Hospital Review | Healthcare News & Analysis
- Oracle Still Denies Breach as Researchers Persist
- Hacker linked to Oracle Cloud intrusion threatens to sell stolen data | Cybersecurity Dive
- Publius on X: "🚨 SIGNAL SCANDAL: Katherine Maher, the leftist NPR CEO, is currently the Chair of the Board of Signal! WHAT ARE THE ODDS? https://t.co/jWNTeAt3Jz" / X
- Mike Waltz Is Losing Support Inside the White House - WSJ
- Waltz and staff used Gmail for government communications, officials say - The Washington Post
- Pete Hegseth, Mike Waltz, Tulsi Gabbard: Private Data and Passwords of Senior U.S. Security Officials Found Online - DER SPIEGEL
- Even More Venmo Accounts Tied to Trump Officials in Signal Group Chat Left Data Public | WIRED
- You Need to Use Signal's Nickname Feature
- SignalGate Is Driving the Most US Downloads of Signal Ever | WIRED
- Wickr - Wikipedia
- When Getting Phished Puts You in Mortal Danger – Krebs on Security
- DPRK IT Workers Expanding in Scope and Scale | Google Cloud Blog
- How the FBI Tracked, and Froze, Millions Sent to Criminals in Massive Caesars Casino Hack
- Defense contractor to pay $4.6 million over third-party provider’s security weakness | The Record from Recorded Future News
- Surge in Palo Alto Networks Scanner Activity Indicates Possible Upcoming Threats
- CISA warns new malware targeting Ivanti zero-day vulnerability | Cybersecurity Dive
- Canadian hacker arrested for allegedly stealing data from Texas Republican Party | The Record from Recorded Future News
- British intel intern pleads guilty to smuggling top secret data out of protected facility | The Record from Recorded Future News
dts.podtrac.com -
Wide World of Cyber: DeepSeek lobs an AI hand grenade
In this episode of the Wide World of Cyber podcast Risky Business host Patrick Gray chats with SentinelOne’s Chris Krebs and Alex Stamos about AI, DeepSeek, and regulation.
From its bad transport security to its Chinese ownership and the economic implications of China “entering the chat”, everyone’s freaking out over this new model. But should they be?
Pat, Alex and Chris dissect the model’s significance, the politics of it all and how AI regulation in Europe, the US and China will shape the future of LLMs.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #778 -- Musk's child soldiers seize control of FedGov IT systems
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- DeepSeek leaves an unauthed database on the internet
- Russia hacked UK prime minister’s personal mail
- Australia sanctions a Telegram group… which is more sensible than it sounds
- Medical device backdoor turns out to be just poorly thought out upgrade feature
- Google abuses weak hashing to patch AMD CPU microcode
- And much, much more.
This week’s episode is sponsored by email security boffins Sublime. Their co-founder and CEO Josh Kamdjou joins to talk about how attackers’ abuse of legitimate services like Docusign is a challenge for email security vendors.
This episode is also available on Youtube.
Show notes
- Exclusive: Musk aides lock workers out of OPM computer systems | Reuters
- Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History | Wiz Blog
- Криптостилер SparkCat в магазинах Google Play и App Store | Securelist
- Russian hackers suspected of compromising British PM’s personal email account | The Record from Recorded Future News
- PowerSchool hack: missed basic security step resulted in data breach
- Australia sanctions ‘Terrorgram’ white supremacist online group | The Record from Recorded Future News
- ‘Paid actors’ could be behind some antisemitic attacks, Albanese says | Australian security and counter-terrorism | The Guardian
- Interview with James Glenday, ABC News Breakfast | Australian Minister for Foreign Affairs
- WhatsApp says spyware company Paragon Solutions targeted journalists
- Spyware maker Paragon confirms US government is a customer | TechCrunch
- Former Polish justice minister arrested in sprawling spyware probe | The Record from Recorded Future News
- Sweden releases suspected ship, says cable break ‘clearly’ not sabotage | The Record from Recorded Future News
- Backdoor found in two healthcare patient monitors, linked to IP in China
- Attackers exploit zero-day vulnerability in Zyxel CPE devices | Cybersecurity Dive
- AMD: Microcode Signature Verification Vulnerability · Advisory · google/security-research · GitHub
- 22-year-old math wiz indicted for alleged DeFI hack that stole $65M - Ars Technica
- A method to assess 'forgivable' vs 'unforgivable'... - NCSC.GOV.UK
- Living Off the Land: Credential Phishing via Docusign abuse
- Living Off the Land: Callback Phishing via Docusign comment
- B2B freight-forwarding scams on the rise to evade financial fraud crackdowns
- Callback phishing via invoice abuse and distribution list relays
- Enhanced message groups: Improving efficiency in email incident response
dts.podtrac.com -
Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- L3Harris Trenchant boss accused of selling exploits to Russia once worked at the Australian Signals Directorate
- Microsoft WSUS bug being exploited in the wild
- Dan Kaminsky DNS cache poisoning comes back because of a bad PRNG
- SpaceX finally starts disabling Starlink terminals used by scammers
- Garbage HP update deletes certificates that authed Windows systems to Entra
This week’s episode is sponsored by automation company Tines. Field CISO Matt Muller joins to discuss how Tines has embraced LLMs and the agentic-AI future into their workflow automation.
This episode is also available on Youtube.
Show notes
- US accuses former L3Harris cyber boss of stealing and selling secrets to Russian buyer | TechCrunch
- Attackers bypass patch in deprecated Windows Server update tool | CyberScoop
- CVE-2025-59287 WSUS Unauthenticated RCE | HawkTrace
- CVE-2025-59287 WSUS Remote Code Execution | HawkTrace
- Catching Credential Guard Off Guard - SpecterOps
- Cache poisoning vulnerabilities found in 2 DNS resolving apps - Ars Technica
- Uncovering Qilin attack methods exposed through multiple cases
- Safety on X: "By November 10, we’re asking all accounts that use a security key as their two factor authentication (2FA) method to re-enroll their key to continue accessing X. You can re-enroll your existing security key, or enroll a new one. A reminder: if you enroll a new security key, any" / X
- SpaceX disables more than 2,000 Starlink devices used in Myanmar scam compounds | The Record from Recorded Future News
- SpaceX: Update Your Inactive Starlink Dishes Now or They'll Be Bricked
- How we linked ForumTroll APT to Dante spyware by Memento Labs | Securelist
- Former Polish official indicted over spyware purchase | The Record from Recorded Future News
- HP OneAgent Update Broke Entra Trust on HP AI Devices
- Windows' Built-in OpenSSH for Offensive Security
- How Hacked Card Shufflers Allegedly Enabled a Mob-Fueled Poker Scam That Rocked the NBA | WIRED
dts.podtrac.com -
Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack
In the final show of 2025, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- React2Shell attacks continue, surprising no one
- The unholy combination of OAuth consent phishing, social engineering and Azure CLI
- Venezuela’s state oil firm gets ransomware’d, blames US… but what if it really is a US cyber op?!
- Russian junk-hacktivist gets indicted for cybering critical… err… a car wash and a fountain
- Microsoft finally turns RC4 off by default in Active Directory Kerberos
- Traefik’s TLS verify=on … turns it off, whoopsie 🤡
This week’s episode is sponsored by Sublime Security, makers of an email filtering solution that’s up for dealing with modern problems. Founder and CEO Josh Kamdjou joins to talk about calendar invite phishing, and the extra steps they’ve had to take to reach into people’s calendars and fix the mess.
The Risky Business weekly show is taking holiday break, and will return on 14 January for its twentieth year! Good luck out there, internet friends.
This episode is also available on Youtube.
Show notes
- React2Shell attacks expand widely across multiple sectors | Cybersecurity Dive
- React issues new patches after security researchers flag additional flaws | Cybersecurity Dive
- ConsentFix: Browser-native ClickFix hijacks OAuth grants
- Hacking Endpoint to Identity (Microsoft 365): "ConsentFix" - YouTube
- Announced pick for No. 2 at NSA won’t get the job as another candidate surfaces | The Record from Recorded Future News
- Laura Loomer on X: "EXCLUSIVE: 🚨 White House Official Confirms Ongoing Search for NSA Deputy Director As Tim Kosiba's Deep State And Anti-Trump Ties Raise Red Flags 🚨"
- Senior official at Indo-Pacific Command is set to be Trump’s pick to lead Cyber Command, NSA | The Record from Recorded Future News
- Trump Administration Turning to Private Firms in Cyber Offensive - Bloomberg
- PdV says cyber attacks contained | Latest Market News
- Venezuela state oil company blames cyberattack on US after tanker seizure | The Record from Recorded Future News
- Office of Public Affairs | Justice Department Announces Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups | United States Department of Justice
- DOJ, CISA warn of Russia-linked attacks targeting meat processing plants, nuclear regulatory entities and other critical infrastructure | The Record from Recorded Future News
- vx-underground on X: "The United States government has indicted a state-sponsored Threat Actor named Victoria Eduardovna Dubranova"
- vx-underground on X: "I'm actually laughing. One of the compromises is so dumb"
- German parliament suffers suspected cyber attack during Zelenskyy’s visit
- Während Selenskyj-Besuch: Große Internet-Störung im Bundestag! | Politik | BILD.de
- Germany summons Russian ambassador over cyberattack, election disinformation | The Record from Recorded Future News
- Russische hackgroep had toegang tot openbare waterfontein in Nederland | de Volkskrant
- Most Parked Domains Now Serving Malicious Content – Krebs on Security
- PornHub extorted after hackers steal Premium member activity data
- Office of Public Affairs | Senior Manager for Government Contractor Charged in Cybersecurity Fraud Scheme | United States Department of Justice
- Microsoft will finally kill obsolete cipher that has wreaked decades of havoc - Ars Technica
- CVE-2025-66491: Traefik's "Verify=On" Turned TLS Off | AISLE
- Dylan O'Donnell 🦋 on X: "This week I was rushed to hospital with a diagnosis of oesophageal cancer."
dts.podtrac.com -
Risky Biz Soap Box: How to measure vulnerability reachability
In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications.
It’s great to know there’s a CVE in a library you’re using, but it’s even better if you can say whether or not that vulnerability actually impacts your application.
They also talk about how Socket started out as a way to discover malicious packages in software projects, but these days it’s playing the CVE game as well.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #817 -- Less carnage than your usual Thanksgiving
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. It’s a quiet week with Thanksgiving in the US, but there’s always some cyber to talk about:
- Airbus rolls out software updates after a cosmic ray bitflips an A320 into a dive
- Krebs tracks down a Scattered Lapsus$ Hunters teen through the usual poor opsec…
- … as Wired publishes an opsec guide for teens.
- Microsoft decides its login portal is worth a Content Security Policy
- South Korean online retailer data breach covers 65% of the country
This week’s episode is sponsored by Nebulock. Founder and CEO Damien Lewke joins to talk through their work bringing more SIgma threat detection rules to MacOS.
This episode is also available on Youtube.
Show notes
- Airlines race to fix their Airbus planes after warning solar radiation could cause pilots to lose control | CNN
- Congress calls on Anthropic CEO to testify on Chinese Claude espionage campaign | CyberScoop
- Post-mortem of Shai-Hulud attack on November 24th, 2025 - PostHog
- Update: Shai-Hulud and the npm Ecosystem: Why CTEM Must Extend Beyond Your Walls | Armis
- Glassworm's resurgence | Secure Annex
- 4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign | Koi Blog
- Post by @spuxx.bsky.social — Bluesky
- Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’ – Krebs on Security
- The WIRED Guide to Digital Opsec for Teens | WIRED
- Perth hacker Michael Clapsis jailed after setting up fake Qantas Wi-Fi, stealing sex videos - ABC News
- Ed Conway on X: "The person who first downloaded the OBR's document at 11:35 on Budget day (I'm guessing someone at Reuters, given they first reported it) had already guessed the web address and tried and failed to download it 32 times so far that day(!) https://t.co/6iLm2uEUj2" / X
- Reuters accused of hack attack | ZDNET
- The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been ‘Performative’ | WIRED
- Microsoft tightens cloud login process to prevent common attack | Cybersecurity Dive
- Fortinet FortiWeb flaws found in unsupported versions of web application firewall | Cybersecurity Dive
- Cryptomixer platform raided by European police; $29 million in bitcoin seized | The Record from Recorded Future News
- Officials accuse North Korea’s Lazarus of $30 million theft from crypto exchange | The Record from Recorded Future News
- Data breach hits 'South Korea's Amazon,' potentially affecting 65% of country’s population | The Record from Recorded Future News
- NSA Contractor Groomed Teenage Girls On Reddit, DOJ Alleges
- Nebulock developed coreSigma for MacOS
- coreSigma repo:
dts.podtrac.com -
Risky Business #808 -- Insane megabug in Entra left all tenants exposed
On this week’s show Patrick Gray and special guest Rob Joyce discuss the week’s cybersecurity news, including:
- Secret Service raids a SIM farm in New York
- MI6 launches a dark web portal
- Are the 2023 Scattered Spider kids finally getting their comeuppance?
- Production halt continues for Jaguar Land Rover
- GitHub tightens its security after Shai-Hulud worm
This week’s episode is sponsored by Sublime Security. In this week’s sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI in an email security platform.
This episode is also available on YouTube
Show notes
- U.S. Secret Service disrupts telecom network that threatened NYC during U.N. General Assembly
- MI6 launches darkweb portal to recruit foreign spies | The Record from Recorded Future News
- One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens | dirkjanm.io
- Github npm changes
- Flights across Europe delayed after cyberattack targets third-party vendor | Cybersecurity Dive
- Major European airports work to restore services after cyberattack on check-in systems | The Record from Recorded Future News
- When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on | DataBreaches.Net
- UK arrests 2 more alleged Scattered Spider hackers over London transit system breach | Cybersecurity Dive
- Alleged Scattered Spider member turns self in to Las Vegas police | The Record from Recorded Future News
- Las Vegas police arrest minor accused of high-profile 2023 casino attacks | CyberScoop
- DOJ: Scattered Spider took $115 million in ransoms, breached a US court system | The Record from Recorded Future News
- vx-underground on X: "Scattered Spider ransoms company for 964BTC - wtf_thats_alot.jpeg - Document says "Cost of BTC at time was $36M" - $36M / 964BTC = $37.5K - BTC value was $37.5K in November, 2023 - Google "Ransomware, November, 2023" - omfg.exe https://t.co/uv2EzbL5HT" | X
- JLR ‘cyber shockwave ripping through UK industry’ as supplier share price plummets by 55% | The Record from Recorded Future News
- Jaguar Land Rover to extend production pause into October following cyberattack | Cybersecurity Dive
- New plan would give Congress another 18 months to revisit Section 702 surveillance powers | The Record from Recorded Future News
- AI-powered vulnerability detection will make things worse, not better, former US cyber official warns | Cybersecurity Dive
dts.podtrac.com -
Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Github Actions supply chain attack loots keys and secrets from 23k projects
- Why a VC fund now owns a minority stake in Risky Business Media (!?!?)
- China doxes Taiwanese military hackers
- Microsoft thinks .lnk file whitespace trick isn’t worth patching but APTs sure love it
- CISA delivers government efficiency by re-hiring fired staff… to put them on paid leave
- …and Google acquires Wiz for $32bn
This week’s show is sponsored by Zero Networks, and they have sent along a happy customer to talk about their experience. Aaron Steinke is Head of Infrastructure at La Trobe Financial, an asset management firm in Australia. Aaron talks through bringing modern zero-trust goodness to the reality of a technology environment that’s been around 40 years.
This episode is also available on Youtube.
Show notes
- Risky Bulletin: GitHub supply chain attack prints everyone's secrets in build logs - Risky Business Media
- China says Taiwan's military is behind PoisonIvy APT
- China identifies Taiwanese hackers allegedly behind cyberattacks and espionage | The Record from Recorded Future News
- Crypto exchange OKX shuts down tool used by North Korean hackers to launder stolen funds | The Record from Recorded Future News
- Lazarus Group deceives developers with 6 new malicious npm packages | CyberScoop
- Poisoned Windows shortcuts found to be a favorite of Chinese, Russian, N. Korean state hackers | The Record from Recorded Future News
- 'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in January | The Record from Recorded Future News
- Black Basta uses brute-forcing tool to attack edge devices | Cybersecurity Dive
- Alleged Russian LockBit developer extradited from Israel, appears in New Jersey court | The Record from Recorded Future News
- CISA works to contact probationary employees for reinstatement after court order - Nextgov/FCW
- ‘People Are Scared’: Inside CISA as It Reels From Trump’s Purge | WIRED
- The Wiretap: CISA Staff Are Cautiously Optimistic About Trump’s Pick For Director
- White House instructs agencies to avoid firing cybersecurity staff, email says | Reuters
- Signal no longer cooperating with Ukraine on Russian cyberthreats, official says | The Record from Recorded Future News
- Telegram CEO Pavel Durov allowed to leave France amid investigation
- Appellate court upholds sentence for former Uber cyber executive Joe Sullivan | The Record from Recorded Future News
- Google buys cloud security provider Wiz for $32 billion | The Record from Recorded Future News
- Pat Gray, Founder of Risky Business, Joins Decibel as Founder Advisor - Decibel
dts.podtrac.com -
Risky Business #779 -- DOGE staffer linked to The Com
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Musk’s DOGE kid has a history with The Com
- Paragon fires Italy as a spyware customer
- Thailand cuts power to scam compounds…
- … and arrests Phobos/8Base Russian cybercrims
- The CyberCX DFIR report shows non-U2F MFA is well and truly over
- And much, much more.
This week’s episode is sponsored by Dropzone.AI. They make an AI SOC analysis platform that relieves your analysts of the necessary but tedious work, so they can focus on the value of human insight. Dropzone’s founder and CEO Edward Wu joins to talk about how they approach the problem.
This episode is also available on Youtube.
Show notes
- Teen on Musk’s DOGE Team Graduated from ‘The Com’ – Krebs on Security
- ACLU Warns DOGE’s ‘Unchecked’ Access Could Violate Federal Law | WIRED
- Lawsuit accuses Trump administration of violating federal information security law | The Record from Recorded Future News
- The Recruitment Effort That Helped Build Elon Musk’s DOGE Army | WIRED
- States prepare privacy lawsuit against DOGE over access to federal data | The Record from Recorded Future News
- Union groups sue Treasury over giving DOGE access to sensitive data | The Record from Recorded Future News
- Student group sues Education Department over reported DOGE access to financial aid databases | The Record from Recorded Future News
- Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts | The Record from Recorded Future News
- DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers - Ars Technica
- DeepSeek Is a Win for Chinese Hackers - Risky Business
- Owner of spyware used in alleged WhatsApp breach ends contract with Italy | WhatsApp | The Guardian
- Another person targeted by Paragon spyware comes forward | TechCrunch
- Apple fixes security flaw allowing third-party access to locked devices | The Record from Recorded Future News
- U.S. sanctions bulletproof hosting provider for supplying LockBit infrastructure | CyberScoop
- Thailand cuts power supply to Myanmar scam hubs | The Record from Recorded Future News
- 8Base ransomware site taken down as Thai authorities arrest 4 connected to operation | The Record from Recorded Future News
- Two Russian nationals arrested in takedown of Phobos ransomware infrastructure | The Record from Recorded Future News
- The Company Man: Binance exec detained in Nigeria breaks his silence | The Record from Recorded Future News
- Deloitte pays $5M in connection with breach of Rhode Island benefits site | Cybersecurity Dive
- DFIR - Threat Report 2025 | CyberCX
- Request a Demo | Dropzone AI
dts.podtrac.com -
Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- TeleMessage memory dumps show up on DDoSecrets
- Coinbase contractor bribed to hand over user data
- Telegram does seem to be actually cooperating with law enforcement
- Britain’s legal aid service gets 15 years worth of applicant data stolen
- Shocking no one, Ivanti were weaseling when they blamed latest bugs on a third party library
This week’s episode is sponsored by Prowler, who make an open source cloud security tool. Founder and original project developer Toni de la Fuente joins to talk through the flexibility that open tooling brings. Prowler is also adding support for SaaS platforms like M365, and of course, an AI assistant to help you write checks!
This episode is also available on Youtube.
Show notes
- TeleMessage - Distributed Denial of Secrets
- How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes | WIRED
- Coinbase says thieves stole user data and tried to extort $20M
- Hack could cost Coinbase up to $400M: filing | Cybersecurity Dive
- Severed Fingers and ‘Wrench Attacks’ Rattle the Crypto Elite
- Money Stuff: US Debt Rates Itself | NewsletterHunt
- 2 massive black market services blocked by Telegram, messaging app says | Reuters
- Telegram Gave Authorities Data on More than 20,000 Users
- GovDelivery, an email alert system used by governments, abused to send scam messages | TechCrunch
- ATO warning as hackers steal $14,000 in tax returns: ‘Be wary’
- Hack of SEC social media account earns 14-month prison sentence for Alabama man | The Record from Recorded Future News
- 19-year-old accused of largest child data breach in U.S. agrees to plead guilty
- Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy | 7NEWS
- Pegasus spyware maker rebuffed in efforts to get off trade blacklist - The Washington Post
- Ransomware attack hits supplier of refrigerated groceries to British supermarkets | The Record from Recorded Future News
- UK government confirms massive data breach following hack of Legal Aid Agency | The Record from Recorded Future News
- Ivanti Endpoint Mobile Manager customers exploited via chained vulnerabilities | Cybersecurity Dive
- Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
dts.podtrac.com -
Risky Business #780 -- ASD torched Zservers data while admins were drunk
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Australian spooks scrubbed Medibank data off Zservers bulletproof hosting
- Why device code phishing is the latest trick in confusing poor users about cloud authentication
- Cloudflare gets blocked in Spain, but only on weekends and because of… football?
- Palo Alto has yet another dumb bug
- Adam gushes about Qualys’ latest OpenSSH vulns
Enterprise browser maker Island is this week’s sponsor and Chief Customer Officer Bradon Rogers joins the show to talk about how the adoption of AI everywhere is causing headaches.
This episode is also available on Youtube.
Show notes
- Five Russians went out drinking. When they got back, Australia had struck
- Dutch police say they took down 127 servers used by sanctioned hosting service | The Record from Recorded Future News
- Further cyber sanctions in response to Medibank Private cyberattack | Defence Ministers
- What is device code phishing, and why are Russian spies so successful at it? - Ars Technica
- Anyone Can Push Updates to the DOGE.gov Website
- Piracy Crisis: Cloudflare Says LaLiga Knew Dangers, Blocked IP Address Anyway (Update) * TorrentFreak
- Palo Alto Networks warns firewall vulnerability is under active exploitation | Cybersecurity Dive
- Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466 | Qualys Security Blog
- China’s Salt Typhoon hackers targeting Cisco devices used by telcos, universities | The Record from Recorded Future News
- RedMike Exploits Unpatched Cisco Devices in Global Telecommunications Campaign
- A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks | WIRED
- How Phished Data Turns into Apple & Google Wallets – Krebs on Security
- New hack uses prompt injection to corrupt Gemini’s long-term memory
- Arizona woman pleads guilty to running laptop farm for N. Korean IT workers, faces 9-year sentence | The Record from Recorded Future News
- US reportedly releases Russian cybercrime figure Alexander Vinnik in prisoner swap | The Record from Recorded Future News
- EXCLUSIVE: A Russia-linked Telegram network is inciting terrorism and is behind hate crimes in the UK – HOPE not hate
- Remembering David Jorm - fundraising for Mental Health research
dts.podtrac.com -
Snake Oilers: Realm Security, Horizon3 and Persona
In this edition of the Snake Oilers podcast, three vendors pop in to pitch you all on their wares:
- Realm Security: A security focussed, AI-first data pipeline platform
- Horizon3: AI hackers! Pentesting robots!! They’re coming fer yur jerbs!
- Persona: Verify customer and staff identities with live capture
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #788 -- Trump targets Chris Krebs, SentinelOne
On this week’s show Patrick Gray talks to former NSA Cybersecurity Director Rob Joyce about Donald Trump’s unprecedented, unwarranted and completely bonkers political persecution of Chris Krebs and his employer SentinelOne.
They also talk through the week’s cybersecurity news, covering:
- Mitre’s stewardship of the CVE database gets its funding DOGE’d
- The US signs on to the Pall Mall anti-spyware agreement
- China tries to play the nationstate cyber-attribution game, but comedically badly
- Hackers run their malware inside the Windows sandbox, for security against EDR
This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins to talk through the increasing sprawl of the identity ecosystem.
This episode is also available on Youtube.
Show notes
- Cybersecurity industry falls silent as Trump turns ire on SentinelOne | Reuters
- U.S. cyber defenders shaken by Trump's attack on their former boss
- Trump Revenge Tour Targets Cyber Leaders, Elections – Krebs on Security
- Wyden to block Trump's CISA nominee until agency releases report on telecoms’ ‘negligent cybersecurity’ | The Record from Recorded Future News
- Gabbard sets up DOGE-style team to cut costs, uncover intel ‘weaponization’
- MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty
- US to sign Pall Mall pact aimed at countering spyware abuses | The Record from Recorded Future News
- Court document reveals locations of WhatsApp victims targeted by NSO spyware | TechCrunch
- Spyware Maker NSO Group Is Paving a Path Back Into Trump’s America | WIRED
- NCSC shares technical details of spyware targeting Uyghur, Tibetan and Taiwanese groups | The Record from Recorded Future News
- Risky Bulletin: Chinese APT abuses Windows Sandbox to go invisible on infected hosts
- China escalates cyber fight with U.S., names alleged NSA hackers
- Researcher uncovers dozens of sketchy Chrome extensions with 4 million installs - Ars Technica
- China-based SMS Phishing Triad Pivots to Banks – Krebs on Security
- Risky Bulletin: CA/B Forum approves 47-days TLS certs
- Ransomware in het mkb: Cybercriminelen verhogen losgeld bij cyberverzekering
- 4chan Is Down Following What Looks to Be a Major Hack Spurred By Meme War
dts.podtrac.com -
Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Australia expels Iranian ambassador
- Hackers sabotage Iranian shipping satcoms
- APT hacker got doxxed in Phrack. Kind of. They’re probably Chinese, not DPRK?
- Trail of Bits uses image-downscaling to sneak prompts into Google Gemini
- The Com’s King Bob gets ten years in the slammer
- It’s a day that ends in -y, so of course there’s a new Citrix Netscaler RCE being used in the wild.
This week’s episode is brought to you by Corelight. Chief Strategy Officer Greg Bell talks through how they’ve been implementing AI for sifting through your network data. A model-context-protocol server that can rummage in all those packet logs for you while you keep investigating? Yes please.
This episode is also available on Youtube.
Show notes
- Embassy staff flee Canberra in dead of night | news.com.au — Australia’s leading news site for latest headlines
- Swedish security service says Iran uses criminal networks in Sweden | Reuters
- Risky Bulletin: Hackers sabotage Iranian ships at sea, again - Risky Business Media
- Microsoft scales back Chinese access to cyber early warning system | Reuters
- Microsoft Didn’t Disclose Key Details to U.S. Officials of China-Based Engineers, Record Shows — ProPublica
- .:: Phrack Magazine ::.
- Uncovering the Chinese Proxy Service Used in APT Campaigns
- Weaponizing image scaling against production AI systems -The Trail of Bits Blog
- FBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations | Cybersecurity Dive
- CrowdStrike warns of uptick in Silk Typhoon attacks this summer | CyberScoop
- Kevin Beaumont: "There’s a bunch of new Netscal…" - Cyberplace
- US charges Oregon man in vast botnet-for-hire operation | Cybersecurity Dive
- South Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities | The Record from Recorded Future News
- SIM-Swapper, Scattered Spider Hacker Gets 10 Years – Krebs on Security
- Chinese national who sabotaged Ohio company’s systems handed four-year jail stint | The Record from Recorded Future News
- Nevada state offices close after wide-ranging 'network security incident' | Reuters
- DSLRoot, Proxies, and the Threat of ‘Legal Botnets’ – Krebs on Security
- Russia weighs Google Meet ban as part of foreign tech crackdown | The Record from Recorded Future News
- Kremlin-Mandated Messaging App Max Is Designed To Spy On Users
- Иеромонах РПЦ Макарий призвал помолиться за мессенджер MAX
dts.podtrac.com -
How the World Got Owned Episode 1: The 1980s
In this special documentary episode, Patrick Gray and Amberleigh Jack take a historical dive into hacking in the 1980s. Through the words of those that were there, they discuss life on the ARPANET, the 414s hacking group, the Morris Worm, the vibe inside the NSA and a parallel hunt for German hackers happening at a similar time to Cliff Stoll’s famous Cuckoo’s Egg story.
This podcast features the memories of:
- Jon Callas, former principal software engineer at Digital Equipment Corporation
- Mark Rasch, Morris Worm prosecutor
- Timothy Winslow, former 414 hacker
- Greg Chartrand, author of Cracking the Cuckoos Egg and
- Tony Sager, former NSA
How the World Got Owned is produced in partnership with SentinelOne.
Show notes
- 1988 Federal sentencing guidelines manual
- Computer Intruder is put on probation and fined $10,000 | The New York Times
- Computer Intruder is found guilty | The New York Times
- United States of America, Appellee, v. Robert Tappan Morris, Defendant-appellant, 928 F.2d 504 (2d Cir. 1991)
- The Cuckoo’s Egg: Tracking a Spy Through the Maze of Computer Espionage | Clifford Stoll
- Cracking the Cuckoo’s Egg: The Untold Story of tracking and finding Karl Koch aka Hagbard of the Chaos Computer Club | Greg Chartrand
- Computer Buffs Tapped NASA Files | The New York Times
- Young Computer Bandits Byte off More than They Could Chew | The Washington Post
- ‘Hacker’ is used by Mainstream Media, September 5, 1983 | EDN
- Neal Patrick to testify before congressional committee
- Wargames official trailer, 1983
- CBS News Segment on Robert Morris Computer Hacker
- The Fall of the Berlin Wall | Sky News
- I Hacked a Nuclear Facility in the 1980’s. You’re Welcome | CNN
dts.podtrac.com -
Wide World of Cyber: How state adversaries attack security vendors
In this edition of the Wide World of Cyber podcast Patrick Gray talks to SentinelOne’s Steve Stone and Alex Stamos about how foreign adversaries are targeting security vendors, including them.
From North Korean IT workers to Chinese supply chain attacks, SentinelOne and its competitors are constantly fending off sophisticated hacking campaigns.
This edition of the Wide World of Cyber was recorded in front of a live audience in San Francisco, with Patrick attending via Zoom.
The Wide World of Cyber podcast series is a wholly sponsored co-production between SentinelOne and Risky Business Media.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #795 -- How The Com is hacking Salesforce tenants
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- New York Times gets a little stolen Russian FSB data as a treat
- iVerify spots possible evidence of iOS exploitation against the Harris-Walz campaign
- Researcher figures out a trick to get Google account holders’ full names and phone numbers
- Major US food distributor gets ransomwared
- The Com’s social engineering of Salesforce app authorisations is a harbinger of our future problems
- Australian Navy forgets New Zealand has computers, zaps Kiwis with their giant radar.
This week’s episode is sponsored by identity provider Okta. Long-time friend of the show Alex Tilley is Okta’s Global Threat Research Coordinator, and he joins to discuss how organisations can use both human and technical signals to spot North Koreans in their midst.
This episode is also available on Youtube.
Show notes
- How The Times Obtained Secret Russian Intelligence Documents - The New York Times
- Ukraine's military intelligence claims cyberattack on Russian strategic bomber maker | The Record from Recorded Future News
- Harris-Walz campaign may have been targeted by iPhone hackers, cybersecurity firm says
- iVerify Uncovers Evidence of Zero-Click Mobile Exploitation in the U.S.
- Spyware maker cuts ties with Italy after government refused audit into hack of journalist’s phone | The Record from Recorded Future News
- Italian lawmakers say Italy used spyware to target phones of immigration activists, but not against journalist | TechCrunch
- Android chipmaker Qualcomm fixes three zero-days exploited by hackers | TechCrunch
- Cellebrite to acquire mobile testing firm Corellium in $200 million deal | CyberScoop
- Apple Gave Governments Data on Thousands of Push Notifications
- A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
- Bruteforcing the phone number of any Google user
- Acreed infostealer poised to replace Lumma after global crackdown | The Record from Recorded Future News
- BidenCash darknet forum taken down by US, Dutch law enforcement | The Record from Recorded Future News
- NHS calls for 1 million blood donors as UK stocks remain low following cyberattack | The Record from Recorded Future News
- Major food wholesaler says cyberattack impacting distribution systems | The Record from Recorded Future News
- Kettering Health confirms attack by Interlock ransomware group as health record system is restored | The Record from Recorded Future News
- Hackers abuse malicious version of Salesforce tool for data theft, extortion | Cybersecurity Dive
- shubs on X: "IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue: https://t.co/X3dkMz9gwK" / X
- Ross Ulbricht Got a $31 Million Donation From a Dark Web Dealer, Crypto Tracers Suspect | WIRED
- Australian navy ship causes radio and internet outages to parts of New Zealand
dts.podtrac.com -
Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- We roll our eyes over the “16 billion credentials” leak hitting mainstream news
- Some interesting cyber angles emerge from the conflict in Iran
- Opensource maintainer of libxml2 is fed up with this hacker crap
- Shockingly, there are yet more ways to trick people into pasting commands into Windows
- Veeam “patches” its backup software RCE like it’s 2002 … by breaking the public PoC
This week’s episode is sponsored by Internet-wide honeypot reconnaissance platform, Greynoise. Founder Andrew Morris joins to talk about their journey spotting Chinese ORB-builders hacking thousands of ASUS routers, and why they’re destined for the woodchipper.
This episode is also available on Youtube.
Show notes
- No, the 16 billion credentials leak is not a new data breach
- Canadian telecom hacked by suspected China state group - Ars Technica
- Telecom giant Viasat breached by China's Salt Typhoon hackers
- WarTranslated on X: "Iran’s jamming GPS in the Strait of Hormuz, messing with ~970 ships, per Windward. UKMTO confirms the interference. Faulty AIS coordinates are screwing up navigation in the Persian Gulf. The IRGC threatens to shut the strait down in hours. https://t.co/kdMJvshOGC" / X
- Dmitri Alperovitch on X: "Chairman of the Joint Chiefs Gen. Dan Caine says @US_CYBERCOM supported this strike mission" / X
- Top Pentagon spy pick rejected by White House - POLITICO
- DHS warns of heightened cyber threat as US enters Iran conflict | Cybersecurity Dive
- Exclusive: Early US intel assessment suggests strikes on Iran did not destroy nuclear sites, sources say
- U.S. braces for Iran's response after overnight strikes on nuclear sites
- Assessing the Damage to Iran’s Nuclear Program
- Iran Hacks Tirana Municipality in Retaliation Over MEK - Tirana Times
- Iran's government says it shut down internet to protect against cyberattacks | TechCrunch
- Aflac discloses cyber intrusion linked to wider crime spree targeting insurance industry | Cybersecurity Dive
- Tonga Ministry of Health hit with cyberattack affecting website, IT systems | The Record from Recorded Future News
- Alleged Ryuk ransomware gang member arrested in Ukraine and extradited to US | The Record from Recorded Future News
- Russia releases REvil members after convictions for payment card fraud | The Record from Recorded Future News
- OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys - SpecterOps
- Triaging security issues reported by third parties (#913) · Issue · GNOME/libxml2
- README: Set expectations straight (35d04a08) · Commits · GNOME / libxml2 · GitLab
- What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog
- FileFix - A ClickFix Alternative | mr.d0x
- Address bar shows hp.com. Browser displays scammers’ malicious text anyway. - Ars Technica
- Researchers urge vigilance as Veeam releases patch to address critical flaw | Cybersecurity Dive
- ASUSpicious Flaw - Millions of Users’ Information Exposed Since 2022 | MrBruh's Epic Blog
- Perth dad who created ‘evil twin’ Wi-Fi did so to access pictures of women
- GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
dts.podtrac.com -
Soap Box: AI has entered the SOC, and it ain't going anywhere
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Dropzone AI founder Ed Wu about the role of LLMs in the SOC.
The debate about whether AI agents are going to wind up in the SOC is over, they’ve already arrived. But what are they good for? What are they NOT good for? And where else will we see AI popping up in security?
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape
In this podcast, Patrick Gray chats with SentinelOne’s Chris Krebs and Alex Stamos about the huge changes afoot in the United States government and what they mean for the threat environment. From the director of NSA being fired to massive job cuts at CISA and huge foreign policy shifts, tomorrow’s threat environment is going to be very different to today’s. Tune in to hear analysis from two of the best in the business!
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Struggling to find that pesky passwords.xlsx in Sharepoint? Copilot has your back!
- The ransomware ecosystem is finding life a bit tough lately
- SAP Netweaver bug being used by Chinese APT crew
- Academics keep just keep finding CPU side-channel attacks
- And of course… bugs! Asus, Ivanti, Fortinet… and a Nissan LEAF?
This week’s episode is sponsored by Resourcely, who will soothe your Terraform pains. Founder and CEO Tracis McPeak joins to talk about how to get from a very red dashboard full of cloud problems to a workable future.
This episode is also available on Youtube.
Show notes
- Exploiting Copilot AI for SharePoint | Pen Test Partners
- MrBruh's Epic Blog
- Ransomware group Lockbit appears to have been hacked, analysts say | Reuters
- "CONTI LEAK: Video they tried to bury! 6+ Conti members on a private jet. TARGET’s birthday — $10M bounty on his head. Filmed by TARGET himself. Original erased — we kept a copy."
- Mysterious hackers who targeted Marks and Spencer's computer systems hint at political allegiance as they warn other tech criminals not to attack former Soviet states
- The organizational structure of ransomware groups is evolving rapidly.
- SAP NetWeaver exploitation enters second wave of threat activity
- China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures
- DOGE software engineer’s computer infected by info-stealing malware
- Hackers hijack Japanese financial accounts to conduct nearly $2 billion in trades
- FBI and Dutch police seize and shut down botnet of hacked routers
- Poland arrests four in global DDoS-for-hire takedown
- School districts hit with extortion attempts after PowerSchool breach
- EU launches vulnerability database to tackle cybersecurity threats
- Training Solo - vusec
- Branch Privilege Injection: Exploiting Branch Predictor Race Conditions – Computer Security Group
- Remote Exploitation of Nissan Leaf: Controlling Critical Body Elements from the Internet
- PSIRT | FortiGuard Labs
- EPMM Security Update | Ivanti
dts.podtrac.com -
Risky Business #782 -- Are the USA and Russia cyber friends now?
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Did the US decide to stop caring about Russian cyber, or not?
- Adam stans hard for North Korea’s massive ByBit crypto-theft
- Cellebrite firing Serbia is an example of the system working
- Starlink keeps scam compounds in Myanmar running
- Biggest DDoS botnet yet pushes over 6Tbps
This week’s episode is sponsored by network visibility company Corelight. Vincent Stoffer, field CTO at Corelight joins to talk through where eyes on your network can spot attackers like Salt and Volt Typhoon.
This episode is also available on Youtube.
Show notes
- Sygnia Preliminary Bybit Investigation Report
- Verichains Bybit Incident Investigation Preliminary Report
- North Koreans finish initial laundering stage after more than $1 billion stolen from Bybit | The Record from Recorded Future News
- Risky Bulletin: Trump administration stops treating Russian hackers as a threat - Risky Business
- Did Trump Admin Order U.S. Cyber Command and CISA to Stand Down on Russia? (Story updated)
- Russia to redeploy resources freed up by end of war in Ukraine, warns Finnish intelligence | The Record from Recorded Future News
- FBI urges crypto community to avoid laundering funds from Bybit hack | The Record from Recorded Future News
- Risky Bulletin: Cellebrite bans bad boy Serbia - Risky Business
- Belgium probes suspected Chinese hack of state security service | The Record from Recorded Future News
- Gabbard: UK demand to Apple for backdoor access is 'grave concern' to US | The Record from Recorded Future News
- Elon Musk’s Starlink Is Keeping Modern Slavery Compounds Online | WIRED
- U.S. Soldier Charged in AT&T Hack Searched “Can Hacking Be Treason” – Krebs on Security
- Google Password Manager finally syncs to iOS—here’s how - Ars Technica
- Gmail Security Alert: Google To Ditch SMS Codes For Billions Of Users
- Massive Iran-linked botnet launches DDoS attacks against telecom, gaming platforms | Cybersecurity Dive
- Microsoft-signed driver used in ransomware attacks | Cybersecurity Dive
- London member of ‘Com’ network convicted of making indecent images of children | The Record from Recorded Future News
- Volt Typhoon & Salt Typhoon Attackers Are Evading EDR: What Can You Do? | Corelight
dts.podtrac.com -
Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- White House’s off-brand Israeli Signal fork logs cleartext messages with hard coded creds while getting hacked (twice). Just … Wow.
- Ransomware attacks on UK retailers are linked, and Marks & Spencer has it extra bad
- After six years dormant, a Magento eCommerce platform backdoor comes to life
- The North Korean IT worker scam is truly webscale
- NSO group owes Meta $168m for hacking WhatsApp
This week’s episode is sponsored by vulnerability management wranglers, Nucleus Security. Aaron Unterberger joins to talk through the complexities of tracking vulnerabilities in cloud components - left to the source, right to the deployments, and …sideways into the sidecars?
This week’s show also features an excerpt from Pat’s interview with Senator Mark Warner - Scoot back one in your podcast feed to check out the full chat, or find it on Youtube.
This episode is available on Youtube too.
Show notes
- Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages
- Despite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logs
- The Signal Clone the Trump Admin Uses Was Hacked
- App used by Mike Waltz suspends services after hacking claims
- Senator Demands Investigation into Trump Admin Signal Clone After 404 Media Investigation
- MG on X: "Looks like TeleMessage was probably procured and rolled out under Biden. There are public records for it. https://t.co/XCuZpi8PL3" / X
- Harrods becomes latest retailer to announce attempted cyberattack | The Record from Recorded Future News
- Co-op DragonForce cyber attack includes customer data, firm admits
- Co-op cyber attack: Staff told to keep cameras on in meetings
- Hundreds of e-commerce sites hacked in supply-chain attack - Ars Technica
- Microsoft’s new “passwordless by default” is great but comes at a cost - Ars Technica
- Windows RDP lets you log in using revoked passwords. Microsoft is OK with that. - Ars Technica
- North Korean operatives have infiltrated hundreds of Fortune 500 companies | CyberScoop
- US wants to cut off key player in Southeast Asian cybercrime industry | The Record from Recorded Future News
- Myanmar militia leader sanctioned by US over cyber scam connections | The Record from Recorded Future News
- Trump proposes major cut to CISA’s budget, citing false ‘censorship’ claims | Cybersecurity Dive
- NSA to cut up to 2,000 civilian roles as part of intel community downsizing | The Record from Recorded Future News
- NSO Group owes $168M in damages to WhatsApp over spyware infections, jury says | CyberScoop
dts.podtrac.com -
Snake Oilers: Pangea, Cosive and Sysdig
In this edition of Snake Oilers three vendors pitch host Patrick Gray on their tech:
- Pangea: Guardrails and security for AI agents and applications (https://pangea.cloud)
Worried about your AI apps going rogue, being mean to your customers or even disclosing sensitive information? Pangea exists to address these risks. Fascinating stuff.
- Cosive: A threat intelligence company that can host your MISP server in AWS. CloudMISP! (https://www.cosive.com/snakeoilers)
Are you running a MISP server on some old hardware under a desk in your SOC? There’s a better way! Cosive can run it for you on AWS so you can just use it instead of wrestling with maintaining it. They also do some CTI consulting to help you get better use out of MISP.
- Sysdig: A Linux runtime security platform (https://sysdig.com/)
The modern Windows network is an all-singing, all-dancing, perfectly orchestrated, EDR-protected ballet. The modern Linux production environment… isn’t. Find out how Sysdig can help you get some visibility and control over your Linux fleet.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Soap Box: Why AI can't fix bad security products
In this Soap Box edition of the show Patrick Gray chats with the CEO of email security company Sublime Security, Josh Kamdjou. They talk about where AI is useful, where it isn’t, and why AI can’t save vendors from their bad product design choices.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #831 -- The AI bugpocalypse begins
On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
- Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package
- TeamPCP appear to have ransacked Cisco’s source and cloud environments
- AI is getting legitimately good at being told to “just go find some 0day in this”
- Kaspersky says Coruna and Triangulation do share code lineage
- Iranian hackers dump Kash Patel’s gmail spool
- Oh, and of course there’s a Citrix Netscaler memory leak being exploited in the wild
This week’s episode is sponsored by Dropzone AI, who make automated AI SOC analysts. Head honcho Ed Wu explains how they’ve built pre-canned ‘hunt packs’ to lead the AI off into your environment to find weird, interesting and security relevant things.
This episode is also available on Youtube.
Show notes
- Google links axios supply chain attack to North Korean group | The Record from Recorded Future News
- Cisco source code stolen in Trivy-linked dev environment breach
- chiefofautism on X: "someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo"
- h0mbre on X: "Claude is somehow better at kernel exploitation than creating meal plans."
- Vulnerability Research Is Cooked — Quarrelsome
- MAD Bugs: vim vs emacs vs Claude - Calif
- MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
- A Risky Biz Experiment: Hunting for iOS 0day with AI - Risky Business Media
- Security leaders say the next two years are going to be 'insane' | CyberScoop
- Coruna framework: an exploit kit and ties to Operation Triangulation | Securelist
- Apple says no one using Lockdown Mode has been hacked with spyware | TechCrunch
- Reverse engineering Apple’s silent security fixes - Calif
- Jury finds Meta's platforms are harmful to children in 1st wave of social media addiction lawsuits | PBS News
- Meta and YouTube found liable in social media addiction trial
- Iranian hackers publish emails allegedly stolen from Kash Patel
- Iran Us War: 'Legitimate targets': Iran issues warning to US tech firms including Google, Amazon, Microsoft, Nvidia - The Times of India
- Drop Site on X: "IRGC: From now on, for every assassination, an American company will be destroyed"
- OSINTtechnical on X: "Starlink shutdowns are forcing Russian troops even deeper into Ubiquiti’s ecosystem. "
- Citrix NetScaler products confirmed to be under exploitation | Cybersecurity Dive
- CISA tells federal agencies to patch Citrix NetScaler bug by Thursday | The Record from Recorded Future News
- Using a VPN May Subject You to NSA Spying | WIRED
- Post reporters called the White House. Their phones showed ‘Epstein Island.’ - The Washington Post
dts.podtrac.com -
Risky Biz Soap Box: runZero shakes up vulnerability management
In this sponsored Soap Box edition of the Risky Business podcast, industry legend HD Moore joins the show to talk about runZero’s major push into vulnerability management.
With its new Nuclei integration, runZero is now able to get a very accurate picture of what’s vulnerable in your environment, without spraying highly privileged credentials at attackers on your network.
It can also integrate with your EDR platform, and other data sources, to give you powerful visibility into the true state of things on your network and in your cloud.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #796 -- With special guest co-host Chris Krebs
On this week’s show Patrick Gray and Adam Boileau are joined by special guest Chris Krebs to discuss the week’s cybersecurity news. They talk through:
- Israeli “hacktivists” take out an Iranian state-owned bank
- Scattered-spider and friends pivot into attacking insurers
- Securing identities in a cloud-first world keeps us awake at night
- Microsoft takes the “aas” out of SaaS for Europe, leaving us with just software!
- An AI prompt injection into M365 exfils corporate data
This week’s episode is sponsored by Kroll’s Cyber practice. Kroll Cyber Associate Managing Director George Glass is based in London and talks through his experiences helping organisations in the UK deal with the Scattered Spider attacks.
This episode is also available on Youtube.
Show notes
- Iran’s Bank Sepah disrupted by cyberattack claimed by pro-Israel hacktivist group | CyberScoop
- Iran orders officials to ditch connected devices
- Heightened Cyberthreat Amidst Israel-Iran Conflict
- Threat group linked to UK, US retail attacks now targeting insurance industry | Cybersecurity Dive
- Coming to Apple OSes: A seamless, secure way to import and export passkeys - Ars Technica
- Cyberattack on Washington Post Compromises Email Accounts of Journalists
- Hackers impersonating US government compromise email account of prominent Russia researcher | The Record from Recorded Future News
- A good one to talk to Chris about:
- Breaking down ‘EchoLeak’, the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
- CISA warns of supply chain risks as ransomware attacks exploit SimpleHelp flaws | Cybersecurity Dive
- Whole Foods supplier making progress on restoration after cyberattack left shelves empty | The Record from Recorded Future News
- Ransomware attack on ticketing platform upends South Korean entertainment industry | The Record from Recorded Future News
- Advisory: Cybersecurity incident
dts.podtrac.com -
Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Cyber firms agree to deconflict and cross-reference hacker group names
- Russian nuclear facility blueprints gathered from public procurement websites
- Someone audio deepfaked the White House Chief of Staff, but for the dumbest reasons
- Germany identifies the Trickbot kingpin
- Google spots China’s MSS using Calendar events for malware C2
- Meta apps abuse localhost listeners to track web sessions.
This week’s episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss an open letter penned by JP Morgan Chase’s CISO that pleads with Software as a Service suppliers to try to suck less at security.
This episode is also available on Youtube.
Show notes
- 'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames | Reuters
- Ukraine's Massive Drone Attack Was Powered by Open Source Software
- Massive security breach: Russian nuclear facilities exposed online
- How a Spyware App Compromised Assad’s Army - New Lines Magazine
- Exclusive | Federal Authorities Probe Effort to Impersonate White House Chief of Staff Susie Wiles - WSJ
- Malaysian home minister’s WhatsApp hacked, used to scam contacts | The Record from Recorded Future News
- U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on Security
- Top counter antivirus service disrupted in global takedown | CyberScoop
- Cops in Germany Claim They’ve ID’d the Mysterious Trickbot Ransomware Kingpin | WIRED
- Australian ransomware victims now must tell the government if they pay up | The Record from Recorded Future News
- Google: China-backed hackers hiding malware in calendar events | Cybersecurity Dive
- Coinbase breach linked to customer data leak in India, sources say | Reuters
- US military IT specialist arrested for allegedly trying to leak secrets to foreign government | The Record from Recorded Future News
- NSO appeals WhatsApp decision, says it can’t pay $168 million in ‘unlawful’ damages | The Record from Recorded Future News
- ConnectWise says nation-state attack targeted multiple ScreenConnect customers | The Record from Recorded Future News
- Google Online Security Blog: Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store
- Meta and Yandex are de-anonymizing Android users’ web browsing identifiers - Ars Technica
- An Open Letter to Third-Party Suppliers
dts.podtrac.com -
Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Oracle’s long term CSO departs, and we’re not that sad about it
- Canada’s House of Commons gets popped through a Microsoft bug
- Russia degrades voice calls via Whatsapp and Telegram to push people towards Max
- South-East Asian scam compounds are also behind child sextortion
- Reports that the UK has backed down on Apple crypto are… strange
- Oh and of course there’s a Fortinet bug! There’s always a Fortinet bug!
This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins the show this week, and explains the journey of implementing SSO backed login on Windows, Mac and Linux. You’ll never guess which one was a few lines of PAM config, and which was a multi-month engineering project!
This episode is also available on Youtube.
Show notes
- Is Oracle facing headwinds? After layoffs, its 4-decade veteran Chief Security Officer Mary Ann Davidson departs
- Oracle CSO blasted over anti-security research rant - iTnews
- New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts | The Record from Recorded Future News
- Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme – Krebs on Security
- How we found TeaOnHer spilling users' driver's licenses in less than 10 minutes | TechCrunch
- UK has backed down on demand to access US Apple user data, spy chief says
- DNI Tulsi Gabbard on X: "As a result, the UK has agreed to drop its mandate for"
- Hackers target Workday in social engineering attack
- Russia curbs WhatsApp, Telegram calls to counter cybercrime | The Record from Recorded Future News
- Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability | The Record from Recorded Future News
- Norway police believe pro-Russian hackers were behind April dam sabotage | The Record from Recorded Future News
- US agencies, international allies issue guidance on OT asset inventorying | Cybersecurity Dive
- FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970)
- U.S. State Dept - Near Eastern Affairs on X: "He did not claim diplomatic immunity and was released by a state judge"
- 493 Cases of Sextortion Against Children Linked to Notorious Scam Compounds | WIRED
- .:: Phrack Magazine ::.
- Accenture to buy Australian cyber security firm CyberCX - iTnews
dts.podtrac.com -
Wide World of Cyber: Microsoft's China Entanglement
The Wide World of Cyber podcast is back! In this episode host Patrick Gray chats with Alex Stamos and Chris Krebs about Microsoft’s entanglement in China.
Redmond has been using Chinese engineers to do everything from remotely support US DoD private cloud systems to maintain the on premise version of the SharePoint code base. It’s all blown up in the press over the last month, but how did we get here? Did Microsoft make these decisions to save money? Or was it more about getting access to the Chinese market? And how can we all make the world’s most important software company stop doing things like this? Tune in to the Wide World of Cyber podcast to find out!
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Microsoft reshuffles security leadership. It doesn’t spark joy.
- Russia is hacking the Winter Olympics. Again. But y tho?
- China-linked groups are keeping busy, hacking telcos in Norway, Singapore and dozens of others
- Campaigns underway targeting Ivanti, BeyondTrust and SolarWinds products
- An unknown hero blocks 23/tcp on the US internet backbone
- And James Wilson pops into talk about Claude’s go at a C compiler
This week’s episode is sponsored by Ent.AI, an AI startup that isn’t quite ready to tell us all what they’re doing. But nevertheless, founder Brandon Dixon joins to discuss AI’s role in security. Where does language-based understanding take us that previous methods couldn’t?
This episode is also available on Youtube.
Show notes
- Updates in two of our core priorities - The Official Microsoft Blog
- Strengthening Windows trust and security through User Transparency and Consent | Windows Experience Blog
- Microsoft prepares to refresh Secure Boot’s digital certificate | Cybersecurity Dive
- Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilities | CyberScoop
- Microsoft releases urgent Office patch. Russian-state hackers pounce. - Ars Technica
- Italy blames Russia-linked hackers for cyberattacks ahead of Winter Olympics | The Record from Recorded Future News
- Researchers uncover vast cyberespionage operation targeting dozens of governments worldwide | The Record from Recorded Future News
- Germany warns of state-linked phishing campaign targeting journalists, government officials | The Record from Recorded Future News
- Norwegian intelligence discloses country hit by Salt Typhoon campaign | The Record from Recorded Future News
- Singapore says China-linked hackers targeted telecom providers in major spying campaign | The Record from Recorded Future News
- Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector | Cyber Security Agency of Singapore
- How Intel and Google Collaborate to Strengthen Intel® TDX
- Strengthening the Foundation: A Joint Security Review of Intel TDX 1.5 - Google Bug Hunters
- Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399) | Huntress
- EU, Dutch government announce hacks following Ivanti zero-days | The Record from Recorded Future News
- North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam | The Record from Recorded Future News
- BeyondTrust warns of critical RCE flaw in remote support software
- Rapid7 Analysis of CVE-2026-1731
- Building a C compiler with a team of parallel Claudes \ Anthropic
- (1) Post by @ryiron.bsky.social — Bluesky
- What AI Security Research Looks Like When It Works | AISLE
- South Korean crypto exchange races to recover $40bn of bitcoin sent to customers by mistake | South Korea | The Guardian
- White House to meet with GOP lawmakers on FISA Section 702 renewal | The Record from Recorded Future News
dts.podtrac.com -
Risky Business #810 -- Data extortion attacks have a silver lining
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- FBI intervenes in Scattered Spider Salesforce leaksite
- Clop loots Oracle E-Biz deployments
- Plus so much more data extortion.. At least it’s not ransomware … we guess?
- The US still can’t decide who’s gonna be in charge of NSA & Cybercom
- Cambodian scam compounds get sanctioned and $15b in crypto is seized
- NSO gets sold for pocket-lint-grade money
- Bugs! Redis CVSS 10, Ivanti, Crowdstrike and… Internet Explorer?! zeroday?! In the wild?!!!?
This week’s episode is sponsored by Stairwell. Founder Mike Wiacek talks about how Stairwell brings VirusTotal-like visibility to private files, and about integrating the insights that brings into your SOC workflow.
This episode is also available on Youtube.
Show notes
- FBI takedown banner appears on BreachForums site as Scattered Spider promotes leak | The Record from Recorded Future News
- Dozens of Oracle customers impacted by Clop data theft for extortion campaign | CyberScoop
- Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882)
- Clop is a Big Fish, But Not Worth Hunting - Risky Business Media
- ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security
- The company Discord blamed for its recent breach says it wasn't hacked
- Qantas confirms cybercriminals released stolen customer data | The Record from Recorded Future News
- Red Hat confirms breach of GitLab instance, which stored company’s consulting data | CyberScoop
- Risky Bulletin: Microsoft revamps Edge's "IE Mode" after zero-day attacks - Risky Business Media
- Teenagers arrested in England over cyberattack on nursery chain Kido | The Record from Recorded Future News
- Acting US Cyber Command, NSA chief won’t be nominated for the job, sources say | The Record from Recorded Future News
- Layoffs, reassignments further deplete CISA | Cybersecurity Dive
- Trump’s scandalous directive to AG Pam Bondi reached the public by accident
- Feds sanction Cambodian conglomerate over cyber scams, seize $15 billion from chairman | The Record from Recorded Future News
- US Congress committee investigating Musk-owned Starlink over Myanmar scam centres | Myanmar | The Guardian
- Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data | WIRED
- Netherlands invokes special powers against Chinese-owned semiconductor company Nexperia | The Record from Recorded Future News
- Spyware maker NSO Group confirms acquisition by US investors | TechCrunch
- Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits | WIRED
- Wiz Finds Critical Redis RCE Vulnerability: CVE‑2025‑49844 | Wiz Blog
- SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal | CyberScoop
- SonicWall SSLVPN devices compromised using valid credentials | Cybersecurity Dive
- Issues Affecting CrowdStrike Falcon Sensor for Windows
- ZDI Drops 13 Unpatched Ivanti Endpoint Manager Vulnerabilities - SecurityWeek
- Jaguar Land Rover launches phased restart at factories after cyber-attack | Jaguar Land Rover | The Guardian
- Windows 10 support ends today — here's who's affected and what you need to do
dts.podtrac.com -
Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Did the SharePoint bug leak out of the Microsoft MAPP program?
- Expel retracts its FIDO bypass writeup
- The mess surrounding the women-only dating-safety app Tea gets worse
- Broadcom customers struggle to get patches for VMWare hypervisor escapes
- Aeroflot gets hacked by the Cyber Partisans, disrupting flights
This week’s episode is sponsored by Push Security. Daniel Cuthbert joins and explains how having telemetry about identity from inside the browser is a key pillar for investigating intrusions in the browser-centric future.
This episode is also available on Youtube.
Show notes
- Microsoft Probing Whether Cyber Alert Tipped Off Chinese Hackers
- Microsoft says Warlock ransomware deployed in SharePoint attacks as governments scramble | The Record from Recorded Future News
- What we know about the Microsoft SharePoint attacks | Cybersecurity Dive
- An important update (and apology) on our PoisonSeed blog
- Tea User Files Class Action After Women’s Safety App Exposes Data
- A Second Tea Breach Reveals Users’ DMs About Abortions and Cheating
- Top Lawyer for National Security Agency Is Fired
- From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944
- VMware prevents some perpetual license holders from downloading patches
- Pro-Ukrainian hackers take credit for attack that snarls Russian flight travel - Ars Technica
- КИБЕРУДАР ПО АЭРОФЛОТУ РФ!v
- Treasury sanctions North Koreans involved in IT-worker schemes | Cybersecurity Dive
- Minnesota governor activates National Guard amid St. Paul cyberattack | StateScoop
- Outage was result of cyberattack, Post Luxembourg says
- Clorox files $380 million suit blaming Cognizant for 2023 cyberattack | Cybersecurity Dive
- Cisco network access security platform vulnerabilities under active exploitation | CyberScoop
- Arizona woman sentenced to 8.5 years for running North Korean laptop farm | The Record from Recorded Future News
- Cybercrime forum Leak Zone publicly exposed its users' IP addresses | TechCrunch
dts.podtrac.com -
Risky Business #799 -- Everyone's Sharepoint gets shelled
Risky Biz returns after two weeks off, and there sure is cybersecurity news to catch up on. Patrick Gray and Adam Boileau discuss:
- Microsoft tried to make outsourcing the Pentagon’s cloud maintenance to China okay (it was not)
- She shells Sharepoint by the sea-shore (by ‘she’ we mean ‘China’)
- Four (alleged) Scattered Spider members arrested (and bailed) in the UK
- Hackers spend $2700 to buy creds for a Brazilian payment system, steal $100M
- Fortinet has SQLI in the auth header, Citrix mem leak is weaponised, HP hardcodes creds and Sonicwalls get user-moderootkits. Just security vendor things!
This week’s episode is sponsored by Airlock Digital. CEO David Cottingham talks through what it takes to build a mature, resilient management platform for a security critical system.
This episode is also available on Youtube.
Show notes
- Update on DOD’s cloud services
- Microsoft to stop using engineers in China for tech support of US military, Hegseth orders review
- A Little-Known Microsoft Program Could Expose the Defense Department to Chinese Hackers
- While DOD policy bans unauthorized apps like TikTok from being on employees phones over national security risks
- Microsoft Fix Targets Attacks on SharePoint Zero-Day – Krebs on Security
- National Guard was hacked by China's 'Salt Typhoon' group, DHS says
- Suspected contractor for China’s Hafnium group arrested in in Italy | Cybersecurity Dive
- Singapore accuses Chinese state-backed hackers of attacking critical infrastructure networks | The Record from Recorded Future News
- UK Arrests Four in ‘Scattered Spider’ Ransom Group – Krebs on Security
- Four people bailed after arrests over cyber attacks on M&S, Co-op and Harrods
- Brazilian police arrest IT worker over $100 million cyber theft | The Record from Recorded Future News
- At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds | WIRED
- Hacker returns cryptocurrency stolen from GMX exchange after $5 million bounty payment | The Record
- Indian crypto exchange CoinDCX says $44 million stolen from reserves | The Record
- Chainalysis: $2.17 billion in crypto stolen in first half of 2025, driven by North Korean hacks | The Record
- PoisonSeed bypassing FIDO keys to ‘fetch’ user accounts
- Risky Bulletin: Browser extensions hijacked for web scraping botnet
- A Startup is Selling Data Hacked from Peoples’ Computers to Debt Collectors
- A surveillance vendor was caught exploiting a new SS7 attack to track people's phone locations | TechCrunch
- Ukrainian hackers wipe databases at Russia's Gazprom in major cyberattack, intelligence source says
- File transfer company CrushFTP warns of zero-day exploit seen in the wild | The Record
- HPE warns of hardcoded passwords in Aruba access points
- Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)
- Researchers, CISA confirm active exploitation of critical Citrix Netscaler flaw | Cybersecurity Dive
- Google finds custom backdoor being installed on SonicWall network devices - Ars Technica
- Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years
dts.podtrac.com -
Risky Business #818 -- React2Shell is a fun one
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- There’s a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?
- China is out popping shells with it
- Linux adds support for PCIe bus encryption
- Amnesty International says Intellexa can just TeamViewer into its customers’ surveillance systems
- …and a Belgian murder suspect complains that GrapheneOS’s duress wipe feature failed him?
This week’s episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll’s Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board?
This episode is also available on Youtube.
Show notes
- Risky Bulletin: APTs go after the React2Shell vulnerability within hours - Risky Business Media
- Guillermo Rauch on X: "React2Shell" / X
- React2Shell-CVE-2025-55182-original-poc/README.md at main · lachlan2k/React2Shell-CVE-2025-55182-original-poc · GitHub
- Hydrogen: Shopify’s headless commerce framework
- Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSS | The Record from Recorded Future News
- Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
- Three hacking groups, two vulnerabilities and all eyes on China | The Record from Recorded Future News
- Risky Bulletin: Linux adds PCIe encryption to help secure cloud servers
- Sean Plankey nomination to lead CISA appears to be over after Thursday vote | CyberScoop
- 🕳 on X: "This guy is complaining that GrapheneOS “failed him”. Showing a Belgian 🇧🇪 police request for an interrogation regarding premeditated murder (as a suspect)." / X
- Sanctioned spyware maker Intellexa had direct access to government espionage victims, researchers say | TechCrunch
- To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
- Is ransomware finally on the decline? Treasury data offers cautious hope | CyberScoop
- UK cyber agency warns LLMs will always be vulnerable to prompt injection | CyberScoop
- In comedy of errors, men accused of wiping gov databases turned to an AI tool - Ars Technica
dts.podtrac.com -
Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
- Australian airline Qantas looks like it got a Scattered Spider-ing
- Microsoft works towards blunting the next CrowdStrike disaster
- Changes are coming for Microsoft’s default enterprise app consenting setup
- Synology downplays hardcoded passwords for its M365 cloud backup agent
- The next Citrix Netscaler memory disclosure looks nasty
- Drug cartels used technical surveillance to find, fix and finish FBI informants and witnesses
This week’s episode is sponsored by RAD Security. Co-founder Jimmy Mesta joins to talk through how they use AI automation to assess the security posture of sprawling cloud environments.
This episode is also available on Youtube.
Show notes
- Qantas hit by cyber attack, leaving 6 million customer records at risk of data breach
- Scattered Spider appears to pivot toward aviation sector | Cybersecurity Dive
- Microsoft to make Windows more resilient following 2024 IT outage | Cybersecurity Dive
- (384) The Ultimate Guide to App Consent in Microsoft Entra - YouTube
- When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365" / modzero
- AT&T deploys new account lock feature to counter SIM swapping | CyberScoop
- Iran-linked hackers threaten to release Trump aides' emails | Reuters
- US government warns of new Iran-linked cyber threats on critical infrastructure | Cybersecurity Dive
- Actively exploited vulnerability gives extraordinary control over server fleets - Ars Technica
- Critical vulnerability in Citrix Netscaler raises specter of exploitation wave | Cybersecurity Dive
- Identities of More Than 80 Americans Stolen for North Korean IT Worker Scams | WIRED
- Cloudflare confirms Russia restricting access to services amid free internet crackdown | The Record from Recorded Future News
- Mexican drug cartel used hacker to track FBI official, then killed potential FBI informants, government audit says | CNN Politics
- Audit of the FBI's Efforts to Mitigate the Effects of Ubiquitous Technical Surveillance - Redacted Report
- NATO members aim for spending 5% of GDP on defense, with 1.5% eligible for cyber | The Record from Recorded Future News
- US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations | CyberScoop
- US, French authorities confirm arrest of BreachForums hackers | TechCrunch
- Spanish police arrest five over $542 million crypto investment scheme | The Record from Recorded Future News
- Scam compounds labeled a 'living nightmare' as Cambodian government accused of turning a blind eye | The Record from Recorded Future News
dts.podtrac.com -
Risky Biz Soap Box: Prowler, the open cloud security platform
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, founder of open source multi-cloud security product Prowler.
Toni explains how Prowler came to be, and how its journey followed his own learning about the cloud. The pair also discuss Prowler’s successful transition from an open-source project into a community, and now a growing business with an as-a-service platform.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs
In this extended interview the Vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner, joins Risky Business host Patrick Gray to talk about:
- The latest developments in the Signalgate scandal
- Why America needs to be more aggressive in responding to Volt Typhoon
- How tariffs are affecting American alliances
- Why the Five Eyes alliance is sacrosanct
This episode is available on Youtube
Show notes
dts.podtrac.com -
Risky Business #809 -- Hackers try to pay a journalist for access to the BBC
On this week’s show Patrick Gray is on holiday so Amberleigh Jack and Adam Boileau hijack the studio to discuss the week’s cybersecurity news, including:
- Hackers learn that trying to coerce a journalist just makes for … a great story?
- A man in his 40s gets arrested over the European airport chaos. Yep, we’re surprised, too.
- Adam fanboys over Watchtowr Labs while bemoaning Fortra.
- Academics pick apart Tile trackers and find them lacking
- CISA tells agencies to patch their damn Cisco gear
This episode is also available on YouTube.
Show notes
- 'You'll never need to work again': Criminals offer reporter money to hack BBC
- Government to guarantee £1.5bn Jaguar Land Rover loan after cyber shutdown
- Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms – Krebs on Security
- UK authorities arrest man in connection with cyberattack against aviation vendor | Cybersecurity Dive
- Chinese scammer pleads guilty after UK seizes nearly $7 billion in bitcoin
- Cyberattack on Japanese beer giant Asahi limits shipping, call center operations | The Record from Recorded Future News
- Afghanistan plunged into nationwide internet blackout, disrupting air travel, medical care | The Record from Recorded Future News
- Tile trackers are a stalker's dream, say Georgia Tech researchers
- Intel and AMD trusted enclaves, the backbone of network security, fall to physical attacks - Ars Technica
- Supermicro server motherboards can be infected with unremovable malware - Ars Technica
- China-linked hackers use ‘BRICKSTORM’ backdoor to steal IP | The Record from Recorded Future News
- Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
- Federal agencies given one day to patch exploited Cisco firewall bugs | The Record from Recorded Future News
- Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
- Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035)
- It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2
dts.podtrac.com -
Risky Biz Soap Box: Push Security's browser-first twist on identity security
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.
Push has built an identity security platform that collects identity information and events from your users’ browsers. It can detect phish kits and shut down phishing attempts, protect SSO credentials, and find shadow/personal account that a user has spun up.
It’s extremely difficult to bypass. That’s because when you’re in the browser it doesn’t matter how a phishing link arrives, or how a threat actor has concealed it from your detection stack – if the user sees it, Push sees it.
There are solutions for protecting your users SSO credentials, like passkeys. But what about all the SaaS in your environment? Even if it’s enrolled into your SSO, are you sure that’s how your users are authenticating to it? What about the automation platforms your developers and admins use? What about data platforms like Snowflake? Are your using setting up passkeys for those accounts? How would you know, and what problems can it cause if those accounts are vulnerable?
This is a fun one!
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #825 -- Palo Alto Networks blames it on the boogie
On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:
- Palo Alto threat researchers want to attribute to China, but management says shush
- An increasing proportion of ransomware is data extortion. Is this good?
- Cambodia says it’s going to dismantle scam compounds
- CISA sufferers through yet another shutdown
- Google Gemini’s training secrets are being systematically harvested to improve other LLMs
- Academics assess SaaS password managers’ resilience against a malicious server
This episode is sponsored by SSO-firewall integration vendor Knocknoc. Chief exec Adam Pointon joins to talk about the latest in defences… which is to say Knocknoc for Solaris/Sparc and HPUX on PA-RISC?! Okay also that other little known OS… Windows.
This episode is also available on Youtube.
Show notes
- Data-only extortion grows as ransomware gangs seek better profits | Cybersecurity Dive
- Arctic Wolf Threat Report 2026
- Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say
- Risky Bulletin: Cambodia promises to dismantle scam networks by April - Risky Business Media
- Age of the ‘scam state’: how an illicit, multibillion-dollar industry has taken root in south-east Asia | Cybercrime | The Guardian
- Critical flaw in BeyondTrust Remote Support sees early signs of exploitation | Cybersecurity Dive
- CISA Navigates DHS Shutdown With Reduced Staff - SecurityWeek
- Kimwolf Botnet Swamps Anonymity Network I2P – Krebs on Security
- BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign — Elastic Security Labs
- Over 500,000 VKontakte accounts hijacked through malicious Chrome extensions | The Record from Recorded Future News
- Password managers' promise that they can't see your vaults isn't always true - Ars Technica
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers
- Google finds state-sponsored hackers use AI at 'all stages' of attack cycle | CyberScoop
- Google: Gemini hit with 100,000+ prompts in cloning attempt
- Proofpoint acquires Acuvity to tackle the security risks of agentic AI | CyberScoop
- Cisco Redefines Security for the Agentic Era with AI Defense Expansion and AI-Aware SASE
- Sophos Acquires Arco Cyber to Bring CISO-Level, Agentic AI-Powered Expertise to Every Organization
- Dave Kennedy on X: "Regarding this, there was a couple questions on does the pacemaker continue to advertise - most BLE implantable devices go into a sleep type mode. In this case, we are lucky - it does not. We know based on law enforcement answers that she is using a more modern pacemaker with" / X
- Clash Report on X: "BIG: Dutch Defence Minister Gijs Tuinman hints that software independence is possible for F-35 jets. He literally said you can “jailbreak” an F-35. When asked if Europe can modify it without US approval: “That’s not the point… we’ll see whether the Americans will show https://t.co/f11cGvtYsO" / X
- Dutch police arrest man who refused to delete confidential files shared by mistake | The Record from Recorded Future News
dts.podtrac.com -
Risky Biz Soap Box: The lethal trifecta of AI risks
There’s a lethal trifecta of AI risks: access to private data, exposure to untrusted content, and external communication. In this conversation, Risky Business host Patrick Gray chats with Josh Devon, the co-founder of Sondera, about how to best address these risks.
There is no magic solution to this problem. AI models mix code and data, are non-deterministic, and are crawling around all over your enterprise data and APIs as you read this.
But in this sponsored interview, Josh outlines how we can start to wrap our hands around the problem.
This episode is also available on Youtube.
Show notes
dts.podtrac.com -
Risky Business #814 -- It's a bad time to be a scam compound operator
In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- The KK Park scam compound in Myanmar gets blasted with actual dynamite
- China sentences more scammers TO DEATH
- While Singapore is opting to lash them with the cane
- Chinese security firm KnownSec leaks a bunch of documents
- Necromancy continues on NSO Group, with a Trump associate in charge
- OWASP freshens up the Top 10, you won’t believe what’s number three!
This week’s episode is sponsored by Thinkst Canary. Big bird Haroon Meer joins and, as usual, makes a good point. If you’re going to trust a vendor to do something risky like put a box on your network, they have an obligation to explain how they make that safe. Thinkst has a /security page that does exactly that. So why do we let Palo Alto and Fortinet get away with “trust me, bro”?
This episode is also available on Youtube.
Show notes
- Myanmar Junta Dynamites Scam Hub in PR Move as Global Pressure Grows
- China sentences 5 Myanmar scam kingpins to death | The Record from Recorded Future News
- Law passed for scammers, mules to be caned after victims in Singapore lose almost $4b since 2020 | The Straits Times
- KnownSec breach: What we know so far. - NetAskari
- Risky Bulletin: Another Chinese security firm has its data leaked
- Inside Congress Live
- The Government Shutdown Is a Ticking Cybersecurity Time Bomb | WIRED
- Former Trump official named NSO Group executive chairman | The Record from Recorded Future News
- Short-term renewal of cyber information sharing law appears in bill to end shutdown | The Record from Recorded Future News
- Jaguar Land Rover hack hurt the U.K.'s GDP, Bank of England says
- Monetary Policy Report - November 2025 | Bank of England
- SonicWall says state-linked actor behind attacks against cloud backup service | Cybersecurity Dive
- Japanese media giant Nikkei reports Slack breach exposing employee and partner records | The Record from Recorded Future News
- "Intel sues former employee for allegedly stealing confidential data" Post by @campuscodi.risky.biz — Bluesky
- Introduction - OWASP Top 10:2025 RC1
dts.podtrac.com -
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- CISA warns about the path from on-prem Exchange to the cloud
- Microsoft awards a crisp zero dollar bill for a report about what a mess its internal Entra-authed apps are
- Everyone and their dog seems to have a shell in US Federal Court information systems
- Google pays $250k for a Chrome sandbox escape
- Attackers use javascript in adult SVG files to … farm facebook likes?!
- SonicWall says users aren’t getting hacked with an 0day… this time.
This week’s episode is sponsored by SpecterOps. Chief product officer Justin Kohler talks about how the flagship Bloodhound tool has evolved to map attack paths anywhere. Bring your own applications, directories and systems into the graph, and join the identity attacks together.
This episode is also available on Youtube.
Show notes
- CISA, Microsoft issue alerts on ‘high-severity’ Exchange vulnerability | The Record from Recorded Future News
- Advanced Active Directory to Entra ID lateral movement techniques
- Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications
- Cartels may be able to target witnesses after major court hack
- Federal judiciary tightens digital security as it deals with ‘escalated cyberattacks’ | The Record from Recorded Future News
- Citrix NetScaler flaws lead to critical infrastructure breaches | Cybersecurity Dive
- DARPA touts value of AI-powered vulnerability detection as it announces competition winners | Cybersecurity Dive
- Buttercup is now open-source!
- HTTP/1.1 must die: the desync endgame
- US confirms takedown of BlackSuit ransomware gang that racked up $370 million in ransoms | The Record from Recorded Future News
- North Korean cyber-espionage group ScarCruft adds ransomware in recent attack | The Record from Recorded Future News
- Adult sites are stashing exploit code inside racy .svg files - Ars Technica
- Google pays 250k for Chromium sandbox escape
- SonicWall says recent attack wave involved previously disclosed flaw, not zero-day | Cybersecurity Dive
- Two groups exploit WinRAR flaws in separate cyber-espionage campaigns | The Record from Recorded Future News
- Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge | The Record from Recorded Future News
- Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home | WIRED
- Malware in Open VSX: These Vibes Are Off
- How attackers are using Active Directory Federation Services to phish with legit office.com links
- Introducing our guide to phishing detection evasion techniques
- The State of Attack Path Management
dts.podtrac.com -
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
- Apple ruins exploit developers’ week with fresh memory corruption mitigations
- Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack
- Salesloft says its GitHub was the initial entry point for its compromise
- Sitecore says people should “patch” its using-the-keymat-from-the-documentation “zero day”
- Rogue certs for 1.1.1.1 appear to be just (stupid) testing
- Jaguar Land Rover ransomware attackers are courting trouble
This week’s episode is sponsored by open source cloud security tool, Prowler. Founder Toni de la Fuente joins to discuss their new support for Microsoft 365. Time to point Prowler at your OneDrive and Sharepoint!
This episode is also available on Youtube.
Show notes
- Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
- Venezuela's president thinks American spies can't hack Huawei phones | TechCrunch
- 18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security
- Software packages with more than 2 billion weekly downloads hit in supply-chain attack - Ars Technica
- Salesloft platform integration restored after probe reveals monthslong GitHub account compromise | Cybersecurity Dive
- CISA orders federal agencies to patch Sitecore zero-day following hacking reports | The Record from Recorded Future News
- SAP warns of high-severity vulnerabilities in multiple products - Ars Technica
- The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest. - Ars Technica
- Cyberattack on Jaguar Land Rover threatens to hit British economic growth | The Record from Recorded Future News
- Cyberattack forces Jaguar Land Rover to tell staff to stay at home | The Record from Recorded Future News
- Bridgestone Americas continues probe as it looks to restore operations | Cybersecurity Dive
- Qantas penalizes executives for July cyberattack | The Record from Recorded Future News
- Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat' | The Record from Recorded Future News
- GOP Cries Censorship Over Spam Filters That Work – Krebs on Security
- Risky Bulletin: APT report? No, just a phishing test! - Risky Business Media
- Post by @patrick.risky.biz — Bluesky
dts.podtrac.com -
Risky Business #827 -- Iranian cyber threat actors are down but not out
On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:
- The US-Israeli attack on Iran had a whole lot of cyber. It’s clearly in the playbook now!
- The NSA Triangulation / L3 Harris Trenchant iOS exploit kit is on the loose, and being used by Chinese crypto scammers
- So long Maddhu Gottumukkala, but CISA’s annus horribilis continues
- Adam “humbug” Boileau complains about the Airsnitch wifi attack just being three ethernets in a trenchcoat
- ASD’s Cisco SD-WAN threat hunting guide is clearly borne of … experience
This week’s episode is sponsored by AI threat hunting platform Nebulock. Sydney Marrone joins to talk about how useful AI models are on the hunt, and her work building out an open source framework and maturity model. It’s methodology agnostic, so you can adapt it for your environment, and the github link is in the show notes!
This episode is also available on Youtube.
Show notes
- Inside the plan to kill Ali Khamenei
- Hacked traffic cams and hijacked TVs: How cyber operations supported the war against Iran | TechCrunch
- Matthew Prince 🌥 on X: "Counter to what some cyber vendors are saying, there’s been a dramatic drop in Iranian cyber operations. Likely as the operators are sheltering. They may pick back up, but right now there’s a noticeable lull." / X
- Cyber Command disrupted Iranian comms, sensors, top general says | The Record from Recorded Future News
- Iranian Hackers Use Elon Musk’s Starlink To Stay Online
- Exclusive | U.S. Smuggled Thousands of Starlink Terminals Into Iran After Protest Crackdown - WSJ
- Attacks on GPS Spike Amid US and Israeli War on Iran | WIRED
- Amazon Data Centers on Fire After Iranian Missile Strikes on Dubai
- A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals | WIRED
- Canceled contracts, a failed polygraph and personal disputes: Inside the turbulent tenure of Noem’s former cyber czar - POLITICO
- CISA CIO Robert Costello exits agency | CyberScoop
- OpenAI alters deal with Pentagon as critics sound alarm over surveillance
- Inside Anthropic’s Killer-Robot Dispute With the Pentagon - The Atlantic
- Read the full transcript of our interview with Anthropic CEO Dario Amodei - CBS News
- CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements
- Large-Scale Online Deanonymization with LLMs
- Hackers Weaponize Claude Code in Mexican Government Cyberattack - SecurityWeek
- New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises - Ars Technica
- CISA orders agencies to patch Cisco devices now under attack | Cybersecurity Dive
- CISCO SD-WAN THREAT HUNT GUIDE
- ClawJacked attack let malicious websites hijack OpenClaw to steal data
- Area Man Accidentally Hacks 6,700 Camera-Enabled Robot Vacuums | WIRED
- Intellexa founder, three others sentenced to 8 years in prison over Greek spyware scandal | The Record from Recorded Future News
- Moscow man accused of posing as FSB officer to extort Conti ransomware gang | The Record from Recorded Future News
- Farewell, Felix · The Recurity Lablog
- Atmos Sphere 2026 | Atmos
- The Agentic Threat Hunting Framework | Nebulock blog
- GitHub - Nebulock-Inc/agentic-threat-hunting-framework: ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy. · GitHub
dts.podtrac.com