Risky Business #796 -- With special guest co-host Chris Krebs
On this week’s show Patrick Gray and Adam Boileau are joined by special guest Chris Krebs to discuss the week’s cybersecurity news. They talk through:
Israeli “hacktivists” take out an Iranian state-owned bank
Scattered-spider and friends pivot into attacking insurers
Securing identities in a cloud-first world keeps us awake at night
Microsoft takes the “aas” out of SaaS for Europe, leaving us with just software!
An AI prompt injection into M365 exfils corporate data
This week’s episode is sponsored by Kroll’s Cyber practice. Kroll Cyber Associate Managing Director George Glass is based in London and talks through his experiences helping organisations in the UK deal with the Scattered Spider attacks.
This episode is also available on Youtube.
Show notes
Iran’s Bank Sepah disrupted by cyberattack claimed by pro-Israel hacktivist group | CyberScoop
Iran orders officials to ditch connected devices
Heightened Cyberthreat Amidst Israel-Iran Conflict
Threat group linked to UK, US retail attacks now targeting insurance industry | Cybersecurity Dive
Coming to Apple OSes: A seamless, secure way to import and export passkeys - Ars Technica
Cyberattack on Washington Post Compromises Email Accounts of Journalists
Hackers impersonating US government compromise email account of prominent Russia researcher | The Record from Recorded Future News
A good one to talk to Chris about:
Breaking down ‘EchoLeak’, the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
CISA warns of supply chain risks as ransomware attacks exploit SimpleHelp flaws | Cybersecurity Dive
Whole Foods supplier making progress on restoration after cyberattack left shelves empty | The Record from Recorded Future News
Ransomware attack on ticketing platform upends South Korean entertainment industry | The Record from Recorded Future News
Advisory: Cybersecurity incident
--------
1:01:04
Soap Box: AI has entered the SOC, and it ain't going anywhere
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Dropzone AI founder Ed Wu about the role of LLMs in the SOC.
The debate about whether AI agents are going to wind up in the SOC is over, they’ve already arrived. But what are they good for? What are they NOT good for? And where else will we see AI popping up in security?
This episode is also available on Youtube.
Show notes
--------
30:58
Risky Business #795 -- How The Com is hacking Salesforce tenants
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
New York Times gets a little stolen Russian FSB data as a treat
iVerify spots possible evidence of iOS exploitation against the Harris-Walz campaign
Researcher figures out a trick to get Google account holders’ full names and phone numbers
Major US food distributor gets ransomwared
The Com’s social engineering of Salesforce app authorisations is a harbinger of our future problems
Australian Navy forgets New Zealand has computers, zaps Kiwis with their giant radar.
This week’s episode is sponsored by identity provider Okta. Long-time friend of the show Alex Tilley is Okta’s Global Threat Research Coordinator, and he joins to discuss how organisations can use both human and technical signals to spot North Koreans in their midst.
This episode is also available on Youtube.
Show notes
How The Times Obtained Secret Russian Intelligence Documents - The New York Times
Ukraine's military intelligence claims cyberattack on Russian strategic bomber maker | The Record from Recorded Future News
Harris-Walz campaign may have been targeted by iPhone hackers, cybersecurity firm says
iVerify Uncovers Evidence of Zero-Click Mobile Exploitation in the U.S.
Spyware maker cuts ties with Italy after government refused audit into hack of journalist’s phone | The Record from Recorded Future News
Italian lawmakers say Italy used spyware to target phones of immigration activists, but not against journalist | TechCrunch
Android chipmaker Qualcomm fixes three zero-days exploited by hackers | TechCrunch
Cellebrite to acquire mobile testing firm Corellium in $200 million deal | CyberScoop
Apple Gave Governments Data on Thousands of Push Notifications
A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
Bruteforcing the phone number of any Google user
Acreed infostealer poised to replace Lumma after global crackdown | The Record from Recorded Future News
BidenCash darknet forum taken down by US, Dutch law enforcement | The Record from Recorded Future News
NHS calls for 1 million blood donors as UK stocks remain low following cyberattack | The Record from Recorded Future News
Major food wholesaler says cyberattack impacting distribution systems | The Record from Recorded Future News
Kettering Health confirms attack by Interlock ransomware group as health record system is restored | The Record from Recorded Future News
Hackers abuse malicious version of Salesforce tool for data theft, extortion | Cybersecurity Dive
shubs on X: "IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue: https://t.co/X3dkMz9gwK" / X
Ross Ulbricht Got a $31 Million Donation From a Dark Web Dealer, Crypto Tracers Suspect | WIRED
Australian navy ship causes radio and internet outages to parts of New Zealand
--------
1:07:34
Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Cyber firms agree to deconflict and cross-reference hacker group names
Russian nuclear facility blueprints gathered from public procurement websites
Someone audio deepfaked the White House Chief of Staff, but for the dumbest reasons
Germany identifies the Trickbot kingpin
Google spots China’s MSS using Calendar events for malware C2
Meta apps abuse localhost listeners to track web sessions.
This week’s episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss an open letter penned by JP Morgan Chase’s CISO that pleads with Software as a Service suppliers to try to suck less at security.
This episode is also available on Youtube.
Show notes
'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames | Reuters
Ukraine's Massive Drone Attack Was Powered by Open Source Software
Massive security breach: Russian nuclear facilities exposed online
How a Spyware App Compromised Assad’s Army - New Lines Magazine
Exclusive | Federal Authorities Probe Effort to Impersonate White House Chief of Staff Susie Wiles - WSJ
Malaysian home minister’s WhatsApp hacked, used to scam contacts | The Record from Recorded Future News
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on Security
Top counter antivirus service disrupted in global takedown | CyberScoop
Cops in Germany Claim They’ve ID’d the Mysterious Trickbot Ransomware Kingpin | WIRED
Australian ransomware victims now must tell the government if they pay up | The Record from Recorded Future News
Google: China-backed hackers hiding malware in calendar events | Cybersecurity Dive
Coinbase breach linked to customer data leak in India, sources say | Reuters
US military IT specialist arrested for allegedly trying to leak secrets to foreign government | The Record from Recorded Future News
NSO appeals WhatsApp decision, says it can’t pay $168 million in ‘unlawful’ damages | The Record from Recorded Future News
ConnectWise says nation-state attack targeted multiple ScreenConnect customers | The Record from Recorded Future News
Google Online Security Blog: Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store
Meta and Yandex are de-anonymizing Android users’ web browsing identifiers - Ars Technica
An Open Letter to Third-Party Suppliers
--------
58:22
Risky Business #793 -- Scattered Spider is hijacking MX records
In this week’s edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the week’s news, including:
EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes
The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed
Brian Krebs eats a 6.3Tbps DDoS … ‘cause that’s how you demo your packet cannon
Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers
Iranian behind 2019 Baltimore ransomware mysteriously appears in North Carolina and pleads guilty
CISA’s leadership is fleeing in droves, even though the US needs them more than ever.
This week’s episode is sponsored by Thinkst Canary. Long time friend of the show Haroon Meer joins and talks through where he feels the industry is at, having just returned home from the AI-fueled hype at this year’s RSA conference.
This episode is also available on Youtube.
Show notes
China-linked ‘Silk Typhoon’ hackers accessed Commvault cloud environments, person familiar says - Nextgov/FCW
Risky Bulletin: SVG use for phishing explodes in 2025 - Risky Business Media
KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS – Krebs on Security
Midwestern telco Cellcom confirms cyber incident after days of service outages | The Record from Recorded Future News
Microsoft leads international takedown of Lumma Stealer | Cybersecurity Dive
Who said what? on X: "Message from the administrator of Lumma Stealer on the forums about the recent events🕊️👀 https://t.co/MOjCSMMErK" / X
Ransomware hackers charged, infrastructure dismantled in international law enforcement operation | The Record from Recorded Future News
Oops: DanaBot Malware Devs Infected Their Own PCs – Krebs on Security
DOJ charges man allegedly behind Qakbot malware | The Record from Recorded Future News
US, Europol arrest 270 dark web drug traffickers in Operation RapTor | The Record from Recorded Future News
Iranian pleads guilty to launching Baltimore ransomware attack, faces 30 years behind bars | The Record from Recorded Future News
Decentralized crypto platform Cetus hit with $223 million hack | The Record from Recorded Future News
Nearly 70,000 impacted by Coinbase breach involving $20 million ransom demand | The Record from Recorded Future News
USA: Crypto investor charged with kidnapping, torturing man in an NYC apartment
Vietnam orders ban on Telegram messaging app over security concerns | The Record from Recorded Future News
Exclusive: Hacker who breached communications app used by Trump aide stole data from across US government | Reuters
CISA loses nearly all top officials as purge continues | Cybersecurity Dive
White House dismisses scores of National Security Council staff - The Washington Post
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.