Przejdź do treści
PodcastyTechnologiaRisky Business

Risky Business

Risky Business Media
Risky Business
Najnowszy odcinek

179 odcinków

  • Risky Business

    Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms

    02.09.2026 | 58 min.
    On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including:

    Two alleged TeamPCP hackers got arrested in Australia

    The White House has a plan to boost security for water facilities, but we can’t see it working

    OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief

    Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots

    Much, much more…

    This week’s show is brought to you by Ent AI. Co-founder Brandon Dixon joins Pat to talk through some of the absolutely wild fraud and abuse the company’s endpoint security tool is finding when it’s deployed inside large organisations.

    This episode is also available on YouTube



    Show notes



    Two Alleged ‘TeamPCP’ Hackers Arrested in Australia | krebsonsecurity.com


    How Brian Krebs doxxed TeamPCP - Risky Business Media | Social Signals


    FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America’s water systems | Social Signals


    OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers | wired.com


    The Rise and Fall of Agent Civilizations |


    clem 🤗 (@ClementDelangue) on X | X (formerly Twitter)


    Matthew Zeitlin (@MattZeitlin) on X | X (formerly Twitter)


    100-plus companies call for ‘global surge’ in AI-powered cyber defense | CyberScoop


    China's AI-Enabled APT Operations Are Getting Interesting - Risky Business Media |


    SilkParasite: Tracking a China-Nexus APT Across Central Asia |


    DoD confirms ‘refrigeration disruption’ at military commissaries | Military Times


    Claude, Codex, and Hermes installed unowned code inside corporate networks | arstechnica.com


    Ukraine to give Britain access to battlefield data to train AI | therecord.media


    Anthropic warns infostealer malware is hijacking Claude sessions to drain usage | BleepingComputer


    White House bans foreign-made equipment for power generation over cyber backdoor concerns | therecord.media


    Large DDoS attack knocks Norwegian public services offline | The Record


    Researchers warn about chained SharePoint sequence | Cybersecurity Dive


    PaperCut warns of hackers using printer management software flaw in attacks | therecord.media


    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes | BleepingComputer


    Slovenian casinos reopen after cyberattack knocked gaming systems offline | therecord.media


    DOJ firearms agency says hackers breached system containing investigation targets | therecord.media
  • Risky Business

    Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs

    26.08.2026 | 1 godz. 2 min.
    On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:

    Iranian hackers take down a small-scale power generator in the UK

    Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.

    Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet

    Prompt injection isn’t going away

    LLMs are deceiving us meat sacks and it’s a worry

    Much, much more…

    This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.

    This episode is also available on YouTube



    Show notes



    Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com


    Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com


    Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts


    US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media


    T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com


    The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com


    CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer


    Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive


    Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer


    Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer


    Rust supply chain attack linked to North Korean hackers | securityweek.com


    Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com


    New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com


    Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer


    Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer


    Hackers infect Android car head units with proxy botnet malware | BleepingComputer


    ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer


    New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer


    Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer


    AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com


    EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com


    Detections and customer notifications | Okta Threat Intelligence
  • Risky Business

    Risky Business #849 -- Trump will unleash contractors on cybercriminals

    19.08.2026 | 59 min.
    On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:

    Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
    OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
    Anthropic’s models start a turf war when given the same task, surprising… nobody
    We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
    Much, much more

    This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.

    This episode is also available on YouTube



    Show notes



    Trump signs memo authorizing private sector to launch cyberattacks | washingtonpost.com


    Trump taps cyber firms to go on offensive against criminals | therecord.media


    OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue | wired.com


    Pacing model development in an era of cyber-critical capabilities |


    Anthropic set AI agents loose on the same task. They started a turf war. | TechCrunch Security


    Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan | cyberscoop.com


    Researchers find AI-powered hacking tools for sale in underground forums | Cybersecurity Dive


    Terabytes of credentials leaked in massive supply-chain attack | arstechnica.com


    Trivy, Not LiteLLM Behind the 2,500 Org Compromise | securityweek.com


    Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes | The Record


    ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators | TechCrunch Security


    This Coin-Sized Device Can Hack a Boeing 737 | wired.com


    "City-Forum" data-theft attacks target Salesforce, ServiceNow portals | BleepingComputer


    Max severity SAP Commerce Cloud flaw now targeted in attacks | BleepingComputer


    Shell investigates 'potential incident' after Clop data theft claims | BleepingComputer


    Philips and GE investigating Clop ransomware data theft claims | BleepingComputer


    Uber Freight reportedly investigating after hacking group claims data breach | TechCrunch Security


    Details emerge on BlackFile’s recent attacks on financial companies | cyberscoop.com


    After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch Security


    Kimwolf botnet rebuilt to survive takedowns, researchers say | cyberscoop.com


    Hundreds of fake Chrome VPN extensions route traffic through a proxy | BleepingComputer


    Deepfake hiccup unmasks suspected digital certificate fraudster | theregister.com


    Vulnerability giving attackers full control of Macs is under active exploitation | arstechnica.com


    Critical VMware vCenter RCE flaw exploited for reverse SSH access | BleepingComputer


    Poland probes MyDr healthcare software breach potentially affecting 19 million people | therecord.media


    Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts | TechCrunch Security


    [un]prompted.au — AI × Cybersecurity Conference · Sydney, 18–19 September 2026 | [un]prompted.au
  • Risky Business

    Soap Box: Zero Trust(ish) Networks

    14.08.2026 | 29 min.
    In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.

    Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.

    Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.

    Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.

    This episode is also available on YouTube



    Show notes
  • Risky Business

    Risky Business #848 -- OpenAI comes clean

    12.08.2026 | 59 min.
    On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

    The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot

    Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious

    More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed

    It turns out TeamPCP has been around longer than we thought and predates the AI era

    Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways

    Much, much more

    This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.

    This episode is also available on YouTube



    Show notes



    How a simple request for AI to book a gym class exposed a major threat | Social Signals


    OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com


    OpenAI BlackHat talk re Hugging Face incident |


    OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop


    Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media


    Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate | therecord.media


    Local governments in four states dealing with cyberattacks that have shut down services | The Record


    Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska


    Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record


    State Department says Trump raised cyber scam compound issue with Xi | therecord.media


    Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop


    A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | wired.com


    Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun - Risky Business Media |


    Chrome adopts what may be the best protection yet against account takeovers | Ars Technica


    CSS:the bomb inside your inbox | PortSwigger Research


    Security update available for Metabase - Please upgrade now | Social Signals


    Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media


    British ‘Com’ member who abused more than 100 girls worldwide jailed for two years | therecord.media


    FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | TechCrunch Security


    AI is getting better at election facts, but voters shouldn’t rely on it | CyberScoop


    The FTC wants to regulate AI for ideological bias | cyberscoop.com


    US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer


    CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer


    CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer


    N-able N-central exploitation results in RMM tool deployment | Sophos


    Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security


    mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub
Więcej Technologia podcastów
O Risky Business
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Strona internetowa podcastu

Słuchaj Risky Business, Techlove - z miłości do technologii i wielu innych podcastów z całego świata dzięki aplikacji radio.pl

Uzyskaj bezpłatną aplikację radio.pl

  • Stacje i podcasty do zakładek
  • Strumieniuj przez Wi-Fi lub Bluetooth
  • Obsługuje Carplay & Android Auto
  • Jeszcze więcej funkcjonalności
Risky Business: Podcasty w grupie