Risky Business cover image

Risky Business

Latest episodes

undefined
16 snips
Apr 17, 2025 • 48min

Snake Oilers: Pangea, Cosive and Sysdig

In this discussion, Chris Horsley, Founder of Cosive, shares insights on hosting MISP servers in the cloud, freeing cybersecurity teams from outdated hardware. Alex Lawrence, from Sysdig, unveils innovations enhancing Linux security in cloud environments. Oliver Friedrichs, CEO of Pangea, tackles pressing concerns around AI applications, discussing the importance of guardrails to prevent rogue outputs and protect sensitive data. The trio emphasizes the evolving landscape of cybersecurity, underscored by collaboration and AI integration.
undefined
35 snips
Apr 16, 2025 • 54min

Risky Business #788 -- Trump targets Chris Krebs, SentinelOne

Rob Joyce, former NSA Cybersecurity Director, discusses the fallout from Trump targeting Chris Krebs for his election security stance. The implications for the cybersecurity industry are alarming, with potential chilling effects on public safety. Fletcher Heisler, CEO of Authentik, dives into the complexities of the identity ecosystem and how innovative solutions are emerging to tackle these challenges. They also touch on recent cyber threats, including ransomware trends and the ongoing push for accountability in the spy industry.
undefined
11 snips
Apr 10, 2025 • 43min

Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape

Chris Krebs, the former founding director of CISA and current director at SentinelOne, and Alex Stamos, Chief Security Officer at SentinelOne and former CISO of Facebook, discuss the seismic shifts in U.S. cybersecurity policy under the Trump administration. They analyze significant leadership changes and their implications for national security, explore the evolving dynamics of transatlantic data privacy, and tackle the challenges for American companies amidst stricter European regulations. Additionally, they highlight the rising cybersecurity threats tied to geopolitical tensions, particularly with China.
undefined
42 snips
Apr 9, 2025 • 53min

Risky Business #787 -- Trump fires NSA director, CISA cuts inbound

Derek Hansen, Vice President of Solutions Architecture at Yubico, dives into the complexities of passkey ecosystems for enterprises. He highlights the challenges companies face in adopting consumer-driven passkey technologies while maintaining security. The conversation covers the synchronization issues in password managers and the importance of robust security frameworks to combat malware threats. Hansen emphasizes the evolution towards passwordless authentication and the pivotal role of hardware keys in enhancing cybersecurity amidst the shifting technological landscape.
undefined
13 snips
Apr 2, 2025 • 55min

Risky Business #786 -- Oracle is lying

Tjaden Hess, a Principal Security Engineer at Trail of Bits specializing in cryptography and cryptocurrency exchange security, joins the discussion on recent cybersecurity events. He highlights the alarming breach at Oracle, casting a critical eye on their lack of transparency regarding the exposure of sensitive health data. Hess also emphasizes the essential practices for secure cryptocurrency exchanges, particularly the importance of cold wallets, and contrasts these with the vulnerabilities revealed in the Bybit incident. The conversation paints a vivid picture of the cybersecurity landscape's ongoing challenges.
undefined
8 snips
Mar 26, 2025 • 31min

Soap Box: Knocknoc glues your SSO to your firewalls for Just-in-Time network access

In this engaging conversation, Adam Pointon, CEO of Knocknoc, shares his expertise in innovative network access control solutions. He discusses the importance of securing Single Sign-On services and minimizing exposure by integrating advanced tools like Identity-Aware Proxies. Adam clarifies common misconceptions about SSO vulnerabilities and highlights strategies to isolate critical applications from the internet to enhance security. With a focus on Just-in-Time Network Access Control, he outlines how to streamline access while maintaining robust protection for sensitive environments.
undefined
25 snips
Mar 26, 2025 • 59min

Risky Business #785 -- Signal-gate is actually as bad as it looks

HD Moore, founder of RunZero and a network vulnerability scanning expert, joins to discuss the recent chaos in cybersecurity. He highlights the absurdity of a security breach involving the Trump administration mistakenly including a journalist in sensitive discussions. The conversation also delves into the shortcomings of traditional vulnerability management and what he's doing to revitalize network scanning. Additionally, they explore recent cyber incidents, from GitHub supply chain attacks to Kubernetes vulnerabilities, pushing the urgency for robust security solutions.
undefined
20 snips
Mar 19, 2025 • 57min

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

Aaron Steinke, Head of Infrastructure at La Trobe Financial, shares his insights on implementing Zero Networks' micro-segmentation product, transforming a legacy tech environment. The conversation dives into a significant GitHub supply chain attack that compromised 23,000 projects, revealing sensitive information. They also discuss the complex geopolitical tensions surrounding cyber threats, especially between Taiwan and China, and the rise of malicious hacks involving North Korean groups. Steinke's experience illustrates the challenges and innovations in modernizing cybersecurity practices.
undefined
54 snips
Mar 12, 2025 • 1h 4min

Risky Business #783 -- Evil webcam ransomwares entire Windows network

Rob Joyce, former Special Assistant to the US President and cybersecurity director at the NSA, shares his insights on national security challenges. He discusses groundbreaking cyber threats, including a ransomware attack using a Linux webcam to infiltrate Windows networks. Lee Chagolla-Christensen, Principal Security Researcher at SpecterOps, dives into the vulnerabilities of NTLM authentication in Active Directory and the potential of Bloodhound to address these issues. The conversation highlights the evolving landscape of cybersecurity and the importance of robust defense mechanisms.
undefined
22 snips
Mar 5, 2025 • 50min

Risky Business #782 -- Are the USA and Russia cyber friends now?

Vincent Stouffer, Field CTO at Corelight, brings his expertise in network visibility and attacker detection to the discussion. The conversation covers North Korea's impressive cyber theft tactics, particularly the Bybit hack. They analyze the U.S.'s shifting stance on Russian cyber threats and how that impacts global security. Stouffer emphasizes the importance of monitoring network traffic to uncover hidden threats while underscoring the challenges of credential management. The dialogue also highlights innovative authentication methods evolving in the cybersecurity landscape.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner