

Risky Business
Patrick Gray
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Episodes
Mentioned books

15 snips
Jul 30, 2024 • 45min
Wide World of Cyber: Why we should show CrowdStrike no mercy
Chris Krebs, a former government cybersecurity official, and Alex Stamos, a prominent security expert, dive deep into the fallout from a recent incident involving CrowdStrike. They highlight the critical operational failures that led to widespread issues like blue screens. The discussion shifts to the evolving landscape of antivirus software and the importance of rigorous testing practices. They also scrutinize Microsoft's role and the urgent need for enhanced accountability and transparent security measures in the tech industry to rebuild trust.

17 snips
Jul 24, 2024 • 59min
Risky Business #756 -- Move fast and break everything
In this podcast, they discuss CrowdStrike's faulty update affecting millions, AT&T's breached call records, Squarespace's domain hijack, and SolarWinds' SEC case. They also cover cybercriminal incidents, Ukraine malware attack, and Disney Slack dumps. Internet Explorer vulnerabilities resurface, and email security platform Sublime Security is highlighted. The podcast delves into shadow SaaS accounts, ICS malware attacks, ransomware costs, and efficient email security management.

Jul 17, 2024 • 31min
Risky Biz Soap Box: Mike Wiacek on lazy mode threat hunting
Mike Wiacek, CEO of Stairwell, discusses file analysis for threat hunting. Stairwell provides transparency and customization for malware analysis and file relationship identification. The importance of active threat analysis, APIs in security tools, and automating threat hunting are key topics. The podcast also addresses the challenges in threat reporting and advanced malware detection.

12 snips
Jul 10, 2024 • 40min
Wide World of Cyber: State directed cybercrime
Cybersecurity experts Alex Stamos, Chris Krebs, and Patrick Gray discuss how governments like North Korea and the Kremlin are involved in ransomware attacks for financial gain and political purposes. They highlight the challenges in combatting state-directed cybercrime and the importance of multinational efforts in disrupting cybercriminal operations.

11 snips
Jul 3, 2024 • 59min
Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!
Discussion on polyfill JavaScript supply chain attack, MacOS supply chain disaster, OpenSSH remote code execution, Google distrusts Entrust CA, South Korean telco malware attack, Microsoft disappoints, TeamViewer data breach, ransomware incidents, and more cybersecurity news.

Jun 28, 2024 • 35min
Risky Biz Soap Box: Why AI shouldn't really change your security controls
Abhishek Agrawal, CEO of Material Security, discusses the importance of securing cloud email data and the limitations of MFA. They explore the impact of AI on security controls, evolving email security solutions, and the challenges of implementing retention policies. The conversation highlights the necessity for robust detection technologies and extending security measures to cover entire productivity suites like Google Workspace and Microsoft 365.

7 snips
Jun 26, 2024 • 57min
Risky Business #754 -- Assange pleads guilty to espionage, walks free
Crowdstrike co-founder Dmitri Alperovitch discusses Assange's release, US banning Kaspersky, CDK ransomware, healthcare attacks, Windows proximity bugs, and more. Topics include ransomware impact on cancer operations, UK government action against Russian hackers, and Telegram's engineering concerns. The episode also covers Windows bluetooth vulnerabilities, Mac security configurability, and the benefits of enterprise browser control for enhanced security.

Jun 19, 2024 • 1h 4min
Risky Business #753 – Congress and vuln researchers maul Microsoft
The podcast discusses Microsoft's security troubles, from the Recall feature recall to a Windows kernel wifi code-exec vulnerability. It also covers the arrest of a Scattered Spider bigwig, flawed Pentagon info-op, and the debate around E2E crypto. The show dives into various cybersecurity news, including vulnerabilities, privacy concerns, ransomware attacks, and disinformation campaigns.

31 snips
Jun 12, 2024 • 1h 4min
Risky Business #752 -- Apple announcements thrill and terrify at the same time
Former NSA boffin, Rob Joyce, joins to discuss Apple's leap into cloud computing, privacy concerns with iPhone-Mac integration, Snowflake breach, credit ratings impacted by cyber incidents, Microsoft Azure flaw fix, and more cybersecurity news. Yubico's COO shares insights on hardware authentication challenges.

12 snips
Jun 5, 2024 • 1h 4min
Risky Business #751 -- Snowflake, operation Endgame and Microsoft's looming FTC problem
Joseph Cox, 404 Media co-founder, discusses FBI's Anom sting in his new book Dark Wire. Topics include Snowflake breach, Operation Endgame against malware services, and potential FTC probe into Microsoft. Show also covers ransomware hits in Russia, cybersecurity incidents, and Phantom Secure's downfall. Terraform simplification and cloud security management practices are highlighted for efficient operations.