Risky Business

Patrick Gray
undefined
6 snips
Aug 14, 2024 • 1h 5min

Risky Business #759 – Why Iran's hack and leak will amount to naught

Iranian hackers have resurfaced, leaking materials from the Trump campaign, reminiscent of their 2016 tactics, but skeptics question its impact today. A notable blunder by Crowdstrike earned them the ‘Epic Fail’ award at DEF CON. The podcast also tackles serious cybersecurity issues, like a hefty fine for a healthcare SaaS provider due to poor security practices, and debates on geofence warrants and privacy concerns. Additionally, recent Black Hat insights unveil alarming vulnerabilities in AMD CPUs and cloud security, while DARPA's AI Challenge showcases innovative approaches to bug detection.
undefined
Aug 12, 2024 • 35min

Soap Box: Making security tech more people friendly

Ryan Kalember, Chief Strategy Officer at Proofpoint, dives into making security technology more user-friendly. He discusses the importance of improving how security tools interact with users, advocating for clearer communication to bridge the gap in cybersecurity. Kalember highlights the need for enhanced user risk profiling and the integration of security tools to boost incident response. He also touches on the challenges of identity management in SaaS and the rise of enterprise browsers designed to better protect users.
undefined
Aug 7, 2024 • 53min

Risky Business #758 – Crowdstrike's postmortem underwhelms

Dmitri Alperovitch, a prominent expert on geopolitical issues and technology, shares insights on the recent Russian prisoner swap and its implications. Marko Slaviero, a cybersecurity innovator, discusses the unique approach of a one-VM-per-customer hosting solution and the security benefits it brings. The conversation dives into CrowdStrike's controversial postmortem and the ongoing legal battles with Delta Airlines. They also tackle the evolving landscape of ransomware and the challenges facing security in cloud architectures.
undefined
Jul 31, 2024 • 1h 1min

Risky Business #757 – The ClownStrike cleanup continues

Dive into the chaotic aftermath of a major cybersecurity incident involving CrowdStrike and its fallout in the insurance sector. Explore Google's email validation flaws that led to unauthorized access and examine vulnerabilities in VMware systems. Delve into the complex world of Secure Boot and hardware integrity challenges. Unpack the digital threats from North Korea, focusing on ethical dilemmas surrounding ransomware payments. Finally, hear insights on innovative cybersecurity solutions and the struggles of integrating with Microsoft's APIs.
undefined
15 snips
Jul 30, 2024 • 45min

Wide World of Cyber: Why we should show CrowdStrike no mercy

Chris Krebs, a former government cybersecurity official, and Alex Stamos, a prominent security expert, dive deep into the fallout from a recent incident involving CrowdStrike. They highlight the critical operational failures that led to widespread issues like blue screens. The discussion shifts to the evolving landscape of antivirus software and the importance of rigorous testing practices. They also scrutinize Microsoft's role and the urgent need for enhanced accountability and transparent security measures in the tech industry to rebuild trust.
undefined
17 snips
Jul 24, 2024 • 59min

Risky Business #756 -- Move fast and break everything

In this podcast, they discuss CrowdStrike's faulty update affecting millions, AT&T's breached call records, Squarespace's domain hijack, and SolarWinds' SEC case. They also cover cybercriminal incidents, Ukraine malware attack, and Disney Slack dumps. Internet Explorer vulnerabilities resurface, and email security platform Sublime Security is highlighted. The podcast delves into shadow SaaS accounts, ICS malware attacks, ransomware costs, and efficient email security management.
undefined
Jul 17, 2024 • 31min

Risky Biz Soap Box: Mike Wiacek on lazy mode threat hunting

Mike Wiacek, CEO of Stairwell, discusses file analysis for threat hunting. Stairwell provides transparency and customization for malware analysis and file relationship identification. The importance of active threat analysis, APIs in security tools, and automating threat hunting are key topics. The podcast also addresses the challenges in threat reporting and advanced malware detection.
undefined
12 snips
Jul 10, 2024 • 40min

Wide World of Cyber: State directed cybercrime

Cybersecurity experts Alex Stamos, Chris Krebs, and Patrick Gray discuss how governments like North Korea and the Kremlin are involved in ransomware attacks for financial gain and political purposes. They highlight the challenges in combatting state-directed cybercrime and the importance of multinational efforts in disrupting cybercriminal operations.
undefined
11 snips
Jul 3, 2024 • 59min

Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!

Discussion on polyfill JavaScript supply chain attack, MacOS supply chain disaster, OpenSSH remote code execution, Google distrusts Entrust CA, South Korean telco malware attack, Microsoft disappoints, TeamViewer data breach, ransomware incidents, and more cybersecurity news.
undefined
Jun 28, 2024 • 35min

Risky Biz Soap Box: Why AI shouldn't really change your security controls

Abhishek Agrawal, CEO of Material Security, discusses the importance of securing cloud email data and the limitations of MFA. They explore the impact of AI on security controls, evolving email security solutions, and the challenges of implementing retention policies. The conversation highlights the necessity for robust detection technologies and extending security measures to cover entire productivity suites like Google Workspace and Microsoft 365.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app