

Risky Business
Patrick Gray
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Episodes
Mentioned books

6 snips
Aug 14, 2024 • 1h 5min
Risky Business #759 – Why Iran's hack and leak will amount to naught
Iranian hackers have resurfaced, leaking materials from the Trump campaign, reminiscent of their 2016 tactics, but skeptics question its impact today. A notable blunder by Crowdstrike earned them the ‘Epic Fail’ award at DEF CON. The podcast also tackles serious cybersecurity issues, like a hefty fine for a healthcare SaaS provider due to poor security practices, and debates on geofence warrants and privacy concerns. Additionally, recent Black Hat insights unveil alarming vulnerabilities in AMD CPUs and cloud security, while DARPA's AI Challenge showcases innovative approaches to bug detection.

Aug 12, 2024 • 35min
Soap Box: Making security tech more people friendly
Ryan Kalember, Chief Strategy Officer at Proofpoint, dives into making security technology more user-friendly. He discusses the importance of improving how security tools interact with users, advocating for clearer communication to bridge the gap in cybersecurity. Kalember highlights the need for enhanced user risk profiling and the integration of security tools to boost incident response. He also touches on the challenges of identity management in SaaS and the rise of enterprise browsers designed to better protect users.

Aug 7, 2024 • 53min
Risky Business #758 – Crowdstrike's postmortem underwhelms
Dmitri Alperovitch, a prominent expert on geopolitical issues and technology, shares insights on the recent Russian prisoner swap and its implications. Marko Slaviero, a cybersecurity innovator, discusses the unique approach of a one-VM-per-customer hosting solution and the security benefits it brings. The conversation dives into CrowdStrike's controversial postmortem and the ongoing legal battles with Delta Airlines. They also tackle the evolving landscape of ransomware and the challenges facing security in cloud architectures.

Jul 31, 2024 • 1h 1min
Risky Business #757 – The ClownStrike cleanup continues
Dive into the chaotic aftermath of a major cybersecurity incident involving CrowdStrike and its fallout in the insurance sector. Explore Google's email validation flaws that led to unauthorized access and examine vulnerabilities in VMware systems. Delve into the complex world of Secure Boot and hardware integrity challenges. Unpack the digital threats from North Korea, focusing on ethical dilemmas surrounding ransomware payments. Finally, hear insights on innovative cybersecurity solutions and the struggles of integrating with Microsoft's APIs.

15 snips
Jul 30, 2024 • 45min
Wide World of Cyber: Why we should show CrowdStrike no mercy
Chris Krebs, a former government cybersecurity official, and Alex Stamos, a prominent security expert, dive deep into the fallout from a recent incident involving CrowdStrike. They highlight the critical operational failures that led to widespread issues like blue screens. The discussion shifts to the evolving landscape of antivirus software and the importance of rigorous testing practices. They also scrutinize Microsoft's role and the urgent need for enhanced accountability and transparent security measures in the tech industry to rebuild trust.

17 snips
Jul 24, 2024 • 59min
Risky Business #756 -- Move fast and break everything
In this podcast, they discuss CrowdStrike's faulty update affecting millions, AT&T's breached call records, Squarespace's domain hijack, and SolarWinds' SEC case. They also cover cybercriminal incidents, Ukraine malware attack, and Disney Slack dumps. Internet Explorer vulnerabilities resurface, and email security platform Sublime Security is highlighted. The podcast delves into shadow SaaS accounts, ICS malware attacks, ransomware costs, and efficient email security management.

Jul 17, 2024 • 31min
Risky Biz Soap Box: Mike Wiacek on lazy mode threat hunting
Mike Wiacek, CEO of Stairwell, discusses file analysis for threat hunting. Stairwell provides transparency and customization for malware analysis and file relationship identification. The importance of active threat analysis, APIs in security tools, and automating threat hunting are key topics. The podcast also addresses the challenges in threat reporting and advanced malware detection.

12 snips
Jul 10, 2024 • 40min
Wide World of Cyber: State directed cybercrime
Cybersecurity experts Alex Stamos, Chris Krebs, and Patrick Gray discuss how governments like North Korea and the Kremlin are involved in ransomware attacks for financial gain and political purposes. They highlight the challenges in combatting state-directed cybercrime and the importance of multinational efforts in disrupting cybercriminal operations.

11 snips
Jul 3, 2024 • 59min
Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!
Discussion on polyfill JavaScript supply chain attack, MacOS supply chain disaster, OpenSSH remote code execution, Google distrusts Entrust CA, South Korean telco malware attack, Microsoft disappoints, TeamViewer data breach, ransomware incidents, and more cybersecurity news.

Jun 28, 2024 • 35min
Risky Biz Soap Box: Why AI shouldn't really change your security controls
Abhishek Agrawal, CEO of Material Security, discusses the importance of securing cloud email data and the limitations of MFA. They explore the impact of AI on security controls, evolving email security solutions, and the challenges of implementing retention policies. The conversation highlights the necessity for robust detection technologies and extending security measures to cover entire productivity suites like Google Workspace and Microsoft 365.


