

Risky Business
Patrick Gray
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Episodes
Mentioned books

Apr 4, 2024 • 42min
Snake Oilers: Kodex, ClearVector and Censys
Former FireEye/Mandiant SVP/CTO John Laliberte discusses innovative cybersecurity solutions from three companies: Kodex revolutionizes law enforcement data requests, ClearVector offers cloud security monitoring, and Censys scans the internet for attacker infrastructure. Topics include streamlining data requests, tracking developer activities in cloud environments, managing identities and detecting risks, diverse customer profiles, internet asset discovery, and risks of unpatched systems.

Apr 3, 2024 • 58min
Risky Business #743 -- A chat about the xz backdoor with the guy who found it
Andres Freund, the Postgres developer, talks about discovering a backdoor in the xz Linux compression library. The podcast delves into the SSH backdoor issue, Microsoft's security vulnerabilities, Ukraine hacking Russia, and push-notifications vs Apple. They also discuss the implications of the supply chain attack in Linuxland and explore the technical aspects of the backdoor issue.

Mar 26, 2024 • 1h 5min
Risky Business #742 -- China bans AMD and Intel, pivots to Linux on the desktop
Haroon Meer, founder of Thinkst Canary, joins to discuss cybersecurity attitudes, China's shift to domestic tech, and Apple's antitrust issues. Topics include the DOJ targeting Chinese APT operators, China banning western CPUs, Nigeria's Binance stoush, Rowhammer on AMD Zen, and Ukraine's drone defense. The conversation also touches on Russia's wiper attacks, North Korea's crypto heists, and the challenges of balancing company success with product quality.

Mar 21, 2024 • 34min
Risky Biz Soap Box: Why Azure vulns should get CVEs
In this podcast, Scott Kuffer discusses the importance of assigning CVEs to cloud service vulnerabilities, challenges in vulnerability prioritization, concerns with the NVD database delays, and navigating federal government contracts. The journey of a cyber defense company from small to large enterprises is also explored.

Mar 19, 2024 • 53min
Risky Business #741 -- The Mintlify breach and modern supply chains
This week's show covers AI code review flaws, Mintlify's Github token loss, UDP loop DoS attack resurgence, challenges in recon satellites, Microsoft restricting Russia's PowerShell, LockBit cyberattack aftermath, SpaceX's spy satellite network, and Russians losing access to Microsoft cloud services.

Mar 12, 2024 • 1h 4min
Risky Business #740 -- Midnight Blizzard's Microsoft hack isn't over
John P Carlin, former principal associate deputy attorney general, discusses SEC issues and the SolarWinds case. Topics include Midnight Blizzard's Microsoft hack, e-prescription drug sales, CISA ownership, and VMware's Tianfu Cup. Also covered are ransomware attacks, AI in cybersecurity, SEC disclosure requirements, and baselining cloud workloads.

Mar 5, 2024 • 59min
Risky Business #739 -- ALPHV exit scams while Change Healthcare burns
This podcast discusses the aftermath of a healthcare ransomware attack, including a hefty payment to AlphaV and an exit scam. They explore memory safety in cybersecurity, the urgency for improved security measures after a breach, and enhancing security with continuous access evaluation profiles. Additionally, they address stability in identity infrastructure administration and highlight the importance of strong authentication measures at the IDP level.

Feb 27, 2024 • 55min
Risky Business #738 -- LockBit is down but not out. Yet.
Cybersecurity expert Dmitri Alperovitch discusses Starlink, Starshield, and Congress row about Taiwan. LockBit group resurfaces post-takedown, Russia detains Medibank hacker. ConnectWise faces attacks, Microsoft expands logging. Sandvine added to US Entity List.

Feb 20, 2024 • 58min
Risky Business #737 -- LockBit gets absolutely rekt
Law enforcement takes down LockBit ransomware, Chinese contractor I-SOON leaks info, GRU network shutdown, Signal's username challenges, Ukrainian media targeted by Russian hackers, Pegasus spyware in Poland, hackers use facial recognition for bank fraud, Ivanti's backdoor vulnerability, Windows policy challenges discussed

Feb 18, 2024 • 40min
Soap Box: A deep dive on how Russia's SVR is hacking Microsoft 365 tenants
Cybersecurity expert Andy Robbins from SpecterOps discusses Russia's SVR hacking Microsoft 365 tenants. Topics include Entra ID security, detecting attack paths, managing permissions, hacking tactics for email inboxes, and the importance of permissions auditing in Azure environments.