Risky Bulletin
Risky Bulletin
Risky Business Media
Regular cybersecurity news updates from the Risky Business team...
Between Two Nerds: The eye of Sauron
In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders. This episode is also available on YouTube.
Aug 17
32 min
Risky Bulletin: The EU publishes its upcoming cybersecurity standards
The EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.
Aug 17
8 min
Sponsored: What npm 12 fixes… and what it doesn’t
In this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what third-party code actually does before allowing it into their environments.
Aug 16
17 min
Risky Bulletin: US will let private companies carry out offensive cyber ops
The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.
Aug 14
11 min
Srsly Risky Biz: Data extortion is booming. Hooray!
Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up. They also discuss how the rise of AI makes it worth reinvigorating CISA’s Secure by Design initiative.
Aug 13
30 min
Risky Bulletin: Russian hackers jump on the fake job interview train
Russian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams.
Aug 12
9 min
Between Two Nerds: The cyber resistance!
In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals. This epsiode is also available on YouTube.
Aug 10
29 min
Risky Bulletin: Two law firms pay giant ransoms
Two American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!
Aug 10
8 min
Sponsored: Island's expansion to SASE and enterprise AI
In this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI.
Aug 9
16 min
Risky Bulletin: A Meta AI model also escaped a testing sandbox
A Meta AI model also escaped a testing sandbox, a cyberattack disrupts ports in North Carolina, the Philippines will establish a cybersecurity agency, and a Ransom Cartel admin gets 16 years in prison.
Aug 7
7 min
Load more