
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with industry legend HD Moore about how his company runZero wound up being used heavily to discover OT devices in enterprise networks.
They also talk about the vulnpocalypse and how frontier lab fearmongering is reminiscent of the collective freakout when HD released the Metasploit exploit framework back in 2003.
This episode is also available on YouTube.
Sep 29
34 min

THE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14
On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including:
Google’s Gemini finally did some crimes
OpenAI admits more agents did silly things because “alignment”
US Treasury’s Scott Bessent rules out a liability waiver for the frontier labs, saying, roughly: “Lol. Lmao even.”
Jev is Silicon Valley’s “hot dog/not hotdog” app brought to life, and it will really improve security tooling
The FBI and Coast Guard boarded oil tankers after they were allegedly hacked
Much, much more…
This week’s show is brought to you by Thinkst Canary. Founder Haroon Meer joins Patrick to talk about Thinkst’s new deception tools that trick the AI agents that are targeting you. It’s actually hilarious how well deception tech works against hacking agents.
This episode is also available on YouTube
Sep 23
54 min

On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including:
More tech guys penned more open letters and AI will destroy us all!
Another Wednesday, another congregation of OpenAI agents on wikis… yawn
OpenAI agents were behind the headscratching RubyGems hacking campaign in May
The FBI will disrupt more adversary operations, NSA is creating more mission centres, lawmakers want sanctions on hackers-for-hire… Release more hounds!
So many platforms, so many bugs, so many patches breaking other stuff
Much, much more…
This week’s show is brought to you by Airlock Digital. Its co-founders Daniel Schell and David Cottingham join Patrick to talk about how Airlock has integrated itself with Crowdstrike via its Falcon Foundry platform.
This episode is also available on YouTube
Sep 16
59 min

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:
watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do?
XBOW: The AI pentesting company pitches its approach
CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView!
This episode is also available on YouTube.
Sep 11
42 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:
ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits
The US government plans to pay private contractors to conduct military hacks
The US accuses China of distillation attacks, a.k.a. forbidden training
It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki
Much, much more…
This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace.
This episode is also available on YouTube
Sep 9
1 hr 3 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including:
Two alleged TeamPCP hackers got arrested in Australia
The White House has a plan to boost security for water facilities, but we can’t see it working
OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief
Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots
Much, much more…
This week’s show is brought to you by Ent AI. Co-founder Brandon Dixon joins Pat to talk through some of the absolutely wild fraud and abuse the company’s endpoint security tool is finding when it’s deployed inside large organisations.
This episode is also available on YouTube
Sep 2
58 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
Iranian hackers take down a small-scale power generator in the UK
Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
Prompt injection isn’t going away
LLMs are deceiving us meat sacks and it’s a worry
Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
This episode is also available on YouTube
Aug 26
1 hr 2 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:
Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
Anthropic’s models start a turf war when given the same task, surprising… nobody
We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
Much, much more
This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.
This episode is also available on YouTube
Aug 19
59 min

In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.
Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.
Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.
Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.
This episode is also available on YouTube
Aug 14
29 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:
The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
It turns out TeamPCP has been around longer than we thought and predates the AI era
Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
Much, much more
This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.
This episode is also available on YouTube
Aug 12
59 min
Load more
