
On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including:
Two alleged TeamPCP hackers got arrested in Australia
The White House has a plan to boost security for water facilities, but we can’t see it working
OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief
Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots
Much, much more…
This week’s show is brought to you by Ent AI. Co-founder Brandon Dixon joins Pat to talk through some of the absolutely wild fraud and abuse the company’s endpoint security tool is finding when it’s deployed inside large organisations.
This episode is also available on YouTube
Sep 2
58 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
Iranian hackers take down a small-scale power generator in the UK
Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
Prompt injection isn’t going away
LLMs are deceiving us meat sacks and it’s a worry
Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
This episode is also available on YouTube
Aug 26
1 hr 2 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:
Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
Anthropic’s models start a turf war when given the same task, surprising… nobody
We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
Much, much more
This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.
This episode is also available on YouTube
Aug 19
59 min

In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.
Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.
Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.
Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp.
This episode is also available on YouTube
Aug 14
29 min

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:
The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
It turns out TeamPCP has been around longer than we thought and predates the AI era
Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
Much, much more
This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.
This episode is also available on YouTube
Aug 12
59 min

On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including:
Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny
The bugpocalypse is so chaotic, Microsoft can’t patch fast enough
A ColdCard wallet flaw led to millions in Bitcoin theft, but the back story behind the bug is bonkers
Iran hacks and disrupts water infrastructure in multiple American states
North Korea’s state-backed hackers turn criminal. Or their criminals turn into state-backed hackers. Or something. It’s all a bit confusing, actually.
Much, much more!
This week’s show is brought to you by Sondera. Co-founder Josh Devon joins Patrick and James to talk through some absolutely hilarious LLM horror stories.
This episode is also available on YouTube
Aug 5
1 hr 8 min

On this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
Everyone signs the open weights open letter, except Anthropic… of course.
OpenAI had no idea it had hacked Hugging Face
Kimi K3 open weights released and they’re massive!
Why a more aggressive response is needed to cyber attacks on OT
And much, much more!
This week’s show is brought to you by SpecterOps. In this week’s sponsor interview Justin Kohler and Jared Atkinson talk about how SpecterOps’ Bloodhound now supports AWS attack paths. Run it against your AWS infra, but only if you have a strong stomach. The results will terrify you.
This episode is also available on YouTube.
Jul 29
1 hr 2 min

On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:
Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face
US and China trade AI model ban threats
Iran has been using SS7 queries to locate and target US troops
Scattered Spider is having a hard time, not just because of Microsoft’s GDID
And much, much more!
This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it.
This episode is also available on YouTube.
Jul 22
1 hr 9 min

In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection.
Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections.
This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you’re going to build a good graph, do you want to build it for a person to use, or an agent to use?
This is truly a conversation for the security nerd’s nerd. Enjoy!
This episode is also available on YouTube
Jul 8
35 min

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail
Distillation, cheap tokens, and AI chat harvesting is an industry in China
Edge becomes a lolbin via a new malicious extension
An Iranian APT boss’s vacation in a beautiful place goes wrong
Much, much more!
In this week’s sponsor interview Daf Stuttard and Katie Warren from Portswigger pop along to talk about how they built an AI security testing product that people would actually feel comfortable using.
This episode is also available on YouTube.
Jul 1
1 hr
Load more
