Risky Business Media
Risky Bulletin
Regular cybersecurity news updates from the Risky Business team...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Risky Bulletin: NSA Tailored Access Operations is back 10.07.2026 7:54
The NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor. The Risky Bulletin newsletter and podcast will be on an editorial break until July 20. Show notes Risky Bulletin: India bans app used to hack e-rickshaws in viral videos
Sponsored: Why Sublime doesn’t toss AI at every email 10.07.2026 14:30
In this Risky Business sponsored interview, Tom Uren chats with Sublime Security Product Manager AJ Williams about how the company targets its AI use. Rather than throwing its AI agents at everything, Sublime gives them the time-consuming email security tasks that humans don’t want to do. Its ASA (Autonomous Security Analyst) agent investigates suspicious and user-reported messages, while the ADÉ...
Srsly Risky Biz: US Supreme Court undermines Section 702 intel 09.07.2026 27:55
Tom Uren and James Wilson talk about a new US Supreme Court decision that puts the current EU-US data sharing agreement at risk. American intelligence collection efforts have been at the centre of legal challenges of these on-again off-again data transfer agreements, and if the current agreement were struck down it would cripple Section 702 collection from Europe. They also discuss Canada’s effort...
Risky Bulletin: DHS IG investigates forced CISA reassignments 08.07.2026 9:48
The DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels. Show notes Risky Bulletin: All new cars to include a camera aimed at the driver's face
Between Two Nerds: Why AI has not meant more hacks. Yet. 06.07.2026 32:14
In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs. This episode is also available on YouTube . Show notes Jerry Gamblin | X Cyber: Ignore the Penetration Testers Phineas Fisher's hacking team write up Phineas Fisher
Risky Bulletin: EU official’s phone infected with Pegasus 06.07.2026 5:46
A European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel. Show notes Risky Bulletin: Android drops PIN guessing limit from 1,800 attempts to just 20
Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices 03.07.2026 9:20
FatFs bugs enable physical access attacks on industrial equipment, a clever password spraying attack bypasses M365 MFA, an AI agent is deploying ransomware in live attacks, and a webinar platform sues two security firms over bad IOCs. Show notes Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
Srsly Risky Biz: America won't beat the distillation ecosystem 02.07.2026 30:02
Tom Uren and James Wilson talk about Chinese AI labs stealing the special sauce of American AI models in ‘distillation attacks’. These attacks are fed by a grey market in which Chinese consumers buy access to American models, where one of the byproducts is logs of user requests and responses. These make wonderful inputs into distillation attacks and the whole market might be subsidised by Chinese...
Risky Bulletin: Researcher drops giant cache of zero-days 01.07.2026 9:45
An anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts geofence warrants, and security firm Huntress has denied accusations of a malicious insider. Show notes Risky Bulletin: Researcher drops giant cache of zero-days
Between Two Nerds: Set cyberspace ablaze 29.06.2026 39:08
In this edition of Between Two Nerds, Tom Uren and The Grugq discuss whether cyber organisations should actually be separated from Signals Intelligence organisations. The Grugq argues that having cyber expertise subordinate to intelligence collection means that many opportunities are never explored. This episode is also available on YouTube . Show notes All the Shah's Men - Wikipedia
Risky Bulletin: White House asks OpenAI to restrict GPT 5.6 29.06.2026 7:28
The White House asks OpenAI to keep a tight grip on ChatGPT 5.6, the US Secret Service made some appalling OpSec mistakes, AMD has reintroduced a CPU security feature after consumer backlash, and an Iranian APT operator has been arrested in Montenegro. Show notes Risky Bulletin: Microsoft disrupts StegoAd operation
Sponsored: Corelight’s blueprint for AI-era defence 29.06.2026 19:27
In this sponsored interview James Wilson chats with Corelight’s VP of Product Vijit Nair about defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance between proactive and reactive measures. On the proactive side, you need modelling of assets and threats. On the reactive side you’ll need telemetry so you can act quickly if a threat...
Risky Bulletin: Operation Endgame dismantles Amadey and StealerC 26.06.2026 10:15
Law enforcement dismantles two more malware operations, Japan’s army used infected USB drives, Anthropic accuses Alibaba of distillation attacks, and Australia finds “digital dynamite” on critical networks. Show notes Risky Bulletin: Law enforcement agencies and security firms take down Amadey and StealerC
Srsly Risky Biz: Open weight models make the Mythos debate moot 25.06.2026 28:28
Tom Uren and James Wilson talk about the Five Eyes cyber security agencies warning about the arrival of AI-enabled cyber threats. The call-to-action is driven by the recognition that it is no longer possible to limit AI’s offensive cyber security capabilities to benign actors. The genie is out of the bottle, regardless of export controls on frontier models. They also discuss the progress of Operat...
Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing 24.06.2026 8:43
The FortiBleed hacks are worse than a credentials leak, a new White House executive order sets out a hard 2031 post quantum cryptography deadline, Meta leaks employee keystroke data, and a third of Samsung and LG TVs act as proxies. Show notes Risky Bulletin: The FortiBleed incident is so much worse than a simple credentials leak
Sponsored: Trail of Bits and OpenAI patch the planet 23.06.2026 18:27
In this sponsored interview James Wilson chats with Trail of Bits founder and CEO Dan Guido about its newly announced partnership with OpenAI. Together, they’ve started a new initiative called “Patch the Planet” to support open source maintainers. Being an open source maintainer is more difficult than ever. Just using frontier models to keep up with all the bug reports isn’t enough. Trail of Bits...
Between Two Nerds: The PRC vs AI 22.06.2026 35:22
In this edition of Between Two Nerds Tom Uren and The Grugq discuss the idea that the People’s Republic of China has mobilised its influence operations against the construction of US data centres and its build out of AI capacity. This episode is also available on YouTube . Show notes Red Rap Two Sessions Get on the Beers
Risky Bulletin: Klue breach impacts security firms 22.06.2026 8:08
A data breach at business analytics platform Klue spreads to security firms, a hacker breaches Brazil’s national alert system, North Koreans are behind the Mastra supply chain attack, and a new, unfixable vulnerability has been found in Apple’s A12 and A13 chips. Show notes Risky Bulletin: Klue breach impacts security firms
Risky Bulletin: Creds for 74,000 Fortinet devices leaked 19.06.2026 11:00
A LOT of Fortinet creds have leaked online, Canada’s spy agency allowed to remove a botnet from Canadian devices, a supply chain attack hits the Mastra AI framework, and Europol disrupts SocGolish. Show notes Risky Bulletin: Canada’s spy agency allowed to remove a botnet from Canadian devices
Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligence 18.06.2026 31:22
Tom Uren and James Wilson talk about Anthropic rolling out its latest models only to have them effectively banned by the US government within days. Although the administration’s process for assessing new models is, ahem, amorphous, Anthropic is doing itself no favours by dismissing its concerns. The company needs to show some emotional intelligence and learn how to manage upwards. They also discus...
Risky Bulletin: China arrests Silver Fox cybercrime group suspects 17.06.2026 10:54
66 members of the Silver Fox cybercrime group arrested in China, the EU will help Ukraine in the event of a major cyberattack, MS-ISAC loses 70% of its members after a DHS funding cut, and S-BOMs are still not widely adopted. Show notes Risky Bulletin: China arrests Silver Fox cybercrime group suspects
Between Two Nerds: Why NATO and cyber don't mix 15.06.2026 28:37
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how NATO is set up to deter conventional conflict, and how that approach is fundamentally unsuited for ongoing, everyday cyber operations that are intended to confound adversaries. This episode is also available on YouTube . Show notes
Risky Bulletin: Arch Linux supply chain attack hits 1,900 packages 15.06.2026 11:14
Almost 2,000 Arch Linux packages have been infected with malware in a supply chain attack, FISA surveillance powers expire for the first time since 2008, the FBI takes down a Chinese phishing service, and a major supply chain attack hits the WordPress ecosystem. Show notes Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages
Sponsored: Ent on using AI to track human behavior on the endpoint 14.06.2026 19:36
In this Risky Business sponsored interview, Catalin Cimpanu talks with Brandon Dixon, co-founder and CTO of Ent AI, about the company’s innovative use of local LLMs to track user behavior on the endpoint, and add context to suspicious events to detect or prevent malicious activity. Show notes Brandon Dixon on LinkedIn
Risky Bulletin: CISA tightens patching rules amid bug deluge 12.06.2026 9:49
CISA changes federal patching rules due to AI, a House Republican was hacked by Russia, ShinyHunters go on an Oracle hacking spree, and npm will block auto-run install scripts by default. Show notes Risky Bulletin: In the age of AI, CISA changes federal patching rules
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.