Risky Business

By Patrick Gray

Listen to a podcast, please open Podcast Republic app. Available on Google Play Store.


Category: Tech News

Open in Apple Podcasts


Open RSS feed


Open Website


Rate for this podcast

Subscribers: 1289
Reviews: 3


 Aug 1, 2021

Anders
 Jul 13, 2020


 Oct 10, 2018

Description

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Episode Date
Risky Business #652 -- Cyber Partisans take down Belarusian rail systems

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Belarusian Cyber Partisans ransom train network
  • A look at developments in Ukraine
  • Merck wins NotPetya insurance lawsuit
  • US VC firm in talks to acquire NSO Group
  • Much, much more

This week’s show is brought to you by Trail of Bits, the security engineering firm. Dan Guido joins us this week week to talk about zkdocs, a bunch of documentation Trail of Bits put together to provide guidance on how to implement some of these newfangled concepts – like zero knowledge proofs – that are popular in blockchain and cryptoland.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Jan 26, 2022
Risky Business #651 -- Russia's ransomware diplomacy

On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including:

  • Russia arrests REvil crew
  • Ukraine government hit in messy hacks
  • White House hosts open source pow-wow, but is it pointless?
  • US cyber reporting law will come back from the dead
  • Report: Israeli police targeted activists with NSO but without warrants
  • Much, much more

This week’s sponsor interview is with HD Moore, the founder of Rumble. We’re talking through what how he and his team helped customers respond to the log4j drama. They quickly added the capability to scan customer’s environments for log4shell-affected tech. When asset discovery meets rapid vuln response!

Links to everything that we discussed are below and you can follow Patrick, Dmitri or Adam on Twitter if that’s your thing.

Show notes

Jan 19, 2022
Risky Biz Soap Box: Rolling your own threat intelligence with Steve Miller

In this edition of the soap box we’re chatting with Steve Miller, a senior researcher at Stairwell. Steve has a long history doing this sort of stuff. He worked inside various bits of the US government doing cyber things, and also spent a decent chunk of his career at Mandiant.

His new employer, Stairwell, makes a platform that collects information about all files present in your environment and let’s you do some fancy stuff with that information. You’ll hear a little bit more about what they do in this interview, but we’re not really talking that much about Stairwell in this interview. It’s more about the evolution of threat intel.

As you’ll hear, Steve said the first iteration of the commercial threat intel space was very much born of govvies jumping out and bringing their thinking with them, but the space is evolving. The take away from this interview is that threat intelligence is more something that you do, not something you just blindly consume.

Jan 14, 2022
Risky Business #650 -- USG drops Russia advisory as Ukraine tensions mount

On this week’s show Patrick Gray, Katie Nickels and Joe Slowik discuss the week’s security news, including:

  • US Government warns of impending critical infrastructure hacks
  • Log4j bug in VMWare gets a workout
  • Ex Uber CSO Joe Sullivan facing wire fraud charges
  • Signal to push ahead on cryptocurrency payments
  • Italian literary nerd busted for running one man APT operation
  • Much, much more

This week’s show is brought to you by Okta. Marc Rogers is the executive director of cybersecurity there and he’s joining us this week to talk about the log4j bug and some adjacent issues. He’s working on a paper with IST about the bug and what it all means, and he’s joining us this week to talk about why the log4j drama was different.

Links to everything that we discussed are below and you can follow Katie, Joe or Patrick on Twitter if that’s your thing.

Show notes

Jan 12, 2022
Risky Business #649 -- Java being a fiddly mess saves the day

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The log4j bug wrap
  • The ransomware wrap
  • The human rights and surveillance industry wrap
  • Research and carnage wrap

This week’s show is brought to you by Airlock Digital. They make allowlisting software that has mostly been used in Windows environments, but as you’re about to hear they’ve now got a very, very nice solution for the bigger Linux distros, and their Mac agent is going to be launched in a few weeks.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Jan 05, 2022
Risky Biz Soap Box: Why Thinkst gives its honeytoken tech away for free

This isn’t the normal weekly news episode of the show, if you’re looking for the regular weekly Risky Business podcast, scroll one back in your podcast feed. This is a Soap Box edition, a wholly sponsored podcast brought to you in this instance by Thinkst Canary.

For those who don’t know, Thinkst makes hardware and virtual honeypots you can put on your network or into your cloud environments – they’ll start chirping if an attacker interacts with them. They’re a low cost and extremely effective detection tool. But you might not know that Thinkst also operates canarytokens.org where you can go set up a bunch of honeytokens for free. Hundreds of thousands of people are using canarytokens.org, but Thinkst doesn’t charge anything for it, it’s free to use. They’ll even give you a docker container of the whole thing so you can run it yourself.

Our guest today is Thinkst’s founder and infosec legend Haroon Meer. He spent a chunk of his career at the South African security consultancy SensePost before founding Thinkst Applied Research and eventually launching Canary.Tools. In this interview we talk about what the industry is getting wrong, supply chain security, effective detections and more. But I started off by asking him why Thinkst hasn’t tried to monetise canarytokens.org given how many people use it.

Dec 10, 2021
Risky Business #648 -- Adios, 2021, it's been real

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • NSO Group tools found on US embassy staff phones in Uganda
  • Mitto is up to shady bidnez
  • Ubiquiti “whistleblower” charged over hack
  • Hounds everywhere
  • Planned Parenthood breached
  • Much, much more

This week’s sponsor interview is with Andrew Morris of Greynoise.

Greynoise has a bunch of sensors out there on the Internets, so they can tell you when and IP that’s hitting you is also hitting everyone else. If you work in a SOC, you know this is very useful. Greynoise has just signed a $30m deal with the US Department of Defense. As Andrew will explain in just a moment, this means if you work in a DoD agency it’s now very easy for you to get a subscription. In this interview I also talk to Andrew about his adventures chasing down one of the people spamming Internet attached receipt printers with the antiwork manifesto from Reddit.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Dec 08, 2021
Risky Business #647 -- Israel slashes cyber exports, Interpol takes down 1,000 crooks

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Israel slashes number of countries it will export cyber tools to
  • Interpol takes down 1,000 Internet fraudsters
  • Ransomware crews lying low?
  • When the tabloids do cyber the results are sometimes awesome
  • Much, much more…

This week’s sponsor interview is with Ryan Kalember of Proofpoint. He’s the EVP of Cybersecurity Strategy there and he’s joining me this week to talk about how investment activity in cybersecurity is basically leaving everyone who isn’t a mega enterprise behind.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Dec 01, 2021
Risky Business #646 -- Apple cracks the sads, sues NSO Group

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Apple sues NSO Group and it’s all a bit weird
  • Israel charges defence minister’s house cleaner with Iranian hacker collusion (really)
  • USA charges two Iranians over “Proud Boy” emails
  • Cyber insurers nope out of comprehensive coverage
  • Prodaft shells Conti, drops report like it’s a Normal Thing
  • Much, much more

This week’s show is sponsored by VMRay. We’ll be chatting with one of VMRay’s customers in this week’s sponsor interview. Jim Byrge works on the CSIRT team at Valvoline, and he’ll be along to talk about how they replaced their ageing, in-house developed SOAR platform with commercial tools. It was still harder than it should be in 2021, but they got there in the end.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Nov 24, 2021
Risky Biz Soap Box: DDoS crews will hit you creatively

In this edition of the Risky Biz Soap Box podcast we chat with Sean Leach, the Chief Product Architect at Fastly, about the history and current status of the DDoS ecosystem. Despite never really making money for criminals, DDoS attacks are still a problem.

CDNs have soaked up a lot of the problem, so DDoS crews are getting creative. Do you know where you’re vulnerable?

Nov 19, 2021
Risky Business #645 -- How Israel used NSO to make friends in low places

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Watering hole attacks are getting much better
  • How Israel’s government used NSO to strengthen its diplomatic ties
  • Randori sat on some PAN 0day. This is fine.
  • Facebook outs state-backed ops
  • FBi has unfortunate incident with its mail boxes
  • Much, much more

This week’s sponsor interview is with HD Moore. He’s the founder of Rumble, the network asset discovery scanner, and he’s joining us to talk about some new tricks he’s added to the product, like integrations with cloud service APIs and external discovery products like Censys.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Nov 17, 2021
Risky Biz Soap Box: Linux is an infrastructure OS, act accordingly

In this edition of the Soap Box podcast we’re chatting with Jake King. Jake is a co-founder of Cmd Security, a Linux Security startup that was recently acquired by Elastic.

Cmd’s technology basically started out as a control and visibility tool for Linux systems that could restrict user actions. But over time, the product evolved to be more detection and response oriented.

In this interview we talk to Jake about why Cmd wound up where it is, product wise, and what customers can expect now his company has been swept up by Elastic as a part of its broader push into XDR, or Extended Detection and Response.

Nov 12, 2021
Risky Business #644 -- USA sanctions NSO Group, hits REvil

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • US sanctions NSO, Candiru, COSEINC and Positive Technologies
  • We wrap up the action in ransomware
  • Why exploit tournaments are boring in America and exciting in China
  • More malicious npm packages in the wild
  • Pentagon updates CMMC to 2.0
  • Much, much more

We’ll hear from Corelight’s CISO Bernard Brantley in this week’s sponsor interview. We’re talking about how attackers think in graphs and defenders think in lists.. Microsoft’s John Lambert wrote a post about that back in 2015, and Bernard joins the show this week to talk about why it’s just as relevant as ever. Stick around for that one.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Nov 10, 2021
Risky Business #643 -- Iranian fuel stations targeted, PNG ransomware a regional security risk

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Someone took down Iranian fuel stations
  • Papua New Guinea ransomware attack is pretty grim stuff
  • Russia’s SVR still going berserk in cloudtown
  • China Telecom America gets the boot
  • Much, much more

We’ll be hearing from Senetas CEO Andrew Wilson in this week’s sponsor interview. He’s joining us to talk about how the global semiconductor shortage is making him a very, very sad panda.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Nov 03, 2021
Risky Biz Feature Interview: Mark Dowd on the 0day market and future of exceptional access

This feature podcast was made possible by the Hewlett Foundation’s Cyber Initiative. The foundation has given us grant funding to produce this podcast series, which is designed to educate policymakers in cybersecurity so they can make better decisions.

In this edition you’ll hear an interview I recorded with Mark Dowd.

Mark is a world-renowned security researcher who, some years ago, co-founded a company called Azimuth Security. As you’ll hear, the original plan was to provide security research and consulting services to vendors. But, pretty quickly, Azimuth became a serious player in offensive security, selling exploits and other tools to government agencies in the Five Eyes countries.

We recorded this interview touching on the history of Azimuth, what the public gets wrong when talking about 0day and surveillance, and were this whole thing could go – especially considering writing memory corruption exploits is getting so much harder.

Oct 19, 2021
Risky Business #642 -- Brits, Dutch and Aussies embrace Hounds Doctrine

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • UK, Netherlands and Australia promise offensive response to big ticket ransomware
  • Wave of major cyber regulation and legislation in USA
  • Iran up in yer O365s, Russians in yer gmails
  • Submarine spy guy would have been fine, if he didn’t make one very big mistake
  • Much, much more

Jonathan Reiber is this week’s sponsor guest. He’s senior director of cybersecurity at AttackIQ and he’s joining us to talk through the US Government’s executive order on Zero Trust. Jonathan says it is actually born of a realisation the US Government needs to do something differently, that the old approaches aren’t working.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Oct 13, 2021
Risky Business #641 -- Lawsuit: Ransomware contributed to baby's death

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Group-IB CEO arrested in Russia for treason
  • Lawsuit alleges ransomware contributed to hospitalised baby’s death
  • Nakasone outs self as hound release advocate
  • Syniverse owned, but we don’t know how badly
  • Why Google keyword warrants are awesome
  • Much, much more…

Nucleus co-founder Scott Kuffer is this week’s sponsor guest and the topic is actually a bit hilarious. They’ve found a killer use case that customers are clamouring for: Being able to map vulnerabilities to org groups within your enterprise so you can see who’s slacking off when it comes to patching.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Oct 06, 2021
Risky Biz Snake Oilers: Mike Wiacek launches Stairwell, Red Canary on modern MDR and Datadog pitches full stack monitoring

In this edition of the Snake Oilers we’ll hear pitches from three vendors:

  • Stairwell! A new startup from Chronicle Security co-founder Mike Wiacek
  • Red Canary explains what modern managed detection and response looks like
  • Pierre Betouin from Datadog talks about the challenges around bringing together DevOps and Security while providing full-stack security

Links to everything we talked about are in the show notes.

[CORRECTION: Mike Wiacek was originally described as the co-founder of VirusTotal in this podcast. He is in fact a co-founder of Chronicle Security, which absorbed VirusTotal after launching.]

Oct 01, 2021
Risky Business #640 -- Huh. The CIA really was out to neck Assange

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The amazing Yahoo! News story on the former CIA director’s awesome brainwaves
  • Hostage diplomacy pays off for Huawei CFO
  • NSA releases great guidance on VPN security
  • Microsoft has actually hired a cybersecurity executive
  • Much, much more

This week’s show is brought to you by Material Security. Material’s co-founder Ryan Noon will be along in this week’s sponsor interview to talk about smarter ways to do email retention and destruction. They have a product that interfaces with your mail provider’s API – whether you’re on Google Workspace or O365 – to do things like archive and redact email, and they’re finding their customers are using these features to actually implement retention email strategies.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Sep 29, 2021
Risky Business #639 -- USA's ransomware non-policy fails to meet its unstated objective

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • BlackMatter is back in the USA’s critical supply chain
  • The FBI and friends apparently got up in REvil’s business
  • The Azure OMI thing is totally the disaster we were expecting
  • Much, much more

Brett Winterford is this week’s sponsor guest. These days Brett is a senior director of cybersecurity strategy at Okta, but the reason you might recognise his name is because he took a year off working for vendors to be our newsletter author – he was the founding editor of the Seriously Risky Business newsletter.

He’ll be along to talk about legacy auth and why vendors should have deprecation policies.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Sep 22, 2021
Risky Business #638 -- Licensed to Pwn

On this week’s show Patrick Gray and Adam Boileau discuss recent security news, including:

  • Apple 0day has everyone freaking out
  • So much more 0day in the wild
  • American Project Raven staffers settle with DoJ
  • Two absolutely bonkers Azure security problems
  • SEC tells corporate America to spill on breaches
  • Much, much more

In this week’s sponsor interview Gigamon’s security product manager Fayyaz Rajpari will be along to talk about some of the work they’ve been doing to integrate their NDR product with Crowdstrike.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

Sep 15, 2021