• Risky Business

  • 著者: Patrick Gray
  • ポッドキャスト

Risky Business

著者: Patrick Gray
  • サマリー

  • Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
    Copyright 2007-2024 Patrick Gray
    続きを読む 一部表示

あらすじ・解説

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Copyright 2007-2024 Patrick Gray
エピソード
  • Risky Business #770 -- A Russian IR guy discovers extremely cool spookware
    2024/11/13

    On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

    • Apple frustrates law enforcement with iOS auto-reboot
    • CISA says most KEV vulnerabilities in 2023 were first used as zero days
    • Russians roll incident response on some sweet Linux spookware
    • Regular users can create mailboxes in M365?
    • Tor tracks down the source of its joe-job abuse complaints
    • And much, much more.

    This week’s feature guest is former FBI agent Chris Tarbell, who arrested Silk Road operator Ross Ulbricht way back in 2013. As suggestions swirl that an incoming Trump administration might release Ulbricht, Chris talks about the reality of the Dread Pirate Roberts.

    This episode is sponsored by software supply chain security firm Socket.dev. Founder Feross Aboukhadijeh thinks that we need a CVE-like catalogue for supply-chain attacks, and he makes a solid argument.

    The show is also available on Youtube.

    Show notes
    • Jason Koebler: "New: We’ve confirmed Apple quietly introduced a feature in the new iOS that is preventing cops from hacking iPhones that they have confiscated as evidence. Apple really did say ACAB www.404media.co/apple-quietl..." — Bluesky
    • Apple Quietly Introduced iPhone Reboot Code Which is Locking Out Cops
    • Exclusive | U.S. Agency Warns Employees About Phone Use Amid Ongoing China Hack - WSJ
    • Surge in exploits of zero-day vulnerabilities is ‘new normal’ warns Five Eyes alliance
    • The Elusive GoblinRAT: How a Linux Backdoor Infiltrated Government Infrastructures
    • Microsoft Bookings – Facilitating Impersonation | Cyberis Limited
    • TrustedSec | EKUwu: Not just another AD CS ESC
    • Russia’s internet watchdog blocks thousands of websites that use Cloudflare's privacy service
    • Defending the Tor network: Mitigating IP spoofing against Tor | The Tor Project
    • Law enforcement operation takes down 22,000 malicious IP addresses worldwide - Ars Technica
    • Press Conference - Parliament House, Canberra | Prime Minister of Australia
    • DHS nominee Kristi Noem stood alone for rejecting department cyber grants to state, local governments | CyberScoop
    • Patrick Gray: "Allies will feel comfortable until these guys get fired in their first 100 days for opposing Trump’s proposed annexation of Iceland or something. People have forgotten… Trump is out of his gourd" — Bluesky
    続きを読む 一部表示
    1 時間 3 分
  • Risky Biz Soap Box: Why black box email security is dead
    2024/11/11

    In this edition of the Risky Business Soap Box we’re talking all about email security with Sublime Security co-founder Josh Kamdjou.

    Email security is one of the oldest product categories in security, but as you’ll hear, Josh thinks the incumbents are just doing it wrong. He joins Risky Business host Patrick Gray for this interview about Sublime’s origin story and its new approach to email security.

    続きを読む 一部表示
    36 分
  • Risky Business #769 -- Sophos drops implants on Chinese exploit devs
    2024/11/06

    On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

    • Sophos drops implants on Chinese firewall exploit devs
    • Microsoft workshops better just-in-time Windows admin privileges
    • Snowflake hacker arrested in Canada
    • Okta has a fun, but not very impactful auth-bypass bug
    • Russians bring dumb-but-smart RDP client attacks
    • And much, much more.

    Special guest Sophos CISO Ross McKerchar joined us to talk about its “hacking back” campaign. The full interview is available on Youtube for those who want to really live vicariously through Sophos doing what every vendor probably wants to do.

    This week’s episode is sponsored by attack surface mapping vendor runZero. Founder and CEO HD Moore joins to talk about marrying up the outside and inside views of your network.

    You can also watch this episode on Youtube

    Show notes
    • Okta AD/LDAP Delegated Authentication - Username Above 52 Characters Security Advisory
    • Does bcrypt have a maximum password length? - Information Security Stack Exchange
    • Local Administrator Protection | Privilege Protection
    • Inside Sophos' 5-Year War With the Chinese Hackers Hijacking Its Devices | WIRED
    • A Deeper Look at FortiJump (FortiManager CVE-2024-47575) | Bishop Fox
    • Man Arrested for Snowflake Hacking Spree Faces US Extradition | WIRED
    • Google uses large language model to discover real-world vulnerability
    • GreyNoise Intelligence Discovers Zero-Day Vulnerabilities in Live Streaming Cameras with the Help of AI
    • Thousands of hacked TP-Link routers used in yearslong account takeover attacks - Ars Technica
    • CISA warns of foreign threat group launching spearphishing campaign using malicious RDP files | Cybersecurity Dive
    • Chinese state-backed hackers breached 20 Canadian government networks over four years, agency warns
    • India-Canada row: Canadian officials confess to leaking 'intel' against India to Washington Post - India Today
    • Amid diplomatic row, Canada names India in ‘cyberthreat adversary’ list, accuses it of ‘likely spying’ | World News - The Indian Express
    • The Untold Story of Trump's Failed Attempt to Overthrow Venezuela's President | WIRED
    • Risky Biz News: The mystery at Mango Park
    • North Korean hackers seen collaborating with Play ransomware group, researchers say
    続きを読む 一部表示
    57 分

Risky Businessに寄せられたリスナーの声

カスタマーレビュー:以下のタブを選択することで、他のサイトのレビューをご覧になれます。