• Between Two Nerds: The AI-first crime gang
    May 12 2026

    In this edition of Between Two Nerds Tom Uren and The Grugq discuss why it makes even more sense for criminal organisations to adopt AI as compared to regular businesses.

    This episode is also available on YouTube.

    Show notes
    • Microsoft's 2026 Work Trend Index Annual Report
    • Cybersecurity Looks Like Proof of Work Now
    • On the Hunt for FIN7
    Show More Show Less
    26 mins
  • Risky Bulletin: FCC relaxes foreign router security patch ban
    May 11 2026

    The FCC relaxes its foreign router ban to allow for security updates, the ShinyHunters group disrupts schools across the globe, a 21-year-old remote code execution bug turns up in FreeBSD, and another Linux privilege escalation bug was disclosed… without a patch.

    Show notes
    • Risky Bulletin: FCC relaxes foreign router ban to allow for security updates
    Show More Show Less
    11 mins
  • Sponsored: Knocknoc built a Greynoise integration
    May 10 2026

    In this sponsored interview Patrick Gray chats with Knocknoc CEO Adam Pointon about their Greynoise integration.

    Knocknoc allowlists network connections from users’ IPs after they’ve been through an SSO challenge. It’s great for protecting vulnerable or risky assets that your org has to connect to the internet. But what happens when one of your users tries to authenticate from a bad IP? You probably don’t want to add that one to your allowlist!

    Thanks to Knocknoc’s new Greynoise integration, you don’t have to!

    Show notes
      Show More Show Less
      10 mins
    • Risky Bulletin: State sponsored group exploits Palo 0day
      May 8 2026

      Palo Alto Networks patches a firewall zero-day, Google patches an Android remote takeover bug, Ivanti also patches one, and a leak exposes Russia’s spy and hacker school.

      Show notes
      • Risky Bulletin: Google patches Android remote takeover bug
      Show More Show Less
      8 mins
    • Srsly Risky Biz: After Mythos, US government weighs AI regulation
      May 7 2026

      Tom Uren and James Wilson talk about the sudden drive to put regulation around the releases of new AI models because of their cyber security implications. A standardised approach is desirable, but clamping down too hard won’t achieve as much as might be hoped. Experts with older or even open models can get just as far as novices with the latest models.

      They also discuss Australia’s new Cyber Incident Review Board. It has been hamstrung and won’t be as successful as it could be because it can’t assign blame.

      This episode is also available on YouTube

      Show notes
        Show More Show Less
        23 mins
      • Risky Bulletin: Targeted supply chain attack hits DAEMON Tools
        May 6 2026

        The DAEMON Tools website was hit in a targeted supply chain attack, Australia gets its own CSRB, the US arrests a wanted VOIP server hacker after 17 years, and Oracle switches to monthly security updates.

        Show notes
        • Risky Bulletin: Extremely targeted supply chain attack hits DAEMON Tools
        Show More Show Less
        9 mins
      • Between Two Nerds: The wild wild west
        May 4 2026

        In this edition of Between Two Nerds Tom Uren and The Grugq discuss the breakdown of cyber norms. What would have been an unthinkable cyber operation just a few years ago is now a regular occurrence.

        This episode is also available on YouTube.

        Show notes
        • Fast16 analysis by SentinelOne
        • Fast16 malware
        • Zero Day on the wiper targeting Venezuela's state oil company
        Show More Show Less
        32 mins
      • Risky Bulletin: DigiCert hacked with a malicious screensaver file
        May 4 2026

        DigiCert got hacked via a malicious screensaver file, two ransomware negotiators each get four years in prison, Trellix discloses a security breach, and another Russian hacker gets arrested while vacationing in the wrong place.

        Show notes
        • Risky Bulletin: DigiCert hacked with a malicious screensaver file
        Show More Show Less
        10 mins