Risky Business cover art

Risky Business

Risky Business

By: Patrick Gray
Listen for free

About this listen

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.Copyright Risky Business Media 2007-2025 Politics & Government
Episodes
  • Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy
    Aug 27 2025
    On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: Australia expels Iranian ambassadorHackers sabotage Iranian shipping satcomsAPT hacker got doxxed in Phrack. Kind of. They’re probably Chinese, not DPRK?Trail of Bits uses image-downscaling to sneak prompts into Google GeminiThe Com’s King Bob gets ten years in the slammerIt’s a day that ends in -y, so of course there’s a new Citrix Netscaler RCE being used in the wild. This week’s episode is brought to you by Corelight. Chief Strategy Officer Greg Bell talks through how they’ve been implementing AI for sifting through your network data. A model-context-protocol server that can rummage in all those packet logs for you while you keep investigating? Yes please. This episode is also available on Youtube. Show notes Embassy staff flee Canberra in dead of night | news.com.au — Australia’s leading news site for latest headlinesSwedish security service says Iran uses criminal networks in Sweden | ReutersRisky Bulletin: Hackers sabotage Iranian ships at sea, again - Risky Business MediaMicrosoft scales back Chinese access to cyber early warning system | ReutersMicrosoft Didn’t Disclose Key Details to U.S. Officials of China-Based Engineers, Record Shows — ProPublica.:: Phrack Magazine ::.Uncovering the Chinese Proxy Service Used in APT CampaignsWeaponizing image scaling against production AI systems -The Trail of Bits BlogFBI, Cisco warn of Russia-linked hackers targeting critical infrastructure organizations | Cybersecurity DiveCrowdStrike warns of uptick in Silk Typhoon attacks this summer | CyberScoopKevin Beaumont: "There’s a bunch of new Netscal…" - CyberplaceUS charges Oregon man in vast botnet-for-hire operation | Cybersecurity DiveSouth Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities | The Record from Recorded Future NewsSIM-Swapper, Scattered Spider Hacker Gets 10 Years – Krebs on SecurityChinese national who sabotaged Ohio company’s systems handed four-year jail stint | The Record from Recorded Future NewsNevada state offices close after wide-ranging 'network security incident' | ReutersDSLRoot, Proxies, and the Threat of ‘Legal Botnets’ – Krebs on SecurityRussia weighs Google Meet ban as part of foreign tech crackdown | The Record from Recorded Future NewsKremlin-Mandated Messaging App Max Is Designed To Spy On UsersИеромонах РПЦ Макарий призвал помолиться за мессенджер MAX
    Show More Show Less
    54 mins
  • Wide World of Cyber: Microsoft's China Entanglement
    Aug 25 2025

    The Wide World of Cyber podcast is back! In this episode host Patrick Gray chats with Alex Stamos and Chris Krebs about Microsoft’s entanglement in China.

    Redmond has been using Chinese engineers to do everything from remotely support US DoD private cloud systems to maintain the on premise version of the SharePoint code base. It’s all blown up in the press over the last month, but how did we get here? Did Microsoft make these decisions to save money? Or was it more about getting access to the Chinese market? And how can we all make the world’s most important software company stop doing things like this? Tune in to the Wide World of Cyber podcast to find out!

    This episode is also available on Youtube.

    Show notes
      Show More Show Less
      46 mins
    • Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs
      Aug 20 2025

      On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

      • Oracle’s long term CSO departs, and we’re not that sad about it
      • Canada’s House of Commons gets popped through a Microsoft bug
      • Russia degrades voice calls via Whatsapp and Telegram to push people towards Max
      • South-East Asian scam compounds are also behind child sextortion
      • Reports that the UK has backed down on Apple crypto are… strange
      • Oh and of course there’s a Fortinet bug! There’s always a Fortinet bug!

      This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins the show this week, and explains the journey of implementing SSO backed login on Windows, Mac and Linux. You’ll never guess which one was a few lines of PAM config, and which was a multi-month engineering project!

      This episode is also available on Youtube.

      Show notes
      • Is Oracle facing headwinds? After layoffs, its 4-decade veteran Chief Security Officer Mary Ann Davidson departs
      • Oracle CSO blasted over anti-security research rant - iTnews
      • New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts | The Record from Recorded Future News
      • Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme – Krebs on Security
      • How we found TeaOnHer spilling users' driver's licenses in less than 10 minutes | TechCrunch
      • UK has backed down on demand to access US Apple user data, spy chief says
      • DNI Tulsi Gabbard on X: "As a result, the UK has agreed to drop its mandate for"
      • Hackers target Workday in social engineering attack
      • Russia curbs WhatsApp, Telegram calls to counter cybercrime | The Record from Recorded Future News
      • Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability | The Record from Recorded Future News
      • Norway police believe pro-Russian hackers were behind April dam sabotage | The Record from Recorded Future News
      • US agencies, international allies issue guidance on OT asset inventorying | Cybersecurity Dive
      • FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970)
      • U.S. State Dept - Near Eastern Affairs on X: "He did not claim diplomatic immunity and was released by a state judge"
      • 493 Cases of Sextortion Against Children Linked to Notorious Scam Compounds | WIRED
      • .:: Phrack Magazine ::.
      • Accenture to buy Australian cyber security firm CyberCX - iTnews
      Show More Show Less
      58 mins
    No reviews yet
    In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.