• Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now
    May 21 2025

    On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

    • TeleMessage memory dumps show up on DDoSecrets
    • Coinbase contractor bribed to hand over user data
    • Telegram does seem to be actually cooperating with law enforcement
    • Britain’s legal aid service gets 15 years worth of applicant data stolen
    • Shocking no one, Ivanti were weaseling when they blamed latest bugs on a third party library

    This week’s episode is sponsored by Prowler, who make an open source cloud security tool. Founder and original project developer Toni de la Fuente joins to talk through the flexibility that open tooling brings. Prowler is also adding support for SaaS platforms like M365, and of course, an AI assistant to help you write checks!

    This episode is also available on Youtube.

    Show notes
    • TeleMessage - Distributed Denial of Secrets
    • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes | WIRED
    • Coinbase says thieves stole user data and tried to extort $20M
    • Hack could cost Coinbase up to $400M: filing | Cybersecurity Dive
    • Severed Fingers and ‘Wrench Attacks’ Rattle the Crypto Elite
    • Money Stuff: US Debt Rates Itself | NewsletterHunt
    • 2 massive black market services blocked by Telegram, messaging app says | Reuters
    • Telegram Gave Authorities Data on More than 20,000 Users
    • GovDelivery, an email alert system used by governments, abused to send scam messages | TechCrunch
    • ATO warning as hackers steal $14,000 in tax returns: ‘Be wary’
    • Hack of SEC social media account earns 14-month prison sentence for Alabama man | The Record from Recorded Future News
    • 19-year-old accused of largest child data breach in U.S. agrees to plead guilty
    • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy | 7NEWS
    • Pegasus spyware maker rebuffed in efforts to get off trade blacklist - The Washington Post
    • Ransomware attack hits supplier of refrigerated groceries to British supermarkets | The Record from Recorded Future News
    • UK government confirms massive data breach following hack of Legal Aid Agency | The Record from Recorded Future News
    • Ivanti Endpoint Mobile Manager customers exploited via chained vulnerabilities | Cybersecurity Dive
    • Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
    Show More Show Less
    53 mins
  • Risky Biz Soap Box: Push Security does identity security in your browser
    May 15 2025

    In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.

    Push has built an identity security platform that collects identity information from your users’ browsers. It can detect phish kits and stop them, protect SSO passwords, and even find every single shadow/personal account that a user has spun up.

    We think about phishing as protecting your users’ SSO details. But what about all the SaaS they’re using? What about the automation platforms your developers and admins use? What about data platforms like Snowflake? Are they using MFA? How would you know?

    This is a fun one!

    This episode is also available on Youtube.

    Show notes
      Show More Show Less
      34 mins
    • Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys
      May 14 2025

      On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

      • Struggling to find that pesky passwords.xlsx in Sharepoint? Copilot has your back!
      • The ransomware ecosystem is finding life a bit tough lately
      • SAP Netweaver bug being used by Chinese APT crew
      • Academics keep just keep finding CPU side-channel attacks
      • And of course… bugs! Asus, Ivanti, Fortinet… and a Nissan LEAF?

      This week’s episode is sponsored by Resourcely, who will soothe your Terraform pains. Founder and CEO Tracis McPeak joins to talk about how to get from a very red dashboard full of cloud problems to a workable future.

      This episode is also available on Youtube.

      Show notes
      • Exploiting Copilot AI for SharePoint | Pen Test Partners
      • MrBruh's Epic Blog
      • Ransomware group Lockbit appears to have been hacked, analysts say | Reuters
      • "CONTI LEAK: Video they tried to bury! 6+ Conti members on a private jet. TARGET’s birthday — $10M bounty on his head. Filmed by TARGET himself. Original erased — we kept a copy."
      • Mysterious hackers who targeted Marks and Spencer's computer systems hint at political allegiance as they warn other tech criminals not to attack former Soviet states
      • The organizational structure of ransomware groups is evolving rapidly.
      • SAP NetWeaver exploitation enters second wave of threat activity
      • China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures
      • DOGE software engineer’s computer infected by info-stealing malware
      • Hackers hijack Japanese financial accounts to conduct nearly $2 billion in trades
      • FBI and Dutch police seize and shut down botnet of hacked routers
      • Poland arrests four in global DDoS-for-hire takedown
      • School districts hit with extortion attempts after PowerSchool breach
      • EU launches vulnerability database to tackle cybersecurity threats
      • Training Solo - vusec
      • Branch Privilege Injection: Exploiting Branch Predictor Race Conditions – Computer Security Group
      • Remote Exploitation of Nissan Leaf: Controlling Critical Body Elements from the Internet
      • PSIRT | FortiGuard Labs
      • EPMM Security Update | Ivanti
      Show More Show Less
      58 mins
    • Wide World of Cyber: How state adversaries attack security vendors
      May 9 2025

      In this edition of the Wide World of Cyber podcast Patrick Gray talks to SentinelOne’s Steve Stone and Alex Stamos about how foreign adversaries are targeting security vendors, including them.

      From North Korean IT workers to Chinese supply chain attacks, SentinelOne and its competitors are constantly fending off sophisticated hacking campaigns.

      This edition of the Wide World of Cyber was recorded in front of a live audience in San Francisco, with Patrick attending via Zoom.

      The Wide World of Cyber podcast series is a wholly sponsored co-production between SentinelOne and Risky Business Media.

      This episode is also available on Youtube.

      Show notes
        Show More Show Less
        53 mins
      • Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate
        May 7 2025
        On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news: White House’s off-brand Israeli Signal fork logs cleartext messages with hard coded creds while getting hacked (twice). Just … Wow.Ransomware attacks on UK retailers are linked, and Marks & Spencer has it extra badAfter six years dormant, a Magento eCommerce platform backdoor comes to lifeThe North Korean IT worker scam is truly webscaleNSO group owes Meta $168m for hacking WhatsApp This week’s episode is sponsored by vulnerability management wranglers, Nucleus Security. Aaron Unterberger joins to talk through the complexities of tracking vulnerabilities in cloud components - left to the source, right to the deployments, and …sideways into the sidecars? This week’s show also features an excerpt from Pat’s interview with Senator Mark Warner - Scoot back one in your podcast feed to check out the full chat, or find it on Youtube. This episode is available on Youtube too. Show notes Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal MessagesDespite misleading marketing, Israeli company TeleMessage, used by Trump officials, can access plaintext chat logsThe Signal Clone the Trump Admin Uses Was HackedApp used by Mike Waltz suspends services after hacking claimsSenator Demands Investigation into Trump Admin Signal Clone After 404 Media InvestigationMG on X: "Looks like TeleMessage was probably procured and rolled out under Biden. There are public records for it. https://t.co/XCuZpi8PL3" / XHarrods becomes latest retailer to announce attempted cyberattack | The Record from Recorded Future NewsCo-op DragonForce cyber attack includes customer data, firm admitsCo-op cyber attack: Staff told to keep cameras on in meetingsHundreds of e-commerce sites hacked in supply-chain attack - Ars TechnicaMicrosoft’s new “passwordless by default” is great but comes at a cost - Ars TechnicaWindows RDP lets you log in using revoked passwords. Microsoft is OK with that. - Ars TechnicaNorth Korean operatives have infiltrated hundreds of Fortune 500 companies | CyberScoopUS wants to cut off key player in Southeast Asian cybercrime industry | The Record from Recorded Future NewsMyanmar militia leader sanctioned by US over cyber scam connections | The Record from Recorded Future NewsTrump proposes major cut to CISA’s budget, citing false ‘censorship’ claims | Cybersecurity DiveNSA to cut up to 2,000 civilian roles as part of intel community downsizing | The Record from Recorded Future NewsNSO Group owes $168M in damages to WhatsApp over spyware infections, jury says | CyberScoop
        Show More Show Less
        56 mins
      • BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs
        May 6 2025

        In this extended interview the Vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner, joins Risky Business host Patrick Gray to talk about:

        • The latest developments in the Signalgate scandal
        • Why America needs to be more aggressive in responding to Volt Typhoon
        • How tariffs are affecting American alliances
        • Why the Five Eyes alliance is sacrosanct

        This episode is available on Youtube

        Show notes
          Show More Show Less
          50 mins
        • Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful
          Apr 30 2025
          On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news: British retail stalwart Marks & Spencer gets cyberedSouth Korean telco sets out to replace all its subscriber SIMs after (we assume) it lost the keymatIt’s a good exploit week! Bugs in Apple Airplay, SAP webservers, Erlang SSH and CommVault backupsJuice jacking! No, really! Some researchers actually did it (so still not in the wild, then)Anti-DOGE whistleblower sure sounds like he has a point This week’s episode is sponsored by Knocknoc, who let you glue your firewalls to your single sign on. Knocknoc’s CEO Adam Pointon talks about the joy that having end-to-end IPv6 would bring for zero-trust access control. He also touches on people using Knocknoc inside their network to isolate critical systems. Editors Note : Pat also gives Adam (Boileau) stick in the sponsor interview about the Risky Biz webserver not having IPv6 enabled, which fact-checking during the edit says is FAKE NEWS. Just uh, don’t look at how fresh that AAAA record in the DNS is, friends 😉 This episode is also available on Youtube. Show notes British retailer M&S confirms being hit by ‘cyber incident’ amid store delays | The Record from Recorded Future NewsM&S cyber-attack linked to hacking group Scattered Spider | Marks & Spencer | The GuardianBina Puri shares, Warrant B close sharply lower day after hackingBina Puri, Pos Malaysia tumble following hacking incident | FMTJapan warns of hundreds of millions of dollars in unauthorized trades from hacked accounts | The Record from Recorded Future NewsUS conducts cyberattacks against major Chinese commercial encryption provider: report - Global TimesIran says major cyberattack on infrastructure repelled | Iran InternationalSpain rules out cyber attack - but what could have caused power cut?South Korea's SK Telecom begins SIM card replacement after data breachAirBorne: Wormable Zero-Click RCE in Apple AirPlay Puts Billions of Devices at Risk | Oligo Security | Oligo SecurityiOS and Android juice jacking defenses have been trivial to bypass for years - Ars TechnicaHow Android 16's new security mode will stop USB-based attacks - Android AuthorityResearchers warn of critical flaw found in Erlang OTP SSH | Cybersecurity DiveCritical vulnerability in SAP NetWeaver under threat of active exploitation | Cybersecurity DiveCVE-2025-31324: Critical SAP Flaw Explained | StrobesFire In The Hole, We’re Breaching The Vault - Commvault Remote Code Execution (CVE-2025-34028)Risky Bulletin: NFC card malware keeps evolving in Russia, a bad omen for the future - Risky Business MediaHegseth had unsecured internet line in Pentagon for Signal, sources say | AP NewsWhistleblower: DOGE Siphoned NLRB Case Data – Krebs on Security2025_0414_Berulis-Disclosure-with-Exhibits.s.pdfCISA gets a deputy director as it braces for major layoffs | Cybersecurity DiveTwo top cyber officials resign from CISA | The Record from Recorded Future NewsEx-CISA chief Chris Krebs leaving SentinelOne following Trump pressure | ReutersFormer cyber official targeted by Trump speaks out after cuts to digital defenseTop Tier Target | What It Takes to Defend a Cybersecurity Company from Today's Adversaries | SentinelOneZachXBT on X: "Nine hours ago a suspicious transfer was made from a potential victim for 3520 BTC ($330.7M)"
          Show More Show Less
          1 hr and 3 mins
        • Snake Oilers: LimaCharlie, Honeywell Cyber Insights, CobaltStrike and Outflank
          Apr 28 2025

          In this edition of the Snake Oilers podcast, three sponsors come along to pitch their products:

          • LimaCharlie: A public cloud for SecOps
          • Honeywell Cyber Insights: An OT security/discovery solution
          • Fortra’s CobaltStrike and Outflank: Security tooling for red teamers

          This episode is also available on Youtube.

          Show notes
            Show More Show Less
            39 mins