Risky Bulletin

Risky Bulletin

Risky Business Media
Maa Yhdysvallat
Kieli EN
Jaksot 100
Viimeisin 11.09.2026

Regular cybersecurity news updates from the Risky Business team.

Jaksot

  • Risky Bulletin: Anthropic agents went hacking again 11.09.2026 10min
    Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.
  • Srsly Risky Biz: America's drivers licence breach is a national security disaster 10.09.2026 24min
    Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences. They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough. Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy. This episode is also available on YouTube
  • Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal 09.09.2026 7min
    Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.
  • Between Two Nerds: Can AI defend critical infrastructure? 08.09.2026 27min
    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line. This episode is also available on YouTube.
  • Risky Bulletin: BEC campaign steals €35 million from French notaries 07.09.2026 8min
    Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.
  • Sponsored: Authentik is rethinking PAM for AI agents 07.09.2026 20min
    In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human. They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access.
  • Risky Bulletin: Russia tells data centers to deploy drone defenses 04.09.2026 10min
    Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs.
  • Srsly Risky Biz: China's botnets are worth disrupting 03.09.2026 22min
    Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal! Finally, they discuss efforts to fix US water sector security. Sprinkling free tools on the problem will have limited impact. This episode is also available on YouTube
  • Risky Bulletin: BGP hijack delivers malicious Virtualizor updates 02.09.2026 9min
    A BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness.
  • Between Two Nerds: The perfect hacker 01.09.2026 29min
    In this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals. This episode is also available on YouTube.
  • Risky Bulletin: New powers for Dutch intelligence services 31.08.2026 7min
    Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service.
  • Sponsored: Attackers need to be right more than once 31.08.2026 21min
    In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown jewels”. The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times.
  • Risky Bulletin: Two TeamPCP members arrested in Australia 28.08.2026 10min
    Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic.
  • Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting 27.08.2026 19min
    Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense. This episode is also available on YouTube
  • Risky Bulletin: Russia starts blocking DoH and DoT 26.08.2026 8min
    Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common.
  • Between Two Nerds: Attribution is dead, long live attribution 25.08.2026 32min
    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available on YouTube.
  • Risky Bulletin: Expired credit cards can be used for malicious transactions 24.08.2026 5min
    Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.
  • Sponsored: Passkeys won’t stop authorisation phishing 24.08.2026 20min
    In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if their controls against these attacks actually work.
  • Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs 21.08.2026 6min
    The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great Firewall
  • Srsly Risky Biz: Trump's private hacker memo is the right idea 20.08.2026 31min
    Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disruption operations, but there simply isn’t enough government capacity. So it is time to bring in the private sector. They also discuss Ukraine’s combined cyber and kinetic strikes against Wildberries, the logistics company that is called the Amazon of Russia. These cyber operations didn’t amplify the effects of kinetic strikes, but it is great propaganda to say that they did. This episode is also available on YouTube

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.