Risky Business
Risky Business Media
0
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, it is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Jaksot
-
Risky Business #853 -- We're all gonna die, apparently 16.09.2026 59minOn this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including: More tech guys penned more open letters and AI will destroy us all! Another Wednesday, another congregation of OpenAI agents on wikis… yawn OpenAI agents were behind the headscratching RubyGems hacking campaign in May The FBI will disrupt more adversary operations, NSA is creating more mission centres, lawmakers want sanctions on hackers-for-hire… Release more hounds! So many platforms, so many bugs, so many patches breaking other stuff Much, much more… This week’s show is brought to you by Airlock Digital. Its co-founders Daniel Schell and David Cottingham join Patrick to talk about how Airlock has integrated itself with Crowdstrike via its Falcon Foundry platform. This episode is also available on YouTube -
Snake Oilers: watchTowr, XBOW and CoreView 11.09.2026 42minIn this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do? XBOW: The AI pentesting company pitches its approach CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView! This episode is also available on YouTube. -
Risky Business #852 -- Cyber Command wants to buy shells 09.09.2026 1t 3minOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including: ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits The US government plans to pay private contractors to conduct military hacks The US accuses China of distillation attacks, a.k.a. forbidden training It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki Much, much more… This week’s show is brought to you by Sublime Security. Sublime’s head of detection engineering Randy Pargman joins the show to chat about how the company is preparing for prompt injection attacks to move from being largely theoretical to commonplace. This episode is also available on YouTube -
Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms 02.09.2026 58minOn this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including: Two alleged TeamPCP hackers got arrested in Australia The White House has a plan to boost security for water facilities, but we can’t see it working OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots Much, much more… This week’s show is brought to you by Ent AI. Co-founder Brandon Dixon joins Pat to talk through some of the absolutely wild fraud and abuse the company’s endpoint security tool is finding when it’s deployed inside large organisations. This episode is also available on YouTube -
Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs 26.08.2026 1t 2minOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including: Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too. Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet Prompt injection isn’t going away LLMs are deceiving us meat sacks and it’s a worry Much, much more… This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line. This episode is also available on YouTube -
Risky Business #849 -- Trump will unleash contractors on cybercriminals 19.08.2026 59minOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including: Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing Anthropic’s models start a turf war when given the same task, surprising… nobody We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something. Much, much more This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper. This episode is also available on YouTube -
Soap Box: Zero Trust(ish) Networks 14.08.2026 29minIn this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture. Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049. Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible. Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp. This episode is also available on YouTube -
Risky Business #848 -- OpenAI comes clean 12.08.2026 59minOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including: The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed It turns out TeamPCP has been around longer than we thought and predates the AI era Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways Much, much more This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler. This episode is also available on YouTube -
Risky Business #847 -- Oops! Claude's accidental hacking spree 05.08.2026 1t 8minOn this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is so chaotic, Microsoft can’t patch fast enough A ColdCard wallet flaw led to millions in Bitcoin theft, but the back story behind the bug is bonkers Iran hacks and disrupts water infrastructure in multiple American states North Korea’s state-backed hackers turn criminal. Or their criminals turn into state-backed hackers. Or something. It’s all a bit confusing, actually. Much, much more! This week’s show is brought to you by Sondera. Co-founder Josh Devon joins Patrick and James to talk through some absolutely hilarious LLM horror stories. This episode is also available on YouTube -
Risky Business #846 -- OpenAI built a fireplace out of wood 29.07.2026 1t 2minOn this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Everyone signs the open weights open letter, except Anthropic… of course. OpenAI had no idea it had hacked Hugging Face Kimi K3 open weights released and they’re massive! Why a more aggressive response is needed to cyber attacks on OT And much, much more! This week’s show is brought to you by SpecterOps. In this week’s sponsor interview Justin Kohler and Jared Atkinson talk about how SpecterOps’ Bloodhound now supports AWS attack paths. Run it against your AWS infra, but only if you have a strong stomach. The results will terrify you. This episode is also available on YouTube. -
Risky Business #845 -- OpenAI's Skynet moment 22.07.2026 1t 9minOn this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just because of Microsoft’s GDID And much, much more! This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it. This episode is also available on YouTube. -
Soap Box: Using threat hunting to drive detection 08.07.2026 35minIn this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections. This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you’re going to build a good graph, do you want to build it for a person to use, or an agent to use? This is truly a conversation for the security nerd’s nerd. Enjoy! This episode is also available on YouTube -
Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban 01.07.2026 1tOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail Distillation, cheap tokens, and AI chat harvesting is an industry in China Edge becomes a lolbin via a new malicious extension An Iranian APT boss’s vacation in a beautiful place goes wrong Much, much more! In this week’s sponsor interview Daf Stuttard and Katie Warren from Portswigger pop along to talk about how they built an AI security testing product that people would actually feel comfortable using. This episode is also available on YouTube. -
Risky Business #843 -- Fortibleed is kinda awesome, actually 24.06.2026 1t 3minOn this week’s show special guest co-host Rob Joyce joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Rob served as an advisor to Donald Trump during his first term as president and also served at NSA for 34 years. While at the agency, Joyce led Tailored Access Operations (TAO), and later became NSA’s Director of Cybersecurity. They cover: The surprisingly well done Fortibleed campaign Stolen Klue OAuth tokens lead to Salesforce data theft OpenAI wants to patch the planet runZero gets acquired by Accenture, congrats HD Moore! Much, much more! This episode is also available on YouTube. -
Risky Business #842 -- Anthropic needs an adult in the C suite 17.06.2026 59minOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security” Why “guardrails” won’t keep the world safe from your AI doomsday machine The FISA 702 statute expired, but the spying can (probably) continue! NPM v12 delivers some protection against supply chain attacks, but not enough. Microsoft has a series of bugs that prevent Windows Update from … updating Much, much more! This episode is also available on YouTube -
Risky Business #841 -- Microsoft gets owned and 0day'd 10.06.2026 1t 3minOn this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on them Meanwhile, researchers are choosing full disclosure instead of engaging MSRC Meta’s AI support agent allowed a staggering 20,000 accounts to be stolen! Apple pulls Russia’s MAX messenger from the App Store and disables notifications Anthropic gives the public our first Mythos-class model but it won’t do cybersecurity work Stripe and Google Tag Manager used in eCommerce website hack campaign And much, much more! This week’s show is brought to you by runZero. HD Moore, runZeros’ founder, drops by in this week’s sponsor interview to talk about the AI vibe shift. Everyone is very worried about getting owned all of a sudden, and it’s really changing the cybersecurity business. This episode is also available on YouTube. -
Soap Box: Detection and response in the AI age 05.06.2026 36minIn this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Edward Wu, founder of Dropzone, about what AI is doing to detection, response and the SOC more generally. Dropzone makes AI agents that conduct alert investigations in your SOC, but will the SOC as we know it even exist in the future? Ed has a deep expertise in SOC tech, having previously led AI/ML detection engineering at Extrahop. This interview is a fantastic look at what the future may bring for detection and response professionals. This episode is also available on YouTube -
Risky Business #840 -- Microsoft walks back researcher threats 03.06.2026 1t 6minOn this week’s show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution. They cover: Adversaries are tracking US troop locations with commercially available location data A new Signal phishing campaign is going after message backups 404 Media is suing ICE to get its spyware contract with REDLattice (lol) Microsoft’s tone-deaf response to ‘never justifiable’ zero-day disclosures Mini Shai-Hulud pops up again just as Glassworm gets shattered Much, much more This week’s episode is sponsored by Authentik, an open source identity platform that you can host yourself. In this week’s sponsor interview Authentik’s CEO Fletcher Heisler joins Patrick Gray to talk about how they’re keeping up with the bugpocalypse, and also the work they’re doing to support identities for AI agents. This episode is also available on YouTube. -
Risky Business #839 -- TeamPCP stole GitHub's internal repos 27.05.2026 1tOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Much, much more This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun! This episode is also available on YouTube -
Risky Business #838 -- GitHub investigates possible breach 20.05.2026 1t 2minOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: GitHub announced a possible breach CISA leaks important creds, keys in public repo Awful vulnerability in Bitlocker renders it useless without a PIN So. Many. Patches. Polish Government urges officials to ditch Signal for mSzyfr Much, much more This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy. This episode is also available on YouTube.
Suosittu maassa
Tämä podcast esiintyy myös näiden maiden podcast-listoilla.