Explore every episode of the podcast Risky Business
Dive into the complete episode list for Risky Business. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
Rows per page:
50
1–50 of 100
Title
Pub. Date
Duration
Risky Business #782 -- Are the USA and Russia cyber friends now?
05 Mar 2025
00:50:12
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Did the US decide to stop caring about Russian cyber, or not?
Adam stans hard for North Korea’s massive ByBit crypto-theft
Cellebrite firing Serbia is an example of the system working
Starlink keeps scam compounds in Myanmar running
Biggest DDoS botnet yet pushes over 6Tbps
This week’s episode is sponsored by network visibility company Corelight. Vincent Stoffer, field CTO at Corelight joins to talk through where eyes on your network can spot attackers like Salt and Volt Typhoon.
Risky Business #783 -- Evil webcam ransomwares entire Windows network
12 Mar 2025
01:03:40
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news with special guest Rob Joyce, a Former Special Assistant to the US President and Director of Cybersecurity for NSA.
They talk through:
A realistic bluetooth-proximity phishing attack against Passkeys
A very patient ransomware actor encrypts an entire enterprise with a puny linux webcam processor
The ESP32 backdoor that is neither a door nor at the back
The X DDoS that Elon said was Ukraine is claimed by pro-Palestinian hacktivists
Years later, LastPass hackers are still emptying crypto-wallets
…and it turns out North Korea nailed {Safe}Wallet with a malicious docker image. Nice!
Rob Joyce recently testified to the US House Select Committee on the Chinese Communist Party, and he explains why DOGE kicking probationary employees to the curb is “devastating” for the national security staff pipeline.
This week’s episode is sponsored by SpecterOps, makers of the BloodHound identity attack path mapping tool. Chief Product Officer Justin Kohler and Principal Security Researcher Lee Chagolla-Christensen discuss their pragmatic approach to disabling NTLM authentication in Active Directory using BloodHound’s insight.
Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
19 Mar 2025
00:56:58
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Github Actions supply chain attack loots keys and secrets from 23k projects
Why a VC fund now owns a minority stake in Risky Business Media (!?!?)
China doxes Taiwanese military hackers
Microsoft thinks .lnk file whitespace trick isn’t worth patching but APTs sure love it
CISA delivers government efficiency by re-hiring fired staff… to put them on paid leave
…and Google acquires Wiz for $32bn
This week’s show is sponsored by Zero Networks, and they have sent along a happy customer to talk about their experience. Aaron Steinke is Head of Infrastructure at La Trobe Financial, an asset management firm in Australia. Aaron talks through bringing modern zero-trust goodness to the reality of a technology environment that’s been around 40 years.
Soap Box: Knocknoc glues your SSO to your firewalls for Just-in-Time network access
26 Mar 2025
00:30:46
In this Soap Box edition of Risky Business host Patrick Gray talks to Knocknoc CEO Adam Pointon about how to easily rein in attack surface by glueing your single sign-on service to your network controls.
Do your Palo Alto and Fortinet devices really need to be discoverable by ransomware crews? Does your file transfer appliance need to be open to the whole world? What about your SSH and RDP? Your Citrix? Your (gasp) Exchange Online servers??
You can do a lot with IP allowlisting and simple Identity Aware Proxies (IAPs) to minimise your exposure.
Knocknoc is a bit of a “Risky Business special”, too. Pat helped Knocknoc to raise a seed round through Decibel Partners where he’s a founder advisor. He also serves on Knocknoc’s board of directors.
Risky Business #785 -- Signal-gate is actually as bad as it looks
26 Mar 2025
00:59:05
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Yes, the Trump admin really did just add a journo to their Yemen-attack-planning Signal group
The Github actions hack is smaller than we thought, but was targeting crypto
Remote code exec in Kubernetes, ouch
Oracle denies its cloud got owned, but that sure does look like customer keymat
Taiwanese hardware maker Clevo packs its private keys into bios update zip
US Treasury un-sanctions Tornado Cash, party time in Pyongyang?
This week’s episode is sponsored by runZero. Long time hackerman HD Moore joins to talk about how network vulnerability scanning has atrophied, and what he’s doing to bring it back en vogue. Do you miss early 2000s Nessus? HD knows it, he’s got you fam.
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Yes, Oracle Health and Oracle Cloud did get hacked
The fallout from Signalgate continues
North Korean IT workers pivot to Europe
Honeypot data suggests a storm is brewing for Palo Alto VPNs
Canadian Anon gets arrested for hacking Texas GOP
This week’s episode is sponsored by Trail of Bits. Tjaden Hess, a Principal Security Engineer at Trail of Bits who specialises in cryptography, joins the show this week to talk about what a responsible crypto-currency exchange cold wallet setup looks like, and … contrasts that with Bybit.
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Oracle quietly cops to being hacked, but immediately pivots into pretending it didn’t matter
NSA and CyberCom leaders fired for not being MAGA enough
US Treasury had some dusty corners it hadn’t found China in yet, looked, found China in them
…which is a great time to discuss slashing CISA’s staffing
Ransomware crews and bullet proof hosting providers are getting rekt, and we love it
And Microsoft patches yet another logging 0-day being used in the wild.
This episode is sponsored by Yubico, makers of Yubikey hardware authentication tokens. Yubico’s Vice President of Solutions Architecture and Alliances Derek Hanson joins to discuss how the consumer-centric passkey ecosystem has become a real challenge for enterprises. One that Yubico is actually ideally positioned to solve.
Risky Business #788 -- Trump targets Chris Krebs, SentinelOne
16 Apr 2025
00:53:35
On this week’s show Patrick Gray talks to former NSA Cybersecurity Director Rob Joyce about Donald Trump’s unprecedented, unwarranted and completely bonkers political persecution of Chris Krebs and his employer SentinelOne.
They also talk through the week’s cybersecurity news, covering:
Mitre’s stewardship of the CVE database gets its funding DOGE’d
The US signs on to the Pall Mall anti-spyware agreement
China tries to play the nationstate cyber-attribution game, but comedically badly
Hackers run their malware inside the Windows sandbox, for security against EDR
This week’s episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins to talk through the increasing sprawl of the identity ecosystem.
In this edition of Snake Oilers three vendors pitch host Patrick Gray on their tech:
Pangea: Guardrails and security for AI agents and applications (https://pangea.cloud)
Worried about your AI apps going rogue, being mean to your customers or even disclosing sensitive information? Pangea exists to address these risks. Fascinating stuff.
Cosive: A threat intelligence company that can host your MISP server in AWS. CloudMISP! (https://www.cosive.com/snakeoilers)
Are you running a MISP server on some old hardware under a desk in your SOC? There’s a better way! Cosive can run it for you on AWS so you can just use it instead of wrestling with maintaining it. They also do some CTI consulting to help you get better use out of MISP.
Sysdig: A Linux runtime security platform (https://sysdig.com/)
The modern Windows network is an all-singing, all-dancing, perfectly orchestrated, EDR-protected ballet. The modern Linux production environment… isn’t. Find out how Sysdig can help you get some visibility and control over your Linux fleet.
Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape
10 Apr 2025
00:43:29
In this podcast, Patrick Gray chats with SentinelOne’s Chris Krebs and Alex Stamos about the huge changes afoot in the United States government and what they mean for the threat environment. From the director of NSA being fired to massive job cuts at CISA and huge foreign policy shifts, tomorrow’s threat environment is going to be very different to today’s. Tune in to hear analysis from two of the best in the business!
Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful
30 Apr 2025
01:02:31
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
British retail stalwart Marks & Spencer gets cybered
South Korean telco sets out to replace all its subscriber SIMs after (we assume) it lost the keymat
It’s a good exploit week! Bugs in Apple Airplay, SAP webservers, Erlang SSH and CommVault backups
Juice jacking! No, really! Some researchers actually did it (so still not in the wild, then)
Anti-DOGE whistleblower sure sounds like he has a point
This week’s episode is sponsored by Knocknoc, who let you glue your firewalls to your single sign on. Knocknoc’s CEO Adam Pointon talks about the joy that having end-to-end IPv6 would bring for zero-trust access control. He also touches on people using Knocknoc inside their network to isolate critical systems.
Editors Note : Pat also gives Adam (Boileau) stick in the sponsor interview about the Risky Biz webserver not having IPv6 enabled, which fact-checking during the edit says is FAKE NEWS. Just uh, don’t look at how fresh that AAAA record in the DNS is, friends 😉
Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate
07 May 2025
00:56:12
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
White House’s off-brand Israeli Signal fork logs cleartext messages with hard coded creds while getting hacked (twice). Just … Wow.
Ransomware attacks on UK retailers are linked, and Marks & Spencer has it extra bad
After six years dormant, a Magento eCommerce platform backdoor comes to life
The North Korean IT worker scam is truly webscale
NSO group owes Meta $168m for hacking WhatsApp
This week’s episode is sponsored by vulnerability management wranglers, Nucleus Security. Aaron Unterberger joins to talk through the complexities of tracking vulnerabilities in cloud components - left to the source, right to the deployments, and …sideways into the sidecars?
This week’s show also features an excerpt from Pat’s interview with Senator Mark Warner - Scoot back one in your podcast feed to check out the full chat, or find it on Youtube.
BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs
06 May 2025
00:49:44
In this extended interview the Vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner, joins Risky Business host Patrick Gray to talk about:
The latest developments in the Signalgate scandal
Why America needs to be more aggressive in responding to Volt Typhoon
Wide World of Cyber: How state adversaries attack security vendors
09 May 2025
00:52:42
In this edition of the Wide World of Cyber podcast Patrick Gray talks to SentinelOne’s Steve Stone and Alex Stamos about how foreign adversaries are targeting security vendors, including them.
From North Korean IT workers to Chinese supply chain attacks, SentinelOne and its competitors are constantly fending off sophisticated hacking campaigns.
This edition of the Wide World of Cyber was recorded in front of a live audience in San Francisco, with Patrick attending via Zoom.
The Wide World of Cyber podcast series is a wholly sponsored co-production between SentinelOne and Risky Business Media.
Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys
14 May 2025
00:57:52
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Struggling to find that pesky passwords.xlsx in Sharepoint? Copilot has your back!
The ransomware ecosystem is finding life a bit tough lately
SAP Netweaver bug being used by Chinese APT crew
Academics keep just keep finding CPU side-channel attacks
And of course… bugs! Asus, Ivanti, Fortinet… and a Nissan LEAF?
This week’s episode is sponsored by Resourcely, who will soothe your Terraform pains. Founder and CEO Tracis McPeak joins to talk about how to get from a very red dashboard full of cloud problems to a workable future.
Risky Biz Soap Box: Push Security's browser-first twist on identity security
15 May 2025
00:34:24
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.
Push has built an identity security platform that collects identity information and events from your users’ browsers. It can detect phish kits and shut down phishing attempts, protect SSO credentials, and find shadow/personal account that a user has spun up.
It’s extremely difficult to bypass. That’s because when you’re in the browser it doesn’t matter how a phishing link arrives, or how a threat actor has concealed it from your detection stack – if the user sees it, Push sees it.
There are solutions for protecting your users SSO credentials, like passkeys. But what about all the SaaS in your environment? Even if it’s enrolled into your SSO, are you sure that’s how your users are authenticating to it? What about the automation platforms your developers and admins use? What about data platforms like Snowflake? Are your using setting up passkeys for those accounts? How would you know, and what problems can it cause if those accounts are vulnerable?
Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now
21 May 2025
00:53:01
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
TeleMessage memory dumps show up on DDoSecrets
Coinbase contractor bribed to hand over user data
Telegram does seem to be actually cooperating with law enforcement
Britain’s legal aid service gets 15 years worth of applicant data stolen
Shocking no one, Ivanti were weaseling when they blamed latest bugs on a third party library
This week’s episode is sponsored by Prowler, who make an open source cloud security tool. Founder and original project developer Toni de la Fuente joins to talk through the flexibility that open tooling brings. Prowler is also adding support for SaaS platforms like M365, and of course, an AI assistant to help you write checks!
Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242
04 Jun 2025
00:58:22
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Cyber firms agree to deconflict and cross-reference hacker group names
Russian nuclear facility blueprints gathered from public procurement websites
Someone audio deepfaked the White House Chief of Staff, but for the dumbest reasons
Germany identifies the Trickbot kingpin
Google spots China’s MSS using Calendar events for malware C2
Meta apps abuse localhost listeners to track web sessions.
This week’s episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss an open letter penned by JP Morgan Chase’s CISO that pleads with Software as a Service suppliers to try to suck less at security.
Risky Business #793 -- Scattered Spider is hijacking MX records
28 May 2025
01:04:52
In this week’s edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the week’s news, including:
EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes
The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed
Brian Krebs eats a 6.3Tbps DDoS … ‘cause that’s how you demo your packet cannon
Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers
Iranian behind 2019 Baltimore ransomware mysteriously appears in North Carolina and pleads guilty
CISA’s leadership is fleeing in droves, even though the US needs them more than ever.
This week’s episode is sponsored by Thinkst Canary. Long time friend of the show Haroon Meer joins and talks through where he feels the industry is at, having just returned home from the AI-fueled hype at this year’s RSA conference.
Risky Business #795 -- How The Com is hacking Salesforce tenants
11 Jun 2025
01:07:34
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
New York Times gets a little stolen Russian FSB data as a treat
iVerify spots possible evidence of iOS exploitation against the Harris-Walz campaign
Researcher figures out a trick to get Google account holders’ full names and phone numbers
Major US food distributor gets ransomwared
The Com’s social engineering of Salesforce app authorisations is a harbinger of our future problems
Australian Navy forgets New Zealand has computers, zaps Kiwis with their giant radar.
This week’s episode is sponsored by identity provider Okta. Long-time friend of the show Alex Tilley is Okta’s Global Threat Research Coordinator, and he joins to discuss how organisations can use both human and technical signals to spot North Koreans in their midst.
Soap Box: AI has entered the SOC, and it ain't going anywhere
16 Jun 2025
00:30:58
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Dropzone AI founder Ed Wu about the role of LLMs in the SOC.
The debate about whether AI agents are going to wind up in the SOC is over, they’ve already arrived. But what are they good for? What are they NOT good for? And where else will we see AI popping up in security?
Risky Business #796 -- With special guest co-host Chris Krebs
18 Jun 2025
01:01:04
On this week’s show Patrick Gray and Adam Boileau are joined by special guest Chris Krebs to discuss the week’s cybersecurity news. They talk through:
Israeli “hacktivists” take out an Iranian state-owned bank
Scattered-spider and friends pivot into attacking insurers
Securing identities in a cloud-first world keeps us awake at night
Microsoft takes the “aas” out of SaaS for Europe, leaving us with just software!
An AI prompt injection into M365 exfils corporate data
This week’s episode is sponsored by Kroll’s Cyber practice. Kroll Cyber Associate Managing Director George Glass is based in London and talks through his experiences helping organisations in the UK deal with the Scattered Spider attacks.
Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses
02 Jul 2025
01:02:19
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Australian airline Qantas looks like it got a Scattered Spider-ing
Microsoft works towards blunting the next CrowdStrike disaster
Changes are coming for Microsoft’s default enterprise app consenting setup
Synology downplays hardcoded passwords for its M365 cloud backup agent
The next Citrix Netscaler memory disclosure looks nasty
Drug cartels used technical surveillance to find, fix and finish FBI informants and witnesses
This week’s episode is sponsored by RAD Security. Co-founder Jimmy Mesta joins to talk through how they use AI automation to assess the security posture of sprawling cloud environments.
Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators
25 Jun 2025
01:02:16
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
We roll our eyes over the “16 billion credentials” leak hitting mainstream news
Some interesting cyber angles emerge from the conflict in Iran
Opensource maintainer of libxml2 is fed up with this hacker crap
Shockingly, there are yet more ways to trick people into pasting commands into Windows
Veeam “patches” its backup software RCE like it’s 2002 … by breaking the public PoC
This week’s episode is sponsored by Internet-wide honeypot reconnaissance platform, Greynoise. Founder Andrew Morris joins to talk about their journey spotting Chinese ORB-builders hacking thousands of ASUS routers, and why they’re destined for the woodchipper.
Risky Biz Soap Box: Prowler, the open cloud security platform
14 Jul 2025
00:32:08
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, founder of open source multi-cloud security product Prowler.
Toni explains how Prowler came to be, and how its journey followed his own learning about the cloud. The pair also discuss Prowler’s successful transition from an open-source project into a community, and now a growing business with an as-a-service platform.
Risky Business #799 -- Everyone's Sharepoint gets shelled
23 Jul 2025
01:13:55
Risky Biz returns after two weeks off, and there sure is cybersecurity news to catch up on. Patrick Gray and Adam Boileau discuss:
Microsoft tried to make outsourcing the Pentagon’s cloud maintenance to China okay (it was not)
She shells Sharepoint by the sea-shore (by ‘she’ we mean ‘China’)
Four (alleged) Scattered Spider members arrested (and bailed) in the UK
Hackers spend $2700 to buy creds for a Brazilian payment system, steal $100M
Fortinet has SQLI in the auth header, Citrix mem leak is weaponised, HP hardcodes creds and Sonicwalls get user-moderootkits. Just security vendor things!
This week’s episode is sponsored by Airlock Digital. CEO David Cottingham talks through what it takes to build a mature, resilient management platform for a security critical system.
In this Soap Box edition of the show Patrick Gray chats with the CEO of email security company Sublime Security, Josh Kamdjou. They talk about where AI is useful, where it isn’t, and why AI can’t save vendors from their bad product design choices.
Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP
30 Jul 2025
00:53:37
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Did the SharePoint bug leak out of the Microsoft MAPP program?
Expel retracts its FIDO bypass writeup
The mess surrounding the women-only dating-safety app Tea gets worse
Broadcom customers struggle to get patches for VMWare hypervisor escapes
Aeroflot gets hacked by the Cyber Partisans, disrupting flights
This week’s episode is sponsored by Push Security. Daniel Cuthbert joins and explains how having telemetry about identity from inside the browser is a key pillar for investigating intrusions in the browser-centric future.
Risky Business #801 -- AI models can hack well now and it's weirding us out
06 Aug 2025
01:06:01
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news. Google security engineering VP Heather Adkins drops by to talk about their AI bug hunter, and Risky Business producer Amberleigh Jack makes her main show debut.
This episode explores the rise of AI-powered bug hunting:
Google’s Project Zero and Deepmind team up to find and report 20 bugs to open source projects
The XBOW AI bug hunting platform sees success on HackerOne
Is an AI James Kettle on the horizon?
There’s also plenty of regular cybersecurity news to discuss:
On-prem Sharepoint’s codebase is maintained out of China… awkward!
China frets about the US backdooring its NVIDIA chips, how you like ‘dem apples, China?
SonicWall advises customers to turn off their VPNs
Hardware controlling Dell laptop fingerprint and card readers has nasty driver bugs
Russia uses its ISPs to in-the-middle embassy computers and backdoor ‘em.
The Russian government pushes VK’s Max messenger for everything
This week’s show is sponsored by device management platform Devicie. Head of Solutions Sean Ollerton talks through the impending Windows 10 apocalypse, as Microsoft ends mainstream support. He says Windows 11 isn’t as scary as people make out, but if the update isn’t on your radar now, time is running out.
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds
13 Aug 2025
01:00:00
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
CISA warns about the path from on-prem Exchange to the cloud
Microsoft awards a crisp zero dollar bill for a report about what a mess its internal Entra-authed apps are
Everyone and their dog seems to have a shell in US Federal Court information systems
Google pays $250k for a Chrome sandbox escape
Attackers use javascript in adult SVG files to … farm facebook likes?!
SonicWall says users aren’t getting hacked with an 0day… this time.
This week’s episode is sponsored by SpecterOps. Chief product officer Justin Kohler talks about how the flagship Bloodhound tool has evolved to map attack paths anywhere. Bring your own applications, directories and systems into the graph, and join the identity attacks together.
Risky Biz Soap Box: How to measure vulnerability reachability
14 Aug 2025
00:35:48
In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications.
It’s great to know there’s a CVE in a library you’re using, but it’s even better if you can say whether or not that vulnerability actually impacts your application.
They also talk about how Socket started out as a way to discover malicious packages in software projects, but these days it’s playing the CVE game as well.
Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms
02 Sep 2026
00:58:38
On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including:
Two alleged TeamPCP hackers got arrested in Australia
The White House has a plan to boost security for water facilities, but we can’t see it working
OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief
Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots
Much, much more…
This week’s show is brought to you by Ent AI. Co-founder Brandon Dixon joins Pat to talk through some of the absolutely wild fraud and abuse the company’s endpoint security tool is finding when it’s deployed inside large organisations.
Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
26 Aug 2026
01:02:53
On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
Iranian hackers take down a small-scale power generator in the UK
Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
Prompt injection isn’t going away
LLMs are deceiving us meat sacks and it’s a worry
Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
Risky Business #843 -- Fortibleed is kinda awesome, actually
24 Jun 2026
01:03:35
On this week’s show special guest co-host Rob Joyce joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Rob served as an advisor to Donald Trump during his first term as president and also served at NSA for 34 years. While at the agency, Joyce led Tailored Access Operations (TAO), and later became NSA’s Director of Cybersecurity.
They cover:
The surprisingly well done Fortibleed campaign
Stolen Klue OAuth tokens lead to Salesforce data theft
OpenAI wants to patch the planet
runZero gets acquired by Accenture, congrats HD Moore!
Risky Business #841 -- Microsoft gets owned and 0day'd
10 Jun 2026
01:03:02
On this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news.
They cover:
Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on them
Meanwhile, researchers are choosing full disclosure instead of engaging MSRC
Meta’s AI support agent allowed a staggering 20,000 accounts to be stolen!
Apple pulls Russia’s MAX messenger from the App Store and disables notifications
Anthropic gives the public our first Mythos-class model but it won’t do cybersecurity work
Stripe and Google Tag Manager used in eCommerce website hack campaign
And much, much more!
This week’s show is brought to you by runZero. HD Moore, runZeros’ founder, drops by in this week’s sponsor interview to talk about the AI vibe shift. Everyone is very worried about getting owned all of a sudden, and it’s really changing the cybersecurity business.
In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Edward Wu, founder of Dropzone, about what AI is doing to detection, response and the SOC more generally.
Dropzone makes AI agents that conduct alert investigations in your SOC, but will the SOC as we know it even exist in the future?
Ed has a deep expertise in SOC tech, having previously led AI/ML detection engineering at Extrahop. This interview is a fantastic look at what the future may bring for detection and response professionals.
Risky Business #840 -- Microsoft walks back researcher threats
03 Jun 2026
01:06:03
On this week’s show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution.
They cover:
Adversaries are tracking US troop locations with commercially available location data
A new Signal phishing campaign is going after message backups
404 Media is suing ICE to get its spyware contract with REDLattice (lol)
Microsoft’s tone-deaf response to ‘never justifiable’ zero-day disclosures
Mini Shai-Hulud pops up again just as Glassworm gets shattered
Much, much more
This week’s episode is sponsored by Authentik, an open source identity platform that you can host yourself. In this week’s sponsor interview Authentik’s CEO Fletcher Heisler joins Patrick Gray to talk about how they’re keeping up with the bugpocalypse, and also the work they’re doing to support identities for AI agents.
Risky Business #839 -- TeamPCP stole GitHub's internal repos
27 May 2026
01:00:23
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
TeamPCP breached GitHub’s internal repos. Now what?
Some absolute plonker glued Coruna to a hijacked npm package
CISA is worried about about open source and wants third party submissions for KEV
AI infrastructure is “systemically” insecure
Much, much more
This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun!
Risky Business #838 -- GitHub investigates possible breach
20 May 2026
01:02:49
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.
They cover:
GitHub announced a possible breach
CISA leaks important creds, keys in public repo
Awful vulnerability in Bitlocker renders it useless without a PIN
So. Many. Patches.
Polish Government urges officials to ditch Signal for mSzyfr
Much, much more
This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy.
In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.
Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.
Risky Business #837 -- GitHub Actions footgun claims TanStack
13 May 2026
01:05:15
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.
They cover:
Mini Shai-Hulud and the TanStack compromise using Github Actions
Instructure pays Canvas elearning platform data extortionists
More Linux privilege escalation 0days!
CISA helping critical infrastructure operators rearchitect their networks so they work offline
This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.
Risky Business #836 -- You can't patch the bugpocalypse
06 May 2026
01:01:56
On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including:
The US Government says we just have to patch faster, but…
Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn’t enough
James gets mad about lame AI Agent adoption advice from the US and Australian Governments
James Kettle and Niels Provos both showed us that any model can find 0day like Mythos
And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars
This week’s show is sponsored by SpecterOps. Their CTO, Jared Atkinson, chats to Pat about the big changes in the threat landscape, brought about by AI, that are causing a pivot away from detection and remediation, and toward prevention.
Risky Business #849 -- Trump will unleash contractors on cybercriminals
19 Aug 2026
00:59:06
On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:
Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry!
OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing
Anthropic’s models start a turf war when given the same task, surprising… nobody
We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something.
Much, much more
This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper.
Risky Business #835 -- Why the Fast16 malware is badass
29 Apr 2026
01:06:28
On this week’s show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week’s cybersecurity news, including:
The US government is mad as hell about Chinese firms stealing American AI technology
Dmitri has an opinion or two about the US selling Nvidia chips to China
Speaking of Chinese AI, Kimi’s new 2.6 is very interesting
The US sanctions a Cambodian senator for earning mega bucks through scam compounds
And a ransomware family is promoting itself as being … quantum-safe?
This week’s show is sponsored by Trail of Bits. CEO and co-founder Dan Guido chats to Pat about how private inference works and Trail of Bits’ audit of WhatsApp’s private AI setup.
Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs
22 Apr 2026
01:00:33
On this week’s show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week’s cybersecurity news, including:
Vercel got owned, and there’s a few infostealer and compromised employee dots to connect
Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse
Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs?
The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing
And DDos attacks hit a couple of smaller-player socials
This week’s episode is sponsored by Permiso. Ian Ahl chats to Pat about the subtle signals Permiso uses to detect ShinyHunters-style activity in cloud and on-prem environments.
Risky Business #833 -- The Great Mythos Freakout of 2026
15 Apr 2026
00:59:45
On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet
CISA adds a 2009 Excel bug to the KEV list, u wot?
Adobe also parties like it’s the 2000s, and fixes an Acrobat Reader bug
Disgraced former Trenchant exec Peter Williams’ sob story fails to resonate with … anyone
Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were “secured” by the password: 1234.
This week’s episode is sponsored by mobile network operator, Cape. Ajit Gokhale talks with James about the ways to get being a telco right when you’re starting from scratch and solving the security problems of 2026.
Snake Oilers: Burp AI, Sondera and Truffle Security
09 Apr 2026
00:48:00
In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:
Burp AI and DAST: The founder of PortSwigger and creator of legendary security software Burp Suite, Dafydd Stuttard, drops by to pitch listeners on Burp AI and Burp Suite DAST.
Sondera: Josh Devon talks about Sondera, a technology designed to intervene when AI models start doing the wrong thing by statefully tracking their trajectories. This isn’t a permissions suite for AI agents, it’s a way to stick agents in a harness and make sure they adhere to hard policy boundaries.
Truffle Security: Dylan Ayrey, the founder of Truffle Security, joins Risky Business again to talk through the latest bells and whistles in Trufflehog, a security tool that searches for exposed secrets and validates them. The Truffle team has done a lot of work on the remediation part of their product over the last few years, and Dylan tells us all about it!