Risky Business Media
Risky Business Media
  • Видео 76
  • Просмотров 68 996
Risky Business (777): It's SonicWall's turn
Risky Business #777 -- It's SonicWall's turn
Coming to you from the same room in Risky Business headquarters Patrick Gray and Adam Boileau discuss the week's cybersecurity news. They talk through:
Sonicwall firewalls hand out remote code exec like candy
Mastercard make a slapstick-grade mistake with their DNS
The data breach at PowerSchool and other niche SaaS providers
Academic research proposes taking down Europe's power grid
Apple CPUs get a new speculative execution side channel
And much, much more.
This week's episode is sponsored by Push Security, who make an identity security product that runs inside browsers. Luke Jennings joins to discuss some of the pitfalls of federated authentication...
Просмотров: 708

Видео

Risky Business Weekly (776): Trump will flex America's cyber muscles
Просмотров 78319 часов назад
Risky Business #776 Trump will flex America's cyber muscles Risky Business returns for its 19th year! Patrick Gray and Adam Boileau discuss the week's cybersecurity news and there is a whole bunch of it. They discuss: The incoming Trump administration guts the CSRB Biden's last cyber Executive Order has sensible things in it China's breach of the US Treasury gets our reluctant admiration Ross U...
Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser
Просмотров 428Месяц назад
In this sponsored Soap Box edition of the show Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes. This is largely a conversation about compliance, but it's actually interesting and fun. These are words we never thought we'd type! You can find Island at...
Product demo: The PantherFlow piped query language for the Panther SIEM
Просмотров 142Месяц назад
In this product demo the Panther team join Patrick Gray to walk him through their new piped query language for incident response on the Panther SIEM platform. Panther is a cloud-native SIEM capable of ingesting incredible amounts of data and applying detection-as-code to it in real time. With this new release they've moved into the threat hunting space as well.
Srsly Risky Biz: Why two hats are better than two heads
Просмотров 333Месяц назад
In this podcast Tom Uren and Patrick Gray talk about the likelihood that the incoming Trump administration will end the 'dual-hat' arrangement where a single officer leads both US Cyber Command and the National Security Agency. This would result in Cyber Command outranking NSA and could prioritise cyber disruption operations over intelligence collection. That would be a bad outcome. They also t...
Risky Business Weekly (775): Cl0p is back, SEC hack disclosures disappoint
Просмотров 1 тыс.Месяц назад
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: * The SEC's cyber incident reporting isn't very exciting after all * China Telecom on the way to being thrown out of the US * The NSA/Cybercom might get two separate hats * The Cl0p ransomware crew are back and taking responsibility for the Cleo hacks * (Yet another) File upload bug in Struts ma...
Between Two Nerds: How Russian cyber operations in Ukraine have evolved
Просмотров 513Месяц назад
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the evolution of Russian cyber operations during its invasion of Ukraine.
Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations
Просмотров 1,4 тыс.Месяц назад
In this edition of the Wild World of Cyber podcast Patrick Gray sits down with SentinelOne's Chief Intelligence and Public Policy Officer Chris Krebs to talk all about Chinese cyber operations. They look at the Salt Typhoon and Volt Typhoon campaigns, the last 20 years of Chinese operations, and the evolution of the cyber roles of China's Ministry of State Security and People's Liberation Army....
Product Demo: Proofpoint's Adaptive Email Security and Adaptive DLP
Просмотров 247Месяц назад
In this product demo Patrick Gray sits down with Ryan Kalember who walks him through Proofpoint's Adaptive Email Security and Adaptive DLP products. In short, these email security and DLP products learn about and adapt to individual customer environments to deliver better controls and alerts.
Srsly Risky Biz: FCC demands telcos improve security
Просмотров 291Месяц назад
In this podcast Tom Uren and Patrick Gray talk about the US Federal Communications Commission effort to get US telcos to lift their security game and compares it to UK and Australian efforts. The US is very late to the game, and improving security is a huge job. They also talk about Chinese cyber actors continuing to pointlessly sow chaos and how an influence campaign in Romania is an absolute ...
Risky Business Weekly: Cleo file transfer appliances under widespread attack
Просмотров 674Месяц назад
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: * Cleo file transfer products have a remote code exec, here we go again! * Snowflake phases out password-based auth * Chinese Sophos-exploit-dev company gets sanctioned * Romania's election gets rolled back after Tiktok changed the outcome * AMD's encrypted VM tech bamboozled by RAM with one ext...
Between Two Nerds: How loose is too loose?
Просмотров 850Месяц назад
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how states have very different approaches to controlling cyber operations. At the very beginning they refer to this Microsoft Threat Intelligence post here: www.microsoft.com/en-us/security/blog/2024/12/04/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/
Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered
Просмотров 369Месяц назад
In this interview Patrick Gray talks to Yubico's COO and President Jerrod Chong about a new Yubikey feature: pre-registration. You can now ship pre-registered Yubikeys to your staff so you don't need to rely on your staff to enrol them. They've achieved this with really slick Okta and Entra ID integrations. Jerrod also talks about a recent trip to Singapore and concerns he has about the cyberse...
Srsly Risky Biz: Why hack and leak is still a big deal
Просмотров 355Месяц назад
In this podcast Tom Uren and Adam Boileau talk about the continued importance of hack and leak operations. They didn't really affect the recent US presidential election, but they are still a powerful tool for vested interests to influence public policy. They also discuss the police bust of MATRIX, yet another encrypted messenger that is marketed to criminals and designed to resist police survei...
Risky Business Weekly (773): Cybercriminals are dropping like flies in Russia
Просмотров 1,7 тыс.Месяц назад
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including: * The FTC decides its time to take another look at Microsoft * Exxon's opponents targeted by hackers * Russian hackers keep getting sentenced and it confuses us * The Feds recommend Signal, because throwing hackers out of telcos ain't gonna happen * A South Korean set-top-box manufacturer shippe...
Srsly Risky Biz: The Australian government will shut down AN0M evidence appeals
Просмотров 3912 месяца назад
Srsly Risky Biz: The Australian government will shut down AN0M evidence appeals
Risky Business Weekly (772): Salt Typhoon is a true national security disaster
Просмотров 1,5 тыс.2 месяца назад
Risky Business Weekly (772): Salt Typhoon is a true national security disaster
Srsly Risky Biz: The PLA's cyber operations go dark
Просмотров 4712 месяца назад
Srsly Risky Biz: The PLA's cyber operations go dark
Risky Business Weekly (771): Palo Alto's firewall 0days are very, very stupid
Просмотров 1 тыс.2 месяца назад
Risky Business Weekly (771): Palo Alto's firewall 0days are very, very stupid
Product Demo: Software supply chain security with Socket
Просмотров 2682 месяца назад
Product Demo: Software supply chain security with Socket
Srsly Risky Biz: How Trump will drive covert operations
Просмотров 4672 месяца назад
Srsly Risky Biz: How Trump will drive covert operations
Risky Business Weekly (770): Why Ross Ulbricht should stay in prison
Просмотров 1,6 тыс.2 месяца назад
Risky Business Weekly (770): Why Ross Ulbricht should stay in prison
Risky Biz Soap Box: Why black box email security is dead
Просмотров 3422 месяца назад
Risky Biz Soap Box: Why black box email security is dead
Srsly Risky Biz: Don't bring a banana to a knife fight
Просмотров 3512 месяца назад
Srsly Risky Biz: Don't bring a banana to a knife fight
Risky Business Weekly (769): Sophos pwns Chinese APTs
Просмотров 1,1 тыс.2 месяца назад
Risky Business Weekly (769): Sophos pwns Chinese APTs
BONUS INTERVIEW: Sophos CISO talks Pacific Rim and dropping implants on Chinese APTs
Просмотров 9602 месяца назад
BONUS INTERVIEW: Sophos CISO talks Pacific Rim and dropping implants on Chinese APTs
Risky Business Weekly: Chinese APT Wiretaps the US Presidential Race (768)
Просмотров 7003 месяца назад
Risky Business Weekly: Chinese APT Wiretaps the US Presidential Race (768)
Risky Biz Soap Box: Thinkst Canary's decade of deception
Просмотров 1903 месяца назад
Risky Biz Soap Box: Thinkst Canary's decade of deception
Product Demo: Securing M365 and Google Workspace with Material Security
Просмотров 4453 месяца назад
Product Demo: Securing M365 and Google Workspace with Material Security
Srsly Risky Biz: EU lobs software liability hand grenade
Просмотров 3773 месяца назад
Srsly Risky Biz: EU lobs software liability hand grenade

Комментарии

  • @joeljohnson4512
    @joeljohnson4512 День назад

    Either Adam's shorter than I expected .... Or Patrick's sitting in the "Power Chair" :D

    • @riskybizmedia
      @riskybizmedia 16 часов назад

      Adam is a hair taller than me... we're both around 5ft 10... I think I was just a bit closer to the camera or something -- Pat

  • @holly.earendil5187
    @holly.earendil5187 День назад

    Do you reckon the school one is related to Blackboard Learn getting hit? It’s been going nuts, not working and apparently they’ve said it’s a security breach right after they introduced this fancy 2FA system that drives everyone up the wall SSO.

  • @Esta95_
    @Esta95_ День назад

    Delighted to see this! Big thanks to both of you, such a great resource for keeping up to date with cyber world.

  • @Hefe-oj4ec
    @Hefe-oj4ec День назад

    I'd be careful showing that much background Pat (if thats your actual house). The geoguessers can find anyone now with not much at all.

    • @riskybizmedia
      @riskybizmedia 20 часов назад

      I've had them find me already off far less. Horse has truly bolted on that one I'm afraid - P

  • @Mendleson
    @Mendleson 7 дней назад

    Blah blah blah Ross is free as bird 👊🏻 unlucky lads

  • @brownpaperbagyea
    @brownpaperbagyea 8 дней назад

    Risky business is BACK 💻👑🐐🔥♈️

  • @FragileMaleEggo
    @FragileMaleEggo 8 дней назад

    Yaaaaaaaaaayyyyyyyyyyyyyy!!!!!!!! Welcome Back!!!!

  • @JZK-Tech
    @JZK-Tech 8 дней назад

    Mercyful Fate!

  • @JZK-Tech
    @JZK-Tech 8 дней назад

    😳

  • @DylanODonnell
    @DylanODonnell 8 дней назад

    First

  • @brownpaperbagyea
    @brownpaperbagyea 12 дней назад

    i miss the goats 🐐👑

  • @brownpaperbagyea
    @brownpaperbagyea Месяц назад

    goated thumbnail frfr

  • @modrobert
    @modrobert Месяц назад

    A "real cyber war", but the discussion is only about the Russian strategy and attacks, nothing about the Ukraine (NATO) cyber effort during this period except mentioning that it was decentralized.

  • @maxsec2
    @maxsec2 Месяц назад

    Materiality is something general council should decide.... its not a cyber measure

    • @riskybizmedia
      @riskybizmedia Месяц назад

      I don't think we said otherwise?

    • @maxsec2
      @maxsec2 Месяц назад

      @@riskybizmedia quite, just the mad panic from "IT" about its defn when the business has been doing this measure for decades

  • @pyhoff
    @pyhoff Месяц назад

    senators making noise in 🇺🇸, yeah but nothing going to happen, maybe donations to their Super PACs. politicians are just racketeers.

  • @andrewhart6200
    @andrewhart6200 Месяц назад

    HOLD CORPORATE GREED'S FEET and MAKE THEM SCREAM - Thanks so much!

  • @MarkT
    @MarkT Месяц назад

    Sometimes I miss-click and realize I've watched this episode. No problem, let it run, again!

  • @JoshuaWrightHack
    @JoshuaWrightHack Месяц назад

    No closed captions for this episode?

  • @dandandan22
    @dandandan22 Месяц назад

    that south korean b2b hack is straight out of a william gibson's novel

  • @EvilestMinion
    @EvilestMinion Месяц назад

    Mentioned at the end of the video, what did Andrew from GreyNoise do useful with LLMs Patrick the host made a comment about this at the very end of the sponsored segment. I went back and listened but couldn't tell how any of it related to LLMs.

    • @riskybizmedia
      @riskybizmedia Месяц назад

      A part of the interview discusses how Greynoise SIFT, which is an LLM-based analysis engine, discovered some 0day being exploited in the wild.

    • @EvilestMinion
      @EvilestMinion Месяц назад

      @@riskybizmedia thank you! Exactly what I wanted to know. Wasnt familiar with the product.

  • @EvilestMinion
    @EvilestMinion Месяц назад

    Please keep uploading these here. It's the best place for me to listen. I see people aren't viewing too much on youtube right now, but if you keep telling us they are available on RUclips, the masses will come. Patience.

    • @riskybizmedia
      @riskybizmedia Месяц назад

      We're not really posting here for "numbers"... the nice thing about RUclips is it puts our podcast in front of people who might not know about it yet. Totally happy with 1k per episode even if the main show does more like 25k. We'll keep going.

    • @EvilestMinion
      @EvilestMinion Месяц назад

      @riskybizmedia Great to know it won't stop. You may be interested then that the podcast does not seem to reach RUclips Music users looking for the podcast or exploring cybersecurity podcasts. If I search for the title of the video or channel in RUclips Music, nothing comes up. This might be an easy fix. To "add an existing playlist of videos as a podcast" in RUclips Studio, you can click the 3 dot menu item on the video playlist and set it to - set as podcast. Once clicking - done - it should start showing up in RUclips Music for users to discover as well as regular RUclips. Maybe you're already aware and there is a good reason the videos aren't set as also being podcasts. But this would be very useful to my listening. However, I could be the only person in the world using RUclips music to find podcasts. I don't think it's a popular choice. Thanks for your replies.

  • @Jemono
    @Jemono 2 месяца назад

    For the el go: Top tier cyber security podcast. Legends.

  • @armorguy1108
    @armorguy1108 2 месяца назад

    Exciting to see a national parliament be able to react so quickly to an issue of this importance. As someone from the United States I can only look on with no small amount of envy.

  • @brownpaperbagyea
    @brownpaperbagyea 2 месяца назад

    Patrick and Adam da 🐐s no 🧢

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    Yikes.

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    That d0umb😂

  • @chrisbatman1566
    @chrisbatman1566 2 месяца назад

    America's biggest dis/misinformation maybe ever, is the lefts narrative of Trump and conservatives. Even until today, they form BS, straight up lies, that so many eat up hook-line and sinker. The amount of red-pilling so many are now experiencing is insane. You want to understand? Just honestly and objectively learn about all the lies and BS spoon fed to you about Trump, their admin, and conservatives. Even this Hegesworth comment. The man is combat vet, multiple bronze stars, graduate from top school, and more.. he isn't "crazy" unless you been duped by the crazy left. Liberals are now gone.

  • @YeshBalof
    @YeshBalof 2 месяца назад

    he was sentanced to life he did multiple years ADX Supermax and has served multiple in a penitentary i think hes learned his lesson

  • @darwinxavior9104
    @darwinxavior9104 2 месяца назад

    Forbes reports: "While he designed the website to prohibit items like child pornography, violent services, and stolen goods, Silk Road became synonymous with facilitating illegal activities, including drug trafficking." "prejudicial claims of murder-for-hire that were never proven in court and the involvement of corrupt federal agents who tampered with evidence, for which they were later convicted.' This is a test of Trump's election promises. Did he really mean it? We will find out "on day one"!

  • @jrdougan
    @jrdougan 2 месяца назад

    The Canadian Govts. decision make more sense if you consider the idea that some of the leadership might be compromised. They have to do something, so do something less effective.

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    They can’t get rid of CISA. Thank you Australia and New Zealand

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    Thanks! I mean Bishop Fox ? What is that ?

  • @brownpaperbagyea
    @brownpaperbagyea 2 месяца назад

    Not defending Ross or the Silk Road but I think the much larger benefit/risk reduction comes from vendors having reviews. Without looking at stats I would bet my life savings more people die from tainted/cut drugs vs “going to a bad neighborhood”

  • @Johnny5477
    @Johnny5477 2 месяца назад

    Back in the day, the hacker community would’ve been more or less united in freeing Ulbricht. But now that it’s about opposition to Trump, we’re all in with the Feds?

  • @MistaGobo
    @MistaGobo 2 месяца назад

    Free Ross Ulbricht!

    • @hulkingmass
      @hulkingmass 2 месяца назад

      the only people that want him freed are people that agree with him politically, and these people will excuse any wrongdoing of those on their "team" because they mistakenly believe they are at war with a cultural enemy

    • @SJHosek1
      @SJHosek1 Месяц назад

      Nah.

  • @davey64
    @davey64 2 месяца назад

    Kudos to Apple. I'd rather they error on the side of privacy than for LE.

  • @maxsec2
    @maxsec2 2 месяца назад

    On the network edge story, it's interesting that folks just aren't patching stuff, From the newletter alot of the stuff in the list had patches months ago.. Set and forget doesnt work. Never has never will. Sigh

  • @sunny_disposition
    @sunny_disposition 2 месяца назад

    Holy shit, give them a B? Do you remember when 1password got popped through a supply chain hack on okta where okta didn't know they had been hacked until 1password let them know? And then okta releases an incident report the following Friday night midnight eastern time which said the breach happened like 5 days before 1password let them know (yeah right as if hadn't been going on for months) Imagine if CrowdStrike was letting shit like this happen, and risky biz was giving them a "I guess a B, it's not an A though LOL"

    • @riskybizmedia
      @riskybizmedia 2 месяца назад

      Yeah the HAR file thing was pretty sloppy, forgot about that one. The "B" was over this specific incident where they had introduced a bad bug but managed to catch it internally within a couple of months. Shouldn't have happened, but the fact they caught it independently is good

  • @DerekMK
    @DerekMK 2 месяца назад

    Liking the new animated intro for the YT uploads! It might need to be faded out into the video footage though, it's a bit jarring with the hard-cut.

  • @brownpaperbagyea
    @brownpaperbagyea 2 месяца назад

    🐐🍌

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    Bishop Fox…Hmm. Reminds me of some gross elected “Americans”

    • @JZK-Tech
      @JZK-Tech 2 месяца назад

      I guess it’s worth looking into! j/s. Management traffic matters..Come on?!?!?

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    Priest or Maiden? Okta is fine..I mean come on

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    The AP wireless mess around from a wireless frame and an Ethernet frame is wackado when this happens 😂

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    The internet still does DNS right?

  • @JZK-Tech
    @JZK-Tech 2 месяца назад

    I’m here for it.

  • @DylanODonnell
    @DylanODonnell 2 месяца назад

    That opening animation tho

  • @ProBallerJake7
    @ProBallerJake7 2 месяца назад

    Thank you for covering this! I just subscribed.

  • @kevinmassey4052
    @kevinmassey4052 3 месяца назад

    I appreciate Adam letting his hair down. 10/10 would watch again

  • @brownpaperbagyea
    @brownpaperbagyea 3 месяца назад

    Nice thumbnail btw

    • @riskybizmedia
      @riskybizmedia 3 месяца назад

      Thank you, proud of that one -- Pat

  • @dannylberry
    @dannylberry 3 месяца назад

    any one know if Thinkst Canary have a home lab license? I'd like to have a play around with it at home

    • @riskybizmedia
      @riskybizmedia 3 месяца назад

      Not sure tbh -- canarytokens is free though, and you can do a lot with them