Risky Bulletin Regular cybersecurity news updates from the Risky Business team…
- Srsly Risky Biz: China Fights Scam Compounds ⌠For Chinaby risky.biz on January 15, 2026 at 1:02 am
Tom Uren and Amberleigh Jack talk about the Chinese governmentâs reactive approach to tackling scam compounds. Itâs driven by bad news on domestic media and therefore focusses on the compounds that are targeting Chinese citizens. Rather than eliminating the industry, that may instead be shaping the industry to focus on other countries and particularly Americans. They also discuss the role of disruptive cyber operations in the USâs raid to capture Venezuelan President NicolĂĄs Maduro. This episode is also available on Youtube. Show notes
- Risky Bulletin: Russia fines 33 telcos for surveillance non-complianceby risky.biz on January 14, 2026 at 3:22 am
Russia fines 33 telcos for surveillance non-compliance, AVCheck admin is arrested in Amsterdam, Poland repels an attack on its power grid, and voice cloning defenses can be bypassed. Show notes Risky Bulletin: Voice cloning defenses still weak, can be bypassed
- Between Two Nerds: Lights out!by risky.biz on January 12, 2026 at 8:32 pm
In this edition of Between Two Nerds Tom Uren and The Grugq about the role of cyber operations in the US capture of Venezuelaâs president Nicolas Maduro. This episode is also available on Youtube. Show notes Maduro’s fall puts US cyber power in the spotlight Trump suggests US used cyberattacks to turn off lights in Venezuela during strikes Venezuela strike marks a turning point for US cyber warfare Power outages, but not cyber (from Oleg Shakirov) NYTimes Inside ‘Operation Absolute Resolve’ Spec Ops by William McRaven
- Risky Bulletin: Apex Legends streamers hacked againby risky.biz on January 11, 2026 at 10:32 pm
The Apex Legends game is hacked again, data about 17 million Instagram users put up for sale, Indonesia blocks X over pornographic content, and a ransomware attack hits major Chilean energy provider Show notes Risky Bulletin: Apex Legends streamers hacked again
- Sponsored: What AI workloads mean for Cloud securityby risky.biz on January 11, 2026 at 7:13 pm
In this Risky Business News sponsored interview the CEO and founder of Prowler, Toni de la Fuente, explains how implementing AI systems brings new security challenges that differ for traditional cloud workloads. Toni also talks about âattack pathsâ in the context of cloud infrastructure and using them to minimise risk. Show notes
- Risky Bulletin: Belarus deploys spyware on journalists’ phonesby risky.biz on December 19, 2025 at 2:02 am
Belarus deployed spyware on journalistsâ phones, a man is arrested for installing malware on a ferry, France arrests the hacker behind an Interior Ministry email server breach, and new Cisco and SonicWall zero-days. Show notes Risky Bulletin: Belarus deploys spyware on journalists’ phones
- Srsly Risky Biz: Like Huawei, but for electricityby risky.biz on December 17, 2025 at 11:56 pm
Tom Uren and Patrick Gray talk about Americaâs increasing dependence on Chinese manufacturers for electrical sector equipment. This doesnât seem like a good idea when China is hacking electric utilities for sabotage and PLA researchers are dreaming up ways to attack the grid. They also discuss the possibility that the US was responsible for a cyber attack on Venezuelaâs state oil company and how Russian state-backed hacktivism is so dumb. This episode is also available on Youtube. Show notes
- Risky Bulletin: Most smart devices run outdated web browsersby risky.biz on December 17, 2025 at 12:39 am
Most smart devices run outdated web browsers, Ukrainian hacktivists breach a major Russian defense contractor, ransomware hits Venezuelaâs state-owned oil company, and hackers are trying to extort PornHub with stolen user data. Show notes Risky Bulletin: Most smart devices run outdated web browsers
- Between Three Nerds: The evolution of Iranian cyber espionageby risky.biz on December 15, 2025 at 8:37 pm
In this edition of Between Two Nerds Tom Uren and The Grugq talk to Hamid Kashfi, CEO and founder of DarkCell, talk about the Iranian cyber espionage scene. Kashfi talks about how the regime once forced people to hack and crushed the domestic security research scene. He describes how and why the government has changed its approach and is now reaping the rewards of improved Iranian capabilities. This episode is available on Youtube. Show notes The “Mossad or not” threat model by James Mickens Shamoon wiper iLO rootkit
- Risky Bulletin: African freelancers behind anti-US and anti-French disinfo campaignsby risky.biz on December 15, 2025 at 1:56 am
Russia is hiring African freelancers for disinformation campaigns, the US is preparing to let contractors run offensive cyber operations, Germany blames Russia for the hack of its air traffic control agency, and Apple patches two WebKit zero-days. Show notes Risky Bulletin: African freelancers behind anti-US and anti-French disinfo campaigns
- Sponsored: ConsentFix and Push Security’s browser attack taxonomyby risky.biz on December 14, 2025 at 8:17 pm
In this sponsored interview Casey Ellis is joined by Push Securityâs Field CTO, Mark Orlando. They chat about the ways that browser-based attacks are evolving and how Push Security is finding and cataloging them. Show notes ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants Introducing our guide to phishing detection evasion techniques
- Risky Bulletin: EU has a problem attracting and retaining cyber talentby risky.biz on December 12, 2025 at 2:59 am
The EU has a problem attracting and retaining cyber talent, the CEO of Coupang resigns following the companyâs security breach, Microsoft expands its bug bounty program to cover third party code, and Chrome and Gogs patch zero-days. Show notes Risky Bulletin: EU has a problem attracting and retaining cyber talent
- Risky Bulletin: Linux adds PCIe encryption to help secure cloud serversby risky.biz on December 10, 2025 at 12:12 am
Linux adds PCIe encryption to help secure cloud servers, Europol cracks down on Violence-as-a-Service providers, the International Criminal Court prepares for cyber-enabled genocide, and Cambodia busts a warehouse full of SMS blasters. Show notes Risky Bulletin: Linux adds PCIe encryption to help secure cloud servers
- Risky Bulletin: APTs go after the React2Shell vulnerability within hoursby risky.biz on December 7, 2025 at 11:32 pm
APTs go after the React2Shell vulnerability just hours after public disclosure. CISA remains without a director after the nomination stalls again, NSA is down 2,000 staff this year, and Intellexa is still active despite sanctions. Show notes
- Srsly Risky Biz: When cyber campaigns cross a lineby risky.biz on December 4, 2025 at 12:02 am
Tom Uren and Patrick Gray discuss a new report proposing a framework for deciding when cyber operations raise red flags. It suggests seven red flags and could help clarify thinking about how to respond to different operations. They also discuss Anthropic testifying to Congress and Iran using cyber intelligence to target missile strikes including by sharing it with Houthi rebels who fired at a specific ship. And finally, we are not reassured by Chinaâs white paper about being a good cyber citizen. This episode is also available of Youtube. Show notes Assessing Irresponsibility in Cyber Operations AWS on state actors bridging cyber and kinetic warfare
- Between Two Nerds: Beating back state espionageby risky.biz on December 1, 2025 at 7:56 pm
In this edition of Between Two Nerds Tom Uren and The Grugq wonder whether it is possible to deter states from cyber espionage with doxxing and other disruption measures. This episode is also available on Youtube. Show notes Department 40 exposed Charming Kitten exposed
- Sponsored: Why Mastercard got into threat intelby risky.biz on November 30, 2025 at 10:21 pm
In this Risky Business News sponsor interview, Mike Lashlee, CSO of Mastercard talks to Tom Uren about why the company got into threat intelligence. Mike talks about bringing together payments insights with threat intel to get strong signals about fraud or crime, the benefits of international collaboration and when it makes sense for your CSO to also be the CISO. Show notes
- Srsly Risky Biz: DeepSeek and Musk’s Grok both toe the party lineby risky.biz on November 27, 2025 at 2:07 am
Tom Uren and Amberleigh Jack talk about new research that shows the Chinese-made DeepSeek-R1 AI model produces insecure code when prompts include topics that the Chinese Communist Party dislikes. Itâs interesting research, but the CCP doesnât have a monopoly on imposing AI bias. They also discuss the complete doxxing of the Iranian cyber espionage group known as APT35 or Charming Kitten. This episode is also available on Youtube. Show notes
- Between Two Nerds: Telcos bad, Cloud good.by risky.biz on November 24, 2025 at 8:36 pm
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the differences between telcos and cloud companies. Does the nature of the business force cloud companies to be better at security? This episode is also available on Youtube. Show notes FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess Netflix’s Chaos Monkey Brian in Pittsburgh BTN145 Ultra
- Srsly Risky Biz: AI-Powered espionage will favor Chinaby risky.biz on November 20, 2025 at 1:46 am
Tom Uren and Amberleigh Jack talk about Anthropicâs discovery of an âAI-orchestratedâ cyber espionage campaign. To Tom, it feels a research project, but itâs pretty clear it will be really useful for threat actors that arenât focussed on specific high-priority targets. Think ransomware, Chinese intellectual property theft and North Korean hackers. But it wonât be so good for Western intelligence agencies. They also discuss Googleâs legal disruption of the China-based Lighthouse phishing as a service operation. Surprisingly, it seems to be working! Finally, they talk about why the memory safe Rust language has been a triple win for Android. This episode is also available on Youtube. Show notes






