Risky Business Cybersecurity

Risky Bulletin Regular cybersecurity news updates from the Risky Business team…

  • Risky Bulletin: New powers for Dutch intelligence services
    by Risky Business Media on August 31, 2026 at 3:20 am

    Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service. Show notes Risky Bulletin: Dutch intel services to get extensive new powers

  • Sponsored: Attackers need to be right more than once
    by Risky Business Media on August 30, 2026 at 8:01 pm

    In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown jewels”. The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times. Show notes

  • Risky Bulletin: Two TeamPCP members arrested in Australia
    by Risky Business Media on August 28, 2026 at 4:34 am

    Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic. Show notes Risky Bulletin: Two TeamPCP members arrested in Australia

  • Srsly Risky Biz: China’s AI-Enabled APT Operations Are Getting Interesting
    by Risky Business Media on August 27, 2026 at 4:53 am

    Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense. This episode is also available on YouTube Show notes

  • Risky Bulletin: Russia starts blocking DoH and DoT
    by Risky Business Media on August 26, 2026 at 3:02 am

    Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common. Show notes Risky Bulletin: Russia starts blocking DoH and DoT

  • Between Two Nerds: Attribution is dead, long live attribution
    by Risky Business Media on August 24, 2026 at 7:53 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available on YouTube. Show notes Florian Roth X post Phrack issue 59, Defeating Forensic Analysis on Unix Phrack issue 62, Remote Exec

  • Risky Bulletin: Expired credit cards can be used for malicious transactions
    by Risky Business Media on August 24, 2026 at 4:31 am

    Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars. Show notes Risky Bulletin: Expired cards can be used for new transactions

  • Sponsored: Passkeys won’t stop authorisation phishing
    by Risky Business Media on August 23, 2026 at 7:49 pm

    In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if their controls against these attacks actually work. Show notes

  • Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs
    by Risky Business Media on August 21, 2026 at 2:47 am

    The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great Firewall Show notes Risky Bulletin: Academics find source code overlaps between Geedge and China’s Great Firewall

  • Srsly Risky Biz: Trump’s private hacker memo is the right idea
    by Risky Business Media on August 20, 2026 at 5:24 am

    Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disruption operations, but there simply isn’t enough government capacity. So it is time to bring in the private sector. They also discuss Ukraine’s combined cyber and kinetic strikes against Wildberries, the logistics company that is called the Amazon of Russia. These cyber operations didn’t amplify the effects of kinetic strikes, but it is great propaganda to say that they did. This episode is also available on YouTube Show notes

  • Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
    by Risky Business Media on August 19, 2026 at 4:46 am

    Slovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm. Show notes Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

  • Between Two Nerds: The eye of Sauron
    by Risky Business Media on August 17, 2026 at 7:57 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders. This episode is also available on YouTube. Show notes The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber Defense Between Two Nerds: Exploits are not cyber power

  • Risky Bulletin: The EU publishes its upcoming cybersecurity standards
    by Risky Business Media on August 17, 2026 at 4:52 am

    The EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction. Show notes Risky Bulletin: The EU publishes its upcoming cybersecurity standards

  • Sponsored: What npm 12 fixes… and what it doesn’t
    by Risky Business Media on August 16, 2026 at 7:08 pm

    In this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what third-party code actually does before allowing it into their environments. Show notes

  • Risky Bulletin: US will let private companies carry out offensive cyber ops
    by Risky Business Media on August 14, 2026 at 4:37 am

    The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs. Show notes Risky Bulletin: White House lets private companies carry out offensive cyber ops

  • Srsly Risky Biz: Data extortion is booming. Hooray!
    by Risky Business Media on August 13, 2026 at 9:40 am

    Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat than having their files locked up. They also discuss how the rise of AI makes it worth reinvigorating CISA’s Secure by Design initiative. Show notes

  • Risky Bulletin: Russian hackers jump on the fake job interview train
    by Risky Business Media on August 12, 2026 at 3:23 am

    Russian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams. Show notes Risky Bulletin: Russian hackers adopt the fake job interview tactics

  • Between Two Nerds: The cyber resistance!
    by Risky Business Media on August 10, 2026 at 7:57 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals. This epsiode is also available on YouTube. Show notes The Record on the Belarus Cyber Partisans BTN6, How Ukraine could use its IT army

  • Risky Bulletin: Two law firms pay giant ransoms
    by Risky Business Media on August 10, 2026 at 2:17 am

    Two American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again! Show notes Risky Bulletin: Pwnie Awards 2026 winners

  • Sponsored: Island’s expansion to SASE and enterprise AI
    by Risky Business Media on August 9, 2026 at 7:49 pm

    In this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI. Show notes About Michael Leland

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.