Risky Business Cybersecurity

Risky Bulletin Regular cybersecurity news updates from the Risky Business team…

  • Risky Bulletin: EU scraps Chat Control vote
    by risky.biz on October 10, 2025 at 2:56 am

    The EU scraps its upcoming vote on Chat Control, Ukraine establishes a Cyber Force, CISA workers are reassigned to immigration enforcement, and two teens are arrested over the UK nursery hacks. Show notes Risky Bulletin: EU scraps Chat Control vote

  • Srsly Risky Biz: Clop is a big fish, but not worth hunting
    by risky.biz on October 9, 2025 at 1:27 am

    Tom Uren and Amberleigh Jack talk about the Clop ransomware gang. It is interesting because the group has arrived at a strategy that rinses a whole lot of enterprises at once and comes with a decent pay day, But it’s actually the least damaging kind of ransomware. Tom wonders why can’t more gangs be like Clop? They also discuss the US government having second thoughts about ignoring foreign influence operations. Its adversaries run them all the time, so perhaps just sticking its head in the sand isn’t the best strategy. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Redis vulnerability impacts all versions released in the last 13 years
    by risky.biz on October 7, 2025 at 11:42 pm

    Redis patches a remote code execution vulnerability, Oracle out-of-band-fixes a zero-day used in a recent extortion campaign, Medusa ransomware group was behind a recent Fortra zero-day, and India fixes a tax filing system flaw; Show notes Risky Bulletin: Redis vulnerability impacts all versions released in the last 13 years

  • Between Two Nerds: What drives 0day mass exploitation
    by risky.biz on October 6, 2025 at 7:00 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about the 0day mass exploitation of SharePoint and Exchange. This type of widespread hacking appears to be increasingly common… but is it? This episode is also available on YouTube. Show notes X post | Brian in Pittsburgh

  • Risky Bulletin: Microsoft tells users to uninstall games affected by a Unity bug
    by risky.biz on October 5, 2025 at 11:56 pm

    Microsoft tells users to uninstall games affected by a Unity bug, Discord discloses a data breach, Google rolls out end-to-end encryption for Gmail, and Apple and Google block an ICE tracking app. Show notes Risky Bulletin: Microsoft tells users to uninstall games affected by major Unity bug

  • Sponsored: Corelight on where will NDRs go next
    by risky.biz on October 5, 2025 at 8:03 pm

    In this Risky Business News sponsor interview, Catalin Cimpanu talks with Ashish Malpani, Head of Product Marketing at Corelight. The discussion looks at how NDRs might evolve, such as expanding to protect inter-cloud networks and complementing EDRs. Show notes Corelight

  • Risky Bulletin: Scam compound operators sentenced to death in China
    by risky.biz on October 3, 2025 at 3:22 am

    China sentences 11 scam compound operators to death, the UK makes another request for Apple user data, an Iranian APT gets doxxed again, and Microsoft launches a Security Store. Show notes Risky Bulletin: Scam compound operators sentenced to death in China

  • Srsly Risky Biz: The cyberespionage gig economy
    by risky.biz on October 2, 2025 at 2:01 am

    Tom Uren and Amberleigh Jack talk about different ways foreign intelligence services are finding to recruit local proxies. These methods could be too risky for Western intelligence agencies, but for some state’s services they just make sense. They also discuss a report into DOGE and how speed was prioritised over robust governance. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Router APIs abused to send SMS spam
    by risky.biz on October 1, 2025 at 1:43 am

    A Cybercrime group abuses routers to send SMS spam, CISA announces a new collaboration model for state governments, South Korea raises its cyber threat level after a data center fire, and Tile tracking devices expose their location. Show notes Risky Bulletin: Router APIs abused to send SMS spam waves

  • Between Two Nerds: The power of cyber
    by risky.biz on September 29, 2025 at 8:48 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq discuss the power of cyber. This episode is also available on Youtube. Show notes Narrow windows of opportunity: the limited utility of cyber operations in war RUSI’s UK cyber effects network RUSI call for abstracts The fate of nations BTN discussion UK National Cyber Force’s Responsible Cyber Power in Practice Sponsor interview on the importance of resilient IdPs

  • Risky Bulletin: UK to bail out Jaguar Land Rover
    by risky.biz on September 29, 2025 at 12:55 am

    The UK will bail out Jaguar Land Rover following its cyberattack, hackers try to extort a ransom using childrens’ photos, Dutch police arrest two teens over sniffing WiFi for Russian spies, and a recent GoAnywhere MFT bug is being exploited. Show notes Risky Bulletin: UK to bail out Jaguar Land Rover

  • Sponsored: Why identity is critical
    by risky.biz on September 28, 2025 at 7:07 pm

    In this sponsored interview, Authentik CEO Fletcher Heisler talks to Tom Uren about how identity providers (IdP) are fundamental to everything an organisation does. He explains how organisations are making themselves resilient by managing their redundancy and failover options. Show notes

  • Risky Bulletin: EU users to get free Windows 10 extended security updates
    by risky.biz on September 26, 2025 at 4:03 am

    European users will get free Windows 10 extended security updates, Cisco patches three zero-days, Microsoft drops an Israeli intel surveillance contract and a UK man is arrested for the EU airport disruptions. Show notes Risky Bulletin: EU users to get free Windows 10 extended security updates

  • Srsly Risky Biz: The kids aren’t alright
    by risky.biz on September 25, 2025 at 3:15 am

    Tom Uren and Amberleigh Jack talk about how the funnel that turns kids into cyber criminals has evolved over the last decade. Cybercrime’s reach has broadened, it is more lucrative and more violent. They also talk about new thinking about deterring America’s cyber adversaries. This episode is also available on YouTube Show notes CSIS’s Playbook for Winning the Cyber War Bloomberg reporting on Scattered Spider

  • Risky Bulletin: US raids SIM farm in New York
    by risky.biz on September 24, 2025 at 1:24 am

    The US Secret Service raids a SIM farm in New York, EU airport disruptions were caused by ransomware, thieves steal gold nuggets from a French museum after a cyberattack and SonicWall releases a firmware update to remove SMA rootkits. Show notes Risky Bulletin: US raids SIM farm in New York

  • Between Two Nerds: How the US can win the cyber war
    by risky.biz on September 22, 2025 at 8:50 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq look at a new Center for Strategic and International Studies report: A Playbook for Winning the Cyber War. This episode is also available on YouTube. Show notes CSIS Playbook

  • Risky Bulletin: Cyberattack disrupts airports across Europe
    by risky.biz on September 22, 2025 at 12:37 am

    A cyberattack disrupts European airports, a Scattered Spider member turns himself in to US authorities, the Pentagon hires a new cyber policy leader and two Russian APTs work together for the first time. Show notes Risky Bulletin: Cyberattack disrupts airports across Europe

  • Sponsored: SpecterOps on identities at rest and identities in transit
    by risky.biz on September 21, 2025 at 7:53 pm

    In this Risky Business News sponsor interview, Catalin Cimpanu talks with Jared Atkinson, CTO at SpecterOps. They discuss how SpecterOps is using classifying identities under two categories, identities at rest and identities in transit, what they are and how they should be treated differently. Show notes Shifting the Paradigm: Managing Identities at Rest vs. Identities in Transit BloodHound OpenGraph

  • Risky Bulletin: Pentagon has more than 70,000 cyber personnel
    by risky.biz on September 19, 2025 at 12:50 am

    America’s Government Accountability Office says the Pentagon employs more than 70,000 cyber personnel, hackers steal SonicWall firewall configs, DeepSeek returns insecure code for groups China doesn’t like, and two Scattered Spider members arrested in the UK. Show notes Risky Bulletin: Pentagon has +70K cyber staff, and a lot of overlap

  • Srsly Risky Biz: US investment in spyware skyrockets
    by risky.biz on September 18, 2025 at 3:03 am

    Tom Uren and Amberleigh Jack talk about why it is good news that US investment in spyware vendors has skyrocketed. They also discuss the in-principle agreement for TikTok to remain in the US. It’s a win-win: a win for China and a win for TikTok, but not so much a win for US national security. This episode is also available on YouTube. Show notes

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.