Risky Bulletin Regular cybersecurity news updates from the Risky Business team…
- Between Two Nerds: The intelligence cultby Risky Business Media on June 2, 2026 at 12:52 am
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the ways in which intelligence agencies are just like cults. This episode is also available on YouTube Show notes
- Risky Bulletin: Recently patched PAN 0day exploited in the wildby Risky Business Media on June 1, 2026 at 2:48 am
A new Palo Alto Networks firewall bug is being exploited in the wild, Russia expands SORM surveillance, NIST is looking for new post quantum algorithms, and ENSOC launches in Europe. Show notes Risky Bulletin: Russia greatly expands SORM surveillance requirements
- Sponsored: Inside CISA’s disastrous secrets leakby Risky Business Media on May 31, 2026 at 11:01 pm
In this sponsored interview Casey Ellis chats with Truffle Securityâs founder and CEO Dylan Ayrey about the recent CISA secrets leak. Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISAâs org. Dylan walks through why deleting the repo doesnât fix anything, why most cloud vendors wonât hard-revoke exposed keys (OpenAI and Slack will; AWS, Google and friends mostly wonât), why Hugging Face datasets now hold more secrets than GitHub itself, and what the next generation of multi-provider credential-harvesting supply chain worms is going to look like. Show notes
- Risky Bulletin: Dutch police take down 17m device botnetby Risky Business Media on May 29, 2026 at 2:31 am
Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer is arrested for insider trading on Polymarket, and Gogs and the Casdoor IAM leave major bugs unpatched. Show notes Risky Bulletin: Dutch police take down giant botnet of 17 million devices
- Risky Bulletin: Iran to reconnect to the Internetby Risky Business Media on May 27, 2026 at 6:23 am
Iran will reconnect to the Internet, a new vulnerability lets attackers bypass authentication on AI infrastructure, hackers breach Lithuaniaâs state registry, security firms take down the Glassworm botnet, and CERT India releases strict patching advice. Show notes Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure
- Risky Bulletin: Mythos has found thousands of critical bugsby Risky Business Media on May 25, 2026 at 4:28 am
Anthropic says Mythos has found thousands of critical bugs, hackers leak documents from a Russian disinfo group, GitHub rolls out new npm security features, and Dutch police raid two bulletproof hosting providers. Show notes Risky Bulletin: Mythos has found thousands of critical bugs
- Sponsored: Teaching AI agents the rules of the roadby Risky Business Media on May 24, 2026 at 8:24 pm
In this sponsored interview James Wilson chats with Sondera CEO Josh Devon about why guardrails and instruction files arenât enough to keep AI agents from going haywire. EDR, DLP and other traditional controls canât and wonât prevent agents from going rogue. Josh explains Sonderaâs âprinciple of least autonomyâ for agents: let them do useful work, but put them in a deterministic policy harness so they canât leak secrets, abuse tools or wander off-task. Show notes
- Risky Bulletin: Microsoft ends SMS MFA for personal accountsby Risky Business Media on May 22, 2026 at 12:48 am
Microsoft ends support for SMS MFA on personal accounts, GitHub was hacked via a malicious VS Code extension, CISA will let researchers submit new KEV entries, and an SMS blaster was detained at Eurovision. Show notes Risky Bulletin: Microsoft ends SMS MFA for personal accounts
- Srsly Risky Biz: Politicians ditch Signal for homegrown appsby Risky Business Media on May 21, 2026 at 6:16 am
Tom Uren and James Wilson talk about moves from several European governments to ditch Signal and set up their own encrypted messaging systems for internal government use. These efforts are motivated by concerns about phishing and sovereignty, but the solutions being adopted are imperfect and will come with their own set of problems. Signal fills a space that canât be filled with sovereign capability. They also talk about Fast16 malware. We are only now learning about the second arm of a mid-2000s campaign to delay Iranâs nuclear weapons program that included the infamous Stuxnet worm. This episode is also available on YouTube Show notes
- Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangsby Risky Business Media on May 20, 2026 at 3:36 am
Microsoft disrupts a malware-signing service used by ransomware gangs, a CISA contractor leaks sensitive GovCloud keys, vulnerability exploitation is now the dominant network entry vector, and Drupal readies security updates for a âhighly criticalâ vulnerability. Show notes Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs
- Between Two Nerds: Russia’s hacker universityby Risky Business Media on May 19, 2026 at 12:24 am
In this edition of Between Two Nerds Tom Uren and The Grugq look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russiaâs cyber program and look at what Western intelligence agencies do instead. This episode is also available on YouTube. Show notes The GRU’s Hogwarts Vlodymyr Styran’s substack BTN92 with Alex Joske, how the MSS became a cyber juggernaut
- Risky Bulletin: Indonesia emerges as a new hub for cyber scamsby Risky Business Media on May 18, 2026 at 5:24 am
Indonesia emerges as a new cyber scam hub, Grafana got hacked and held for ransom, the Fast16 malware subverted software used to simulate nuclear explosions, and a new Microsoft Exchange zero-day is under attack. Show notes Risky Bulletin: Indonesia emerges as a new hub for cyber scams
- Sponsored: Push Security goes AI threat hunting in browser telemetryby Risky Business Media on May 17, 2026 at 10:06 pm
In this sponsored interview James Wilson chats with Push Securityâs Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform. Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers. Show notes
- Risky Bulletin: Shai-Hulud goes open-sourceby Risky Business Media on May 15, 2026 at 1:39 am
The source code for the Shai-Hulud worm has been released online, a dark web market admin was charged after a major OPSEC failure, France investigates an Israeli disinfo firm, and âComposerâ rushes to fix a GitHub token leak. Show notes Risky Bulletin: Shai-Hulud goes open-source
- Srsly Risky Biz: The AI Regulation Knife Fightby Risky Business Media on May 14, 2026 at 5:22 am
Tom Uren and James Wilson talk about the argy bargy within the Trump administration about AI regulation. They cover who is fighting, what is at stake and what the real areas of concern are. They also cover low earth orbit satellite constellations. Russiaâs building one, the EU has plans and China is building two. They are the new must-have accessory for any country with global ambitions. This episode is also available on YouTube Show notes
- Risky Bulletin: Damaging worm rips through npm ecosystemby Risky Business Media on May 13, 2026 at 5:39 am
RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and another major supply chain attack on npm (yawn). Show notes Risky Bulletin: RubyGems disables sign-ups after attack on staff
- Between Two Nerds: The AI-first crime gangby Risky Business Media on May 12, 2026 at 2:09 am
In this edition of Between Two Nerds Tom Uren and The Grugq discuss why it makes even more sense for criminal organisations to adopt AI as compared to regular businesses. This episode is also available on YouTube. Show notes Microsoft’s 2026 Work Trend Index Annual Report Cybersecurity Looks Like Proof of Work Now On the Hunt for FIN7
- Risky Bulletin: FCC relaxes foreign router security patch banby Risky Business Media on May 11, 2026 at 12:39 am
The FCC relaxes its foreign router ban to allow for security updates, the ShinyHunters group disrupts schools across the globe, a 21-year-old remote code execution bug turns up in FreeBSD, and another Linux privilege escalation bug was disclosed⌠without a patch. Show notes Risky Bulletin: FCC relaxes foreign router ban to allow for security updates
- Sponsored: Knocknoc built a Greynoise integrationby Risky Business Media on May 10, 2026 at 9:51 pm
In this sponsored interview Patrick Gray chats with Knocknoc CEO Adam Pointon about their Greynoise integration. Knocknoc allowlists network connections from usersâ IPs after theyâve been through an SSO challenge. Itâs great for protecting vulnerable or risky assets that your org has to connect to the internet. But what happens when one of your users tries to authenticate from a bad IP? You probably donât want to add that one to your allowlist! Thanks to Knocknocâs new Greynoise integration, you donât have to! Show notes
- Risky Bulletin: State sponsored group exploits Palo 0dayby Risky Business Media on May 8, 2026 at 2:03 am
Palo Alto Networks patches a firewall zero-day, Google patches an Android remote takeover bug, Ivanti also patches one, and a leak exposes Russiaâs spy and hacker school. Show notes Risky Bulletin: Google patches Android remote takeover bug





