Risky Bulletin Regular cybersecurity news updates from the Risky Business team…
- Srsly Risky Biz: DeepSeek and Musk’s Grok both toe the party lineby risky.biz on November 27, 2025 at 2:07 am
Tom Uren and Amberleigh Jack talk about new research that shows the Chinese-made DeepSeek-R1 AI model produces insecure code when prompts include topics that the Chinese Communist Party dislikes. Itās interesting research, but the CCP doesnāt have a monopoly on imposing AI bias. They also discuss the complete doxxing of the Iranian cyber espionage group known as APT35 or Charming Kitten. This episode is also available on Youtube. Show notes
- Between Two Nerds: Telcos bad, Cloud good.by risky.biz on November 24, 2025 at 8:36 pm
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the differences between telcos and cloud companies. Does the nature of the business force cloud companies to be better at security? This episode is also available on Youtube. Show notes FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess Netflix’s Chaos Monkey Brian in Pittsburgh BTN145 Ultra
- Srsly Risky Biz: AI-Powered espionage will favor Chinaby risky.biz on November 20, 2025 at 1:46 am
Tom Uren and Amberleigh Jack talk about Anthropicās discovery of an āAI-orchestratedā cyber espionage campaign. To Tom, it feels a research project, but itās pretty clear it will be really useful for threat actors that arenāt focussed on specific high-priority targets. Think ransomware, Chinese intellectual property theft and North Korean hackers. But it wonāt be so good for Western intelligence agencies. They also discuss Googleās legal disruption of the China-based Lighthouse phishing as a service operation. Surprisingly, it seems to be working! Finally, they talk about why the memory safe Rust language has been a triple win for Android. This episode is also available on Youtube. Show notes
- Between Two Nerds: Russia’s cyber war on wheatby risky.biz on November 17, 2025 at 8:18 pm
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the strategic ālogicā of Russian wiper attacks on the Ukrainian grain sector. This episode is also available on Youtube. Show notes ESET report Soesanto and Gajos at Lawfare
- Risky Bulletin: Europol takes down Elysium, VenomRAT, and Rhadamanthysby risky.biz on November 14, 2025 at 2:45 am
Europol takes down servers behind three malware operations, the US sanctions another Burmese military group linked to scam compounds, Google backs down from mandatory Android developer registration, and Checkout-dot-com donates its ransom to cybercrime researchers instead of paying hackers. Show notes Risky Bulletin: Europol takes down Elysium, VenomRAT, and Rhadamanthys infrastructure
- Srsly Risky Biz: Meta’s fraud profit scandalby risky.biz on November 13, 2025 at 1:35 am
Tom Uren and Amberleigh Jack talk about a new Reutersā report that reveals how Meta is knowingly raking in cash from scam advertisements. Itās around $16 billion worth, and in documents Meta calculates that it outweighs the costs of possible regulatory action. They also discuss recent state-backed supply chain attacks that have, so far, remained targeted and responsible. Finally they look at the UKās decision to stop sharing intelligence with the US about suspected drug boats in the Caribbean. This episode is also available on Youtube. Show notes
- Risky Bulletin: Another Chinese security firm has its data leakedby risky.biz on November 11, 2025 at 11:13 pm
Internal data leaks from another Chinese security firm, a US Congressional Budget Office breach has not been contained, the Cyber infosharing act likely to be extended until January, and we have a new OWASP Top 10. Show notes Risky Bulletin: Another Chinese security firm has its data leaked
- Between Two Nerds: Why AI in malware is lameby risky.biz on November 10, 2025 at 8:44 pm
In this edition of Between Two Nerds Tom Uren and The Grugq discuss how cyber criminals and even state actors are being dumb about using AI. This episode is also available on Youtube. Show notes Google’s AI Threat Tracker Script framework
- Risky Bulletin: Myanmar scam compound goes boom!by risky.biz on November 10, 2025 at 2:43 am
Myanmar starts demolishing the KK Park scam compound, the US Congressional Budget Office gets hacked by a foreign APT, Chrome will remove risky X-S-L-T support, and scammers in Singapore will get the cane. Show notes
- Sponsored: Prowler uses AI how AI works bestby risky.biz on November 9, 2025 at 8:12 pm
In this sponsored interview Casey Ellis chats to Toni de la Fuente, founder and CEO of Prowler, an open source platform for cloud security. They chat about how and why Prowler selectively applies AI to ensure it adds value rather than just because they can. Show notes
- Risky Bulletin: Europol arrests massive credit card fraud ringby risky.biz on November 7, 2025 at 1:39 am
Payment service provider executives arrested over a credit card fraud ring, Meta makes a fortune showing scam ads, South Korean telco KT tried to hide a second breach and five more scammers are sentenced to death in China. Show notes Risky Bulletin: Europol arrests payment service executives for role in credit card fraud ring
- Srsly Risky Biz: The cyber regime change pipe dreamby risky.biz on November 6, 2025 at 1:46 am
Tom Uren and Amberleigh Jack talk about aggressive US cyber operations targeting the Venezuelan government in President Trumpās first term. These were narrowly successful in that they achieved their immediate operational goals, but they didnāt achieve Trumpās broader policy goal of ousting Venezuelan leader NicolĆ”s Maduro. They also talk about why the adtech ecosystem is a national security problem all round the world and how cybercriminals are collaborating with organised crime to steal cargo from logistics companies. This episode is also available on Youtube. Show notes
- Risky Bulletin: US indicts two rogue cybersecurity employees for ransomware attacksby risky.biz on November 5, 2025 at 2:51 am
The US indicts two cybersecurity employees over ransomware attacks, hackers extort customers of South Korean massage parlors, another crypto firm gets hacked for $128 million dollars, and cargo thieves collab with hackers to target freight companies. Show notes Risky Bulletin: US indicts two rogue cybersecurity employees for ransomware attacks
- Between Two Nerds: Lost in transmissionby risky.biz on November 3, 2025 at 8:06 pm
In this edition of Between Two Nerds Tom Uren and The Grugq discuss the futility of using aggressive cyber operations to send messages between states. This episode is also available on Youtube. Show notes The Record, Volt Typhoon was not successful Sand in the gears: Sabotage in world politics by Joshua Rovner, Rory Cormac and Lennart Maschmeyer
- Risky Bulletin: Norway skittish of its Chinese electric busesby risky.biz on November 3, 2025 at 1:24 am
Norway finds remote control features in its Chinese electric buses, the US CyberCorps program may saddle students with debt, Edge and Chrome get AI-based scareware blockers, and a Conti member has been extradited to the US. Show notes Risky Bulletin: Norway skittish of its Chinese electric buses
- Sponsored: Sublime can save a s**t tonne of timeby risky.biz on November 2, 2025 at 7:46 pm
In this sponsored interview, Casey Ellis chats to Sublime Security CEO and founder, Josh Kamdjou about how Sublime is seeing a massive surge in ICS or calendar invite phishing and how the email security platform can help. Show notes
- Risky Bulletin: Russia arrests Meduza Stealer groupby risky.biz on October 30, 2025 at 11:22 pm
Russian police arrest the Meduza-Stealer trio, a Former L-3Harris manager pleads guilty to selling exploits to Russia, the US hacked Venezuela in 2020, and Windows 11 Administrator Protection goes live. Show notes Risky Bulletin: Russia arrests Meduza Stealer group
- Srsly Risky Biz: Peter Williams, Ex-ASD, Pleads Guilty to Selling Eight Exploits to Russiaby risky.biz on October 30, 2025 at 2:26 am
Tom Uren and Amberleigh Jack talk about Peter Williams, the general manager of vulnerability research firm Trenchant, who has pleaded guilty to selling exploits to the Russian 0day broker Operation Zero. Itās a terrible look, but it doesnāt mean the private sector canāt be trusted to develop exploits. They also discuss a new reportās recommendations to empower the Office of the National Cyber Director. Itās a good idea, but it wonāt make up for the cuts in funding and personnel across the Trump administrationās cyber portfolio. This episode is also available on Youtube. Show notes
- Risky Bulletin: HackingTeam is back!by risky.biz on October 28, 2025 at 11:01 pm
HackingTeamās successor is targeting Russia and Belarus, X users must re-enroll their security keys, Chrome will put HTTP behind a warning dialogue, and 15 people are expected to plead guilty in an Italian hacking scandal. Show notes Risky Bulletin: HackingTeam successor linked to recent Chrome zero-days
- Between Two Nerds: NSA gets its mojo back!by risky.biz on October 27, 2025 at 6:57 pm
In this edition of Between Two Nerds Tom Uren and The Grugq dissect a recent Chinese CERT report that the NSA had hacked Chinaās national time keeping service. This episode is also available on Youtube. Show notes MSS Weixin post CN-CERT technical analysis Global Times on X BTN110: The NSA’s nine to five hacking campaign







