Risky Business Cybersecurity

Risky Bulletin Regular cybersecurity news updates from the Risky Business team…

  • Between Two Nerds: The evolution of cyber ops in Ukraine
    by Risky Business Media on March 2, 2026 at 8:37 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq how the use of cyber operations in the war in Ukraine has evolved over time. This episode is also available on Youtube. Show notes Russia using cyber espionage to direct grid missile strikes The Spectator article on US-UK relations BTN72 on the Taurus missile leak

  • Risky Bulletin: LLMs can deanonymize internet users based on their comments
    by Risky Business Media on March 2, 2026 at 1:17 am

    LLMs can deanonymize internet users based on their comments, CISA gets a new acting director, hackers steal 15 million records from the French Ministry of Health, and Google takes down an ad fraud botnet. Show notes Risky Bulletin: LLMs can deanonymize internet users based on their past comments

  • Sponsored: AI Agents need distinct identities
    by Risky Business Media on March 1, 2026 at 7:47 pm

    In this sponsored interview Casey Ellis chats to Harish Peri, SVP and general manager for AI security at Okta, a cloud-based identity and access management company. The pair chat about the fact that AI is forcing enterprises to relearn the basics around identity security, and how Okta for AI Agents can help. Show notes

  • Risky Bulletin: Russian man extorts Conti ransomware group
    by Risky Business Media on February 27, 2026 at 2:42 am

    A Russian man prosecuted for extorting the Conti ransomware group, Google takes down a Chinese cyber-espionage operation, Anthropic tells Department of War to pound sand over AI restrictions, and a Cisco zero-day was exploited in the wild for three years. Show notes Risky Bulletin: Russian man investigated for extorting Conti ransomware group

  • Srsly Risky Biz: Is Claude too woke for war?
    by Risky Business Media on February 26, 2026 at 12:59 am

    Tom Uren and Amberleigh Jack talk about the argy-bargy between the Pentagon and AI company Anthropic. US Defense Secretary Pete Hegseth is demanding that all safeguards are lifted from Claude, while Anthropic CEO Dario Amodei is insisting on protections against mass surveillance of Americans and use in lethal autonomous weapons. They also discuss the return of Volt Typhoon, the Chinese hacker group prepositioning in critical infrastructure for sabotage in the event of a conflict over Taiwan. The group is still around, even though the US government declared victory against it last July. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Russia starts criminal probe of Telegram founder Pavel Durov
    by Risky Business Media on February 25, 2026 at 1:29 am

    Russia launches a criminal probe into Telegram’s founder, two teenagers arrested for a South Korean bike share hack, Anthropic accuses Chinese AI firms of distillation attacks, and the US Treasury sanctions a Russian exploit broker. Show notes Risky Bulletin: Russia starts criminal probe of Telegram founder Pavel Durov

  • Between Two Nerds: How NSA will use AI
    by Risky Business Media on February 23, 2026 at 9:13 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about how ā€˜professional’ Five Eyes cyber espionage agencies like NSA will use AI. These agencies place a premium on stealth and won’t yolo AI. This episode is available on Youtube. Show notes How AI-powered espionage will favour China Google’s AI threat tracker, February 2026

  • Risky Bulletin: AI-driven hacking campaign breaches 600+ Fortinet devices
    by Risky Business Media on February 23, 2026 at 12:48 am

    An AI-driven hacking campaign breached 600 Fortinet devices, Ivanti was hacked via its own product, Wikipedia bans Archive-dot-Today for DDoS attacks, and Chinese hackers breached Italy’s police force. Show notes Risky Bulletin: AI-driven hacking campaign breaches 600+ Fortinet devices

  • Sponsored: The smouldering trashfire of AI and open source
    by Risky Business Media on February 22, 2026 at 7:42 pm

    In this Risky Business sponsor interview, Casey EllisĀ and Feross Aboukhadijeh discuss how AI is affecting open source, chat about a few attacks the company has seen in the wild and introduce Socket’s answer to the smouldering trashfire: Socket Firewall. Show notes

  • Risky Bulletin: RPKI infrastructure sits on shaky ground
    by Risky Business Media on February 20, 2026 at 2:00 am

    RPKI relies on vulnerable servers, the French Ministry of Economy discloses a data breach, the UK gives tech platforms 48 hours to remove revenge porn, and ClickFix-attacks are responsible for 50% of malware infections. Show notes Risky Bulletin: RPKI infrastructure sits on shaky ground

  • Srsly Risky Biz: Cyber bullets can’t replace political will
    by Risky Business Media on February 19, 2026 at 1:55 am

    Tom Uren and Amberleigh Jack talk about a groundswell of calls from European officials to build cyber capabilities to strike back against adversaries. There are good reasons that countries should have their own cyber capabilities, but if you don’t have the political will to strike back, having a magic cyber weapon doesn’t really make a difference. They also talk about ā€˜distillation attacks’. They are a way that AI developers can steal the secret sauce of advanced models just by asking questions. It looks like American companies need government assistance if the US wants to keep its AI lead. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Supply chain attack plants backdoor on Android tablets
    by Risky Business Media on February 18, 2026 at 3:24 am

    A supply chain attack plants backdoors on Android tablets, the EU blocks AI from lawmakers’ devices, Cellebrite was used against a Kenyan politician, and a Chinese APT is exploiting a Dell zero-day. Show notes Risky Bulletin: Supply chain attack plants backdoor on Android tablets

  • Between Two Nerds: Buying the magic weapon
    by Risky Business Media on February 16, 2026 at 8:24 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq discuss whether middle powers should be investing in military cyber capabilities. This episode is also available on Youtube Show notes The Record on Iranian air defences Max Smeets No Shortcuts RunZero sponsor interview

  • Risky Bulletin: Cambodia promises to dismantle scam compounds by April
    by Risky Business Media on February 16, 2026 at 3:14 am

    Cambodia promises to dismantle cyber scam compounds by April, CISA urges companies to adopt the OpenEoX standard, Linux gets post-quantum crypto support, and Palo Alto Networks avoids attributing an APT to China. Show notes Risky Bulletin: Cambodia promises to dismantle scam networks by April

  • Sponsored: Filtering the KEV was really hard … Until now!
    by Risky Business Media on February 15, 2026 at 7:42 pm

    In this sponsored interview Casey Ellis chats to Tod Beardsley, VP of Security at RunZero about Kevology, the company’s analysis of CISA’s KEV list. Kevology lets you easily identify and fix vulnerabilities from the list that are urgent and relevant to you. Show notes KEVology: An analysis of exploits, scores, & timelines on the CISA KEV

  • Risky Bulletin: IcedID malware developer fakes his own death to escape the FBI
    by Risky Business Media on February 13, 2026 at 2:07 am

    A Malware developer faked his own death to evade the FBI, Apple patches a zero-day used in a targeted attack, the Tianfu Cup quietly returns, and researchers spot the first malicious Outlook add-in. Show notes Risky Bulletin: IcedID malware developer fakes his own death to escape the FBI

  • Srsly Risky Biz: Microsoft forgoes its secure future
    by Risky Business Media on February 12, 2026 at 12:46 am

    Tom Uren and Amberleigh Jack talk about Microsoft CEO Satya Nadella’s messaging around personnel changes at the top of its security organisation. These signal a focus on selling security products rather than on making secure products. They also discuss Expedition Cloud, a Chinese cyber range that replicated the critical infrastructure of neighbouring countries, apparently to develop and fine-tune cyber disruption operations. Finally, they talk about what we’ve learnt about the role of cyber operations in the US bombing of Iranian nuclear facilities. It was far bigger than we previously thought. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Chinese cyber-spies breached all of Singapore’s telcos
    by Risky Business Media on February 11, 2026 at 3:02 am

    China has breached all of Singapore’s major telcos, Microsoft announces two new security features, a hacktivist leaks data from a stalkerware provider, and researchers map out ā€œGRU information warfare unitsā€ based on their insignia. Show notes Risky Bulletin: Chinese cyber-spies breached all of Singapore’s telcos

  • Between Two Nerds: Why we are doomed to insecurity
    by Risky Business Media on February 9, 2026 at 8:59 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about why the world is destined to be perpetually insecure. This episode is also available on Youtube. Show notes Hunterbrook’s Ubiquiti investigation Trail of Bits sponsor interview

  • Risky Bulletin: SmarterTools hacked via its own product
    by Risky Business Media on February 9, 2026 at 2:45 am

    A software company gets hacked through vulnerabilities in its own product, European agencies are hacked via recent Ivanti zero-days, Senegal is being extorted by hackers, and a state actor is behind a Signal phishing campaign in Germany. Show notes Risky Bulletin: SmarterTools hacked via its own product

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.