Risky Bulletin Regular cybersecurity news updates from the Risky Business team…
- Risky Bulletin: Academics pull off novel 5G attackby risky.biz on August 17, 2025 at 11:19 pm
Academics develop a 5G downgrade attack, ransomware hits car salvage yards across North America, multiple VPN apps share the same hardcoded password, and Bangladesh spent $190 million on hacking and surveillance tools. Show notes Risky Bulletin: Academics pull off novel 5G attack
- Risky Bulletin: HTTP2 flaw enables massive DDoS attacksby risky.biz on August 15, 2025 at 1:11 am
An HTTP-2 vulnerability enables DDoS attacks, Russia blocks Telegram and WhatsApp voice calls, attackers abuse a zero-day in N-able servers, and the US government is adding trackers to chip shipments. Show notes Risky Bulletin: MadeYouReset vulnerability enables unlimited HTTP/2 DDoS attacks
- Srsly Risky Biz: Drug cartels are the new APTsby risky.biz on August 14, 2025 at 2:07 am
Tom Uren and Amberleigh Jack talk about a recent hack of the US courts document management system. It’s about as bad as can be, with multiple threat actors including states and possibly even drug cartels rummaging around in there, possibly for years. They also discuss Microsoft’s involvement in an Israeli surveillance system and the head of Australia’s security organisation’s blunt warning about espionage. This episode is also available on Youtube. Show notes
- Risky Bulletin: Russia suspected of US Courts hackby risky.biz on August 13, 2025 at 1:05 am
Russia suspected of hacking a US Court system, researchers break the DarkBit ransomware’s encryption, a new attack can leak sensitive data from AMD processors, and a brute-force campaign targets Fortinet devices. Show notes Risky Bulletin: Crypto-thieves turn their sights to Open VSX
- Risky Bulletin: Researcher scores $250,000 for Chrome bugby risky.biz on August 11, 2025 at 12:34 am
A security researcher scores $250,000 for a Chrome bug, WinRAR patches another zero-day, new vulnerabilities found in the Tetra communications protocol, and a researcher gains access to Microsoft’s internal network for fun… and no profit. Show notes Risky Bulletin: Researcher scores $250,000 for Chrome bug
- Sponsored: The phishing-resistant employeeby risky.biz on August 10, 2025 at 11:00 pm
In this Risky Business News sponsor interview Tom Uren talks to Derek Hanson, Yubico’s Field CTO about making account recovery and onboarding for employees phishing-resistant. They also discuss the problems and opportunities of syncable passkeys. Show notes
- Risky Bulletin: CISA tells federal agencies to mitigate on-prem-to-cloud Exchange attackby risky.biz on August 8, 2025 at 12:47 am
Federal agencies told to patch a new Exchange flaw, millions of sites are vulnerable to HTTP desync attacks, Trend Micro patches a zero-day, and the Salesforce data breaches continue. Show notes Risky Bulletin: CISA tells federal agencies to mitigate on-prem-to-cloud Exchange attack
- Risky Bulletin: Russia’s war on foreign software continuesby risky.biz on August 6, 2025 at 1:11 am
Russian companies must migrate to domestic ERP systems, Ohio’s public sector will have to approve ransom payments in public, Chanel and Cisco disclose data breaches, and a Thai hospital gets fined over the the dumbest data breach ever. Show notes Risky Bulletin: Russia to designate ERPs as “critical information infrastructure”
- Between Two Nerds: The Aeroflot hackby risky.biz on August 4, 2025 at 9:13 pm
In this edition of Between Two Nerds Tom Uren and The Grugq dissect the Belarusian Cyber Partisans hack of Russian airline Aeroflot. Despite the short-term impact, the airline will likely bounce back quite quickly. But it is still a big win for the Cyber Partisans. This episode is also available on Youtube. Show notes The Belarusian Cyber Partisans post on the hack Meduza’s analysis of the hack’s aftermath
- Risky Bulletin: China with the accusations againby risky.biz on August 4, 2025 at 2:10 am
China accuses the US of new cyberattacks, a $14.5b crypto hack discovered five years later, the US National Cyber Director is named, and Lovense considers legal action over a security flaw disclosure. Show notes Risky Bulletin: China with the accusations again
- Sponsored: Tines shines at solving interesting problemsby risky.biz on August 3, 2025 at 11:01 pm
In this week’s sponsor interview, Tines’ Field CISO, Matt Muller, chats to Casey Ellis about the interesting and out-of-the-box ways they’ve seen people using the platform. Tines is a platform designed to automate repetitive tasks for IT and security teams. And, as it turns out, it can be used to … gamify shift handover? Show notes
- Risky Bulletin: Russia spies on local embassies via ISPsby risky.biz on August 1, 2025 at 3:36 am
Russia spies on local embassies via ISPs, a Canadian man jailed for stealing Internet Apes, Signal threatens to leave Australia, and Russian pharmacies go down after a cyberattack. Show notes Risky Bulletin: Russia spies on foreign embassies using local ISPs
- Srsly Risky Biz: The West’s tepid China deterrence is not workingby risky.biz on July 31, 2025 at 1:33 am
Tom Uren and Amberleigh Jack talk about how recent SharePoint exploitation is a blow-by-blow repeat of the 2021 Microsoft Exchange mass compromise event. The international response to that clearly didn’t deter Chinese hackers, so it is time to try something different. They also talk about recent cases where outsourcing IT services has come with increased risk. Convenient, cheap, secure, pick any two. This episode is also available on Youtube. Show notes
- Risky Bulletin: Russia’s Aeroflot cancels flights after hackby risky.biz on July 30, 2025 at 1:10 am
Russia’s national airline cancels more than 100 flights following a cyberattack, the FBI seizes $2.4 million from the Chaos ransomware, Kazakhstan arrests a ransomware suspect, and Kyrgyzstan nationalizes internet access. Show notes Risky Bulletin: US seizes Chaos ransomware funds
- Risky Bulletin: Microsoft investigates MAPP leakby risky.biz on July 27, 2025 at 11:41 pm
Microsoft investigates a MAPP leak as the source of the SharePoint zero-day, US law enforcement takes down the BlackSuit ransomware portal, an Arizona woman is imprisoned for running a North Korean laptop farm, and Allianz life insurance suffers a security breach. Show notes
- Sponsored: Nucleus Security on the evolution of vulnerability managementby risky.biz on July 27, 2025 at 11:30 pm
In this sponsored interview, Nucleus Security co-founder and COO, Scott Kuffer joins Casey Ellis to chat about how vulnerability management evolved into quite a lot more than just patch prioritization. Show notes
- Risky Bulletin: Microsoft rolls out linkable token identifiers to help IR teamsby risky.biz on July 25, 2025 at 4:09 am
Microsoft rolls out better logging for incident responders, the SharePoint hacking spree hits major US agencies, Ukraine arrests the admin of a well-known hacking forum, and China launches a national Digital ID system. Show notes
- Risky Bulletin: Three Chinese APTs are behind the SharePoint zero-day attacksby risky.biz on July 22, 2025 at 11:40 pm
Three Chinese APTs are behind the recent SharePoint zero-day attacks, the UK wants to ban the public sector from paying ransoms, Russia takes down a malware operation, and South Korea charges airline employees over selling celebrity data. Show notes
- Between Two Nerds: How China’s cyber militia make senseby risky.biz on July 21, 2025 at 9:45 pm
In this edition of Between Two Nerds Tom Uren and The Grugq discuss whether China’s ‘cyber militia’ make sense and what they could be good for. This episode is also available on Youtube. Show notes Mobilizing Cyber Power: The Growing Role of Cyber Militias in China’s Network Warfare Force Structure
- Risky Bulletin: Iranian security firm behind airline hacking spreeby risky.biz on July 21, 2025 at 12:54 am
An Iranian security firm is behind an airline hacking spree, Chinese hackers breach Singapore’s critical infrastructure, new SharePoint and CrushFTP zero-days are being used in the wild, and Japan releases free ransomware decrypters. Show notes