Risky Business Cybersecurity

Risky Bulletin Regular cybersecurity news updates from the Risky Business team…

  • Srsly Risky Biz: Trump vs Krebs and the sound of silence
    by risky.biz on April 17, 2025 at 3:45 am

    Tom Uren and Patrick Gray discuss Trump’s order singling out Chris Krebs, former head of CISA, that requires investigations into Krebs and also punishes his employer. It is a move deliberately designed to chill dissent and they look at what the cyber security industry will likely do in response, which is probably not much. The pair also discuss what is being interpreted as an admission that Chinese senior leadership is behind the Volt Typhoon hacking of US critical infrastructure. This episode is also available on Youtube. Show notes

  • Risky Bulletin: MITRE says funding risk could disrupt CVE database
    by risky.biz on April 16, 2025 at 3:41 am

    MITRE corporation says funding cuts will impact the CVE database, China accuses NSA employees of an Asian Winter Games hack, a ransomware attack disrupts dialysis clinics, the CA/Browser Forum will limit TLS certificate lifetime to 47 days, and 4chan gets hacked. Show notes

  • Between Two Nerds: Global critical infrastructure
    by risky.biz on April 15, 2025 at 12:25 am

    In this edition of Between Two Nerds Tom Uren and The Grugq look at the idea of global critical infrastructure. One common example is submarine cables, which are globally important but are vulnerable because they are hard to defend. But what about services from tech giants? Are they global critical infrastructure? This episode is also available on Youtube. Show notes

  • Risky Bulletin: China privately admits to hacking US
    by risky.biz on April 14, 2025 at 12:40 am

    China privately admits to hacking American critical infrastructure, the US Treasury was compromised by password spraying, America will sign a global spyware agreement after all, and a Chinese APT is abusing the Windows Sandbox to hide its malware. Show notes

  • Sponsored: The foundations for modern defensible architecture
    by risky.biz on April 13, 2025 at 10:56 pm

    In this Risky Bulletin sponsor interview David Cottingham and Peter Baussman, Airlock Digital’s CEO and CTO, talk to Tom Uren about a new Australian Cyber Security Centre guidance about building defensible networks. The pair cover what they like about the document and where it could be improved. Show notes Foundations for modern defensible architecture

  • Risky Bulletin: Trump orders investigation into former CISA director Chris Krebs
    by risky.biz on April 11, 2025 at 3:19 am

    Trump orders investigation into former CISA director Chris Krebs, the US DOJ disbands its crypto crime team, NSO hires a new lobby team, and researchers raise the alarm on something called ā€œslopsquattingā€. Show notes

  • Srsly Risky Biz: MAGA’s NSA purge will get messy
    by risky.biz on April 10, 2025 at 2:13 am

    Tom Uren and Patrick Gray discuss Trump’s recent firing of General Timothy Haugh, the head of NSA and Cyber Command. Tom dives into the implications and thinks why this is not good news for the agencies. They also discuss Europe losing faith in the US intelligence commitments that underpin transatlantic data flows. That would be bad news for US tech companies. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Hackers leak data from major bulletproof hosting provider
    by risky.biz on April 9, 2025 at 3:51 am

    Hackers leak data from a major Russian bulletproof hosting provider, Australia deregisters 95 companies linked to cyber scams, the US Treasury gets hacked again, and Meta expands ā€œteen accountsā€ to Facebook and Facebook Messenger. Show notes

  • Between Two Nerds: Feast or famine?
    by risky.biz on April 7, 2025 at 9:27 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq look at the idea of ā€˜false scarcities’ in cyber security. Are bugs and talent rare? Or is our thinking blinkered? This episode is also available on Youtube. Show notes

  • Risky Bulletin: Trump fires CyberCom and NSA head
    by risky.biz on April 7, 2025 at 1:56 am

    Trump fires NSA and CyberCom leadership, CISA looks likely to be halved in size, hackers hit Australian pension funds, and NIST gives up on old CVEs in its backlog. Show notes

  • Risky Bulletin: Android looks set to get its own Lockdown Mode
    by risky.biz on April 4, 2025 at 2:11 am

    Android looks set to get its own Lockdown Mode, China overhauls cybersecurity and privacy laws, a crypto platform gets hacked for $70 million dollars, and Greece’s intel agency is set to hire more hackers. Show notes

  • Srsly Risky Biz: North Korean IT workers head to Europe
    by risky.biz on April 3, 2025 at 12:24 am

    Tom Uren and Patrick Gray discuss how North Korean IT worker scam is shifting towards Europe and employing tactics that make it more dangerous. They also discuss why Signalgate was a massive security failure. We learnt this week that US cabinet members were in multiple Signal groups discussing different topics. Phone hacking is not uncommon, an adversary states will be able to take advantage of the intelligence in these conversations. This episode is also available on Youtube. Show notes

  • Risky Bulletin: North Korean IT worker scams expand to Europe
    by risky.biz on April 2, 2025 at 1:29 am

    A North Korean IT worker scheme pivots to Europe after a US crackdown, 24,000 IPs are looking for Palo Alto Networks VPNs, Gmail rolls out end-to-end encrypted emails for enterprise users, and hackers steal over $100 million via Coinbase phishing. Show notes

  • Between Two Nerds: The 800 pound gorilla
    by risky.biz on March 31, 2025 at 8:35 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq look at all the strands of evidence that make people think NSA is a top-tier cyber actor. This episode is also available on Youtube Show notes

  • Risky Bulletin: Oracle’s healthtech division hacked, customers extorted
    by risky.biz on March 31, 2025 at 2:48 am

    Oracle’s Health Tech division gets hacked and its customers extorted, the Italian government admits it used Paragon to spy on an NGO, a WordPress feature is being abused to silently install malicious plugins, and the Dutch public prosecutor pulls systems offline after a cyber incident. Show notes

  • Sponsored: Why hacked geolocation data is worrying
    by risky.biz on March 30, 2025 at 10:03 pm

    In this Risky Bulletin sponsor interview Ed Currie from Kroll Cyber talks to Tom Uren about the recent hack of the Gravy Analytics geolocation data provider. He explains the hack and how geolocation data can be used by malicious actors. Show notes Kroll’s report on the risks of geolocation hacks

  • Risky Bulletin: France runs phishing test on 2.5 million students
    by risky.biz on March 28, 2025 at 2:43 am

    France runs a phishing test on two and a half million students, Google fixes a Chrome zero-day abused for espionage, China publishes new facial recognition rules, and the DragonForce ransomware group hacks two rivals. Show notes

  • Srsly Risky Biz: The Signalgate clown show
    by risky.biz on March 27, 2025 at 1:19 am

    Tom Uren and Patrick Gray discuss how the Signalgate messages betray an alarming lack of security nous at the highest levels of the US natsec leadership. It’s head-scratchingly bad. They also discuss the possibility the Trump Administration will reconstitute the CSRB. The Board wasn’t perfect, but in our view it is better to get it started again rather than waiting for reviews to determine its perfect form. This episode is also available on Youtube. Show notes

  • Risky Bulletin: Cyberattack hits Ukraine’s state railway
    by risky.biz on March 26, 2025 at 3:25 am

    Ukraine’s state railway hit by a cyberattack, a ransomware attack reduces Malaysia’s largest airport to writing flight details on a whiteboard, buggy exploits put DrayTek routers in a reboot loop, and the NIST CVE backlog grows bigger despite efforts to address it. Show notes

  • Between Two Nerds: The 0day fetish
    by risky.biz on March 24, 2025 at 9:42 pm

    In this edition of Between Two Nerds Tom Uren and The Grugq talk about why people studying cyber operations are fascinated by 0days. These are vulnerabilities or exploits that have been found in a system before the vendor or manufacturer is made aware of them and so therefore no fix exists. This episode is also available on Youtube. Show notes

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.