Risky Bulletin Regular cybersecurity news updates from the Risky Business team…
- Risky Bulletin: Chinese researchers claim to find new North American APTby risky.biz on July 7, 2025 at 12:56 am
Chinese security researchers claim to have found a new American APT, the SEC and SolarWinds are seeking a settlement, a company insider was behind Brazilās bank hack, and Luis Vuitton discloses a security breach. Show notes
- Sponsored: Making Zero Trust work with non-critical, crappy applicationsby risky.biz on July 6, 2025 at 10:33 pm
In this sponsored interview, Patrick Gray chats with the CEO of Knocknoc, Adam Pointon. They talk about the woeful state of internal enterprise networks and how many control system networks arenāt appropriately segmented. Adam also explains why Knocknoc released a very simple identity aware proxy: For too long the Zero Trust āindustryā has focussed on securing access to critical applications, while everything else is left behind to get owned. This is Zero Trust for crappy apps! Zero Trust for the rest of us! Show notes
- Risky Bulletin: Hunters International ransomware shuts down, releases decryption keysby risky.biz on July 4, 2025 at 3:57 am
A ransomware operation shuts down and releases free decryption keys, the FBI investigates a ransomware negotiator for taking kickbacks, Spain arrests two over government hacks, and hackers steal $185 million from Brazilian financial institutions. Show notes
- Srsly Risky Biz: Why Iran is a scaredy cat cyber chickenby risky.biz on July 3, 2025 at 2:05 am
Tom Uren and Patrick Gray discuss warnings about Iranian cyber attacks on US critical infrastructure. Despite many many warnings, there have been no actual attacks and they discuss the reasons why Iran would want to avoid escalatory cyber attacks. They also talk about how the FBI is struggling to deal with the democratisation of surveillance and data analysis, what the agency calls Ubiquitous Technical Surveillance (UTS). A Department of Justice audit of the FBIās response finds the threat from UTS is real and that sources have been murdered. But it seems that the FBI just doesnāt care. This episode is also available on Youtube. Show notes
- Risky Bulletin: The US sanctions another Russian bulletproof hosting providerby risky.biz on July 2, 2025 at 3:58 am
The US sanctions another Russian bulletproof hosting provider, the International Criminal Court discloses a security breach, the US dismantles 29 North Korean laptop farms, and a Chinese student gets jailed in the UK for SMS blasting. Show notes
- Between Two Nerds: Microsoft embraces digital sovereigntyby risky.biz on June 30, 2025 at 9:49 pm
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how Microsoft has embraced digital sovereignty and is bending over backwards to satisfy European tech supply chain concerns. This episode is also available on Youtube. Show notes The New York Times on the ICC Microsoft’s 30 April Brad Smith post Microsoft’s 4 June Brad Smith post
- Risky Bulletin: Scattered Spider targets the aviation sectorby risky.biz on June 30, 2025 at 2:02 am
The Scattered Spider group targets the aviation sector, Russia throttles traffic from Cloudflare, a Mexican cartel hired hackers to track an FBI official, and Canada tells Hikvision to cease operations. Show notes
- Sponsored: Why Linux is the dark matter of the internetby risky.biz on June 29, 2025 at 10:55 pm
In this Risky Bulletin sponsor interview Craig Rowland, CEO of Sandfly Security, talks to Tom Uren about the disconnect between how important Linux systems are and how much security attention they get. The pair discuss the variety of reasons that security teams underinvest in protecting Linux. Show notes
- Risky Bulletin: Phishers abuse forgotten Direct Send featureby risky.biz on June 26, 2025 at 11:57 pm
A phishing group abuses a forgotten Exchange Online feature, a patientās death is linked to the Synnovis ransomware attack, France arrests the BreachForums leadership, and Microsoft offers free Windows 10 Extended Security Updates ⦠with a catch. Show notes
- Srsly Risky Biz: Comparing Chinese and American 0day pipelinesby risky.biz on June 26, 2025 at 2:37 am
Tom Uren and Patrick Gray talk about a new report that compares Chinese and American 0day pipelines. The US is narrowly focussed on acquiring exquisitely stealthy and reliable exploits, while China casts a far broader net. That was fine in the past, but as 0days get harder and harder to find, the report argues that the US needs to change the way it goes about getting them. The pair also talk about Cyber Command supporting the US bomb strikes against Iranian nuclear facilities. We like to believe in magic cyber capabilities, but we suspect the truth was far more mundane in this case. This episode is also available on Youtube. Show notes Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace
- Risky Bulletin: Hackers breach Norwegian dam, open valve at full capacityby risky.biz on June 25, 2025 at 3:47 am
Hackers fully open a valve at a Norwegian dam, the US house bans WhatsApp on staff devices, Russia wants to build a national IMEI database, and four REvil members are released after time served. Show notes
- Between Two Nerds: The evil genius of Predatory Sparrowby risky.biz on June 23, 2025 at 9:05 pm
In this edition of Between Two Nerds Tom Uren and The Grugq dive into the motivations and actions of Predatory Sparrow, a purported hacktivist group that has been attacking Iran for the last five years and has leapt into the Iran-Israel war. This episode is also available on Youtube. Show notes
- Risky Bulletin: White House rejects nominee for NSA & CyberCom leaderby risky.biz on June 23, 2025 at 3:04 am
The White House rejects the Pentagonās nominee for NSA & CyberCom leader, the FCC probes the US Cyber Trust Mark program, a cyberattack disrupts Russiaās animal products industry, and hackers leak data about everyone in Paraguay. Show notes
- Sponsored: The geopolitics of trustby risky.biz on June 22, 2025 at 10:53 pm
In this Risky Bulletin sponsor interview Fletcher Heisler, CEO of Authentik, talks to Tom Uren about the inflection points that make organisations consider rationalising their Identity Providers (IdPs). The pair also discuss sovereign tech stacks and how to earn the trust of customers. Show notes
- Risky Bulletin: Russian hackers abuse app-specific passwords to bypass MFAby risky.biz on June 20, 2025 at 3:48 am
Russian hackers abuse app-specific passwords to bypass multi-factor, the tenth Salt Typhoon victim is identified, Predatory Sparrow destroys $90 million from an Iranian crypto-exchange, and Argentina arrests a Russian disinfo gang. Show notes
- Srsly Risky Biz: Data brokers are a killer’s best friendby risky.biz on June 19, 2025 at 2:50 am
Tom Uren and Patrick Gray talk about a Minnesota man who used people-search services to locate, stalk and eventually murder political targets. They also discuss purported hacktivist group Predatory Sparrow weighing in on the Iran-Israel conflict. It has attacked Iranās financial system including a bank associated with the Iranian Revolutionary Guard Corp and also burnt USD$90 million worth of cryptocurrency from an Iranian exchange This episode is also available on Youtube. Show notes
- Risky Bulletin: Israel-linked hackers claim Iran bank disruptionby risky.biz on June 18, 2025 at 4:14 am
An Israeli-linked hacktivist group claims attack on Iranian bank, Chrome gets a new prompt to prevent local network attacks, a Century-old German napkin company goes under following ransomware attack, and Europol takes down the Archetyp dark web market. Show notes
- Between Two Nerds: Why modern influence operations suckby risky.biz on June 16, 2025 at 9:51 pm
In this edition of Between Two Nerds Tom Uren and The Grugq take a look at a new AI-powered covert influence campaign and compare it to World War 2 efforts. This episode is also available on Youtube. Show notes
- Risky Bulletin: Washington Post email accounts hackedby risky.biz on June 16, 2025 at 3:05 am
Email accounts compromised at the Washington Post, shady email provider Cock.li gets hacked, hackers steal data from a French university, and the EU invests ā¬145 million in hospital cybersecurity. Show notes
- Sponsored: Hardening the browserby risky.biz on June 15, 2025 at 8:47 pm
In this Risky Bulletin sponsor interview Michael Leland, Field CTO of Island, talks about how Island manages risks from extensions, phishing and infostealers. Even when credentials are stolen, it is still not game over and there are still ways to prevent data loss and breaches. Show notes