Risky Business

By: Patrick Gray
  • Summary

  • Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
    Copyright Risky Business Media 2007-2025
    Show More Show Less
activate_mytile_page_redirect_t1
Episodes
  • Risky Business #786 -- Oracle is lying
    Apr 2 2025
    On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news: Yes, Oracle Health and Oracle Cloud did get hackedThe fallout from Signalgate continuesNorth Korean IT workers pivot to EuropeHoneypot data suggests a storm is brewing for Palo Alto VPNsCanadian Anon gets arrested for hacking Texas GOP This week’s episode is sponsored by Trail of Bits. Tjaden Hess, a Principal Security Engineer at Trail of Bits who specialises in cryptography, joins the show this week to talk about what a responsible crypto-currency exchange cold wallet setup looks like, and … contrasts that with Bybit. This episode is also available on Youtube. Show notes Oracle Health breach compromises patient data at US hospitalsFBI probes Oracle hack tied to healthcare extortion: Report - Becker's Hospital Review | Healthcare News & AnalysisOracle Still Denies Breach as Researchers PersistHacker linked to Oracle Cloud intrusion threatens to sell stolen data | Cybersecurity DivePublius on X: "🚨 SIGNAL SCANDAL: Katherine Maher, the leftist NPR CEO, is currently the Chair of the Board of Signal! WHAT ARE THE ODDS? https://t.co/jWNTeAt3Jz" / XMike Waltz Is Losing Support Inside the White House - WSJWaltz and staff used Gmail for government communications, officials say - The Washington PostPete Hegseth, Mike Waltz, Tulsi Gabbard: Private Data and Passwords of Senior U.S. Security Officials Found Online - DER SPIEGELEven More Venmo Accounts Tied to Trump Officials in Signal Group Chat Left Data Public | WIREDYou Need to Use Signal's Nickname FeatureSignalGate Is Driving the Most US Downloads of Signal Ever | WIREDWickr - WikipediaWhen Getting Phished Puts You in Mortal Danger – Krebs on SecurityDPRK IT Workers Expanding in Scope and Scale | Google Cloud BlogHow the FBI Tracked, and Froze, Millions Sent to Criminals in Massive Caesars Casino HackDefense contractor to pay $4.6 million over third-party provider’s security weakness | The Record from Recorded Future NewsSurge in Palo Alto Networks Scanner Activity Indicates Possible Upcoming ThreatsCISA warns new malware targeting Ivanti zero-day vulnerability | Cybersecurity DiveCanadian hacker arrested for allegedly stealing data from Texas Republican Party | The Record from Recorded Future NewsBritish intel intern pleads guilty to smuggling top secret data out of protected facility | The Record from Recorded Future News
    Show More Show Less
    55 mins
  • Soap Box: Knocknoc glues your SSO to your firewalls for Just-in-Time network access
    Mar 26 2025

    In this Soap Box edition of Risky Business host Patrick Gray talks to Knocknoc CEO Adam Pointon about how to easily rein in attack surface by glueing your single sign-on service to your network controls.

    Do your Palo Alto and Fortinet devices really need to be discoverable by ransomware crews? Does your file transfer appliance need to be open to the whole world? What about your SSH and RDP? Your Citrix? Your (gasp) Exchange Online servers??

    You can do a lot with IP allowlisting and simple Identity Aware Proxies (IAPs) to minimise your exposure.

    Knocknoc is a bit of a “Risky Business special”, too. Pat helped Knocknoc to raise a seed round through Decibel Partners where he’s a founder advisor. He also serves on Knocknoc’s board of directors.

    This episode is also available on Youtube.

    Show notes
      Show More Show Less
      31 mins
    • Risky Business #785 -- Signal-gate is actually as bad as it looks
      Mar 26 2025

      On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

      • Yes, the Trump admin really did just add a journo to their Yemen-attack-planning Signal group
      • The Github actions hack is smaller than we thought, but was targeting crypto
      • Remote code exec in Kubernetes, ouch
      • Oracle denies its cloud got owned, but that sure does look like customer keymat
      • Taiwanese hardware maker Clevo packs its private keys into bios update zip
      • US Treasury un-sanctions Tornado Cash, party time in Pyongyang?

      This week’s episode is sponsored by runZero. Long time hackerman HD Moore joins to talk about how network vulnerability scanning has atrophied, and what he’s doing to bring it back en vogue. Do you miss early 2000s Nessus? HD knows it, he’s got you fam.

      This episode is also available on Youtube.

      Show notes
      • The Trump Administration Accidentally Texted Me Its War Plans - The Atlantic
      • Using Starlink Wi-Fi in the White House Is a Slippery Slope for US Federal IT | WIRED
      • Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories' CI/CD Secrets Exposed
      • GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident: Threat Assessment (Updated 3/21)
      • Critical vulnerabilities put Kubernetes environments in jeopardy | Cybersecurity Dive
      • Researchers back claim of Oracle Cloud breach despite company’s denials | Cybersecurity Dive
      • The Biggest Supply Chain Hack Of 2025: 6M Records Exfiltrated from Oracle Cloud affecting over 140k Tenants | CloudSEK
      • Capital One hacker Paige Thompson got too light a sentence, appeals court rules | CyberScoop
      • US scraps sanctions on Tornado Cash, crypto ‘mixer’ accused of laundering North Korea money | Reuters
      • Tornado Cash Delisting | U.S. Department of the Treasury
      • Major web services go dark in Russia amid reported Cloudflare block | The Record from Recorded Future News
      • Clevo Boot Guard Keys Leaked in Update Package
      • Six additional countries identified as suspected Paragon spyware customers | CyberScoop
      • The Citizen Lab’s director dissects spyware and the ‘proliferating’ market for it | The Record from Recorded Future News
      • Malaysia PM says country rejected $10 million ransom demand after airport outages | The Record from Recorded Future News
      • Hacker defaces NYU website, exposing admissions data on 1 million students | The Record from Recorded Future News
      • Notre Dame uni students say outage creating enrolment, graduation, assignment mayhem - ABC News
      • DNA of 15 Million People for Sale in 23andMe Bankruptcy
      Show More Show Less
      59 mins

    What listeners say about Risky Business

    Average Customer Ratings

    Reviews - Please select the tabs below to change the source of reviews.

    In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.