Copyright Risky Business Media 2007-2026
Sep 11, 2026Recent reviews on Apple Podcasts (2)
Great podcast but…
They produce great shows but it gets to be a hard listen when Patrick Gray always talks over everyone. He never lets them finish their thoughts without interjecting all the time. Very annoying to say the least. He clearly wants to be the star.
formersmoker1360 ·
Very informative
Very informative podcast. Love the content. Thank you.
nyboi ·
Episodes (100)

Risky Bulletin: Anthropic agents went hacking again
Sep 11, 202610m
Anthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff. Show notes Risky Bulletin: Anthr

Srsly Risky Biz: America's drivers licence breach is a national security disaster
Sep 10, 202624m
Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences. They also discuss the steps the US military is taking to counter ad

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
Sep 9, 20267m
Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker

Between Two Nerds: Can AI defend critical infrastructure?
Sep 7, 202627m
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line. This episode is also available

Risky Bulletin: BEC campaign steals €35 million from French notaries
Sep 7, 20268m
Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin. Show

Sponsored: Authentik is rethinking PAM for AI agents
Sep 6, 202620m
In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach

Risky Bulletin: Russia tells data centers to deploy drone defenses
Sep 4, 202610m
Russia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs. Show notes Risky Bulletin: Russia tells

Srsly Risky Biz: China's botnets are worth disrupting
Sep 3, 202622m
Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networ

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates
Sep 2, 20269m
A BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness. Show notes Risky Bullet

Between Two Nerds: The perfect hacker
Aug 31, 202629m
In this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals. This episode is also avail

Risky Bulletin: New powers for Dutch intelligence services
Aug 31, 20267m
Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Rus

Sponsored: Attackers need to be right more than once
Aug 30, 202621m
In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across mult

Risky Bulletin: Two TeamPCP members arrested in Australia
Aug 28, 202610m
Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic. Show notes Risky Bulletin: Two TeamPCP members arr

Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting
Aug 27, 202619m
Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attri

Risky Bulletin: Russia starts blocking DoH and DoT
Aug 26, 20268m
Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common. Show notes Risky Bull

Between Two Nerds: Attribution is dead, long live attribution
Aug 24, 202632m
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available o

Risky Bulletin: Expired credit cards can be used for malicious transactions
Aug 24, 20265m
Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars. S

Sponsored: Passkeys won’t stop authorisation phishing
Aug 23, 202620m
In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phish

Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCs
Aug 21, 20266m
The US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge

Srsly Risky Biz: Trump's private hacker memo is the right idea
Aug 20, 202631m
Tom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked

Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
Aug 19, 20267m
Slovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recov

Between Two Nerds: The eye of Sauron
Aug 17, 202632m
In this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders. This episode is al

Risky Bulletin: The EU publishes its upcoming cybersecurity standards
Aug 17, 20268m
The EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction. Show

Sponsored: What npm 12 fixes… and what it doesn’t
Aug 16, 202617m
In this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source

Risky Bulletin: US will let private companies carry out offensive cyber ops
Aug 14, 202611m
The White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet c