Download Podcasts as MP3

Search for a podcast, browse episodes, and download MP3 files directly from the publisher's website. Transcripts included when available.

Episodes from Risky Bulletin

Risky Bulletin: Recently patched PAN 0day exploited in the wild

Risky Bulletin: Recently patched PAN 0day exploited in the wild

A new Palo Alto Networks firewall bug is being exploited in the wild, Russia expands SORM surveillance, NIST is looking for new post quantum algorithms, and ENSOC launches in Europe. Show notes Risky Bulletin: Russia greatly expands SORM surveillance requirements

Jun 1, 20267 min
Sponsored: Inside CISA's disastrous secrets leak

Sponsored: Inside CISA's disastrous secrets leak

In this sponsored interview Casey Ellis chats with Truffle Security’s founder and CEO Dylan Ayrey about the recent CISA secrets leak. Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA’s org. Dylan walks through why deleting the repo doesn’t fix anything, why most cloud vendors won’t hard-revoke exposed keys (OpenAI and Slack will; AWS, Google and friends mostly won’t), why Hugging Face datasets now hold more secrets than GitHub itself, and what the next gener...

May 31, 202619 min
Risky Bulletin: Dutch police take down 17m device botnet

Risky Bulletin: Dutch police take down 17m device botnet

Dutch police take down a botnet of 17 million devices, US military staff have been tracked with ad-tech location data, a Google engineer is arrested for insider trading on Polymarket, and Gogs and the Casdoor IAM leave major bugs unpatched. Show notes Risky Bulletin: Dutch police take down giant botnet of 17 million devices

May 29, 20268 min
Risky Bulletin: Iran to reconnect to the Internet

Risky Bulletin: Iran to reconnect to the Internet

Iran will reconnect to the Internet, a new vulnerability lets attackers bypass authentication on AI infrastructure, hackers breach Lithuania’s state registry, security firms take down the Glassworm botnet, and CERT India releases strict patching advice. Show notes Risky Bulletin: BadHost vulnerability bypasses authentication on AI infrastructure

May 27, 20266 min
Risky Bulletin: Mythos has found thousands of critical bugs

Risky Bulletin: Mythos has found thousands of critical bugs

Anthropic says Mythos has found thousands of critical bugs, hackers leak documents from a Russian disinfo group, GitHub rolls out new npm security features, and Dutch police raid two bulletproof hosting providers. Show notes Risky Bulletin: Mythos has found thousands of critical bugs

May 25, 20268 min
Sponsored: Teaching AI agents the rules of the road

Sponsored: Teaching AI agents the rules of the road

In this sponsored interview James Wilson chats with Sondera CEO Josh Devon about why guardrails and instruction files aren’t enough to keep AI agents from going haywire. EDR, DLP and other traditional controls can’t and won’t prevent agents from going rogue. Josh explains Sondera’s “principle of least autonomy” for agents: let them do useful work, but put them in a deterministic policy harness so they can’t leak secrets, abuse tools or wander off-task. Show notes

May 24, 202626 min
Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Risky Bulletin: Microsoft ends SMS MFA for personal accounts

Microsoft ends support for SMS MFA on personal accounts, GitHub was hacked via a malicious VS Code extension, CISA will let researchers submit new KEV entries, and an SMS blaster was detained at Eurovision. Show notes Risky Bulletin: Microsoft ends SMS MFA for personal accounts

May 22, 20269 min
Srsly Risky Biz: Politicians ditch Signal for homegrown apps

Srsly Risky Biz: Politicians ditch Signal for homegrown apps

Tom Uren and James Wilson talk about moves from several European governments to ditch Signal and set up their own encrypted messaging systems for internal government use. These efforts are motivated by concerns about phishing and sovereignty, but the solutions being adopted are imperfect and will come with their own set of problems. Signal fills a space that can’t be filled with sovereign capability. They also talk about Fast16 malware. We are only now learning about the second arm of a mid-2000s campaign to delay Iran’s nuclear weapons program that included the infamous Stuxnet worm...

May 21, 202628 min
Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs

Risky Bulletin: Microsoft takes down crime SaaS used by ransomware gangs

Microsoft disrupts a malware-signing service used by ransomware gangs, a CISA contractor leaks sensitive GovCloud keys, vulnerability exploitation is now the dominant network entry vector, and Drupal readies security updates for a “highly critical” vulnerability. Show notes Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs

May 20, 20268 min
Between Two Nerds: Russia's hacker university

Between Two Nerds: Russia's hacker university

In this edition of Between Two Nerds Tom Uren and The Grugq look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russia’s cyber program and look at what Western intelligence agencies do instead. This episode is also available on YouTube. Show notes The GRU's Hogwarts Vlodymyr Styran's substack BTN92 with Alex Joske, how the MSS became a cyber juggernaut

May 19, 202629 min
Risky Bulletin: Indonesia emerges as a new hub for cyber scams

Risky Bulletin: Indonesia emerges as a new hub for cyber scams

Indonesia emerges as a new cyber scam hub, Grafana got hacked and held for ransom, the Fast16 malware subverted software used to simulate nuclear explosions, and a new Microsoft Exchange zero-day is under attack. Show notes Risky Bulletin: Indonesia emerges as a new hub for cyber scams

May 18, 202610 min
Sponsored: Push Security goes AI threat hunting in browser telemetry

Sponsored: Push Security goes AI threat hunting in browser telemetry

In this sponsored interview James Wilson chats with Push Security’s Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform. Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers. Show notes

May 17, 202614 min