โŒ

Reading view

There are new articles available, click to refresh the page.

Srsly Risky Biz: Being a North Korean hacker is about to be less fun

Tom Uren and James Wilson talk about North Korea losing control over some of its hacker workforce. Expect some tightening of controls and oversight, and perhaps even a reduction in the countryโ€™s ransomware operations.

They also discuss escalating attacks on American water infrastructure. Although the impact of these attacks is relatively minor so far, the US government has been slow to respond from a political perspective.

This episode is also available on YouTube

Show notes

๐Ÿ’พ

Sponsored: The intrusion signals hiding in plain sight

In this sponsored interview James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments.

Ian explains how ordinary-looking events such as a password reset, a new MFA device, unusual searches and a first-time AWS role assumption can combine to reveal an intrusion. Permisoโ€™s platform connects these signals across identity providers, cloud platforms and SaaS applications. They also discuss how AI is helping attackers move from initial access to extortion in just four hours.

Show notes

๐Ÿ’พ

Srsly Risky Biz: Chipping away at Chinese AI risks

Tom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but letโ€™s not forget that Americaโ€™s overriding goal is to remain ahead of China in the AI race. There are better ways to do that than overindexing on distillation.

They also discuss Iranian attacks on US critical infrastructure. Given that the war in Iran is unpopular, incidents that make headlines without causing serious impact are perfectly calibrated.

This episode is also available on YouTube

Show notes

๐Ÿ’พ

Sponsored: How AI is putting pressure on EDR

In this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections.

LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by โ€œburning tokensโ€. The takeaway is that defenders increasingly need to assume attackers have visibility into how their endpoint security products work.

Show notes

๐Ÿ’พ

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach

Rogue OpenAI models were behind last weekโ€™s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.

Show notes

๐Ÿ’พ

โŒ