❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 25 September 2026Risky Business News

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol

25 September 2026 at 00:17

A major vulnerability has been found in the ancient TACACS+ networking protocol, Australia’s Prime Minister claims an OpenAI agent hacked the country’s Medicare website, OpenAI gives Ukraine access to its Daybreak cyber-defense program and the UK will establish an anti-disinformation center.

Show notes

πŸ’Ύ

Yesterday β€” 24 September 2026Risky Business News

Srsly Risky Biz: Bring on the AI lawsuits

23 September 2026 at 23:47

Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. Its a good move. Leaving the companies on the hook keeps the pressure on them to do better with their cyber security and testing controls.

They also discuss a Russian AI-powered cyberespionage campaign run by a group known as Midnight Blizzard. It used AI workflows to run the entire campaign so they got a lot more hacking done and accepted AI mistakes. This makes sense given that they want more intelligence from Ukrainian targets and don’t care at all about getting caught.

This episode is also available on YouTube.

Show notes

πŸ’Ύ

Before yesterdayRisky Business News

Sponsored: SpecterOps on the impact of AI agents on BloodHound

20 September 2026 at 16:39

In this Risky Business sponsored interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin explains how Entra Agent ID can introduce new identity relationships and potential attack paths.

Show notes

πŸ’Ύ

Srsly Risky Biz: America's drivers licence breach is a national security disaster

9 September 2026 at 23:18

Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.

They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough.

Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy.

This episode is also available on YouTube

Show notes

πŸ’Ύ

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

9 September 2026 at 02:02

Ukraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.

Show notes

πŸ’Ύ

Between Two Nerds: Can AI defend critical infrastructure?

7 September 2026 at 15:58

In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line.

This episode is also available on YouTube.

Show notes

πŸ’Ύ

Risky Bulletin: BEC campaign steals €35 million from French notaries

6 September 2026 at 23:34

Hackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.

Show notes

πŸ’Ύ

Sponsored: Authentik is rethinking PAM for AI agents

6 September 2026 at 16:09

In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt.

Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human.

They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access.

Show notes

πŸ’Ύ

Srsly Risky Biz: China's botnets are worth disrupting

3 September 2026 at 00:19

Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild.

They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal!

Finally, they discuss efforts to fix US water sector security. Sprinkling free tools on the problem will have limited impact.

This episode is also available on YouTube

Show notes

πŸ’Ύ

Risky Bulletin: New powers for Dutch intelligence services

30 August 2026 at 23:20

Dutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service.

Show notes

πŸ’Ύ

Sponsored: Attackers need to be right more than once

30 August 2026 at 16:01

In this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, β€œan attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s β€œcrown jewels”.

The pair chat about where AI helps attackers, why autonomous post-compromise agents aren’t quite here yet, and how AI can bolster the capacity of security teams when investigating alerts and reducing response times.

Show notes

πŸ’Ύ

Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting

27 August 2026 at 00:53

Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution.

They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense.

This episode is also available on YouTube

Show notes

πŸ’Ύ

❌
❌