Copyright Risky Business Media 2007-2026
Jul 22, 2026Recent reviews on Apple Podcasts (2)
Great podcast but…
They produce great shows but it gets to be a hard listen when Patrick Gray always talks over everyone. He never lets them finish their thoughts without interjecting all the time. Very annoying to say the least. He clearly wants to be the star.
formersmoker1360 ·
Very informative
Very informative podcast. Love the content. Thank you.
nyboi ·
Episodes (100)

Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach
Jul 22, 20266m
Rogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and

Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine
Jul 20, 202627m
In this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine. This episode is also available on YouTube . Show note

Risky Bulletin: Hacker wipes Romania's entire land registry database
Jul 20, 20269m
A hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug

Sponsored: Thinkst on building companies that don’t suck
Jul 20, 202621m
In this Risky Business sponsor interview Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoid

Srsly Risky Biz: Ransomware uses AI to amp up negotiations
Jul 16, 202620m
Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over

Between Two Nerds: Exploits are not cyber power
Jul 13, 202630m
In this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency. Thi

Risky Bulletin: NSA Tailored Access Operations is back
Jul 10, 20267m
The NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor. The Risky Bulletin newsletter and

Sponsored: Why Sublime doesn’t toss AI at every email
Jul 10, 202614m
In this Risky Business sponsored interview, Tom Uren chats with Sublime Security Product Manager AJ Williams about how the company targets its AI use. Rather than throwing its AI agents at everything, Sublime gives them

Srsly Risky Biz: US Supreme Court undermines Section 702 intel
Jul 9, 202627m
Tom Uren and James Wilson talk about a new US Supreme Court decision that puts the current EU-US data sharing agreement at risk. American intelligence collection efforts have been at the centre of legal challenges of the

Risky Bulletin: DHS IG investigates forced CISA reassignments
Jul 8, 20269m
The DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels

Between Two Nerds: Why AI has not meant more hacks. Yet.
Jul 6, 202632m
In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs. This episode is also available

Risky Bulletin: EU official’s phone infected with Pegasus
Jul 6, 20265m
A European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel

Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices
Jul 3, 20269m
FatFs bugs enable physical access attacks on industrial equipment, a clever password spraying attack bypasses M365 MFA, an AI agent is deploying ransomware in live attacks, and a webinar platform sues two security firms

Srsly Risky Biz: America won't beat the distillation ecosystem
Jul 2, 202630m
Tom Uren and James Wilson talk about Chinese AI labs stealing the special sauce of American AI models in ‘distillation attacks’. These attacks are fed by a grey market in which Chinese consumers buy access to American mo

Risky Bulletin: Researcher drops giant cache of zero-days
Jul 1, 20269m
An anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts geofence warrants, and security firm Huntress has denied accusations of a malicio

Between Two Nerds: Set cyberspace ablaze
Jun 29, 202639m
In this edition of Between Two Nerds, Tom Uren and The Grugq discuss whether cyber organisations should actually be separated from Signals Intelligence organisations. The Grugq argues that having cyber expertise subordin

Risky Bulletin: White House asks OpenAI to restrict GPT 5.6
Jun 29, 20267m
The White House asks OpenAI to keep a tight grip on ChatGPT 5.6, the US Secret Service made some appalling OpSec mistakes, AMD has reintroduced a CPU security feature after consumer backlash, and an Iranian APT operator

Sponsored: Corelight’s blueprint for AI-era defence
Jun 29, 202619m
In this sponsored interview James Wilson chats with Corelight’s VP of Product Vijit Nair about defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance bet

Risky Bulletin: Operation Endgame dismantles Amadey and StealerC
Jun 26, 202610m
Law enforcement dismantles two more malware operations, Japan’s army used infected USB drives, Anthropic accuses Alibaba of distillation attacks, and Australia finds “digital dynamite” on critical networks. Show notes Ri

Srsly Risky Biz: Open weight models make the Mythos debate moot
Jun 25, 202628m
Tom Uren and James Wilson talk about the Five Eyes cyber security agencies warning about the arrival of AI-enabled cyber threats. The call-to-action is driven by the recognition that it is no longer possible to limit AI’

Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing
Jun 24, 20268m
The FortiBleed hacks are worse than a credentials leak, a new White House executive order sets out a hard 2031 post quantum cryptography deadline, Meta leaks employee keystroke data, and a third of Samsung and LG TVs act

Sponsored: Trail of Bits and OpenAI patch the planet
Jun 23, 202618m
In this sponsored interview James Wilson chats with Trail of Bits founder and CEO Dan Guido about its newly announced partnership with OpenAI. Together, they’ve started a new initiative called “Patch the Planet” to suppo

Between Two Nerds: The PRC vs AI
Jun 22, 202635m
In this edition of Between Two Nerds Tom Uren and The Grugq discuss the idea that the People’s Republic of China has mobilised its influence operations against the construction of US data centres and its build out of AI

Risky Bulletin: Klue breach impacts security firms
Jun 22, 20268m
A data breach at business analytics platform Klue spreads to security firms, a hacker breaches Brazil’s national alert system, North Koreans are behind the Mastra supply chain attack, and a new, unfixable vulnerability h

Risky Bulletin: Creds for 74,000 Fortinet devices leaked
Jun 19, 202611m
A LOT of Fortinet creds have leaked online, Canada’s spy agency allowed to remove a botnet from Canadian devices, a supply chain attack hits the Mastra AI framework, and Europol disrupts SocGolish. Show notes Risky Bulle