Risky Business cover art

Risky Business

Risky Business

By: Risky Business Media
Listen for free

Summary

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.Copyright Risky Business Media 2007-2026 Politics & Government
Episodes
  • Soap Box: Where does AI fit into cloud security?
    May 15 2026

    In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

    Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

    This episode is also available on Youtube.

    Show notes
      Show More Show Less
      34 mins
    • Risky Business #837 -- GitHub Actions footgun claims TanStack
      May 13 2026
      On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Mini Shai-Hulud and the TanStack compromise using Github ActionsInstructure pays Canvas elearning platform data extortionistsMore Linux privilege escalation 0days!CISA helping critical infrastructure operators rearchitect their networks so they work offline This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”. This episode is also available on Youtube. Show notes ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack | CyberScoopHardening TanStack After the npm Compromise | TanStack BlogCanvas Breach Disrupts Schools & Colleges Nationwide – Krebs on SecurityInstructure pays ransom after Canvas incident as Congress announces investigation | The Record from Recorded Future NewsWhen DNSSEC goes wrong: how we responded to the .de TLD outageAdversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Google Cloud BlogMythos smythos! How to find 0day with lesser models - Risky Business MediaGitHub - V4bel/dirtyfrag · GitHubretr0.zipNVD - CVE-2026-42511Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoopIvanti customers confront yet another actively exploited zero-day | CyberScoopPalo Alto warns of critical software bug used in firewall attacks | The Record from Recorded Future NewsWhere Have All the Complex Windows Malware and Their Analyses Gone?Meet Rassvet, Russia’s Answer to Starlink | WIREDDOJ says ransomware gang tapped into Russian government databases | TechCrunchIranian government hackers using Chaos ransomware as cover, researchers say | The Record from Recorded Future NewsFoxconn confirms cyberattack impacting North American factories | The Record from Recorded Future NewsNew CISA initiative aims for critical infrastructure to operate offline during cyberattacks | The Record from Recorded Future News‘HELLO BOSS’: Inside the Chinese Realtime Deepfake Software Powering Scams Around the WorldHow to Disable Google's Gemini in Chrome | WIREDFCC pushes ban on security updates for foreign-made routers, drones to 2029 | The Record from Recorded Future News
      Show More Show Less
      1 hr and 5 mins
    • Risky Business #836 -- You can't patch the bugpocalypse
      May 6 2026

      On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including:

      • The US Government says we just have to patch faster, but…
      • Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn’t enough
      • James gets mad about lame AI Agent adoption advice from the US and Australian Governments
      • James Kettle and Niels Provos both showed us that any model can find 0day like Mythos
      • And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars

      This week’s show is sponsored by SpecterOps. Their CTO, Jared Atkinson, chats to Pat about the big changes in the threat landscape, brought about by AI, that are causing a pivot away from detection and remediation, and toward prevention.

      This episode is also available on Youtube.

      Show notes
      • Exclusive: US officials weigh cutting deadlines to fix digital flaws amid worries over AI-powered hacking, sources say | Reuters
      • British cyber agency warns of looming ‘patch wave’ as AI speeds flaw discovery | The Record from Recorded Future News
      • Federal agencies must patch cPanel bug by Sunday, CISA says | The Record from Recorded Future News
      • cPanel zero-day exploited for months before patch release (CVE-2026-41940) - Help Net Security
      • The most severe Linux threat to surface in years catches the world flat-footed - Ars Technica
      • New MOVEit vulnerabilities prompt urgent patch warning | Cybersecurity Dive
      • US and allies urge ‘careful adoption’ of AI agents | Cybersecurity Dive
      • careful_adoption_of_agentic_ai_services.pdf
      • User just tricked Grok and Bankrbot to send tokens with Morse code - Cryptopolitan
      • Finding Zero-Days with Any Model
      • (1872) Sponsored: James Kettle built an AI hacker - YouTube
      • Feature Interview: Nicholas Carlini, Anthropic - Risky Business Media
      • Trellix investigating breach of source code repository | Cybersecurity Dive
      • Popular DAEMON Tools software compromised | Securelist
      • Komari Red: The Monitoring Tool with a Built-in Reverse Shell | Huntress
      • Hackers earning millions from hijacked cargo, FBI says | The Record from Recorded Future News
      • Congress punts FISA renewal to June | The Record from Recorded Future News
      • Cops Use Apple Data And Car Bluetooth To Identify Crypto Robbery Suspect
      • Stewart Baker, outspoken voice on cybersecurity and national security law, dies at 78 | IAPP
      Show More Show Less
      1 hr and 2 mins
    adbl_web_anon_alc_button_suppression_c
    No reviews yet