Risky Business

40 Episodes
Subscribe

By: Risky Business Media

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

✂️ Turn this podcast into clips
Risky Business #854 -- We're Jevpilled
Today at 6:08 AM

THE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14

On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including:

Google’s Gemini finally did some crimes OpenAI admits more agents did silly things because “alignment” US Treasury’s Scott Bessent rules out a liability waiver for the frontier labs, saying, roughly: “Lol. Lmao even.” Jev is Silicon Valley’s “hot dog/not hotdog” app brought to life, and it will really improve security tooling The FBI and Coast Guard boarde...


Risky Business #853 -- We're all gonna die, apparently
09/16/2026

On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including:

More tech guys penned more open letters and AI will destroy us all! Another Wednesday, another congregation of OpenAI agents on wikis… yawn OpenAI agents were behind the headscratching RubyGems hacking campaign in May The FBI will disrupt more adversary operations, NSA is creating more mission centres, lawmakers want sanctions on hackers-for-hire… Release more hounds! So many platforms, so many bugs, so many pa...


Snake Oilers: watchTowr, XBOW and CoreView
09/11/2026

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do? XBOW: The AI pentesting company pitches its approach CoreView: Your M365 tenant is probably a security disaster. Tame it with CoreView!

This episode is also available on YouTube.

Show notes


Risky Business #852 -- Cyber Command wants to buy shells
09/09/2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including:

ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits The US government plans to pay private contractors to conduct military hacks The US accuses China of distillation attacks, a.k.a. forbidden training It’s Wednesday, so OpenAI’s agents escaped sandboxes again and passed notes around on a German Wiki Much, much more…

This week’s show is brought to y...


Risky Business #851 -- Agents are just ones and zeros, and tigers are just atoms
09/02/2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including:

Two alleged TeamPCP hackers got arrested in Australia The White House has a plan to boost security for water facilities, but we can’t see it working OpenAI keeps the ol’ Hugging Face discourse going for another week with an incident debrief Tech companies write another open letter about AI… we’re getting CISA Shields Up flashbacks, but for robots Much, much more…

This week’s show is brought to you by Ent AI. Co-found...


Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
08/26/2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:

Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too. Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet Prompt injection isn’t going away LLMs are deceiving us meat sacks and it’s a worry Much, much mor...


Risky Business #849 -- Trump will unleash contractors on cybercriminals
08/19/2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including:

Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing Anthropic’s models start a turf war when given the same task, surprising… nobody We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something. Much...


Soap Box: Zero Trust(ish) Networks
08/14/2026

In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture.

Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049.

Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible.

Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It...


Risky Business #848 -- OpenAI comes clean
08/12/2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:

The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed It turns out TeamPCP has been around longer than we thought and predates the AI era S...


Risky Business #847 -- Oops! Claude's accidental hacking spree
08/05/2026

On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including:

Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is so chaotic, Microsoft can’t patch fast enough A ColdCard wallet flaw led to millions in Bitcoin theft, but the back story behind the bug is bonkers Iran hacks and disrupts water infrastructure in multiple American states North Korea’s state-backed hackers turn criminal. Or their criminals turn into state-b...


Risky Business #846 -- OpenAI built a fireplace out of wood
07/29/2026

On this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:

Everyone signs the open weights open letter, except Anthropic… of course. OpenAI had no idea it had hacked Hugging Face Kimi K3 open weights released and they’re massive! Why a more aggressive response is needed to cyber attacks on OT And much, much more!

This week’s show is brought to you by SpecterOps. In this week’s sponsor interview Justin Kohler...


Risky Business #845 -- OpenAI's Skynet moment
07/22/2026

On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover:

Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just because of Microsoft’s GDID And much, much more!

This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing...


Soap Box: Using threat hunting to drive detection
07/08/2026

In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection.

Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections.

This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do...


Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban
07/01/2026

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail Distillation, cheap tokens, and AI chat harvesting is an industry in China Edge becomes a lolbin via a new malicious extension An Iranian APT boss’s vacation in a beautiful place goes wrong Much, much more!

In this week’s sponsor interview Daf Stuttard and Katie Warren from Portswigger pop along to talk about how they built an AI security testing product that people would actual...


Risky Business #843 -- Fortibleed is kinda awesome, actually
06/24/2026

On this week’s show special guest co-host Rob Joyce joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Rob served as an advisor to Donald Trump during his first term as president and also served at NSA for 34 years. While at the agency, Joyce led Tailored Access Operations (TAO), and later became NSA’s Director of Cybersecurity.

They cover:

The surprisingly well done Fortibleed campaign Stolen Klue OAuth tokens lead to Salesforce data theft OpenAI wants to patch the planet runZero gets acquired by Accenture, congrats HD Moore! Much, much more!

This...


Risky Business #842 -- Anthropic needs an adult in the C suite
06/17/2026

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

Anthropic’s Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security” Why “guardrails” won’t keep the world safe from your AI doomsday machine The FISA 702 statute expired, but the spying can (probably) continue! NPM v12 delivers some protection against supply chain attacks, but not enough. Microsoft has a series of bugs that prevent Windows Update from … updating Much, much more!

This episode is also available on YouTube

Show notes

...


Risky Business #841 -- Microsoft gets owned and 0day'd
06/10/2026

On this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news.

They cover:

Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on them Meanwhile, researchers are choosing full disclosure instead of engaging MSRC Meta’s AI support agent allowed a staggering 20,000 accounts to be stolen! Apple pulls Russia’s MAX messenger from the App Store and disables notifications Anthropic gives the public our first Mythos-class model but it won’t do cybersecurity work Stripe and...


Soap Box: Detection and response in the AI age
06/05/2026

In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Edward Wu, founder of Dropzone, about what AI is doing to detection, response and the SOC more generally.

Dropzone makes AI agents that conduct alert investigations in your SOC, but will the SOC as we know it even exist in the future?

Ed has a deep expertise in SOC tech, having previously led AI/ML detection engineering at Extrahop. This interview is a fantastic look at what the future may bring for detection and response professionals.

This episode...


Risky Business #840 -- Microsoft walks back researcher threats
06/03/2026

On this week’s show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution.

They cover:

Adversaries are tracking US troop locations with commercially available location data A new Signal phishing campaign is going after message backups 404 Media is suing ICE to get its spyware contract with REDLattice (lol) Microsoft’s tone-deaf response to ‘never justifiable’ zero-day disclosures Mini Shai-Hulud pops up again just as Glassworm gets shattered Much, much more

This week’s ep...


Risky Business #839 -- TeamPCP stole GitHub's internal repos
05/27/2026

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Much, much more

This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Daniel Schell join Patrick Gray to talk about Microsoft briefly flagging DigitCert’s root certificate as malware. Fun!

This episode is...


Risky Business #838 -- GitHub investigates possible breach
05/20/2026

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

GitHub announced a possible breach CISA leaks important creds, keys in public repo Awful vulnerability in Bitlocker renders it useless without a PIN So. Many. Patches. Polish Government urges officials to ditch Signal for mSzyfr Much, much more

This week’s show is brought to you by Thinkst Canary. Thinkst’s founder, Haroon Meer, is this week’s sponsor guest. He joined James Wilson to talk about how doing “the basics” in security isn’t trivially easy.<...


Soap Box: Where does AI fit into cloud security?
05/15/2026

In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler.

Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated.

...


Risky Business #837 -- GitHub Actions footgun claims TanStack
05/13/2026

On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.

They cover:

Mini Shai-Hulud and the TanStack compromise using Github Actions Instructure pays Canvas elearning platform data extortionists More Linux privilege escalation 0days! CISA helping critical infrastructure operators rearchitect their networks so they work offline

This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick about how agentic AI is being evaluated by buyers in a marketplace that’s experiencing “AI fatigue”.

This episode is also available on Youtube.

...


Risky Business #836 -- You can't patch the bugpocalypse
05/06/2026

On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including:

The US Government says we just have to patch faster, but… Bugs in cPanel, MoveIt and all Linux distributions this week show that patching alone isn’t enough James gets mad about lame AI Agent adoption advice from the US and Australian Governments James Kettle and Niels Provos both showed us that any model can find 0day like Mythos And the cyber-assisted theft of cargo results in an astonishing loss of $725 million dollars ...


Snake Oilers: Ent AI, Spacewalk and Mondoo
05/01/2026

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

Ent AI: Co-founder Brandon Dixon pitched Ent, an intent-aware, AI-powered endpoint security control.

Spacewalk AI: Founders Chris Fuller and Tim Wenzlau pitch Spacewalk, an AI-powered incident response platform.

Mondoo: Co-founder Dominik Richter pitches Mondoo, an AI-powered “service as software” in the vulnerability management space.

This episode is also available on YouTube.

Show notes


Risky Business #835 -- Why the Fast16 malware is badass
04/29/2026

On this week’s show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week’s cybersecurity news, including:

The US government is mad as hell about Chinese firms stealing American AI technology Dmitri has an opinion or two about the US selling Nvidia chips to China Speaking of Chinese AI, Kimi’s new 2.6 is very interesting The US sanctions a Cambodian senator for earning mega bucks through scam compounds And a ransomware family is promoting itself as being … quantum-safe?

This week’s show is sponsored by Trail of Bits. CEO and co-fou...


Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs
04/22/2026

On this week’s show, Patrick Gray and James Wilson are joined by special guest The Grugq. They discuss the week’s cybersecurity news, including:

Vercel got owned, and there’s a few infostealer and compromised employee dots to connect Mozilla used Mythos to find 271 bugs, which feels like a sign of the bug-pocalypse Speaking of the bug-pocalypse, is that why NIST is noping out of enriching a bunch of bugs? The NSA is using Mythos even though the government did that whole Anthropic blacklisting thing And DDos attacks hit a couple of smaller-player socials

This week’s episod...


Risky Business #833 -- The Great Mythos Freakout of 2026
04/15/2026

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet CISA adds a 2009 Excel bug to the KEV list, u wot? Adobe also parties like it’s the 2000s, and fixes an Acrobat Reader bug Disgraced former Trenchant exec Peter Williams’ sob story fails to resonate with … anyone Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were “secured” by the password: 1234.

This week’s episode is sponsored by mobile network...


Snake Oilers: Burp AI, Sondera and Truffle Security
04/09/2026

In this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products:

Burp AI and DAST: The founder of PortSwigger and creator of legendary security software Burp Suite, Dafydd Stuttard, drops by to pitch listeners on Burp AI and Burp Suite DAST.

Sondera: Josh Devon talks about Sondera, a technology designed to intervene when AI models start doing the wrong thing by statefully tracking their trajectories. This isn’t a permissions suite for AI agents, it’s a way to stick agents in a harness and make sure they...


Risky Business #832 -- Anthropic unveils magical 0day computer God
04/08/2026

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

Anthropic’s new Mythos model hunts bugs and chains exploits together so well that… you cant have it… …Unless you’re one of their Project Glasswing partners The world isn’t short on bugs, though. F5, Fortinet, Progress ShareFile, and TrueConf are all getting rekt by humans GPU Rowhammering goes in the GPU, past the IOMMU and back into the host-side Nvidia driver North Korea is spending serious time and money on its crypto hacking Just when the US needs CISA mo...


How the World Got Owned Episode 2: The 1990s, Part One
04/03/2026

In this special documentary episode, Patrick Gray and Amberleigh Jack take a look back at hacking throughout the 1990s, from the feel-good vibes of the early hacking communities to the antics of young hackers who wound up on the run from the FBI.

Part one features recollections from:

Jeff Moss (The Dark Tangent), DefCon and Black Hat founder Chris Wysopal (Weld Pond), L0pht member, co-founder, @Stake Kevin Poulsen (Dark Dante), 1990s hacker turned journalist Elias Levy (Aleph One), author of Smashing the Stack for Fun and Profit, Phrack, 1996

How the World Got Owned is...


Risky Business #831 -- The AI bugpocalypse begins
04/01/2026

On this week’s show, Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:

Those pesky North Koreans shim a backdoor into a 100M-downloads-a-week npm package TeamPCP appear to have ransacked Cisco’s source and cloud environments AI is getting legitimately good at being told to “just go find some 0day in this” Kaspersky says Coruna and Triangulation do share code lineage Iranian hackers dump Kash Patel’s gmail spool Oh, and of course there’s a Citrix Netscaler memory leak being exploited in the wild

This week’s episode is sponsored by Dro...


Soap Box: Red teaming AI systems with SpecterOps
03/27/2026

In this sponsored Soap Box edition of the show, Patrick Gray and James Wilson talk about red teaming AI systems with Russel Van Tuyl, Vice President of Services at elite penetration testing firm SpecterOps.

SpecterOps is the company behind attack path enumeration tool Bloodhound and Bloodhound Enterprise, but they’re also a pentest and red teaming shop with world class expertise in popping shells on all sorts of interesting systems in all sorts of interesting places.

This episode is also available on Youtube.

Show notes


Risky Business #830 -- LiteLLM and security scanner supply chains compromised
03/25/2026

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They talk through:

TeamPCP’s supply chain attack on Github, and they threw in an anti-Iran wiper, because why not?! Anthropic hooks up its models to just… use your whole computer After Stryker’s Very Bad Day, CISA says maybe add some more controls around your Intune? Another iOS exploit kit shows up in the cyber bargain-bin The FTC decides to ban… all new home routers?! U wot m8?! Supermicro founder was personally sanction-busting Nvidia GPUs into China?!

This week’s episo...


Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat
03/18/2026

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They discuss:

Iran’s Intune-based wiper attack on medical device maker Stryker Qihoo 360’s AI publishes its own wildcard TLS cert private key Instagram is canning its end-to-end encrypted messaging What’s going on with mobile internet access in Moscow? The Xbox One’s bootloader gets voltage glitched into submission Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt files…)

This week’s episode is sponsored by browser-based detection and response company, Push Security. R...


Risky Biz Soap Box: It took a decade, but allowlisting is cool again
03/12/2026

In this Soap Box edition of the Risky Business podcast Patrick Gray sits down with Airlock Digital co-founders Daniel Schell and David Cottingham to talk about the role AI models could play in managing enterprise allowlists.

They also talk about the durability of allowlisting as a control. After 12 years in business, the Airlock product hasn’t really changed all that much. That’s a good thing! It also means the Airlock team have been able to spend some time doing deep engineering instead of chasing the latest attacker TTPs and writing detection rules for them.

This...


Risky Business #828 -- The Coruna exploits are truly exquisite
03/11/2026

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

The Coruna exploits were L3 Harris, but it seems Triangulation… was not! Iran’s cyber HQ hit by Israeli (kinetic) strikes Trump’s cyber “strategy” is … well, all we’ve got is jokes cause there’s no serious content NSA and CyberCom finally get a leader after Lt Gen Joshua Rudd gets Senate nod DOGE (remember them?!) employee walked a social security database out on a USB stick

This episode is sponsored by open source cloud security scanner Prowler. Cre...


Risky Business #827 -- Iranian cyber threat actors are down but not out
03/04/2026

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

The US-Israeli attack on Iran had a whole lot of cyber. It’s clearly in the playbook now! The NSA Triangulation / L3 Harris Trenchant iOS exploit kit is on the loose, and being used by Chinese crypto scammers So long Maddhu Gottumukkala, but CISA’s annus horribilis continues Adam “humbug” Boileau complains about the Airsnitch wifi attack just being three ethernets in a trenchcoat ASD’s Cisco SD-WAN threat hunting guide is clearly borne of … experience

This week’s episode i...


Risky Business #826 -- A week of AI mishaps and skulduggery
02/25/2026

On this week’s show, Patrick Gray, Adam Boileau and James WIlson discuss the week’s cybersecurity news. They cover:

Low skill actors compromise 600 Fortinets with AI-generated playbooks Anthropic calls out Chinese AI firms over model distillation Meta’s director of AI safety tells her ClawdBot not to delete her mail… so of course it does Peter Williams cops 7 years in jail for selling L3 Harris Trenchant’s exploits to Russia Ivanti got hacked in 2021 via… bugs in Ivanti

This episode is sponsored by line-rate network capture system Corelight. CEO Brian Dye joins to discuss what AI can do for d...


Risky Biz Soap Box: The lethal trifecta of AI risks
02/19/2026

There’s a lethal trifecta of AI risks: access to private data, exposure to untrusted content, and external communication. In this conversation, Risky Business host Patrick Gray chats with Josh Devon, the co-founder of Sondera, about how to best address these risks.

There is no magic solution to this problem. AI models mix code and data, are non-deterministic, and are crawling around all over your enterprise data and APIs as you read this.

But in this sponsored interview, Josh outlines how we can start to wrap our hands around the problem.

This episode is...