

Risky Bulletin
Risky Business Media
Regular cybersecurity news updates from the Risky Business team...
Episodes
Mentioned books

7 snips
Apr 2, 2026 • 19min
Srsly Risky Biz: America's next top (cyber) model
Tom Uren, policy and intelligence editor focused on cybersecurity and conflict tech. He describes how AI models now autonomously uncover serious software vulnerabilities. He explains why multiple top AI systems matter for state cyber work. He also talks about Ubiquiti gear replacing Starlink in the Russia–Ukraine fighting and the supply-chain issues that enabled it.

15 snips
Apr 1, 2026 • 9min
Risky Bulletin: Iranian password sprays came first, then came the missiles
Cyber attacks tied to real-world strikes and the link between password spraying and missile targets. A major npm package was hijacked to deliver malware and another leaked source code via a map file. Legal fallout from crypto thefts and wash trading charges surfaced alongside long sentences for scam operators. Reports cover new phishing platforms, zero-days pushing malicious updates, and geopolitical threats to tech firms.

4 snips
Mar 30, 2026 • 26min
Between Two Nerds: More secure but less safe
They contrast declining hacking risks for everyday users with a booming, industrialized scam economy. They dissect real exploits and why opportunity, not just capability, matters. They describe AI-boosted social engineering, from fake vendor sites to a $1.25M VIP WhatsApp crypto con. They recount personal scam encounters and how cheap tooling scales confidence tricks.

Mar 30, 2026 • 7min
Risky Bulletin: Apple adds ClickFix warning to macOS terminal
Apple adds a paste-warning to macOS Terminal to block click-to-execute tricks. A high-profile Gmail breach and a massive EU cloud leak raise fresh data security alarms. A major DeFi platform shuts down after a multimillion-dollar hack. Regulators propose banning non-consensual nudify apps across the EU.

Mar 29, 2026 • 16min
Sponsored: AI is making old school prevention cool again
Adam Pointon, CEO of Knocknoc, a leader in identity-gated access and just-in-time host protection. He explains how AI is accelerating exploit timelines. He describes hiding services until users authenticate. He outlines deny-by-default controls, limiting exposure, and just-in-time allowances for maintenance.

Mar 27, 2026 • 7min
Risky Bulletin: Russia to use custom crypto-algorithm for its 5G network
Discussion of Russia mandating a custom NEA7 crypto algorithm for 5G and plans to boost national firewall capacity. Allegations that spyware targeted Hungarian opposition and a large-scale malware infection hit thousands of Luxembourg government phones. Coverage of data-wiping attacks on Israeli firms, a Dutch police phishing breach, and Google's warning about quantum threats to classical encryption.

Mar 26, 2026 • 21min
Srsly Risky Biz: Why get a warrant when you have Kash?
Tom Uren, policy and intelligence editor who analyzes cybersecurity policy and national security, breaks down the FBI buying Americans’ location data and why commercially sourced tracking raises privacy and oversight concerns. He unpacks FCC moves to restrict foreign-made routers as reshoring politics, not security. He also outlines plans to tap private-sector telemetry for government use.

Mar 25, 2026 • 7min
Risky Bulletin: The CEO of Intellexa is big mad at Greece
Intellexa’s CEO lashes out at Greek authorities over alleged misuse. New U.S. bureau targets emerging cyber and space threats. FCC moves to ban foreign-made routers for national security. Major hacks and a supply-chain compromise hit governments and dev tools. Google unveils a threat disruption unit. German police woke companies to warn about critical software bugs.

Mar 23, 2026 • 24min
Between Two Nerds: Its raining iOS exploit kits!
The Grugq, a security researcher known for analyses of threat actor tradecraft, breaks down recent iOS exploit kit sightings. He discusses why top-tier exploits stay hidden. He explains resale and abuse of older tools. He explores geofenced targeting and operator tweaks that add crypto-theft. Practical advice on updating iOS and using Lockdown Mode is also covered.

Mar 23, 2026 • 7min
Risky Bulletin: Russia's Signal phishing nets thousands of accounts
A deep dive into a mass phishing campaign that linked extra devices to thousands of Signal accounts. A supply-chain sabotage tale where a popular scanner was weaponized to steal credentials and seed an NPM worm. Authorities dismantle massive IoT botnets tied to huge DDoS attacks and seize dark websites. Emergency patches, spyware arrests, and high-profile data breaches round out the briefing.


