

Risky Business
Risky Business Media
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Episodes
Mentioned books

36 snips
Aug 25, 2025 • 46min
Wide World of Cyber: Microsoft's China Entanglement
In this discussion, cybersecurity experts Alex Stamos, former CISO at Yahoo and Facebook, and Chris Krebs, founding director of CISA, dive deep into Microsoft's controversial ties with Chinese engineers. They uncover how these collaborations raise unsettling national security concerns, particularly regarding the integrity of military cloud systems. Stamos and Krebs also debate the tricky balance between ethical business practices and profit in China’s tech landscape. The conversation highlights implications for trust, transparency, and the tech industry’s future.

35 snips
Aug 20, 2025 • 58min
Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs
Fletcher Heisler, CEO of Authentik and an expert in open-source identity solutions, shares his insights on the intricacies of implementing SSO across different operating systems. He reveals surprising challenges that varied significantly between Windows, Mac, and Linux. The discussion also touches on the broader cybersecurity landscape, including recent issues surrounding Oracle's departing CSO and the critical need for robust identity management solutions. Tune in for a blend of technical challenges and industry insights!

7 snips
Aug 14, 2025 • 36min
Risky Biz Soap Box: How to measure vulnerability reachability
Feross Aboukhadijeh, the founder and CEO of Socket, dives into the complexities of software supply chain security. He discusses how to measure the reachability of vulnerabilities in applications, emphasizing the importance of knowing whether a CVE actually impacts your project. Feross shares insights on the evolution of Socket from tracking malicious packages to tackling CVEs. He also highlights challenges in navigating legacy applications and the critical need for effective detection of malicious packages, advocating for a nuanced approach to software security.

30 snips
Aug 13, 2025 • 60min
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds
Justin Kohler, Chief Product Officer at SpecterOps and the mastermind behind Bloodhound, dives into the world of cybersecurity vulnerabilities and innovations. He discusses the urgent alerts around Microsoft Exchange systems and the risks of integrating legacy and cloud-based applications. Kohler also unveils Bloodhound's latest enhancements, including expanded attack path modeling, and the collaborative efforts within the cybersecurity community. Expect insights into the evolution of identity attacks and how new tools aim to secure complex infrastructures more effectively.

44 snips
Aug 6, 2025 • 1h 6min
Risky Business #801 -- AI models can hack well now and it's weirding us out
Sean Ollerton, Head of Solutions at Devicie, shares insights on the end of Windows 10's mainstream support and the transition to Windows 11. He reassures listeners that the new OS isn't as daunting as it's made out to be. The discussion also addresses the urgency of updating to Windows 11, emphasizing potential security risks in remaining on an unsupported system. Additionally, the rise of AI in cybersecurity is explored, highlighting its impact on bug detection and the need to balance AI tools with human expertise.

50 snips
Aug 1, 2025 • 37min
Soap Box: Why AI can't fix bad security products
Josh Kamdjou, CEO of Sublime Security, dives into the intricate world of AI in cybersecurity. He candidly discusses how AI can enhance security while also acknowledging its limitations. The conversation highlights the critical balance between AI and human oversight, emphasizing that no AI can compensate for poor product design. They explore the challenges and innovations in email security, including the evolution of real-time detection systems and the complexities of automating incident responses, complete with humorous anecdotes about AI mishaps.

42 snips
Jul 30, 2025 • 54min
Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP
Daniel Cuthbert, a cybersecurity expert from Santander Bank, shares insights on the importance of telemetry for securing browser interactions. He highlights how Push Security enhances detection engineering, crucial for responding to threats. The conversation dives into the fallout from a serious SharePoint bug and its implications for organizations, including the US Department of Energy. Cuthbert discusses the importance of user authentication and the struggles many face in maintaining robust security measures amidst rising cyber threats.

28 snips
Jul 23, 2025 • 1h 14min
Risky Business #799 -- Everyone's Sharepoint gets shelled
David Cottingham, CEO of Airlock Digital, shares insights on building robust security management platforms for critical systems. He delves into evolving allow listing software and the challenges of securing user permissions in diverse environments. The discussion also covers recent cyber threats, including vulnerabilities in SharePoint servers and a significant hacking incident in Brazil. Cottingham emphasizes the importance of automation and identity management in enhancing security, while also addressing the need for timely system updates.

20 snips
Jul 14, 2025 • 32min
Risky Biz Soap Box: Prowler, the open cloud security platform
Toni de la Fuente, the founder of Prowler, a multi-cloud security platform, shares insights from his extensive experience as a cloud security architect. He reveals Prowler's evolution from an open-source project to a robust SaaS offering, highlighting its AI-enhanced features like Prowler Lighthouse. The discussion covers Prowler’s community-driven journey and its innovative pricing model, emphasizing the importance of usability and compliance in cloud security. Toni also explores the impact of AI on security interfaces, making cloud management simpler and more efficient.

39 snips
Jul 2, 2025 • 1h 2min
Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses
This week features Jimmy Mesta, co-founder of RAD Security and a specialist in AI automation for cloud security. He shares insights on the rise of technical surveillance tactics by drug cartels to target FBI informants, showcasing a chilling intersection of cybercrime and law enforcement. The conversation also dives into how AI is revolutionizing vulnerability management in cloud environments, emphasizing its role in enhancing security posture. Fascinatingly, it highlights the growing complexities that cyber threats pose to organizations today.


