Home Podcasts Risky Business
Risky Business

Risky Business

Risky Business Media 100 Episodes Jul 22, 2026

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, it is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Episodes

Risky Business #845 -- OpenAI's Skynet moment
Risky Business #845 -- OpenAI's Skynet moment Jul 22, 2026 4171 On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just
Soap Box: Using threat hunting to drive detection
Soap Box: Using threat hunting to drive detection Jul 8, 2026 2116 In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform th
Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban
Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban Jul 1, 2026 3611 On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail Distillation, cheap tokens, and AI chat harvesting is an industry in China Edge becomes a lolbin via a new malicious extension An Iranian APT boss’s vacation in a be
Risky Business #843 -- Fortibleed is kinda awesome, actually
Risky Business #843 -- Fortibleed is kinda awesome, actually Jun 24, 2026 3815 On this week’s show special guest co-host Rob Joyce joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Rob served as an advisor to Donald Trump during his first term as president and also served at NSA for 34 years. While at the agency, Joyce led Tailored Access Operations (TAO), and later became NSA’s Director of Cybersecurity. They cover
Risky Business #842 -- Anthropic needs an adult in the C suite
Risky Business #842 -- Anthropic needs an adult in the C suite Jun 17, 2026 3599 On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security” Why “guardrails” won’t keep the world safe from your AI doomsday machine The FISA 702 statute expired, but the spying can (probably) continu
Risky Business #841 -- Microsoft gets owned and 0day'd
Risky Business #841 -- Microsoft gets owned and 0day'd Jun 10, 2026 3782 On this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on them Meanwhile, researchers are choosing full disclosure instead of engaging MSRC Meta’s AI s
Soap Box: Detection and response in the AI age
Soap Box: Detection and response in the AI age Jun 5, 2026 2195 In this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Edward Wu, founder of Dropzone, about what AI is doing to detection, response and the SOC more generally. Dropzone makes AI agents that conduct alert investigations in your SOC, but will the SOC as we know it even exist in the future? Ed has a deep expertise in SOC tech, having
Risky Business #840 -- Microsoft walks back researcher threats
Risky Business #840 -- Microsoft walks back researcher threats Jun 3, 2026 3963 On this week’s show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution. They cover: Adversaries are tracking US troop locations with commercially available location data A new Signal phishing ca
Risky Business #839 -- TeamPCP stole GitHub's internal repos
Risky Business #839 -- TeamPCP stole GitHub's internal repos May 27, 2026 3623 On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Mu
Risky Business #838 -- GitHub investigates possible breach
Risky Business #838 -- GitHub investigates possible breach May 20, 2026 3769 On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: GitHub announced a possible breach CISA leaks important creds, keys in public repo Awful vulnerability in Bitlocker renders it useless without a PIN So. Many. Patches. Polish Government urges officials to ditch Signal for mSzyfr Much, much
Soap Box: Where does AI fit into cloud security?
Soap Box: Where does AI fit into cloud security? May 15, 2026 2017 In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler. Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for hi
Risky Business #837 -- GitHub Actions footgun claims TanStack
Risky Business #837 -- GitHub Actions footgun claims TanStack May 13, 2026 3915 On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Mini Shai-Hulud and the TanStack compromise using Github Actions Instructure pays Canvas elearning platform data extortionists More Linux privilege escalation 0days! CISA helping critical infrastructure operators rearchitect their networks so

Recommended