惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
Netflix TechBlog - Medium
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
博客园_首页
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
V
Visual Studio Blog
The Cloudflare Blog
罗磊的独立博客
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
博客园 - 叶小钗
The GitHub Blog
The GitHub Blog
Last Week in AI
Last Week in AI
J
Java Code Geeks
MyScale Blog
MyScale Blog
G
Google Developers Blog
U
Unit 42
Y
Y Combinator Blog
P
Proofpoint News Feed
Vercel News
Vercel News

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack
Risky Business #787 -- Trump fires NSA director, CISA cut...
Adam Boileau · 2025-04-09 · via Risky Business

Risky Business Podcast

April 09, 2025

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • Oracle quietly cops to being hacked, but immediately pivots into pretending it didn’t matter
  • NSA and CyberCom leaders fired for not being MAGA enough
  • US Treasury had some dusty corners it hadn’t found China in yet, looked, found China in them
  • …which is a great time to discuss slashing CISA’s staffing
  • Ransomware crews and bullet proof hosting providers are getting rekt, and we love it
  • And Microsoft patches yet another logging 0-day being used in the wild.

This episode is sponsored by Yubico, makers of Yubikey hardware authentication tokens. Yubico’s Vice President of Solutions Architecture and Alliances Derek Hanson joins to discuss how the consumer-centric passkey ecosystem has become a real challenge for enterprises. One that Yubico is actually ideally positioned to solve.

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #787 -- Trump fires NSA director, CISA cuts inbound

0:00 / 53:01

Logo

Show notes

Oracle privately confirms Cloud breach to customers

Oracle have finally issued a written notification to customers about their cybersecurity incident.

Head of NSA and US Cyber Command reportedly fired | Cybersecurity Dive

Trump fires numerous National Security Council staff - The Washington Post

Trump administration under scrutiny as it puts major round of CISA cuts on the table | Cybersecurity Dive

Hackers Spied on US Bank Regulators’ Emails for Over a Year - Bloomberg

This is how Jeffrey Goldberg got added to the Signal chat

Cybercriminals are trying to loot Australian pension accounts in new campaign | The Record from Recorded Future News

$500,000 stolen in Australian super fund data breach | Superannuation | The Guardian

Australian regulator pulls licenses of 95 companies in effort to crack down on investment scams | The Record from Recorded Future News

Everest ransomware group’s darknet site offline following defacement | The Record from Recorded Future News

On March 28, 2025, a threat actor leaked internal data from Medialand, a major bulletproof hosting (BPH) provider long linked to Yalishanda (LARVA-34).

There's a ransomware group named DragonForce going around hacking its rivals. After Mamona and BlackLock, the group has now hacked RansomHub

The DragonForce ransomware group hacked two rivals this month

CISA, experts warn of Crush file transfer attacks as ransomware gang makes threats | The Record from Recorded Future News

Kill Security Campaign Targets CrushFTP Servers

National Vulnerability Database | NIST

Microsoft patches zero-day actively exploited in string of ransomware attacks | CyberScoop

Exploitation of CLFS zero-day leads to ransomware activity | Microsoft Security Blog

Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure (CVE-2025-22457)