惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
CXSECURITY Database RSS Feed - CXSecurity.com
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
V
Visual Studio Blog
The Register - Security
The Register - Security
Y
Y Combinator Blog
I
InfoQ
小众软件
小众软件
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Scott Helme
Scott Helme
C
Cybersecurity and Infrastructure Security Agency CISA
T
Threatpost
Hacker News: Ask HN
Hacker News: Ask HN
P
Privacy International News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
Arctic Wolf
P
Privacy & Cybersecurity Law Blog
AWS News Blog
AWS News Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Check Point Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Security Archives - TechRepublic
Security Archives - TechRepublic
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
Security Affairs
Cyberwarzone
Cyberwarzone
V
Vulnerabilities – Threatpost
C
Cyber Attacks, Cyber Crime and Cyber Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
爱范儿
爱范儿
Spread Privacy
Spread Privacy
Recent Commits to openclaw:main
Recent Commits to openclaw:main
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog
C
CERT Recently Published Vulnerability Notes
IT之家
IT之家
月光博客
月光博客
雷峰网
雷峰网
博客园 - 【当耐特】
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
NISL@THU
NISL@THU
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack Risky Biz Soap Box: Graph the planet! Risky Business #818 -- React2Shell is a fun one Risky Business #817 -- Less carnage than your usual Thanksgiving Risky Business #816 -- Copilot Actions for Windows is extremely dicey Risky Biz Soap Box: Greynoise knows when bad bugs are coming Risky Business #815 -- Anthropic's AI APT report is a big deal Risky Business #814 -- It's a bad time to be a scam compound operator Risky Business #813 -- FFmpeg has a point Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD Risky Business #811 -- F5 is the tip of the crap software iceberg Wide World of Cyber: A deep dive on the F5 hack Risky Biz Soap Box: Why Mastercard is scaling its cybersecurity business Risky Business #810 -- Data extortion attacks have a silver lining Snake Oilers: Realm Security, Horizon3 and Persona Risky Business #809 -- Hackers try to pay a journalist for access to the BBC Risky Business #808 -- Insane megabug in Entra left all tenants exposed Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc Risky Biz Soap Box: runZero shakes up vulnerability management Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal Snake Oilers: Nebulock, Vali Cyber and Cape Risky Business #805 -- On the Salesloft Drift breach and "OAuth soup" Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy Wide World of Cyber: Microsoft's China Entanglement Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs Risky Biz Soap Box: How to measure vulnerability reachability Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds Risky Business #801 -- AI models can hack well now and it's weirding us out Soap Box: Why AI can't fix bad security products Risky Business #800 — The SharePoint bug may have leaked from Microsoft MAPP Risky Business #799 -- Everyone's Sharepoint gets shelled Risky Biz Soap Box: Prowler, the open cloud security platform Risky Business #798 -- Mexican cartel surveilled the FBI to identify, kill witnesses Risky Business #797 -- Stuxnet vs Massive Ordnance Penetrators Risky Business #796 -- With special guest co-host Chris Krebs Soap Box: AI has entered the SOC, and it ain't going anywhere Risky Business #795 -- How The Com is hacking Salesforce tenants Risky Business #794 -- Psychic Panda outgunned by Fluffy Lizard and UNC56728242 Risky Business #793 -- Scattered Spider is hijacking MX records Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now Risky Biz Soap Box: Push Security's browser-first twist on identity security Risky Business #791 -- Woof! Copilot for Sharepoint coughs up creds and keys Wide World of Cyber: How state adversaries attack security vendors Risky Business #790 -- Bye bye Signal-gate, hello TeleMessage-gate BONUS INTERVIEW: Senator Mark Warner on Signalgate, Volt Typhoon and tariffs Snake Oilers: LimaCharlie, Honeywell Cyber Insights, CobaltStrike and Outflank Snake Oilers: Pangea, Cosive and Sysdig Risky Business #788 -- Trump targets Chris Krebs, SentinelOne Wide World of Cyber: How the Trump admin is changing the cybersecurity landscape Risky Business #787 -- Trump fires NSA director, CISA cuts inbound Risky Business #786 -- Oracle is lying Soap Box: Knocknoc glues your SSO to your firewalls for Just-in-Time network access Risky Business #785 -- Signal-gate is actually as bad as it looks Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects Risky Business #783 -- Evil webcam ransomwares entire Windows network Risky Business #782 -- Are the USA and Russia cyber friends now? Risky Business #781 -- How Bybit oopsied $1.4bn Wide World of Cyber: DeepSeek lobs an AI hand grenade Risky Business #780 -- ASD torched Zservers data while admins were drunk Risky Biz Soap Box: Run your own open source IDP with Authentik Risky Business #779 -- DOGE staffer linked to The Com Risky Business #778 -- Musk's child soldiers seize control of FedGov IT systems Risky Business #777 -- It's SonicWall's turn Risky Business #776 -- Trump will flex American cyber muscles Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser Risky Business #775 -- Cl0p is back, SEC hack disclosures disappoint Wide World of Cyber: SentinelOne's Chris Krebs on Chinese cyber operations Risky Business #774 -- Cleo file transfer appliances under widespread attack Risky Biz Soapbox: Enterprise Yubikeys can now be pre-registered Risky Business #773 -- Cybercriminals are dropping like flies in Russia Risky Business #772 -- Salt Typhoon is truly a national security disaster
Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful
Adam Boileau · 2025-04-30 · via Risky Business

Risky Business Podcast

April 30, 2025

Presented by

Adam Boileau

Adam Boileau

Co-host at large

Patrick Gray

Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:

  • British retail stalwart Marks & Spencer gets cybered
  • South Korean telco sets out to replace all its subscriber SIMs after (we assume) it lost the keymat
  • It’s a good exploit week! Bugs in Apple Airplay, SAP webservers, Erlang SSH and CommVault backups
  • Juice jacking! No, really! Some researchers actually did it (so still not in the wild, then)
  • Anti-DOGE whistleblower sure sounds like he has a point

This week’s episode is sponsored by Knocknoc, who let you glue your firewalls to your single sign on. Knocknoc’s CEO Adam Pointon talks about the joy that having end-to-end IPv6 would bring for zero-trust access control. He also touches on people using Knocknoc inside their network to isolate critical systems.

Editors Note : Pat also gives Adam (Boileau) stick in the sponsor interview about the Risky Biz webserver not having IPv6 enabled, which fact-checking during the edit says is FAKE NEWS. Just uh, don’t look at how fresh that AAAA record in the DNS is, friends 😉

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #789 -- Apple's AirPlay vulns are surprisingly awful

0:00 / 62:31

Logo

Show notes

British retailer M&S confirms being hit by ‘cyber incident’ amid store delays | The Record from Recorded Future News

M&S cyber-attack linked to hacking group Scattered Spider | Marks & Spencer | The Guardian

Bina Puri shares, Warrant B close sharply lower day after hacking

Bina Puri, Pos Malaysia tumble following hacking incident | FMT

Japan warns of hundreds of millions of dollars in unauthorized trades from hacked accounts | The Record from Recorded Future News

US conducts cyberattacks against major Chinese commercial encryption provider: report - Global Times

Iran says major cyberattack on infrastructure repelled | Iran International

Spain rules out cyber attack - but what could have caused power cut?

South Korea's SK Telecom begins SIM card replacement after data breach

AirBorne: Wormable Zero-Click RCE in Apple AirPlay Puts Billions of Devices at Risk | Oligo Security | Oligo Security

iOS and Android juice jacking defenses have been trivial to bypass for years - Ars Technica

How Android 16's new security mode will stop USB-based attacks - Android Authority

Researchers warn of critical flaw found in Erlang OTP SSH | Cybersecurity Dive

Critical vulnerability in SAP NetWeaver under threat of active exploitation | Cybersecurity Dive

CVE-2025-31324: Critical SAP Flaw Explained | Strobes

Fire In The Hole, We’re Breaching The Vault - Commvault Remote Code Execution (CVE-2025-34028)

Risky Bulletin: NFC card malware keeps evolving in Russia, a bad omen for the future - Risky Business Media

Hegseth had unsecured internet line in Pentagon for Signal, sources say | AP News

Whistleblower: DOGE Siphoned NLRB Case Data – Krebs on Security

2025_0414_Berulis-Disclosure-with-Exhibits.s.pdf

CISA gets a deputy director as it braces for major layoffs | Cybersecurity Dive

Two top cyber officials resign from CISA | The Record from Recorded Future News

Ex-CISA chief Chris Krebs leaving SentinelOne following Trump pressure | Reuters

Former cyber official targeted by Trump speaks out after cuts to digital defense

Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today's Adversaries | SentinelOne

ZachXBT on X: "Nine hours ago a suspicious transfer was made from a potential victim for 3520 BTC ($330.7M)"