Episode · Risky Bulletin
Between Two Nerds: Attribution is dead, long live attribution
24 Aug 2026 · 33 min
Episode · Risky Bulletin
24 Aug 2026 · 33 min
In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available on YouTube.
by Risky Business Media · English · Tech & Science
Regular cybersecurity news updates from the Risky Business team...
28 Aug 2026 · 11 min
Two members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic.
27 Aug 2026 · 20 min
Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers by revealing that some of them are hacking the country’s own firms. That’s a new tactic, but making that information public in a Treasury Department sanctions package doesn’t really make sense. This episode is also available on YouTube
26 Aug 2026 · 9 min
Russia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common.
24 Aug 2026 · 6 min
Expired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.
23 Aug 2026 · 20 min
In this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phishing is on the rise. Luke explains how these attacks can survive passkeys and phishing-resistant MFA and, importantly, how defenders can check if their controls against these attacks actually work.
2 Oct 2026 · 10 min
Authorities dismantle the KillSec hacking group, South Africa thwarts a ransomware attack against air traffic control systems, the US sanctions Venezuelan ATM hackers and a Chinese APT targets AI experts.
1 Oct 2026 · 16 min
Amberleigh Jack and James Wilson chat about OpenAI agents’ recent escapades into Australian government websites. OpenAI has promised to “rebuild trust with Australians” but we’re likely getting a glimpse into the new normal, here. They also discuss how the ShinyHunters hacking group has found itself on law enforcement’s target list after breaching FBI systems. The group played some stupid games and they appear to be in the “stupid prizes” stage. This episode is also available on YouTube
30 Sep 2026 · 8 min
A ShinyHunters suspect has been arrested in the Netherlands, Apple fixes an iOS zero-day found by Meta, recent Citrix zero-days see mass exploitation within hours and NVIDIA launches an AI sandboxing platform.
28 Sep 2026 · 28 min
In this edition of Between Two Nerds Tom Uren and The Grugq talk about the rise of fully automated LLM-driven hacking campaigns among criminals and even state hacking groups. For those with the right risk appetite, a move fast and break things hacking approach using AI can pay off. This episode is also available on YouTube.
28 Sep 2026 · 10 min
Intel removes cash rewards from its bug bounty program, OpenAI agents probed dozens of organizations, Fraudsters scam €95 million from an Italian bank and Bitget is hacked for $350 million.