On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

Why former Uber CISO Joe Sullivan’s guilty verdict shouldn’t worry you
United States puts chipmaking restrictions on China, APT activity is coming
Elon blinks and Starlink goes dark on Ukraine’s front line
Master cyber criminal arrested in Australia
Much, much more

This week’s show is brought to you by runZero, the asset inventory and network visibility solution. runZero’s founding CTO and industry legend HD Moore is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.



Show notes


Risky Biz News: Good news for the Capital One hacker, bad news for the former Uber CSO

Joe Sullivan guilty in Uber hacking case - The Washington Post

Security chiefs fear ‘CISO scapegoating’ following Uber-Sullivan verdict - The Record by Recorded Future

U.S. imposes foreign direct product rule on China for AI and supercomputing - The Washington Post

Popular censorship circumvention tools face fresh blockade by China | TechCrunch

'Fear' driving Chinese state to manipulate tech ecosystem... - GCHQ.GOV.UK

Risky Biz News: China blocks several protocols used to bypass the Great Firewall

Joint_CSA_Top_CVEs_Exploited_by_PRC_cyber_actors_TLPWHITE - DocumentCloud

Starlink goes dark

Coverage of Killnet DDoS attacks plays into attackers' hands, experts say - The Record by Recorded Future

Ukrainian cybersecurity officer killed by Russian missile strike - The Record by Recorded Future

Biden signs new US-EU privacy framework, setting up surveillance safeguards - The Record by Recorded Future

White House to unveil ambitious cybersecurity labeling effort modeled after Energy Star

Australian teen charged with using leaked Optus data to blackmail customers - The Record by Recorded Future

Report: Big U.S. Banks Are Stiffing Account Takeover Victims – Krebs on Security

Hackers steal at least $100 million from Binance-linked blockchain - The Record by Recorded Future

Someone is clogging up the Zcash blockchain with a spam attack

Alberto Rodriguez, and Erik Hunstad - Stop writing malware! The Blue team has done it for you - YouTube

CVE-2022-34689 - Security Update Guide - Microsoft - Windows CryptoAPI Spoofing Vulnerability

Get root on macOS 12.3.1: proof-of-concepts for Linus Henze’s CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763) | Worth Doing Badly

Risky Biz News: LofyGang runs amok in the npm ecosystem with minimal gains

Twitter Mentions