Risky Business #821 -- Wiz researchers could have owned every AWS customer

January 21
1h 4m

Episode Description

In this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, joined by a special guest. BBC World Cyber Correspondent Joe Tidy is a long time listener and he pops in for a ride-along in the news segment plus a chat about his new book.

This week news includes:

  • Did the US cyber Venezuela’s power grid, or do they just want us to think they coulda?
  • US govt might boycott the RSAC Conference ‘cause Jen Easterly being CEO makes them mad
  • MS Patch Tuesday fixes CVSS5.5 bug and … stops you shutting down
  • Wiz pulls off cloud stunt hack that ends with control of everyone’s AWS console
  • Millions of Bluetooth devices that use Google’s Fast Pairing will pair with anyone, any time
  • GNU inet-tools’ telnetd parties like it’s 2007, and brings -f root unauthed remote login back

Thinkst is this week’s sponsor, and long time friend of the show Haroon Meer joins. As always they’re polishing their Canary tokens - adding breadcrumbs to lead you to them - but they’re also a bunch of giant nerds who now run South Africa’s Computer Olympiad.

This episode is also available on Youtube.

Show notes

See all episodes

Never lose your place, on any device

Create a free account to sync, back up, and get personal recommendations.