Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy

August 27, 2025 0:53:32 51.41 MB Downloads: 0

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Australia expels Iranian ambassador
  • Hackers sabotage Iranian shipping satcoms
  • APT hacker got doxxed in Phrack. Kind of. They’re probably Chinese, not DPRK?
  • Trail of Bits uses image-downscaling to sneak prompts into Google Gemini
  • The Com’s King Bob gets ten years in the slammer
  • It’s a day that ends in -y, so of course there’s a new Citrix Netscaler RCE being used in the wild.

This week’s episode is brought to you by Corelight. Chief Strategy Officer Greg Bell talks through how they’ve been implementing AI for sifting through your network data. A model-context-protocol server that can rummage in all those packet logs for you while you keep investigating? Yes please.

This episode is also available on Youtube.

Show notes