Risky Business #808 -- Insane megabug in Entra left all tenants exposed
Update: 2025-09-24
Description
On this week’s show Patrick Gray and special guest Rob Joyce discuss the week’s cybersecurity news, including:
- Secret Service raids a SIM farm in New York
- MI6 launches a dark web portal
- Are the 2023 Scattered Spider kids finally getting their comeuppance?
- Production halt continues for Jaguar Land Rover
- GitHub tightens its security after Shai-Hulud worm
This week’s episode is sponsored by Sublime Security. In this week’s sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI in an email security platform.
This episode is also available on YouTube
Show notes
- U.S. Secret Service disrupts telecom network that threatened NYC during U.N. General Assembly
- MI6 launches darkweb portal to recruit foreign spies | The Record from Recorded Future News
- One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens | dirkjanm.io
- Github npm changes
- Flights across Europe delayed after cyberattack targets third-party vendor | Cybersecurity Dive
- Major European airports work to restore services after cyberattack on check-in systems | The Record from Recorded Future News
- When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on | DataBreaches.Net
- UK arrests 2 more alleged Scattered Spider hackers over London transit system breach | Cybersecurity Dive
- Alleged Scattered Spider member turns self in to Las Vegas police | The Record from Recorded Future News
- Las Vegas police arrest minor accused of high-profile 2023 casino attacks | CyberScoop
- DOJ: Scattered Spider took $115 million in ransoms, breached a US court system | The Record from Recorded Future News
- vx-underground on X: "Scattered Spider ransoms company for 964BTC - wtf_thats_alot.jpeg - Document says "Cost of BTC at time was $36M" - $36M / 964BTC = $37.5K - BTC value was $37.5K in November, 2023 - Google "Ransomware, November, 2023" - omfg.exe https://t.co/uv2EzbL5HT" | X
- JLR ‘cyber shockwave ripping through UK industry’ as supplier share price plummets by 55% | The Record from Recorded Future News
- Jaguar Land Rover to extend production pause into October following cyberattack | Cybersecurity Dive
- New plan would give Congress another 18 months to revisit Section 702 surveillance powers | The Record from Recorded Future News
- AI-powered vulnerability detection will make things worse, not better, former US cyber official warns | Cybersecurity Dive
Comments
In Channel