DiscoverRisky BusinessRisky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

Update: 2025-03-19
Share

Description

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:




  • Github Actions supply chain attack loots keys and secrets from 23k projects

  • Why a VC fund now owns a minority stake in Risky Business Media (!?!?)

  • China doxes Taiwanese military hackers

  • Microsoft thinks .lnk file whitespace trick isn’t worth patching but APTs sure love it

  • CISA delivers government efficiency by re-hiring fired staff… to put them on paid leave

  • …and Google acquires Wiz for $32bn



This week’s show is sponsored by Zero Networks, and they have sent along a happy customer to talk about their experience. Aaron Steinke is Head of Infrastructure at La Trobe Financial, an asset management firm in Australia. Aaron talks through bringing modern zero-trust goodness to the reality of a technology environment that’s been around 40 years.



This episode is also available on Youtube.





Show notes


Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects