Artwork for Smashing Security
Technology

Smashing Security

Graham Cluley

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

  • 480 episodes
  • Updated Wednesday

Episodes480

  • Wednesday · 58 min

    This job interview could destroy your company

    You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin. EPISODE LINKS: OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know - Hot for Security. Post by Graeme Bell - Linkedin. HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels - Group-IB. Ransom gang targets Dutch ice arena Thialf in cyberattack - Cybernews. No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE - Tokay0. DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews - SOCRadar. H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion - TRM Labs. 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft - UC San Diego Today. 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft - YouTube. Karr Security. Ann Droid - BBC iPlayer. North Leigh Roman Villa - English Heritage. Uffington White Horse - Wikipedia. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report. NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • July 22 · 50 min

    How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

    A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball. EPISODE LINKS: Bengaluru triple murder: Accused allegedly used AI chatbot to plan killings, police say - The News Minute. Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days - Bleeping Computer. DO NOT BUY: LG’s Spyware TVs, Monitors, and Wiretapping Concerns - YouTube. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage - Microsoft Security Blog. Russia Advises Citizens Wanted in U.S. Against Visiting Thailand - The Moscow Times. Alleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show - Reuters. Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links - Ctrl-Alt-Intel. Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius - 404 Media. "Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack - Unit 42. Black Is The Color Of My Voice trailer - YouTube. Black Is The Color Of My Voice - Official Site - Black is the Colour of my Voice. Avatar: The Last Airbender (2007) - Netflix. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report. NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • July 15 · 38 min

    Remote-control rickshaws and rogue book marketers

    An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in episode 476 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White. EPISODE LINKS: The ransomware negotiator who was working for the other side - Hot for Security. LastPass, Bitwarden users targeted with fake security alerts - Bleeping Computer. German firm files for insolvency, blames cybercrims who shut down production for 6 weeks - The Register. BAT-BMS App: How A Chinese App Is Being Used To Hack E-Rickshaws All Over India; Viral Videos Show Drivers Crying Over Lost Earnings - Free Press Journal. Tirri control prank: Indians use China app to shut down e-rickshaws - The Print. Geoff describes his interactions with a book marketing scam - Linkedin. Smart Plugs - Tapo. Worst Patio Ever! Extreme ASMR Pressure Washing - YouTube. 20 Years of Cracked Mud Covered This Massive Rug - YouTube. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report. NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • July 8 · 46 min

    JadePuffer - the AI that ran a ransomware attack all by itself

    A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity? Also, Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year. All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Zoë Rose. EPISODE LINKS: Politician who investigated spyware abuses had his phone hacked with Pegasus spyware - TechCrunch. Hackers breached DHS information-sharing network, people familiar say - Nextgov. Hackers Use Fake FIFA World Cup 2026 T-Shirt Offers to Spread Voidrift Malware - Hackread. Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts - The Straits Times. Police arrest high school student over cyberattack on net cafe operator - The Japan Times. Japanese teens arrested for using AI to create illegal phone contracts - The Peninsula Qatar. JADEPUFFER: Agentic ransomware for automated database extortion - Sysdig. Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses - 404 Media. Two people arrested in apparent marriage proposal atop Empire State Building - The Guardian. Skywalkers: A Love Story - Netflix. Thermomix - Vorwerk. Operation Safe Escape. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report. NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • July 1 · 42 min

    Polymarket can predict the future. So how did it miss this hack?

    Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Meanwhile, "FortiBleed" sees 75,000 Fortinet firewalls thrown wide open - and the real damage is going to roll on for years. All this and more in episode 474 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Quentyn Taylor. EPISODE LINKS: Danish Police Raided Self-Described Privacy Activist. PM Lives at a Secret Address - State of Surveillance. Hospital probe after 40 staff access crocodile boy's medical records - Cybernews. Third Defendant Sentenced To Prison For Hacking Fantasy Sports And Betting Website - US Dept of Justice. Someone allegedly used a hairdryer to rig Polymarket weather bets - Engadget. Tweet by Polymarket Traders - XCancel. Polymarket says hackers stole users' funds - TechCrunch. Operation Cloud Hopper: China-based Hackers Target Managed Service Providers - SecurityWeek. The Full Story of the Stunning RSA Hack Can Finally Be Told - WIRED. Polymarket points to third-party login tool after users report account breaches - Coindesk. Polymarket Admin Wallet Exploited on Polygon, Says ZachXBT - CryptoPotato. Polymarket reportedly paid creators to post deceptive videos about fake bets - TechCrunch. ‘Unbelievable how accurate’: How paid influencers hype Polymarket’s odds - POLITICO. Polymarket's $345 million Iran peace bet is stuck because nobody can agree on what "permanent" means - TNW. Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways - National Cyber Security Centre. Analysis of Reported Credential Compromise of FortiGate Devices - Fortinet Blog. FortiBleed - Free FortiGate Exposure Checker - SOCRadar. The Boys of Dungeon Lane - Paul McCartney. A closer listen to Paul McCartney's new album 'The Boys of Dungeon Lane' - YouTube. The Summer Portraits - Ludovico Einaudi. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • June 24 · 1 hr

    How a hacker could have Rickrolled the entire World Cup

    A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and TikTok, with a two-week ultimatum to turn themselves in... or else. Meanwhile, a security researcher called Bob DaHacker got her hands on the live broadcast controls for every match of the 2026 FIFA World Cup. She could have Rickrolled the entire planet, but actually spent days trying to find anyone at FIFA who would pick up the phone. Plus! Don't miss our featured interview with Black Kite's Jeffrey Wheatman exploring ransomware and extortion attacks across Europe. All this and more in episode 473 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer. EPISODE LINKS: Suspected cyberattack triggers false emergency alerts across parts of Brazil - The Record. Gizmodo readers hit with ClickFix malware prompts after account compromise - The Register. Two men plead guilty over £39m Transport for London cyber attack - BBC News. Helpdesk scammers are making house calls to make their lies feel more real - The Register. Dutch cops’ shame games nets 74 wanted fraudsters - The Register. Omgebrachte vrouw (80) in Amsterdam vermoedelijk slachtoffer van nepagenten - NU. Mr Benn - Wikipedia. I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID - Bobdahacker. Bug in FIFA World Cup internal system gave anyone ability to modify TV stream - TechCrunch. Iceberger - Draw an iceberg and see how it will float. Fallout: London - GOG. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Black Kite - Read Black Kite's 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe. Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • June 17 · 1 hr 12 min

    AI gets hacked, and BitLocker gets bypassed

    What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious. Plus don't miss our featured interview with Son Nguyen Kim of Proton Pass, who explains why plugging AI agents into your email and calendar without thinking twice is rather like hiring a new employee with the keys to everything - and skipping the background check. All this and more in episode 472 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin. EPISODE LINKS: ShinyHunters claims 61M Sysco records - Cybernews. Derbyshire police officer under investigation for using AI to create evidence - Derbyshire Times. Maine forced to take down data breach portal after fake notices filed with authorities - Hot for Security. A Fake Bug Report Hijacks Your AI Coding Agent - and Nothing Catches It. - Tenet Security. Agentjacking: a fake bug report hijacks AI coding agents - TNW. When anti-virus goes rogue - A trifecta of Defender zero-days - SolCyber. BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber. Microsoft versus Full Disclosure: The ongoing Nightmare Eclipse saga - SolCyber. BitLocker, Defender, zero-days, and bragging rights: More MS nightmares - SolCyber. Inside the FBI’s Kinetic Cyber Range - FBI. Inside the FBI's Kinetic Cyber Range - YouTube. Computer worm strikes International Space Station - Graham Cluley. Raspberry Pi Zero W - Raspberry Pi. There’s still life in old technology. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • June 10 · 46 min

    This AI worm just rewrote its own rules

    Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack. Meanwhile, Meta's shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people's Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email address - and the AI will eventually agree. All this and more in episode 471 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball. EPISODE LINKS: Emmys data leak: update exposes access to award submissions - Cybernews. A $1,000 AI agent found 21 zero-days in FFmpeg, some 23 years old - Martin Cid Magazine. Hackers steal $1.7M condom shipment​ - Cybernews. AI Agents Enable Adaptive Computer Worms - ArXiv. 21 Zero-Days in FFmpeg - Depthfirst. Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot - ~this week in security~. Hackers trick Meta AI support bot to infiltrate Obama White House Instagram account - The Guardian. Look-In Star Portrait Challenge - Monkeon. Final Fantasy VII Remake - Square Enix. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today. OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • June 3 · 57 min

    This AI security flaw might be impossible to fix

    A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who responded. Meanwhile, a paper from Cornell suggests that prompt injection - the technique malicious actors use to trick AI agents into doing things they really shouldn't - may be fundamentally unsolvable. Which is err... awkward, because everyone is rushing to plug AI agents into their email, files, and corporate networks. Plus don't miss our featured interview with Andrea Sivieri of CoreView, who tells us how hackers can lock your entire organisation out of its Microsoft 365 environment... without having to trick you into running a single piece of malicious code or handing over a password. All this and more in episode 470 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Tanya Janca. EPISODE LINKS: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked - 404 Media. Canon Printer Vulnerability Leaks Plaintext Credentials - Praetorian. Password manager Dashlane says hackers stole some customers' password vaults - TechCrunch. UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us - TechCrunch. AI Agents May Always Fall for Prompt Injections - ArXiv. MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure - Cloud Security Alliance. From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness - ArXiv. Design details that feel like magic - Design Spells. Singing lessons. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner. ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • May 27 · 53 min

    What your Oura ring won't tell you

    CISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile. Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted - and when one journalist asked the company how often it hands user data to law enforcement, the answer was quite telling. Plus don't miss our featured interview with OPSWAT's Benny Czarny about his new book "Cybersecurity Upside Down." All this and more in episode 469 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lesley Carhart. EPISODE LINKS: Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet - US Dept of Justice. 700+ education and tech websites hijacked in huge ClickFix malware campaign - Malwarebytes. Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West - Including Islamophobic ‘Pig Head’ Attacks in Paris - OCCRP. Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs On Security. US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs - TechCrunch. Oura says it gets government demands for user data. Will it share how many? - This Week In Security. Privacy and transparency of fitness tracking devices - Whyli. Upfest - Europe’s largest street-art festival. Magnets Are Bad For Hardware Again - Hackaday. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today. OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • May 20 · 55 min

    High-speed train hacks and homicidal lawnmowers

    A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year. Meanwhile, owners of $4,000 robot lawnmowers are discovering that their gadget can be hijacked over the internet, redirected at journalists who foolishly lie down in front of it, and used to harvest Wi-Fi passwords, email addresses, and GPS coordinates. Change the default password? Sure - until the next firmware update silently resets it back. Plus - don't miss our featured interview with XBOW's Brendan Dolan-Gavitt about how AI is transforming penetration testing. All this and more in episode 468 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White. EPISODE LINKS: Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom - TechCrunch. Man accused of stealing Beyoncé’s unreleased music takes guilty plea - ABC News. Shai-Hulud code drop: Open season for supply chain attacks- ReversingLabs. Student hacked Taiwan high-speed rail to trigger emergency brakes - BleepingComputer. Polish teen derails tram after hacking train network - The Register. The Cheap Radio Hack That Disrupted Poland's Railway System - WIRED. The man with an army of Yarbo robot lawn mowers - The Verge. Ever been run over by a robot? I have - for science! - TikTok. RD280UA 28” WQXGA BenQ Programming Monitor with Backlight and Flexible Arm - BenQ. Kai Shun DM-0708 combination sharpening stone, grain 300/1000 - Knives and Tools. AI-Assisted ICS Attack on a Water Utility - Dragos. Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - Google Cloud Blog. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today. OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • May 13 · 1 hr 4 min

    How ShinyHunters hacked the world's biggest universities

    Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap. Meanwhile, a famous finance expert's face has been showing up on Facebook adverts promising hot stock tips and exclusive WhatsApp investment groups. Spoiler: it isn't him, the tips aren't real, and you're about to be scammed. Plus we chat to Mike Nichols of Elastic, about how the SOC isn't dying, attackers and defenders are both deploying AI agents, and how the real security crisis is no longer human users - it's the bots acting on their behalf. All this and more in episode 467 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer. EPISODE LINKS: ICO fines South Staffordshire £963K over 2022 breach - The Register. US bank reports itself after AI customer data mishap - The Register. Hackers abuse Google ads, Claude.ai chats to push Mac malware - Bleeping Computer. Canvas hack: What we know about apparent cyberattack that impacted thousands of schools - CNN. Canvas hack: Company pays criminals to delete students' stolen data - BBC News. Post by @amosmagliocco.bsky.social - Bluesky. Post by @sethcotlar.bsky.social - Bluesky. The Architecture of Deception: How a $187 Million Fraud Ecosystem Exploits Trust Across Australia and the United States - Group IB. The Fake Nobel that Duped the Romanian Academy - Scena9. A (Very) Short History of Life On Earth by Henry Gee - Waterstones. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence. CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • May 6 · 1 hr 2 min

    Meta sees everything, Copy Fail, and a deepfake gets hired

    Meta's smart glasses promise privacy "designed for you" - but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them. Meanwhile, the IT press is in a frenzy over a new Linux bug called "Copy Fail" - complete with logo, dedicated website, and a marketing-friendly name. But is it really the disaster everyone's making it out to be? And in our featured interview, Jake Moore of ESET explains how he tricked a company into offering his deepfake clone a job - after a perfectly normal-looking video interview. All this and more in episode 466 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Paul Ducklin. EPISODE LINKS: Anti-DDoS Firm Heaped Attacks on Brazilian ISPs - Krebs On Security. Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha - Bleeping Computer. Trellix confirms data breach after hack of 'a portion' of its source code - TechRadar. Meta’s AI Smart Glasses and Data Privacy Concerns: Workers Say “We See Everything” - Svd. Dispute over fate of Kenyan workers who saw Meta AI glasses films - BBC News. Copy Fail - CVE-2026-31431. Copy Fail: Hype versus reality - the full story - SolCyber. Flight into Danger: The Original Airplane! - BBC Sounds. The Luton writer behind the original Airplane! - BBC News. Code Dependent by Madhumita Murgia - Pan Macmillan. The Code Book - Simon Singh. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected. Action1 - Keep your systems safe (and your sanity intact) with the patch management platform that just works. The best part? Your first 200 endpoints are free, forever, with no functional limits. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • April 29 · 1 hr 4 min

    This developer wanted to cheat at Roblox. It cost millions

    A developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of organisations. All for some free in-game currency. Meanwhile, there's a 1980s phone protocol called SS7 that lets shadowy surveillance companies track anyone, anywhere, via their mobile phone. Governments know about it. Telecoms know about it. Nobody's fixing it. All this and more in episode 465 of the "Smashing Security" podcast with cybersecurity keynote speaker and industry veteran Graham Cluley, joined this week by special guest James Ball. Plus! Don't miss our featured interview with Rob Edmondson of CoreView, discussing how to lock down Microsoft 365 before it's too late. EPISODE LINKS: Burglar alarm biz gets burgled, ShinyHunters pursues ransom - The Register. Ransomware negotiator pleads guilty after leaking victims' insurance details to 'BlackCat' hackers - Tom’s Hardware. Grok tells researchers pretending to be delusional ‘drive an iron nail through the mirror while reciting Psalm 91 backwards’ - The Guardian. Vercel April 2026 security incident - Vercel. App host Vercel says it was hacked and customer data stolen - TechCrunch. Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials - Hacker News. Sorry for the Nazi spam from my Twitter account - Graham Cluley. Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors - Citizen Lab. Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say - TechCrunch. The rapid rise of phone surveillance firms - The Bureau of Investigative Journalism. Please shut up about your Spotify Wrapped - The New World. Think For Yourself - Beatles Song Identification Game. Nodes: Free Connection Puzzle & Vertex Game Alternative. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • April 22 · 51 min

    Rockstar got hacked. The data was junk. The secrets it revealed were not

    A company that ran anonymous tip lines for 35,000 American schools - handling reports of bullying, weapons, and self-harm - boasted on its website that it had suffered zero security breaches in over 20 years. A hacker called Internet Yiff Machine thought that sounded like a challenge, with predictable results... Meanwhile, Rockstar Games gets hacked again - and the stolen data turns out to be less embarrassing than the financial secrets it accidentally revealed. GTA Online is still making half a billion dollars a year. Red Dead Redemption is not. All this and more in episode 464 of the "Smashing Security" podcast with cybersecurity keynote speaker and industry veteran Graham Cluley, joined this week by special guest BBC cybersecurity correspondent Joe Tidy. Plus! Don't miss our featured interview with Ryan Benson of Meter. EPISODE LINKS: Grinex exchange blames "Western intelligence" for $13.7M crypto hack - Bleeping Computer. Are Former Black Basta Affiliates Automating Executive Targeting? - Reliaquest. Apple is working on passcode bug locking out iPhone users - The Register. Hackers who stole crime tip records offering data cache for $10k - San. P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next - Databreaches.net. Portland police urge residents to avoid Crime Stoppers following hack - San. GTA-maker Rockstar Games hacked again but downplays impact - BBC News. Rockstar hackers release their stolen data, reveal that Rockstar was right to not pay them anything for it - PC Gamer. XCancel. ”We Are Anonymous” by Parmy Olson - Penguin. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence. Meter – Network infrastructure for the enterprise. Get a free personalised demo. Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • April 15 · 50 min

    This AI company leaked its own code. It's also built something terrifying

    A hacking group claims to have broken into the flood defence system protecting Venice's Piazza San Marco - and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthropic accidentally leaked the source code for Claude Code via a basic packaging mistake. Oh, and by the way, they've also just revealed they've built an AI model called Mythos that can find and chain together software vulnerabilities faster than any human. Sleep well. All this and more in episode 463 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Tanya Janca. EPISODE LINKS: Booking.com warns customers of hack that exposed their data - The Guardian. GTA-maker Rockstar Games hacked again but downplays impact - BBC News. Meta removes ads for social media addiction litigation - Axios. Hackers claim control over Venice San Marco anti-flood pumps - Security Affairs. Venezia, attacco hacker al sistema di pompe che difende piazza San Marco dall'acqua: «Abbiamo i codici, possiamo disattivarlo» - Corriere del Veneto. Digging into the Claude Code source - Dave Schumaker’s write-up of Anthropic leaking data in February 2025. Anthropic goes nude, exposes Claude Code source by accident - The Register. Assessing Claude Mythos Preview’s cybersecurity capabilities - Anthropic. Smashing Security transcripts! Shrinking - Apple TV. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Meter - Network infrastructure for the enterprise. Get a free personalised demo. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • April 8 · 41 min

    LinkedIn is spying on you, and you agreed to nothing

    LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you're job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned anywhere in their privacy policy. Meanwhile, California's crypto millionaires are learning that no amount of encryption can protect you from someone who knocks on your door pretending to deliver a pizza. All this and more in episode 462 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Dave Bittner. EPISODE LINKS: Russian government hackers broke into thousands of home routers to steal passwords - TechCrunch. Refusal to Give the Government Passwords to Personal Mobile Device Criminalized in Hong Kong - US Consulate in Hong Kong. "I didn't think millions would see this..." Russians are calling each other through a cat feeder - GUBDaily. BrowserGate. Scanned extensions database - BrowserGate. LinkedIn secretly scans for 6,000+ Chrome extensions, collects data - Bleeping Computer. Translate into LinkedIn speak - Kagi. Security - xkcd. Wealthy California crypto holders targeted in violent ‘wrench attacks’ - KTLA 5. Lost Doctor Who episodes to be released this week - BBC News. Doctor Who: The Daleks’ Master Plan - The Nightmare Begins - BBC iPlayer. Doctor Who: The Daleks’ Master Plan - Devil’s Planet - BBC iPlayer. Milton Bradley Grandmaster Robotic Chess Computer - YouTube. Robot Chess - One-armed gambit - Techmoan on YouTube. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected. Meter - Network infrastructure for the enterprise. Get a free personalised demo. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • April 1 · 45 min

    This man hid $400 million in a fishing rod. Then it vanished

    A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 - and now sits on a fortune worth $400 million. There's just one small problem: the access codes were tucked inside his fishing rod case, which has mysteriously vanished. Or has it? Because this week, one of his frozen wallets suddenly woke up and moved $35 million - and someone had to identify themselves to do it. Meanwhile, Ajax Football Club scores a spectacular cyber own-goal, as a data breach that the club claimed affected "a few hundred" fans turns out to may have exposed the personal details of 300,000 supporters - along with the ability to steal match tickets and quietly remove people from the stadium ban list. All this and much more in episode 461 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest journalist Danny Palmer. EPISODE LINKS: Iran-linked hackers breach FBI director's personal email, publish photos and documents - Reuters. Windows PCs crash three times as often as Macs, report says - TechSpot. Wife used CCTV to steal $176M of husband’s crypto, UK court told - Coin Telegraph. Gardaí open €30m bitcoin virtual wallet, first of 12 accessed since seizure in 2019 - Irish Times. Irish Drug Dealer’s Lost BTC Stack Worth $400m Has Woken Up - Arkham. Ajax FC data breach exposes 300,000 fans, hacker steals tickets an stadium ban details - Cybernews. Small Prophets - BBC iPlayer. RPG Taverns - Dungeons and Dragons tavern in London. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Action1 - Keep your systems safe (and your sanity intact) with the patch management platform that just works. The best part? Your first 200 endpoints are free, forever, with no functional limits. Meter - Network infrastructure for the enterprise. Get a free personalised demo. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • March 26 · 40 min

    Never knock on the door of a nuclear submarine base and ask for a selfie

    A disgruntled data analyst decides that the best response to losing his contract is to steal the entire company payroll database and demand $2.5 million in Bitcoin - signing his extortion emails from a company called "Loot." Meanwhile, two people drive up to the entrance of the UK's nuclear submarine base at Faslane and politely ask if they can have a look around. Tourists? Spies? Something in between? Plus: Female Muslim punk rock group, and a little red book that might save your sanity in a post-truth world. All this and more in episode 460 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Jenny Radcliffe. EPISODE LINKS: A Top Google Search Result for Claude Plugins Was Planted by Hackers - 404 Media. Iowa-based Intoxalock cyberattack disrupts calibration service for interlock users - DysruptionHub. China hacker group leaks $7M crypto theft operation targeting wallet supply chains​ - Crypto News. Federal Jury Convicts Charlotte Man For Cyber Extortion Scheme That Targeted International Technology Company - DOJ. Iranian and Romanian charged after allegedly trying to enter UK nuclear naval base - Sky News. LadyParts - Spotify. On Disinformation: How to Fight for Truth and Protect Democracy - Lee McIntyre. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment. Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! Meter - Network infrastructure for the enterprise. Get a free personalised demo. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • March 19 · 54 min

    This clever scam nearly hijacked a tech CEO's Apple ID

    In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you're immune? Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to reveal everything. And! Human-powered “AI”, and a punishment worse than prison: eight hours on the RSA expo floor... All this, and much more, in episode 459 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Paul Ducklin. EPISODE LINKS: DOGE employee stole Social Security data and put it on a thumb drive, report says - TechCrunch. Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show - Reuters. New font-rendering trick hides malicious commands from AI tools - Bleeping Computer. Lockdown Mode - Apple support. Gone (Almost) Phishin’ - Matt Mullenweg. Listen to the Live Scam Call Targeting Matt Mullenweg’s Apple Account - YouTube. Confidential health records from UK BioBank project exposed online - The Guardian. A message from Professor Sir Rory Collins, Chief Executive and Principal Investigator of UK Biobank - UK BioBank. Psychotherapy data breach blackmailer sent to prison - Paul Ducklin. Your AI slop bores me. Post by Vaughan Shanks - LinkedIn. Judge Sentences CISO to 8 Consecutive Hours on RSA Expo Floor as Formal Punishment for Security Breach - The Exploit. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! Adaptive Security - request a custom demo featuring a real CEO deepfake simulation. Meter - Network infrastructure for the enterprise. Get a free personalised demo. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy