Artwork for Smashing Security
Technology

Smashing Security

Graham Cluley

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

  • 480 episodes
  • Updated Wednesday

Episodes480

  • Aug 24, 2017 · 46 min

    039: Woah - are we talking to a cyborg?

    Hackers could change emails in your inbox after they are delivered, the web is getting more and more encrypted, and hacked robots can be commanded to umm... stab you. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by researcher Scott Helme. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Scott Helme. Sponsored By: Rapid7: Identifying, prioritizing and managing vulnerabilities all the way through to remediation is not only possible, it can be simple. Right now.Build a vulnerability management program that works for you with Insight VM, by Rapid7. Get started with your free 30 day trial now. Support Smashing Security Links: Introducing the ROPEMAKER Email Exploit — Mimecast. Did ROPEMAKER just unravel email security? Nah, it's likely a feature — The Register. Measuring HTTPS adoption on the web [USENIX 17] — Research presented by Adrienne Porter Felt (Google) and April King (Mozilla). Alexa Top 1 Million Analysis - August 2017 — Scott Helme's report. ALPHA 2, The World's First Humanoid Robot for the Family — YouTube. UBTech Alpha 2 turns Chucky — YouTube Researchers warn against 'hackable' robots — IT Pro. Overcooked — Team 17. "Could you be paying for things using just your hand? — BBC Click on Twitter. 250,000 Dominoes - The Incredible Science Machine — YouTube. Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 17, 2017 · 44 min

    038: Gents! Stop airdropping your pics!

    WannaCry hero Marcus Hutchins (aka MalwareTech) pleads not guilty to malware charges, the Scottish parliament is hit by a brute force attack, IoT smart locks aren't so smart, and.. ahem.. someone is sending intimate pics via AirDrop to unsuspecting commuters. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity keynote speaker Graham Cluley and Carole Theriault, joined this week by technology journalist Geoff White. Visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Geoff White. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: "The Secret Life of Your Mobile Phone" — Geoff White's show at the Edinburgh Festival Fringe MalwareTech is back online, as he pleads not guilty to Kronos malware charges — Graham Cluley. Scottish parliament hit by cyber-attack similar to Westminster assault — The Guardian. Hackers try to break into Scottish parliament email accounts weeks after Westminster attack — Graham Cluley. Blocking Brute Force Attacks — Advice from OWASP. Hundreds of 'smart' locks bricked by flubbed remote update — Graham Cluley. Friendly neighborhood hacker helps family regain access to locked car — Graham Cluley. AirDropping penis pics is the latest horrifying subway trend — New York Post. Is there a way to view AirDrop transfer history? — Apple Support community. What Is AirDrop? How Does It Work? — Lifewire. Exposing yourself is illegal - so why should the law tolerate cyber-flashing on online dating apps? — The Independent. Saint Louis Rapid & Blitz — Grand Chess Tour. Amazon's LoveFilm postal rentals is shutting down — Radio Times. "Waking up with Sam Harris" Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 9, 2017 · 37 min

    037: Boobs, dragons and data breaches

    Hackers are holding HBO to ransom after a massive data breach, and have leaked the phone numbers and email addresses of "Game of Thrones" cast members. Has security firm Carbon Black been leaking customers's sensitive files while trying to scan them? And Disney's mobile apps are accused of spying on kids... All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by John Hawes. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Hawes. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: FBI arrests WannaCry's 'accidental hero' in connection with Kronos banking trojan HBO hack ransom note: Watch the video, set to Game of Thrones music Game of Thrones stars' personal phone numbers leaked, as HBO hackers attempt to extort ransom Markus Ueberall's tweet Movie studio tells all about Dark Overlord's leak of 'Orange Is the New Black' Harvesting Cb Response Data Leaks for fun and profit | DirectDefense DirectDefense Incorrectly Asserts Architectural Flaw in Cb Response | Carbon Black — Carbon Black responds. Children's Online Privacy Protection Rule ("COPPA") | Federal Trade Commission Parents claim Disney gobbled up kids' info through mobile games • The Register Adult Life Skills (2016) - IMDb Intelligence (Canadian TV series) - Wikipedia Secrets, Crimes & Audiotape BBC Radio 4 - Seriously... Smashing Security podcast on Facebook Smashing Security online store Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 3, 2017 · 44 min

    036: Flash? Clunk flush... and hacking security researchers

    A security threat researcher is badly hacked in a revenge attack. Some people want to save Adobe Flash, but is that wise? And a poorly-secured electronic billboard starts displaying offensive images... All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Maria Varmazis. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: Hackers Leak Data From Mandiant Security Researcher in Operation #LeakTheAnalyst — Bleeping Computer. Hackers kick off #leaktheanalyst campaign by dumping data of $1bn security firm — The Next Web LinkedIn profile of a Mandiant employee — Warning - contains image of hairy bottom. This is really here just for Maria. How to choose a strong password - simple tips for better security — YouTube video from 2009, featuring Graham (and filmed by Carole). So, who remembered correctly what we actually said in the video? Smashing Security podcast: Protecting webmail — A Smashing Security splinter. Flash & The Future of Interactive Content — Adobe. Petition to open source Flash and Shockwave — Github. Adobe Flash Fans Want a Chance to Fix Its One Million Bugs Under an Open Source License — Gizmodo. Hackers hijack central Cardiff billboard to display swastikas and more... — Graham Cluley. Hackers plant obscene image on electronic billboard in Atlanta — Graham Cluley. Motorists warned of Dalek invasion by hacked road sign — Naked Security. How to Lock Down TeamViewer for More Secure Remote Access — How-To Geek. Long Distance — Reply All podcast by Gimlet Media. Tickled movie — Wikipedia. Tickled documentary to air on HBO with bonus follow-up special — The A.V. Club. Clock face with actual human face uses eyes to tell time — Mashable. Picture of Carole's clock (which Graham hates) — Twitter. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 26, 2017 · 37 min

    035: Up the Roomba with mandatory Chinese spyware

    China is forcing people to install smartphone spyware, young cyberoffenders are offered rehab, and robot vacuum cleaners want to sell maps of the inside of your house to tech firms. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dan Ring. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Dan Ring. Sponsored By: Rapid7: Identifying, prioritizing and managing vulnerabilities all the way through to remediation is not only possible, it can be simple. Right now.Build a vulnerability management program that works for you with Insight VM, by Rapid7. Get started with your free 30 day trial now. Support Smashing Security Links: Xinjiang Users Arrested over State Spyware Usage — Infosecurity Magazine China crams spyware on phones in Muslim-majority province — The Register. Rehab camp aims to put young cyber-crooks on right track — BBC News. Roomba vacuum maker iRobot betting big on the 'smart' home — Reuters. iRobot Wants to Sell Mapping Data Collected by Roomba Vacuums to a Tech Company Like Apple — Mac Rumors. Griffin BreakSafe Magnetic USB C Charging Cable — To make your upgraded MacBook Pro a little less of a downgrade. USB-C MagSafe - Will it work!?!? — iJustine's video on YouTube. Chipotle Blames Norovirus Outbreak on a Sick Employee — Pick of the week? Jim'll Paint It — See what Microsoft Paint can do in the hands of a genius. MS Paint is here to stay — Microsoft. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 20, 2017 · 48 min

    034: The pen is mightier than the password

    The UK government wants you to give your credit card details to porn sites, Ashley Madison offers compensation to the people whose lives it ruined, and an adult website wants you to pass its unorthodox and below-the-belt biometric identity check... gulp! All this and Myspace, Google Glass, Fleabag, and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by technology journalist and broadcaster David McClelland. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: David McClelland. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: BBC One - X-Ray, Summer Specials, Photography Special — Watch David McClelland on iPlayer if you're in the UK. There may also be ways of watching this outside the UK. We couldn't possibly comment... Vladimir Putin Cut From Two Upcoming Hollywood Movies — Hollywood Reporter It's not Yourspace, it's Myspace — Leigh-Anne Galloway shares her research on Myspace's diabolical security. Myspace fixes account security hole - but delete your account anyway The UK will block online porn from next year. Here's what we know — Wired Ashley Madison will pay $11.2 million to data breach victims — Engadget You can now use a dick pic as a password. Why, god? Why. — Mashable Nasty Bug Left Thousands of Internet of Things Devices Open to Hackers — Motherboard Millions of IoT devices at hacking risk due to flaw in open source software library — Bitdefender Box blog Meet the Thirteenth Doctor Who — YouTube. Fleabag — Sadly there is no way at all for anyone outside the UK to watch shows on BBC iPlayer. Definitely not. Nope. No way at all. Impossible. IRL Podcast: Online Life is Real Life — Mozilla's new podcast Google Glass is officially back with a clearer vision — Engadget Black Mirror: The Entire History of You — We didn't mention it on the podcast, but this episode of "Black Mirror" includes the new Doctor Who - Jodie Whittaker. This Startup Wants to Replace Your Office With 3D Holograms - Bloomberg — Article about Meta, which is testing augmented reality technology on its employees Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 13, 2017 · 42 min

    033: 1Password, net neutrality, and spatchcock chicken

    Is password manager 1Password treating its customers unfairly? Are autonomous cars driving us around the bend? And what is this Net Neutrality thing anyway? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Michael Hucks from PC Pitstop. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Michael Hucks. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: sweetsweet — Michael's band. Why Security Experts Are Pissed That ‘1Password’ Is Pushing Users to the Cloud — Motherboard report. 1Password irks security experts in push toward cloud-based vaults — AppleInsider report. Are local vaults going to exist for the foreseeable future? — AgileBits Support Forum — 1Password's support forum. 1Password wants you to sync via the cloud, but won't force you The new Audi A8 luxury sedan is a high-tech beast that can drive itself — The Verge. Tesla owners are ignoring autopilot safety advice and putting the results on YouTube — The Verge. The biggest threat facing connected autonomous vehicles is cybersecurity — TechCrunch. Join the Battle for Net Neutrality The coming battle over 'net neutrality' — BBC News The FCC Insists It Can't Stop Impostors From Lying About My Views On Net Neutrality — Karl Bode isn't very happy in this Techdirt article. A Bot Is Flooding The FCC Website With Fake Anti-Net Neutrality Comments... In Alphabetical Order — Arnold Aardvark isn't a fan of net neutrality apparently. Alexa calls cops on man allegedly beating his girlfriend — Horrendous report from the New York Post, but for once Amazon's Alexa sounds like it did some good. Southern Rail on Twitter — Eddie takes over Southern Rail's Twitter account. Work experience boy runs Southern Rail's Twitter account — Sky News. The Red Pill movie — Wikipedia. Rapidfire Chimney Starter — Weber. Griddled spatchcock poussins with shallot vinaigrette recipe — Apparently Carole makes a mean one of these, although we've only got her word for it. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 6, 2017 · 35 min

    032: The iPhone 8, a data breach at the AA, and a mystery no show

    The iPhone 8 is on its way and may use 3D facial recognition rather than a fingerprint sensor to lock out intruders, and the UK's Automobile Association claims it hasn't leaked any credit card data, so why is it getting so upset about security researchers publishing screenshots of leaked data? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by umm.. nobody. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: Yes - despite what it says - AA customer credit card data was exposed Apple Readies iPhone Overhaul for Smartphone’s 10th Anniversary - Bloomberg The World's Blackest Material - An Inside Look At Vantablack — YouTube video. About Touch ID advanced security technology - Apple Support He thought a book would stop a bullet and make him a YouTube star. Now he’s dead. - The Washington Post Firik Sleep Headphones — For those of you who want to look like John McEnroe when you're snoozing in bed. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 29, 2017 · 44 min

    031: Petya (don't know the name of this ransomware)

    Another major ransomware outbreak rattles the world - but no-one can decide what it's called, the danger posed to driverless cars by kangaroos, and do you really want an Amazon Echo Show? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest David Bisson. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: David Bisson. Sponsored By: Rapid7: Identifying, prioritizing and managing vulnerabilities all the way through to remediation is not only possible, it can be simple. Right now.Build a vulnerability management program that works for you with Insight VM, by Rapid7. Get started with your free 30 day trial now. Support Smashing Security Links: Martijn Grooten on Twitter: "Seriously injured man lies next to tree..." — Martijn seems to be suggesting the infosecurity industry might have the wrong priorities. Global ransomware outbreak hits organisations hard Cybereason discovers NotPetya kill switch — You might want to create a file called "perfc" in your Windows folder. Info on the PetrWrap/Petya ransomware: Email account in question already blocked since midday — Don't pay the ransom folks... Driverless cars: Kangaroos throwing off animal detection software — Cripes! How Flying Cars Will Boost Intel, Uber and Airbus Amazon’s New Echo Show Is Very Cool And A Little Creepy [PSA] Intercom (drop-in) does require calling to be enabled and needs access to your contact list Malicious Life podcast — Interviewing Graham Cluley, Vesselin Bontchev, and others about the early days of malware. 50th anniversary of the ATM opens debate about mobile payments Why Was The World's First Cash Machine In Enfield? "On The Buses" - YouTube — Starring Reg Varney, famous for being one of the first people in the world to use an ATM. The Bright Sessions podcast Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 22, 2017 · 26 min

    030: GDPR - The good and the bad

    In this special "splinter" episode, regular hosts Graham Cluley and Carole Theriault are joined by special guest Kevin Gorsline to discuss the European Union's General Data Protection Regulation (GDPR), and what it means for your business even if you're not based in Europe. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Kevin Gorsline. Support Smashing Security Links: The EU's GDPR legislation — A gentle read before bedtime... EU data protection rules affect everyone, say legal experts — The EU's new data protection rules will impact every entity that holds or uses European personal data both inside and outside of Europe, according to legal experts. Preparing for GDPR - 12 steps to take now (PDF) — Advice from the UK's Information Commissioner's Office. EU GDPR demystified: a straight-forward guide for US firms (Part I) – — Our own Carole Theriault writes about GDPR on the TBG Security blog. EU GDPR demystified: a straightforward reference guide for US firms (Part II) — More from Carole Theriault on the TBG Security blog. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 15, 2017 · 38 min

    029: Exploits to get your English teeth into

    Microsoft gives us a Patch Tuesday shock, malware grows up for the Mac, and your mouse movements might reveal if you're an identity thief. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Javvad Malik of AlienVault. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Javvad Malik. Sponsored By: Foursys: IT security professionals! Register for your free place at SecureTour17, being held at Manchester United's Old Trafford stadium on July 6 2017, and hear security experts (and Graham) talk about threats and the latest technology to fight them. Support Smashing Security Links: June 2017 security update release — Microsoft reveals it is releasing security updates for older versions of Windows that are no longer officially supported. Microsoft security advisory — Guidance related to June 2017 security update release. Microsoft security advisory - guidance for older platforms MacSpy: OS X RAT as a Service — Information from experts at AlienVault on the MacOS malware-as-a-service threat. MacRansom: Offered as Ransomware as a Service — Fortinet's analysis of MacRansom. Identity theft can be thwarted by artificial intelligence analysis of a user's mouse movements — Your mouse movements can indicate whether you're lying. The detection of faked identity using unexpected questions and mouse dynamics — Check out the technical paper by Monaro, Gamberini and Sartori. Rude security video from Javvad Malik — Why spend thousands on complex and innovative security awareness activities, when all you need to do, is train your staff to be rude. Divide and conquer: How Microsoft researchers used AI to master Ms. Pac-Man - Next at Microsoft — Microsoft's researchers have been busy... Video of Microsoft's Ms Pac Man-playing AI. Max Hawkins's website — "For the past two years I’ve been letting randomized computer programs decide what I do." Eager To Burst His Own Bubble, A Techie Made Apps To Randomize His Life — NPR take a look at the odd lifestyle of Max Hawkins. The Dice Man — 1971 novel by Luke Rhinehart. Logitech finally finds a good use for wireless charging: A mouse pad — Would you buy one of these? Seriously? Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 7, 2017 · 38 min

    024: Reality Winner, Gordon Ramsay and a leaky bucket

    Evidence of Russia hacking the US election leaks from the NSA and Reality is not a winner, confidential data is accidentally exposed in the cloud by a defence contractor, and Gordon Ramsay has a few choice words for his hacking father-in-law. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Ian Whalley. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Ian Whalley. Sponsored By: iovation: iovation is offering Smashing Security listeners a free demonstration of its mobile multifactor solution product, LaunchKey, which can be built into your mobile apps, websites and online services to provide a simple, streamlined remote login function. Support Smashing Security Links: The classic era Smashing Security team... reunited at Infosec — Graham and Carole bumped into someone called Vanja Svajcer at the Infosec show in London, and couldn't resist getting a selfie. Top-Secret NSA Report Details Russian Hacking Effort Days Before 2016 Election — The Intercept report which kicked everything off. Affidavit in support of application for Reality Winner's arrest warrant — Read the PDF for yourself. How The Intercept might have helped unmasked Reality Winner to the NSA — David Bisson writes on grahamcluley.com. How The Intercept Outed Reality Winner — Robert Graham's blog post about the really rather hard-to-see little yellow dots. Defense contractor stored intelligence data in Amazon cloud unprotected — Booz Allen Hamilton engineer posted geospatial intelligence to Amazon S3 bucket. Gordon Ramsay's father-in-law jailed over hacking plot — BBC News Online. Gordon Ramsay the hypocrite: How TV chef defended sharks... but previously caught two rare ones for fun — The controversial Daily Mail article that included pictures stolen from Gordon Ramsay's email account. Malcolm Tucker's best insults (Explicit) — YouTube clips from BBC's "The Thick of It". Not for young ears or the easily offended... Smashing Security: 014: Protecting webmail - a Smashing Security splinter — In this podcast we run through our tips on how to better secure your web-based email accounts. Chances are that you're not doing all of these! Smashing Security: Passwords - a Smashing Security splinter — Password best practices explained in our podcast. Boxcryptor - Encryption software to secure cloud files — Encrypt your files before you shove them in the cloud... How to use Google Maps offline — Ian's tip on how to use your smartphone to navigate, even when you don't have a data connection. Trump in translation: president's mangled language stumps interpreters — Carole's pick of the week from The Guardian. Privacy & Opt-Out: https://redcircle.com/privacy

  • May 31, 2017 · 40 min

    023: Covfefe

    Hackers are blackmailing cosmetic surgery patients, and threatening to release their naked photos. A British Airways IT snafu causes travel chaos for thousands. And Germany is threatening to throw hefty fines at Facebook if it can't police its content properly. All this and "Covfefe" is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest John Hawes. Show notes: Cosmetic surgery hacked. Nude photos and data exposed on the dark web, as hackers blackmail patients - Bitdefender. Lithuanian cosmetic surgery firm's website - Grožio Chirurgija. British Airways: Chaos continues at Heathrow - BBC News. What went wrong at BA? - BBC News. Delta finally explained how one power outage grounded an entire airline - BGR. Facebook said Germany's plan to tackle fake news would make social media companies delete legal content - Business Insider. Sgt. Pepper's Lonely Hearts Club Band - The Beatles. Spanish art restorer, 82, who turned Jesus into a 'hairy monkey' in clumsy restoration of famous work signs merchandising deal as image gets imprinted on T-shirts - Daily Mail. Clash of Clans - Supercell. This is what Candy Crush does to your brain - The Guardian. Sweet Sweet - Reverb Nation. Help Sweet Sweet - Bonnaroo Bound! - GoFundMe. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Hawes. Sponsored By: iovation: iovation is offering Smashing Security listeners a free demonstration of its mobile multifactor solution product, LaunchKey, which can be built into your mobile apps, websites and online services to provide a simple, streamlined remote login function. Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • May 24, 2017 · 31 min

    022: Walk this way... to defeat biometrics

    The Samsung Galaxy S8 claims that its iris recognition technology provides "airtight security", but the Chaos Computer Club knows better and shows how it can be easily bypassed. Australian researchers create a wearable gizmo that authenticates you through your walk, but is it ever going to be practical? Mac malware reportedly wastes no time stealing information from a software developer. And the boss of the Bank of England is smart enough not to fall for an email prankster. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Paul "Duck" Ducklin. Show notes: Chaos Computer Clubs breaks iris recognition system of the Samsung Galaxy S8 - Chaos Computer Club. Breaking the iris scanner locking Samsung’s Galaxy S8 is laughably easy - Ars Technica. New technology uses the way you walk as a password - CNet. Hofmeister - follow the bear TV advert - YouTube. Monty Python's Flying Circus's Ministry of Silly Walks sketch - YouTube. Source Code for Several Panic Apps Stolen via HandBrake Malware Attack - MacRumors. Bank of England accused of airbrushing Jane Austen on the new £10 note - Liverpool Echo. Bank of England governor falls for email prank but maintains his composure - The Guardian. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Paul Ducklin. Sponsored By: iovation: iovation is offering Smashing Security listeners a free demonstration of its mobile multifactor solution product, LaunchKey, which can be built into your mobile apps, websites and online services to provide a simple, streamlined remote login function. Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • May 18, 2017 · 35 min

    021: WannaCry - Who's to blame?

    The WannaCry ransomware has struck! But before we tackle that subject, and who we should blame for one of the highest profile malware attacks for years, we discuss how HP has been unwittingly capturing the keystrokes of its laptop users. Then we briefly discuss what might be the worst cinema date in history, before rounding things off with a discussion of hackers extorting money out of movie studios. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Paul "Pob" Baccas. Show notes: Hello to Jason Isaacs - Witterpedia. Unintended/Covert Storage Channel for sensitive data in Conexant HD Audio Driver Package - modzero Security Advisory. Keylogger Found in Audio Driver of HP Laptops - Bleeping Computer. HP responds to laptop keylogger fiasco, promises ‘fix shortly' - Trusted Reviews. Tweet from @ths - Twitter. Backin Up Song - YouTube. The Sobig Worm - Wikipedia. Customer Guidance for WannaCrypt attacks - Microsoft. Microsoft Security Bulletin MS17-010 - Microsoft. Microsoft: WannaCry outbreak reveals why governments shouldn't hoard vulnerabilities - Graham Cluley. ‘THIS IS CRAZY’: Austin man sues date for texting during movie - Statesman. Hackers Seem to Dump Pirates of the Caribbean on Torrent Sites Ahead of Premiere - Softpedia. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Paul Baccas. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • May 10, 2017 · 30 min

    020: Phishing for Donald Trump

    Gizmodo's attempt to reveal Donald Trump's administration ineptitude when it comes to cybersecurity fails to impress. Mac users are warned that the HandBrake DVD-ripping app has been compromised by malware. And will the US Army insist IT security professionals spend months ironing their bedsheets..? All this and more is discussed by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Paul Ducklin from Sophos. Show notes: Here's How Easy It Is to Get Trump Officials to Click on a Fake Link in Email - Gizmodo. Opinion: Some thoughts about Gizmodo's Phishing story - CSO Online. Mac video app HandBrake – now with free spyware - Naked Security. OS X malware spread via signed Transmission app... again - Graham Cluley. DOD’s new Internet strategy boosts role in defending “US interests” - Ars Technica. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Paul Ducklin. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • May 3, 2017 · 29 min

    019: The Love Bug virus

    On May 4th 2000, the Love Bug virus (also known as ILOVEYOU or LoveLetter) rapidly spread around the world, clogging up email systems. Computer security veterans Graham Cluley and Carole Theriault are joined this week by special guest John Hawes for a trip down memory lane. Show notes: Memories of the Love Bug worm - Naked Security "Subject: I Love You" movie trailer - YouTube Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Hawes. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 27, 2017 · 30 min

    018: Windows is a virus. True or False?

    Security firm Webroot drops a clanger when it declared Windows was malicious and borked customers' PCs, millennials are streaming a lot of movies illegally, and blackmailers are targeting members of the Ashley Madison cheating site again. All this and more is discussed by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Michael Hucks from PC Matic. Show notes: Webroot antivirus goes bananas, starts trashing Windows system files - The Register. Webroot causes massive headaches after falsely flagging Windows files as malicious - Graham Cluley. Tweet by Webroot user Bob Ripley - @M5_Driver. W32.Trojan.Gen false positive - advice for home users - Webroot. W32.Trojan.Gen false positive - advice for business users - Webroot. Most millennials regularly stream pirated content, survey finds - Torrent Freak. Malware, data theft, and scams: researchers expose risks of free livestreaming websites - Ku Leuven. File sharer hit with $675,000 fine - Digital Trends. Ashley Madison blackmail roars back to life - ZDNet. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Michael Hucks. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 20, 2017 · 30 min

    017: Data breaches, zero day exploits, and toenail clippings

    Hotel malware has been stealing guests' payment card details... again, should businesses relay delay rolling out vulnerability patches, and Burger King's Whopper TV ad campaign tries to take advantage of viewers' Google Home devices with predictable results. All this and more is discussed by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Paul Ducklin. Show notes: InterContinental Hotels Group (IHG) Notifies Guests of Payment Card Incident at IHG-Branded Franchise Hotel Locations in the Americas Region - IHG. Affected hotel look-up tool - IHG. Been to one of these 1170 IHG hotels? Your credit card details may have been stolen by malware - Bitdefender. Microsoft patches Word zero-day booby-trap exploit - Naked Security. Microsoft zero-day vulnerability was being exploited for cyber-espionage - Graham Cluley. The Shadow Brokers - Wikipedia. Burger King's 'OK Google' sad ad saga somehow gets worse - The Register. Burger King Connected Whopper ad - YouTube. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Paul Ducklin. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 13, 2017 · 27 min

    016: Wonga wronga!

    Spyware companies are filmed plotting to break global sanctions to ship surveillance and spying equipment to dodgy authoritarian regimes, an unsecured database exposed diabetics’ sensitive data, and a massive data breach leaves hundreds of thousands of current and former Wonga customers at risk. All this and more is discussed by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Lisa Vaas. Show notes: Spyware firms in breach of global sanctions - Al Jazeera. Al Jazeera Investigations - Spy Merchants - YouTube. Mounties admit to using cellphone-snooping ‘stingrays’ - Sophos Naked Security. A huge trove of patient data leaks, thanks to telemarketers' bad security - ZDNet. Leak of diabetic patients’ data highlights risks of giving info to telemarketers - DataBreaches.net. Unsecured database exposed diabetics’ sensitive data - Sophos Naked Security. Fraudsters Target People With Diabetes - AARP. Wonga.com TV advert - YouTube. Wonga security incident FAQ - Wonga.com. Wonga data breach puts up to 245,000 UK current and former customers at risk - Graham Cluley. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Lisa Vaas. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy