Artwork for Smashing Security
Technology

Smashing Security

Graham Cluley

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

  • 480 episodes
  • Updated Wednesday

Episodes480

  • Feb 14, 2024 · 51 min

    Declaring war on ransomware gangs, mobile muddles, and AI religion

    Holy mackerel! AI is jumping on the religion bandwagon, ransomware gangs target hospitals, and what's happened to your old mobile phone number? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by "Ransomware Sommelier" Allan Liska. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: I changed my number and now i can log into others accounts - Reddit. Post by Alexander Hanff - LinkedIn. Meta says risk of account theft after phone number recycling isn't its problem to solve - The Register. Things to bear in mind when you change your mobile number - T-Mobile. 20+ hospitals in Romania hit hard by ransomware attack on IT service provider - Graham Cluley. Ransomware gang claims responsibility for Christmas attack on Massachusetts hospital - The Record. Cyberattack Disrupts Operations at Chicago Children’s Hospital: An Examination of the Threat and Its Impact - Medriva. Gods in the machine? The rise of artificial intelligence may result in new religions - The Conversation. AI: a way to freely share technology and stop it being misused already exists - The Conversation. The Friar Who Became the Vatican’s Go-To Guy on AI - The New York Times. How AI could change our relationship with religion - The Conversation. Meet the Vatican’s AI mentor – POLITICO. Focus Areas - AI and Faith - Rome Call. Are chatbots changing the face of religion? Three faith leaders on grappling with AI - The Guardian. “One Day” - Netflix. [Clicks mouth] "The Saint" - Amazon Prime. The Saint goes to Palm Springs - YouTube. God's Favorite Idiot - IMDb. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: BlackBerry - BlackBerry helps keeps you one step ahead. Cylance AI stops more attacks, earlier and with less effort than other solutions in the market today Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Feb 7, 2024 · 51 min

    Hong Kong hijinks, pig butchers, and poor ransomware gangs

    Is this the real life? Is this just fantasy? A company in Hong Kong suffers a sophisticated deepfake duping, be one your guard from pig butchers as Valentine's Day approaches, and spare a moment to feel sorry for poor ransomware gangs. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Lianne Potter from the "Compromising Positions" podcast. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: ‘Everyone looked real’: multinational firm’s Hong Kong office loses HK$200 million after scammers stage deepfake video meeting - South China Morning Post. Countdown’s Rachel Riley is deepfaked by HSBC - Vimeo. Scameter - Cyber Defender HK. Warning as scammers fake police Scameter app - The Standard. Ransomware payment rates drop to new low – now 'only 29% of victims' fork over cash - The Register. New Ransomware Reporting Requirements Kick in as Victims Increasingly Avoid Paying - Coveware. Romance scam reports rose by a fifth in 2023, says Lloyds Bank - The Independent. What is a ‘pig-butchering’ scam – and why is it on the rise? - BBC. Pig butchering mining scams: What they are and how to stop them - SC Media. No love for romance scammers in 2024 - Consumer Advice. Romance scammer reveals how he tricks women after failing to fool Go Public reporter - CBC. Sudoku Exchange. Learn Improv at Laugh at Leeds. Mr Mercedes - Disney+. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jan 31, 2024 · 58 min

    Interview with an iPhone thief, anti-AI, and have we gone too far?

    The iPhone security setting that you should enable right now, the worrying way that AI is predicting what criminals look like, and we play a game of face fake or real... All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Mobile phone stolen every six minutes in London, says Met Police - BBC News. iPhone Thief Explains How He Breaks Into Your Phone - YouTube. About Stolen Device Protection for iPhone - Apple. Cops Used DNA to Predict a Suspect’s Face—and Tried to Run Facial Recognition on It - Wired. Will ChatGPT write ransomware? Yes - Malwarebytes. AI chatbots are making scams more convincing than ever, warn spy chiefs - The Telegraph. Test yourself: which faces were made by AI? - New York Times. AI vs. Human Writing: Experts Fooled Almost 62% of the Time- Neuroscience News. I know that I know nothing - Wikipedia. Yours truly, Johnny Dollar - Comic book. I Heart Umami. Libby. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jan 24, 2024 · 46 min

    Big dumpers, AI defamation, and the slug that slurped

    This week the podcast is more lavatorial than usual, as we explore how privacy may have gone to sh*t on Google Maps, our guest drives hands-free on Britain's motorways (and is defamed by AI), and ransomware attacks an airplane-leasing firm. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by BBC Technology Editor Zoe Kleinman. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: The Great British Public Toilet Map. How one man’s pay-to-use toilet gag revealed Google Maps can be used to track people - Crikey. Please Rob Me site exposes danger of sharing too much information online - Graham Cluley. Artist creates a virtual traffic jam in Google Maps - YouTube. How to Get Google to Quit Tracking Your Location - PC Magazine. Grieving With Google Street View - Slate. Zoe describes her curious tangle with AI - Twitter. What happens when you think AI is lying about you? - BBC News. Aercap confirms cyber threat involving ransomware - Air Finance. Ransomware crims slime AerCap, claim to have stolen 1TB - The Register. AerCap discloses cybersecurity incident - Reuters. BBC staffers warned of payroll data breach. BA and Boots also affected by MOVEit vulnerability - Graham Cluley. Randy Rainbow - YouTube. Donald in the John With Boxes - A Randy Rainbow Song Parody - YouTube. Zoe drives hands-free on a British motorway - Twitter. How to Play Taco Cat Goat Cheese Pizza - Wikihow. Asmodee Taco Cat Card Game - John Lewis. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jan 17, 2024 · 47 min

    Fishy Rishi, 23andMe, and the labour of love

    Has the British Prime Minister been caught secretly profiting from a cryptocurrency app? Were 23andMe right to blame their users after a data breach? And Indian men have hard feelings after falling for a money-for-sex scam. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: What Rishi Sunak gets up to over Christmas… - YouTube. Boris Johnson's Love Actually parody (Conservative Party election broadcast) - YouTube. UK's Rishi Sunak becomes richest ever occupant of Number 10 - Reuters. Over 100 Deep-Faked Rishi Sunak Ads Found on Meta’s Platform - Fenimore Harper Communications. Slew of deepfake video adverts of Sunak on Facebook raises alarm over AI risk to election - The Guardian. 23andMe Blames User “Negligence” for Data Breach - Infosecurity Magazine. All India Pregnant Job service: Indian men conned by 'impregnating women' scam - BBC News. World War II: From the Frontlines - Netflix. Spintronics - Upper Story. Reacher - Amazon Prime. The Trust - Netflix. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Jan 10, 2024 · 48 min

    Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam

    Chuck Norris gives a helping hand to a mysterious cryptocurrency CEO who may have separated investors from over a billion dollars, generative AI creates a nightmare for those wanting to Know Their Customer, and a determined journalist finally gets their revenge on a sneaky Airbnb scammer. All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, who are joined this week by special guest Maria Varmazis. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Chief executive of collapsed crypto fund HyperVerse does not appear to exist - The Guardian. Crypto hedge fund CEO may not exist; probe finds no record of identity - Ars Technica. BUSTED: Fake HyperVerse CEO Who Stole $1.3 Billion Unmasked! - YouTube. Hyperverse’s Steven Reece Lewis outed as Steve Harrison - Behind MLM. HyperVerse crypto promoter ‘Bitcoin Rodney’ arrested and charged in US - The Guardian. GenAI could make KYC effectively useless - TechCrunch. Airbnb Grifter Busted for $7.5 Million 'Bait-and-Switch' Scam, Feds Say - The Daily Beast. I Accidentally Uncovered a Nationwide Scam Run by Fake Hosts on Airbnb - Vice. Percentage Point vs. Percent Difference - Macroption. “Is Math Real?” - Book by Eugenia Cheng. “Julia” trailer - YouTube. Watch Before We Die - Channel 4. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Dec 20, 2023 · 44 min

    Phone hacking, Piers Morgan, and Carole’s Christmas cockup

    Piers Morgan is less than happy after a judgement that there is "no doubt" he knew phone hacking was going on at the Daily Mirror, and a shopper comes a-cropper just before Christmas. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Piers Morgan denies knowing of phone hacking after judge rules he did - The Guardian. I've never told anyone to hack a phone - Piers Morgan tells Laura Kuenssberg - BBC News. Piers Morgan interviewed by BBC’s Amol Rajan about phone hacking at Daily Mirror - BBC News. Piers Morgan will find many ways to deny phone hacking – but how long before his number is up? - Archie Bland’s article in The Guardian. Piers Morgan tells Charlotte Church how to stop her mobile phone from being hacked - YouTube. I'm sorry, Macca, for introducing you to this monster - Piers Morgan describes in the Daily Mail a voicemail he heard between Paul McCartney and Heather Mills. The human cost of phone hacking - Graham Cluley. Eudesignhouse.shop Review – Unmasking the Store Closing Scam - MyAntiSpyware. Whois Domain Lookup. Myth Maker: The Lost Legacy of Donald Cotton - SoundCloud. 15 virtual Christmas party games to play this festive season - Country Living. 21 Virtual Christmas Games To Play On Zoom With Adults - Team Building. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Dec 13, 2023 · 56 min

    For research purposes only

    A hacker bursts the bubble of inflatable fetish fans, Hollywood celebrities unwittingly record videos in a Kremlin plot, and there's a particularly devious WordPress-related malware campaign. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Fuzzy Duck - Wikipedia. Cybercrime author Geoff White demonstrates his NSFW balloon trick at the "Smashing Security" podcast Christmas party - Reddit. Rule 34 - Wikipedia. We are (temporarily) offline - InflateVids on Patreon. Fast Company’s Apple News access hijacked to send an obscene push notification - The Verge. Fast Company Hacker on Rogue Apple News Notification: ‘Anyone Could Have Done It’ - Vice. The WordPress backdoor with its own backdoor! (And fake CVE numbers, too) - Paul Ducklin. Russian influence and cyber operations adapt for long haul and exploit war fatigue - Microsoft. How Zelensky became Hollywood man of the hour - The Guardian. Nigel Farage wishes Hugh Janus a happy birthday - YouTube. Don Johnson - Cameo. Hollywood plays unwitting Cameo in Kremlin plot to discredit Zelensky - The Register. Winning hearts and minds - Military Wiki. AdGuard Home - GitHub. Garmin Edge 130 Plus - Garmin. Garmin Connect IQ - Garmin. The Thermapen. Flat Whisk Stainless Steel Egg Beater Mixer Kitchen Tool - Amazon. Small Silicone Spatulas - Amazon. 3 Pcs Rubber Jar Gripper Pads - Amazon. Marble Dough Roller - Amazon. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Push Security – Monitor and secure your entire identity attack surface, including non-SSO identities. Get notified in real-time to vulnerabilities across all your internet-facing identities, and have your staff guided to fix simple issues. Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Dec 6, 2023 · 59 min

    Nuclear cybersecurity, Marketplace scams, and face up to porn

    Hacking fears are raised at Western Europe's most hazardous building, why porn sites might soon be scanning your face, and our guest narrowly avoids a Facebook Marketplace scammer. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Why Facebook Is Rebranding Itself as Meta - INSEAD. Windscale fire - Wikipedia. Sellafield nuclear site hacked by groups linked to Russia and China - The Guardian. Response to a news report on cyber security at Sellafield - UK Government. Response to Guardian news article - Office for Nuclear Regulation. Common Facebook Marketplace scams and how to avoid them - Comparitech. Advice from Google on how to remove malware and unsafe software from Android devices - Google. New Report Reveals Truths About How Teens Engage with Pornography - Common Sense Media. ‘A lot of it is actually just abuse’- Young people and pornography - Children's Commissioner for England. Implementing the Online Safety Act: Protecting children from online pornography - Ofcom. UK age assurance guidance for porn sites gives thumbs up to AI age checks, digital ID wallets and more - TechCrunch. Demotivational posters. "Her Time: How Trailblazing Women Scientists Decoded the Hidden Universe," by Shohini Ghos. Meet Your Second Wife - Saturday Night Live sketch, YouTube. ‘Modern Love Podcast’: Our 34-Year Age Gap Didn’t Matter, Until It Did - New York Times. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Push Security – Monitor and secure your entire identity attack surface, including non-SSO identities. Get notified in real-time to vulnerabilities across all your internet-facing identities, and have your staff guided to fix simple issues. Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 29, 2023 · 1 hr 4 min

    Think before you shrink! And our guest is faked

    Don't minimise your Teams Meeting video call too hastily, you might reveal your dirty secrets! Would you be prepared to pay for Facebook and Instagram? And who is being faked to promote cryptocurrency scams? All this and much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by technology journalist Jane Wakefield. Plus - don't miss our featured interview with Push Security founder and CEO Adam Bateman. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: XtraVue Trailer demo - YouTube. Nvidia sued after video call mistake showed 'stolen' data - BBC News. Valeo v. Nvidia complaint - DocumentCloud. Fake BBC news article using Jane Wakefield’s name - Twitter. Report a fraudulent webpage to Google Safe Browsing - Google. Meta's EU ad-free subscription faces early privacy challenge - Yahoo! Meta to offer ad-free subscription in Europe in bid to keep tracking other users - TechCrunch. Meta’s EU ad-free subscription faces early privacy challenge - TechCrunch. Facebook and Instagram to Offer Subscription for No Ads in Europe - Facebook. noyb files GDPR complaint against Meta over “Pay or Okay” - NOYB. Big Mac index 2023 - Statista. Euro aea wages 2023 - Take-profit.org. Boat Story review - The Guardian. GlasgowGPT - the world's first Scottish artificial intelligence chatbot. Gergely Orosz uncovers fake female speakers at a tech conference - Twitter. Eliza-May Austin shares her experiences of being invited to speak at tech conferences - LinkedIn. Boat Story - BBC iPlayer. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Push Security - Monitor and secure your entire identity attack surface, including non-SSO identities. Get notified in real-time to vulnerabilities across all your internet-facing identities, and have your staff guided to fix simple issues. Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 22, 2023 · 43 min

    Ransomware gang reports its own crime, and what happened at OpenAI?

    Who gets to decide who should be CEO of OpenAI? ChatGPT or the board? Plus a ransomware gang goes a step further than most, reporting one of its own data breaches to the US Securities and Exchange Commission. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Hackers Use Online Casinos to Gamble Mountains of Cash They Steal from Victims - 404. AlphV files an SEC complaint against MeridianLink for not disclosing a breach to the SEC - DataBreaches.net. SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies - US Securities and Exchange Committee. OpenAI announces leadership transition - OpenAI. The Fear and Tension That Led to Sam Altman’s Ouster at OpenAI - The New York Times. Emergency Pod: Sam Altman is Out at Open AI - The New York Times. What We Know About Sam Altman’s Ouster From OpenAI - The New York Times. Ousted OpenAI C.E.O. Makes Plans for New Artificial Intelligence Company - The New York Times. Microsoft Hires Sam Altman Hours After OpenAI Rejects His Return - The New York Times. In the battle to bring ousted founder Sam Altman back to OpenAI, Microsoft and Satya Nadella hold the trump cards - Fortune. Rate your resignation letter - Twitter account. Suella Braverman’s resignation letter - Twitter. Analysis of letter by Dame Andrea Jenkyns - Twitter. Thread about letter from Dame Andrea Jenkyns - Twitter. The Future by Naomi Alderman review - The Guardian. The Future by Naomi Alderman - Harper Collins. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 15, 2023 · 36 min

    Hacking for chimp change, and AI chatbot birthday

    Who's more incompetent - the cryptocurrency exchanges or some of the people who hack them? Plus a closer look at the reliability of AI chatbots. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Bored Ape NFT Partygoers Blame UV Lights For Burned Eyes And Skin - Kotaku. Poloniex crypto-exchange offers 5% cut to thieves if they return that $120M they nicked - The Register. Raft Suffers $3.3M Exploit That Drove Down Stablecoin 50%, but Hacker Likely Lost Money on Attack - CoinDesk. Leaderboard Comparing LLM Performance at Producing Hallucinations when Summarizing Short Documents - Github. Cut the Bull…. Detecting Hallucinations in Large Language Models - Vectara. Chatbots May ‘Hallucinate’ More Often Than Many Realize - The New York Times. Bing's ChatGPT-Powered Search Has a Misinformation Problem - Vice. ChatGPT gets code questions wrong 52% of the time - The Register. FreeTube. The Wonderful Story of Henry Sugar - Netflix. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! Panoptica – Panoptica is a cloud native application security solution connecting developer and security teams to their organization’s biggest cloud threats from code to production. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 8, 2023 · 1 hr 4 min

    Trolls, military data, and the hitman and her

    A woman's attempt to hire an assassin online backfires badly, it's scary just how cheap it is to buy information about US military personnel, and trolls and tattoos don't mix. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner. Plus don’t miss our featured interview with Jason Meller of Kolide. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Woman jailed after RentaHitman.com assassin turned out to be – surprise – FBI - The Register. Zandra Ellis criminal complaint (PDF). Rent-A-Hitman: Your Point & Click Solution! - YouTube. It’s shockingly easy to buy sensitive data about US military personnel - MIT Technology Review. This Guy Trolls His TikTok Haters By Getting Tattoos of Them - Vice. Man Gets Back at Trolls Online With Revenge Tattoos - MSN. The Beatles - “Now and Then” music video - YouTube. “The Last of Us” piano scene, episode 3 - YouTube. Celeritas podcast. Pick of the week archive - Smashing Security. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! Panoptica – Panoptica is a cloud native application security solution connecting developer and security teams to their organization’s biggest cloud threats from code to production. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 1, 2023 · 41 min

    How hackers are breaching Booking.com, and the untrustworthy reviews

    Workers wonder if their colleagues are actually AI, and we take a deeper look into the curious scams going on via Booking.com. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Art Musings - Gratuitous plug for Carole’s new podcast with Sally Anne-Stewart. Smashing Security #344: What’s cooking at Booking.com? And a podcast built by AI - Smashing Security. Fraudsters target Booking.com customers claiming hotel stay could be cancelled - Graham Cluley. Scammers try to trick Graham again via Booking.com - Twitter. 'Thieves used fake Booking.com emails to steal £1,000 from me before my wedding' - The Mirror. Includes gratuitous mention of Graham’s hunt for aubergines. Unmasking a Sophisticated Phishing Campaign That Targets Hotel Guests - Akamai. Did AI Write Product Reviews? Gannett Says No - The New York Times. Is my co-worker AI? Bizarre product reviews leave Gannett staff wondering - The Verge. How to spot a fake review - Which? Lonely Water - Public information film from 1973. Scarred for Life Volume 1: The 1970s - Lulu. Scarred for Life Volume 2: Television in the 1980s - Lulu. Scarred for Life Twitter account. Say More with Dr? Sheila - Apple Podcasts. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! Panoptica - Panoptica is a cloud native application security solution connecting developer and security teams to their organization’s biggest cloud threats from code to production. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 25, 2023 · 54 min

    Cyber sloppiness, and why does Google really want to hide your IP address?

    Ahoy! There's trouble in the South China Seas as Filipino organisations fail to secure their systems, we take a close look at Google IP protection, and we take a look at just how so much genetic profile data leaked out of 23andMe. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Philippines’ cybersecurity failures exposed as hackers leak state secrets, people’s data - South China Morning Post. IT admins are just as culpable for weak password use - Outpost24. Google Chrome wants to hide your IP address - MalwareBytes. The 23andMe data breach reveals the vulnerabilities of our interconnected data - The Conversation. 23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews - Wired. Worried about the 23andMe hack? Here's what you can do - Washington Post. Paris Police 1905 - BBC iPlayer. British Hen Welfare Trust. Art Musings - Art Musings podcast. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 18, 2023 · 44 min

    What’s cooking at Booking.com? And a podcast built by AI

    How hunting for an aubergine could be all it takes for you to hand your credit card details over to a scammer, and just how good is a podcast entirely built by AI? All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Support Alie Hothersall’s fundraising for Mind - JustGiving. Fraudsters target Booking.com customers claiming hotel stay could be cancelled - Graham Cluley. Security.txt - A proposed standard which allows websites to define security policies. Develop AI launches a completely synthetic podcast - Develop AI. Develop AI podcast. Is It Legal To Pay - The err.. https version of a map of which countries allow you to pay ransom demands. Licorice Pizza - BBC iPlayer. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Devo – Register now to join Devo and other cybersecurity industry professionals on October 18 for sessions and panels focused on de-stressing, SOC career development, and more! Vanta - Expand the scope of your security program with market-leading compliance automation... while saving time and money. Smashing Security listeners get 10% off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 11, 2023 · 48 min

    Four-legged girlfriends, LoveGPT, and a military intelligence failure

    Dream girlfriends, AI love scams, and an alleged spy who is said to have made a series of blunders. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Former Soldier Indicted for Attempting to Pass National Defense Information to People’s Republic of China - US Department of Justice. ‘Dream’ AI Girlfriend Randomly Turns Into Nude Jennifer Lopez, Has Four Legs - 404 Media. LoveGPT: How “single ladies” looking for your data upped their game with ChatGPT - Avast Threat Labs. 5 Signs Your Tinder Match Is a Scam Bot - LifeWire. Support Alie Hothersall’s fundraising for Mind - JustGiving. “The Last Action Heroes” by Nick de Semlyen - Pan Macmillan. Life Kit - NPR. Tom Hanks has made a complaint - Twitter. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Devo – Register now to join Devo and other cybersecurity industry professionals on October 18 for sessions and panels focused on de-stressing, SOC career development, and more! Moonlock — cybersecurity wing of MacPaw. Developers of the antimalware tech in CleanMyMac X — Moonlock Engine. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 4, 2023 · 1 hr 8 min

    Royal family attacked, keyless car theft, and a deepfake Tom Hanks

    Is a deepfake Tom Hanks better than the real thing? Who has been attacking the British Royal Family's website, and why? And how can you protect your vehicle from the spate of keyless car thefts? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis. Plus don't miss our featured interview with Devo CISO Kayla Williams. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: The disturbing uncanny valley of Robert Zemeckis film 'Polar Express' - Far Out magazine. Tom Hanks warns of deepfake video promoting dental plan - Instagram. Fuming Tom Hanks says he had nothing to do with that AI dental ad clone of him - The Register. Tom Hanks warns dental plan ad image is AI fake - BBC News. Robin Williams’ Daughter Zelda Criticizes Use of AI to Re-create His Voice: “I Find It Personally Disturbing” - Hollywood Reporter. Bruce Willis denies selling rights to his face - BBC News. Deepfake Bruce Willis in Russian telecoms advert - YouTube. Could you get "carhacked"? The growing risk of keyless vehicle thefts and how to protect yourself - CBS News. Keyless car theft: What is a relay attack, how can you prevent it, and will your car insurance cover it? - Leasing.com. Testing Phone-Sized Faraday Bags - Matt Blaze. Famous DDoS attacks - Cloudflare. The sinister Russian hackers who've claimed responsibility for crashing Buckingham Palace website - Daily Mail. King Charles rebukes Russia's 'horrifying' invasion of Ukraine in unprecedented speech - Express. Visually, how much paper would a GB and a TB of data fill in terms of physical size? - Quora. “The shop around the corner” - Wikipedia. Evan Designs. “Eight Detectives” by Alex Pavesi - Penguin Books. Review of “Eight Detectives” - The Guardian. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Hunters – A SOC platform, built to empower your security team to reduce risk, complexity and costs. Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Devo - Register now to join Devo and other cybersecurity industry professionals on October 18 for sessions and panels focused on de-stressing, SOC career development, and more! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 27, 2023 · 58 min

    Another T-Mobile breach, ThemeBleed, and farewell Naked Security

    Mix TikTok with facial recognition, and you've got a doxxing nightmare, T-Mobile users report bizarre behaviour in their accounts, and a Windows flaw provides a new means of infecting users. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: T-Mobile customer reports privacy breach - Twitter. T-Mobile US exposes some customer data – but don't call it a breach - The Register. T-Mobile denies new data breach rumors, points to authorized retailer - Bleeping Computer. Connectivity Source - Despite appearances, don’t confuse it with T-Mobile. ThemeBleed exploit is another reason to patch Windows quickly - MalwareBytes. If I Embarrass My Baby on TikTok, Will He Stay My Baby Forever? - New York Times. They Gossiped At Brunch. Now There's a Mob After Them - Rolling Stone. The End of Privacy is a Taylor Swift Fan TikTok Account Armed with Facial Recognition Tech - 404 Media. Egg crack challenge,the last baby is so cute - YouTube. Trailer for “The Deepest Breath” - YouTube. “The Deepest Breath” - Netflix. Nitpick: Meaningless communications. Naked Security. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Gigamon – Download the Gigamon Hybrid Cloud Security Survey to learn about the hidden dangers of encrypted traffic. Drata – With over 14 frameworks including SOC2, GDPR, HIPAA, and ISO 27001, Drata gets you audit-ready for crucial security standards needed to scale your business. As a listener to Smashing Security you can save 10% off Drata and have implementation fees waived. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 20, 2023 · 1 hr 3 min

    Heated seats, car privacy, and Graham’s porn video

    Do you know what data your car is collecting about you? Do you think it's right for a car manufacturer to collect a subscription to keep your bottom warm? And just why has YouPorn sent an email to Graham about his sex video? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Andrew Agnês. Plus don't miss our featured interview with Gigamon's Mark Jow. Warning: This podcast may contain nuts, adult themes, and rude language. Episode links: Yikes! My sex video has been uploaded to YouPorn, apparently - Graham Cluley. 1 million YouPorn users exposed; data breach required no security penetration - Computer World article from 2012. The YouPorn Sextortion Email Spam Campaign Explained - MalwareTips. BMW deems drivers worthy of warmth, ends heated car seat subscription - The Register. Hackers crack Tesla software to get free features - The Independent. It's Official: Cars Are the Worst Product Category We Have Ever Reviewed for Privacy - Mozilla Foundation. Car Companies: Stop Your Huge Data Collection Programs - Mozilla Foundation. Programming language inventor or serial killer? - Vole.wtf. Rask - AI video localisation. Verbalate - Video translation and lip sync software. The Following Events Are Based on a Pack of Lies review - The Guardian. The Following Events Are Based on a Pack of Lies - BBC iPlayer. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Sponsored by: Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today! Gigamon – Download the Gigamon Hybrid Cloud Security Survey to learn about the hidden dangers of encrypted traffic. Drata – With over 14 frameworks including SOC2, GDPR, HIPAA, and ISO 27001, Drata gets you audit-ready for crucial security standards needed to scale your business. As a listener to Smashing Security you can save 10% off Drata and have implementation fees waived. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed! FOLLOW US: Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy