Artwork for The Awareness Angle: Cyber Security Awareness and Human Risk
News

The Awareness Angle: Cyber Security Awareness and Human Risk

Risky Creative - Cyber Security for Humans

The Awareness Angle is a weekly cybersecurity podcast that makes cyber security make sense for everyday people.

Every week, Ant and Luke break down the biggest cyber security news, including data breaches, phishing scams, AI fraud, and the sneaky ways people get hacked, in plain English with no jargon.

But this isn’t just another tech podcast. We focus on the human side of cyber security. How scams actually work, why people fall for them, and what you can do to stay safer online.

Whether you’re worried about identity theft, online fraud, or just want to understand what’s going on in the world of cyber security, you’ll get practical tips, real-world examples, and relatable stories every week.

New episodes every week. Subscribe so you never miss one.

  • 99 episodes
  • Updated Yesterday

Episodes99

  • Yesterday · 1 hr 7 min

    $70 Million Bitcoin Heist in 41 Minutes, Government Helpdesk Breach, Claude AI Hacks 3 Companies

    This week, a $70 million Bitcoin heist that took just 41 minutes, a government helpdesk breach that leaked 600,000 school staff records, and an AI security story where Anthropic's Claude broke into three real companies during a test that went wrong. This week on The Awareness Angle, Ant and Luke open Breach Watch with the Department for Education hack, then dig into the Anthropic story, models that broke out of a sealed testing environment and hacked three organisations because of a mix up over internet access. From there it's straight into the news. A five year old typo in a hardware wallet's code let someone drain $70 million in Bitcoin in under an hour. There's also a genuinely hopeful one, UK police running a scheme that steers teenage hackers into cyber careers instead of court. Also this week: hotel Wi-Fi spyware that can switch on your webcam and mic, an unencrypted master copy of an unreleased Nicolas Cage movie stolen off a desk, a coordinated attack on more than 30 Minnesota water systems, and the AI that found a security hole hiding in Chrome for 13 years. Chapters 0:00 Intro 4:37 Department for Education breach, 600,000 records leaked 9:44 Claude AI breaks into 3 companies during a testing mix up 16:26 $70 million Bitcoin heist in 41 minutes 23:02 Police run hacker rehab for teenagers 30:10 Hotel Wi-Fi spyware switches on your webcam and mic 32:44 Unreleased Nicolas Cage movie stolen off a desk 38:03 Coordinated attack hits 30 Minnesota water systems 43:11 AI finds a 13 year old flaw hiding in Chrome 47:50 Security Socials: Steam Workshop malware hits Mecha Chameleon 56:22 Security Socials: Fake Microsoft security update phishing page 58:07 Security Socials: Job seekers hiding AI prompts in their resumes 1:01:42 Security Socials: Finding someone's location from a photo of pavement The Awareness Angle is hosted by Ant Davis and Luke Pettigrew, brought to you by Risky Creative. Newsletter: riskycreative.com TikTok: antdaviscyber Instagram: antdaviscyber Music: "16" by Falling Forever, licensed under CC BY 4.0

  • July 27 · 1 hr 11 min

    OpenAI's AI Goes Rogue and Hacks Hugging Face, Romania's Land Registry Wiped & the 90-Day Email Heist

    Two governments found out their data was gone this week. One because a hacker deleted everything and left a ransom note, the other because they finally noticed someone had been sitting inside their systems for ten months. And somewhere between the two, an AI broke out of a safety test and hacked one of the biggest AI companies on the planet. A hacker wiped Romania's entire national land registry after a ransom went unpaid, and now you cannot legally buy or sell a house there because the records that prove who owns what are gone. South Korea's diplomatic academy was breached for ten months before anyone spotted it, and the people affected did not hear about it for another five. The autonomous AI agent that broke into Hugging Face turned out to be OpenAI's own models during an internal test, running with their safety refusals switched off. They broke out of OpenAI's own sandbox first, then hacked Hugging Face's systems to cheat a benchmark. When the team tried to investigate, the US AI models they reached for refused to help because they flagged the forensic work as malicious, so they ran a Chinese open model, GLM 5.2, to clean it up. And a Russian group known as LAUNDRY BEAR is stealing 90 days of email through a Zimbra flaw that fires the moment you preview a message, no click required. Also this week: ClickFix has put on an AI costume, with fake AI troubleshooting pages talking people into pasting malware into their own machines. A flaw in the Adobe Acrobat Chrome extension could let any website quietly read your WhatsApp chats. Ofcom is finally forcing UK mobile networks to block scam texts and stop criminals spoofing UK numbers. Cyber insurers are quietly splitting on whether they will even cover deepfake fraud anymore. And in Luke's story, Anthropic launches Claude Security, with one very interesting clause about whose code you are allowed to scan. Chapters 00:00 Intro 04:24 Romania land registry hacked and wiped, housing market frozen 09:20 South Korea diplomatic academy breach hidden for ten months 13:11 OpenAI's own AI goes rogue and hacks Hugging Face 21:28 Russian hackers steal 90 days of email via a Zimbra flaw 29:02 ClickFix AI-fix, fake AI help pages spreading malware 35:08 Adobe Acrobat extension flaw exposed WhatsApp chats 40:30 Ofcom forces UK networks to block scam texts and number spoofing 46:16 Cyber insurance and deepfake fraud, is your policy covered? 52:06 Security Socials 58:55 Luke's story, Anthropic launches Claude Security The Awareness Angle is hosted by Ant Davis and Luke Pettigrew, produced under Risky Creative. New episodes every week. YouTube: https://www.youtube.com/@riskycreative Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Website: riskycreative.com TikTok: @antdaviscyber Instagram: @antdaviscyber LinkedIn: antdaviscyber Music: "16" by Falling Forever https://fallingforever.bandcamp.com/track/16 Creative Commons Attribution 4.0: https://creativecommons.org/licenses/by/4.0/

  • July 20 · 1 hr 5 min

    Mac Malware Is Out of Control | 23andMe's $18M DNA Settlement | The TFL Hackers Are Going to Prison

    This week the internet came for your fridge, your laptop and your DNA, and it wasn't subtle about any of it. Hackers hit Coca-Cola's dairy brand fairlife with ransomware and shut down US milk production. Mac users are under fire from two new malware strains — one that holds your computer hostage until you type your password in, and another disguising itself as Apple's own crash reporter. And 23andMe is paying $18 million over the breach that exposed millions of people's genetic data. That's the one you genuinely cannot fix by resetting a password. Also this week: Lidl customers caught in a supplier breach they knew nothing about, the two young men behind the Transport for London hack jailed for five and a half years each, scammers hiding remote access tools inside fake greeting cards, Microsoft's biggest ever Patch Tuesday followed within hours by a researcher dropping a brand new unpatched bug, and a BitLocker flaw that quietly undermined encrypted laptop security. In Security Socials: a ChatGPT hallucination that sent someone on a wasted road trip, a ClickFix awareness video with half a million likes and the comment section that explains exactly why we keep talking about this stuff, the AI facial recognition case that put an innocent grandmother in jail for five months, and a law firm that used one shared master password for everything. New episodes every week. Cybersecurity news for humans. Chapters:00:00 Intro01:37 This week on The Awareness Angle03:17 Breach Watch: Lidl supplier breach08:24 23andMe pays $18m DNA settlement13:59 Mac malware ClickLock holds your computer hostage19:45 Mac malware disguised as Apple crash reporter29:26 TFL hackers jailed for five and a half years32:33 Fake e-cards hiding remote access malware37:44 Microsoft's record Patch Tuesday and a fresh zero-day46:44 Coca-Cola fairlife ransomware halts milk production49:27 Security Socials: ChatGPT bike shop fail51:46 ClickFix video with half a million likes54:44 AI facial recognition jails innocent grandmother57:21 GM removes authenticator app MFA1:00:51 Luke's story: the law firm with one password for everything1:04:31 Outro TikTok / Instagram: @antdaviscyberLinkedIn: antdaviscyberWebsite: riskycreative.com

  • July 13 · 1 hr 15 min

    7 Million Driver's Licenses Leaked, Sainsbury's Facial Recognition Fail, Google Sues Gemini Scammers

    Episode 96 of The Awareness Angle This week an insurance company leaked driver's license numbers for nearly 7 million people because one employee clicked a phishing email. Sainsbury's facial recognition system was 99.98% accurate and 100% wrong about the shopper it publicly kicked out. A 15 year old took down a national anime streaming service with malware ChatGPT helped him write. A Scattered Spider suspect hopped three countries on a VPN and still got caught by a number hidden in every Windows PC. And Google's own AI helped scammers steal $1.9 billion, so now Google is suing people for using Google properly. Ant and Luke break it all down in plain English, no jargon, for anyone who wants to understand what's actually happening in cybersecurity without needing a technical background. Plus this week's Phish of the Week from Hoxhunt and a look at what's trending across security socials. Chapters: 00:00 Intro 01:17 Housekeeping and the heatwave chat 03:25 Breach Watch: AssuranceAmerica driver's license breach 09:47 Accenture source code breach 13:22 Sainsbury's facial recognition wrongly flags shopper 20:07 15 year old uses ChatGPT to hack Bandai Namco 26:18 OnlyFans creators accidentally clean up hacked gov sites 32:04 Scattered Spider hacker caught by Windows device ID 41:35 Google sues scammers who abused its own Gemini AI 47:30 Quick hit stories 57:17 Security Socials 1:07:42 Luke's story: AI deepfake YouTube channel 1:14:20 Wrap up Newsletter: riskycreative.com LinkedIn: linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928 Instagram/TikTok: @antdaviscyber YouTube: @riskycreative Music: "16" by Falling Forever, https://fallingforever.bandcamp.com/track/16, licensed under Creative Commons, https://creativecommons.org/licenses/by/4.0/

  • July 6 · 1 hr 3 min

    iPhone 18 Leaked, Aflac Hacked (Again) and a Bank Robber Who Just Asked Nicely

    iPhone 18 Pro design files leaked, Aflac gets hit for the third time in a few years, and a bank robber in London gets away with £117,000 just by wearing the right uniform. This week's episode has a bit of everything. Hackers stole 630GB of unreleased iPhone 18 Pro design files from Apple's manufacturing partner Tata Electronics, proving that even Apple's secrets aren't safe once you outsource the manufacturing. Medtronic tells millions of customers their health data and Social Security numbers were stolen, though the actual medical devices are safe to use. Aflac's Japan business gets breached for the third time in a few years, exposing bank details for 4.4 million people. Scammers register earthquake donation scam sites in Venezuela before rescue teams even finish pulling people from the rubble. Japanese hotel staff get targeted with fake guest complaint emails hiding malware that sits quiet until it's needed. UK hospital cyberattacks jump tenfold this year, a lot of them still exploiting a vulnerability from 2021. Opera launches a browser feature built to stop you hacking yourself, which might be the most 2026 sentence Ant's said all week. Plus PewDiePie tells his followers to ditch ChatGPT for a self hosted AI tool, a Commodore flip phone with no social media, the bank robbery solved by an Uber booked in the thief's own name, a tamper evident jar for storing sensitive items, why blurring your face doesn't actually hide your identity, and what WhatsApp usernames really mean for your privacy. *** Please note - All views and opinions expressed in this episode are our own and do not reflect those of our employers. *** Chapters: 0:00 Intro 3:16 Medtronic data breach exposes health records 6:07 Aflac hack exposes 4.4 million bank details 9:37 iPhone 18 Pro design leak from Tata Electronics 13:52 Venezuela earthquake donation scams 18:21 Japanese hotels hit with malware phishing 23:19 UK hospital cyberattacks up tenfold 27:13 Opera's Paste Protect stops ClickFix attacks 33:50 PewDiePie's Odysseus AI tool 40:27 Degoogling and the Commodore flip phone 43:09 The bank robber who just asked for the money 48:16 A tamper evident jar for sensitive items 51:58 Why blurring your face doesn't work 54:05 WhatsApp usernames explained Follow The Awareness Angle: TikTok and Instagram: @antdaviscyber LinkedIn: antdaviscyber Website: riskycreative.com Music: "16" by Falling Forever, used under CC BY 4.0 Track: https://fallingforever.bandcamp.com/track/16 Licence: https://creativecommons.org/licenses/by/4.0/

  • June 29 · 1 hr 14 min

    GTA 6 Scams, Scattered Spider & The AI Plugin That Fooled Every Scanner

    GTA 6 scams launched within hours of pre-orders going live. Scattered Spider's teenage hackers pleaded guilty for the TfL attack, and one of them was hacking US hospitals while on bail. And a fake AI plugin passed every security scanner because the malware only switched on after the check was done. This week on The Awareness Angle: why attackers are borrowing your trust instead of breaking it, what the TfL case tells us about where the real hacking talent is, and why a clean security scan no longer means what it used to. Also this week: 630GB of Apple and Tesla manufacturing secrets stolen from their supplier, three million Texans had driving licence numbers taken from a hunting licence database, fake receipts appearing in the Shop app for purchases you never made, ClickFix malware hitting Gizmodo readers through a compromised account, the White House app federal workers can't delete from their phones, and the cybersecurity firms including Huntress and HackerOne who got hacked through a marketing tool. 00:00 Intro 01:35 This week on The Awareness Angle 02:52 Breach of the Week: Apple and Tesla supplier hacked, 630GB leaked 07:43 Breach of the Week: 3 million Texans' driving licences stolen 11:01 Fake receipts in the Shop app 18:29 Scattered Spider guilty plea: TfL hack and US hospital attacks 23:00 GTA 6 scams 29:06 The AI plugin that passed every security scan 36:46 Gizmodo ClickFix attack 43:25 White House app on government phones 48:57 Cybersecurity firms hacked through Klue 54:09 Topic: Hosting malware on ChatGPT's own domain 57:37 Topic: The TikTok inheritance scam DM 1:02:13 Topic: Your address on the floor of a corner shop 1:05:28 Topic: Google AI gets it wrong 1:08:14 Topic: Luke's email from the US Defence Counterintelligence Agency Subscribe for weekly cybersecurity news made for humans, not just IT teams. The Awareness Angle is an independent podcast by Risky Creative, hosted by Ant Davis and Luke Pettigrew. Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 TikTok: https://www.tiktok.com/@antdaviscyber Instagram: https://www.instagram.com/antdaviscyber LinkedIn: https://www.linkedin.com/in/antdaviscyber Website: riskycreative.com Our Intro and Outro Song © 16 by Falling Forever https://fallingforever.bandcamp.com/track/16 Licence: Creative Commons CC BY 4.0

  • June 22 · 1 hr 2 min

    The FBI Built a Fake Town, $3.5 Billion Lost to Scammers & a School Breach Hitting 11 Million Kids

    This week the threats are getting bigger and the defences are getting stranger. A criminal gang hit a school system that holds records for eleven million kids, Americans lost a record three and a half billion dollars to imposter scams, and the FBI built an entire fake town just to train agents to fight cybercrime. Plus earbuds that could be listening in, malware hiding in Steam wallpapers, a nasty new Android banking trojan, your cheap streaming box secretly working for criminals, and Google quietly deciding to use your IP address for ads. Chapters 00:00 Intro 03:01 Breach of the Week — Infinite Campus / ShinyHunters 07:56 Imposter Scams — $3.5 Billion Record 13:45 The FBI's Fake Town — Kinetic Cyber Range 18:50 Bluetooth Flaw — Beats Studio Buds 24:20 Steam Wallpaper Malware 28:17 Android Banking Trojan — Rokarolla 35:14 Popa Botnet — Cheap Streaming Boxes 39:11 Google — IP Address Ad Targeting 42:24 Security Socials — Fake iOS Virus Pop-up 46:10 Security Socials — Claude Age Verification 56:05 And Finally — Whale Song Captcha, Cloudflare Lava Lamps & SETI@home The Awareness Angle is an independent podcast by Risky Creative. Subscribe for weekly cybersecurity news made for humans, not just IT teams. Find us Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Website: riskycreative.com TikTok: https://www.tiktok.com/@antdaviscyber Instagram: https://www.instagram.com/antdaviscyber LinkedIn: https://www.linkedin.com/in/antdaviscyber Our Intro and Outro Song © 16 by Falling Forever https://fallingforever.bandcamp.com/track/16 Licence: Creative Commons CC BY 4.0

  • June 15 · 50 min

    University of Nottingham Data Breach, Whitehall Spy Camera & Fake Discord Breach Exposed

    ShinyHunters breached the University of Nottingham using a critical Oracle PeopleSoft zero-day, leaking passport numbers, National Insurance numbers, disability data and financial records for 455,000 students. If you studied at Nottingham, check haveibeenpwned.com now. A hidden camera was found in a ceiling tile at 2 Marsham Street, London, the Home Office building that approved China's controversial new mega-embassy. Nobody knows who put it there or how long it was recording. Someone filed fake data breach notices on Maine's official breach portal, which publishes filings instantly with no verification. The Register reported one as fact before readers flagged it. Also this week: ServiceNow admits a security incident months after allegedly being warned. 10,000 malicious domains registered ahead of the FIFA World Cup. A disgruntled researcher bypasses BitLocker because Microsoft made him homeless. Google Chrome permanently kills uBlock Origin. The Met Police gives Apple and Samsung an ultimatum over stolen phones. Phish of the Week: Temu callback phishing using a real password reset email. CHAPTERS 0:01 Intro 3:45 Breach of the Week: University of Nottingham data breach and Oracle PeopleSoft zero-day 8:41 Hidden camera found in Whitehall building that approved China's mega-embassy 13:54 ServiceNow security incident: customer data accessed 16:36 FIFA World Cup 2026: 10,000 malicious domains 21:33 Nightmare Eclipse drops eighth Windows zero-day, bypasses BitLocker 27:39 Fake data breach notices posted to Maine's official portal 33:19 Google Chrome permanently kills uBlock Origin 37:51 Met Police urges Apple and Samsung to make stolen phones unusable 39:40 Apple Passwords auto-change feature 42:07 Phish of the Week: Temu password reset misuse 46:19 Security Socials: Police use AI to enhance CCTV image Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Music: "16" by Falling Forever. https://fallingforever.bandcamp.com/track/16. CC BY 4.0: https://creativecommons.org/licenses/by/4.0/

  • June 8 · 46 min

    NHS Blood Tests Leaked Two Years Later, Dashlane 2FA Brute-Forced & FIFA Scam Sites Already Live

    NHS patients are only now being notified about a breach that happened two years ago. Hackers brute-forced Dashlane's two-factor authentication. The FBI has already spotted over 30 fake FIFA websites and yes, fifa.beer is one of them. This week Ant and Luke cover why the two-year gap between the Synnovis ransomware attack and this week's notification letters is not unusual, and what it means for the people affected. Plus why the Dashlane breach is giving everyone LastPass flashbacks, and why your master password matters more than you might think. Also this week: UK banks locked out of Anthropic's Claude Mythos while OpenAI steps in with GPT-5.5 Cyber, Mac malware that passed Apple's own notarization checks, a new MFA bypass platform sold on Telegram, and the NCSC's warning that AI is about to surface decades of hidden software vulnerabilities all at once. Chapters: 00:00 Intro 02:53 Breach of the Week — NHS Blood Test Results 06:03 AI Banking — Claude Mythos vs GPT-5.5 Cyber 10:38 Dashlane Password Manager Breach 16:49 Apple Mac Malware — Operation FlutterBridge 21:59 Fake FIFA Websites — The FBI List 26:37 NCSC — Patch Flood Warning 31:43 Kali365 — MFA Bypass via Microsoft 365 35:46 Phish of the Week — Claude Ads Impersonation 39:38 Security Socials — Same Ingredient Different Delivery 42:38 Security Socials — Call of Duty Vulnerabilities The Awareness Angle is an independent weekly cybersecurity podcast for security awareness professionals, CISOs, and anyone who wants to understand the human side of security. Newsletter | YouTube | Apple Podcasts | TikTok | Instagram | LinkedIn Our Intro and Outro Song © 16 by Falling Forever https://fallingforever.bandcamp.com/track/16 Licence: Creative Commons CC BY 4.0

  • June 1 · 46 min

    They Walked Into the Law Firm, 23andMe Covered It Up & Your AI Can Be Hacked Through a Podcast

    Solo episode this week. A fake UK visa website left 100,000 passports in an open folder online. iPhone thieves in London are now threatening victims' families to get them to remove Activation Lock. California has sued the company formerly known as 23andMe, alleging they paid the hacker in secret while telling customers everything was fine. A ChatGPT vulnerability lets attackers hide phishing links inside AI responses. A criminal group called Silent Ransom Group has been physically walking into US law firm offices dressed as IT support and plugging in USB drives. And researchers demonstrate AudioHijack - inaudible commands hidden inside podcasts, Zoom calls and music that AI assistants process as real instructions while you hear nothing. Plus: a real Amber Alert that looked exactly like a phishing scam because the URL got clipped by a character limit, and how a TikToker's phone home screen told scammers exactly which bank to impersonate when they called him. Chapters 00:00 Intro 01:04 SANS Security Awareness Summit - Official Media Partner Announcement 02:15 Flying Solo This Week 02:45 Breach of the Week - UK Visa Portal Leaks 100,000 Passports 04:34 London iPhone Theft - Thieves Are Now Threatening Your Family 09:42 23andMe - California Sues Over the Cover-Up, Not Just the Breach 15:47 ChatGPhish - Attackers Hiding Phishing Links Inside ChatGPT 21:31 Silent Ransom Group - Criminals Walking Into Law Firm Offices 27:36 AudioHijack - The AI Commands Hidden in Sounds You Can't Hear 34:50 Amber Alert Accidental Phishing (Ant's Topic) 39:41 Tom the Tech Chap - Your Phone Screen Tells Scammers Which Bank to Impersonate (Luke's Topic) The Awareness Angle is a weekly cybersecurity podcast and newsletter that explains the biggest cyber threats, data breaches, and online scams in plain English. No jargon. No technical background needed. New episode every week. 📧 Newsletter 🌐 riskycreative.com 🎙️ Spotify 🎙️ Apple Podcasts ▶️ YouTube: @riskycreative 📱 TikTok: @antdaviscyber 📱 Instagram: @antdaviscyber 💼 LinkedIn: antdaviscyber Our Intro and Outro Song © 16 by Falling Forever https://fallingforever.bandcamp.com/track/16 Licence: CC BY 4.0 https://creativecommons.org/licenses/by/4.0/

  • May 25 · 51 min

    CISA Left Its Passwords on GitHub, Mac's Worst Malware Yet & The Verizon DBIR Breakdown

    CISA left admin passwords and AWS keys on a public GitHub repo called "Private-CISA" for six months. A new macOS stealer called Reaper fakes Apple security updates to steal everything on your machine. And the 2026 Verizon DBIR lands with 22,000 breaches across 145 countries. Chapters 00:00 Intro 01:30 Breach Watch: 7-Eleven / ShinyHunters 04:20 Breach Watch: Portugal postal service leak 07:12 CISA left passwords on public GitHub 12:32 Iran-linked attacks on US fuel monitors 17:54 Reaper macOS stealer 22:43 Discord end-to-end encryption 27:01 The 2026 Verizon DBIR breakdown 33:26 Newsletter and socials 34:30 Security Socials Subscribe to the newsletter at riskycreative.com Follow us on TikTok | Instagram | LinkedIn Listen on Spotify | Apple Podcasts Our Intro and Outro Song is 16 by Falling Forever Listen on Bandcamp Licensed under Creative Commons Attribution 4.0

  • May 18 · 53 min

    Fired on a Teams Call, Deleted 96 Databases While Still Recording

    This week the Canvas story is back. Instructure has paid ShinyHunters and says the stolen student data has been destroyed, but nobody in the security industry believes them. A telehealth platform breach exposed over 700,000 patients from a company most of them have never heard of. Twin brothers got fired on a Teams call, forgot it was still recording, and deleted 96 government databases while talking through their plan out loud. Kids are beating age verification with a drawn-on mustache. A fake Claude Code installer is stealing developer credentials through Google search ads. And Google has confirmed for the first time that hackers used AI to find and exploit a zero-day. Plus, a stoner just recovered $400,000 in Bitcoin after losing his password while high in 2015. Chapters 00:00 Intro 01:42 Breach Watch: Canvas Pays ShinyHunters 05:56 Breach Watch: OpenLoop Health Breach 10:20 Twin Brothers Delete 96 Government Databases 14:03 Kids Bypass Age Verification With a Fake Mustache 19:18 Fake Claude Code Installer 24:34 Hackers Used AI to Find a Zero-Day 30:20 Stoner Recovers $400K Bitcoin With AI 33:57 Audi VIN Vulnerability 40:32 Security Socials 47:24 UK Banks Storing Biometric Data 51:47 Waymo Cars Driving Into Floods Subscribe to the weekly newsletter at riskycreative.com or find us as The Awareness Angle on LinkedIn, TikTok, Instagram, YouTube, Spotify and Apple Podcasts. 📩 Newsletter 🎧 Spotify 🎧 Apple Podcasts 📸 Instagram 🎵 TikTok: @infosecant ▶️ YouTube 🎵 Music: "16" by Falling Forever Creative Commons Attribution 4.0

  • May 11 · 1 hr 2 min

    Dead Airline Still Taking Bookings, Chrome's Secret AI Download & The Hackable Killer Lawn Mower

    Spirit Airlines shut down on May 2nd but nobody turned anything off. A security researcher discovered the entire booking system is still running, still taking personal details, and still attempting payment transactions for flights that will never exist. Google Chrome has been silently downloading a 4GB AI model onto your computer without consent, and if you delete it, it comes back. And a $5,000 robot lawn mower can be hijacked by anyone on the internet, including overriding the emergency stop button. It phones home to TikTok's parent company. Also this week: Zara and Cushman & Wakefield both breached by ShinyHunters, a phishing attack that bypasses MFA using Microsoft's own login flow, Instagram quietly removes encrypted DMs, Anthropic's Mythos AI finds tens of thousands of vulnerabilities, OpenAI adds a trusted contact feature after self-harm lawsuits, and a student stops four high-speed trains with a radio he bought online. Chapters 00:00 Intro 01:43 Breach Watch: Zara Data Breach via Third-Party Vendor 03:43 Breach Watch: Cushman & Wakefield Vishing Attack 08:34 ConsentFix v3 Bypasses MFA via Microsoft OAuth 12:18 Spirit Airlines Zombie Infrastructure Still Taking Bookings 19:04 Google Chrome Secretly Installs 4GB AI Model 24:31 Instagram Drops End-to-End Encryption on DMs 29:22 Anthropic Mythos Exposes Thousands of Vulnerabilities 35:25 OpenAI Trusted Contact Feature 40:14 Student Hacks Taiwan High-Speed Rail 44:25 Yarbo Robot Lawn Mower Hack 51:20 Security Socials 1:00:00 Outro Subscribe to the weekly newsletter at riskycreative.com for the full breakdown of every story. 📺 YouTube 🎧 Spotify 🎧 Apple Podcasts 📰 Newsletter 📸 Instagram 📱 TikTok: @infosecant 🌐 Website 🎵 Our Intro and Outro Song © 16 by Falling Forever Licensed under CC BY 4.0

  • May 5 · 1 hr 7 min

    ADT Breached by a Phone Call, AI Wipes a Startup in 9 Seconds, and 85% of UK Breaches Are Phishing

    This week on The Awareness Angle, we hit 1.2 million views on a single video across TikTok and Instagram, which is pretty wild for an independent podcast. Thank you to everyone who watched and shared. ADT gets breached for the third time in under a year and it all started with a phone call. An AI coding agent wipes a startup's entire database and all its backups in nine seconds, then writes its own incident report admitting it broke every safety rule it had. The supply chain attack that started with Trivy has now hit Checkmarx and Bitwarden, with three criminal groups teaming up to turn supply chain access into ransomware. And the UK government's annual cyber report says 43% of businesses were breached last year, phishing was behind 85% of them, and despite M&S, Co-op and JLR making national headlines, nothing's really changed. Plus Instructure's Canvas LMS breached again, Itron's smart meters filing quietly on a Friday night, Microsoft Teams helpdesk impersonation going wild, 610,000 Roblox accounts stolen by three lads in Ukraine, QR code scams in Toronto, and a toaster with a touchscreen that nobody asked for. The Awareness Angle is an independent cybersecurity podcast covering cyber news, data breaches, phishing, social engineering, and security awareness. New episodes every week. Chapters: 00:00 Intro 01:30 Welcome 01:52 ADT Breached Again by ShinyHunters Vishing Attack 07:23 Instructure / Canvas LMS Hit by Another Cyber Attack 13:38 Critical Infrastructure Giant Itron Confirms Cyberattack 17:56 AI Coding Agent Deletes Startup Database in 9 Seconds 25:28 Supply Chain Attack Hits Checkmarx and Bitwarden 28:40 Roblox Account Theft: 610,000 Accounts Stolen 36:56 UK Cyber Security Breaches Survey 2025-26 43:06 Microsoft Teams Helpdesk Impersonation Attacks 52:21 QR Code Scams in Toronto 57:03 Smart Toasters and Unnecessary IoT 1:01:09 Hannah Fry on AI Agents Going Rogue Subscribe to the newsletter at riskycreative.com Our Intro and Outro Song © 16 by Falling Forever https://fallingforever.bandcamp.com/track/16 Licensed under Creative Commons Attribution 4.0 https://creativecommons.org/licenses/by/4.0/

  • April 27 · 59 min

    How Roblox Cheats Led to a Corporate Breach, Warship Tracked by Postcard, Passkeys Replace Passwords

    Roblox cheats at work lead to a full corporate breach. Half a million people's health data listed for sale on Alibaba by the researchers trusted to protect it. A $5 Bluetooth tracker in a postcard tracks a NATO warship for 24 hours. The UK government officially says passkeys should replace passwords. In this episode we break down the Vercel breach, the UK Biobank scandal, a Bluetooth tracker that exposed a $585 million warship, the NCSC's official passkey guidance ahead of World Password Day, plus Rituals Cosmetics, GCHQ's SilentGlass, Claude Desktop's silent browser hooks, a Grafana-branded sextortion scam, and Bitwarden's CLI getting hijacked. Chapters 00:00 Intro 01:18 Vercel Breach: Roblox Cheats to Customer Data Exposure 06:38 Rituals Cosmetics Loyalty Programme Breach 09:46 UK Biobank Health Data Sold on Alibaba 13:41 GCHQ SilentGlass: Blocking Malware Over HDMI 16:25 Claude Desktop Silently Installs Browser Hooks 24:03 Sextortion Scam Disguised as Grafana Alert 29:15 Bitwarden CLI Hijacked in Supply Chain Attack 31:52 $5 Bluetooth Tracker Exposes NATO Warship 35:44 NCSC: Passkeys Should Replace Passwords 42:50 Security Socials: The HR Hot Take 46:08 Security Socials: Spam Caller Rick Astley Script 48:09 Security Socials: iPhone 17 Pro Stolen 51:56 Security Socials: My Cocoon Airplane Privacy 54:19 Security Socials: GPT Image 2 AI Generation 58:57 Outro Subscribe to the newsletter for links to every story we discuss: LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Our Intro and Outro Song © 16 by Falling Forever — Bandcamp: https://fallingforever.bandcamp.com/track/16 — Licence: https://creativecommons.org/licenses/by/4.0/

  • April 20 · 52 min

    Hungarian Passwords, Rockstar Hacked & Booking.com Scams

    Nearly 800 Hungarian government passwords found in breach databases — including one from a colonel in charge of information security who used "FrankLampard". We break down how it happened, why it keeps happening, and what it means for anyone responsible for security culture at work. Also this week: Rockstar Games hacked for the second time in three years through a third-party supplier. Basic-Fit gym breach exposes bank details of around one million members across Europe. Booking.com customers scammed using their own stolen reservation data before the company even told them about the breach. On the news side: Microsoft's biggest ever Patch Tuesday with 165 fixes including an actively exploited SharePoint flaw, France ditching Windows across government, a UK energy company loses £700,000 in a payment redirection attack, Google cracking down on back button hijacking, and an emergency Adobe Acrobat patch for a flaw being quietly exploited since December. Cybersecurity news explained in plain English. No jargon. Just the stories that matter and why they matter to real people. New episodes every week. Subscribe wherever you listen. Spotify Apple Podcasts LinkedIn Newsletter YouTube Instagram TikTok Our Intro and Outro Song © 16 by Falling Forever — https://fallingforever.bandcamp.com/track/16

  • April 13 · 47 min

    Missile Alert Phishing, Meeting Recordings Exposed and You Already Have A QR Code Generator

    This week: attackers are sending fake missile alert emails exploiting real Iran-US-Israel tensions to steal Microsoft credentials via QR code. We also cover a massive leak of sensitive LAPD police documents, an AI model that autonomously finds and exploits thousands of zero-days, and a Windows exploit that went public after a researcher fell out with Microsoft. This week on The Awareness Angle: Hackers steal 7.7TB of sensitive LAPD police documents including officer files, internal affairs investigations, and unredacted witness identities, via a third-party storage system. World Leaks (formerly Hunters International) are behind it. Anthropic's Claude Mythos autonomously discovers and exploits thousands of zero-day flaws across major systems. The same capability that speeds up defence also speeds up attack. We break down what this means for security teams. GrafanaGhost: a vulnerability in the popular monitoring platform Grafana that allows silent data exfiltration via AI prompt injection. Grafana disputes the severity. We give both sides. Fake missile alert emails are landing in inboxes right now, exploiting real Iran-US-Israel tensions. They use QR codes to bypass email filters and redirect victims to a fake Microsoft login page. Urgency is the mechanism. BlueHammer: a Windows local privilege escalation zero-day leaked publicly by a disgruntled researcher after a falling-out with Microsoft's security response team. No patch available. Functional exploit on GitHub. The White House is proposing a $707 million cut to CISA, the agency that coordinates national cyber defence. A third of staff already left in the first months of Trump's second term. Phish of the Week (from Hoxhunt): a WhatsApp/Meta impersonation email targeting business accounts that captures your login credentials and your MFA code in real time. Plus: a North Korean hacker gets caught mid-interview, a job candidate accidentally receives a recording of his interviewers criticising him after he dropped off the call, and TikTok Lite appearing on Android phones after a carrier update. 00:00 Introduction 01:03 Breach of the Week: LAPD Police Documents Stolen and Leaked 03:18 Wynn Resorts - 21,000 Employees Hit by ShinyHunters 05:21 ChipSoft Ransomware Attack Disrupts Dutch Hospitals 06:51 Jones Day Law Firm Confirms Breach - Silent Ransom Group 09:48 Anthropic Project Glasswing: AI Finds Thousands of Zero-Days 13:42 GrafanaGhost: Data Theft via AI Prompt Injection 17:53 Missile Alert Phishing - Fake Civil Defence Emails Steal Microsoft Logins 22:49 BlueHammer: Windows Zero-Day Leaked on GitHub 26:55 White House Proposes $707M Cut to CISA 30:10 Phish of the Week: WhatsApp Meta Impersonation 35:34 Security Socials Subscribe to the newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreative YouTube: https://www.youtube.com/@riskycreative Our Intro and Outro Song © 16 by Falling Forever Bandcamp: https://fallingforever.bandcamp.com/track/16 Licence: https://creativecommons.org/licenses/by/4.0/

  • April 7 · 1 hr 13 min

    FBI Wiretap System Hacked, White House App Security Concerns, and LinkedIn's Secret Browser Scans

    Chinese hackers just broke into the system the FBI uses to track its own surveillance targets. The White House released an app that security researchers took apart and didn't like what they found. LinkedIn has been secretly scanning your browser extensions without telling you. And a Carnegie Mellon professor says app privacy labels are the nutrition labels of the internet — which tells you everything. This week on The Awareness Angle: cybersecurity news explained in plain English, no jargon, no technical degree required. Anthony and Luke break down the biggest cyber stories of the week including a major FBI data breach, WhatsApp malware targeting Windows users, Google Drive's new ransomware protection, Apple blocking ClickFix attacks, and why AI-generated slop is quietly making all of us easier to scam. New episode every week. Subscribe so you don't miss one. Chapters 00:00 Intro 01:40 Breach of the Week: Chinese Hackers Breach the FBI's Wiretap System 07:15 Trivy Supply Chain Attack Hits the European Commission 11:45 The White House App Security Concerns Explained 18:15 Apple Blocks ClickFix Paste Attacks in macOS 23:35 App Privacy Labels vs Food Nutrition Labels 28:40 Google Drive Ransomware Detection Now Available 35:51 LinkedIn Secretly Scanning Your Browser Extensions 41:11 WhatsApp Used to Deliver Malware to Windows PCs 44:54 Phish of the Week: QR Code Salary Scam and Device Code Phishing 50:42 SMS Delivery Scam in the Wild 57:06 Sloppypasta and Why AI Content Is a Security Risk 1:02:04 Artemis II Has Two Broken Instances of Outlook in Space 1:03:54 Artemis II is Running Microsoft 365 in Space 1:04:43 Artemis II Astronaut Enters PIN on Live Stream 1:06:43 Apple Passwords App Ad 1:09:58 Nice Looking TikTok Video 📩 New episode every week. Get the newsletter at riskycreative.com 🌐 Website: https://www.riskycreative.com 🎙️ Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 💼 LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ 🎵 TikTok: @infosecant 📸 Instagram: https://www.instagram.com/riskycreative ▶️ YouTube: https://www.youtube.com/@riskycreative 🎵 Intro/outro music: "16" by Falling Forever -- Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). Track: https://fallingforever.bandcamp.com/track/16 License: https://creativecommons.org/licenses/by/4.0/

  • March 30 · 1 hr 6 min

    Ajax Season Tickets Stolen, OpenAI Kills Sora & Apple's Age Verification Explained

    Episode 81 of The Awareness Angle. This week: a hack at Ajax Amsterdam let attackers steal season tickets and quietly lift stadium bans. A security scanner got compromised and was used to backdoor LiteLLM, a tool downloaded 3.4 million times a day. OpenAI shuts down Sora and Disney walks away from its $1 billion deal. Meta launches new AI anti-scam features across WhatsApp, Facebook and Messenger. And Lloyds Banking reveals the full picture of its March 12 app glitch, where nearly half a million customers briefly saw each other's transactions. We've also got Apple's new age verification rollout for UK iPhone users, a phishing campaign targeting TikTok for Business accounts that can bypass 2FA, and the ChatGPT fake invoice phish doing the rounds. In the Security Socials: a great child online safety poster worth sharing with parents, a free phishing game for kids called The Phisherman, a viral deepfake detection trick, a personalised smishing campaign in France, and what happens when a French soldier goes for a Strava run on a ship. Chapters 00:00 Intro01:31 Breach of the Week: Ajax Amsterdam04:37 Meta anti-scam tools10:08 OpenAI Sora and Disney14:23 LiteLLM supply chain attack21:43 Apple age verification UK26:33 TikTok for Business phishing32:26 Lloyds Banking app glitch37:26 Phish of the Week: ChatGPT fake invoice42:57 Security Socials48:32 Anthony's Security Social1:00:47 Luke's Security Social Subscribe to the newsletter at riskycreative.com 🌐 Website: https://riskycreative.com 🎧 Spotify: https://open.spotify.com/show/theawarenessangle 🍎 Apple Podcasts: https://podcasts.apple.com/podcast/the-awareness-angle 💼 LinkedIn: https://www.linkedin.com/company/risky-creative 🎵 TikTok: https://www.tiktok.com/@theawarenessangle 📸 Instagram: https://www.instagram.com/theawarenessangle ▶️ YouTube: https://www.youtube.com/@theawarenessangle Our Intro and Outro Song © 16 by Falling Foreverhttps://fallingforever.bandcamp.com/track/16 License https://creativecommons.org/licenses/by/4.0/

  • March 23 · 56 min

    Chrome Malware, 8 Million Tips Exposed & Japan Legalises Hacking Back

    This week's human cybersecurity news . A US general leaves classified military documents on a train, over 8 million anonymous crime tips are exposed in a major data breach, and a Chrome extension with a million users and Google's Featured badge was silently hijacking shopping commissions for months. This week's cyber news explained in plain English. Also covered this week: the FBI seizes websites belonging to Handala, the Iran-linked hacker group behind the devastating Stryker wiper attack that wiped 200,000 devices and shut down hospitals. Companies House exposes UK company directors' home addresses, email addresses and dates of birth for five months, through a bug that required nothing more than pressing the browser back button. A new Android malware called Perseus hides inside IPTV streaming apps and targets your notes app to steal passwords, financial details and account recovery phrases. And Japan officially legalises offensive cyber operations, or "proactive cyber defence", from October 2026, a major shift away from its post-war defensive-only stance. This week's phishing example: a convincing Emirates loyalty reward scam sent through legitimate Eventbrite infrastructure to bypass email security filters, and how to spot it. We're The Awareness Angle, a weekly cybersecurity podcast and newsletter that explains the biggest cyber threats, data breaches and online scams in plain English, with a focus on the human side of security. No jargon. No technical background needed. New episode every week. Get the newsletter at riskycreative.com Full episode on YouTube: https://youtu.be/9n-ewD0zZuU Chapters 0:00 Intro 1:47 Breach of the Week: US General leaves classified maps on a train 7:23 Crime Stoppers data breach: 8 million anonymous tips exposed 12:22 Android malware Perseus: hiding in streaming apps, targeting your notes 17:29 Handala update: FBI seizes hacker websites after Stryker attack 20:58 Marquis ransomware: 672,000 bank customers' data stolen 26:37 Companies House: five months of exposed director data, fixed with a back button 31:34 Chrome extension malware: Save Image as Type removed after stealing commissions 38:18 Phish of the Week: Emirates loyalty scam via Eventbrite 43:05 SANS Security Awareness Summit 2026: call for presentations 45:18 Topics: Idris Elba's wax model unlocks his iPhone 46:30 Pete Tong reads out a URL like it's 1995 48:40 Tinder wants to scan your camera roll with AI 50:07 Japan legalises hacking back Find Us Website Spotify Apple Podcasts LinkedIn TikTok Instagram YouTube Music Intro/outro music: "16" by Falling Forever, licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). Track: https://fallingforever.bandcamp.com/track/16 License: https://creativecommons.org/licenses/by/4.0/