Smashing Security
Graham Cluley
0
Smashing Security is a weekly podcast that covers stories from the world of hacking, cybersecurity, and rogue AI. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it delivers tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps with sharp insight and humor. The podcast has won multiple awards for best cybersecurity podcast and has had over ten million downloads. New episodes are released every Wednesday.
Épisodes
-
How websites are tracking you with silence 09.09.2026 45minWhen a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web.Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated."All this and more in episode 484 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.EPISODE LINKS:Hackers demand $2.3M in ransom after breaching Berlin government network - Anadolu.Deux suspects interpellés dans le cadre des enquêtes ouvertes après le piratage du fisc - France Info.Hackers are stealing Claude tokens from subscribers - TechCrunch.AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones - The Register.AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting - Matt Callaghan’s blog.Audio Fingerprinting: What It Is + How It Works with Web API - Fingerprint.Communicating Under Pressure: Best Practices for Service Providers - CISA.World Stone Skimming Championships.Mind games and a ‘toss master’: world stone skimming contest returns to Scotland after cheating scandal - The Guardian.World Stone Skimming Championships - Every Toss 2025 - YouTube.”The Pirates’ Code: Laws and Life Aboard Ship” by Rebecca Simon - Waterstones.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:ThreatLocker - Book a demo today and start securing your organisation.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Intruder - The depth of a manual pentest, on-demand. Start an AI pentest in minutes - 25% off your first pentest for Smashing Security listeners.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This AI helps thieves steal your iPhone 02.09.2026 44minYou've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone.Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open?All this and more in episode 483 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.EPISODE LINKS:Hacker leaks GTA VI footage to push a crypto token before pulling off a $270,000 cash-out - Coindesk.ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions - The Hacker News.FulcrumSec claims Manchester Airports hack, theft of 86 GB of data - Bleeping Computer.Mugged for my phone, then locked out of my life - The Times.Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain - SOCRadar.AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes - Bleeping Computer.Investigating three real-world incidents in our cybersecurity evaluations - Anthropic.The Hugging Face incident and the road ahead - OpenAI.Irregular says ‘human oversight’ responsible for AI sandbox escape incidents - CyberScoop.Control. Ownership. Perspective - Ciaran Martin.Steno: Highly-Secure AI Notetaker for Government & Defence - Steno.Inside the Factory - BBC.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:ThreatLocker - Book a demo today and start securing your organisation.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Intruder - The depth of a manual pentest, on-demand. Start an AI pentest in minutes - 25% off your first pentest for Smashing Security listeners.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This hacker leaked GTA 6 - and launched their own cryptocurrency 26.08.2026 50minA hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club...Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet connection.All this and more in episode 482 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.EPISODE LINKS:Iranian hackers shut down UK power plant - The Telegraph.Ransomware crook poses as recovery firm to steal payments from fellow extortionists - The Register.The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile - Zimperium.Technical forensic research and provenance breakdown of the latest August 2026 GTA 6 gameplay leaks and map files. - GitHub.Everything we know about Cyberleek and his GTA VI build - Reddit.Who needs a laptop to hack when you have a Firestick? - Smashing Security.Evading Residential Proxy Networks: Protecting Your Devices from Becoming a Tool for Criminals - FBI.Busted! Rogue VPN provider who co-opted millions into cybercrime - Paul Ducklin.Disrupting the World's Largest Residential Proxy Network - Google Cloud Blog.Google’s Continued Disruption of Malicious Residential Proxy Networks - Google Cloud Blog.TimeGuessr.Scientific Curiosity by Cyril Aydon - Waterstones.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:ThreatLocker - Book a demo today and start securing your organisation.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Black Kite - Read Black Kite's 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
Never say this to a robot dog 19.08.2026 45minAt Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment?Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of cybersecurity.All this and more in episode 481 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Jenny Radcliffe.EPISODE LINKS:Burnham exchanged messages with person posing as Trump's chief of staff - BBC News.New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges - Bleeping Computer.SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers - The Hacker News.macOS ‘Screen Sharing’ flaw exploited for crypto-mining - Hot for Security.Kinetic Prompt Injection: Agent Compromise With a Physical Blast - Greptalks.Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius - YouTube.More Than 200 Golden Mozart Statuettes Stolen From Salzburg Months After Famed Composer’s 270th Birthday - Smithsonian Magazine.An Art Installation of More Than 100 Wagner Figurines Outside a German Theater Has Mysteriously Disappeared - Artnet News.Ray Alan - Wikipedia.Ray Alan with "Lord Charles" - World's Greatest Ventriloquist - YouTube.Educating Archie - YouTube.Peter Brough - Wikipedia.No. 10: Full Confidence - A Game of Political Survival.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:ThreatLocker - Book a demo today and start securing your organisation.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Black Kite - Read Black Kite's 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This is the AI service you should never sign up to 12.08.2026 45minWould you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters...Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation.All this and more in episode 480 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.EPISODE LINKS:US cloud 'kill switch' is as dangerous as ransomware, European businesses fear - IT Pro.Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M - Decrypt.Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison - US Department of Justice.Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt - The Hacker News.Free tokens for sale: How fake signups drive AI fraud - Okta.Post by Rory Cellan-Jones - Bluesky.Inside Greatness: Telegram-Distributed M365 AiTM PhaaS - ZeroBEC.Tailscale.RustDesk.League of the Lexicon - Two Brothers Games.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
How a fake police officer nearly stole Graham's cryptocurrency 05.08.2026 59minGraham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet.Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group.And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education - sending an unusually polite ransom demand.All this and more in episode 479 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.EPISODE LINKS:Cryptocurrency mailing list compromised - Tweet by Trezor.Users’ seemingly private conversations with Anthropic’s Claude showed up in Google search results - Fortune.Sweeping cyberattack on water systems in multiple states has US officials on edge - CNN.Minnesota not Iran to blame for state's water issues, says Trump - BBC News.Google pauses AI satellite images, after fears of deepfakes in the sky - NPR.CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Microsoft Security Blog.DNS Poisoning Tactics Expand to Hospitality Wi-Fi - ReliaQuest.Hackers steal sensitive data from UK Department for Education and police - The Guardian.University of Arts London on Securing Creativity Against Cyber Threats - Infosecurity Magazine.7 Things About Doctor Who I Learned From “When I Say Run, Run” - The Doctor Who Companion.What Stanley didn't say - The Guardian.Adrian Rigelsford - Wikipedia.Black Mesa: Re-visit the world that started the Half-Life continuum - Crowbar Collective.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This job interview could destroy your company 29.07.2026 58minYou've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone.Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed.All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.EPISODE LINKS:OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know - Hot for Security.Post by Graeme Bell - Linkedin.HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels - Group-IB.Ransom gang targets Dutch ice arena Thialf in cyberattack - Cybernews.No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE - Tokay0.DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews - SOCRadar.H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion - TRM Labs.2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft - UC San Diego Today.2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft - YouTube.Karr Security.Ann Droid - BBC iPlayer.North Leigh Roman Villa - English Heritage.Uffington White Horse - Wikipedia.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
How 14 orders of chicken McNuggets helped nail a suspected Russian hacker 22.07.2026 50minA Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets.Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models.All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.EPISODE LINKS:Bengaluru triple murder: Accused allegedly used AI chatbot to plan killings, police say - The News Minute.Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days - Bleeping Computer.DO NOT BUY: LG’s Spyware TVs, Monitors, and Wiretapping Concerns - YouTube.New Russia-affiliated actor Void Blizzard targets critical sectors for espionage - Microsoft Security Blog.Russia Advises Citizens Wanted in U.S. Against Visiting Thailand - The Moscow Times.Alleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show - Reuters.Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links - Ctrl-Alt-Intel.Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius - 404 Media."Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack - Unit 42.Black Is The Color Of My Voice trailer - YouTube.Black Is The Color Of My Voice - Official Site - Black is the Colour of my Voice.Avatar: The Last Airbender (2007) - Netflix.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
Remote-control rickshaws and rogue book marketers 15.07.2026 38minAn app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game...All this and more in episode 476 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.EPISODE LINKS:The ransomware negotiator who was working for the other side - Hot for Security.LastPass, Bitwarden users targeted with fake security alerts - Bleeping Computer.German firm files for insolvency, blames cybercrims who shut down production for 6 weeks - The Register.BAT-BMS App: How A Chinese App Is Being Used To Hack E-Rickshaws All Over India; Viral Videos Show Drivers Crying Over Lost Earnings - Free Press Journal.Tirri control prank: Indians use China app to shut down e-rickshaws - The Print.Geoff describes his interactions with a book marketing scam - Linkedin.Smart Plugs - Tapo.Worst Patio Ever! Extreme ASMR Pressure Washing - YouTube.20 Years of Cracked Mud Covered This Massive Rug - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
JadePuffer - the AI that ran a ransomware attack all by itself 08.07.2026 46minA 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity?Also, Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year.All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Zoë Rose.EPISODE LINKS:Politician who investigated spyware abuses had his phone hacked with Pegasus spyware - TechCrunch.Hackers breached DHS information-sharing network, people familiar say - Nextgov.Hackers Use Fake FIFA World Cup 2026 T-Shirt Offers to Spread Voidrift Malware - Hackread.Japanese teen arrested for cyberattack that unsubscribed over 46,000 anime accounts - The Straits Times.Police arrest high school student over cyberattack on net cafe operator - The Japan Times.Japanese teens arrested for using AI to create illegal phone contracts - The Peninsula Qatar.JADEPUFFER: Agentic ransomware for automated database extortion - Sysdig.Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses - 404 Media.Two people arrested in apparent marriage proposal atop Empire State Building - The Guardian.Skywalkers: A Love Story - Netflix.Thermomix - Vorwerk.Operation Safe Escape.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Arctic Wolf - See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.NordLayer - the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
Polymarket can predict the future. So how did it miss this hack? 01.07.2026 42minPolymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer.Meanwhile, "FortiBleed" sees 75,000 Fortinet firewalls thrown wide open - and the real damage is going to roll on for years.All this and more in episode 474 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Quentyn Taylor.EPISODE LINKS:Danish Police Raided Self-Described Privacy Activist. PM Lives at a Secret Address - State of Surveillance.Hospital probe after 40 staff access crocodile boy's medical records - Cybernews.Third Defendant Sentenced To Prison For Hacking Fantasy Sports And Betting Website - US Dept of Justice.Someone allegedly used a hairdryer to rig Polymarket weather bets - Engadget.Tweet by Polymarket Traders - XCancel.Polymarket says hackers stole users' funds - TechCrunch.Operation Cloud Hopper: China-based Hackers Target Managed Service Providers - SecurityWeek.The Full Story of the Stunning RSA Hack Can Finally Be Told - WIRED.Polymarket points to third-party login tool after users report account breaches - Coindesk.Polymarket Admin Wallet Exploited on Polygon, Says ZachXBT - CryptoPotato.Polymarket reportedly paid creators to post deceptive videos about fake bets - TechCrunch.‘Unbelievable how accurate’: How paid influencers hype Polymarket’s odds - POLITICO.Polymarket's $345 million Iran peace bet is stuck because nobody can agree on what "permanent" means - TNW.Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways - National Cyber Security Centre.Analysis of Reported Credential Compromise of FortiGate Devices - Fortinet Blog.FortiBleed - Free FortiGate Exposure Checker - SOCRadar.The Boys of Dungeon Lane - Paul McCartney.A closer listen to Paul McCartney's new album 'The Boys of Dungeon Lane' - YouTube.The Summer Portraits - Ludovico Einaudi.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
How a hacker could have Rickrolled the entire World Cup 24.06.2026 1hA polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and TikTok, with a two-week ultimatum to turn themselves in... or else.Meanwhile, a security researcher called Bob DaHacker got her hands on the live broadcast controls for every match of the 2026 FIFA World Cup. She could have Rickrolled the entire planet, but actually spent days trying to find anyone at FIFA who would pick up the phone.Plus! Don't miss our featured interview with Black Kite's Jeffrey Wheatman exploring ransomware and extortion attacks across Europe.All this and more in episode 473 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.EPISODE LINKS:Suspected cyberattack triggers false emergency alerts across parts of Brazil - The Record.Gizmodo readers hit with ClickFix malware prompts after account compromise - The Register.Two men plead guilty over £39m Transport for London cyber attack - BBC News.Helpdesk scammers are making house calls to make their lies feel more real - The Register.Dutch cops’ shame games nets 74 wanted fraudsters - The Register.Omgebrachte vrouw (80) in Amsterdam vermoedelijk slachtoffer van nepagenten - NU.Mr Benn - Wikipedia.I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID - Bobdahacker.Bug in FIFA World Cup internal system gave anyone ability to modify TV stream - TechCrunch.Iceberger - Draw an iceberg and see how it will float.Fallout: London - GOG.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Black Kite - Read Black Kite's 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe.Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
AI gets hacked, and BitLocker gets bypassed 17.06.2026 1h 12minWhat if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told.Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious.Plus don't miss our featured interview with Son Nguyen Kim of Proton Pass, who explains why plugging AI agents into your email and calendar without thinking twice is rather like hiring a new employee with the keys to everything - and skipping the background check.All this and more in episode 472 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.EPISODE LINKS:ShinyHunters claims 61M Sysco records - Cybernews.Derbyshire police officer under investigation for using AI to create evidence - Derbyshire Times.Maine forced to take down data breach portal after fake notices filed with authorities - Hot for Security.A Fake Bug Report Hijacks Your AI Coding Agent - and Nothing Catches It. - Tenet Security.Agentjacking: a fake bug report hijacks AI coding agents - TNW.When anti-virus goes rogue - A trifecta of Defender zero-days - SolCyber.BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber.Microsoft versus Full Disclosure: The ongoing Nightmare Eclipse saga - SolCyber.BitLocker, Defender, zero-days, and bragging rights: More MS nightmares - SolCyber.Inside the FBI’s Kinetic Cyber Range - FBI.Inside the FBI's Kinetic Cyber Range - YouTube.Computer worm strikes International Space Station - Graham Cluley.Raspberry Pi Zero W - Raspberry Pi.There’s still life in old technology.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This AI worm just rewrote its own rules 10.06.2026 46minResearchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack.Meanwhile, Meta's shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people's Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email address - and the AI will eventually agree.All this and more in episode 471 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.EPISODE LINKS:Emmys data leak: update exposes access to award submissions - Cybernews.A $1,000 AI agent found 21 zero-days in FFmpeg, some 23 years old - Martin Cid Magazine.Hackers steal $1.7M condom shipment - Cybernews.AI Agents Enable Adaptive Computer Worms - ArXiv.21 Zero-Days in FFmpeg - Depthfirst.Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot - ~this week in security~.Hackers trick Meta AI support bot to infiltrate Obama White House Instagram account - The Guardian.Look-In Star Portrait Challenge - Monkeon.Final Fantasy VII Remake - Square Enix.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This AI security flaw might be impossible to fix 03.06.2026 57minA website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who responded.Meanwhile, a paper from Cornell suggests that prompt injection - the technique malicious actors use to trick AI agents into doing things they really shouldn't - may be fundamentally unsolvable. Which is err... awkward, because everyone is rushing to plug AI agents into their email, files, and corporate networks.Plus don't miss our featured interview with Andrea Sivieri of CoreView, who tells us how hackers can lock your entire organisation out of its Microsoft 365 environment... without having to trick you into running a single piece of malicious code or handing over a password.All this and more in episode 470 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Tanya Janca.EPISODE LINKS:Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked - 404 Media.Canon Printer Vulnerability Leaks Plaintext Credentials - Praetorian.Password manager Dashlane says hackers stole some customers' password vaults - TechCrunch.UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us - TechCrunch.AI Agents May Always Fall for Prompt Injections - ArXiv.MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure - Cloud Security Alliance.From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness - ArXiv.Design details that feel like magic - Design Spells.Singing lessons.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
What your Oura ring won't tell you 27.05.2026 53minCISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile.Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted - and when one journalist asked the company how often it hands user data to law enforcement, the answer was quite telling.Plus don't miss our featured interview with OPSWAT's Benny Czarny about his new book "Cybersecurity Upside Down."All this and more in episode 469 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lesley Carhart.EPISODE LINKS:Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet - US Dept of Justice.700+ education and tech websites hijacked in huge ClickFix malware campaign - Malwarebytes.Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West - Including Islamophobic ‘Pig Head’ Attacks in Paris - OCCRP.Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs On Security.US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs - TechCrunch.Oura says it gets government demands for user data. Will it share how many? - This Week In Security.Privacy and transparency of fitness tracking devices - Whyli.Upfest - Europe’s largest street-art festival.Magnets Are Bad For Hardware Again - Hackaday.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
High-speed train hacks and homicidal lawnmowers 20.05.2026 55minA 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year.Meanwhile, owners of $4,000 robot lawnmowers are discovering that their gadget can be hijacked over the internet, redirected at journalists who foolishly lie down in front of it, and used to harvest Wi-Fi passwords, email addresses, and GPS coordinates. Change the default password? Sure - until the next firmware update silently resets it back.Plus - don't miss our featured interview with XBOW's Brendan Dolan-Gavitt about how AI is transforming penetration testing.All this and more in episode 468 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.EPISODE LINKS:Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom - TechCrunch.Man accused of stealing Beyoncé’s unreleased music takes guilty plea - ABC News.Shai-Hulud code drop: Open season for supply chain attacks- ReversingLabs.Student hacked Taiwan high-speed rail to trigger emergency brakes - BleepingComputer.Polish teen derails tram after hacking train network - The Register.The Cheap Radio Hack That Disrupted Poland's Railway System - WIRED.The man with an army of Yarbo robot lawn mowers - The Verge.Ever been run over by a robot? I have - for science! - TikTok.RD280UA 28” WQXGA BenQ Programming Monitor with Backlight and Flexible Arm - BenQ.Kai Shun DM-0708 combination sharpening stone, grain 300/1000 - Knives and Tools.AI-Assisted ICS Attack on a Water Utility - Dragos.Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - Google Cloud Blog.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
How ShinyHunters hacked the world's biggest universities 13.05.2026 1h 4minWelcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap.Meanwhile, a famous finance expert's face has been showing up on Facebook adverts promising hot stock tips and exclusive WhatsApp investment groups. Spoiler: it isn't him, the tips aren't real, and you're about to be scammed.Plus we chat to Mike Nichols of Elastic, about how the SOC isn't dying, attackers and defenders are both deploying AI agents, and how the real security crisis is no longer human users - it's the bots acting on their behalf.All this and more in episode 467 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.EPISODE LINKS:ICO fines South Staffordshire £963K over 2022 breach - The Register.US bank reports itself after AI customer data mishap - The Register.Hackers abuse Google ads, Claude.ai chats to push Mac malware - Bleeping Computer.Canvas hack: What we know about apparent cyberattack that impacted thousands of schools - CNN.Canvas hack: Company pays criminals to delete students' stolen data - BBC News.Post by @amosmagliocco.bsky.social - Bluesky.Post by @sethcotlar.bsky.social - Bluesky.The Architecture of Deception: How a $187 Million Fraud Ecosystem Exploits Trust Across Australia and the United States - Group IB.The Fake Nobel that Duped the Romanian Academy - Scena9.A (Very) Short History of Life On Earth by Henry Gee - Waterstones.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence.CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
Meta sees everything, Copy Fail, and a deepfake gets hired 06.05.2026 1h 2minMeta's smart glasses promise privacy "designed for you" - but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them.Meanwhile, the IT press is in a frenzy over a new Linux bug called "Copy Fail" - complete with logo, dedicated website, and a marketing-friendly name. But is it really the disaster everyone's making it out to be?And in our featured interview, Jake Moore of ESET explains how he tricked a company into offering his deepfake clone a job - after a perfectly normal-looking video interview.All this and more in episode 466 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Paul Ducklin.EPISODE LINKS:Anti-DDoS Firm Heaped Attacks on Brazilian ISPs - Krebs On Security.Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha - Bleeping Computer.Trellix confirms data breach after hack of 'a portion' of its source code - TechRadar.Meta’s AI Smart Glasses and Data Privacy Concerns: Workers Say “We See Everything” - Svd.Dispute over fate of Kenyan workers who saw Meta AI glasses films - BBC News.Copy Fail - CVE-2026-31431.Copy Fail: Hype versus reality - the full story - SolCyber.Flight into Danger: The Original Airplane! - BBC Sounds.The Luton writer behind the original Airplane! - BBC News.Code Dependent by Madhumita Murgia - Pan Macmillan.The Code Book - Simon Singh.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.Action1 - Keep your systems safe (and your sanity intact) with the patch management platform that just works. The best part? Your first 200 endpoints are free, forever, with no functional limits.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy -
This developer wanted to cheat at Roblox. It cost millions 29.04.2026 1h 4minA developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of organisations. All for some free in-game currency.Meanwhile, there's a 1980s phone protocol called SS7 that lets shadowy surveillance companies track anyone, anywhere, via their mobile phone. Governments know about it. Telecoms know about it. Nobody's fixing it.All this and more in episode 465 of the "Smashing Security" podcast with cybersecurity keynote speaker and industry veteran Graham Cluley, joined this week by special guest James Ball.Plus! Don't miss our featured interview with Rob Edmondson of CoreView, discussing how to lock down Microsoft 365 before it's too late.EPISODE LINKS:Burglar alarm biz gets burgled, ShinyHunters pursues ransom - The Register.Ransomware negotiator pleads guilty after leaking victims' insurance details to 'BlackCat' hackers - Tom’s Hardware.Grok tells researchers pretending to be delusional ‘drive an iron nail through the mirror while reciting Psalm 91 backwards’ - The Guardian.Vercel April 2026 security incident - Vercel.App host Vercel says it was hacked and customer data stolen - TechCrunch.Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials - Hacker News.Sorry for the Nazi spam from my Twitter account - Graham Cluley.Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors - Citizen Lab.Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say - TechCrunch.The rapid rise of phone surveillance firms - The Bureau of Investigative Journalism.Please shut up about your Spotify Wrapped - The New World.Think For Yourself - Beatles Song Identification Game.Nodes: Free Connection Puzzle & Vertex Game Alternative.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy
Populaire dans
Ce podcast figure aussi dans les classements de podcasts de ces pays.