PodcastsKomedieSmashing Security

Smashing Security

Graham Cluley
Smashing Security
Nieuwste aflevering

475 afleveringen

  • Smashing Security

    How a hacker could have Rickrolled the entire World Cup

    24-06-2026 | 1 u.
    A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and TikTok, with a two-week ultimatum to turn themselves in... or else.
    Meanwhile, a security researcher called Bob DaHacker got her hands on the live broadcast controls for every match of the 2026 FIFA World Cup. She could have Rickrolled the entire planet, but actually spent days trying to find anyone at FIFA who would pick up the phone.
    Plus! Don't miss our featured interview with Black Kite's Jeffrey Wheatman exploring ransomware and extortion attacks across Europe.
    All this and more in episode 473 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

    EPISODE LINKS:

    Suspected cyberattack triggers false emergency alerts across parts of Brazil - The Record.
    Gizmodo readers hit with ClickFix malware prompts after account compromise - The Register.
    Two men plead guilty over £39m Transport for London cyber attack - BBC News.
    Helpdesk scammers are making house calls to make their lies feel more real - The Register.
    Dutch cops’ shame games nets 74 wanted fraudsters - The Register.
    Omgebrachte vrouw (80) in Amsterdam vermoedelijk slachtoffer van nepagenten - NU.
    Mr Benn - Wikipedia.
    I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID - Bobdahacker.
    Bug in FIFA World Cup internal system gave anyone ability to modify TV stream - TechCrunch.
    Iceberger - Draw an iceberg and see how it will float.
    Fallout: London - GOG.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Black Kite - Read Black Kite's 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe.
    Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    AI gets hacked, and BitLocker gets bypassed

    17-06-2026 | 1 u. 12 Min.
    What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told.
    Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious.
    Plus don't miss our featured interview with Son Nguyen Kim of Proton Pass, who explains why plugging AI agents into your email and calendar without thinking twice is rather like hiring a new employee with the keys to everything - and skipping the background check.
    All this and more in episode 472 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.

    EPISODE LINKS:

    ShinyHunters claims 61M Sysco records - Cybernews.
    Derbyshire police officer under investigation for using AI to create evidence - Derbyshire Times.
    Maine forced to take down data breach portal after fake notices filed with authorities - Hot for Security.
    A Fake Bug Report Hijacks Your AI Coding Agent - and Nothing Catches It. - Tenet Security.
    Agentjacking: a fake bug report hijacks AI coding agents - TNW.
    When anti-virus goes rogue - A trifecta of Defender zero-days - SolCyber.
    BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber.
    Microsoft versus Full Disclosure: The ongoing Nightmare Eclipse saga - SolCyber.
    BitLocker, Defender, zero-days, and bragging rights: More MS nightmares - SolCyber.
    Inside the FBI’s Kinetic Cyber Range - FBI.
    Inside the FBI's Kinetic Cyber Range - YouTube.
    Computer worm strikes International Space Station - Graham Cluley.
    Raspberry Pi Zero W - Raspberry Pi.
    There’s still life in old technology.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    This AI worm just rewrote its own rules

    10-06-2026 | 46 Min.
    Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack.
    Meanwhile, Meta's shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people's Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email address - and the AI will eventually agree.
    All this and more in episode 471 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.

    EPISODE LINKS:

    Emmys data leak: update exposes access to award submissions - Cybernews.
    A $1,000 AI agent found 21 zero-days in FFmpeg, some 23 years old - Martin Cid Magazine.
    Hackers steal $1.7M condom shipment​ - Cybernews.
    AI Agents Enable Adaptive Computer Worms - ArXiv.
    21 Zero-Days in FFmpeg - Depthfirst.
    Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot - ~this week in security~.
    Hackers trick Meta AI support bot to infiltrate Obama White House Instagram account - The Guardian.
    Look-In Star Portrait Challenge - Monkeon.
    Final Fantasy VII Remake - Square Enix.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    This AI security flaw might be impossible to fix

    03-06-2026 | 57 Min.
    A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who responded.
    Meanwhile, a paper from Cornell suggests that prompt injection - the technique malicious actors use to trick AI agents into doing things they really shouldn't - may be fundamentally unsolvable. Which is err... awkward, because everyone is rushing to plug AI agents into their email, files, and corporate networks.
    Plus don't miss our featured interview with Andrea Sivieri of CoreView, who tells us how hackers can lock your entire organisation out of its Microsoft 365 environment... without having to trick you into running a single piece of malicious code or handing over a password.
    All this and more in episode 470 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Tanya Janca.

    EPISODE LINKS:
    Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked - 404 Media.
    Canon Printer Vulnerability Leaks Plaintext Credentials - Praetorian.
    Password manager Dashlane says hackers stole some customers' password vaults - TechCrunch.
    UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us - TechCrunch.
    AI Agents May Always Fall for Prompt Injections - ArXiv.
    MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure - Cloud Security Alliance.
    From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness - ArXiv.
    Design details that feel like magic - Design Spells.
    Singing lessons.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.
    ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    What your Oura ring won't tell you

    27-05-2026 | 53 Min.
    CISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile.
    Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted - and when one journalist asked the company how often it hands user data to law enforcement, the answer was quite telling.
    Plus don't miss our featured interview with OPSWAT's Benny Czarny about his new book "Cybersecurity Upside Down."
    All this and more in episode 469 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lesley Carhart.

    EPISODE LINKS:

    Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet - US Dept of Justice.
    700+ education and tech websites hijacked in huge ClickFix malware campaign - Malwarebytes.
    Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West - Including Islamophobic ‘Pig Head’ Attacks in Paris - OCCRP.
    Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs On Security.
    US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs - TechCrunch.
    Oura says it gets government demands for user data. Will it share how many? - This Week In Security.
    Privacy and transparency of fitness tracking devices - Whyli.
    Upfest - Europe’s largest street-art festival.
    Magnets Are Bad For Hardware Again - Hackaday.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
Meer Komedie podcasts
Over Smashing Security
Stories from the world of hacking, cybersecurity, and rogue AI.Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.New episodes released at 7pm EST every Wednesday (midnight UK).
Podcast website

Luister naar Smashing Security, Zo, Opgelost en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies