Sign in
Technology
News
Graham Cluley & Carole Theriault
A helpful and hilarious take on the week's tech SNAFUs.
Computer security industry veterans Graham Cluley and Carole Theriault chat with guests about cybercrime, hacking, and online privacy. It's not your typical cybersecurity podcast...
Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Rory Cellan-Jones.
Follow the podcast on Twitter at @smashinsecurity, and subscribe for free in your favourite podcast app. New episodes released at 7pm EST every Wednesday (midnight UK).
This podcast uses the following third-party services for analysis:
OP3 - https://op3.dev/privacy
Twitter turmoil, AI animal chatters, and metaverse at work
Twitter has a new chief twit in the form of Elon Musk and he's causing problems, scientists say artificial intelligence may help us communicate with animals, and is the office of the future set in the metaverse?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Warning: This podcast may contain nuts, adult themes, dolphin noises, and rude language.Episode links:Twitter employees are sleeping on the office floor to meet Elon Musk’s deadlines - The Verge.Elon Musk shows what being Chief Twit is all about across weird weekend - The Register.Pranksters pretending to be laid-off Twitter employees leave San Francisco HQ - YouTube.Twitter Limits Content-Enforcement Work as US Election Looms - Bloomberg.Twitter’s Yoel Roth comments on the firm’s trust and safety staff having their access to moderation and enforcement tools frozen - Twitter. Paul Pelosi Conspiracy Theory Trends on Twitter After Elon Musk Pushes It - Rolling Stone.Yoel Roth describes how Twitter will warn users of misleading information - Twitter.Yoel Roth describes “surge in hateful conduct on Twitter” - Twitter.The Demise of Digg: How an Online Giant Lost Control of the Digital Crowd - Harvard.Follow Graham on Mastodon.How tech is helping us talk to animals - Vox.“The Sounds of Life: How Digital Technology Is Bringing Us Closer to the Worlds of Animals and Plants” - Book by Karen Bakker.Project CETI - The Cetacean Translation Initiative. Not to be mixed-up with Project SETI.The Dark Side Of VR - The Intercept. <a...
55:1003/11/2022
Slushygate, sextortion, and nano-targeting
What is slushygate and how does it link to sextortion in the States? What is the most impersonated brand when it comes to delivering phishing emails? And what the flip is nano-targeting?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by fan favourite Maria Varmazis.Warning: This podcast may contain nuts, adult themes, and rude language.No contortionists were hurt during the making of this episode.Episode links:Memorandum of sentencing of Bryan Wilson - United States District Court Western District Court of Kentucky at Louisville.Accurint for Law Enforcement - LexisNexis.LexisNexis illegally collected and sold people's personal data, lawsuit alleges - CBS News.Ex-cop abused police tool in Snapshot sextortion plot that stole sexually explicit photos and videos - Bitdefender.Congress should consider enhancing protections around scores used to rank consumers (PDF) - Government Accountability Office. Online Shoppers Beware: Scammers Most Likely to Impersonate DHL - Check Point.Why Am I Seeing That Political Ad? Check Your ‘Trump Resistance’ Score - New York Times.I Got Access to My Secret Consumer Score. Now You Can Get Yours, Too - New York Times.Mixed Idioms.Apollo Remastered.Cosmic Background.Death of an Artist - Pushkin podcasts.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – the SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted
52:2727/10/2022
The Virgin trains swindler, cyber clowns, and AirTag election debacle
Someone's election-fiddling is uncovered with an Apple AirTag, a cyber scandal rocks Germany, and a swindler steals a fortune due to trains being delayed.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by runZero's Chris Kitsch.Plus don't miss our featured interview with Akamai's Patrick Sullivan talking about how retailers can better thwart bots this holiday season.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:The rundown on becoming runZero: What I learned rebranding a company - Chris Kirsch on the runZero blog.Tweet by Melissa Shusterman - Twitter.Apple AirTag Used To Find Over 100 Stolen Democratic Campaign Signs, Police Say - Forbes.Wie eine russische Firma ungestört Deutschland hackt - ZDF Magazin Royale on YouTube.German cybersecurity chief investigated over Russia ties - AP News.German cybersecurity chief sacked following reports of Russia ties - The Guardian. Fraudster swindled Virgin Trains out of £116,000 in 'sophisticated' scam - MSN. Virgin Trains worker, 37, swindled rail firm out of £116,000 in 'delay and repay' compensation scam by photoshopping tickets to exploit flaw in system - Daily Mail. Train delays:How to claim if it's late or cancelled - Money Saving Expert.How many trains arrive on time - Gov.uk.Employee swindled Virgin Trains out of £116,000 in delay and repay compensation scam - Birmingham Mail. Fat Bear Week 2022.‘Fat Bear Week’ Hit By Voter-Fraud Attempt - Rolling Stone.PimEyes - Face search engine.<a...
01:10:1420/10/2022
Massive crypto bungle, and the slave scammers
A couple unexpectedly find $10.5 million in their cryptocurrency account, and in Cambodia people are being forced to commit pig-butchering scams.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who are flying solo again this week.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:DeFi bug accidentally gives $90 million to users, founder begs them to return it - CNBC.Compound boss begs users to return $90 million worth of cryptocurrency they were accidentally gifted - Robert Leshner on Twitter.Couple mistakenly given $10.5m from Crypto.com thought they had won contest, court hears - The Guardian.Mother accused of spending spree after mistakenly receiving $10 million in crypto bungle heads to trial - 9 News.Sold to gangs, forced to run online scams: inside Cambodia’s cybercrime crisis - The Guardian.ZÈRTZ game.ZÈRTZ - Wikipedia.GIPF project - Wikipedia.The Capture - BBC iPlayer.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – the SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Support the show:You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.Become a Patreon supporter for ad-free episodes and our early-release...
38:4413/10/2022
Trussterflucks and eBay stalking
Has new UK prime minister Liz Truss been careless with her mobile phone, and hear the most extraordinary story of corporate cyberstalking.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by nobody for reasons that will become obvious.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Prison for ex-eBay staff who aggressively cyberstalked company's critics with Craigslist sex party ads and funeral wreaths - Graham Cluley.Two Former eBay Executives Sentenced to Prison for Cyberstalking - US Department of Justice.Jonathan Pie: Welcome to Britain. Everything is Terrible - NYT Opinion.UK Supermarket’s Loans-for-Groceries Offer Attracts Huge Take Up - Bloomberg.Liz Truss' mobile number is being sold online for £6.49 - Daily Mail.How to Cook a Soft Boiled Egg Perfectly Every Time - YouTube.11 Best Twitter Bots to Follow to Boost Productivity - Gadgetshouse.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – the SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Akamai - Make the most of Cybersecurity Awareness Month by connecting with Akamai’s experts on how you can achieve unmatched security. Where else can you take advantage of insights from 7 trillion DNS queries per day?Support the show:You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.Become a Patreon...
39:4306/10/2022
Deepfake dangers, AI image opt out, and controlling your urges
Anti-porn "shameware" apps take a privacy pounding, is your image already being used by AI, and deepfake danger continues to deepen.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:The Ungodly Surveillance of Anti-Porn ‘Shameware’ Apps - WIRED.Covenant Eyes.Sick and tired of trying to quit porn? You’re not alone - Covenant Eyes promotional video.Fortify.AI Is Probably Using Your Images and It's Not Easy to Opt Out - Vice.ISIS Executions and Non-Consensual Porn Are Powering AI Art - Vice.Have I been trained?The Deepfake Danger: When It Wasn’t You On That Zoom Call - CSO Online.Deepfake Audio Has A Tell – Researchers Use Fluid Dynamics To Spot Artificial Imposter Voices - The Conversation. Deephy: On Deepfake Phylogeny - Cornell University.On The Horizon: Interactive And Compositional Deepfakes - Microsoft. Detect DeepFakes: How to counteract misinformation created by AI - MIT University. New Deepfake Threats Loom, Says Microsoft’s Chief Science Officer - Venture Beat.The Joy of Sets - BBC Archive.Steam Deck.Am I Being Unreasonable? - BBC iPlayer.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – the SaaS app that sends
56:1029/09/2022
Uber, Rockstar, and crystal balls
Researchers reveal how your eyeglasses could be leaking secrets when you're on video conferencing calls, we take a look at the recent data breaches involving Uber and Grand Theft Auto 6, and we cast an eye at what threats may be around the corner...All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.Plus - don't miss our featured interview with Sal Aurigemma, the faculty director of the Master of Science in Cyber Security program at the University of Tulsa.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:“Iain Exotic”, Iain Thomson’s dress-up homage to Joe Exotic, the Tiger King - Twitter.“Private Eye: On the Limits of Textual Screen Peeking via Eyeglass Reflections in Video Conferencing” - Research paper by Yan Long, Chen Yan, Shilin Xiao, Shivan Prasad, Wenyuan Xu, and Kevin Fu.“We saved you a seat in chat” - Rather large text on the Twitch website.Stalker zoomed in on Japanese idol’s eyes to find out where she lived - Graham Cluley.Uber is looking for more security staff - Twitter.Uber explains how it was pwned this month, points finger at Lapsus$ gang - The Register.Uber’s hacker *irritated* his way into its network, stole internal documents - Graham Cluley.Security update - Uber.Grand Theft Auto 6 maker confirms source code, vids stolen in cyber-heist - The Register.Cybersecurity Awareness Month - CISA. The scary future of the internet: How the tech of tomorrow will pose even bigger cybersecurity threats - ZDNet.U.S. Government Spending Billions on Cybersecurity - Hacker News.The Mitchells vs The Machines trailer - YouTube.The Mitchells vs The Machines - Netflix.<a...
01:04:1622/09/2022
Printer peeves, health data hangups, and Twitter tussles - with Rory Cellan-Jones
How could your inkjet printer finally help you make some money, why is it so hard to share our health data even if we want to, and what result do you want to see from the Elon Musk vs Twitter bunfight?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Rory Cellan-Jones.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Dynamic Cartridge Security - disable please - Angry customers complain on HP support forum.Update now! Many HP printers affected by three critical security vulnerabilities - MalwareBytes.HP will pay customers for blocking non-HP ink cartridges in EU - Bleeping Computer.HP and Euroconsumers settle on Dynamic Security - Euroconsumers.Ink cartridges are a scam - YouTube.Why printer ink is so expensive - Insider.Trying to print something - YouTube.UK Biobank - why won't GPs share data? - Rory’s Always On Newsletter.Another data sharing fiasco - Rory's Always On Newsletter.Tweet by Kate Bingham - Twitter.The Twitter Whistleblower Needs You to Trust Him - Time.Twitter denies whistleblower payout violates Musk’s takeover deal - MSN.Elon Musk earns a split decision in Delaware court - The New York Times.Twitter’s whistleblower has pitched up at a very inconvenient moment - The Guardian.Damning claims about Twitter’s bots...
56:3115/09/2022
Chiquita banana, dumb criminals, and detecting ring binders
Students learn a valuable lesson when it comes to AI detecting guns on campus, SIM swappers are surprisingly stupid, and romance scammers get scammed by someone (or some thing?) calling themselves Chiquita Banana.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:‘The least safe day’: rollout of gun-detecting AI scanners in schools has been a ‘cluster,’ emails show - Motherboard.Gun detection AI the latest tech to make schools less safe - TechDirt.The unproven, invasive surveillance technology schools are using to monitor students - ProPublica. NYC Mayor considering a subway security system that can’t differentiate between a laptop and a handgun - Motherboard.Violence-as-a-Service: Brickings, Firebombings & Shootings for Hire - Brian Krebs.USA vs Patrick McGovern-Allen (PDF) - Court Listener.Reports of romance scams hit record highs in 2021 - FTC.Meeting you was a fake: Investigating the increase in romance fraud during COVID-19 - Academic Research.This dating app fought scammers with bots… hilarity ensued - TechCrunch.She was 69. He Was Young, Hunky,,, and a Fraud - The Daily Beast.Gladbeck: The Hostage Crisis trailer – YouTube.Watch Gladbeck: The Hostage Crisis - Netflix.The Ocean Cleanup.We flooded our dating app with bots… to scam scammers -...
50:5308/09/2022
Lost in translation, spiders, and slapping tortillas - with Mikko Hyppönen
We're back from our summer break as we ask how did a cryptomining campaign stay unspotted for years, quiz special guest and infosec rockstar Mikko Hyppönen about his book, and ponder what spiders teach us about misinformation.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:The 20 Funniest Finnish Expressions (and How To Use Them) - Matador Network.Sophos punts anti-virus for Klingon - The Register.Helsinki named Klingon-speaking capital of the world – Naked Security.Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications - Check Point Research.If It's Smart It's Vulnerable - Book by Mikko Hyppönen.Psychological inoculation improves resilience against misinformation on social media -Science Advances.Let’s flatten the infodemic curve - WHO.The global spread of misinformation on spiders - Current Biology.A Journey Into Misinformation on Social Media - The New York Times.Google Looks to Vaccination to Combat Misinformation In Searches - The New York Times.Spiders Are Caught in a Global Web of Misinformation - The New York Times.The rock-paper-scissors/tortilla wrap game.DEF CON: The Documentary.Smashing Security Painting competition – Carole.wtf.Open Exhibition, Summer 2022 - Oxford Art Society.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:<a href="https://bitwarden.com/smashing/" rel="noopener noreferrer"...
53:5601/09/2022
Hackers doxxed, Pornhub probs, and Co-op security measures
Pornhub has a problem, the UK's Co-op supermarket is accused of big brother tactics, and we take a look at a security researcher's attempt to reveal the true identify of hackers.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:On security researcher's newsletter, exposing cybercriminals behind ransomware — CyberScoop.‘Imma Make U Dig Ur Own Grave’: He Doxes Ransomware Hackers and Gets Death Threats in Return — Vice.Intrusion Truth - Five Years of Naming and Shaming China’s Spies — Kim Zetter.Who Is 'Intrusion Truth,' Group Exposing Alleged Chinese Hackers? — Daily Dot.The Leopards Eating People's Faces Party meme — Know Your Meme.Tweet by Bill Ackman.Judge Refuses Visa’s Request to Escape Pornhub-Related Lawsuit — The New York Times.How to Prevent and Handle Robberies and Theft in Retail — Vend Retail Blog.Abuse of shopworkers is on the rise – coronavirus brought it to our attention and now we need to act — The Conversation.‘Tackling violence and abuse in retail must be one of the industry’s highest priorities’ — Retail Week.Convenience store spy cameras face legal challenge — BBC News.Looking back at the career of Bernard Cribbins — YouTube.Tribute to David Warner — YouTube.Webb Compare — John Christensen.Support Maria Varmazis on the Pan-Mass Challenge.<a href="https://www.smashingsecurity.com/store" rel="noopener noreferrer"...
53:2604/08/2022
Uber's hidden hack, tips for travel, and AI accent fixes
Uber may not face prosecution over its handling of a 2016 data breach - but its former chief security head does; how to defend your digital devices' data while on vacation, and how to change your accent with artificial intelligence.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Naked Security's Paul Ducklin.Plus don't miss our featured interview with Ian Farquhar of Gigamon.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:Uber Enters Non-Prosecution Agreement Related to 2016 Data Breach — US Department of Justice.Former Uber Security Chief Joe Sullivan Must Face Driver Fraud Charges — Bloomberg.Uber to pay $148 million in data breach settlement — TechCrunch.Uber paid hackers $100,000 to keep data breach quiet — Graham Cluley.Uber CISO's trial underscores the importance of truth, transparency, and trust — CSO Online.7 cybersecurity tips for your summer vacation! — Naked Security.Sanas demo.Sanas Raises $32M for Breakthrough AI Technology for Real-Time Accent Translation — Sanas press release.This 6-Million-Dollar AI Changes Accents as You Speak — IEEE Spectrum.Call centre workers can use AI to mimic your accent on the phone — New Scientist.A little less accent, a little more customer service — ComputerWorld.What Is Accent Reduction? — Accent Advisor.Compound pejoratives on Reddit – from 'buttface' to 'wankpuffin' — Colin Morris.Melissa computer virus — Wikipedia.<a...
01:08:0628/07/2022
The Most Wanted Missing CryptoQueen
In this special edition of the "Smashing Security" podcast, computer security veterans Graham Cluley and Carole Theriault welcome back author and journalist Jamie Bartlett - host of "The Missing CryptoQueen" podcast.Jamie tells us about his new book, which shares more details about the disappearance of cryptocurrency scammer Dr Ruja Ignatova, and the subsequent hunt by law enforcement.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:The Missing CryptoQueen podcast — BBC.The Missing CryptoQueen book — Penguin.Missing Cryptoqueen: FBI adds Ruja Ignatova to top ten most wanted — BBC News.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Drata – Put Security and Compliance on Autopilot. Build trust with your customers and scale securely with Drata, the smartest way to achieve continuous SOC 2, ISO 27001 & HIPAA compliance.Cyber Security Inside podcast -bringing you the most important and timely security topics as well as other industry experts for insightful conversations.Support the show:You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.Become a Patreon supporter for ad-free episodes and our early-release feed!Follow us:Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy
42:4421/07/2022
Disney's social dumpster fire, Anom phones, and TikTok tragedies
A self-proclaimed "super hacker" causes problems in the Magic Kingdom, criminals regret trusting Anom phones, and lawsuits are filed against TikTok.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.Plus don't miss our featured interview with Scott McCrady, the CEO of SolCyber Managed Security Services.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:Official Disneyland Instagram Account Hacked This Morning! — The Disney blog.Disneyland social media accounts hacked, offensive messages posted — Hot for Security.We Got the Phone the FBI Secretly Sold to Criminals — Vice.Parents Sue TikTok, Saying Children Died After Viewing ‘Blackout Challenge’ — The New York Times.Lawmakers Want Social Media Companies to Stop Getting Kids Hooked — Wired.How Social Media Tricks Us Into Thinking We Are Paying Attention — Forbes.Facebook could be sued for addicting children under California bill — Ars Technica.Kids Are Using Social Media More Than Ever, Study Finds — New York Times.2021 Facebook leak — Wikipedia.California Parents Could Soon Sue for Social Media Addiction — Gizmodo.Absurd Trolley Problems.Weird or Confusing.Google Quick, Draw!Unfinished London — Jay Foreman on YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:<a...
54:4714/07/2022
Raising money through ransomware, China's mega-leak, and hackers for hire
A hacked university might have made a profit after paying a cryptocurrency ransom, China suffers possibly the biggest data breach in history, and Reuters investigates digital mercenaries.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:Dutch university paid $220,000 ransom to hackers after Christmas attack — Graham Cluley.Remarkable development in investigation into Maastricht University cyberattack — Maastricht University.Dutch University profits from returned ransomware payment — The Register.Favorable exchange rate on a fake cryptoexchange — Kaspersky.Tweet from @cz_binance about mega-leak.Vast Cache of Chinese Police Files Offered for Sale in Alleged Hack — Wall Street Journal.How mercenary hackers sway litigation battles — Reuters.Countering hack-for-hire groups — Google.The business of hackers-for-hire threat actors — TechRepublic.Fransdita Muafidin on Instagram.Giant Cats Disturbing Civilization — Geeks are sexy.Watch Good Luck to You, Leo Grande — Hulu.Good luck to you Leo Grande (Trailer) — YouTube.This is Love podcast.Cain's Jawbone — Wikipedia.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:<a href="https://bitwarden.com/smashing/" rel="noopener noreferrer"...
45:1807/07/2022
Debug ransomware and win $1,000,000, period-tracking apps, and AI gets emotional
A new version of the LockBit ransomware offers a bug bounty, women uninstall period-tracking apps in fear of how their data might be used against them, and Microsoft's facial recognition tech no longer wants to know how you're feeling.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Thom Langford from The Host Unknown podcast.Plus don't miss our featured interview with Bitwarden founder and CTO Kyle Spearrin.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:LockBit 3.0 introduces the first ransomware bug bounty program — Bleeping Computer.Fake copyright infringement emails install LockBit ransomware — Bleeping Computer.Why US women are deleting their period tracking apps — The Guardian.Privacy not included — Mozilla Foundation.The #1 Period Tracker on the App Store Will Hand Over Data Without a Warrant — Vice.Microsoft is removing emotion recognition features from its facial recognition tech — NBC News.Top 10 Emotional AI Examples in 2022 & Reasons for Success — AI Multiple.Analysis of Speech Features for Emotion Detection: A Review — IEEE Xplore.Microsoft's framework for building AI systems responsibly — Microsoft.The Swedish chemist shop sketch — As performed by Mel Smith and Rowan Atkinson on Not the Nine O'Clock News.Alley Cat — Wikipedia.Play Alley Cat — Internet Archive.Alley Cat Remeow Edition — Game Jolt.reMarkable.SOLAR podcast.<a...
59:4730/06/2022
Hot tub hijinx, and a sentient AI
Internet-connected jacuzzis find themselves in hot water, and a Google engineer claims that their AI has developed feelings.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Episode links:Hot Tub Time Machine trailer — YouTube.Hacking into the worldwide Jacuzzi SmartTub network — Eaton Works.SmartTub — Apple iOS App Store.SmartTub — Google Play store.Hot tub hack reveals washed-up security protection — BBC News.Google engineer Blake Lemoine thinks its LaMDA AI has come to life — The Washington Post.Google engineer put on leave after saying AI chatbot has become sentient — The Guardian.AI's most convincing conversations are not what they seem — The Register.Blake Lemoine's blog.Van Gogh Bristol Exhibition: The Immersive Experience.Van Gogh: The Immersive Experience — YouTube.The Inquiry — BBC World Service.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide - the SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Bitwarden - Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Drata - Put Security and Compliance on Autopilot. Build trust with your customers and scale securely with Drata, the smartest way to achieve continuous SOC 2, ISO 27001 & HIPAA compliance.Support...
40:2023/06/2022
Encrypted notes, and a deadly case of AirTag spying
How did a saxophonist sneak sensitive information in and out of the Soviet Union? How might an Apple AirTag have led to murder? And isn't the world of cryptocurrency and blockchain doing just great?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Visit https://www.smashingsecurity.com/279 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Bitwarden: A password manager is an important tool for generating and saving secure credentials for every online account. Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Open source with published 3rd party security audits, Bitwarden is transparent and secure, utilizing end-to-end and zero knowledge encryption with source code that can be scrutinized by all.Learn how Bitwarden can help you do business faster and more securely at bitwarden.com/smashing and start a free business plan trial today.Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only...
36:5015/06/2022
Tim Hortons, avoiding sanctions, and good faith security research
Trouble brews with the Tim Hortons app, Mandiant gets in a tussle with a Russian ransomware gang, and should good faith security researchers be at risk of prosecution?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.Visit https://www.smashingsecurity.com/278 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Geoff White.Sponsored By:Snyk: Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.Get started right now, with a free forever account, at snyk.co/smashingKolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Bitwarden: A password manager is an important tool for generating and saving secure credentials for every online account. Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Open source with published 3rd party security audits, Bitwarden is transparent and secure, utilizing end-to-end and zero knowledge encryption with source
40:2608/06/2022
Bad bots, cheeky ransoms, and good deepfakes
Ransom acts of kindness are top of our mind, as we also explore how bad bots are hogging more and more of the internet's activity, and look at how deepfakes could be a good thing after all.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Ray [REDACTED].Visit https://www.smashingsecurity.com/277 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Ray [REDACTED].Sponsored By:Bitwarden: A password manager is an important tool for generating and saving secure credentials for every online account. Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Open source with published 3rd party security audits, Bitwarden is transparent and secure, utilizing end-to-end and zero knowledge encryption with source code that can be scrutinized by all.Learn how Bitwarden can help you do business faster and more securely at bitwarden.com/smashing and start a free business plan trial today.Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing SecurityLinks:Popcorn Time ransomware invites you to get ‘nasty’ to recover your files — Graham Cluley.<a...
51:1101/06/2022
Webcam extortion, Michael Fish, and food foul-ups
A browser extension bug let malicious websites spy on webcams, hackers threaten the global food supply chain, and Michael Fish (not that one...) hacked into his female classmates' online accounts, hunting for nude photos and videos.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Visit https://www.smashingsecurity.com/276 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Mark Stockley.Sponsored By:GoodAccess: GoodAccess - Free Business Cloud VPN for up to 100 Users.Get a cloud VPN with strong network encryption and unprecedented online threat protection. No hardware. 100% free. Just create your team and enjoy GoodAccess forever.Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card required.Rumble: Rumble, made by the creator of Metasploit, finds many devices connected to your network that other solutions miss, including orphaned machines running outdated operating systems. It can even tell you which machines are missing endpoint protection, from your local network to the cloud. Sign up
54:3025/05/2022
Jail for Bing, and mental health apps may not be good for you
A man hacks his employer to prove its security sucks, Telegram provides a helping hand to the Eternity Project malware, and what the heck do mental health apps think they're up to?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dr Jessica Barker.Plus don't miss our featured interview with Rumble's Chris Kirsch.Visit https://www.smashingsecurity.com/275 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guests: Chris Kirsch and Jessica Barker.Sponsored By:Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. GoodAccess: GoodAccess - Free Business Cloud VPN for up to 100 Users.Get a cloud VPN with strong network encryption and unprecedented online threat protection. No hardware. 100% free. Just create your team and enjoy GoodAccess forever.Rumble: Rumble, made by the creator of Metasploit, finds many devices connected to your network that other solutions miss, including orphaned machines running outdated operating systems. It can even tell you which machines are missing endpoint protection, from your local network to the cloud. <a href="https://www.rumble.run" rel="noopener noreferrer"...
01:05:3518/05/2022
Hands off my biometrics, and a wormhole squirmish
Clearview AI receives something of a slap in the face, and who is wrestling over an internet wormhole?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.And don't miss our featured interview with Artur Kane of GoodAccess.Visit https://www.smashingsecurity.com/274 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Artur Kane.Sponsored By:GoodAccess: GoodAccess - Free Business Cloud VPN for up to 100 Users.Get a cloud VPN with strong network encryption and unprecedented online threat protection. No hardware. 100% free. Just create your team and enjoy GoodAccess forever.Rumble: Rumble, made by the creator of Metasploit, finds many devices connected to your network that other solutions miss, including orphaned machines running outdated operating systems. It can even tell you which machines are missing endpoint protection, from your local network to the cloud. Sign up for a free trial and build your asset inventory in minutes. Get your trial at rumble.runKolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card...
49:1011/05/2022
Password blips, and who's calling the airport?
We find out why calls to Dublin airport's noise complaints line have soared, and Carole quizzes Graham to celebrate World Password Day.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.And don't miss our special featured interview with Clint Dovholuk of NetFoundry.Visit https://www.smashingsecurity.com/273 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Clint Dovholuk.Sponsored By:Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. NetFoundry: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything.Embed SDKs inside your app, tunnelers to run on all major operating systems, or deploy an Edge Router for any cloud.No networking engineering skills required. No more pain of inbound ports, VPNs, complex firewall rules, public DNS, and more.Learn more and try it for yourself at netfoundry.io/smashingsecurity/Support Smashing SecurityLinks:<a href="https://www.chron.com/news/houston-texas/article/Houston-Zoo-asks-FBI-to-investigate-text-message-1755868.php" rel="noopener noreferrer"...
50:1204/05/2022
Going ape over the Kardashians, and the face of romance scams
Members of The Bored Ape Yacht Club get that sinking feeling, a face unwittingly launches hundreds of romance scams, and is an as-yet unseen Kim Kardashian sex tape a load of old Roblox?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by the BBC's cyber correspondent Joe Tidy.Visit https://www.smashingsecurity.com/272 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Joe Tidy.Sponsored By:Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card required.NetFoundry: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything.Embed SDKs inside your app, tunnelers to run on all major operating systems, or deploy an Edge Router for any cloud.No networking engineering skills required. No more pain of inbound ports, VPNs, complex firewall rules, public DNS, and more.Learn more and try it for yourself at netfoundry.io/smashingsecurity/Support Smashing SecurityLinks:<a href="https://twitter.com/etienneshrdlu/status/1485956332989693953" rel="noopener noreferrer"...
50:2427/04/2022
Crypto break-in, Google blurring, and mics not muting
A man loses $650,000 from his cryptocurrency wallet after his Apple iCloud account is hacked, video conferencing apps may not be muting your mic quite the way you imagined, and Google has unblurred military bases in Russia... or has it? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Visit https://www.smashingsecurity.com/271 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Dave Bittner.Sponsored By:NetFoundry: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything.Embed SDKs inside your app, tunnelers to run on all major operating systems, or deploy an Edge Router for any cloud.No networking engineering skills required. No more pain of inbound ports, VPNs, complex firewall rules, public DNS, and more.Learn more and try it for yourself at netfoundry.io/smashingsecurity/Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card required.Support Smashing SecurityLinks:<a href="https://twitter.com/revive_dom"...
50:4620/04/2022
Bearded Barbie, EDR scams, and hobbyist crime detectives
Pulchritudinous women with glossy long hair are targeting Israeli officials via Facebook - but why? Scammers have found a new way to gain access to your most sensitive information - but how? And armchair detectives are helping investigating cold cases involving DNA - but should they?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Visit https://www.smashingsecurity.com/270 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Maria Varmazis.Sponsored By:Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Keeper Security: Keeper Security’s enterprise password management platform locks down logins, payment cards, confidential documents, API keys, and database passwords in a patented Zero-Knowledge encrypted vault. And, it takes less than an hour to deploy across your organization.Sign up for a Keeper free trial for your organization today, and get a free 3-year personal plan, at keepersecurity.com/smashingSupport Smashing SecurityLinks:How Barbie's body size would look in real life — Daily Mail.<a...
51:0113/04/2022
Trezor Deep Throat, a CCTV stalker, and Amazon's list of banned words
There's monkey business involving cryptocurrency thieves and MailChimp, a stalker exploits his ex-partner's CCTV cameras, and what are the naughty words Amazon doesn't want its staff using?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Zoë Rose.Visit https://www.smashingsecurity.com/269 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Zoë Rose.Sponsored By:Keeper Security: Keeper Security’s enterprise password management platform locks down logins, payment cards, confidential documents, API keys, and database passwords in a patented Zero-Knowledge encrypted vault. And, it takes less than an hour to deploy across your organization.Sign up for a Keeper free trial for your organization today, and get a free 3-year personal plan, at keepersecurity.com/smashingKolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing SecurityLinks:Trezor wallets hacked? Don’t be duped by phishing attack email — Graham Cluley.Tweet by Trezor.<a...
50:0906/04/2022
LinkedIn deepfakes, doxxing Russian spies, and a false alarm
Strange goings-on on LinkedIn, Ukraine publishes a list of alleged Russian FSB agents, and police in Pittsburgh investigate an odd report of an active shooter.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.Visit https://www.smashingsecurity.com/268 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Geoff White.Sponsored By:Keeper Security: Keeper Security’s enterprise password management platform locks down logins, payment cards, confidential documents, API keys, and database passwords in a patented Zero-Knowledge encrypted vault. And, it takes less than an hour to deploy across your organization.Sign up for a Keeper free trial for your organization today, and get a free 3-year personal plan, at keepersecurity.com/smashingKolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing SecurityLinks:North Korea tests its ‘largest intercontinental ballistic missile’ — YouTube.LinkedIn Professional Community Policies — LinkedIn.<a...
48:3930/03/2022
Virtual kidnapping, two helipads, and a naughty Apple employee
A Russian bank tells its customers to stop installing security updates, an Apple employee ends up in hot water, and learn our tips to avoid being virtually kidnapped.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.Visit https://www.smashingsecurity.com/267 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Anna Brading.Sponsored By:Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card required.Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it tooCountless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drataSupport...
53:5124/03/2022
Cyberflashing, Kaspersky, and secret spies
Germany tells consumers to stop using Kaspersky anti-virus products, OSINT reveals a secret government department (with help from an Apple AirTag), and the UK says it's taking a hard line on cyberflashing.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Chris Kirsch.Visit https://www.smashingsecurity.com/266 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Chris Kirsch.Sponsored By:Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it tooCountless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drataKolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. <a href="https://www.patreon.com/smashingsecurity" rel="noopener noreferrer"...
58:2217/03/2022
The Nigerian supercop and Alexa vs. Alexa
The most famous policeman in Nigeria is in hot water over his links to Hushpuppi, has your Amazon Echo been talking to itself, and can an AI girlfriend save your marriage?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Plus don't miss our featured interview with Jason Meller of Kolide.Visit https://www.smashingsecurity.com/265 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Jason Meller.Sponsored By:Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it tooCountless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drataKolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card required.<a href="https://www.patreon.com/smashingsecurity"...
54:1110/03/2022
Hacked car chargers, Telegram sextortionists, and secret bossware
Why might Russian EV chargers be displaying an anti-Putin message? Why are Telegram groups sharing sharing explicit images of women without their consent? And who is watching you in the workplace?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Jessica Barker.Visit https://www.smashingsecurity.com/264 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Jessica Barker.Sponsored By:Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing SecurityLinks:Three ways you can help the people of Ukraine from the UK — The Guardian.How You Can Help Ukraine — London City Hall.Ukrainian Astronomers Named a Star 'Putin Is a D**khead' — The Atlantic.Video of hacked EV charger — AutoEnterprise on Facebook.Explanation for EV charger outage — Rosseti on Facebook.<a...
47:5703/03/2022
Problèmes de Weefeee, AI artists, and Web 3.0
Ooh la la! Horreur Wi-Fi en France! Some folks have experienced the drawbacks of Web 3.0 as their NFTs are stolen, and should computers own the copyright over the art they produce?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.And don't miss our featured interview with Sean Herbert of baramundi.Visit https://www.smashingsecurity.com/263 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guests: Mark Stockley and Sean Herbert.Sponsored By:Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated.Try Kolide Free for 14 Days; no credit card required.baramundi: Optimize your IT processes with the baramundi Management Suite and make optimal use of resources by automating time-consuming routine tasks.Stay in control and maximize your productivity by automating routine tasks. The Unified Endpoint Management Software can be installed and implemented quickly, is intuitive to use, has a modular structure and offers a high level of usability and transparency.Try out the free 30-Day full version for yourself today at baramundi.com/smashingsecuritySupport Smashing SecurityLinks:<a...
01:06:2824/02/2022
Macro progress, eyeball-tracking ads, and encryption backdoors
How does Microsoft hope to defeat the macro terror? How is the UK Government trying to influence the public's opinion on end-to-end encryption? And what is MoviePass hoping to do with your eyeballs?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Thom Langford.Visit https://www.smashingsecurity.com/262 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Thom Langford.Sponsored By:Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security.You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. baramundi: Optimize your IT processes with the baramundi Management Suite and make optimal use of resources by automating time-consuming routine tasks.Stay in control and maximize your productivity by automating routine tasks. The Unified Endpoint Management Software can be installed and implemented quickly, is intuitive to use, has a modular structure and offers a high level of usability and transparency.Try out the free 30-Day full version for yourself today at baramundi.com/smashingsecuritySupport Smashing SecurityLinks:Macros from the internet are blocked by default in...
58:0017/02/2022
North Korea hacked, DEA cosplay, and Horizon Worlds drama
Who's wearing the pyjamas while they take down North Korea's internet? Is it a case of cop or cosplay in Oregon? And what's to fear about the metaverse?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Visit https://www.smashingsecurity.com/261 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Dave Bittner.Sponsored By:1Password: 1Password Families makes sharing passwords, logins, credit cards and more a (romantic) walk in the park. From now until February 28th, when you sign up for - or upgrade your individual account to - a 1Password Families membership, you’ll get $20 off the entire year!Learn more at smashingsecurity.com/love1passwordbaramundi: Optimize your IT processes with the baramundi Management Suite and make optimal use of resources by automating time-consuming routine tasks.Stay in control and maximize your productivity by automating routine tasks. The Unified Endpoint Management Software can be installed and implemented quickly, is intuitive to use, has a modular structure and offers a high level of usability and transparency.Try out the free 30-Day full version for yourself today at baramundi.com/smashingsecuritySupport Smashing SecurityLinks:Space Station Photos Show North Korea at Night, Cloaked in Darkness — National Geographic.North Korea Hacked Him. So He Took Down Its Internet — Wired.<a...
50:4210/02/2022
New hire mystery, hacktivist ransomware, and digi-dating
Who's that new guy working at your company, and why don't you recognise him from the interview? How are hacktivists raising the heat in Belarus? And should you be fully vaxxed for your online date?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Visit https://www.smashingsecurity.com/260 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Maria Varmazis.Sponsored By:1Password: Secure online payments and grow your business with Brex and 1Password.Brex and 1Password have partnered to make online payments secure and frictionless. 1Password customers can now use Brex virtual credit cards to check out online with just two clicks.1Password's integration with Brex is available right now to 1Password Teams and Business customers based in the United States.Learn more at smashingsecurity.com/brexUptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping.Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform.Find out more and try it for free at...
47:4103/02/2022
Techquilibrium and mediocre linguistic escapades
Wordle - good or bad for the world? Whatever your opinion, at least someone wants to spoil players' fun. Meanwhile, we take a look at the threat mobile phones can pose to your mental health.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Visit https://www.smashingsecurity.com/259 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:1Password: Secure online payments and grow your business with Brex and 1Password.Brex and 1Password have partnered to make online payments secure and frictionless. 1Password customers can now use Brex virtual credit cards to check out online with just two clicks.1Password's integration with Brex is available right now to 1Password Teams and Business customers based in the United States.Learn more at smashingsecurity.com/brexThinkst: Most companies discover they’ve been breached way too late. Thinkst Canary fixes this: just 3 minutes of setup; no ongoing overhead; nearly 0 false positives, and you can detect attackers long before they dig in. Go to canary.tools to find out why its Physical, VM and Cloud Based Canaries are deployed and loved on all 7 continents...Listeners who mail in referencing Smashing Security get a 10% discount on their order!Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes...
42:4827/01/2022
Tesla remote hijacks and revolting YouTubers
Carole's still on jury service, but the show must go on! We take a look at how some Tesla owners are at risk of having their expensive cars remotely hijacked, and why YouTubers are up in arms over NFTs.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Visit https://www.smashingsecurity.com/258 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping.Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform.Find out more and try it for free at uptycs.com1Password: 1Password has put its 15 years of security experience into creating 1Password University, a fun, dynamic, and free learning resource for people of all skill levels.Broaden your knowledge, starting with the basic building blocks of security. Learn at your own pace and learn how to create form an entire ecosystem of tools and tactics that help keep you safe on the internet.Whether you’re a business leader looking to create a culture of security in the workplace, or you’re just trying to understand why you need a unique password for each account, 1Password University’s...
33:0520/01/2022
Pokemon-hunting cops and the Spine Collector scammer
Who has been playing video games rather than hunting down criminals? How is a man alleged to have stolen manuscripts of unpublished books from celebrity authors? Which pot contains an elephant? And why has Graham been listening to podcasts about pest control marketing?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Visit https://www.smashingsecurity.com/257 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping.Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform.Find out more and try it for free at uptycs.com1Password: 1Password has put its 15 years of security experience into creating 1Password University, a fun, dynamic, and free learning resource for people of all skill levels.Broaden your knowledge, starting with the basic building blocks of security. Learn at your own pace and learn how to create form an entire ecosystem of tools and tactics that help keep you safe on the internet.Whether you’re a business leader looking to create a culture of security in the workplace, or you’re just trying to understand why you
44:1613/01/2022
Virgin Media just won't take no for an answer, NFT apes, and bad optics
After a brief discussion of the Log4Shell vulnerability panic, we chat about how Virgin Media has got itself into hot water, a fat-fingered fumble at the Bored Ape Yacht Club, and how to hack around your sleeping girlfriend's facial recognition.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined by Mark Stockley for our last episode of the year!Visit https://www.smashingsecurity.com/256 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Mark Stockley.Sponsored By:1Password: The first annual 1Password “State of Access” benchmark study illuminates the grave dangers unwittingly posed by checked-out, apathetic employees — including security professionals.Burned-out employees are 3 times more likely to say security rules and policies “aren’t worth the hassle,” and nearly half of burned-out security professionals say it’s unrealistic for companies to be aware of and manage all apps and devices that employees use.Read the report and find out what you can do at 1password.com/resources.Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping.Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform.Find out more and
50:1016/12/2021
Revolting receipts, a Twitter fandango, and shopkeeper cyber tips
"Demonically" possessed devices print out antiwork propaganda, advice on how to secure your store, and is Twitter's new photo privacy policy practical?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.Visit https://www.smashingsecurity.com/255 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Dinah Davis.Sponsored By:Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping.Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform.Find out more and try it for free at uptycs.com1Password: It’s that time again when we’re all thinking about plans for the upcoming year. Does your plan include making your team more productive and secure? 100,000 businesses use 1Password to secure employees at scale by encrypting their passwords and sensitive information and helping them get more done, faster.That’s why, for a limited time only, new customers can get 25% off the first year of 1Password Business and find out how 1Password can boost productivity while protecting their most sensitive data.Act fast! This deal is only...
53:2809/12/2021
A dead hamster, a brass pen, and The Beatles
Cryptocurrency traders suffer a hamster-related loss, beware of charity scammers this holiday season, and do you have the patience to sit through Peter Jackson's eight-hour Beatles documentary?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who are flying solo this week.Visit https://www.smashingsecurity.com/254 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface.Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem.Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping.Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform.Find out more and try it for free at uptycs.com1Password: It’s that time again when we’re all thinking about plans for the upcoming year. Does your plan include making your team more productive and secure? 100,000 businesses use 1Password to secure employees at scale by encrypting their passwords and sensitive information and helping them get more done, faster.That’s why, for a limited time only, new customers can get 25% off the first year of 1Password Business and find out how 1Password can boost productivity while protecting their most sensitive data.Act fast! This deal is only good
37:5402/12/2021
Cybercrime unicorns, HVAC hacks, and NFT piracy - with Mikko Hyppönen
Heating systems are left vulnerable to attack in the high courts, cybercrime unicorns have become a reality (but what are they?), over 15 Terabytes of NFTs are made available for anyone to download ... and Carole reveals her Pick of the Year.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mikko Hyppönen.Visit https://www.smashingsecurity.com/253 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Mikko Hyppönen.Sponsored By:Thinkst: Most companies discover they’ve been breached way too late. Thinkst Canary fixes this: just 3 minutes of setup; no ongoing overhead; nearly 0 false positives, and you can detect attackers long before they dig in. Go to canary.tools to find out why its Physical, VM and Cloud Based Canaries are deployed and loved on all 7 continents...Listeners who mail in referencing Smashing Security get a 10% discount on their order!Perimeter 81: Perimeter 81 is the first-ever Cybersecurity Experience Platform, designed around Instant Deployment, Unified Management, Integrated Security, and Full Visibility.Perimeter 81 allows organizations of any and all industry sizes to support IT teams with robust tools to secure and manage your global network with one unified platform. Securing remote access for cloud and hybrid businesses and organizations, Perimeter 81 provides unified solutions such as Zero Trust Network Access, Firewall as a Service, Device Posture Check, and more.Learn more and request a demo at perimeter81.com1Password: 1Password 8 for Windows has been reimagined to feel right at home on the world's most popular desktop operating system.<a href="https://www.1password.com" rel="noopener noreferrer"...
48:0525/11/2021
Hotel hacks, workplace spies, and the FBI
Booking.com got hacked five years ago, and didn't tell its customers... but now we know who might have been behind it. Bossware rears its ugly head again in the workplace, spying on employees. And did you receive a warning email from the FBI?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Brian Klaas of the "Power Corrupts" podcast.Plus we have a featured interview with Perimeter 81 co-founder and CEO Amit Bareket.Visit https://www.smashingsecurity.com/252 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guests: Amit Bareket and Brian Klaas.Sponsored By:Perimeter 81: Perimeter 81 is the first-ever Cybersecurity Experience Platform, designed around Instant Deployment, Unified Management, Integrated Security, and Full Visibility.Perimeter 81 allows organizations of any and all industry sizes to support IT teams with robust tools to secure and manage your global network with one unified platform. Securing remote access for cloud and hybrid businesses and organizations, Perimeter 81 provides unified solutions such as Zero Trust Network Access, Firewall as a Service, Device Posture Check, and more.Learn more and request a demo at perimeter81.comQualys: Qualys was one of the first SaaS security companies, and delivers continuous, critical security intelligence via its Qualys Cloud Platform and integrated Cloud Apps.Its powerful solutions empower organisations to streamline and consolidate their security and compliance solutions in a single platform and achieve greater business agility, better outcomes and substantial cost savings.Qualys recently announced three new solutions designed to address today’s challenges faced by enterprises: Ransomware Risk Assessment, Cybersecurity Asset Management, and Zero Touch...
01:01:1518/11/2021
PrawnHub, Tesla recall, and IoT luggage
Fishing fanatics find themselves in deep water, Teslas go haywire after an update, and is there actually some good news about IoT?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Ken Munro.Visit https://www.smashingsecurity.com/251 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Ken Munro.Sponsored By:1Password: From start-up to enterprise, 1Password makes it easy for your team to store, generate and share strong passwords. The less time you need to spend dealing with hacks, phishing scams, and lost passwords, the better.Not just for IT and Security teams – all kinds of teams like Finance, HR, Legal, and Marketing can also store and share business credit cards, sensitive documents and shared logins in 1Password.Work securely from home or in the office. 1Password allows secure access to logins and important resources anywhere you work.Instantly deploy, grant and revoke access to shared vaults. You can securely add new team members and recover locked-out user accounts.Find out more and try 1Password free for 14 days at 1Password.comQualys: Qualys Security Conference 2021 is taking place in Las Vegas November 15-18 2021, and you can attend either in person or online.Hear from experts such as Chris Krebs, former Director of the DHS & CISA, learn strategies and tactics to secure your organization, and network with your peers and other Qualys experts to accelerate your career. To learn more about attending the Qualys Security Conference 2021 in person or online visit smashingsecurity.com/qualyslasvegas<a...
41:5911/11/2021
Yes, you heard that correctly. Two hundred and fifty
A game about Squid Game pulls the rug from under cryptocurrency investors in what appears to be a scam, PayPal hackers use a devious trick to break into 2FA-protected accounts, and have you received a job offer that's too good to be true?All this and much much more is discussed in this celebratory edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dr Jessica Barker.Plus don't miss our featured interview with the CEO and president of Qualys, Sumedh Thakar.Oh, and huge thanks to Darknet Diaries' Jack Rhysider, F-Secure's Mikko Hyppönen, The Cyberwire's Dave Bittner, and Host Unknown's Andrew Agnês, Thom Langford, and Javvad Malik for their special contributions to this episode.Visit https://www.smashingsecurity.com/250 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guests: Andrew Agnês, Dave Bittner, Jack Rhysider, Javvad Malik, Jessica Barker, Mikko Hyppönen, Sumedh Thakar, and Thom Langford.Sponsored By:Qualys: Qualys Security Conference 2021 is taking place in Las Vegas November 15-18 2021, and you can attend either in person or online.Hear from experts such as Chris Krebs, former Director of the DHS & CISA, learn strategies and tactics to secure your organization, and network with your peers and other Qualys experts to accelerate your career. To learn more about attending the Qualys Security Conference 2021 in person or online visit smashingsecurity.com/qualyslasvegas1Password: From start-up to enterprise, 1Password makes it easy for your team to store, generate and share strong passwords. The less time you need to spend dealing with hacks, phishing scams, and lost passwords, the better.Not just for IT and Security teams – all kinds of teams like Finance, HR, Legal, and Marketing can also store and share business credit cards, sensitive documents and shared logins in 1Password.<a href="https://www.1password.com" rel="noopener...
01:01:4704/11/2021
Devious licks, Netflix, and sensitive hackers
Ransomware attackers have got hurt feelings, what does Netflix know about you, and why are schoolkids stealing lavatory seats?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by 1Password's Matt Davey from the "Random but Memorable" podcast.Visit https://www.smashingsecurity.com/249 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Matt Davey.Sponsored By:Thinkst: Most companies discover they’ve been breached way too late. Thinkst Canary fixes this: just 3 minutes of setup; no ongoing overhead; nearly 0 false positives, and you can detect attackers long before they dig in. Go to canary.tools to find out why its Physical, VM and Cloud Based Canaries are deployed and loved on all 7 continents...Listeners who mail in referencing Smashing Security get a 10% discount on their order!1Password: 1Password has put its 15 years of security experience into creating 1Password University, a fun, dynamic, and free learning resource for people of all skill levels.Broaden your knowledge, starting with the basic building blocks of security. Learn at your own pace and learn how to create form an entire ecosystem of tools and tactics that help keep you safe on the internet.Whether you’re a business leader looking to create a culture of security in the workplace, or you’re just trying to understand why you need a unique password for each account, 1Password University’s growing catalogue of courses has something for you.Visit 1Password University for free online security resources, made for everyone.Support Smashing SecurityLinks:<a...
47:0627/10/2021
Press F12 to hack
A journalist is threatened with prosecution after choosing to "View Source" on a public webpage, Amazon Ring owners might be in line for a hefty fine if their neighbours complain, and is the school lunch queue a good place for facial recognition?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Visit https://www.smashingsecurity.com/248 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Dave Bittner.Sponsored By:1Password: 1Password has put its 15 years of security experience into creating 1Password University, a fun, dynamic, and free learning resource for people of all skill levels.Broaden your knowledge, starting with the basic building blocks of security. Learn at your own pace and learn how to create form an entire ecosystem of tools and tactics that help keep you safe on the internet.Whether you’re a business leader looking to create a culture of security in the workplace, or you’re just trying to understand why you need a unique password for each account, 1Password University’s growing catalogue of courses has something for you.Visit 1Password University for free online security resources, made for everyone.Support Smashing SecurityLinks:Missouri teachers’ Social Security numbers at risk on state agency’s website — St Louis Post-Despatch.Missouri governor vows criminal prosecution of reporter who found flaw in state website — Missouri Independent.<a...
45:3220/10/2021
Rickrolling submarine secrets
A married couple are accused of selling nuclear sub secrets, Facebook continues to make young lives a misery, and a school hacker lets loose one heck of a prank.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Visit https://www.smashingsecurity.com/247 to check out this episode’s show notes and episode links.Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes.Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Maria Varmazis.Sponsored By:1Password: With 1Password you only ever need to memorize one password. All your other passwords and important information are protected by your Master Password, which only you know. Take the 14 day free trial now.Support Smashing SecurityLinks:Maryland Nuclear Engineer and Spouse Arrested on Espionage-Related Charges — US Department of Justice.Couple charged with leaking US nuclear sub designs — The Register.Facebook will add new safety features, notably for teens, after whistleblower leak — CNBC.Unfollow Everything cease-and-desist letter from Facebook — Louis Barclay.IoT Hacking and Rickrolling My High School District — WhiteHoodHacker.Board Game Arena — Play board games online from your browser.Foundation — Official Trailer — YouTube.Foundation — Apple TV.<a href="https://filmcourage.com/"...
49:4913/10/2021