Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured…

Transcript

Read the transcript · about 11,450 words, follows along as you listen

Researcher:So we're gonna have a private conversation about our next crypto scam, and it would really be unfortunate if anyone had a recording of this.

Robot:Smashing Security, episode 485. These researchers got drunk to hack an LG TV with Graham Cluley and special guest Lianne Potter.

Graham Cluley:Hello, hello, and welcome to Smashing Security. Smashing Security, episode 485. My name's Graham Cluley.

Lianne Potter:And I'm Lianne Potter.

Graham Cluley:Lianne, welcome back to the show. Always great to have you here. Now, you are, of course, quite the aficionado when it comes to podcasts. You've got podcasts coming out of your ears, haven't you?

Lianne Potter:I'm a millennial. You have to have multiple podcasts.

Graham Cluley:But you haven't just got one podcast, you've got multiple podcasts. So you've got your Compromising Positions podcast, all about cybersecurity. Excellent, groovy stuff there. But you also do Tech Film Noir, where you are looking at old movies and seeing how well they've predicted future tech in particular, right?

Lianne Potter:It's just an excuse to watch the films I absolutely adore, mostly Arnold Schwarzenegger sci-fi movies.

Graham Cluley:Well, the latest episode you've put out is all about Weird Science, which was from about 1985, which hit me at precisely the right time. It was in my formative teenage years.

Lianne Potter:So does that explain it all then, Graham?

Graham Cluley:For anyone who hasn't seen it, it's about a couple of teenagers who decide to use technology to magic up the perfect woman in the shape of Kelly LeBrock.

Lianne Potter:And what a shape. That's all I have to say. Loving controversy on the podcast.

Graham Cluley:Goodness gracious me. They were like, Lianne, you know, we can't really do this podcast 'cause it's not age-grade. And I said, well, that's the whole point of this podcast, that it's not age-grade. The technology hasn't aged great and neither has the ethical quandaries. Oh, well, I haven't seen it for a while, but I remember I enjoyed it at the time. These couple of nerds, they boot up a Memotech MTX computer, a home computer, which wasn't very popular. And with it, they managed to create Kelly LeBrock. Now, the thing I have to tell you, Lianne, is I had a Memotech MTX computer.

Lianne Potter:Boom! My head just exploded. No, you didn't. Really?

Graham Cluley:I really did.

Lianne Potter:We should have got you on the episode.

Graham Cluley:My original home computer was the Sinclair ZX81.

Lianne Potter:Yeah.

Graham Cluley:But my dad actually got us a Memotech MTX. I can't remember if it was the 500 or the 512. They had different amounts of RAM in them.

Lianne Potter:Yeah, yeah.

Graham Cluley:And I wrote games for them. I have to say, the graphics were nothing like as good as— That was my next question. How does it compare? But it is a very nostalgic movie for me, 'cause it's like, oh my goodness, I remember this computer.

Lianne Potter:That's your life.

Graham Cluley:This was where I was at. It was fantastic.

Lianne Potter:Were you living the high life with 3 screens though, like this young lad does in the film?

Graham Cluley:Oh no.

Lianne Potter:'Cause I remember just thinking when I saw that, I was like, 3 screens, wow.

Graham Cluley:Who would need 3 screens? You've only got 2 eyes, haven't you?

Lianne Potter:I mean, it's—

Graham Cluley:2 feels like an extravagance to me.

Lianne Potter:Do you still have it or?

Graham Cluley:No, long gone, unfortunately.

Lianne Potter:Oh, such a shame, because we could do a follow-up episode and we could literally try and rebuild Kelly LeBrock from it.

Graham Cluley:I suspect that they go for a fortune on eBay now. They're probably very collectible.

Lianne Potter:I bet they are as well. Oh, that's so cool, Graham. That's really, really cool.

Graham Cluley:Anyway, before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, Intruder, and Vanta. We'll be hearing more about them later on in the podcast. This week on Smashing Security. We won't be talking about how scammers tricked Revolut into handing over customer data by posing as a government agency. You'll hear no discussion of how the Reddit account of HBO Max was hijacked by hackers to spread malware. And we won't even mention how the UK and United States have joined forces to take down global scam centres. So, Lianne, what are you going to be talking about this week?

Lianne Potter:Well, I'm talking about a piece of Android malware that, if it was an all-you-can-eat buffet, it would get kicked out for being too greedy.

Graham Cluley:And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs. Plus, we've got a featured interview with Andy Hornegold of Intruder, so look forward to that. All this and much more coming up on this episode of Smashing Security. This episode is sponsored by Intruder. Now, Joe, quick quiz. How often does your team ship code?

Joe:Multiple times a week. Maybe more if someone's had too much coffee.

Graham Cluley:And how often do you get a proper pen test?

Lianne Potter:Oof.

Graham Cluley:Once a year?

Joe:If we remember?

Graham Cluley:Well, that's the problem right there. Software moves weekly. Pen testing moves yearly. So most of what you ship never actually gets tested properly.

Joe:Which is exactly the gap Intruder's AI pen testing closes. You get the depth of a real manual pen test, but on demand whenever you need it. No scoping calls, no 6-week wait, and it costs a fraction of the traditional price.

Graham Cluley:It's built by Intruder's own certified pen testers, so the agents catch the complex stuff human testers can miss, and every finding is validated against your actual app. Real issues, not noise. You get an audit-ready report within hours.

Joe:And it plugs straight into Intruder's full platform — attack surface monitoring, cloud security, vulnerability management, all watching around the clock. It flags what's exploitable, what to fix first, and how, so your team can act without waiting around for the security team.

Graham Cluley:Over 3,000 companies already trust Intruder with their attack surface.

Joe:You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Graham Cluley:Ooh! So just head to intruder.io/smashing. That's intruder.io/smashing.

Joe:And thanks to Intruder for supporting the show.

Graham Cluley:Lianne, during your cybersecurity career, have you ever, or your staff, intentionally got a little bit sozzled? You know, something pickled, maybe legless, blotto, plastered. Has that ever happened to you?

Lianne Potter:I can confirm nor deny that alcohol is sometimes involved in the cybersecurity industry, just to lubricate the onion tours going down nicely.

Graham Cluley:I think I might be a little bit of an oddity in the industry because I don't drink.

Lianne Potter:You're like some sort of lizard, you know, you just kind of take in nutrients from the ground and stuff.

Graham Cluley:Perhaps. Well, the reason I asked if alcohol has ever helped you in terms of cybersecurity is it turns out sometimes there is an acceptable reason to get a bit pissed.

Lianne Potter:I'm looking forward to hearing what this is.

Graham Cluley:Pissed in the British sense rather than the American sense of being upset. So, there's a bunch of researchers. They've just published their research into LG TVs. Now, I don't know if you have one of those enormous TVs in your house, you know, the ones which cover about 90% of your wall.

Lianne Potter:I have been playing the LG game for quite a number of years as my TV of choice.

Graham Cluley:Okay.

Lianne Potter:So I'm very interested in what you have to say about this because I'm very scared.

Graham Cluley:Well, it seems to become the norm, doesn't it, to have a flashy smart TV leaving barely enough room for your sofa and your coffee table. And LG is one of the really major brands.

Lianne Potter:Yes.

Graham Cluley:Its TVs have been the subject of a deep dive investigation that's just been published on YouTube, because that's where you publish your cybersecurity research these days. You don't do a paper at Black Hat, you produce a video.

Lianne Potter:Because TikTok dances are all so last year now.

Graham Cluley:So this is up on the Gamers Nexus YouTube channel, and they wanted to find out what these TVs get up to behind the scenes.

Lianne Potter:What do you mean? Did they go off and get drunk or something?

Graham Cluley:No, it's not the TVs getting drunk. I mean, they can barely get out the front door, let's face it, they're so enormous.

Lianne Potter:They can barely navigate to Spotify half the time.

Graham Cluley:Well, they found some pretty jaw-dropping things about these tellies because I'm afraid it can impact your privacy as well as earning the TV manufacturers an absolute ton of cash, and raises the question of who actually owns your TV. So I asked about you and getting blotto, and the reason I ask that is this was key to how the team behind the investigation prepared for this research. So setting up an LG TV — in fact, any TV probably these days — requires you to accept its terms and conditions, right? There'd be some dialogue which pops up at some point and says, you can go and read 30,000 words of legalese.

Lianne Potter:Absolutely. Tons of pages.

Graham Cluley:Yeah.

Lianne Potter:That you're never gonna do.

Graham Cluley:You're never gonna do that. You just say, yeah, yeah, come on. I wanna see if the TV's any good.

Lianne Potter:Yeah.

Graham Cluley:So you click through. Now, we all know no one reads them, but of course you're kind of bound by those terms and conditions which you've agreed to. And one of the terms and conditions may say something like, you agree not to test the TV for security vulnerabilities and find flaws.

Lianne Potter:Killjoys.

Graham Cluley:Yeah, killjoys. Exactly. You agree not to reverse engineer any of the algorithms. But the investigators' lawyers apparently pointed out to the researchers, they said, look, you can't be legally bound by a contract which you agree to while drunk. Because you don't actually—

Lianne Potter:Ah, okay. I like — does this loophole apply to life?

Graham Cluley:Sadly not. Sadly, I don't think, sorry, my lord, I was completely plastered. I don't think that'll get you off anything, particularly bad driving.

Lianne Potter:No.

Graham Cluley:So the researchers, they decided that they would use this loophole. So they got plastered. And they were quite clearly very merry at this point.

Researcher:We have Ethernet plugged into Gamers Nexus LLC's TV. There you go. That Gamers Nexus purchased while it was inebriated heavily. It was unable to agree to the EULA. If a checkbox were checked. It was entirely accidental. Right. Yes. But we don't know if one had been checked. Unlikely. Because of the inebriation. Yes. Yeah. You see that Stanley Cup over there? It's just all margarita. Just the entire thing.

Unknown:So.

Graham Cluley:They've sort of accepted the agreement, but LG can't actually hold them to any of it. And that's rather brilliant, I think. So these agreements, they're so long, ploughing through them drunk isn't actually that different to doing it sober, I think. No one's gonna understand them. So what did these researchers find? Well, it's bad news for anyone who owns an LG TV, Lianne.

Lianne Potter:Damn it.

Graham Cluley:Okay.

Lianne Potter:Hit me with it. Hit me with the bad news.

Graham Cluley:Because your TV might be listening even when it looks like it's been turned off.

Lianne Potter:Listening how? Like to what?

Graham Cluley:So of course, smart TVs these days have microphones just like your— are we allowed to use the Alexa word? Are we allowed to say Siri and Google?

Lianne Potter:You've just set everyone off now.

Graham Cluley:You've set everything off. But like all those smart devices, TVs these days have microphones. So, you know, there is a way of commanding televisions through voice, and so they've got a microphone.

Lianne Potter:Yeah. There's a button that I press when I can't be bothered typing.

Graham Cluley:I suspect depending on your model of LG TV, it may be that you can give it a wake word as well, and you could actually just talk to it.

Unknown:I'm not sure.

Graham Cluley:It depends on the TV. So in one test, these researchers staged a fake whispered conversation about a made-up crypto scam right in front of their TV, a TV that looked entirely switched off.

Researcher:So we're gonna have a private conversation about our next rug pull crypto scam, and it would really be unfortunate if anyone had a recording of this. All right, so the screen appears to be off right now. Currently, Wendell and I are in a boardroom to discuss our new crypto coin rug pull scam. We don't want anyone to hear about this. We trust that no device in the thing is listening because of the appearance here. And right, definitely things capturing video and audio surreptitiously would be very bad. Well, the only device in this room is the TV and it looks like it's off. It sure does look like it's off. So the plan is we're gonna launch the coin, we're gonna let the price go up, then we're gonna sell all of our tokens and rug pull everyone.

Researcher:Rug pull coins. Yeah. I mean, how else would you do a crypto? I hope they don't hear about it.

Graham Cluley:The screen was black.

Lianne Potter:Mm-hmm.

Graham Cluley:There were no lights on. And afterwards they found that entire conversation. It saved it onto the actual TV.

Unknown:Word for word?

Graham Cluley:Word for word. It had been transcribed into the TV.

Lianne Potter:I mean, anyone with headphones on, Grim, how low was this whisper? Was it like this big?

Graham Cluley:It is extraordinary, isn't it? Some of these smart devices, they can hear you even when you whisper from the corner of a room, sometimes even when you're playing music.

Lianne Potter:I can barely hear other people when they whisper.

Graham Cluley:You need ears like an LG TV.

Lianne Potter:Exactly.

Graham Cluley:In another test, this TV picked up someone's voice clearly from around 70 feet away through a wall. Now, how big does your TV have to be for you to want to sit 70 feet away? I can't imagine, so I can't understand the use case for that. Now, to be fair, that particular demo and the fake crypto conversation one, they required the researchers to first exploit vulnerabilities. To hack their way into the TV, which they were allowed to do because they were drunk when they went through the terms and conditions.

Lianne Potter:And we all know that hacking is so complicated nowadays. And you know, you need lots of expertise to be able to do that. So it's totally unfeasible that this would happen.

Graham Cluley:Yes. Or you need an AI account maybe to look for the vulnerability as well. So what they were proving was that this capability existed inside these televisions for a listening device to be built without your knowledge if someone with the right access, or should we call it the wrong access, wanted to do it. So it had the capability to do that, even if you weren't pressing the button, even if you were 70 feet away, even if you weren't known. So why do these TVs have the functionality to listen to you? And it isn't, Lianne, so you can say, play the latest series of Game of Thrones or whatever it is that you wanted to watch.

Lianne Potter:Play the latest episode of Smashing Security.

Graham Cluley:Oh, such a crawler. Now, I'm sure you and lots of our listeners can guess what this is all about. It's about targeted advertising. So modern smart TVs, they make a lot of their money, if not more of their money — if you actually look at their financial results — not from selling you the boxes, but from selling advertisers information about you and giving advertisers access to you as well.

Lianne Potter:So did they sit around in the marketing discussion and they were just like, do you know how people are always really paranoid that their smartphones are listening? How about we take that to the next level and make it a dream come true?

Graham Cluley:Exactly. Let's have something else which people have around them a great proportion of the day. And if the TV knows what you watch and it knows who else lives in your house and what other gadgets they own, that data has enormous value, of course. And these TV manufacturing companies have entire divisions who are devoted to monetising the data in that way. So the business model of a modern smart TV is built around watching you back.

Lianne Potter:Not literally though, right? Not like with cameras and stuff?

Graham Cluley:Well, not with most of them, no. And not in this particular test.

Lianne Potter:This is where you tell me it's got some sort of dolphin echolocation that when you're talking, it can see your shape.

Graham Cluley:Oh my goodness. That is a brilliant idea.

Lianne Potter:Oh no, you're watching TV with your hands down your pants like Al Bundy from Married... with Children again.

Graham Cluley:So, LG executives, they're shown in this video up on YouTube saying that LG owns the glass, meaning the screen that you paid £2,500 for, isn't really yours. It belongs to LG. You are just borrowing it. Another big issue is that the TV knows about your whole home, not just you. So the researchers discovered that these TVs are quietly scanning people's entire home networks, building a list of every device connected to the same Wi-Fi. Yes, you may well gulp at the thought of that. So—

Lianne Potter:Yeah, I did. A lovely non-visual medium, but I was just like, ugh, okay.

Graham Cluley:So phones, your smartwatches, they even picked up a 3D printer — Lord knows what they're gonna do with that. So this was regardless of whether those devices had anything to do with the TV at all, they were being picked up. And it was also picking up other nearby Wi-Fi signals. So it was enough information potentially to work out roughly where in the world somebody physically was, which of course is useful in terms of sending out targeted advertising as well.

Lianne Potter:So I wasn't far off about echolocation then.

Graham Cluley:The good news is you don't have to worry about this because TVs have got privacy controls, right? Right, Lianne?

Lianne Potter:Right, right, right. We all know that companies love a good privacy control.

Graham Cluley:So on the LG TV, these researchers tested the button, which basically said, don't sell my personal information, don't be a bad guy. Now that was turned off by default, and that was before the TV had even been connected to the internet. So it wasn't possible to connect to the internet initially with that option turned off. So when you retrospectively disabled the collection of that private data, that wasn't any good either, because when the researchers told the TV to delete their voice recordings, the recordings remained. They only actually disappeared when the TV was completely unplugged from the wall — a complete and utter power-off, like pull the plug, not just the internet connection, not just the aerial or whatever you might have. Pull the plug out of the wall, and then that information would be wiped.

Lianne Potter:This is where Martin Lewis, the money-saving expert, would be like, oh, I've been telling you for years to unplug your devices and save a bit of money.

Graham Cluley:Save yourself 13 pence.

Lianne Potter:Save yourself 13 pence, and then now save yourself from having all your data sold.

Graham Cluley:And ticking this box marked Delete My Data didn't actually delete your data. But it gets worse than that. Again, this next bit comes from the same sort of hacked rooted TV, which they meddled with rather than one fresh out of the box. They found with those modified units, even when they pulled out a network cable and physically pulled it out, so there was no internet connection at all — it wasn't connected via Wi-Fi, wasn't connected via an ethernet cable.

Lianne Potter:All the things you'd expect. Yeah.

Graham Cluley:The TV would carry on quietly recording and storing everything it picked up. And the moment you plugged the network back in, what do you think happened?

Lianne Potter:Was it party time at data and marketing HQ at LG?

Graham Cluley:Yeah, yeah, because all of that stored data got sent straight up to their servers again. So it'd been sort of waiting for the chance. So unplugging your TV from the internet isn't really the safety net you might hope for. The TV doesn't need to be online at the moment it's listening to you — it just needs to be online eventually.

Lianne Potter:Wow.

Graham Cluley:Now, to be fair to LG, they dispute a lot of this and the seriousness of a lot of this. Their official line is that the TV only processes your voice when you deliberately press the button on your remote, like you were describing, or you say a wake word. They say that any tracking features require you to opt in first, which sounds really reasonable. But then you go and watch their marketing material of their advertising division, which is so boastful about all the data they're collecting when they're speaking to the big advertisers, like, we know everything about people.

Lianne Potter:I can imagine.

Graham Cluley:Yeah. So some people will think, well, you know, does this really matter that much? But it does because you're not just sharing that data with advertisers, as we've talked about before. Law enforcement agencies can quietly buy up this data and they can find out about your location, your behaviour.

Lianne Potter:Also, a lot of these organisations hiring contractors and stuff like that. You know, that don't work for the company and you can't really — not casting aspersions on contractors — but you can't really control what they do. And so if they take a shine to listening in onto certain conversations, what's gonna stop them?

Graham Cluley:And the fact that these TVs are vulnerable to security vulnerabilities, which have apparently been reported to LG now by these researchers who are able to do all kinds of hacks, means that potentially a criminal could break into a TV. It's a TV which knows what you're watching, knows who's in the room, it knows roughly where your house is. It makes you a more valuable target, I think, than someone who's just in the market for travel insurance or trainers or a different breakfast cereal.

Lianne Potter:Because how many times have you sat in your living room and phoned up your bank and your bank says, okay, give me your card details so that I can find your account. Speaking to other providers and giving them account details and other things like that. Really private, personal conversations. Lots of lovey-dovey time on the sofa.

Graham Cluley:Imagine you're the CEO of an organisation and you're about to do a merger or an acquisition or a big announcement. A hacker could come in.

Lianne Potter:You just wanna watch an episode of Neighbours, calms you down just before a big presentation. Yeah, absolutely. It's gonna be terrible.

Graham Cluley:Imagine you're a politician.

Lianne Potter:Well, that's what I was thinking. I was thinking the scariest use case here would be espionage and very high-profile targets.

Graham Cluley:Yes, these sort of things do happen. It's not the first time we've talked about smart TVs being used for something other than watching TV.

Lianne Potter:Mm-hmm.

Graham Cluley:So it can be done for bad. Regular listeners will remember just a few episodes ago, we were talking about residential proxies. Turns out these LG TVs are vulnerable to this kind of thing where other people's internet traffic can get quietly routed through your home connection without you realising, making your IP address look like the source of whatever they are up to. And sure enough, these LG TVs are vulnerable to that. Nearly half of the apps they tested in LG's own app store had the ability to turn your TV into exactly that kind of proxy.

Graham Cluley:So on top of everything else, there's a decent chance your smart TV has been helping someone else disguise themselves on the internet. So having depressed everybody, what can you do about this? And the advice from the researchers seemed straightforward. I was reading this and I thought, well—

Lianne Potter:I'm waiting with bated breath, obviously.

Graham Cluley:All right. So what their advice is is that you don't use the smart features of the TV itself. What you should do, they say, is why don't you use a separate streaming stick? Amazon Fire Stick is the most famous one. If you want those smart features rather than using the apps which the TV manufacturers themselves have built into the operating system.

Lianne Potter:Okay. Yeah.

Graham Cluley:Now, the reason why I'm slightly nervous about that is of course, who's to say that Amazon can be entirely trusted as well?

Lianne Potter:Or any of them, yeah.

Graham Cluley:Maybe there's more eyes watching them as opposed to 5 Eyes watching them.

Lianne Potter:Which one is the lesser of the evils of all of them?

Graham Cluley:Yes, it's difficult, isn't it? So that was the advice which came out from the video is you may want to do that.

Lianne Potter:I think my mum had better advice, to be honest, because what she used to always tell me is, don't watch too much TV, it'll rot your brain. But really, don't watch too much TV because it'll steal your identity.

Joe:This episode of Smashing Security is supported by ThreatLocker. Agentic AI is beginning to change the tempo of cyberattacks.

Graham Cluley:Ransomware that thinks for itself, worms that rewrite their own playbook mid-attack, agents happily chaining exploits together without ever pausing to ask a human, is this all right?

Joe:Which is all very interesting, just so long as it isn't your network they're experimenting on.

Graham Cluley:And that's the problem. When a machine can scope out your network, break in, and start creeping sideways through it faster than you can finish your coffee, you can't rely on the hope that someone will notice the alert eventually. And this is where ThreatLocker earns its keep. Default deny and least privilege sit right in the agent's path, so nothing runs just because it asks nicely. Application allowlisting decides what's even allowed to execute. Ring-fencing keeps trusted apps from wandering off and touching things they shouldn't. And privileged access management quietly confiscates the elevated access nobody needed in the first place.

Joe:The attacker may be moving faster, but the controls are already in place. Agentic AI doesn't make established security principles obsolete; it makes getting them right considerably more urgent.

Graham Cluley:So while the attacks are picking up speed, make sure ThreatLocker is already standing in the way. Head to threatlocker.com/smashing to find out more and grab your free demo.

Joe:That's threatlocker.com/smashing, and thanks to ThreatLocker for supporting the show.

Graham Cluley:Lianne, what's your story for us this week?

Lianne Potter:So, you know how all the frontier AI companies are now saying, let's slow down on superintelligence? I think we in cyber need to get together and have a really hard, long look at our malware naming conventions.

Graham Cluley:Okay.

Lianne Potter:So today I'm going to talk about MantaXotax.

Graham Cluley:I beg your pardon?

Lianne Potter:MantaXotax.

Graham Cluley:Is that all one word?

Lianne Potter:No, it's 2 words.

Graham Cluley:Okay.

Lianne Potter:I think I'm saying it correctly. But it made me think about whoever named this strain of malware was just looking around the room and saw a man and maybe their tax return and was just like, that's the name of this strain of malware. So I Googled it because I thought, does this mean something really special or clever? And it is an Indonesian piece of malware. And in Indonesian, Mantax means awesome.

Graham Cluley:Oh, okay.

Lianne Potter:Which got me thinking and actually got my goat, because remember last time I was on, I was talking about the phishing service as a platform called Greatness. And honestly, who is naming this stuff? Cybercrime brought to you by the makers of Live Laugh Hack signs. Sorry, I'm digressing here, but cyber naming conventions is just such a touchy subject for me. Awesome for a malware, Greatness for a phishing as a service platform — our naming conventions suck. It's an embarrassment. That's not the story though. I just needed to get that off my chest.

Lianne Potter:So a few days ago, it was disclosed that MantaXotax is a horrible little bit of Android malware that is doing the rounds. But there's something a little bit special about this one, because malware tends to specialise. So you've got malware that does info stealing, you've got your RATs, you've got your spyware, you've got your ransomware, but MantaXotax — I'm just going to call it Mantax going forward — apparently looked at all those and went, why should I choose between those?

Lianne Potter:Why don't I just use all of them? So this piece of Android malware can nick your texts, your contacts, your browser history, your WhatsApp and Telegram data, grab screenshots, record your screen, take photos using your camera. And just when you're thinking, well, that's quite bad, it then encrypts your files and demands a ransom.

Graham Cluley:Quite bad? I'd say this is worse than having an LG TV.

Lianne Potter:On the scale of things, perhaps. It gets worse.

Graham Cluley:Okay.

Lianne Potter:So the cybersecurity experts are calling this a new Android malware cybercriminal cocktail, partly because it mixes ransomware and malware into a lovely fusion-style drink, but also because once it hits you, your phone ends up shaken, stirred, and absolutely on the rocks.

Graham Cluley:My goodness.

Lianne Potter:And it's interesting because it's spread through dodgy APKs, through Telegram channels, forums, and phishing rather than the official Google Play App Store.

Graham Cluley:Oh, okay. So if you sideload an app onto your Android phone, rather than going from the Google Play Store, you could potentially install this piece of malware.

Lianne Potter:Correct. And apparently it's really nasty on old versions of Android too. So as I say, it's an Indonesian flavour of malware. And how it works is, you don't go through the Google Play Store — you're likely to get this sent to you by phishing or through socially engineered messages. Again, through WhatsApp and Telegram. And once you install it, the malware asks for permissions to use your accessibility services, and then once it's got that, it pretty much has control of everything it needs to compromise your device.

Lianne Potter:And then in typical malware style, it pings to a command and control infrastructure, sends the data of the victim back to its location, and then it starts going rogue. It starts everything that's in a cybersecurity textbook. You know, as I say, remote control, locks your screen, collects all your passwords, especially one-time passwords if you get SMS messages through there, everything. But what is a bridge too far in this case is it's also got something called harassment features. So if your day wasn't rude enough about your phone getting locked and full of malware and ransomware, they actually added in — and this is an actual line of code, it's literally called this — jump scare.

Graham Cluley:Jump?

Lianne Potter:Not like in horror movies, jump scare. So they know exactly what they're doing — it's literally a line of code called jump scare. And for an extra bit of spice in your awful day of getting your phone owned, they send you rapid full-screen videos and images, and they even use text-to-speech messages played through the device's speakers, screaming at you, shouting at you. So this isn't just your typical malware strain. For me, it's a reminder that the Android ecosystem is a bit like the devil's playground, really. I mean, if you're going to sideload random apps from places like Telegram, then you're basically the cybersecurity equivalent of getting a drink from someone called Kevlar Dave in a nightclub that you've never met before. So the piece of advice to avoid this is to make sure you have an updated operating system, because as I say, the old ones are hit hardest, which is just true to life, I think. Basically, don't install random crap from Telegram.

Graham Cluley:Yeah. So this jump scare, which it displays — I imagine that isn't something which happens while it's stealing your data. That's after they've encrypted you. This is an extra inducement to pay the ransom, I imagine. It's like, my phone has gone completely haywire.

Lianne Potter:It would scare the crap out of me. Yes. It happens afterwards. So once they've done all the little cyber hacking in the background, they decided to go one up and start turning your device into a haunted device, I guess.

Graham Cluley:Yeah, it'll be like it's possessed.

Lianne Potter:Yeah, yeah.

Graham Cluley:Absolutely horrendous.

Lianne Potter:We need to get the Ouija board out and that little lady from Poltergeist to come and help.

Graham Cluley:Now, of course, some Android phones are notoriously worse at getting the latest updates to the Android operating system compared to others, aren't they? So if you've got a cheap phone which has been lying around for a few years, maybe it's no longer supported.

Lianne Potter:But I don't know about you, but I've worked with clients and Android devices are used in so many other things that are not just phones as well. Like keypads at petrol stations and things like that. And they almost never get updated. So all it would take would be for someone to install something similar on these devices and then it's game over again.

Joe:This episode is supported by Vanta.

Graham Cluley:Joe, what's the thing that keeps you up at 2 o'clock in the morning security-wise?

Joe:Honestly, whether I remembered to hit the record button. No, no, no.

Graham Cluley:I mean a real worry. Have I got the right controls in place? Can I actually trust my vendors?

Joe:Nope. I'm still worried we might not actually be recording.

Graham Cluley:Try this one for size. How do I ever climb out from under all these clunky old tools? Okay, fair enough.

Joe:That does sound scary.

Graham Cluley:Well, that's where Vanta comes in. It takes the manual misery off your plate. So no more wrestling spreadsheets, hunting down audit evidence, or slogging through endless questionnaires.

Joe:That's right. Their trust management platform continuously monitors your systems, centralises your data, and uses AI to flag risks and keep you audit ready all the time.

Graham Cluley:Going for SOC 2, ISO 27001, GDPR, HIPAA, whatever it is, Vanta gets you there faster and lets you scale with confidence.

Joe:And actually get back to sleep.

Graham Cluley:Head to vanta.com/smashing to get started. That's V-A-N-T-A.com/smashing. And our listeners get $1,000 off.

Joe:And thanks to Vanta for supporting the show.

Graham Cluley:Joe, the record button, you definitely pressed it this time, right?

Joe:I thought it was you.

Graham Cluley:And welcome back, and you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week. Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they wish. It doesn't have to be security-related necessarily.

Lianne Potter:Better not be.

Graham Cluley:Well, well, well, Lianne, I know you're a cyber anthropologist, but are you also a vexillologist?

Lianne Potter:Well, I'm currently looking at the League of Lexicon game that we discussed as a previous pick of the week. That word is not in my vocabulary. Please explain.

Graham Cluley:Well, a vexillologist is someone who loves the study of flags.

Lianne Potter:All right. Okay.

Graham Cluley:And we have an international audience listening to Smashing Security. Certainly here in the UK, flags have become a bit of a hot topic.

Lianne Potter:A bit, yeah, it's a bit controversial to have one out.

Graham Cluley:Yeah, well, yes, exactly. Some people are very keen on particular flags. Some people have even been termed as flag shaggers to indicate their love of flags.

Lianne Potter:Yeah, I find it so interesting when you speak to people from other countries, when you tell them that, it blows their mind, 'cause I think it's quite unique to the UK, that.

Graham Cluley:It is a strange thing. Yeah, sometimes flags are great. Sometimes I will see a flag outside the window of a pub, and it'll all be stripy and rainbow. And I think, well, that's lovely. Everyone loves a rainbow, don't they?

Lianne Potter:Absolutely. There's a nice flag, you know, blowing in the wind at a pub that says, no LG, you know, LG with a cross in it. And you're not going to be welcomed in this pub.

Graham Cluley:Last night, I watched Last Night at the Proms on the BBC.

Lianne Potter:Lovely.

Graham Cluley:It's lots of fun. Last night at the Proms, at one point, the magnificent tenor Nicky Spence, he unfurled his kilt mid-song to reveal—

Lianne Potter:To reveal what, Graham?

Graham Cluley:What did you reveal? To reveal the LGBTQ flag.

Lianne Potter:Okay.

Graham Cluley:Right? And I thought, that's great. So there we've got lots of flags, everyone having fun, music bringing everyone together. That's all good in my mind. But sometimes you can be baffled by a flag. Sometimes you see a flag and you say, what is that kind of flag? And that is where my pick of the week this week comes from. It is a website called flaglookup.com. And what it does is it helps you identify flags, not by name, but by what they actually look like. So you can search by a colour or a shape or a symbol. You can say, oh, it's got a crescent or a circle or a stripe, and it will narrow things down for you.

Lianne Potter:Oh, that's really good, actually. Yeah. Obviously, you can't look up a flag name if you don't know where it is.

Graham Cluley:Exactly. You'd have to look through hundreds and hundreds. So they've got basically all the flags of the world and all of the US states. And by the way, some of the American states have got bonkers flags. They may have a sea lion perched on top of a tricycle or something.

Lianne Potter:I don't know if you're being serious or not.

Graham Cluley:It's not that far off the truth. But anyway, flaglookup.com. It's completely free. No one's trying to sell you anything. It's a genuinely handy tool that sort of answers that problem where you go, well, whose flag is that? And then you can find out. And that is my pick of the week. Lianne, what's your pick of the week?

Lianne Potter:So, when murder cases go cold, we can always find a trusty nerd with AI to solve it, which is a phrase I think we're going to be hearing a lot more of going forward. Now, Graham, are you into your true crime?

Graham Cluley:Well, not—

Lianne Potter:Is it because you're not a middle-aged woman? Is that what—

Graham Cluley:I think I'd rather have fictional crime than true crime. Sometimes I feel like it's sort of glorifying and enjoying too much other people's misery.

Lianne Potter:Well, welcome to my pick of the week. Well, all right. Okay.

Graham Cluley:Okay.

Lianne Potter:Well, I do enjoy true crime, but what my pick of the week is going to be about is, everyone's going gaga for OpenAI cracking that 92-year-old maths problem in less than 100 hours, right? Well, my pick of the week explores Alex Barber and Michael Connelly as they show us the receipts using AI to solve a murder mystery that has been going on for decades.

Graham Cluley:Right.

Lianne Potter:And this mystery is where citizens detectives try to solve not one, but two of America's famous cold cases, the Black Dahlia case and the Zodiac Killer.

Graham Cluley:Ah, they're both famous, aren't they? Yes.

Lianne Potter:Yes, yes. And this podcast called Killer in the Code is one of those really sharp, oh my God, I must continue to binge this kind of podcast. It's all about how they used AI to break these ciphers. Are you familiar with the Black Dahlia or Zodiac Killer cases?

Graham Cluley:So the Zodiac Killer, if I remember correctly, he was sending coded messages to the police.

Lianne Potter:Yeah. Taunting them in the '60s.

Graham Cluley:So for years, people have been trying to decode them or try and work out the identity of who's behind it. The Black Dahlia, I think that was from an earlier time. So was that from the '30s or the '40s?

Lianne Potter:So the Black Dahlia was 1947, and that was Elizabeth Short. The Zodiac Killer worked in California — call it work, I don't know. Both acted in California as the Dahlia Killer was also in Los Angeles. It was really brutal and it remained unsolved. But there's been a lot of discussion and speculation about whether these are — yeah, yeah — because they have a very similar MO. Now, some of the Zodiac Killer's ciphers were cracked pretty quickly at the time during the '60s. But there was one big case, and when I was checking pick of the week for this to make sure no one else had had it on, you actually talked about this in a really old episode in 2020.

Lianne Potter:Oh. It was because one of the ciphers actually, decades later—

Graham Cluley:Had been cracked.

Lianne Potter:Had been cracked, yeah.

Unknown:Yes.

Lianne Potter:The Z340 cipher, or 340 cipher. But there's one remaining, and it's the Z13, because it's only 13 characters long. And basically, all the cipher cryptologist boffins have been scratching their heads for years saying, I don't actually think this could be cracked, because it's too short.

Graham Cluley:Yes.

Lianne Potter:And it's known as the My Name Is cipher, because the killer literally wrote, "my name is," and then put the cipher in. So if you crack this one, you've basically cracked the most notorious serial killer case ever.

Graham Cluley:The answer isn't Slim Shady, is it?

Lianne Potter:It's not, but I'm not going to reveal the answer. Because they say it's uncrackable until now. And that's what this podcast is about. So they used AI to basically crack this cipher, but then used lots of investigation sources that weren't used during the original investigation in the '40s and the '60s to make a very, very compelling case of who they think it is. And it does suggest that the Black Dahlia killing and the Zodiac killing are by one and the same person. Unfortunately, that person has now passed away, so they can't ask him.

Graham Cluley:Fortunately, he's passed away.

Lianne Potter:Well, he doesn't get brought to justice, does he?

Graham Cluley:I suppose not.

Lianne Potter:But what is really interesting, in one of the episodes, they go to the family and they show handwriting from the Zodiac Killer, and they're like, that's my dad's handwriting.

Unknown:Oh.

Lianne Potter:So people who actually used to work in the FBI on this case when it was a live case, and then later on when it became a cold case, because you get allocated cold cases if you've not got enough work to do and things like that. And they're all saying, actually, the evidence is so compelling. Compelling that this person is this person, and they think it's now solved because they solved the cipher, and then all this other evidence combined that they found over the episodes, and it's still ongoing. Every week there's something new coming out.

Lianne Potter:The Zodiac Killer case might be solved along with the Black Dahlia murder. And as I say, it's my pick of the week because if you like true crime, if you like a mystery, if you like your tech, then you're gonna love this podcast. It's so bingeable.

Graham Cluley:It sounds really interesting. As with many things AI, I do tend to feel like there are good things AI can be used for, but do we want to trust it with everything? And do we want people to rely upon it to solve crime? Maybe we do to an extent, but maybe we also want to be a bit careful not to trust it too much. But by heck, it sounds like a hell of a story. And yeah, I'll certainly be tuning in.

Lianne Potter:Well, yeah. So there is a question about, you know, is this guy just randomly pattern matching and just got lucky? But with all the other evidence, and I would say the same, with all the other evidence though, it makes a very compelling argument. And there's a lot of people in that community, particularly the Zodiac Killer community, who have kind of written books about who they think it is. They're pretty cheesed off about this podcast. Like, well, that just blows all my suspects out the water. And so they address actually these people coming forward saying, I don't think it's this person because of this and this and this. But then they go, boom, voiceover evidence. So it's really, really compelling.

Graham Cluley:Fantastic. Well, we've got some time right now to hear from an expert — we're joined by Andy Hornegold. He is the Chief Security Technologist over at Intruder. Andy, thank you very much for joining us today.

Andy Hornegold:Thank you very much for having me. Appreciate it.

Graham Cluley:Now, for anyone who hasn't come across you before or Intruder, can you give me a quick summary of what Intruder does and who it's for?

Andy Hornegold:Yeah, absolutely. I'm the Chief Security Technologist at Intruder. Been at Intruder for five years, and my background is pretty heavily in the offensive security space. So previously I was at Mandiant, where I was the EU Red Team Lead. Intruder's mission is to essentially prevent breaches before they start. We focus very heavily on that initial access side of things, where we're trying to find weaknesses and exposures that may result in a breach, and we're trying to help our customers solve those problems and remediate those risks as soon as possible. So essentially reducing that window of opportunity for attackers down to zero seconds. I suppose the customers that we resonate most with are that mid-market space. So mid-market, smaller customers. Pretty much the whole product has been built to service those kinds of businesses. We try and make it as simple as possible so that you don't need to be a cybersecurity expert to use Intruder and protect your business.

Graham Cluley:So you say that Intruder's focused on this sort of mid-market space, medium-sized businesses. What makes those kind of businesses more vulnerable than a larger enterprise, which may have a full security team?

Andy Hornegold:It's interesting. We've published a little bit of research recently, and when it comes to risk, we seem to find that the large enterprises generally, on average, they're fixing risk and exposures quicker than that mid-market. And as you think about it, it kind of makes sense. You have more people able to shoulder the security burden, as it were. You have larger security teams, larger budgets. But as we move more towards the mid-market, that's not necessarily true. Conversely, as well, if we think about small businesses — you know, one-person, two-person, five-person companies these days — traditionally they're using cloud infrastructure, they're using Git repositories, their application code is available. And if you're small, you're able to act super quick as well, because you know your application, you know your business. If you have some idea of what the risk is, you're able to fix it and act on it really quickly. But that mid-market has this almost bell curve where that time to fix increases, because I suppose you're hustling, you're trying to keep the business going.

Andy Hornegold:You don't have the same kind of budgets that enterprise customers have. You don't necessarily have the time and knowledge of the whole business that you would have done when you were a smaller business. So you get this strange little increase in the middle where time to fix and potential exposure — they stay open for longer. The interesting one as well, right, is that large enterprises historically, yes, they're able to spend money on the security problem, but these days pretty much every organisation is pulling in data from smaller businesses. They're in the supply chain, right — they're able to get in. And part of that is, how do you make sure that that supply chain is secure and those smaller businesses are secure? Because frankly, if you're a threat actor, it's pretty cost prohibitive to go after these huge enterprises. But the weaker underbelly is, can I hit that mid-market instead and find a way to pivot into the larger organisation? Or is there just more value in that mid-market?

Graham Cluley:And of course, these larger companies who are working with medium-sized companies and smaller businesses, they are demanding that those smaller companies do have decent cybersecurity.

Andy Hornegold:Absolutely.

Graham Cluley:Otherwise, you're simply not going to get the contract, are you?

Andy Hornegold:Exactly. There are obviously the two driving forces — there are multiple, but there's the compliance requirement, the regulatory requirement. If you're in any of those highly regulated fields, you'll have a regulator breathing down your neck telling you we need you to make sure that all of this stuff is of a certain security threshold or risk threshold. But then you're absolutely right. Those smaller businesses in that mid-market, usually the main driving force these days for people to start on their security journey is we need a contract over the line, and that customer that is potentially going to sign the contract has asked us for proof that we're doing vulnerability management, attack surface management, exposure management, or at least the pen testing to prove that there is some level of security baked in.

Graham Cluley:Now, every time I go to a security conference or I give a talk, the one topic which keeps on coming up, the thing that everyone is talking about, is of course AI and how it is being used to power cyberattacks right now. In plain terms, from your point of view, what's actually changed for attackers this year? Is it happening in the real world already from your point of view, or is it still more of a worry for the future?

Andy Hornegold:It's funny. You can see from the Unit 42 — Palo Alto's report recently — where they've shown that end-to-end exploitation from initial access to full ransomware in six hours, with seemingly almost no one in that loop, or at least someone being able to move at significant pace through that environment, has happened. There's also — I believe it was GTIG over at Google — a released review of an incident they investigated as well. So I don't think we can say that they're going to get faster in the future — it's certainly here, it's certainly happening now — whether it's as be-all and end-all and the world is ending and the foundations are crumbling, whether it's that bad at the moment, I don't necessarily think that's the case, but we are definitely seeing those threat actors move quicker. And over the last eight months, it's definitely started to build up and become more of a thing.

Graham Cluley:And of course, AI isn't just a tool for offence, it's a tool for defence as well, which is a nice way to talk about something Intruder's actually done about this. You guys have just launched a tool that uses AI to test websites and apps for security holes the way a hired hacker would. Can you talk me through what that actually does, what it can find that an older style automated scanner or even a real human tester might miss?

Andy Hornegold:Yeah, absolutely. This whole topic is just fascinating. When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism. There was a lot of conversations internally within the company about how effective is this really going to be? We're using a non-deterministic machine to try and find vulnerabilities and weaknesses within these applications. And the more we talked about it, the more we realised how much of that is really different from having one consultant, one year pen test your application, to a different consultant on the second year pen testing your application. They're going to have different approaches. Things are going to be slightly different. So this whole topic is really fascinating where we've had conversations from people saying AI pen testing isn't going to be as good as human-led pen testing. Now, I don't think that's necessarily true. I think there are differences between the two. And as AI progresses, as these services become more established, I think that day-to-day or almost routine pen testing that happens of things like web applications is going to be handed over to more AI-led pen testing so that human pen testers can focus more on the interesting cutting edge, the kind of things that require expertise, not just experience, to be able to validate and make sure there is an appropriate level of assurance in those environments.

Andy Hornegold:But we've started essentially building this AI pen testing platform. It is no human in the loop. We have obviously QA processes that sit outside of that cycle of pen testing, but the results we're getting are pretty incredible. And they're pretty incredible because, A, the methodology we've taken has been more of a code-assisted approach. We're not just doing uninformed traditional black box pen testing. It is informed pen testing, which obviously means you're able to find more vulnerabilities in the source code, and then you're able to validate that those findings truly do exist or don't exist by carrying out attacks against the live application. So if you think about human pen testers, Graham, I don't know about you, but when it came to doing code reviews historically as a consultant, code reviews were always the thing everybody shied away from. Nobody in the consulting pool wanted to do it, right? And it's because you have to learn 3 million lines of code to work out where there are potential attack vectors. How does it all bolt together? That takes time. With a day rate from a consultant, it can take a serious amount of money as well.

Graham Cluley:Yes.

Andy Hornegold:But the way models work these days is you can very easily scale up hundreds of agents to fully ingest 3.1 million lines of code, and it can draw those attack paths and those attack vectors through the source code significantly quicker and more effectively than giving a human who is unindoctrinated into your codebase, just dumping it in their lap and being like, find all of the vulns and off you go. So we're finding that actually the results we're getting are incredible. They're really cool because we've had people who have been doing pen testing annually for every year for maybe 5, 6, 7 years. Now, obviously we support that mid-market. We have a long tail of customers who are on the smaller side of things, so they aren't going to the full security process that maybe an enterprise customer is.

Andy Hornegold:But what we're finding is hundreds of vulnerabilities that have been sat in those code bases for years. That's mostly because of the methodology we take, which is the white box approach. So we can find more of those vulnerabilities in a shorter timeframe. We then validate them against the real live application, so you reduce any hallucination or false positives.

Graham Cluley:That's what I was interested in, because I was thinking a security test is only as useful as how accurate it is, right? So you're not just dumping a great big pile of maybe real, maybe fake hallucinated issues onto the team to go and explore.

Andy Hornegold:Yeah, absolutely. We obviously benchmark our whole platform against an eval suite, which allows us to validate any changes we make. We are either increasing accuracy or recall to allow us to essentially progress rather than fall back to potentially worse results. Now, we do run the frontier models just without any of the harness that we have, because we want to validate and make sure that the pen test that we're delivering is providing better results than, say, a customer just running their chosen coding agent across their code base to be able to find vulnerabilities. And you're absolutely right. When you just run those agents across your code base without the validation step, you do find a huge number of false positives and you'll find people inundated with things that don't exist.

Graham Cluley:That's reassuring on the accuracy side, but there's also a trust question, isn't there? Whenever you let a piece of software loose testing a live real-world system, is it actually as safe to let an AI do this kind of security testing as it is to have a trained person do it?

Andy Hornegold:It's one that we battle with. It's a constant debate, I think, within security, but also within Intruder ourselves. I think historically human pen testing has never been low risk, right? I'm a pen tester. I could have all of the expertise in the world, all of the experience in the world. I'll run one command or I'll try one injection payload that I think is benign, or I think is not going to have an adverse effect on the target that I'm testing. But there is some weird logic in the background, and suddenly the entire system goes offline. And it happens.

Andy Hornegold:It's happened to me. It's happened to a bunch of people that I used to work with. But you have controls in place to make sure that any impact during that human-led pen test is minimised, right? You take backups, you test in a staging environment or something that is very similar to production, but isn't actually a production environment. You're able to restore from any backups. You make sure the data is clean, and you keep a track of everything that you may have changed as a pen tester, and you present that to the customer at the end. All of those risk controls are still valid for AI pen testing.

Graham Cluley:So this question of trust, it actually connects to something bigger, which happened back in June this year, right? We saw the US government, for a short while, force Anthropic, who make the Claude models, to switch off their most advanced AI for everyone practically overnight. It was no longer there, over a security concern. Now that only lasted a few weeks before it was resolved, but it's the kind of thing that is clearly concerning. Now, is that something which makes you nervous? Are you beginning to look at other options when it comes to AI models?

Andy Hornegold:I think nervous is probably the right word to potentially use. At Intruder, we benchmark different models to try and work out which one's going to give us the best results. Claude is obviously one of those. I think it would be crazy of us not to include Claude in that process. And absolutely, when we saw the export controls come into force, very reminiscent of old school cybersecurity days, it brought a whole bunch of concerns up for us. How do we build a product and a business around that product if one of the suppliers that we're using is able to just switch off under the hood anything that we put out to customers? How does that impact running pen tests? How does that impact ongoing contracts that we have with customers? So it's been an ongoing concern for us about how we address that. Now, the Frontier models are still excellent. They are able to produce results that are incredible, and we're going to continue to use. But it would be remiss of us if we did not have some level of risk management involved, which is where we are starting to look at those other models. Are there open weight models that are out there that allow us to hedge our bets, essentially? If those models go off overnight, can we fall back on open weight models instead? It is worth mentioning as well, actually, the pen testing results we're seeing under the hood — we haven't been using Fable or Mythos. Actually, the older Opus models are still incredibly effective at finding vulnerabilities. So yeah, that's the balance that we've been trying to find.

Graham Cluley:Can you foresee yourself maybe in the future using a Chinese-made AI model in your security product, or would that raise concerns?

Andy Hornegold:I'm not going to rule it out entirely. I don't think it would be appropriate to say a hard no, that's never going to happen. I think if those models are as effective — and I suppose what would be important to note is I'm not sure we would be sending data to Chinese AI houses. I'm not sure that's something we are going to be willing to do as a UK-based company with a predominant US customer base. But anything that is open weight that we're able to set up ourselves, that we're able to run ourselves on our own infrastructure, that would be something we'd likely investigate.

Graham Cluley:We're both here in the UK at the moment. The UK government has put something like, I think, £500 million they're talking about into a homegrown AI as a kind of alternative to allay some of these fears. Is that enough or is that just a token gesture? No pun intended.

Andy Hornegold:I love it. So there's the Sovereign AI Fund that was launched, I believe, back in April in the UK to try and build or help the UK have some footing in the AI race. And there's two sides to it. One, the fact that the UK government has stepped in and done anything at all is positive — I think it's a good step. But to your question, is it enough? I'm not sure it is. At the moment, there is availability for compute, there is the £500 million available for the AI space, but there is more that we could be doing. I think we're already pretty far behind when it comes to the race against the US. And particularly US and China, but also Europe are pulling ahead as well. And I'm still very fond and I would still consider European models as being something that is worth the UK being involved in as well. So I believe there's more that we could be doing.

Graham Cluley:It seems to me like AI cuts both ways in cybersecurity. It can genuinely help the good guys, but it can also make life easier for the attackers too. What side of that fence would you fall on, do you think?

Andy Hornegold:I think the answer is probably that AI is here and it's going to be used by both sides. It is a tool that is going to be wielded by the good guys and the bad guys alike. Anything that helps people do what they need to more efficiently, I think they're going to lean on. I think as we start to see attacks speed up, and attackers have a kind of asymmetric benefit to using AI and being able to use them in their attacks, in that as an attacker, I don't really care about contractual obligations and terms of services, right? As a defender, my business is running on this model.

Andy Hornegold:I have a lot invested. I need to make sure that I'm not going to have my organisation banned overnight by trying to bypass safety. And that's kind of what we've seen in the defensive operations side of things, is that as an attacker, I can try and bypass safeguards and use those AI models to exploit organisations faster, more effectively. But as a defender, I'll get blocked because I hit a safeguard when I'm trying to defend against an AI-enabled attacker. So it feels like there's some asymmetry there between the good guys and the bad guys.

Andy Hornegold:But when it comes to the defensive side of things, there's a huge benefit that you can have as a defender. The cost of pen testing now, of the ability to find risk and exposures within those web apps, has crashed. It is becoming cheaper and more affordable to find risk more effectively, more quickly, more consistently. We've seen people running pen tests once a year, right? And for decades we've been saying one pen test a year isn't enough, right? It needs to be continuous. But it feels like we're potentially finally there. AI does seem to be the linchpin to that answer of: can I do continuous security validation?

Andy Hornegold:Can I find risk more continuously, more effectively, and with the same level, or at least almost equivalent level of reasoning and understanding and context that I would get from a human? And finally, I feel like we probably are. I feel like that AI-led pen testing is finding more stuff more quickly, and it can be leveraged for good to hopefully make the internet a safer place. Well, that is a great note to end on.

Graham Cluley:And listeners, you can learn more about Intruder or even start your own AI pen test in minutes. All you have to do is visit intruder.io/smashing. That's intruder.io/smashing. And as a Smashing Security listener, you can save 25% off your first pen test by using the code SMASHING25. Andy Hornegold, Chief Security Technology Officer.

Andy Thornegold:Thanks, Graham.

Graham Cluley:Thank you so much for joining us today. It's been really interesting, and we appreciate you coming on the show.

Andy Hornegold:Thank you very much for having me, Graham. It's been a pleasure.

Graham Cluley:Well, that just about wraps up the show for this week. Thank you so much, Lianne, for joining us. I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way to do that?

Lianne Potter:I'm on LinkedIn, so you can find me under Lianne Potter, or you can listen to my Yorkshire tones on either Compromising Positions podcast — do type in that full thing. Don't just type in compromising positions on the internet. And Tech Phil Noir, where you can look up the Memotech and see what Graham's talking about. I'm really pleased that I've actually met someone who's had that computer. It's really awesome.

Graham Cluley:And of course, you can find me, Graham Cluley, on LinkedIn, Bluesky, Mastodon, Instagram, and the Tok of Tik. The list goes on and on. Or you can follow Smashing Security on Reddit, Bluesky, and Mastodon. And don't forget, to ensure you never miss another episode, make sure to follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts. For episode show notes, sponsorship info, guest lists, and the entire back catalogue of over 480 episodes, check out smashingsecurity.com. Until next time, cheerio. Bye-bye.

Lianne Potter:Bye.

Graham Cluley:You've been listening to Smashing Security with me, Graham Cluley, and massive thanks to Lianne Potter for joining me this week, and to Andy Hornegold for popping by as well, and to this week's sponsors ThreatLocker, Intruder, and Vanta, whose cash we've pocketed with tremendous glee and only the faintest trace of guilt. Well, huge thanks as well to those wonderful Smashing Security patrons. First up, we've got Dan H. He definitely had a surname once. I just can't locate it anymore. Jeff Ambler, still out there holding doors open for strangers everywhere. A shout out to Benjamin Harouf and Nigel Scott and to Sharon, who requires no introduction at all and certainly isn't offering one herself. Lots of love to Yuri Taraday and Steve Lupton. And to the marvellously hyphenated Adina Bogut O'Brien. She's fully prepared for whatever comes next. And last but not least for this week, huge thanks to Ask Leo, still delivering his exclamation point energy that we all secretly crave.

Graham Cluley:These marvellous, upstanding, and clearly somewhat unwise individuals are members of Smashing Security Plus, which means that they enjoy ad-free episodes, and they get them ahead of everybody else. And arguably the biggest perk of all is that they have their names read aloud at the show's end in a tone which I would like to say sounds like general appreciation, but others may consider to be slightly mocking. So would you fancy a way into this exclusive circle of the marvellous and mildly ridiculous? All you gotta do is head over to smashingsecurity.com/support. And you'll be in, where a small fee buys you the privilege of being publicly ribbed by a middle-aged British cybersecurity podcaster. Who can say fairer than that? Now, there are plenty of free ways to support the show as well. You can subscribe. You can drop a five-star review wherever you listen. You can tell your mates about it. We can bang on about the podcast in the pub until people gently suggest that you leave and go home.

Graham Cluley:Well, however you support the show, maybe it's just by tuning in each week. Thank you very much indeed. It really is appreciated. Until next week's show, cheerio. Bye bye.

Transcript supplied by the publisher with the episode.

Smashing Security

by Graham Cluley · English · Tech & Science

Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all…

More from Smashing Security

  1. E487 · 58 min

    Clippy's crypto comeback

    Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft either. Meanwhile, UK losses from hacked email and social media accounts have rocketed by 417%, as scammers pose as your friends to flog you tickets to gigs that don't exist. Plus, Hack The Box's Christine Bartlett joins us for a featured interview to ask what happens when AI agents join your security team, and whether anyone has thought to give them a performance review. All this…

  2. E486 · 41 min

    Vibe-coded shops, and hackable Flock cameras

    A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside. All this and more in episode 486 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner. EPISODE LINKS: Claude Opus…

  3. E484 · 46 min

    How websites are tracking you with silence

    When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated." All…

  4. E483 · 44 min

    This AI helps thieves steal your iPhone

    You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just…

  5. E482 · 50 min

    This hacker leaked GTA 6 - and launched their own cryptocurrency

    A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet…

  6. E481 · 46 min

    Never say this to a robot dog

    At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of…

  7. E480 · 46 min

    This is the AI service you should never sign up to

    Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in…

  8. E479 · 1 hr

    How a fake police officer nearly stole Graham's cryptocurrency

    Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education - sending an…

  9. E478 · 59 min

    This job interview could destroy your company

    You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly…

  10. E477 · 51 min

    How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

    A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball. EPISODE LINKS: Bengaluru triple murder: Accused allegedly used…

Every episode of Smashing Security →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play