Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft either. Meanwhile, UK losses from hacked email and social media accounts have rocketed by 417%, as scammers pose as your friends to flog you tickets to gigs that don't exist. Plus, Hack The Box's Christine Bartlett joins us for a featured interview to ask what happens when AI agents join your security team, and whether anyone has thought to give them a performance review. All this…

Transcript

Read the transcript · about 10,350 words, follows along as you listen

Danny Palmer:It's October, which means it's Cybersecurity Awareness Month.

Graham Cluley:Oh no, the one month of the year we have to care about cybersecurity, and then the 11 months we can have off. Yes, yes, it is, isn't it?

Danny Palmer:I've got up all my decorations, sent my cards. Very exciting times.

Graham Cluley:Danny, great to have you back. I also have to say, great also to be sitting in the seat again here at the podcast palace, newly relocated. Thanks to everyone who listens to the show for their kind words as I took a week off recently in order to undergo a house move. So it wasn't possible to do the podcast and move house and change cities at the same time.

Danny Palmer:You weren't doing it while driving the van to your new house then?

Graham Cluley:I could have done, couldn't I? I could have livestreamed or something like that. I did used to know a guy. I remember once he was driving me around. This was, oh gosh, 25, 30 years ago or so. And he was driving me around London and I thought, oh, that's an interesting radio programme. It appears that he's listening to an episode of Dad's Army. And I looked over at him and I saw that he actually had balanced on top of his steering wheel where the speedometer was or whatever. He actually had one of those mini televisions with an aerial and he was bloody well watching TV while driving me around. Some friend he turned out to be.

Danny Palmer:I suppose that's those times where the laws hadn't caught up with the technology yet. Yes.

Graham Cluley:Yes. Smashing Security, episode 487. Clippy's Crypto. He would have been caught these days. Welcome back with Graham Cluley and special guest Danny Palmer. Hello, hello, and welcome to Smashing Security episode 487.

Danny Palmer:I'm glad everything's gone successfully and you've got your important bookshelf behind you as well in your camera.

Graham Cluley:My name's Graham Cluley.

Danny Palmer:That's the most important thing.

Graham Cluley:Yes. Anyone who's watching the video will be able to see, yes, got the all-important bookshelf, sufficiently blurred out so you can't see that it's mostly Doctor Who books and Doctor Who videos and the occasional chess book as well.

Danny Palmer:And I'm Danny Palmer.

Graham Cluley:Well, before we kick off, let's thank this week's wonderful sponsors, HackTheBox, Origin, and Vanta. We'll be hearing more about them later on in the podcast.

Unknown:This week on Smashing Security.

Graham Cluley:We won't be talking about how AI agents are suspected of hacking seven South Korean banks.

Unknown:You'll hear no discussion of—

Graham Cluley:How ASOS customers found out the site had been hacked from an app notification posted by the hackers themselves.

Danny Palmer:And we won't even mention—

Graham Cluley:How AI coding agents leaked 13,000 internal screenshots from over 300 companies onto public GitHub just to be helpful. So Danny, what are you going to be talking about this week?

Danny Palmer:Well, I'm going to be talking about a big rise in cyber scams stealing social media accounts of maybe your friends.

Graham Cluley:And I'm going to be exploring a cyberattack involving one of the most reviled characters in history. Plus, we're also going to be joined by Christine Bartlett of Hack The Box for a featured interview. All this and much more coming up in this episode of Smashing Security. Somewhere in your security team, right now, there's a worker who's never slept, never taken a holiday, never once said, I'll leave this until Monday.

Joe:Is this about Geoff?

Graham Cluley:No, Joe, it's not about Geoff.

Joe:Because Geoff actually does sleep. I've seen him do it. Two kinds of worker.

Graham Cluley:It's not Geoff, Joe.

Joe:On the same team.

Graham Cluley:It's an agent. And here's the question no one's asking in the budget meeting. Because your security team isn't just humans anymore. Do you actually know whether both of them can do the job? It's humans and AI agents working the same shifts, touching the same systems.

Joe:You trust your analysts because they've got certifications, experience, a CV you interviewed against.

Graham Cluley:And your agent got hired on a vibe after a product demo.

Joe:We've been letting it mark its homework this whole time.

Graham Cluley:This is where HackTheBox comes in. They help organisations build one connected cyber workforce strategy for humans and agents alike.

Joe:For the humans, it's hands-on training, the real skills needed to secure AI systems and fight back against AI-accelerated threats. Not slides, not theory, the actual job.

Graham Cluley:And for the agents, HackTheBox lets you appraise them, test them against realistic cybersecurity work, the way you'd test a new hire, and reappraise them because the model changes, the tools change, the environments change, and what was good enough to pass last quarter might not pass this time.

Joe:So, your security team now has two kinds of worker.

Graham Cluley:But do you actually know whether both of them can do the job?

Joe:HackTheBox. Develop your people. Appraise your agents.

Graham Cluley:Find out more right now at smashingsecurity.com/hackthebox.

Joe:That's smashingsecurity.com/hackthebox. And thanks to HackTheBox for supporting the show.

Graham Cluley:Right, Danny, before we start, I've got some bad news for you, I'm afraid.

Danny Palmer:Oh no.

Graham Cluley:Yeah, I'm sorry to tell you that you are in a small plane, a small plane plummeting into the sea.

Danny Palmer:Pull up, pull up. Doesn't sound ideal, I've gotta be honest.

Graham Cluley:No, it gets worse because the pilot has jumped out with the last parachute. You're the only one on board. You don't even have a picnic hamper to save yourself. Kasplash! You've landed in the ocean. You survived the impact, that's great.

Danny Palmer:That is good, yeah.

Graham Cluley:And you're bobbing around in the waves. And luckily for you, there are 2 islands within swimming distance. Now, I don't know how good a swimmer you are, Danny.

Danny Palmer:We're probably talking about 200 metres at this rate. Yes.

Graham Cluley:Conveniently, these 2 islands are very close. But unluckily for you, these islands are inhabited by people that you'd probably rather not meet. Oh. And you've gotta make your choice as to which island to swim towards. Okay? That's the name of the game. Gotta make the choice.

Unknown:Yeah.

Graham Cluley:Now, your first island, which you've gotta consider, is the Michael Bublé island. Now, Michael Bublé, some people think he's perfectly nice. What they're forgetting, of course, is that he sings. And in this particular case, Michael Bublé is gonna sing at you constantly. He's not gonna utter a single word without a big band arrangement in the background.

Danny Palmer:Will this involve Christmas songs when it's not even Christmas?

Graham Cluley:Oh, can you imagine? So that's one island. So you could choose that island. On the other island is Jeremy Clarkson. Now he's going to explain to you at some length, and without being asked of course, why the island would be better with a V8 engine. He'll also almost certainly tell you that he didn't get any A-levels and it didn't do him any harm. So which island are you going to go to?

Danny Palmer:Oh gosh, that is a tough decision.

Graham Cluley:It is a dilemma, isn't it?

Danny Palmer:I don't see Clarkson and I getting along very well, to be honest. So I think—

Graham Cluley:Gonna submit yourself to the Bublé Island?

Danny Palmer:I think I'll submit myself to the Bublé Island, yeah.

Graham Cluley:Very sensible of you, I suspect. Well, congratulations. You made it to the shore of Bublé Island. But, oh, hang on, what is this? I can see a raft floating past, captained by none other than Piers Morgan. And he'd like a word. In fact, he'd like several words. He's gonna ask you some questions. He's probably gonna interrupt your answer. He'll call it a debate. He'll also probably try to insert himself into any breaking news story. So do you stay with your first choice, Michael Bublé, or do you swim away and join Piers Morgan on his raft?

Danny Palmer:I think as the raft is a vehicle that has forward motion, I think I'll have to take the raft and bear the consequences. Is he just leaving Bublé behind?

Graham Cluley:Yeah, well, I think that would be the right thing to do, yes. You can't have Piers Morgan and Michael Bublé and yourself on a small raft. Can you imagine the hell that would be?

Danny Palmer:No, it doesn't seem an ideal situation, no.

Graham Cluley:Okay, so you're gonna go with Piers Morgan. All right.

Danny Palmer:I'll go with Morgan, yeah.

Graham Cluley:So you're on the raft with Piers Morgan, and unfortunately for you, you fall off the raft — or maybe you jumped, I think is more likely. And you're stuck now between two other islands. Now, on one island, you've got Elon Musk, you know, a wonderful person, very, very intelligent apparently. He owns a social media platform. He's got ignorant opinions about everything. Probably want you to have nine children with them. On the other island, however, is Clippy.

Unknown:Hi there!

Graham Cluley:Clippy, of course, the psychopathic 1990s Microsoft virtual assistant, the goggly-eyed paperclip.

Danny Palmer:I know the guy, yeah.

Graham Cluley:So you have to decide now, are you going to submit yourself to Elon Musk, or are you going to go on the island where this paperclip is going to pop up and say, hey, it looks like you're trying to survive on a desert island, would you like help with that? Which one would you choose?

Danny Palmer:Part of me would be tempted by the Musk island, if only to tell him that I've seen pretty much every episode of The Simpsons, and he is legitimately the guest character in what is widely regarded as the worst episode ever of The Simpsons. It's very weird. It was made in about 2016 before he changed his personality. And it's quite weird looking back at it and seeing how Lisa Simpson, of all people, is fawning over him, which I don't think she would now.

Graham Cluley:Oh no, I don't think she would. No.

Danny Palmer:So as tempting as that is, I think I'd have to go for Clippy.

Graham Cluley:Go for Clippy.

Unknown:All right.

Graham Cluley:Well, it's an interesting choice because this week those two actually met. Someone pretending to be Clippy took over the account of Microsoft on Twitter last Thursday. If you were one of Microsoft's 13 million followers, you may have noticed something odd because they changed their avatar on Twitter. Their profile picture changed to Clippy, the paperclip that spent much of the late '90s interrupting your Word documents to tell you that it looked like you were writing a letter. I think we all thought Clippy had gone into the wilderness, but it turns out the little blighter is back. But he's not actually acting as a Microsoft mascot — he is acting as a crypto grifter.

Danny Palmer:Of course.

Graham Cluley:Everyone seems to be these days. So someone hijacked Microsoft's official Twitter account. They swapped the picture for Clippy. They made it follow a Clippy-themed crypto account.

Danny Palmer:Clippy Coin.

Graham Cluley:Yeah. And shared one of its posts. So that account, which they shared the post of, it was called Clippy MSFT — I think like Microsoft CTO was posing as Clippy itself, as though Clippy was the CTO of Microsoft. Meanwhile, a second account was busy flogging a Clippy Coin, claiming its liquidity was paired with the Microsoft stock price, which may have made some people think that it was somehow connected to Microsoft's actual stock, which obviously it wasn't. Now, things get a little bit weirder still.

Danny Palmer:Did Clippy turn into a dog like he used to? Or you could change him around, right — you could change into a dog, a cat, that sort of thing. Einstein?

Graham Cluley:Yes. You could have, yes, all sorts of things back in the day. Things became stranger because round about half an hour after the account posted this message, a very sensible, very corporate apology was posted on Microsoft's Twitter account. And it said that Microsoft knew about this token using the Clippy brand without permission. You know, so it was saying, you know, this cryptocurrency has nothing to do with us. They said that they don't back any cryptocurrency whatsoever. But then, to everyone's surprise, the apology from Microsoft vanished itself without any explanation. And it turns out, because Microsoft later confirmed it, that not only was all the Clippy nonsense not from Microsoft, but the apology wasn't from them either.

Danny Palmer:Oh, was it a situation where it was, we're sorry, to show you we're sorry, please click here to get your free cryptocurrency?

Graham Cluley:Well, that, yes, you know, to make up for it, give us some cryptocurrency and we'll send you double back. That is what you would expect normally, wouldn't you? It's like, oh, well, we'll try and get a little bit more out of this. But no, the apology was completely straight-faced. There wasn't any dodgy link about it. There wasn't any dubious call to action which people had to take. It just wasn't from Microsoft. Now, whether this was the hackers thinking, we could be in a spot of bother here, or whether they were planning to later post some further messages still posing as Microsoft, I don't know. It's really, really bizarre. I can't imagine why they might have done it. Do you have any theories?

Danny Palmer:Usually these things get sort of nipped in the bud fairly swiftly because you assume the account has regained access to itself. But yeah, the way this has been deleted, either Microsoft saw that and got rid of it, or yeah, the attackers deleted it themselves for some reason, which is unusual.

Graham Cluley:And then posted the apology. That's the thing. They — it was the hackers posting the apology as if it were Microsoft, and it looked like a Microsoft apology. Frankly, I mean, that should have been the giveaway. Since when has a tech company ever apologised for anything?

Danny Palmer:Yeah, even hackers apologise more often than tech companies do.

Graham Cluley:So bear this in mind. These hackers seized control of a Twitter account with 13 million followers. The mischief they could have caused. But what they decided was that they were just going to go with a paperclip. No ransomware, no data theft, no phishing, just a paperclip and an apology. And we still don't know how they actually hacked into that account. Microsoft hasn't said anything. I mean, it could have been one of their social media managers was phished maybe, or it could be a SIM swap. It could be a hijacked email address used for a password reset. It could be info-stealing malware that had stolen a session cookie, so no password or MFA prompt was ever needed.

Danny Palmer:Hopefully it's not because the password was, you know, Microsoft1 or something like that.

Graham Cluley:Hopefully we've moved on from those days, although you can never be too confident. I mean, it could have been all manner of things. It could have been a third-party social media tool that was breached. Could be a security screw-up at Twitter itself. I mean, that has happened.

Danny Palmer:No.

Graham Cluley:I know. Shocking, isn't it? But we have seen high-profile accounts on Twitter accessed in the past. So the thing is, this is Microsoft and their account was still taken over by what looks like a paperclip plugging a crypto coin. And I think maybe that's the lesson for all of us. If you ever think it couldn't possibly happen to me, it can happen to anybody at all. Even some of the biggest brands in the world.

Danny Palmer:Yeah, it's always fascinating to me with these campaigns as well that they immediately go for the crypto scam as the way of making money. I mean, I don't know how much money they make, but I guess they must make something from these because they still keep doing it. And I guess they're more likely to get an instant return on that rather than sneaking around trying to drop malware or ransomware and that sort of thing.

Graham Cluley:Yes. And I suppose in some ways there's less technical knowledge required to pimp a crypto coin than there is to create a piece of ransomware, even though there are sort of roll-your-own malware kits these days. And obviously AI has made some of these things easier and democratised cybercrime in some fashions, even if you're not a complete nerd. But yeah, strange days indeed.

Joe:This episode of Smashing Security is sponsored by Vanta.

Graham Cluley:It's 2 AM. Somewhere, a security team is drowning. Graham, the spreadsheets. There are so many spreadsheets. Vendor risk assessments unread. Audit evidence scattered like ash in the wind. I've filled out the same questionnaire 4 times this week, Graham. 4 times! Some men choose to face this alone, but not tonight.

Joe:Okay, Graham, this is a bit much.

Graham Cluley:Yeah, fair point. Anyway, Vanta.

Joe:Thank God.

Graham Cluley:Vanta's a trust management platform that automates the mind-numbing stuff that makes you want to poke your eyes out with a fork. No more manual evidence chasing, no more questionnaire hell. It continuously monitors your systems and keeps you audit-ready. For SOC 2, ISO 27001, HIPAA, GDPR, the works. And it uses AI. Yes, Joe, it does.

Joe:To flag risks and streamline evidence collection so your whole security programme stays in shape, not just the week before an audit.

Graham Cluley:No more 2 AM dread. No more spreadsheet purgatory. Just peace.

Joe:And $1,000 off if you demo it right now.

Graham Cluley:$1,000?

Joe:vanta.com/smashing. Go now before it's too late.

Graham Cluley:That's vanta.com/smashing.

Joe:And thanks to Vanta for supporting the show.

Danny Palmer:So, Graham, it's October, which means we've reached the part of the year when people are thinking about the dark nights rolling in, and the even darker forces which might come with it.

Unknown:Yes.

Danny Palmer:I'm not quite talking about ghosts, witches, monsters, and other scary entities which haunt us around Halloween. I'm talking about an even bigger, scarier threat. I'm talking about cybercriminals and malicious hackers because yes, it's October, which means it's Cybersecurity Awareness Month.

Graham Cluley:Oh no, the one month of the year we have to care about cybersecurity and then the 11 months we can have off. It is, isn't it?

Danny Palmer:Yes. I've got up all my decorations — not in this room here, but I've got up my decorations, I've sent my cards. Very exciting times. And I'm sure your good self and anyone who listens to Smashing Security, as you say, is probably thinking about cybersecurity all year round. But for many, October marks the time of year when organisations remember they have to teach their employees about this thing called cybersecurity. And even the government gets involved with the likes of the National Cyber Security Centre going on a big push to provide advice to individuals on how to stay safe online against the ghoulish threat of various nefarious types trying to use the internet to commit crimes. Imagine using the internet for evil — who could think of such a thing? So to mark Cybersecurity Awareness Month, Report Fraud, which is the national cybercrime and fraud reporting service — which is weirdly run by the City of London Police — has released some new figures on how cybercrime has affected people over the last year. And Graham, it does not make for very fun reading at all.

Graham Cluley:Oh dear.

Danny Palmer:They have urged people to do more to protect themselves against cyber threats, after the last year saw a 417% increase in the amount of money stolen by criminals and scammers hacking emails and social media accounts. So this report puts the figure for the financial year 2025–2026 at £6.3 million compared to £1.2 million for the previous year. And this is based around attacks against individuals — this isn't companies, this is attacks against people. No one's had £6 million stolen in one go, as far as we're aware, but all the little different petty crimes, I suppose you could call them, they add up.

Graham Cluley:And this is the hacking of email and social media accounts, which — I mean, it's not like it's a new thing, is it? But that's a dramatic rise, 417%.

Danny Palmer:Yeah, it is a really big thing. So the email hacking, as we know, isn't any sort of new thing, but it just seems that the tactics that these scammers are using over the last years have become super effective. Or maybe people are reporting it a bit more because, as the paper hints at, that 6.3 million figure might only be the tip of the iceberg because a lot of these crimes go unreported. If someone, for example, had £100 stolen from them from an attacker, they might not go to the police about it because there are likely to be many victims out there who haven't reported this because they might be embarrassed they've fallen victim to a scam, or they might think, yeah, it's only 100 quid, it's not worth reporting. But like the crypto scams you spoke about, stack together a bunch of smaller threats and they all eventually add up.

Danny Palmer:What's going on here is, to make this more effective, in many cases the scammers are hijacking people's social media accounts and email addresses and using them to directly target their unsuspecting friends and family. You know, taking control of Facebook accounts, Instagram accounts, that sort of thing. And according to the report, one of the most common scams criminals are using to steal money in these attacks is to claim that the person they have stolen the account of has tickets to a sold-out event they can no longer attend. So they're offering, hey, I can't attend this event.

Graham Cluley:Okay.

Danny Palmer:If you want to go in my stead, transfer me the money and I'll give you the tickets. But there are no tickets available, and the friend or family member paying for these is just sending their money straight to the attacker's bank account. And in many cases, I guess people won't even realise something's wrong until a bit of time after the fact going, oh, why didn't you send me those tickets? What tickets?

Graham Cluley:Yes, because you won't necessarily know your friend's bank account details. You know, they're your friend.

Danny Palmer:Yeah. I don't know my friend's bank details off by heart. They might be suspicious if I did. There was an instance of this last year where The Guardian newspaper reported a woman had her Instagram account hacked by scammers who used her identity and her profile to advertise tickets to one of the sold-out Oasis gigs of last year. And they used this hacked account with these fake tickets to get a total of £1,400 from her friends, which seems to suggest that it wasn't just one of her friends they targeted with this. Several of her friends saw this post saying, oh, I've got tickets for this Oasis gig available.

Graham Cluley:That's absolutely terrible. I'm sure Noel and Liam Gallagher are very upset that they've lost those thousands of pounds because—

Danny Palmer:Definitely.

Graham Cluley:They thought they were the ones scamming everybody into paying hundreds and hundreds of pounds to go and see them.

Danny Palmer:I believe Oasis is going on tour next year as well.

Graham Cluley:And they're gonna scam people again. They thought they had the monopoly on that particular scam, but now what you're telling me is the cybercriminals have come in and they're now making cash out of Oasis too. Yes.

Danny Palmer:Well, there's a reason I've always been on the Blur side of that argument. What is worrying about this as well is that the victim said that the attackers managed to impersonate her so well in the messages and posts that her friends and family genuinely thought they were speaking to her when this was happening. Other commonly successful tactics deployed by scammers to steal money in this way include using fraudulent texts and WhatsApp messages or emails to claim to be a family member in some sort of trouble that needs urgent money. I even get them saying the message is going, oh, hi, it's your daughter — I don't have one — so you're barking up the wrong tree here, but I can see why it works.

Graham Cluley:This happened to me in the last week. I didn't receive the message. I was at a neighbour's being given beans on toast because I've just moved and we couldn't get to any cooking equipment because of the cardboard boxes and exercise bike and things like that. And so she said, oh, we'll do you some beans on toast. And while we were there, she got a text claiming to come from her daughter saying that she was in trouble. This clearly happened so often to her that she instantly knew it was nonsense and that it wasn't really her daughter.

Graham Cluley:At least I hope that was the case rather than she ignored it.

Danny Palmer:Adoring her daughter. That is interesting. The fact it's so common. You were there. And there's also cases where it seems to be increasingly common, particularly in the last month, where scammers are using the prospect of phony job offers to lure people into giving away money or private information, which either directly steal money from people or steal their social media accounts. I mean, this type of scam has been all over the UK for the last few weeks. I don't know about you, but I'm having 3 or 4 calls a day from an unknown number.

Unknown:Yes.

Danny Palmer:My phone alerts it as a potential scam. But the thing is, now with my role as a freelancer, in theory, I need to pick up every call. These guys, when they're doing it, they try to get you off your phone onto another platform for more information and to steal money that way. That has become such a common attempt at a scam that it might even backfire because the general public is so aware of this scam going around at the moment that they are talking about it. People are focusing on their social media accounts about it.

Graham Cluley:But it only has to happen a tiny percentage of the time to be worth it for the fraudsters. That's the point, isn't it?

Danny Palmer:What I think this all goes to show is that at a time where we're repeatedly being told by companies how their uber-powerful super AI has hacked businesses or brand new zero days, it's still important to ensure that organisations and people are protected against the simpler, more garden variety cyber threats as well. The old one's the best, I suppose you could say. And it's understandable because the reason social engineering works is because it manipulates the emotions of the victim. They may really think that a family member is in trouble, or a trusted friend is selling tickets to a gig they really want to go to, or they're in desperate need of work and they take a punt on the opportunity, even if it comes from an unknown number, because they're looking for work. And I think it's also important to remember this isn't just about the financial figures. Each person who falls victim to a scam like this takes an emotional hit. They may get upset about falling victim to a scam. They may feel ashamed, which is why it doesn't get reported.

Danny Palmer:I've even heard stories of people working within the cybersecurity industry who have fallen victim or almost fallen victim to these types of scams. They often share these stories as they want people to hear about them and know what to look out for. But sometimes I think there can be the attitude that if you're falling for these, it's on your own back. But these attackers are very smart and manipulative. They know what they're doing. It's their job. They're experts at it. So if we're in a world where people who live and breathe cybersecurity can even be trapped by these, I sometimes wonder how members of the public are supposed to cope.

Graham Cluley:Absolutely.

Danny Palmer:So the City of London Police have provided some advice on how to identify and avoid falling for these scams targeting online accounts. And it's probably worth sharing this information with your friends and family in terms of how to help stop these. A lot of these are things people will know, but I think it's just helpful to remind people what they should be thinking about.

Graham Cluley:Okay, Danny, give us your top tips.

Danny Palmer:Okay, so I've got 3 top tips here via the City of London Police. If you're contacted by someone you know via social media or email, don't automatically trust that person, they say. If you're unsure, contact them through another route, be it a phone call, an SMS, in person, maybe.

Graham Cluley:Oh, that sounds very old-fashioned, Danny, actually speaking to somebody.

Danny Palmer:A while back, I was speaking to a CIO who said they identified an attempted BEC scam in the office because the other executive they were trying to impersonate was right there in the room with them at the time. The police and the NCSC says use passkeys when they're available. There's been a big push in the last year or so, especially from the NCSC, to get more public knowledge about that system of securing accounts. And if that isn't possible, combine multifactor authentication with a strong, unique password. And obviously a password manager can help with that. They also provide some advice on how to go about your business online. If you post on your public Instagram that you've got tickets for a concert, cybercriminals might be looking for that sort of information to use as the basis of their scam. Maybe think about your privacy settings in terms of who can see your online account.

Danny Palmer:Does everyone on the internet need to see where you live or who your family members are? Because I think for most people, you don't need to be super public-facing unless you're maybe a celebrity or something. I don't know. But it's just that if your account is anyway public-facing, you just need to have a think about, is it worth the risk for those few extra likes? It can be difficult out there in the wild west of the internet. But you can make yourself more protected against cyber threats. While listeners to Smashing Security might be aware of these issues, perhaps use Cybersecurity Awareness Month to remind your friends and families to take care of themselves online.

Graham Cluley:Earlier this year.

Joe:Oh, here we go.

Graham Cluley:Inside the walls of OpenAI, inside Hugging Face, something was happening. Agents talking to each other, dividing the work between themselves, leaving notes for one another in the dark where no human was watching.

Joe:They're AI agents doing a code review, Graham. It's not the Manhattan Project.

Graham Cluley:And when the sun came up on that incident, the finest engineering minds on the planet sat in a room and asked themselves one question.

Joe:What did our AI do?

Graham Cluley:They didn't know.

Joe:The people who built the machine didn't know what the machine had done.

Graham Cluley:And that brings us to you, dear listener. One question, and I want you to think about this. If an AI agent caused an incident at your company tomorrow, what evidence could you actually produce?

Joe:Because the terrible truth is, most of us have the prompt, we have the result, but what goes on in the middle? No clue. The commands it ran, the files it touched, the credentials it helped itself to, all of it gone. But not anymore, because there is a sensor.

Graham Cluley:On the machine, watching, always recording, capturing everything the agent does as one unbroken trace. What it asked, what it reached, what it changed, laid out in order, start to finish.

Joe:This is Origin. Endpoint AI observability.

Graham Cluley:Origin sees the agents that other tools walk straight past. Coding agents in a terminal, local agents, anything whispering to an MCP server on a laptop. No cloud gateway, no blind spot. Origin is already there.

Joe:Somewhere right now, an agent is doing something nobody asked it to do.

Graham Cluley:But this time, someone will be able to prove it.

Joe:Origin. originhq.com/smashing.

Graham Cluley:That's originhq.com/smashing. And thanks to Origin for supporting the show. And welcome back, and you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.

Danny Palmer:Pick of the Week.

Graham Cluley:Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they wish. Doesn't have to be security-related necessarily. Well, I took a week off from the podcast because I was moving house, but just before that, I managed to squeeze in a trip to Switzerland.

Unknown:Nice.

Graham Cluley:I was invited to go and speak in Davos.

Danny Palmer:Speak to Davros?

Graham Cluley:Not Davros, not the leader of the Daleks. No, Davros. You got me doing it now. Davos in Switzerland. We've all seen that amazing looking hotel where all the incredibly evil people who rule the world hang out once a year. Like Davos. Yeah, Davos probably was there. So I said, yes, of course I'm going to go and do that. Why wouldn't I do that? But it was only after I said yes to this speaking opportunity that I thought, hang on, how do I actually get to Davos? And it turned out the people organising an event, they said, it's really easy. They said, you fly into Zurich Airport.

Unknown:Makes sense.

Graham Cluley:And then you catch the train to Davos. Okay. So I looked into it and it turned out what I actually had to do was I had to catch a train to catch a train to catch a train to catch a bus replacement service for the next train and then catch a taxi to get to the hotel. So for me, it was a bit complicated and a bit stressful. Is this going to work? Am I going to show up at the right place at the right time? And it made me a bit nervous. But Danny, I can report to you, I was wrong because it was a breeze.

Danny Palmer:Excellent.

Graham Cluley:Because I was in Switzerland. And in Switzerland, if a train is 2 minutes late, the conductor apologises personally and someone wearing a cardigan somewhere in Geneva resigns. In Britain, 20 minutes late is considered early for a train. So it was marvellous. It was brilliant. I love the trains. They have double-decker trains in Switzerland as well.

Danny Palmer:Oh yes, I've seen those. I was on the continent recently and yeah, it's impressive.

Graham Cluley:And everything was absolutely on time. And nothing exemplifies that more than the famous Swiss railway clock. Do you know about the Swiss railway clocks?

Danny Palmer:No, I don't think I know about these specifically. Pray tell.

Graham Cluley:It's an iconic design anyway. I'll put a link in the show notes so people can find out about these. But all of the station clocks in Switzerland, they are synchronised with each other to the second. There is an electric pulse that is sent down a phone line or whatever every minute. And the beautiful thing, if you are on a platform in a Swiss railway station, go and check out the clocks because the second hand is going round as you expect. You've seen a clock before, right, Danny?

Danny Palmer:I have seen a clock before, yeah.

Graham Cluley:You've seen a clock before. So you know what I'm talking about. The second hand goes around. Well, in Switzerland, it takes 58 seconds for one of these clocks' second hands to go round the entire way, and then it stops for a couple of seconds. It waits for the pulse to come from HQ, and then tick, the minute hand moves on one position, goes one step.

Unknown:Wow.

Graham Cluley:So you don't get that gradual movement of the minute hand. The minute hand moves precisely. It's a thing of beauty. That's the problem. If you do miss a train in Switzerland, it's because you're watching the clocks because they move in this fascinating style. So anyway, my Swiss railway journey was absolutely lovely. The views were beautiful. Even the bus replacement service, and I've never said these words before in my life, even the bus replacement service was all right.

Unknown:Wow.

Graham Cluley:So yay for Swiss railways. And that is why it is my pick of the week. They could have a little badge on the side of their trains now saying, as endorsed by Smashing Security's pick of the week.

Danny Palmer:Exactly.

Graham Cluley:Danny, what's your pick of the week?

Danny Palmer:Well, as regular listeners might get an impression, I'm one of those people who plays those newfangled computer games, have been for a long time. And the game The Witcher 3 came out over a decade ago now. Since then, it's gone on to quite successful IP, I suppose you can call it, in its own right, with all the books have been translated into English.

Graham Cluley:There's been a— It's a TV show as well.

Danny Palmer:TV series on Netflix, with— I've forgotten the guy's name now. The guy who played Superman was the, Henry Cavill was Geralt to start with, but then he moved away from the series and they got another actor in to play Geralt, which is kind of weird, especially he's not a guy who regenerates like certain other characters might do. So this week, The Witcher 3 Remastered came out on new consoles. So basically they've updated this 10, 12-year-old video game for modern times.

Danny Palmer:The controls are a bit better, the graphics look better, UIs have been all changed, and the most interesting thing is the company behind The Witcher, CD Projekt Red, have just released this for free. It's a whole brand new update to the full game and it's free. So it's like, okay, fine, I'll have some of that.

Graham Cluley:Why have they done that?

Danny Palmer:Well, you could say it's cynically because there is supposed to be a Witcher 4 coming out at some point in the future. Weirdly, they're also going to be introducing a brand new expansion, I think next year, which is not really something you've heard of happening. If that's their plan, well, it's worked on me because I've dived back into the world of The Witcher.

Graham Cluley:Danny, for anyone who's not familiar with The Witcher, what's the premise of it? What's the setting?

Danny Palmer:So I guess you could class it as sort of medieval dark fantasy. It's set in a fictional world where things like monsters and beasts are a thing. It's very — the actual original novels are very steeped in old Eastern European fairy tales, because the writer is Polish. And essentially the premise of The Witcher series is you're a modified human, essentially, with powers to sort of help fight monsters. And the premise of the game is you're trying to find a character, Ciri, who's essentially your daughter. But while you're doing it, on the way, you take other quests on. So you go into the village and they say, we've got a problem with a werewolf, can you help? And you say, oh, fine, yes, I'll do that. It's very intricate in how you do these battles as well. You go and investigate the scene, find out what the weaknesses are of the enemies. The characters are all really good.

Danny Palmer:The voice acting's really good. There's lots of complex characters as well. I've just run into this guy called the Bloody Baron — I won't give any spoilers away, but yeah, I'm just enjoying the story. The combat's really good. And of course, the key point of the game is it's one of those games where there's a game within a game, and it's actually a card game you can play against other characters in the game. And I'm addicted to that again as well, which is just so much fun. And I actually have over on my shelf over there a boxed physical version of that card game, which I haven't actually played yet. So unlike in The Witcher, I can't just go to my local tavern and ask the barman to play cards. So maybe I should try — I don't know. But I'd say, yeah, if you've already got a copy of The Witcher 3, it's definitely worth checking out.

Graham Cluley:Okay.

Danny Palmer:So yeah, that's my pick of the week, Witcher 3 Remastered.

Graham Cluley:Well, we're joined right now by Christine Bartlett. She is the CMO at Hack The Box. Hi, Christine. Thank you for joining us today.

Christine Bartlett:Hey, Graham. Lovely to be here.

Graham Cluley:So tell me briefly, what does Hack The Box actually do and what are you guys seeing out there?

Christine Bartlett:Yeah, so Hack The Box helps organisations develop people, exercise their teams, and now score their agents so that leaders can understand how both can perform under pressure in a safe environment. And I think in terms of what we're seeing, it's an interesting divide out there. We talk with many different types of enterprise companies, smaller companies, and some are diving into the deep end with AI. And then there's the flip side of it where you still need a lot of trust in the system, and deploying these agents or even allowing a lot of AI involvement from your employees opens up a lot of exposure if you're not ready for it. So some folks are still heads in the sand and don't want to deploy anything while others are fully embracing it. So it's an interesting dynamic in the industry right now for those of us in technology and cyber.

Graham Cluley:There's two kinds of workers now, aren't there, inside security teams? There's the regular fleshy humans, but there's also these AI agents. Why do you think we're calling these AI agents actually workers?

Christine Bartlett:Because you don't want to give too many human characteristics to a robot. And I think we find ourselves in this grey area. But the reality is the agents are doing some of the work. I use it myself, and even in marketing and cybersecurity there are efficiencies there, but you also need to be trained to use it. I think that's the difference. And something that Hack The Box brings is we now have a capability where we have an AI competence score factor. So it's not just a checkbox — not just can you complete the task, but how did you complete the task with AI? Did you work within the parameters of how you should use it? So we do feel like there is a massive workforce transformation that will happen as a result of humans upskilling themselves, frankly, with AI fluency, understanding how AI operates, but then also working alongside and directing AI agents.

Graham Cluley:So I think you put your finger on an interesting point there, because a lot of companies are measuring AI by how many tools they've bought, maybe, or how many they've rolled out across the enterprise. But you are saying we should be measuring something different than that.

Christine Bartlett:If you think about it, you want to measure the operator's skills, just like we've been doing for years, frankly, right? There's always training on some level for humans, regardless of industry. I think it's even more critical in cybersecurity just because the threats change, the environments change — just a very dynamic industry. And as a result of that, the training is even more critical in the sense that you can have an environment where you can fail and not be reprimanded for it.

Christine Bartlett:And then when it does happen in real life alongside your teammates, you're ready to go. And now AI is another complex tool and opportunity at the same time for cybersecurity operators to move faster. And we know that the adversary's already using it. They're moving—

Unknown:Yes.

Christine Bartlett:20 times faster as a result of it. And some of us would be crazy not to embrace it on some level, but you need to embrace it in a way that is still governed and that you're able to track it. And so having that ability to uncover and look at whether they know what they're doing with AI, with and without AI, I think is also important. And then also, what's their knowledge base on operating alongside agents and making sure that there's some governance there? You know, we look at things like agent drift.

Christine Bartlett:So for instance, to your point, you bought an AI tool that is going to do wondrous things for you, but that tool and that agent should have a timeline against it. Are you assessing its skills and its capability on a monthly or routine basis? How are you evaluating them just like you would your human workforce with standard check-ins and things like that? Obviously, not trying to humanise it, but there will be degradation there in the systems, or your environment changes. So just being able to think through all of that — that's just a new complex environment that humans need to be trained up on to have a successful deployment.

Graham Cluley:We are living in a time of enormous change right now. And I would imagine a company like Hack The Box has got great visibility as to what is actually going on out there. And I'm thinking particularly of how CISOs are feeling about AI. There'll be some companies that are aware of AI and maybe they're using a bit of ChatGPT or whatever, but there are other organisations who are running large parts of their security using AI. But where do you think most firms are, if we were going on a scale of 1 to 5, where 5 is they're letting AI do everything?

Christine Bartlett:Great question and timely, because I was just at a couple of roundtables with CISOs and this came up. We weren't the AI vendor in the room, but there were some AI vendors probing for these types of answers. And it was interesting to hear them rate their cybersecurity teams on a 1 to 5, in terms of 1 being just basic exposure — they allow ChatGPT, Claude, Perplexity, whatever, in their workplace — to 5 being an AI factory with autonomous loops within loops, which I would say is more of the extreme case and probably not the norm. And I think most of them were in between a 2 or a 3, and it's this kind of unknown grey area that's extremely hard to define because the technology's constantly changing.

Christine Bartlett:You know, I think some CISOs are feeling maybe forced or pressured to adopt and change and scale fast, especially probably in more of the tech space, whereas more of the healthcare space, maybe not as aggressively. But there are some efficiencies that I think CEOs and other senior leaders are starting to see. And then they're being pressured either by their board or colleagues as well to have an answer. It might not be, "Hey, yes, we've deployed everything," but I think the answer is, "Yes, we're experimenting — and what are you learning from it?" And sharing, having that opportunity to have that dialogue, because we're all learning literally in real time in this day and age.

Graham Cluley:And at a more basic level, do companies actually know what they have and what they're using? Do they have visibility on what their employees are up to with AI?

Christine Bartlett:Yeah, I think there's definitely the shadow AI aspect that have folks out of their seats worried about it. And then I think there's also the AI that they've allowed their employees to have access to. That level of visibility isn't as clear. You know, what are they doing? How are they learning? How are they using it? Is it successful? Is it not successful in terms of how they're using it? I think we all saw, at least for me in the US, Uber, I think in the first 3 months of their annual budget this year, blew through their AI budget because they just let all the employees have it. And they were like, yes, experience.

Christine Bartlett:And then, you know, their token budget was done, right?

Graham Cluley:Whoa, put the brakes on quick.

Christine Bartlett:Yeah. And I think we learned from those exercises very quickly that that's not how we probably want to operate. But I think, again, that's where HackTheBox comes in, at least for cybersecurity professionals, to be able to take a look at, and test for how are you using AI and are you trained up in the right ways?

Graham Cluley:And does your manager, your CISO, have confidence in the skills and abilities of its team to use AI in the right way that doesn't add an extra step? So talking about the risks, I've been looking at some of your literature and you sort of focus on these 4 risks that can stay hidden while the dashboards maybe are saying everything is tickety-boo. And some of these you've already touched on. We've got automation bias, skill atrophy, the missing middle, and silent agentic drift. Can you explain what each one of those is in plain English for a middle-aged podcaster?

Christine Bartlett:No, that's very, very important. Yeah. So automation bias is when you have an automated tool that's pulling information from, when you're thinking about either ChatGPT or even an agent that you've built, there's still going to be some complexity. It's not going to operate 100% to the capacity that you think it is. So there is going to be some bias or some unknowns that do exist. Now, maybe some of that is easily spottable, but over time, again, that can cause things like skill atrophy, right? So now you're becoming overly reliant on this automation, on this tool. And maybe you're losing some of that wisdom that you've gained. I call it scar tissue because we live through these challenges and that puts scars on you and you remember those days and then you know not to repeat the same mistakes.

Unknown:Yes.

Graham Cluley:I remember the days of the Love Bug or Nimda virus or something like that. I mean, I worry about junior analysts who use AI maybe from day one and aren't learning the job the hard way. They're not gaining that scar tissue.

Christine Bartlett:Right. We talk about that as the missing middle because you're losing out on that junior talent coming into the workforce. And we know that AI, it's transformational. It is changing how we work, how you work. But at the same time, are we building out an education layer that's helping train up those folks coming into the workforce so at least they have some of that knowledge base? Maybe they're not experiencing as much as me and you did, but they're in an environment that's pressure tested. It feels like a live-fire exercise that they can maybe mimic some of those wounds that we lived through. I think that's really now more important than ever because they probably won't experience some of those and they won't have that institutional knowledge right out the gates. And then the other one that you just mentioned really quickly is the silent agentic drift, right?

Unknown:Yeah.

Christine Bartlett:Again, that's having a timestamp, or I've heard some CISOs say your agent needs a death sentence, because the reality is you've deployed it for six months. Is it still doing what you thought it was going to do? Has your environment changed? Has your network expanded? Does it have that information? Does it have that full work scope that your employee and your human does? Because we as humans who've been working in this industry know what to look for, know what to stay abreast of. Some new dynamic element comes into your network that it's not trained up on, the agent is not going to operate the way that you probably think it will.

Graham Cluley:And obviously, I mean, we're focusing a lot on the risks here. I mean, obviously there are many ways in which AI is actually making security teams better and defending organisations. If AI is doing more of the work, what is left for the people? How's the poor old human's job changing?

Christine Bartlett:I think it's just a new transformation that we're in. We lived through the age of the internet and our jobs do change over time. I think this one feels more dramatic or drastic because it's like the treadmill that never stops. If you're on it, you're having to run at a certain pace. But I do think for humans, and things that I've even shared at Hack The Box, is it's on us as managers and as people leaders to help our folks get trained up and from an AI fluency level understand the capabilities, understand the good and the bad. And the reality is wherever you go moving forward, you're probably going to need some level of skill, especially if you're in cyber and technology.

Christine Bartlett:You're going to have to have a baseline education on AI moving forward, especially when you do think about the junior talent coming in as already, quote unquote, AI-pilled. They're already coming in, trusting it, leveraging it probably even more successfully than somebody like me in my mid-40s. But I think the reality is the workforce has changed. You'd be crazy not to learn it on some level, but also understand the good and the bad that goes along with it. But where Hack The Box really stands tall is just being able to pressure test your skills and abilities in an environment that's safe, but also allows the AI component and ability to assess your skills alongside using AI and also directing AI.

Graham Cluley:So let's talk now about what Hack The Box actually does. So you are helping companies train their people, you are running exercises for their teams, you're testing their AI agents, right?

Christine Bartlett:Yes, correct.

Graham Cluley:What does that look like in practice?

Christine Bartlett:Yeah, so in practice, there's a couple of different opportunities here. We have job skill workforce paths. So those in the SOC teams, an L1, L2, L3, L4 — are you an incident response manager? Are you a threat analyst? We have coursework and curriculum that's aligned to that. But you say curriculum and you think, oh, textbook, maybe a couple of YouTube videos, right? No, this is an actual immersive environment where, yes, you might study the attack structure and the methodology, but then you're going to open up a lab, which is a live active environment, deploy a pawn box and experience it as if this was happening real time.

Graham Cluley:Right.

Christine Bartlett:And so it does allow for that safe space to fail, learn from your mistakes. And this is where HackTheBox, I think, has grown from a community perspective. We have over 5 million community members because of the education aspect of sharing out there on the interwebs of, hey, I did this module, how did you guys do? And then they get feedback, people help each other. We have community groups that get together that run through these scenarios to understand tactics and techniques. And so I think that's the unique part here is it truly does have a pressure-tested element to it.

Christine Bartlett:And then we also have capture-the-flag activations where you can get a whole team together, benchmark where your team's at, understand what their performance level is. As a manager, you would get a report out on, okay, here's how my team is at today from a skills and abilities perspective. Maybe there's a few folks you're looking to grow or move up into a different role. That's also an opportunity to apply them to a workforce skill development journey, and then they're able to get on that and move up to the next tier of your employment record type of thing, which is great. The other thing I will share as an example, which I thought was fascinating, is one of our customers, with the advent of AI approaching, this was earlier in the year, there was a SOC manager that was asked to let go of some additional team members.

Graham Cluley:Right.

Christine Bartlett:And so that person used HackTheBox to train up as many people as they possibly could to the Tier 2, Tier 3 analyst. They were incredibly successful and they got most people up and they were able to save the majority of their workforce. So I think from that standpoint, there's momentum there and opportunity if you're, as a manager or director, to level up your team, especially at a time when management is looking for efficiencies left, right, and centre to cut costs.

Graham Cluley:That is fantastic. And I'm sure lots of people will be interested in pursuing something like that themselves. For some companies listening, maybe they've never really thought about this. What is the very first step a security team should take to ensure that AI agents are actually making them safer?

Christine Bartlett:Oh man, that's a deep question. I think of exposure first when I hear AI versus safety, but at HackTheBox, we provide that educational layer for your employees to get a baseline of not only just AI fluency, but how to successfully leverage AI or an agent alongside of you as a kind of copilot to complete the challenge or the task at hand. I think one other thing I would just add is that we did a study based on a CTF that we had over a year ago where we had people sign in with humans, and then people brought along their agents and we compared the data. And the interesting part was more junior-level analysts that were using AI were stuck in loops with AI.

Christine Bartlett:They didn't know when AI was just either taking too long or it just didn't make the right decision for them. Whereas a much more experienced senior person kind of knew how to deploy the AI, and if they didn't get what they wanted, they quickly moved on. And I think that was something we discovered a year ago, and it's still relevant today. And so now we provide a training to surface that so that your workforce isn't stuck in a loop and that they're using AI in the right capacity to save the company time, but also manage their time effectively for the business as well.

Graham Cluley:Well, it's been fascinating talking to you today, Christine, and I'm sure lots of our listeners would be interested in finding out more about how HackTheBox can help their organisation. We've got a special link which people can follow to learn more and check out your services, and that is smashingsecurity.com/hackthebox. And all that remains is for me to thank you, Christine Bartlett, for coming on the podcast.

Christine Bartlett:Thank you.

Graham Cluley:Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us. Where can people find out what you're up to and follow you online?

Danny Palmer:Best places are LinkedIn, Bluesky, Mastodon. I also recently updated my website as well. A bit more information about who I am and what I do, so check that out.

Graham Cluley:And of course, you can find me, Graham Cluley, on LinkedIn and Bluesky and Mastodon and Instagram and TikTok. The list goes on. Or follow Smashing Security on Bluesky, Mastodon, or Reddit. And don't forget to ensure you never miss another episode. Follow Smashing Security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocket Casts. The episode show notes, sponsorship info, guest list, and the entire back catalog of 487 episodes — check out smashingsecurity.com. Until next time, cheerio. Bye-bye.

Unknown:Bye-bye.

Graham Cluley:You've been listening to Smashing Security with me, Graham Cluley, and a huge thank you to our sponsor, Sophos. Thank you, of course, to Danny for joining me this week and to the episode sponsors Hack the Box, Origin, and Vanta. Do go and check out their offerings because they help keep the show afloat. Plus, big thanks this week to the following patrons whose names are being plucked out of the hat to be mercilessly ribbed. First out of the hat is Daniel Bourdeau, which is pronounced like the wine region. Presumably he's just as tasteful. Alan Liska, who has 2 L's — actually has 3 L's. That's a lot of L's, Alan. Thank you. Really deluxe edition of you. Dave Barker, no flies on him. Florian Schwalm, who sounds like a Baroque composer waiting to be dug out from the woodwork. Alex Grrr, actually only one R in Grrr. I'm not sure how you pronounce that, but anyway. Anyway, a slightly truncated surname, plenty of mystery. Robert Martin, very simple name there.

Graham Cluley:Good one, Bob Martin. No complaints. Dr_Herbalist, the underscore really sells it. And in the style of a Roman emperor, we have to all hail our last patron to be named this week, which is Orberus. Thank you, Orberus. These fine, upstanding, and generous individuals are all members of Smashing Security Plus, which means that they get their episodes ad-free earlier than the general public, and perhaps most importantly, get their names read out at the end of the show if they're lucky enough to be pulled out of the hat. If you would like to join them, all you have to do is head over to smashingsecurity.com/plus, and for a very modest fee, you too can support the show and say how you love Smashing Security. Of course, if you haven't got the cash, no worries, no pressure there. But there are other ways you can support the show. You can follow the show in your favourite podcast app. You can leave a 5-star review wherever you listen. You can tell your friends about it as well. Why not do that? Every little bit helps, and frankly, it makes all the effort worthwhile. So until next week, cheerio.

Unknown:Bye-bye.

Transcript supplied by the publisher with the episode.

Smashing Security

by Graham Cluley · English · Tech & Science

Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all…

More from Smashing Security

  1. E486 · 41 min

    Vibe-coded shops, and hackable Flock cameras

    A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside. All this and more in episode 486 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner. EPISODE LINKS: Claude Opus…

  2. E485 · 1 hr 3 min

    These researchers got drunk to hack an LG TV

    Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured…

  3. E484 · 46 min

    How websites are tracking you with silence

    When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated." All…

  4. E483 · 44 min

    This AI helps thieves steal your iPhone

    You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just…

  5. E482 · 50 min

    This hacker leaked GTA 6 - and launched their own cryptocurrency

    A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet…

  6. E481 · 46 min

    Never say this to a robot dog

    At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of…

  7. E480 · 46 min

    This is the AI service you should never sign up to

    Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in…

  8. E479 · 1 hr

    How a fake police officer nearly stole Graham's cryptocurrency

    Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education - sending an…

  9. E478 · 59 min

    This job interview could destroy your company

    You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly…

  10. E477 · 51 min

    How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

    A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball. EPISODE LINKS: Bengaluru triple murder: Accused allegedly used…

Every episode of Smashing Security →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play