Smashing Security-logo

Smashing Security

Technology Podcasts

Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror...

Location:

United Kingdom

Description:

Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle. Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider. Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app. New episodes released at 7pm EST every Wednesday (midnight UK).

Language:

English


Episodes
Ask host to enable sharing for playback control

Rockstar got hacked. The data was junk. The secrets it revealed were not

4/22/2026
A company that ran anonymous tip lines for 35,000 American schools - handling reports of bullying, weapons, and self-harm - boasted on its website that it had suffered zero security breaches in over 20 years. A hacker called Internet Yiff Machine thought that sounded like a challenge, with predictable results... Meanwhile, Rockstar Games gets hacked again - and the stolen data turns out to be less embarrassing than the financial secrets it accidentally revealed. GTA Online is still making half a billion dollars a year. Red Dead Redemption is not. All this and more in episode 464 of the "Smashing Security" podcast with cybersecurity keynote speaker and industry veteran Graham Cluley, joined this week by special guest BBC cybersecurity correspondent Joe Tidy. Plus! Don't miss our featured interview with Ryan Benson of Meter. EPISODE LINKS: Grinex exchange blames "Western intelligence" for $13.7M crypto hackAre Former Black Basta Affiliates Automating Executive Targeting?Apple is working on passcode bug locking out iPhone usersHackers who stole crime tip records offering data cache for $10kP3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened NextPortland police urge residents to avoid Crime Stoppers following hackGTA-maker Rockstar Games hacked again but downplays impactRockstar hackers release their stolen data, reveal that Rockstar was right to not pay them anything for itXCancel”We Are Anonymous” by Parmy OlsonSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ElasticMeterVanta SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:51:25

Ask host to enable sharing for playback control

This AI company leaked its own code. It's also built something terrifying

4/15/2026
A hacking group claims to have broken into the flood defence system protecting Venice's Piazza San Marco - and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthropic accidentally leaked the source code for Claude Code via a basic packaging mistake. Oh, and by the way, they've also just revealed they've built an AI model called Mythos that can find and chain together software vulnerabilities faster than any human. Sleep well. All this and more in episode 463 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Tanya Janca. EPISODE LINKS: Booking.com warns customers of hack that exposed their data - The Guardian.GTA-maker Rockstar Games hacked again but downplays impact - BBC News.Meta removes ads for social media addiction litigation - Axios.Hackers claim control over Venice San Marco anti-flood pumps - Security Affairs.Venezia, attacco hacker al sistema di pompe che difende piazza San Marco dall'acqua: «Abbiamo i codici, possiamo disattivarlo» - Corriere del Veneto. Digging into the Claude Code source - Dave Schumaker’s write-up of Anthropic leaking data in February 2025.Anthropic goes nude, exposes Claude Code source by accident - The Register.Assessing Claude Mythos Preview’s cybersecurity capabilities - Anthropic.Smashing Security transcripts!Shrinking - Apple TV. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: MeterVantaCoreview SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:50:35

Ask host to enable sharing for playback control

LinkedIn is spying on you, and you agreed to nothing

4/8/2026
LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you're job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned anywhere in their privacy policy. Meanwhile, California's crypto millionaires are learning that no amount of encryption can protect you from someone who knocks on your door pretending to deliver a pizza. All this and more in episode 462 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Dave Bittner. EPISODE LINKS: Russian government hackers broke into thousands of home routers to steal passwordsRefusal to Give the Government Passwords to Personal Mobile Device Criminalized in Hong Kong"I didn't think millions would see this..." Russians are calling each other through a cat feederBrowserGateScanned extensions databaseLinkedIn secretly scans for 6,000+ Chrome extensions, collects dataTranslate into LinkedIn speakSecurityWealthy California crypto holders targeted in violent ‘wrench attacks’Lost Doctor Who episodes to be released this weekDoctor Who: The Daleks’ Master Plan - The Nightmare BeginsDoctor Who: The Daleks’ Master Plan - Devil’s PlanetMilton Bradley Grandmaster Robotic Chess ComputerRobot Chess - One-armed gambitSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ESETMeterVanta SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:41:59

Ask host to enable sharing for playback control

This man hid $400 million in a fishing rod. Then it vanished

4/1/2026
A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 - and now sits on a fortune worth $400 million. There's just one small problem: the access codes were tucked inside his fishing rod case, which has mysteriously vanished. Or has it? Because this week, one of his frozen wallets suddenly woke up and moved $35 million - and someone had to identify themselves to do it. Meanwhile, Ajax Football Club scores a spectacular cyber own-goal, as a data breach that the club claimed affected "a few hundred" fans turns out to may have exposed the personal details of 300,000 supporters - along with the ability to steal match tickets and quietly remove people from the stadium ban list. All this and more in episode 461 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Danny Palmer. EPISODE LINKS: Iran-linked hackers breach FBI director's personal email, publish photos and documentsWindows PCs crash three times as often as Macs, report saysWife used CCTV to steal $176M of husband’s crypto, UK court toldGardaí open €30m bitcoin virtual wallet, first of 12 accessed since seizure in 2019Irish Drug Dealer’s Lost BTC Stack Worth $400m Has Woken UpAjax FC data breach exposes 300,000 fans, hacker steals tickets an stadium ban detailsSmall ProphetsRPG TavernsSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Action1MeterVanta SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:45:32

Ask host to enable sharing for playback control

Never knock on the door of a nuclear submarine base and ask for a selfie

3/25/2026
A disgruntled data analyst decides that the best response to losing his contract is to steal the entire company payroll database and demand $2.5 million in Bitcoin - signing his extortion emails from a company called "Loot." Meanwhile, two people drive up to the entrance of the UK's nuclear submarine base at Faslane and politely ask if they can have a look around. Tourists? Spies? Something in between? Plus: Female Muslim punk rock group, and a little red book that might save your sanity in a post-truth world. All this and more in episode 460 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Jenny Radcliffe. EPISODE LINKS: A Top Google Search Result for Claude Plugins Was Planted by HackersIowa-based Intoxalock cyberattack disrupts calibration service for interlock usersChina hacker group leaks $7M crypto theft operation targeting wallet supply chainsFederal Jury Convicts Charlotte Man For Cyber Extortion Scheme That Targeted International Technology CompanyIranian and Romanian charged after allegedly trying to enter UK nuclear naval baseLadyPartsOn Disinformation: How to Fight for Truth and Protect DemocracySmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ThreatLockerVantaMeter SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:40:43

Ask host to enable sharing for playback control

This clever scam nearly hijacked a tech CEO's Apple ID

3/18/2026
In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you're immune? Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to reveal everything. And! Human-powered “AI”, and a punishment worse than prison: eight hours on the RSA expo floor... All this, and much more, in episode 459 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Paul Ducklin. EPISODE LINKS: DOGE employee stole Social Security data and put it on a thumb drive, report says - TechCrunch.Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show - Reuters.New font-rendering trick hides malicious commands from AI tools - Bleeping Computer.Lockdown Mode - Apple support.Gone (Almost) Phishin’ - Matt Mullenweg.Listen to the Live Scam Call Targeting Matt Mullenweg’s Apple Account - YouTube.Confidential health records from UK BioBank project exposed online - The Guardian.A message from Professor Sir Rory Collins, Chief Executive and Principal Investigator of UK Biobank - UK BioBank.Psychotherapy data breach blackmailer sent to prison - Paul Ducklin.Your AI slop bores me.Post by Vaughan Shanks - LinkedIn.Judge Sentences CISO to 8 Consecutive Hours on RSA Expo Floor as Formal Punishment for Security Breach - The Exploit.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaAdaptive SecurityMeter SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:54:43

Ask host to enable sharing for playback control

How not to steal $46 million from the US government

3/11/2026
A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn't stirred since 2024 - and within minutes, giant woodpecker images are plastered across the internet's favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized digital assets allegedly decides to help himself to $46 million of it - and then brags about it on a recorded Telegram call. Plus: Graham champions Asterix, Trisha discovers the fantasy novels of Robin Hobb, and someone called "Lick" ends up in the nick. All this, and much more, in episode 458 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Tricia Howard. EPISODE LINKS: Major data leak forum dismantled in global action against cybercrime forum - Europol.Ericsson blames vendor vishing slip-up for breach exposing thousands of records - The Register.How hackers bypassed MFA with a $120 phishing kit – until law enforcement shut them down - Hot for Security.Wikipedia hit by self-propagating JavaScript worm that vandalized pages - Bleeping Computer.FBI arrests crypto thief accused of stealing $46 million from seized government wallet - Tom’s Hardware.Twitter thread by ZachXBT about John Daghita’s arrest - Twitter.Asterix - Wikipedia.Robin Hobb.The Complete Farseer trilogy - Harper Collins.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaThreatLockerMeter SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:41:16

Ask host to enable sharing for playback control

How a cybersecurity boss framed his own employee

3/4/2026
When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker... who promptly sent an innocent colleague into a career-ending ambush. In this episode, we unravel the jaw-dropping tale of a defence contractor caught selling zero-day exploits to a Russia-linked broker. Plus: are nation states quietly poisoning AI models to bend reality itself? We explore how “foreign information manipulation interference” could target not just social media users, but the large language models we increasingly trust for answers — and what that might mean for truth, trust, and the future of online influence. All this, and much more, in episode 457 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Carl Miller. EPISODE LINKS: Large-Scale Online Deanonymization with LLMsHacked Prayer App Sends ‘Surrender’ Messages to Iranians Amid Israeli and US Strikes“Stay safe out there gamers”: Streamers say Amazon just made Wishlists a doxxing riskApple alerts exploit developer that his iPhone was targeted with government spywareFormer General Manager for U.S. Defense Contractor Sentenced to 87 Months for Selling Stolen Trade Secrets to Russian BrokerTreasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber ToolsInside the story of the US defense contractor who leaked hacking tools to Russia​​Hundreds of English-language websites link to pro-Kremlin propagandaThe Incredible Shrinking Man“The Immortalists” by Aleks KortoskiSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Action1MeterVanta SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:49:31

Ask host to enable sharing for playback control

How to lose friends and DDoS people

2/25/2026
When the mysterious operator of an internet archiving-service decided to silence a curious Finnish blogger, they didn’t just send a stroppy email - they allegedly weaponised their own CAPTCHA page to launch a DDoS attack, threatened to invent an entirely new genre of AI porn, and tampered with parts of their own archive to smear the blogger's name. In this episode, we unravel how a website designed to preserve history may have trashed its own credibility - and how Wikipedia responded when trust went out the window. Plus a ransomware gang shoots itself in the foot with a classic case of buffoonery, accidentally corrupting the very keys victims would need to decrypt their data. When even the criminals can’t unlock your files, what happens next? All this, a surprisingly zen Pick of the Week, and a gloriously splenetic rant against web forms, on episode 456 of the award-winning "Smashing Security" podcast, with cybersecurity veteran Graham Cluley and special guest Paul Ducklin. EPISODE LINKS: This App Will Detect People Wearing Smart Glasses Near You - Lifehacker.Patients listed as dead after major NZ health app MediMap hacked - 1News.Why fake AI videos of UK urban decline are taking over social media - BBC News.FBI orders domain registrar to reveal who runs mysterious Archive.is site - Ars Technica.Archive.today CAPTCHA page executes DDoS; Wikipedia considers banning site - Ars Technica.Archive.today is directing a DDOS attack against my blog - Gyrovague.Critical buffer overflow bug - in ESXi ransomware - SolCyber.Yoga with Adriene - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: CoreviewVantaThreatLocker SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:48:43

Ask host to enable sharing for playback control

Face off: Meta’s Glasses and America’s internet kill switch

2/18/2026
Could America turn off Europe's internet? That’s one of the questions that Graham and special guest James Ball will be exploring as they discuss tech sovereignty. Could Gmail, cloud services, and critical infrastructure really become geopolitical leverage? And is anyone actually building a Plan B? Plus we explore if Meta is quietly plotting to turn its smart glasses into face-recognising surveillance specs? With reports of internal memos suggesting they plan to launch controversial features while everyone’s distracted by political chaos, we ask: is this innovation really wanted by the public... or something far creepier? All of this, and much more, in episode 455 of the award-winning "Smashing Security" podcast with cybersecurity veteran Graham Cluley, joined this week by journalist and author James Ball. EPISODE LINKS: Meta Plans to Add Facial Recognition Technology to Its Smart GlassesTrading Sovereignty for Scale? The Costs of the US - UK Tech Prosperity DealJust Mercy Just Mercy trailerBryan Stevenson’s TED talk: We need to talk about an injusticeThe ResidenceSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaPassworkAdaptive Security SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:44:53

Ask host to enable sharing for playback control

AI was not plotting humanity’s demise. Humans were

2/11/2026
AI bots are having existential crises, inventing religions, and allegedly plotting against humanity... or so the internet would have you believe. We dig into Moltbook, the “AI-only” social network that sent Twitter into a meltdown, attracted breathless talk of the singularity, and turned out to be far less Terminator and far more humans role-playing as bots. Plus we discuss why "vibe coding" your app might be a catastrophically bad idea, when security researchers can easily peek inside rifle through your private messages, API keys, and databases. Also this week we learn that pro-Russian hackers are circling the Winter Olympics - or is it the Jamaican Bobsleigh team? All this and more is discussed in episode 454 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Iain Thomson. EPISODE LINKS: AI Agents Created Their Own Religion, Crustafarianism, On An Agent-Only Social Network - Forbes.I Infiltrated Moltbook, the AI-Only Social Network Where Humans Aren’t Allowed - Wired.'Moltbook' social media site for AI agents had big security hole, cyber firm Wiz says - Reuters.Italy blames Russia-linked hackers for cyberattacks ahead of Winter Olympics - The Record.Italy says railways hit by 'serious sabotage' as Winter Olympics begin - BBC News.EpsteIN - GitHub.Private Eye.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: MeterVantaPasswork SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:40:19

Ask host to enable sharing for playback control

The Epstein Files didn’t hide this hacker very well

2/4/2026
Supposedly redacted Jeffrey Epstein files can still reveal exactly who they’re talking about - especially when AI, LinkedIn, and a few biographical breadcrumbs do the heavy lifting. Sloppy redaction leads to explosive claims, and difficult reputational consequences for cybersecurity vendors, and we learn how trust - once cracked - can be almost impossible to fully restore. Elsewhere, the spotlight turns to insider threat in the age of AI, after a senior US cybersecurity official uploads sensitive government material into the public version of ChatGPT. Oops. All this, and much more, in episode 453 of Smashing Security with cybersecurity veteran Graham Cluley and special guest Tricia Howard. EPISODE LINKS: Notepad++ hijacked to serve malware in targeted attacks - Notepad++.Porn-quitting app caught leaking users’ sexual habits - 404 Media.MicroWorld Technologies’ eScan anti-virus update turned into a malware delivery system - Morphisec.Jmail.World.Informant told FBI that Jeffrey Epstein had a ‘personal hacker’ - Techcrunch.Confidential informant statement given to FBI - US Department of Justice.Post by Graham Cluley - LinkedIn.Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - Politico.We are Lady Parts - Channel 4.We are Lady Parts trailer - YouTube.“Bashir with a good beard” by We are Lady Parts - YouTube.“Voldermort under my headscarf” by We are Lady Parts - YouTube.Doctor Who: The Shakespeare Notebooks - Penguin.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: PassworkMeterVanta SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:36:38

Ask host to enable sharing for playback control

The dark web's worst assassins, and Pegasus in the dock

1/28/2026
In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus, we go looking for professional hitmen online - only to uncover uncomfortable questions about why some crimes attract customers but very few complaints. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veteran Graham Cluley, joined this week by special guest Joe Tidy. EPISODE LINKS: Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patchRussian state hackers likely behind wiper malware attack on Poland’s power gridUS charges 31 more suspects linked to ATM malware attacksDark web arrests in Romania linked to portal which offered services including murderRomanian scammers ran fake hitman-for-hire site, lured desperate perpetrators as 'incompetent assassins'This Fake Hitman Site Is the Most Elaborate, Twisted Dark Web Scam YetUnlikely Assassin, The Murder of Amy AllwineSaudi dissident awarded $4.1 million by UK court for hacking, assault 'by Saudi Arabia'Stalkerware: The software that spies on your partnerUsing 'stalkerware' to spy on a colleague's phone“Polite Society” trailerElegoo Saturn 3 3D printerSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: PassworkCoreviewVanta SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:45:37

Ask host to enable sharing for playback control

I hacked the government, and your headphones are next

1/21/2026
In episode 451 of "Smashing Security," we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more - and then helpfully posted screenshots (and even someone’s blood type) on an account called "I hacked the government." Plus we discuss how researchers uncovered a creepy flaw that lets attackers hijack wireless headphones, listen in on calls, inject audio, and even turn your earbuds into a stalking device - all without you noticing. All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Ray [REDACTED] EPISODE LINKS: Tennessee Man Pleads in Hacking U.S. Supreme Court, AmeriCorps, and VA Health System - US Department of Justice.Paris Hilton’s hacker sentenced to 57 months in prison - Graham Cluley.WhisperPair.One Tap To Hijack Them All - A Security Analysis of the Google Fast Pair Protocol - YouTube.Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking - Wired.Line of Duty - Wikipedia.Line of Duty - BBC iPlayer.Forgive the haters - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaThreatLockerAdaptive Security SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Y Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:45:15

Ask host to enable sharing for playback control

From Instagram panic to Grok gone wild

1/14/2026
Confusion reigns after claims that data linked to 17.5 million Instagram accounts is up for sale - sparked by a vague post, contradictory statements, and a flood of password reset emails nobody asked for. And we dig into Grok, Elon Musk’s AI chatbot, after it started generating sexualised images of women and children - raising uncomfortable questions about guardrails, accountability, and why playing the censorship card doesn’t make the problem go away. All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Monica Verma. EPISODE LINKS: Free Speech Union website down after alleged funders exposed by trans hackers - Pink News.Illinois Man Charged in Snapchat Hacking Investigation - US Dept of Justice.Hackers get hacked, as BreachForums database is leaked - Hot for Security.Post by Malwarebytes - Bluesky.Post by Instagram - Twitter.Instagram denies breach amid claims of 17 million account data leak - Bleeping Computer.Ofcom asks X about reports its Grok AI makes sexualised images of children - BBC News.Musk’s Grok blocked by Indonesia, Malaysia over sexualized images in world first - CNN.Elon Musk shares AI images of Starmer in bikini in row over grim Grok deepfakes - Mirror.Soul Music - BBC Sounds.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaMeter SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. ENJOYED THE SHOW? Make sure to check out our sister podcast, "The AI Fix". Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:36:30

Ask host to enable sharing for playback control

How to scam someone in seven days

1/7/2026
Romance scammers have apparently discovered astrology... and Taurus is their secret weapon. In episode 449 of "Smashing Security", we take a look inside an actual romance-fraud handbook - complete with scripts, personality “types”, corporate jargon, and a seven-day plan to get victims from hello to hand over the crypto. Then Lesley "hacks4pancakes" Carhart delivers a reality check on the dire cybersecurity jobs market for juniors: why entry-level roles are evaporating, how automated CV screening is chewing candidates up, and what hopeful newcomers (and weary veterans) can do about it. Plus, Graham talks to ThreatLocker CEO Danny Jenkins about why misconfigurations are behind an uncomfortable number of breaches, how default-deny security actually works in practice, and why detecting attacks after they’ve started is already too late. All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Lesley Carhart. EPISODE LINKS: Millions of Android Powered TVs and Streaming Devices Infected by Kimwolf Botnet - Hackread.Ilya Lichtenstein, Bitcoin hacker behind massive crypto theft, credits Trump for early prison release - CNBC.How Fake BSODs and Trusted Build Tools Are Used to Construct a Malware Infection - Securonix.A scammer's guide: How cybercriminals plot to rob a target in a week - Reuters.Game of Wool: Britian’s Best Knitter - Channel 4.Game of Wool trailer - YouTube.Earthrise One: Melbourne's Premier Sci-Fi Escape Room Adventure.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaThreatLockerMeter SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. ENJOYED THE SHOW? Make sure to check out our sister podcast, "The AI Fix". Privacy & Opt-Out: https://redcircle.com/privacy

Duration:01:01:10

Ask host to enable sharing for playback control

The Kindle that got pwned

12/17/2025
Think your Kindle is harmless? Think again! In this episode, Graham and special guest Danny Palmer unpack a Black Hat Europe talk revealing how a boobytrapped audiobook could exploit the Amazon eBook reader - potentially letting an attacker break into your account and seize control of your credit card. Plus a blast from 2021's "summer of ransomware" returns to haunt Ireland's Health Service Executive, as victims are offered €750 each. And because it's the last show before the Christmas break, there's also a Pick of the Week that veers from cosy rom-com comfort to pointy-polygon nostalgia. All this, and more, in episode 448 of the "Smashing Security" podcast with Graham Cluley, and special guest Danny Palmer. 🎅 🎄 Thanks to everyone for listening to "Smashing Security" during 2025 - we look forward to being back in your ear'oles in early January. Stay safe! 🎅 🎄 EPISODE LINKS: Password manager provider fined £1.2m by ICO for data breach affecting up to 1.6 million people in the UK - ICO.Trump Administration Turning to Private Firms in Cyber Offensive - Bloomberg.Russian ban on Roblox gaming platform sparks rare protest - Reuters.Once upon an exploit: how fake audiobook led to Kindle takeover - Cybernews.Four years later, Irish health service offers €750 to victims of ransomware attack - Bitdefender.When Harry Met Sally - Wikipedia.When Harry Met Sally trailer - YouTube.Tomb Raider 1-3 Remastered review - you were never going to smooth these games out - Eurogamer.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaThreatLocker SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. ENJOYED THE SHOW? Make sure to check out our sister podcast, "The AI Fix". Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:36:41

Ask host to enable sharing for playback control

Grok the stalker, the Louvre heist, and Microsoft 365 mayhem

12/10/2025
On this week's show we learn that AI really can be a stalker’s best friend, as we explore a strange tale that starts with a manatee-shaped mailbox on a millionaire's lawn and ends with Grok happily doxxing real people, mapping out stalking "strategies," and handing out revenge-porn tips. Then we go inside the Louvre heist, where thieves in hi-vis and a hire van waltzed off with the French crown jewels in broad daylight, exploiting our assumptions about what "looks normal" - the same kind of bias we’re now baking into security AIs. Plus, Graham chats with Rob Edmondson from CoreView about why misconfigurations and over-privileged accounts can make Microsoft 365 dangerously vulnerable. All this, and more, in episode 447 of the "Smashing Security" podcast with Graham Cluley, and special guest Jenny Radcliffe. EPISODE LINKS: Khashoggi widow files complaint in France alleging Saudi government infected devices with spywareUS Posts $10 Million Bounty for Iranian HackersInfostealer has entered the chatDave Portnoy posts a photo of his lawn (including a manatee-shaped mailbox)Elon Musk’s Grok AI Is Doxxing Home Addresses of Everyday PeopleElon Musk’s Grok Is Providing Extremely Detailed and Creepy Instructions for StalkingHow the Louvre thieves exploited human psychology to avoid suspicion – and what it reveals about AIOutrageous (TV series)Outrageous trailerMan charged with theft after allegedly swallowing Fabergé pendant in jewellery storeFree Microsoft 365 Tenant Security ScannerSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: VantaHorizon3.aiCoreView SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. ENJOYED THE SHOW? Make sure to check out our sister podcast, "The AI Fix". Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:55:38

Ask host to enable sharing for playback control

A hacker doxxes himself, and social engineering-as-a-service

12/3/2025
A teenage cybercriminal posts a smug screenshot to mock a sextortion scammer... and accidentally hands over the keys to his real-world identity. Meanwhile, we look into the crystal ball for 2026 and consider how stolen data is now the jet fuel of cybercrime – and how next year could be even nastier than 2025. Plus, Graham rants about recipe sites that won’t shut up, and there's even more love for Lily Allen's album "West End Girl" album. All this and more is discussed in episode 446 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Rik Ferguson. EPISODE LINKS: Europol nukes Cryptomixer laundering hub, seizing €25M in Bitcoin4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware CampaignUncovering a Calendly-themed phishing campaign targeting business ad manager accountsMeet Rey, the Admin of ‘Scattered Lapsus$ Hunters’Jonathan Ross email goof highlights Twitter security issueVIDEO: Mark Zuckerberg’s password choices are dadada-dumb!Password to Louvre’s video surveillance system was 'Louvre', according to employeeJust the RecipeWest End GirlWest End GirlSmashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: 1PasswordVantaDrata SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. ENJOYED THE SHOW? Make sure to check out our sister podcast, "The AI Fix". Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:44:32

Ask host to enable sharing for playback control

The hack that brought back the zombie apocalypse

11/26/2025
America's airwaves are haunted by zombies again, as we dig into a decade of broadcasters leaving their hardware open to attack, giving hackers the chance to hijack TV shows, blast out fake emergency alerts, and even replace religious sermons with explicit furry podcasts. Meanwhile, we look at how a worker at a cybersecurity firm allegedly leaked internal information to a hacking gang - raising big questions about insider threats. Plus: Frankenstein on Netflix, Vine nostalgia, and why Barney the Dinosaur may be the true criminal mastermind behind it all. All this and more is discussed in episode 445 of the “Smashing Security” podcast with cybersecurity veteran Graham Cluley, and special guest Dan Raywood. EPISODE LINKS: Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix - Acronis.Tokyo Court Finds Cloudflare Liable For Manga Piracy in Long-Running Lawsuit - TorrentFreak.Former Google chief accused of spying on employees through account ‘backdoor’ - LA Times.Bogus zombie apocalypse warnings undermine US emergency alert system - Ars Technica.2013 EAS Zombie Hoax - Emergency Alert System Wiki.The 1987 Max Headroom incident - YouTube.Nation-wide radio station hack airs hours of vulgar “furry sex” ramblings - Ars Technica.ESPN 97.5 Houston Victim Of Barix Hack - Radio Insight.ESPN Houston apologises to viewers - Facebook.CrowdStrike fires ‘suspicious insider’ who passed information to hackers - TechCrunch.Frankenstein official trailer - YouTube.Frankenstein - Netflix.Vine: Six Seconds that changed the world - Global Player.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Action1VantaHorizon3.ai SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. ENJOYED THE SHOW? Make sure to check out our sister podcast, "The AI Fix". Privacy & Opt-Out: https://redcircle.com/privacy

Duration:00:40:58