Graham Cluley
@grahamcluley
Award-winning #cybersecurity keynote speaker, writer, podcaster | Host of multi-award-winning @smashingsecurity.com podcast. ❤️ #DoctorWho, #Beatles, #Chess He/him 🌐 🎙️
Watch out!! I almost fell for it when a "fake policeman" rang me up to talk about my cryptocurrency wallet. Huge thanks to @dannypalmer.bsky.social palmer for joining me on episode 479 of the "Smashing Security" podcast! #cybersecurity #podcast #crypto #cryptocurrency
Paul Ducklin shares a LinkedIn post he found with the audience of the "Smashing Security" podcast, discussing the recent news about AI models breaking out of their supposedly-secure environments... Hear more in episode 478 of the "Smashing Security" podcast! pod.link/1195001633/e...
Anthropic not wanting to be left behind by OpenAI, I see... No doubt someone in their marketing department was crying into their coffee that OpenAI got there first...
𝗕𝗥𝗘𝗔𝗞𝗜𝗡𝗚 𝗡𝗘𝗪𝗦: Microsoft has accidentally invented the weekend... on a Thursday.
"Grok, generate a historically accurate adaptation of a 2,800-year-old poem about a one-eyed giant, a six-headed sea monster, and a witch who turns men into pigs."
Geoff White was approached by a scammer offereing to promote his books, but they didn't know who they were dealing with... Hear the whole story on episode 476 of the "Smashing Security" podcast with me and special guest @geoffwhite247.bsky.social of Lazarus Heist fame. #cybersecurity #podcast
Scattered Spider members who hacked TfL from their bedroom, costing £39 million and exposing data on 10 million customers, were sentenced to 5 years and 6 months each today. The NCA had video footage of them doing it. Video footage they had taken themselves! Remember - crime doesn't pay.
I’m rather distracted during GB News* presenter Andrew Pierce’s reaction to Ann Widdecombe’s death… by the fact he owns a life-size cardboard cut-out of Margaret Thatcher. * I’m err, not a regular viewer…
Thanks (I think) to @rosesec.bsky.social for joining me on episode 475 of the "Smashing Security" podcast, where she appears to want AI to help cybercriminals cover their tracks... Sheesh! Listen to the full pod in your favourite podcast app or at www.smashingsecurity.com/475
Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year Thanks to @rosesec.bsky.social for joining me on episode 475 of the "Smashing Security" podcast! Find it in all the usual places, or www.smashingsecurity.com/475
In the wake of Fortibleed hitting Fortinet firewall users, "Smashing Security" podcast special guest @quentyn.bsky.social recommends you should be bouncing your credentials.... oh, and you are using passkeys and hardware tokens for your MFA, right? www.smashingsecurity.com/474
Despite their name, there is nothing polite or refined about The Gentlemen ransomware group. Learn more about them in my article on the Fortra blog: www.fortra.com/blog/gentlem...
Someone is pretending to be your bank, your government, or your local planning office. And according to the FTC, they're making billions doing it. Read more in my article on the Fortra blog about the rising tide of imposter scams. www.fortra.com/blog/imposte...
Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. www.fortra.com/blog/silent-...
Hmm. Remembering 1985, when I bought this godawful single… Doctor Who feels like it is returning to the wilderness years… which may be the best thing for it for a while.
Hackers have been hijacking Instagram accounts at scale by exploiting Meta's AI support chatbot. And, as if that weren't bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog: www.fortra.com/blog/metas-o...
Thanks to @shehackspurple.bsky.social for joining the podcast this week. Amongst other topics, we discussed a paper from Cornell that suggests prompt injection - the technique malicious actors use to trick AI agents into doing things they really shouldn't - may be fundamentally unsolvable. 1/3
The fab @hacks4pancakes.com pays a visit to the "Smashing Security" podcast in episode 469, to discuss how the Oura ring fitness tracker transmits unencrypted data... but the company can't say how often it shares it with law enforcement Check out the Smashing Security show in all good podcast apps!
A 14-year-old turned the tram system in the Polish city of Lodz into his own personal train set in 2008, triggering chaos and derailing four vehicles, using a modified a TV remote control. Join me, and special guest Geoff White, on episode 468 of "Smashing Security" in all good podcast apps.
Going to be at Infosecurity Europe next week? Join me, and the experts from Varonis for an exclusive invite‑only panel and buffet lunch where we'll be discussing how AI is changing attacks, where most breaches really start, and why stopping them is harder than ever. ▶️ grahamcluley.com/aipanel
For 19 years, stolen credentials have topped the Verizon Data Breach Investigations Report as the number one way attackers get into networks. But not anymore. I've written up the key takeaways. Worth a quick read before you tackle the full report: www.fortra.com/blog/defende...
Could hacked robot lawn mowers be used to kill? A journalist at @theverge.com put it to the test... with uncomfortable results. Hear more in episode 468 of the "Smashing Security" podcast with Graham Cluley and special guest @geoffwhite247.bsky.social www.smashingsecurity.com/468
Fab to have @dannypalmer.bsky.social back on the podcast. This week: 30 million students log into Canvas mid-finals and find a winky-faced ransom note waiting for them. Canvas initially refused to pay, so the hackers came back through the cat flap - defacing login pages. 1/3
One in eight UK workers admits to selling their company login credentials - or knowing someone who has - in the past 12 months. The really alarming bit? Their bosses are even more relaxed about it. Read more in my article on the Fortra blog: www.fortra.com/blog/one-eig...
Always great to have @jamesrball.com as a guest on the "Smashing Security" podcast! This week: we look at SS7 - the ancient phone protocol that lets surveillance companies track anyone, anywhere, via their mobile. Governments know. Telecoms know. Nobody's doing anything about it. 1/3