• How to lose friends and DDoS people
    Feb 26 2026
    When the mysterious operator of an internet archiving-service decided to silence a curious Finnish blogger, they didn’t just send a stroppy email - they allegedly weaponised their own CAPTCHA page to launch a DDoS attack, threatened to invent an entirely new genre of AI porn, and tampered with parts of their own archive to smear the blogger's name.In this episode, we unravel how a website designed to preserve history may have trashed its own credibility - and how Wikipedia responded when trust went out the window.Plus a ransomware gang shoots itself in the foot with a classic case of buffoonery, accidentally corrupting the very keys victims would need to decrypt their data. When even the criminals can’t unlock your files, what happens next?All this, a surprisingly zen Pick of the Week, and a gloriously splenetic rant against web forms, on episode 456 of the award-winning "Smashing Security" podcast, with cybersecurity veteran Graham Cluley and special guest Paul Ducklin.EPISODE LINKS:This App Will Detect People Wearing Smart Glasses Near You - Lifehacker.Patients listed as dead after major NZ health app MediMap hacked - 1News.Why fake AI videos of UK urban decline are taking over social media - BBC News.FBI orders domain registrar to reveal who runs mysterious Archive.is site - Ars Technica.Archive.today CAPTCHA page executes DDoS; Wikipedia considers banning site - Ars Technica.Archive.today is directing a DDOS attack against my blog - Gyrovague.Critical buffer overflow bug - in ESXi ransomware - SolCyber.Yoga with Adriene - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    49 mins
  • Face off: Meta’s Glasses and America’s internet kill switch
    Feb 19 2026

    Could America turn off Europe's internet?

    That’s one of the questions that Graham and special guest James Ball will be exploring as they discuss tech sovereignty. Could Gmail, cloud services, and critical infrastructure really become geopolitical leverage? And is anyone actually building a Plan B?

    Plus we explore if Meta is quietly plotting to turn its smart glasses into face-recognising surveillance specs? With reports of internal memos suggesting they plan to launch controversial features while everyone’s distracted by political chaos, we ask: is this innovation really wanted by the public... or something far creepier?

    All of this, and much more, in episode 455 of the award-winning "Smashing Security" podcast with cybersecurity veteran Graham Cluley, joined this week by journalist and author James Ball.


    EPISODE LINKS:


    • Meta Plans to Add Facial Recognition Technology to Its Smart Glasses - New York Times.
    • Trading Sovereignty for Scale? The Costs of the US - UK Tech Prosperity Deal - Just Security.
    • Just Mercy - Wikipedia.
    • Just Mercy trailer - YouTube.
    • Bryan Stevenson’s TED talk: We need to talk about an injustice - YouTube.
    • The Residence - Netflix.
    • Smashing Security merchandise (t-shirts, mugs, stickers and stuff)



    SPONSORS:

    • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    • Passwork - a reliable secrets manager and password management solution.
    • Adaptive Security - request a custom demo featuring a real CEO deepfake simulation.


    SUPPORT THE SHOW:

    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


    FOLLOW THE SHOW:

    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


    THANKS:

    Theme tune: "Vinyl Memories" by Mikael Manvelyan.

    Assorted sound effects: AudioBlocks.



    Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    45 mins
  • AI was not plotting humanity’s demise. Humans were
    Feb 12 2026

    AI bots are having existential crises, inventing religions, and allegedly plotting against humanity... or so the internet would have you believe.

    We dig into Moltbook, the “AI-only” social network that sent Twitter into a meltdown, attracted breathless talk of the singularity, and turned out to be far less Terminator and far more humans role-playing as bots.

    Plus we discuss why "vibe coding" your app might be a catastrophically bad idea, when security researchers can easily peek inside rifle through your private messages, API keys, and databases.

    Also this week we learn that pro-Russian hackers are circling the Winter Olympics - or is it the Jamaican Bobsleigh team?

    All this and more is discussed in episode 454 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Iain Thomson.


    EPISODE LINKS:


    • AI Agents Created Their Own Religion, Crustafarianism, On An Agent-Only Social Network - Forbes.
    • I Infiltrated Moltbook, the AI-Only Social Network Where Humans Aren’t Allowed - Wired.
    • 'Moltbook' social media site for AI agents had big security hole, cyber firm Wiz says - Reuters.
    • Italy blames Russia-linked hackers for cyberattacks ahead of Winter Olympics - The Record.
    • Italy says railways hit by 'serious sabotage' as Winter Olympics begin - BBC News.
    • EpsteIN - GitHub.
    • Private Eye.
    • Smashing Security merchandise (t-shirts, mugs, stickers and stuff)



    SPONSORS:

    • Meter - Network infrastructure for the enterprise. Get a free personalised demo.
    • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    • Passwork - a reliable secrets manager and password management solution.



    SUPPORT THE SHOW:

    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


    FOLLOW THE SHOW:

    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


    THANKS:

    Theme tune: "Vinyl Memories" by Mikael Manvelyan.

    Assorted sound effects: AudioBlocks.




    Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    40 mins
  • The Epstein Files didn’t hide this hacker very well
    Feb 5 2026
    Supposedly redacted Jeffrey Epstein files can still reveal exactly who they’re talking about - especially when AI, LinkedIn, and a few biographical breadcrumbs do the heavy lifting.Sloppy redaction leads to explosive claims, and difficult reputational consequences for cybersecurity vendors, and we learn how trust - once cracked - can be almost impossible to fully restore.Elsewhere, the spotlight turns to insider threat in the age of AI, after a senior US cybersecurity official uploads sensitive government material into the public version of ChatGPT. Oops.All this, and much more, in episode 453 of Smashing Security with cybersecurity veteran Graham Cluley and special guest Tricia Howard.EPISODE LINKS:Notepad++ hijacked to serve malware in targeted attacks - Notepad++.Porn-quitting app caught leaking users’ sexual habits - 404 Media.MicroWorld Technologies’ eScan anti-virus update turned into a malware delivery system - Morphisec.Jmail.World.Informant told FBI that Jeffrey Epstein had a ‘personal hacker’ - Techcrunch.Confidential informant statement given to FBI - US Department of Justice.Post by Graham Cluley - LinkedIn.Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - Politico.We are Lady Parts - Channel 4.We are Lady Parts trailer - YouTube.“Bashir with a good beard” by We are Lady Parts - YouTube.“Voldermort under my headscarf” by We are Lady Parts - YouTube.Doctor Who: The Shakespeare Notebooks - Penguin.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Passwork - a reliable secrets manager and password management solution.Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    37 mins
  • The dark web's worst assassins, and Pegasus in the dock
    Jan 29 2026
    In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device.Plus, we go looking for professional hitmen online - only to uncover uncomfortable questions about why some crimes attract customers but very few complaints.All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veteran Graham Cluley, joined this week by special guest Joe Tidy.EPISODE LINKS:Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch - The Register.Russian state hackers likely behind wiper malware attack on Poland’s power grid - The Record.US charges 31 more suspects linked to ATM malware attacks - Bleeping Computer.Dark web arrests in Romania linked to portal which offered services including murder - ROCU.Romanian scammers ran fake hitman-for-hire site, lured desperate perpetrators as 'incompetent assassins' - Fox News.This Fake Hitman Site Is the Most Elaborate, Twisted Dark Web Scam Yet - VICE.Unlikely Assassin, The Murder of Amy Allwine - Rooster.Saudi dissident awarded $4.1 million by UK court for hacking, assault 'by Saudi Arabia' - Reuters.Stalkerware: The software that spies on your partner - BBC News.Using 'stalkerware' to spy on a colleague's phone - YouTube.“Polite Society” trailer - YouTube.Elegoo Saturn 3 3D printer - Elegoo.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Passwork - a reliable secrets manager and password management solution.Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    46 mins
  • I hacked the government, and your headphones are next
    Jan 22 2026

    In episode 451 of "Smashing Security," we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more - and then helpfully posted screenshots (and even someone’s blood type) on an account called "I hacked the government."

    Plus we discuss how researchers uncovered a creepy flaw that lets attackers hijack wireless headphones, listen in on calls, inject audio, and even turn your earbuds into a stalking device - all without you noticing.

    All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Ray [REDACTED]


    EPISODE LINKS:


    • Tennessee Man Pleads in Hacking U.S. Supreme Court, AmeriCorps, and VA Health System - US Department of Justice.
    • Paris Hilton’s hacker sentenced to 57 months in prison - Graham Cluley.
    • WhisperPair.
    • One Tap To Hijack Them All - A Security Analysis of the Google Fast Pair Protocol - YouTube.
    • Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking - Wired.
    • Line of Duty - Wikipedia.
    • Line of Duty - BBC iPlayer.
    • Forgive the haters - YouTube.
    • Smashing Security merchandise (t-shirts, mugs, stickers and stuff)



    SPONSORS:

    • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    • ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment.
    • Adaptive Security - request a custom demo featuring a real CEO deepfake simulation today from adaptivesecurity.com.


    SUPPORT THE SHOW:

    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


    FOLLOW THE SHOW:

    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


    THANKS:

    Theme tune: "Vinyl Memories" by Mikael Manvelyan.

    Assorted sound effects: AudioBlocks.



    Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    45 mins
  • From Instagram panic to Grok gone wild
    Jan 15 2026

    Confusion reigns after claims that data linked to 17.5 million Instagram accounts is up for sale - sparked by a vague post, contradictory statements, and a flood of password reset emails nobody asked for.

    And we dig into Grok, Elon Musk’s AI chatbot, after it started generating sexualised images of women and children - raising uncomfortable questions about guardrails, accountability, and why playing the censorship card doesn’t make the problem go away.

    All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Monica Verma.


    EPISODE LINKS:

    • Free Speech Union website down after alleged funders exposed by trans hackers - Pink News.
    • Illinois Man Charged in Snapchat Hacking Investigation - US Dept of Justice.
    • Hackers get hacked, as BreachForums database is leaked - Hot for Security.
    • Post by Malwarebytes - Bluesky.
    • Post by Instagram - Twitter.
    • Instagram denies breach amid claims of 17 million account data leak - Bleeping Computer.
    • Ofcom asks X about reports its Grok AI makes sexualised images of children - BBC News.
    • Musk’s Grok blocked by Indonesia, Malaysia over sexualized images in world first - CNN.
    • Elon Musk shares AI images of Starmer in bikini in row over grim Grok deepfakes - Mirror.
    • Soul Music - BBC Sounds.
    • Smashing Security merchandise (t-shirts, mugs, stickers and stuff)


    SPONSORS:

    • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    • Meter - Network infrastructure for the enterprise. Get a free personalised demo.


    SUPPORT THE SHOW:

    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


    FOLLOW THE SHOW:

    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


    THANKS:

    Theme tune: "Vinyl Memories" by Mikael Manvelyan.

    Assorted sound effects: AudioBlocks.


    ENJOYED THE SHOW?

    Make sure to check out our sister podcast, "The AI Fix".



    Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    37 mins
  • How to scam someone in seven days
    Jan 8 2026

    Romance scammers have apparently discovered astrology... and Taurus is their secret weapon.

    In episode 449 of "Smashing Security", we take a look inside an actual romance-fraud handbook - complete with scripts, personality “types”, corporate jargon, and a seven-day plan to get victims from hello to hand over the crypto.

    Then Lesley "hacks4pancakes" Carhart delivers a reality check on the dire cybersecurity jobs market for juniors: why entry-level roles are evaporating, how automated CV screening is chewing candidates up, and what hopeful newcomers (and weary veterans) can do about it.

    Plus, Graham talks to ThreatLocker CEO Danny Jenkins about why misconfigurations are behind an uncomfortable number of breaches, how default-deny security actually works in practice, and why detecting attacks after they’ve started is already too late.

    All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Lesley Carhart.


    EPISODE LINKS:

    • Millions of Android Powered TVs and Streaming Devices Infected by Kimwolf Botnet - Hackread.
    • Ilya Lichtenstein, Bitcoin hacker behind massive crypto theft, credits Trump for early prison release - CNBC.
    • How Fake BSODs and Trusted Build Tools Are Used to Construct a Malware Infection - Securonix.
    • A scammer's guide: How cybercriminals plot to rob a target in a week - Reuters.
    • Game of Wool: Britian’s Best Knitter - Channel 4.
    • Game of Wool trailer - YouTube.
    • Earthrise One: Melbourne's Premier Sci-Fi Escape Room Adventure.
    • Smashing Security merchandise (t-shirts, mugs, stickers and stuff)



    SPONSORS:

    • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    • ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment.
    • Meter - Network infrastructure for the enterprise. Get a free personalised demo.



    SUPPORT THE SHOW:

    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


    FOLLOW THE SHOW:

    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


    THANKS:

    Theme tune: "Vinyl Memories" by Mikael Manvelyan.

    Assorted sound effects: AudioBlocks.


    ENJOYED THE SHOW?

    Make sure to check out our sister podcast, "The AI Fix".



    Privacy & Opt-Out: https://redcircle.com/privacy
    Show More Show Less
    1 hr and 1 min