1195001633
Smashing Security

Advertise on podcast: Smashing Security

Rating
★★★★★
4.5
from
315 reviews
This podcast has
476 episodes
Language
English
Publisher
Graham Cluley
Explicit
No
Date created
2017/01/13
Latest episode
2026/04/22
Average duration
46 min.
Release period
7 days

Description

Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle. Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider. Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app. New episodes released at 7pm EST every Wednesday (midnight UK).

Unlock Smashing Security podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Social media

Check Smashing Security social media presence


Podcast episodes

Check latest episodes from Smashing Security podcast


Rockstar got hacked. The data was junk. The secrets it revealed were not
2026/04/22
A company that ran anonymous tip lines for 35,000 American schools - handling reports of bullying, weapons, and self-harm - boasted on its website that it had suffered zero security breaches in over 20 years. A hacker called Internet Yiff Machine thought that sounded like a challenge, with predictable results... Meanwhile, Rockstar Games gets hacked again - and the stolen data turns out to be less embarrassing than the financial secrets it accidentally revealed. GTA Online is still making half a billion dollars a year. Red Dead Redemption is not. All this and more in episode 464 of the "Smashing Security" podcast with cybersecurity keynote speaker and industry veteran Graham Cluley, joined this week by special guest BBC cybersecurity correspondent Joe Tidy. Plus! Don't miss our featured interview with Ryan Benson of Meter. EPISODE LINKS: Grinex exchange blames "Western intelligence" for $13.7M crypto hack - Bleeping Computer.Are Former Black Basta Affiliates Automating Executive Targeting? - Reliaquest.Apple is working on passcode bug locking out iPhone users - The Register.Hackers who stole crime tip records offering data cache for $10k - San.P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next - Databreaches.net.Portland police urge residents to avoid Crime Stoppers following hack - San.GTA-maker Rockstar Games hacked again but downplays impact - BBC News.Rockstar hackers release their stolen data, reveal that Rockstar was right to not pay them anything for it - PC Gamer.XCancel.”We Are Anonymous” by Parmy Olson - Penguin.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence.Meter – Network infrastructure for the enterprise. Get a free personalised demo.Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
This AI company leaked its own code. It's also built something terrifying
2026/04/15
A hacking group claims to have broken into the flood defence system protecting Venice's Piazza San Marco - and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthropic accidentally leaked the source code for Claude Code via a basic packaging mistake. Oh, and by the way, they've also just revealed they've built an AI model called Mythos that can find and chain together software vulnerabilities faster than any human. Sleep well. All this and more in episode 463 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Tanya Janca. EPISODE LINKS: Booking.com warns customers of hack that exposed their data - The Guardian.GTA-maker Rockstar Games hacked again but downplays impact - BBC News.Meta removes ads for social media addiction litigation - Axios.Hackers claim control over Venice San Marco anti-flood pumps - Security Affairs.Venezia, attacco hacker al sistema di pompe che difende piazza San Marco dall'acqua: «Abbiamo i codici, possiamo disattivarlo» - Corriere del Veneto. Digging into the Claude Code source - Dave Schumaker’s write-up of Anthropic leaking data in February 2025.Anthropic goes nude, exposes Claude Code source by accident - The Register.Assessing Claude Mythos Preview’s cybersecurity capabilities - Anthropic.Smashing Security transcripts!Shrinking - Apple TV. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
LinkedIn is spying on you, and you agreed to nothing
2026/04/08
LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you're job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned anywhere in their privacy policy. Meanwhile, California's crypto millionaires are learning that no amount of encryption can protect you from someone who knocks on your door pretending to deliver a pizza. All this and more in episode 462 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Dave Bittner. EPISODE LINKS: Russian government hackers broke into thousands of home routers to steal passwords - TechCrunch.Refusal to Give the Government Passwords to Personal Mobile Device Criminalized in Hong Kong - US Consulate in Hong Kong."I didn't think millions would see this..." Russians are calling each other through a cat feeder - GUBDaily.BrowserGate.Scanned extensions database - BrowserGate.LinkedIn secretly scans for 6,000+ Chrome extensions, collects data - Bleeping Computer.Translate into LinkedIn speak - Kagi.Security - xkcd.Wealthy California crypto holders targeted in violent ‘wrench attacks’ - KTLA 5.Lost Doctor Who episodes to be released this week - BBC News.Doctor Who: The Daleks’ Master Plan - The Nightmare Begins - BBC iPlayer.Doctor Who: The Daleks’ Master Plan - Devil’s Planet - BBC iPlayer.Milton Bradley Grandmaster Robotic Chess Computer - YouTube.Robot Chess - One-armed gambit - Techmoan on YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
This man hid $400 million in a fishing rod. Then it vanished
2026/04/01
A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 - and now sits on a fortune worth $400 million. There's just one small problem: the access codes were tucked inside his fishing rod case, which has mysteriously vanished. Or has it? Because this week, one of his frozen wallets suddenly woke up and moved $35 million - and someone had to identify themselves to do it. Meanwhile, Ajax Football Club scores a spectacular cyber own-goal, as a data breach that the club claimed affected "a few hundred" fans turns out to may have exposed the personal details of 300,000 supporters - along with the ability to steal match tickets and quietly remove people from the stadium ban list. All this and much more in episode 461 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest journalist Danny Palmer. EPISODE LINKS: Iran-linked hackers breach FBI director's personal email, publish photos and documents - Reuters.Windows PCs crash three times as often as Macs, report says - TechSpot.Wife used CCTV to steal $176M of husband’s crypto, UK court told - Coin Telegraph.Gardaí open €30m bitcoin virtual wallet, first of 12 accessed since seizure in 2019 - Irish Times.Irish Drug Dealer’s Lost BTC Stack Worth $400m Has Woken Up - Arkham.Ajax FC data breach exposes 300,000 fans, hacker steals tickets an stadium ban details - Cybernews.Small Prophets - BBC iPlayer.RPG Taverns - Dungeons and Dragons tavern in London.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Action1 - Keep your systems safe (and your sanity intact) with the patch management platform that just works. The best part? Your first 200 endpoints are free, forever, with no functional limits.Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
Never knock on the door of a nuclear submarine base and ask for a selfie
2026/03/26
A disgruntled data analyst decides that the best response to losing his contract is to steal the entire company payroll database and demand $2.5 million in Bitcoin - signing his extortion emails from a company called "Loot." Meanwhile, two people drive up to the entrance of the UK's nuclear submarine base at Faslane and politely ask if they can have a look around. Tourists? Spies? Something in between? Plus: Female Muslim punk rock group, and a little red book that might save your sanity in a post-truth world. All this and more in episode 460 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Jenny Radcliffe. EPISODE LINKS: A Top Google Search Result for Claude Plugins Was Planted by Hackers - 404 Media.Iowa-based Intoxalock cyberattack disrupts calibration service for interlock users - DysruptionHub.China hacker group leaks $7M crypto theft operation targeting wallet supply chains​ - Crypto News.Federal Jury Convicts Charlotte Man For Cyber Extortion Scheme That Targeted International Technology Company - DOJ.Iranian and Romanian charged after allegedly trying to enter UK nuclear naval base - Sky News.LadyParts - Spotify.On Disinformation: How to Fight for Truth and Protect Democracy - Lee McIntyre.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Meter - Network infrastructure for the enterprise. Get a free personalised demo. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
This clever scam nearly hijacked a tech CEO's Apple ID
2026/03/19
In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you're immune? Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to reveal everything. And! Human-powered “AI”, and a punishment worse than prison: eight hours on the RSA expo floor... All this, and much more, in episode 459 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Paul Ducklin. EPISODE LINKS: DOGE employee stole Social Security data and put it on a thumb drive, report says - TechCrunch.Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show - Reuters.New font-rendering trick hides malicious commands from AI tools - Bleeping Computer.Lockdown Mode - Apple support.Gone (Almost) Phishin’ - Matt Mullenweg.Listen to the Live Scam Call Targeting Matt Mullenweg’s Apple Account - YouTube.Confidential health records from UK BioBank project exposed online - The Guardian.A message from Professor Sir Rory Collins, Chief Executive and Principal Investigator of UK Biobank - UK BioBank.Psychotherapy data breach blackmailer sent to prison - Paul Ducklin.Your AI slop bores me.Post by Vaughan Shanks - LinkedIn.Judge Sentences CISO to 8 Consecutive Hours on RSA Expo Floor as Formal Punishment for Security Breach - The Exploit.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Adaptive Security - request a custom demo featuring a real CEO deepfake simulation.Meter - Network infrastructure for the enterprise. Get a free personalised demo. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
How not to steal $46 million from the US government
2026/03/12
A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn't stirred since 2024 - and within minutes, giant woodpecker images are plastered across the internet's favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized digital assets allegedly decides to help himself to $46 million of it - and then brags about it on a recorded Telegram call. Plus: Graham champions Asterix, Trisha discovers the fantasy novels of Robin Hobb, and someone called "Lick" ends up in the nick. All this, and much more, in episode 458 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Tricia Howard. EPISODE LINKS: Major data leak forum dismantled in global action against cybercrime forum - Europol.Ericsson blames vendor vishing slip-up for breach exposing thousands of records - The Register.How hackers bypassed MFA with a $120 phishing kit – until law enforcement  shut them down - Hot for Security.Wikipedia hit by self-propagating JavaScript worm that vandalized pages - Bleeping Computer.FBI arrests crypto thief accused of stealing $46 million from seized government wallet - Tom’s Hardware.Twitter thread by ZachXBT about John Daghita’s arrest - Twitter.Asterix - Wikipedia.Robin Hobb.The Complete Farseer trilogy - Harper Collins.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment.Meter - Network infrastructure for the enterprise. Get a free personalised demo. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
How a cybersecurity boss framed his own employee
2026/03/05
When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker... who promptly sent an innocent colleague into a career-ending ambush. In this episode, we unravel the jaw-dropping tale of a defence contractor caught selling zero-day exploits to a Russia-linked broker. Plus: are nation states quietly poisoning AI models to bend reality itself? We explore how “foreign information manipulation interference” could target not just social media users, but the large language models we increasingly trust for answers — and what that might mean for truth, trust, and the future of online influence. All this, and much more, in episode 457 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Carl Miller. EPISODE LINKS: Large-Scale Online Deanonymization with LLMs - Simon Lermen.Hacked Prayer App Sends ‘Surrender’ Messages to Iranians Amid Israeli and US Strikes - Wired.“Stay safe out there gamers”: Streamers say Amazon just made Wishlists a doxxing risk - Daily Dot.Apple alerts exploit developer that his iPhone was targeted with government spyware - TechCrunch.Former General Manager for U.S. Defense Contractor Sentenced to 87 Months for Selling Stolen Trade Secrets to Russian Broker - US Department of Justice.Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools - US Department of Treasury.Inside the story of the US defense contractor who leaked hacking tools to Russia - TechCrunch.​​Hundreds of English-language websites link to pro-Kremlin propaganda - Guardian.The Incredible Shrinking Man - Internet Archive.“The Immortalists” by Aleks Kortoski - Penguin Books.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Action1 - Keep your systems safe (and your sanity intact) with the patch management platform that just works. The best part? Your first 200 endpoints are free, forever, with no functional limits.Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
How to lose friends and DDoS people
2026/02/26
When the mysterious operator of an internet archiving-service decided to silence a curious Finnish blogger, they didn’t just send a stroppy email - they allegedly weaponised their own CAPTCHA page to launch a DDoS attack, threatened to invent an entirely new genre of AI porn, and tampered with parts of their own archive to smear the blogger's name. In this episode, we unravel how a website designed to preserve history may have trashed its own credibility - and how Wikipedia responded when trust went out the window. Plus a ransomware gang shoots itself in the foot with a classic case of buffoonery, accidentally corrupting the very keys victims would need to decrypt their data. When even the criminals can’t unlock your files, what happens next? All this, a surprisingly zen Pick of the Week, and a gloriously splenetic rant against web forms, on episode 456 of the award-winning "Smashing Security" podcast, with cybersecurity veteran Graham Cluley and special guest Paul Ducklin. EPISODE LINKS: This App Will Detect People Wearing Smart Glasses Near You - Lifehacker.Patients listed as dead after major NZ health app MediMap hacked - 1News.Why fake AI videos of UK urban decline are taking over social media - BBC News.FBI orders domain registrar to reveal who runs mysterious Archive.is site - Ars Technica.Archive.today CAPTCHA page executes DDoS; Wikipedia considers banning site - Ars Technica.Archive.today is directing a DDOS attack against my blog - Gyrovague.Critical buffer overflow bug - in ESXi ransomware - SolCyber.Yoga with Adriene - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
Face off: Meta’s Glasses and America’s internet kill switch
2026/02/19
Could America turn off Europe's internet? That’s one of the questions that Graham and special guest James Ball will be exploring as they discuss tech sovereignty. Could Gmail, cloud services, and critical infrastructure really become geopolitical leverage? And is anyone actually building a Plan B? Plus we explore if Meta is quietly plotting to turn its smart glasses into face-recognising surveillance specs? With reports of internal memos suggesting they plan to launch controversial features while everyone’s distracted by political chaos, we ask: is this innovation really wanted by the public... or something far creepier? All of this, and much more, in episode 455 of the award-winning "Smashing Security" podcast with cybersecurity veteran Graham Cluley, joined this week by journalist and author James Ball. EPISODE LINKS: IcedID malware developer fakes his own death to escape the FBI - Risky Business.Sex toys maker Tenga says hacker stole customer information - TechCrunch.Dutch police arrest man for "hacking" after accidentally sending him confidential files - Hot for Security.Meta Plans to Add Facial Recognition Technology to Its Smart Glasses - New York Times.Trading Sovereignty for Scale? The Costs of the US - UK Tech Prosperity Deal - Just Security.Just Mercy - Wikipedia.Just Mercy trailer - YouTube.Bryan Stevenson’s TED talk: We need to talk about an injustice - YouTube.The Residence - Netflix.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Passwork - a reliable secrets manager and password management solution.Adaptive Security - request a custom demo featuring a real CEO deepfake simulation. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
AI was not plotting humanity’s demise. Humans were
2026/02/12
AI bots are having existential crises, inventing religions, and allegedly plotting against humanity... or so the internet would have you believe. We dig into Moltbook, the “AI-only” social network that sent Twitter into a meltdown, attracted breathless talk of the singularity, and turned out to be far less Terminator and far more humans role-playing as bots. Plus we discuss why "vibe coding" your app might be a catastrophically bad idea, when security researchers can easily peek inside rifle through your private messages, API keys, and databases. Also this week we learn that pro-Russian hackers are circling the Winter Olympics - or is it the Jamaican Bobsleigh team? All this and more is discussed in episode 454 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Iain Thomson. EPISODE LINKS: AI Agents Created Their Own Religion, Crustafarianism, On An Agent-Only Social Network - Forbes.I Infiltrated Moltbook, the AI-Only Social Network Where Humans Aren’t Allowed - Wired.'Moltbook' social media site for AI agents had big security hole, cyber firm Wiz says - Reuters.Italy blames Russia-linked hackers for cyberattacks ahead of Winter Olympics - The Record.Italy says railways hit by 'serious sabotage' as Winter Olympics begin - BBC News.EpsteIN - GitHub.Private Eye.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Passwork - a reliable secrets manager and password management solution. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
The Epstein Files didn’t hide this hacker very well
2026/02/05
Supposedly redacted Jeffrey Epstein files can still reveal exactly who they’re talking about - especially when AI, LinkedIn, and a few biographical breadcrumbs do the heavy lifting. Sloppy redaction leads to explosive claims, and difficult reputational consequences for cybersecurity vendors, and we learn how trust - once cracked - can be almost impossible to fully restore. Elsewhere, the spotlight turns to insider threat in the age of AI, after a senior US cybersecurity official uploads sensitive government material into the public version of ChatGPT. Oops. All this, and much more, in episode 453 of Smashing Security with cybersecurity veteran Graham Cluley and special guest Tricia Howard. EPISODE LINKS: Notepad++ hijacked to serve malware in targeted attacks - Notepad++.Porn-quitting app caught leaking users’ sexual habits - 404 Media.MicroWorld Technologies’ eScan anti-virus update turned into a malware delivery system - Morphisec.Jmail.World.Informant told FBI that Jeffrey Epstein had a ‘personal hacker’ - Techcrunch.Confidential informant statement given to FBI - US Department of Justice.Post by Graham Cluley - LinkedIn.Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT - Politico.We are Lady Parts - Channel 4.We are Lady Parts trailer - YouTube.“Bashir with a good beard” by We are Lady Parts - YouTube.“Voldermort under my headscarf” by We are Lady Parts - YouTube.Doctor Who: The Shakespeare Notebooks - Penguin.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Passwork - a reliable secrets manager and password management solution.Meter - Network infrastructure for the enterprise. Get a free personalised demo.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
The Epstein Files didn’t hide this hacker very well
2026/02/04
This is a special early-access, ad-free edition of the "Smashing Security" podcast for subscribers to Smashing Security PLUS. Supposedly redacted Jeffrey Epstein files can still reveal exactly who they’re talking about - especially when AI, LinkedIn, and a few biographical breadcrumbs do the heavy lifting. Sloppy redaction leads to explosive claims, and difficult reputational consequences for cybersecurity vendors, and we learn how trust - once cracked - can be almost impossible to fully restore. Elsewhere, the spotlight turns to insider threat in the age of AI, after a senior US cybersecurity official uploads sensitive government material into the public version of ChatGPT. Oops. All this, and much more, in episode 453 of Smashing Security with cybersecurity veteran Graham Cluley and special guest Tricia Howard. All this and more is discussed in episode 453 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest... For full show notes visit the episode's webpage at https://www.smashingsecurity.com/453 SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. FOLLOW US: Follow us on Bluesky at @smashingsecurity.com, or Mastodon, or on the Smashing Security subreddit, and visit our website for more information. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks.
The dark web's worst assassins, and Pegasus in the dock
2026/01/29
In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus, we go looking for professional hitmen online - only to uncover uncomfortable questions about why some crimes attract customers but very few complaints. All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veteran Graham Cluley, joined this week by special guest Joe Tidy. EPISODE LINKS: Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch - The Register.Russian state hackers likely behind wiper malware attack on Poland’s power grid - The Record.US charges 31 more suspects linked to ATM malware attacks - Bleeping Computer.Dark web arrests in Romania linked to portal which offered services including murder - ROCU.Romanian scammers ran fake hitman-for-hire site, lured desperate perpetrators as 'incompetent assassins' - Fox News.This Fake Hitman Site Is the Most Elaborate, Twisted Dark Web Scam Yet - VICE.Unlikely Assassin, The Murder of Amy Allwine - Rooster.Saudi dissident awarded $4.1 million by UK court for hacking, assault 'by Saudi Arabia' - Reuters.Stalkerware: The software that spies on your partner - BBC News.Using 'stalkerware' to spy on a colleague's phone - YouTube.“Polite Society” trailer - YouTube.Elegoo Saturn 3 3D printer - Elegoo.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Passwork - a reliable secrets manager and password management solution.Coreview - Download "Total Tenant Takeover", a white paper about the Microsoft 365 Disaster No One Is Ready For.Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off! SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy
I hacked the government, and your headphones are next
2026/01/22
In episode 451 of "Smashing Security," we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more - and then helpfully posted screenshots (and even someone’s blood type) on an account called "I hacked the government." Plus we discuss how researchers uncovered a creepy flaw that lets attackers hijack wireless headphones, listen in on calls, inject audio, and even turn your earbuds into a stalking device - all without you noticing. All this, and much more, in this episode of the "Smashing Security" podcast with Graham Cluley, and special guest Ray [REDACTED] EPISODE LINKS: Tennessee Man Pleads in Hacking U.S. Supreme Court, AmeriCorps, and VA Health System - US Department of Justice.Paris Hilton’s hacker sentenced to 57 months in prison - Graham Cluley.WhisperPair.One Tap To Hijack Them All - A Security Analysis of the Google Fast Pair Protocol - YouTube.Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking - Wired.Line of Duty - Wikipedia.Line of Duty - BBC iPlayer.Forgive the haters - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff) SPONSORS: Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!ThreatLocker - Start your free trial and book a demo of ThreatLocker today to see how you can implement Zero Trust in your environment.Adaptive Security - request a custom demo featuring a real CEO deepfake simulation today from adaptivesecurity.com. SUPPORT THE SHOW: Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser. Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed! FOLLOW THE SHOW: Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes. THANKS: Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Privacy & Opt-Out: https://redcircle.com/privacy

Podcast reviews

Read Smashing Security podcast reviews


4.5 out of 5
315 reviews
★★★★★
ႦυႦႦʅҽɠυɱ Ⴆʅυҽʂ 2026/03/05
Love this show
… I do miss Carole, thought her voice was just perfect, like Grahams, for presenting the news. Hope she visits.
★★★★★
anisali01 2025/11/13
Great show for a lighthearted view toward cyber security.
Appreciate the light tone toward cyber security Graham and Carole (when she was here) have. Keeps it enjoyable and makes me instantly jump to it whene...
★★★★★
USA Mknitter 2024/07/25
I learn a lot from this podcast
Thanks for a great podcast—great information and laughs! Thanks to Carole for the links to “Break” (break dancing) at the 2024 Paris Olympics!
★☆☆☆☆
R1921aaaa 2025/08/28
Quality dropped
Missing Carole already. Tom had an uninformed take on quantum computing. He drops a bunch of random rants that are distracting and unhelpful trying ...
★★★★★
TasneemPenn2013 2023/11/12
In my Top 3 Fave CS Podcasts!
I make it a point to listen to a variety of podcasts to stay current on the news, and this is in the top 3 for me. Carole, fricking love the wit but...
★★☆☆☆
jd2020 2024/03/04
Really?
Wow. I would like the time I wasted listening to half of an episode back please. I’m sure SS appeals to someone. I’m just not sure who that would be.
★★★★★
BK1923 2023/05/03
As good as it gets
Truly one of the best out there. Thanks for what y’all do for the community.
★☆☆☆☆
TheSloanster 2023/10/05
Just a bunch of bullies
The Podcast app kept recommending Smashing Security, and the description suggested humor is what differentiates it from other security focused podcast...
★★★★★
Qwertiop8 2023/04/11
Painless & entertaining cyber security education!
Really fantastic and informative fun for the interested amateur…especially the kind of person whose friends think they are way too paranoid about cybe...
★★☆☆☆
Slish* 2022/12/08
Eh
They just summarize articles, some of which came out years ago. You could read the articles in 10 minutes or listen to an hour of not-so-witty banter....
check all reviews on apple podcasts

Podcast sponsorship advertising

Start advertising on Smashing Security relevant audience podcasts


What do you want to promote?