
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday – and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets.
Meanwhile, AI music generator Suno has been hacked – and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models.
All this and more in episode 477 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.
Show full transcript ▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
So I do think it's completely reprehensible of me. Yes. Smashing Security, episode 477.
How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.
Hello, hello, and welcome to Smashing Security episode 477. My name's Graham Cluley.
Now, I was following you on Blue Sky and I saw that you had an unusual way of handling the extreme heat which we were experiencing a couple of weeks ago.
Many people have been caught out by those scam adverts on YouTube for things which claim to be able to air condition your room. But what did you do?
And there were lots of sort of things where it's like, well, about £20, or this place is also in the heatwave. Northern Scotland was really expensive.
And it turned out that actually going up to the Arctic — I mean, I spent a week there and including the flights, it cost me less than £1,000.
Although the nice thing was the day after, I was sort of worried I'd have to try and put on a really terrible American accent or something.
And they did all sort of say, look, just beat Argentina. We don't want Argentina to win. And I heard that from 3 or 4 different people. So they were kind of okay with it.
They were cooler than they could have been. But strongly recommend it. Tromsø is great. Just don't get a curry there. Norway does not do spice.
I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.
This week on Smashing Security, we won't be talking about how a man in India has been accused of using an AI chatbot to help him plan a triple murder.
You'll hear no discussion of how the July 2026 patch update from Microsoft comes with security updates for a record-breaking 570 vulnerabilities.
And we won't even mention how plugging in an LG monitor can automatically install adware on your Windows PC that bombards you with McAfee pop-ups without ever asking your permission.
So James, what are you going to be talking about this week?
All this and much more coming up in this episode of Smashing Security.
Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today's sponsors, Vanta.
Why on earth are we still running our entire security program out of a spreadsheet?
Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.
Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.
The upshot of this is you move faster, scale without the usual headaches, and maybe, just maybe, actually get a decent night's sleep.
What's the worst thing that could possibly occur if you were actually working for the Russians?
Would your biggest threat be having your identity exposed, being found out by the FBI?
Would it be about Western intelligence agencies finding out where you're based, locating your identity and extraditing you?
Or would the biggest threat actually be about Chicken McNuggets? That is the thing we're going to be exploring. Do you stand anywhere in particular on Chicken McNuggets, James?
And so I've travelled in many, many countries in the world and every single one that had a McDonald's, I've been to the McDonald's in that country.
And via that account, they had then grabbed the data of tens of thousands — I think over 64,000 — officers in the force.
Officers' names, addresses, identities, also of their informants.
The Dutch intelligence agency at the time described it as the first time that the country had fallen victim to deliberate sabotage by a Russian-backed hacking group.
It caused a big furore in the press, as you can expect, and they didn't break in to plant ransomware or extort money — this was all about stealing intelligence, gathering intel in order to exploit it later.
So this was effectively a police force's entire contact database — you know who the police are, who they're talking to, who talks to them.
And Microsoft, working with Dutch intelligence, publicly named the hacking group responsible for this back in May 2025 as Void Blizzard.
I love the names which are sometimes given to these groups.
Which, given this is a pretty good hack, actually getting 64,000 officers and the contact database, I think maybe they deserve a promotion — Laundry, maybe to Scullery, Scullery Bear.
So anyway, Microsoft and the Dutch intelligence agency said that this attack hadn't just targeted the police, it turns out, but other sectors — defence, healthcare, government — not just the Netherlands as well, but also countries across NATO and Ukraine as well, of course.
So you can all kind of guess where this attack is likely to be coming from, and the typical attack would come in the form of a personal invitation via email.
You might get invited to a European Defence Summit, and if you click on the link or you scan the QR code sent in the PDF which you've been sent, you get taken to a login page.
Looks like Microsoft Teams you're logging into, and of course it's the usual story — they're grabbing your username and password so that they can then log into your account and steal your information.
So this was fairly standard state-sponsored cyber espionage directed at Western security infrastructure.
And at the heart of it, according to US prosecutors, is a chap called Denis Obrezhko.
He is a 36-year-old Russian IT nerd, and at the end of October 2025, he made possibly a worse mistake than you going up to the Arctic Circle — he chose to go to Phuket in Thailand.
He grabbed himself a ticket there, he fancied a little break, a little holiday, and less than a week later, Thai police were knocking on his door, seizing his laptop and his mobile phone and probably a digital wallet as well, and placing him under arrest, believing him to be a hacker involved in this attack.
And of course, the first rule, if you are a Russian hacker, is you shouldn't leave Russia. If you're in Russia and you're only attacking organisations outside, stay in Russia.
Maybe bits of Central Africa, but I think anywhere with a US extradition treaty should probably not be on the destination list, right?
They issued a warning to their citizens saying, do not travel to Thailand — there is a threat of you being arrested at the request of the United States.
They said, we strongly advise Russian citizens who have even the slightest reason to suspect they might be subject to criminal prosecution by US authorities to refrain from travelling to Thailand.
So this Denis chap, Denis Obrezhko, he has since been extradited to the United States.
This month he's appeared in a federal court in Boston, he's pled not guilty to hacking charges, and if he is found guilty, he could be facing, I don't know, 10 years in prison maybe.
And now the thing is about Denis Obrezhko — I tried to find him on LinkedIn, which is my standard.
I couldn't find him, but he is alleged to have had quite an interesting job history. So according to the FBI, for 5 years between 2012 and 2017, he was working for the FSB.
And for anyone who doesn't know, the FSB is like New Labour to Old Labour — it's the rebranded version of the KGB.
Because there've been so many stories about them being linked to the Kremlin and to the FSB, and they've had to shut down their operations.
You know, they have some real pros. And they get incredibly awkward about it because of course most people who work there just work and have a job, don't they?
Even before everyone was saying it, people either very enthusiastically deny that they've ever seen anything or done anything with it, or try and move the conversation on, in my experience.
What's it been like for you?
They're only selling online, their offices are shut down, they've laid off their staff.
I think it's actually illegal to sell it at all in America now, even to consumers, not just to government organisations.
My friend's a very nice chap and he's not a spy, and it happened that he got a job 25 years ago or whatever it was for an antivirus company which happened to be based in Russia.
And I've known Eugene for many, many years. I haven't seen him for quite a few years, to be honest, but I know him — seems like a very nice guy.
But you do have to wonder, would it be possible to be a successful businessman — and he was an extremely successful businessman in Russia — without kowtowing to what the Russian authorities want?
Because they would make your life extremely difficult, if not impossible.
You have to at least be friendly and cooperative, and given the importance of hacking to Russia's soft power and how it conducts diplomacy and sort of information operations, I just don't think you could be in a job as sensitive as that and not do that.
I mean, let's be honest, the eight biggest cybersecurity companies that operate in the UK coordinate with NCSC and with the intelligence agencies.
There are certain companies, if you're on critical national infrastructure, there's an approved list. And I'm not saying anyone does anything out of line with the law.
We are a Western democracy. Everything is in the statute and above board to that level. But we cooperate with them in that way.
It's not weird to say, would a company with a similar stature and a similar reach and scope that's headquartered in Russia have a relationship with the Kremlin? Of course it would.
It'd be impossible for it not to.
I feel like Kaspersky found itself in an impossible position, and obviously there were accusations that maybe their software could be used to sabotage companies or to steal information from companies, with a malicious update at the behest of the Kremlin.
I don't think I've ever seen any evidence whatsoever that that was something which was planned to do, but obviously you only need a certain amount of doubt, a small amount of doubt, and that's enough to convince people, well, maybe we shouldn't use that product, maybe we should use this other one instead.
So unfortunately world events sort of overtook things, which is a shame because it was in many ways a good product. Yeah.
They say that the alleged hacking activity didn't happen until after he had left. But it gets more interesting than that.
Five years ago in 2021, Abrezko gave a guest lecture at the Moscow Technical University of Communications and Informatics, and he was introduced as the Deputy Director of the Information and Analytical Center of Russia's Ministry of Emergency Situations.
Imagine working at the Ministry of Emergency Situations.
And the prosecutors then say he became a deputy director at a Russian tech firm called UTECH.NN, which is alleged to have been a cover organisation for Void Blizzard's hacking campaign.
So this isn't actually that unusual, in that companies will be set up appearing to do one thing — in this case, it was IT consultancy and project management, product development, all very dull.
But when you look into the public records, apparently they show that that company holds an FSB-issued licence for what is described as the covert acquisition of information.
So you get your licence from the Russian government saying, yes, you are allowed to secretly, without other people's knowledge, acquire information.
It seems a little bit unusual, but again, it makes you think, what does this company actually do?
He'd chosen the name Ethan Hunt, which is from a movie I've seen, Mission: Impossible, the Thom Cruise character.
Obrezhko allegedly emailed Ethan Hunt in quotes, suggesting that they have a meeting to discuss developments.
So it's quite a tangled dark web, which the courts are obviously going to have to unknot to see if this guy is guilty or not. He obviously denies it.
But I was interested in knowing how the investigators have pieced this all together.
How had it come to the situation where the US had asked the Thai police to arrest this guy if he ever turned up in Phuket? And it's rather interesting.
So what happens, it seems, is he had reused the same username and his real Russian phone number across multiple email accounts and social media platforms and financial apps, things like that.
And he'd used the same Google account for cryptocurrency transactions as he'd used to create accounts on Twitter and Instagram and PayPal.
So same username, same avatar, same phone number, same date of birth over and over again.
It's like, guys, if you're going to be criminals, have in your back pocket a whole list of different dates of birth, of different names, of different email addresses — don't make it easy to triangulate who you are.
And the investigators say that they've traced cryptocurrency payments used to fund Void Blizzard, and they followed transactions back through an internet provider.
Eventually they found an email account registered in Obrezhko's own name.
And this is where it becomes really interesting, because independent threat intelligence firm Control Alt Intel took the email address and phone numbers that the FBI had published in their affidavit, and they cross-referenced them with Russian leak databases.
So these are databases of leaked information which have spilled out over time through criminal activity.
And it's not just the criminals who use these — sometimes the threat intel people use them as well.
And what they were able to find was, by going through this data, they got information from banks and social networks and courier companies, food delivery apps, anything like that, which is obviously horrendous from the point of view of if you're a Russian citizen, but great if you're a threat intel researcher.
They were able to search for Denis Obrezhko's email address and phone number, and they kept on popping up in these leak databases, including that he had ordered, on the 1st of March 2021, at half past 3 in the afternoon, a Lipton iced tea, 9 Chicken McNuggets, and a McChicken burger to be delivered to him at the Russian Ministry of Emergency Situations on that particular date.
And they found 13 other separate orders, all delivered to that ministry address, all on weekdays, early in the afternoon. Loved his Chicken McNuggets.
And it's tangled him even more into — yes, this is the ministry you were working in. You were working for the Russian government, despite any claims you may try and make later on.
We were flying between the US, the UK, Brazil.
We were sort of trying to communicate about classified documents all of the time, and we were trying to be quite sort of cautious about that. But you also have to live.
You're staying in hotels, you're trying to sort of spend on credit cards or company cards because my bank account was emptied by the first week.
I was sort of having to get prepaid Visa cards, not for OPSEC, but because I had no money.
But you know, you needed to get a McDonald's at 2 AM or you needed to get a taxi to get back and you were jet lagged.
And so you're trying to do good security, but if you can't remember a password at 2 AM when you haven't slept for 30 hours and you don't know what time zone you're in, there's no point having the password.
And so the compromise between where your kind of normal mundane accounts sort of reach and where your sort of uber ones reach are incredibly complicated to keep up.
And you know, maybe for a week someone can do it, but 3 months in, 6 months in, when it's your everyday life, the things that look very silly when you see them in an indictment or when you see them in a security research, it is that thing where it's like, well, how do you live otherwise?
How do you remember which date of birth you used for your Uber account versus which one you used for your other one?
So all of these details are there, and if you don't use as many real ones as possible, you mess it up.
You know, I remember LulzSec got caught because the leader, Sabu, turned on the other ones.
He got caught because he forgot to change one thing and needed to log back in, and it was about half 3 in the morning, and he'd done everything properly, and he logged in without his VPN once.
And they got him that way, from one failure to use his VPN. And so, you know, this looks shoddy. I mean, this is poor. For a sort of security professional, this is dismal.
But having lived like this, having tried to do it, I can say it is more difficult than you think.
I mean, that's an indictment in itself, isn't it?
They analysed over 800,000 real IT assets to find out how exposed organisations actually are.
Nobody added him, nobody removed him, and he's been quietly in there for 11 years downloading maps of Paraguay.
That's the path of least resistance.
And the report is free to download. Free.
I'm no longer involved in The AI Fix, but it was a weekly podcast about AI developments, which I did for a couple of years. And it did it. I mean, it was a fantastic song.
The AI Fix, a digital zoo. Smart machines, bots with brains, what will they do? Fly us to Mars or bake a bad cake? World domination, a silly mistake.
And so far, I think I've made the sum total of 4 pence out of it.
It tends to make very middle-of-the-road, very sort of basic composition, but it's quite a fun thing to play with.
But inevitably quite contentious in the same way as if you post any AI art, people say, well, you've just taken a job from an illustrator.
If you use Suno music, people say, you know, you're killing music.
In others, if you would never go to pay a musician anyway, you know, if that budget wasn't there, it's just creating something that wouldn't otherwise exist.
There are all sorts of views on this, but—
And my opinion on that has strengthened only over time.
But it means essentially Suno is in the middle of very similar lawsuits to a lot of the other AI companies.
What it generates, there's always a bit of contention — is that original, et cetera?
But the real row is over how they were trained and have they improperly accessed the training material, have they sort of violated that?
I think the best known lawsuit over all of this at the moment is the Anthropic one.
But they didn't bother doing that. They just downloaded a load of pirated books. And so they've had to do an out-of-court settlement. I have to do a disclosure here.
Two of my books are in that settlement. If that goes through, Anthropic owe me, I think, about $5,000. I'm not a party to the case otherwise.
You know, they seem to have thought it was all right for them to take stuff without asking.
But if anyone takes anything from Anthropic without asking, they're not quite so pleased about that.
And because they give it a different name, it's obviously entirely different morally and legally. It is not.
They are really genuinely kicking off at the Chinese companies for exactly the conduct they did.
I mean, exactly right down to a lot of it ends up centring on whether it comes to terms of service violations mean that you accessed unlawfully, etc.
There's lots of very fine points of IP law in this. Now, Suno are right in the middle of all of this.
And to be honest, I think they're in a trickier position than Anthropic and OpenAI, not necessarily because their conduct's any different.
If you want to produce a lot of music, you need to ingest a lot of music. And they have more or less now admitted that they scraped off YouTube, Genius, Deezer, all of these things.
They took a lot of music. Their difficulty is that they're not really up against a bunch of authors who are, you know, generally pretty poor and not that well-resourced.
They're up against big music and big music basically fought this and won this once before.
You know, they beat Napster, they beat LimeWire, they beat all of those, they have a much smaller group who are much more aggressive pursuing them a lot more.
And so Anthropic has got off fairly cheaply for using pirated material.
The question is going to be, if you grab stuff off YouTube and use it to train an AI, that is not in line with how you're supposed to use YouTube. It is very, very dubious.
And they had been dancing around in discovery about whether they'd done this, and now Suno has been hacked and it's been hacked by someone who's put an awful lot of the material online.
And it pretty much categorically seems to show not just that they did train off YouTube, etc., which we kind of knew, but things like exactly how much they've ingested into different parts because it's annotated code.
What I like is that there was one site that had some copyright-free sound and there's only 410 hours from that one. So it sort of tells you some issues.
You know, there is decades and decades and decades worth of original music.
And so if they were ever trying to go, well, prove it, or, you know, you have no evidence of that, this looks dubious.
They'd largely helped themselves to the back catalogue of every musician in the world, and now a hacker has helped themselves to their code.
Now, legally, they're not quite the same status, but morally, that's got to look very similar to a lot of people, isn't it? It's, on one level, a fairly basic hack.
They got in through one programmer using a 2025 worm, Shaihulud. I don't know much about Shai Hulud. Do you?
Basically, a developer inside your company would install a booby-trap package and the malware would quietly steal their credentials and then use them to infect other packages that they maintained.
So it would spread itself automatically across your ecosystem.
And to make matters worse, it also dumped all the things it had stolen into a public GitHub repository under the victim's own account, so sort of broadcasting credentials to the world.
So yeah, a real supply chain menace, that one. An unusual worm, but was affecting a large number of organisations potentially and causing quite a big problem.
But once they're in, of course, yeah, the data which can be extracted.
But what seems to have been used for the interesting stuff is this is all the GitHub submits and back and forth.
What I found particularly interesting here was I started all sorts of musing about whether this was a sort of Hacker Wars 2.0 and whether this was a sort of revenge for the creative industries type thing.
I also wondered if there was a bit of — it is known that corporates hack each other sometimes for various reasons, because it's useful if material can hit the public domain, and you can kind of launder it if you get a third-party hacker.
It's not legal, but a company could, in theory, get a third-party hacker to get some sensitive information, get that third party to disclose it to a journalist, and that journalist, if they run it in a major outlet, they can then use that journalist's reporting to subpoena the information that was hacked and use it in a court case or similar.
Now, I should stress this is illegal.
I'm using this as a general example of something that lawyers and others have talked me through and said, this is something that everyone thinks other people are doing, and everyone says they, of course, would never touch and never do.
Which is what phone hacking was like in journalism back in the day. Everyone said they didn't do it, but they knew people who did.
And I'm sure you, like myself, have been approached by hacking gangs in the past who've said, we've got this data, we've stolen this information, can you publicise this?
We think this is a good story. And there are many —
This was the thing I kind of thought, well, is this some corporate espionage? It doesn't look state to me. Is this exactly that kind of ideological hack? Supposedly not, though.
In a sort of fairly underwhelming line, buried quite deep in the story, the hacker told 404 Media they had no specific motivation for hacking Suno, and said, "I like to hack anything and everything." Now maybe that's true, or maybe that's cover, you know.
It is a clever hack, they've used their access, etc., but they've largely used something off the shelf that someone could grab and play with, you know.
There's not a reason that this has to be super sophisticated or a large number of people, but they're not claiming any ideological motivation here.
But I thought it was a particularly interesting one because it trod on several red buttons all at once.
So I think as well, whatever their motivation, it will end up pulled into the ongoing lawsuits because how could it not?
And it's all about fight the case to try and get the best terms you can and then use it to cut a deal for your future relationship. You know, do they take an ownership stake?
Do you come up with licensing terms? Because presumably your eventual model will be Suno Music getting distributed alongside traditional artists.
Is to commit what some of us would consider to be a crime or to commit something which appears unethical, you know, which is grabbing someone else's music and using it to feed and create your own music.
And then, well, we'll do that now because in the future sometime we'll come to some business relationship or we'll come to some understanding which will make it acceptable.
But by that time we'll have built our business up enough.
There's maybe no good guys in this story.
It's a scary world out there for travelling workers.
But it goes well beyond just encrypting the connection.
You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.
And if someone leaves the company, you revoke their access immediately.
So if someone on your team has started using some AI tool that your security team hasn't approved—
Use the code NLSUMMER26 at checkout.
Pick of the Week.
Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.
It doesn't have to be security related necessarily. Well, my Pick of the Week this week is not security related.
This last weekend I had the chance to see a one-woman play at the Bristol Old Vic, and it so happens I am a big fan of Nina Simone, the music of Nina Simone.
I think she was incredible. Incredible, and her music continues to be. And the play I saw was a one-woman play called Black Is the Colour of My Voice.
And an American actor called Afia Campbell is the writer and performer of the show, which sees her as Nina Bordeaux. She's not Nina Simone.
She's Nina Bordeaux, possibly for legal reasons.
It's a life shaped by racism and civil rights and Martin Luther King and all these things are crossing over into her life.
Anyway, Afia Campbell, she doesn't play the piano, but she sings, and there is a musical accompaniment as well during the performance.
She weaves in some of Nina Simone's really beautiful, haunting songs. I Loves You Porgy, Wild Is the Wind. They're all in the narrative as well. It's about an hour and a quarter long.
I really, really liked it. It was spellbinding. It got your attention. The music obviously was band-bloody-tastic. It's on tour.
And if that sounds like your kind of thing, go and check it out. Link in the show notes. So, Black Is the Colour of My Voice is my pick of the week.
Netflix have launched the second season of their live-action Avatar: The Last Airbender. Oh yes. Which has had very mixed reviews from fans.
There was famously a terrible Avatar movie about 10, 15 years ago that I think is one of the most panned movies of all time. The fandom hated it, the casuals hated it too.
And it was sort of widely regarded as one of the best sort of kids anime series of all time. So this live action season, everyone praises the actors.
You know, these are real children acting. And apparently the SFX are good, but, you know, it's different. It's live action. It's trying to be a bit more adult.
I think it's trying to get people who watched the cartoon as a kid. And so they've been fairly mixed.
Anyway, all of this made me realise I'd never watched the actual original series. Oh, okay. You know, I was a little bit old for it when it was out. But I love that kind of thing.
I was too old for the Pokémon cartoon. They were sort of fun background if you're working or whatever.
And so I've been working my way through these, the original animated Avatar: The Last Airbender.
And honestly, if you've got a sort of 8, 9, 10-year-old, sit down and watch it with them.
Or if you've just got the brain of a child like I do, have it on while you do something else. It is not emotionally taxing, but they are well plotted. They are well structured.
They are 20 minutes long an episode. You know that the story completes, it's 3 seasons and done. It's lovely. And I can see why people loved it. It's a really good show.
So Avatar: The Last Airbender, the latest recommendation anyone will give you for that, I'm sure.
But yeah, I can see why people fell in love with the animated one.
I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way to do that?
And don't forget to ensure you never miss another episode of Smashing Security. Find it in your favourite podcast apps such as Spotify, Pocket Casts, and Apple Podcasts.
For episode show notes, sponsorship info, guest list, and the entire back catalogue of 477 episodes, check out smashingsecurity.com. Until next time, cheerio, bye-bye, farewell.
You've been listening to Smashing Security with me, Graham Cluley.
A big, big thanks to James Ball for joining us this week and to this episode's sponsors, NordLayer, Vanta, and Arctic Wolf.
Go and check out their services and products, why don't you? And also to the following fine folks who are amongst our fantastic Smashing Security patrons.
So picking some out of the hat at random, we start with Matt H and Alvin. Also big thanks to Yuri Taraday and to the letter J, just the letter J, single letter.
Most efficient patron we have ever encountered. Extraordinary commitment to brevity there. Thank you, Jay.
Thank you also to Jessica Orth and Alboros, who remains as delightfully mysterious as ever. And to Lisa, who continues to prove that one name is more than sufficient.
Cheers also to Dan H, who got slightly further than a single letter like Jay, but also kept things admirably concise. And to David Smythe, or is it Smith? I don't know.
Either way, it's a solid sounding name if I ever heard one. And finally for this week, Marvin 71. Marvin, we are still wondering about the other 70 Marvins.
Maybe you can get them to sign up as well.
Those are just a few members of Smashing Security Plus, which means that they get their episodes ad-free and earlier than the general public.
And of course, they can have names pulled out at random to be mercilessly mocked at the end of the show.
If you would like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details. Now, you can also support the show in other ways.
You can like, you can subscribe, you can leave a 5-star review. All that is really appreciated. And do tell your friends about the podcast too.
Go on, go and bash them on the head with a balloon. That's pretty painless because every little bit helps, and you spreading the word really does help me.
Until next time, cheerio, bye-bye.
Host:
Graham Cluley:
Guest:
James Ball:
Episode links:
- Bengaluru triple murder: Accused allegedly used AI chatbot to plan killings, police say – The News Minute.
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days – Bleeping Computer.
- DO NOT BUY: LG’s Spyware TVs, Monitors, and Wiretapping Concerns – YouTube.
- New Russia-affiliated actor Void Blizzard targets critical sectors for espionage – Microsoft Security Blog.
- Russia Advises Citizens Wanted in U.S. Against Visiting Thailand – The Moscow Times.
- Alleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show – Reuters.
- Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links – Ctrl-Alt-Intel.
- Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius – 404 Media.
- “Shai-Hulud” Worm Compromises npm Ecosystem in Supply Chain Attack – Unit 42.
- Black Is The Color Of My Voice trailer – YouTube.
- Black Is The Color Of My Voice – Official Site – Black is the Colour of my Voice.
- Avatar: The Last Airbender (2007) – Netflix.
- Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
Sponsored by:
- Arctic Wolf – See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.
- NordLayer – the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Join Smashing Security PLUS for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.
