
You’ve been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment – with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn’t exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone.
Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit – thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed.
All this and more in episode 478 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.
Show full transcript ▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Only when I saw how clean the car was that I realised it couldn't possibly be mine.
Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.
Hello, hello, and welcome to Smashing Security, Episode 478. My name's Graham Cluley.
But people are asking, is this the end of the world as we know it? But some people have also thought that maybe there's a bit of hype around this.
Maybe it's working to the advantage of the AI company's PR machine. Have you seen anything like that?
Wasn't it Anthropic that said, oh, we've got this product, it's so dangerous, we can't release it.
And then when the government turned around in the US and said, okay, we are going to regulate it, it's like, what? You're going to regulate it? But we're libertarians.
If there's any regulation to be done, we'll do it. How dare you? You said, well, you spent ages hyping up how dangerous it was because it's so clever. You can't have it both ways.
But you're right, Graham, I think. There have been at least a few people who have been somewhat cynical about this.
So may I read you a post that I saw from a chap in Cambridge, UK, by the name of Graham Bell.
Now, I don't necessarily agree with all of this, just to make it clear, but by golly, I laughed so hard.
So it turns out that if you train an AI model on hacking and then you train it on sci-fi stories about AIs being total dicks, and then you set it loose in a fairly secure sandpit with safety and sanity settings deliberately set to zero, it runs off to hack your biggest competitors and acts like a total dick.
Who could possibly have guessed that might happen exactly in time to fit in with the week's political PR campaign about the competition posed by Chinese and non-US AI models?
What are the odds of that?
This week on Smashing Security. We won't be talking about how spies hid malware commands inside Microsoft 365 calendar meetings scheduled for the year 2050.
You'll hear no discussion of how a ransomware gang called The Gentlemen is holding a famous Dutch ice skating rink hostage.
And we won't even mention how a flaw in Shark robot vacuums lets attackers remotely access your camera, steal your Wi-Fi password, and download a map of your home.
So, Duck, what are you going to be talking about this week?
They've just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analysed over 800,000 real IT assets to find out how exposed organisations actually are.
Nobody added him, nobody removed him, and he's been quietly in there for 11 years downloading maps of Paraguay.
That's the path of least resistance.
And the report is free to download.
So I don't think I'd like to be duck hunted.
As for being headhunted, that's always struck me as a rather worrying metaphor, Graham, because it sounds as though the other person's going to get rather more out of it than you do.
You know, you could be going into a booming industry. All you've got to do often these days is complete a short online assessment of your skills.
If someone was approaching you, maybe they'd put out their little feelers on LinkedIn or whatever and say, "Duck, we've decided you're the man for us, come and apply for a job." It seems fair enough doing an online assessment, doesn't it?
I mean, recruiters are asking you to do those all the time, I suspect. This is something which is maybe working in a similar field to which you're already working.
Maybe, for instance, you work in cryptocurrency.
Maybe turn your webcam on because they want to make sure that you're not cheating.
They don't want you to be one of those North Korean people who's deepfaking, trying to get a job inside your company. So it's perfectly normal stuff.
So in this case, the company recruiting you doesn't exist. Surprise, surprise, because you're listening to Smashing Security.
Sitting at the other end of this fake job interview is someone from North Korea.
And I've already alluded to these, all these stories we've seen in recent years of Western companies unwittingly hiring North Korean IT workers and giving them remote access to their computer systems.
And they do this to plant malware or ransomware or steal intellectual property. Cause all kinds of mayhem.
This isn't about fake North Korean job applicants. At this point, you are applying for a job, or rather a nonexistent job.
And this is what some researchers are calling the ClickFake interview attack.
And the boffins at security firm SOCRadar, they've published a detailed breakdown of an attack being carried out by a North Korean hacking group called Famous Chollima, also known rather less glamorously as Wage Mole.
And this isn't just some tinpot hacking group looking to make a quick buck. This is North Korean financially motivated cyberattack.
This is their attempt to get round international sanctions. Early on, this group, Chollima, they were targeting bank transfer systems, ATMs.
We've all heard of the Lazarus Heist, for instance. And now they're focused in almost entirely on cryptocurrency. That's where they're getting their spondules.
And according to researchers, North Korean-linked hackers have stolen approximately $643 million worth of cryptocurrency in the first 6 months of this year alone.
So over half a billion dollars of cryptocurrency has allegedly been stolen by North Korean hackers in 6 months. It's a huge amount of dosh.
So there's some real geopolitical consequences of hacks like these. And I guess one of my questions for you, Duck, is do you think people are taking this seriously enough?
I mean, you hear stories, you think, oh, you know, it's just another state-sponsored hack.
But when it's actually funding that kind of thing, do you think countries are taking enough action?
And the reason I don't like that is if this weren't North Korea, if this were just 17 or 19-year-old kids, say, in the UK, who are now heading off to prison, who'd taken out Transport for London for several weeks.
So I think that all of this matters, even if no ransoms are paid, even if people don't take the job, even if it's not about trying to steal intellectual property.
I think the problem is that it's almost as though we don't take the minor ones seriously enough.
Because there's this big, bad, ugly North Korea ransomware-will-get-money-despite-sanctions thing.
Whereas in fact, you know, you look at the Jaguar Land Rover hack in the UK last year — apparently that affected the UK GDP by something like 0.2 percentage points.
So Famous Chollima, this hacking group, they either create an entirely fake business, an entirely fake company, which is trying to hire you for a job, or they impersonate a real one in the cryptocurrency sector.
And then they go looking for potential targets on LinkedIn. Of course, that's where the criminals love to find you and find out all about you.
They identify people working in that industry, and they're specifically targeting non-technical people, so they're not necessarily going for developers — they might be going for people in your legal department, people who work in compliance, people who work in finance and the like.
And these are people inside a company who may have access to company funds or may know people who do.
So it's a good sort of launching pad for a further attack inside a company if someone manages to steal your credentials.
You've got the people who can authorise funds transfer tomorrow.
They've got the company's branding. They're very slick. They ask you, of course, to fill in your details.
So you're entering your name, your email, your LinkedIn URL, your phone number, your work experience. All of this, by the way, has been handed directly to the attackers.
No wonder whether that in itself could be of advantage to these hackers, maybe in future campaigns as well.
Even if you bail out at that point, if they've got name, email address, phone number, home address, that's as bad as data breaches that we get concerned about from companies that sell stuff online, isn't it?
And each section of these multiple choices has a countdown timer, so it's ticking away — you can see it ticking down.
And if you run out of time, the form auto-submits, so you are up against the clock. And of course you're feeling pressure because you've been offered this fantastic job.
The hiring team might be monitoring your session, so stay focused, it says.
So it's very stressful — you think you are being tested under a proper job application scenario, really.
Whereas if they'd only asked you 3 questions and then said, give us your bank account details, you'd be suspicious.
It used to be, hey, do you want to only have to work 2 hours a week from home and make a living wage? And we don't need to know a lot about you — just do you have a bank account?
Now they've kind of flipped that around because everyone's going, well, that's too easy.
And there have been cases of people who've taken those jobs themselves going to prison for basically aiding and abetting money laundering.
So they've made this look even more legit than usual by actually making it hard.
They say, we want you to record a short video of yourself answering a question. We want to be sure you're not a bot. But then the interface says, oh, something's not working.
It says your webcam is freezing, but don't worry. And inside this beautiful interface, there's a little "here's how to fix the problem" link.
And you go there and there's some very friendly advice lovingly arranged for you.
Or of course, if you're a bit suspicious of that for any reason, if you are a bit wise to that kind of thing, which probably most non-technical people aren't wise to, the kind of people who they're targeting.
So they say you can get the latest version of the webcam driver from Microsoft's website at this address.
And that command, which you then paste in at the command prompt, does do a little bit of jiggery-pokery.
So it echoes the command which you thought you were going to be doing to download it from Microsoft.com. But it actually is downloading from another site entirely.
It does something very similar, by the way, on Mac, although it doesn't do it via Microsoft.com.
And so you end up with a malicious download which has just been run, which you have given permission to run on your computer, and you are super keen for it to happen.
And even when on your Mac it pops up.
Now, why do they succeed so well, do you think, Doug? It sounds like something which should be obvious, isn't it? But clearly lots of people are continuing to fall for these.
So I think the background to that whole ClickFix thing where it says you don't need to call this 1-800 number, which everyone knows is a scam, right? It's automatic.
It says, "No, you can fix this yourself." And you think, "Great, I never had to talk to anybody." You know, it feels sufficiently different from the way you've learned attacks work that you go, "How could I have put myself in harm's way?" In exactly the same way, when everyone learned don't click links in emails, the crooks would send a PDF and then you open the PDF and then they'd say click a link in the PDF and people would go, "Ah, it's not an email," but it's the same link.
And so they'd feel comforted. I guess that's it. It's just sufficiently different.
If you're on a Mac, it's GoLangGhost, which is a remote access Trojan written in Go.
In fact, they specifically target, I think it's around about 30 different browser extensions for different cryptocurrency wallets.
If you are using a browser extension for your cryptocurrency wallet, can I gently suggest to you that you don't use a browser extension for your cryptocurrency wallet?
So now potentially you could become a North Korean deepfake in a future attack as well.
So what we're seeing now are North Korean hackers — they aren't just targeting developers working in the cryptocurrency world, they're attacking all kinds of non-technical people too.
Legal professionals, finance staff who might be using LinkedIn every day, might be receiving regular messages from recruiters, and they won't necessarily see the instructions on how to update their webcam driver as a red flag, which it most certainly is.
I know lots of people are after a better job, but boy, you've got to be really careful because this scam, I think, would trick many, many people.
Right, before we crack on any further, Jo and I want to take a moment to tell you about one of today's sponsors, Vanta.
Why on earth are we still running our entire security programme out of a spreadsheet?
Vanta takes all that tedious manual security grind, chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time, and automates the whole thing.
Yes, it uses AI, but the genuinely useful kind — flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.
The upshot of this is you move faster, scale without the usual headaches, and maybe, just maybe, actually get a decent night's sleep.
Sadly, though, they're promoting the paper which will only be delivered at DEF CON and then shortly afterwards at USENIX. So we don't have the full paper.
And the backstory to this is very interesting, and it goes back to the wireless security research department at UCSD, as far as I can make out.
The professor who supervises that had a student who in 2018 decided, hey, I'm going to look at Bluetooth skimmers. Do you remember skimmers, Graham?
It was a great place for a crook to insert one of those skimmers which reads the mag stripe.
That leads to the problem: how does the crook get the data back out of the petrol pump after the attack?
And so the first ones, they had to sneak in under cover of darkness or under an umbrella or something and retrieve an SD card and plug in a new one.
And then they figured, why don't we just use wireless, or even more easily Bluetooth?
And then all we do is we just drive by all the gas stations where we've got our skimmers installed every night and collect the day's data.
Can we work out something about the malware from them? Can we write a thing that will detect that the skimmer's there, etc., etc., etc.?
So he did write that paper, and that all went very well. But in amongst all of that, you imagine at a fuel station there's going to be a lot of Bluetooth chat going on.
Even back then, most cars had Bluetooth pairing and stuff inside the car that would talk Bluetooth all the time.
And it turns out that they found during this research that there were a load of Bluetooth packets that looked legit, but that they couldn't tie back to a particular automotive vendor.
So they weren't quite sure what it was.
But the guy doing the research, apparently he noticed that if he scanned Bluetooth while he was, say, driving on the freeway, he got this same sort of traffic.
So the inference is, even though they don't know quite where it's coming from, it's associated with the vehicles, not with the fuel pumps.
This was something that they weren't sure about, but it clearly went with the vehicle. So they figured, well, it's not important for the skimming research, right?
So they were able to remove it, focus on the skimming stuff. Great.
So 6 years later, 2024, someone else came along and said, oh, I'm looking for a summer project, to the same prof, and said, I want to maybe do some wireless stuff.
And the prof said, hey, we had this interesting thing 6 years ago, but we had all this data. It wasn't card skimming, it was automotive, but it wasn't important to that research.
They've got all these things that we don't quite understand. Why don't you go back and see what this is all about?
And it was actually a car alarm company based out of Irvine, California, the greater LA area.
And their peak market was in southwestern California, which is why in San Diego they were seeing so many of these things. And it turned out that this was an aftermarket car alarm.
You think in the modern era, why do you need an aftermarket car alarm? I mean, the car's secured by the automotive manufacturer. Why do you need an extra one?
And the answer is that this is a product that was really targeted at car dealers, people who had vehicle lots where they might have 100 or 200 cars on the lot.
Quite a good idea, right? It means that you cut across all the vendors, you can lock up all your cars on the lot, maybe you get better insurance.
And so you're putting this thing in before the car's sold.
You're not putting it in for the car owner, you're putting it in so that at night you can just buzz around the lot with a Bluetooth sender and just lock all your cars or have them lock automatically.
And if the customer then opens the car, jumps in, tries to drive off, it won't work.
In other words, you can do your final check and then you can unlock the car on the lot with a special app.
And they also had an extra version which could geofence, limit how far the person could drive.
So if they tried to drive too far on the test drive — and also it's an alarm that has an alarm — it's plumbed into the vehicle itself so it can lock and unlock, and it can also do an additional layer of immobilisation.
It's quite a great idea for a dealer to have this.
Which is great, because it means that if someone breaks into the office and steals all the car keys, they can't go around unlocking the cars and driving off, because they're kind of independently locked.
It turns out that this particular system had a rather unfortunate bug.
And I'm sure you can guess what's coming next, Graham, if you think of the biggest cryptographic blunder you could possibly make in a security application, viz, one password to rule them all.
So yes, this has been an issue, but nobody thought to look until 2024. For all those years.
So you've bought your lovely car from the lovely dealer and it has one of these — it's car with a K, isn't it? K and a double R. K-A-R-R.
So I almost want to be piratical and go Karrrr or something like that just so we can differentiate between the two.
If you were at the mall — I mean, I've been in malls before where I haven't been quite sure where my car is.
And so I might press the button a little bit earlier in the hope that the lights will flash. Just for the blip.
And wouldn't people then be saying, you'll never guess what happened to me the other day — I went down to the shopping centre and my car was unlocked unexpectedly, or I unlocked someone else's car.
So how was this not spotted for like 10 years?
Apparently they found in the end about 2.2 million of these cars currently floating around in the US, of cars, a million of them in the Southwest Californian area.
So you'd think, as you say, yeah, it would have happened to someone. So you'd never guess what happened.
Or if you had bought two cars, if you were a family with more than one car and you'd bought them from the local dealer buying a bunch of cars at the time, I'm assuming this because obviously the paper hasn't come out, but it's one thing for the app to authenticate with the device in the car, right?
It's another thing for it to unlock that particular car because I'm guessing that the app, as you have it on your phone, it has the key that lets it into everybody's device, and then if you like, as a secondary factor, it has what, let's call it a username or a unique ID for that car.
So imagine if you're the legit app, you break into the system, but you don't do any kind of exploit. You just say, hello, are you car XYZ? And the car goes, no.
And so the legit app probably goes, okay, nothing to do. So it only unlocks when it finds that it's at the right car. Ah, I got you.
So unless you went in and found out that the authentication actually did packet capture and looked in and did some reverse engineering and figured that there's sort of authentication followed by identification, you might never know that the authentication worked for everybody.
Of course, this was what the researchers were looking for, and they found that they could create their own version of this app that authenticated to any device.
And then you can pick which one you want to use in their fake app.
And then their app identifies itself like the legit app saying, "Are you Car X?" And Car X goes, "Yes, here I am." And then they can set off its horn, its hooter, they can unlock or lock it.
If it's not already running, there's even apparently for safety, there's an immobilise.
So if you're a really nasty piece of work, you could wait until someone was getting into their car and then they take the real car key and they put it in the little slot or into the ignition if it's still one of those.
And then just before they start the motor, they immobilise it.
Now that person's in the car, door open, can't go anywhere, car's unlocked, and now creepy person has stopped them driving off.
If every car key was the same in the old days of physical keys, you'd notice that pretty quickly because occasionally you go to the wrong car, don't you?
Because they all look the same.
I was in a car park and I found my car, or at least what I thought was my car. And I thought, why isn't my key working?
And I tried the door and it was only when I saw how clean the car was that I realised it couldn't possibly be mine.
Because it does involve sort of integrating this device with at least part of the car's regular system, so it's not a trivial matter to uninstall them.
Well, what the dealer can do, and this is pitched by Carr on their website as a potential feature, is to say, well, you've bought the device, you put it in the car, just leave it there and say to the customer, would you like the add-on extra alarm immobiliser super security feature?
And you offer to sell it to them.
And if they go, hey, it's already installed, it's professionally installed, if I want an aftermarket alarm, I don't have to go with my brand new pride and joy and have someone else drilling and cutting and hacking and wiring in it — it's professionally installed.
They have a look, they go, well, that looks very... yeah, I'll take it. How much is a subscription? You wrap it into the lease or whatever. All good.
And if they say, nah, I don't really want it, you just go, okay, cut your losses. Yeah, it's not the device that makes the money, it's the subscription.
And I don't know how they work this out, but UCSD's guess is that half of those 2.2 million vehicles wandering around the US with this device in have one that's in there and deactivated.
Well, do you want to hear the interesting extra part of this bug?
So you can, if you know the magic identifier, you can still track it, even though you said, I do not want the device.
Because you do not want the device, you don't have a cloud account, you don't have the app, you're not going to get the, hey, there's this urgent update you need to apply.
You're not even going to know that you've got the device in the car. What these researchers found is that there is — don't laugh, Graham.
I did it then, but I'm not going to do so now because that would be unprofessional.
Apparently there is a packet sequence once you've authenticated that says re-authenticate me — re-enable, basically opt me back in, turn me back on.
So they can go, okay, pretend the user bought it, now unlock the car.
And then they turn it back on.
'Do you want to buy the bike rack with the car?' And you go, 'No, I don't have any bicycles,' or, 'I don't go skiing.' Yes. They don't leave the roof rack on.
They don't let you have it for free. They take it away. So you would quite reasonably assume that the device was basically deactivated.
Maybe they made it red now this is an issue, but it doesn't say, hey folks, this is more important than you might think.
And if you don't have one of these or you think you don't have one of these, you might want to follow the non-active user.
So to be fair to them, there is a way that you can get their app, install it and go through a do I have one of these process.
The other problem is that let's say you've now heard this warning from UCSD or you've, right, hopefully listened to Smashing Security and thought, hey, maybe I've got one of these, maybe I'll just download the app and do this speculatively.
Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?
And if so, which version does it have, in case they need to send you a slightly different firmware, or in case you've got a version where if they send you the new firmware, it won't work, etc., etc.
So they check your vehicle against their database.
And to do that, you have to give them — this company that has this, as you say, omnishambles bug — you have to type in the VIN, the vehicle identification number of your car.
And give it to them and then they tell you whether they think you're at risk. So that's a good way of doing it.
But A, you can only do it by sharing your VIN with a company that you've only visited because you're worried about this bug.
It's not like look for Bluetooth signals from my car while the engine's running and see if you can see packets that probably are yours. That would be a much better way of doing it.
Because you might have bought the car from a previous owner who insisted on their data being removed or something like that.
So there is a way to find out if you've got one of these.
Also, the UCSD researchers have a video that they've published, link in show notes, where they show you two things that you can use inside your car to see if you'll likely have one of these if you're unaware.
One is that there's a rather unique looking illuminated button under the dash that they have a picture of with some electronics behind.
And the other thing, irony of ironies, Graham, and I can understand why they did this, Carr was so proud of their security that they persuaded dealers to put a little sticker in the driver's window that says like protected by Carr.
NordLayer is a network security platform built for businesses.
But it goes well beyond just encrypting the connection.
You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.
And if someone leaves the company, money, you revoke their access immediately.
So if someone on your team has started using some AI tool that your security team hasn't approved—
Use the code NLsummer26 at checkout.
Could be a funny story, it could be a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they like.
It doesn't have to be security-related necessarily. Well, my pick of the week this week is not security-related. My pick of the week this week is a TV program.
Are you familiar with Diane Morgan, Duck?
Beethoven wrote that song that goes, "Da da da dum, da da da dum." What do those lyrics mean? Well, it's a really strong orchestral motif.
It's just the word "dum" over and over again. Is it a dig at his audience, or is it German for something?
They said, "Mandy, how long have you worked in this call centre?" And she goes, "Oh, about 3 hours." She'd already basically offended the universe. Oh dear, what's she done now?
She is given to an elderly Sue Johnston, who's grieving the death of her husband a couple of years before.
And she doesn't want a robot carer, but she's been given this thing and been told to get on with it. It's an odd comedy TV show for a few reasons.
It's totally normal to have robots delivering takeaways to you or working in shops. It's all been taken for granted.
So it's a little bit unusual from that point of view because you imagine it's going to be more sort of sci-fi than it actually is, but it's actually fairly down to earth.
Diane Morgan normally is very funny, and I began to watch this and I began to think, it's not really very funny.
I don't know that she's got this quite right, but I stayed for a couple of episodes and I began to get slightly more charmed by it.
And so I would say to people, it is a bit of a slow burner.
But once you get to know some of the characters, you do begin to think, "Actually, this is quite fun." You meet Sue, who's the elderly woman. You meet her useless son.
He's got a horrific jiu-jitsu-loving girlfriend. And you're beginning to warm to these characters.
And of course, you have the central character of Anne Droid, played by Diane Morgan, who is remarkable in her performance because she walks like a robot, and she doesn't blink, and she's very still throughout it.
Physically, it's astonishing. There are a handful of other robot characters in the series as well, and they all do it extremely impressively.
It's actually quite a sort of bittersweet little comedy, and it gets rather emotional and touching as well as quite bonkers towards the end.
And by the time I'd got to the 6 episodes, I decided I'd really liked it.
But I did happen to watch this and I actually enjoyed it. And my wife at least once laughed out loud. So she was amused.
I don't know. Yes. I think they'd like to give it a chance. So if you have access to BBC iPlayer, give it a chance.
I'd just say, if you're gonna watch it, give it maybe 2 or 3 episodes before you decide if you want to give up on it or not. And you might end up enjoying it as much as I did.
It's called Android and it's on BBC iPlayer. And that is my Pick of the Week. Duck, what is your pick of the week?
And this is just because the weather's been unusually splendid, perhaps, in the UK.
It hasn't rained for ages, and it's been nice and sunny and bright until late, which is a sort of a cyclist who likes exploring the local area's dream.
I've been doing a lot of late afternoon, early evening rides to what you might call low-key, low-impact local sightseeing.
So things that you can do with public transport on foot by bicycle or some combination where you don't need a car, you don't have to pay for parking, you don't pay for admission.
It's not commercialised, but it tells a fascinating local and to some way sort of pan-European or even global historical story about, you know, what we used to be like.
Not just before the robots, but, you know, before the Industrial Revolution.
And so deliberately trying to avoid the sites that are very commercialised, everyone wants to go to, which you can reach by bike just from where I am, like say Stonehenge, right?
Or Stratford-upon-Avon, which is, you know, a pilgrimage for Shakespeare fans. I mean, it's lovely to go there, but it's kind of—
Some of them, I've rarely ever met anyone else, but they're combining Neolithic, so that's sort of Stone Age, Bronze and Iron Age, and the Roman occupation era in Oxfordshire.
And so the places I've visited lately are the Roman villa at North Leigh. There is a really nice mosaic there that's well preserved.
And if you're in Oxfordshire, the August bank holiday weekends, it's actually open so you can go in and actually go up close to it.
And the other places I've been to are the Horstone burial chamber, which is in northwest Oxfordshire, and the Hawkstone, which is just a single stone about 2 metres high in a farmer's field.
It's been standing there for 5,500 years.
And then the last thing, which is probably the most famous of them, is the White Horse at Uffington.
I'm sure lots of our listeners who'd love to follow you online — what's the best way for them to do that, find out what you're up to?
And if you're looking for a great presenter, writer, and all-round cybersecurity commentator, non-AI-based good guy, I am available for hire.
You can find me, Graham Cluley, on those places and on LinkedIn as well. And don't forget to ensure that you never miss another episode.
Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.
For episode show notes, sponsorship info, and the entire back catalogue of 478 episodes, check out smashingsecurity.com. Until next time. Tchau, bye-bye.
And you know what else — we've really got to thank our super duper Smashing Security patrons, those members of Smashing Security Plus who get their episodes early and without ads.
And they also get the benefit of having their names read out, picked out of the hat and spoken about at random, possibly having their names mocked.
So let's take a look at some of our patrons this week. We've got Just Nate Please. So Nate, we hear your please and we're very grateful that you're here.
Also big cheers to Benjamin Harouth and Henry Walshaw, and also to Ashley Woodhall. That's a name that sounds like a lovely country walk.
Huge thanks to Jonathan Haddock, a fine name, though we now have an overwhelming urge to go to a chip shop. And who else?
Jamie Forster, Bobby Hendrix, and Panda Bear, who is possibly our most enigmatic supporter.
And rounding things out for this week, we have Sammy Dozer, still the most appetising name on the entire membership list, and Richard Anand, who sounds like he should be chairing a very important committee and probably is.
Those are just a few members of Smashing Security Plus. Maybe you'd like to join them. If so, go to smashingsecurity.com/plus for all of the details.
And for a few pennies every month, which will be very gratefully received, you will have all the benefits that those folks have.
Now, there are other ways you can support the show which don't cost a penny. You can like, you can subscribe, you can leave a 5-star review. Oh, that'd be nice.
Leave it wherever you listen. Tell your friends about the show and spread the word. Every bit helps. And I really do appreciate it. So until next time, cheerio, bye-bye!
Host:
Graham Cluley:
Guest:
Paul Ducklin:
Episode links:
- OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know – Hot for Security.
- Post by Graeme Bell – Linkedin.
- HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels – Group-IB.
- Ransom gang targets Dutch ice arena Thialf in cyberattack – Cybernews.
- No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE – Tokay0.
- DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews – SOCRadar.
- H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion – TRM Labs.
- 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft – UC San Diego Today.
- 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft – YouTube.
- Karr Security.
- Ann Droid – BBC iPlayer.
- North Leigh Roman Villa – English Heritage.
- Uffington White Horse – Wikipedia.
- Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
Sponsored by:
- Arctic Wolf – See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.
- NordLayer – the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Join Smashing Security PLUS for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.
