Graham Cluley
gcluley@mastodon.green
<p>Computer <a href="https://mastodon.green/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a> chap. Public speaker, blogger, <a href="https://mastodon.green/tags/DoctorWho" class="mention hashtag" rel="tag">#<span>DoctorWho</span></a> fan since 1972. Author of Jacaranda Jim and Humbug games. Host of the <span class="h-card" translate="no"><a href="https://mastodon.green/@smashingsecurity" class="u-url mention">@<span>smashingsecurity</span></a></span> <a href="https://mastodon.green/tags/podcast" class="mention hashtag" rel="tag">#<span>podcast</span></a>. Needs haircut. </p><p><a href="https://mastodon.green/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> <a href="https://mastodon.green/tags/infosec" class="mention hashtag"
Posts
-
Post #4278136
Anthropic not wanting to be left behind by OpenAI, I see... No doubt someone in their marketing department was crying into their coffee that OpenAI got there first...
-
Post #4136033
Russian disinformation is being designed to be invisible to humans - but highly visible to AI. This new report from Demos reveals how a sanctioned Russian propaganda operation (the "Foundation to Battle Injustice") deliberately crafted websites to *avoid* appearing prominently in Google search results, while maximising how much AI systems like ChatGPT, Gemini and Claude would extract their text and parrot it out. Definitely worth a read... https://demos.co.uk/research/geo-for-geopol...
-
Post #4061780
Worst companion since Bonnie Langford?
-
Post #4041067
Great to have James Ball join me on the latest episode of the "Smashing Security" podcast where he explains how Suno was hacked, revealing awkward details of how it taught its AI to generate music. Plus we discuss the case of the hacker suspected of links to the Kremlin, who may have been caught out by his McDonald's Chicken McNugget deliveries... All this, and more, in episode 477 of the "Smashing Security" podcast... https://pod.link/1195001633/episode/NGVlNTY2YWMtYzQ...
-
Post #4038256
You can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the newspaper headlines suggest? https://www.bitdefender.com/en-us/blog/hotforsecurity/openais-hacks-hugging-face
-
Post #3987231
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is using fake CAPTCHA checks to trick people into compromising their own PCs. https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself
-
Post #3896994
Google's Gemini lets strangers send messages from your locked Android phone Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone... Read more in my article on the Bitdefender blog : https://www.bitdefender.com/en-us/blog/hotforsecurity/googles-gemini-strangers-messages-locked-android-phone
-
Post #3859447
Scattered Spider members who hacked TfL from their bedroom, costing £39 million and exposing data on 10 million customers, were sentenced to 5 years and 6 months each today. The NCA had video footage of them doing it. Video footage they had taken themselves! Remember - crime doesn't pay.
-
Post #3803791
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't expect is that their trusted negotiator might be separately sharing details of the victim's cyber-insurance policy and negotiation strategy directly with the attackers themselves. https://www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiato...
-
Post #3692871
Hacker hijacks Brazil&#39;s national alert system, sending &quot;misanthropy&quot; to millions of phones. Emergency alert systems work because people believe them. Every time one of these systems issues a false alert - whether through negligence or a deliberate attack - trust erodes. Read more in my article on the Bitdefender blog: https://www.bitdefender.com/en-us/blog/hotforsecurity/hacker-hijacks-brazils-national-alert-system
-
Post #3692870
Thanks to Danny Palmer and Black Kite&#39;s Jeffrey Wheatman for joining me on the latest &quot;Smashing Security&quot; podcast: * A security researcher who found she could access the live broadcast controls for every match of the 2026 FIFA World Cup... and spent days trying to get anyone at FIFA to pick up the phone. * Dutch police&#39;s genius - and slightly cheeky - response to a wave of fraudsters targeting elderly victims * Europe&#39;s ransomware surge. https://www...
-
Post #3692869
Scammers wasted no time exploiting Venezuela&#39;s devastating earthquake, with researchers uncovering 212 newly-registered emergency relief-themed domains in just five days. Read more in my article on the Bitdefender blog: https://www.bitdefender.com/en-us/blog/hotforsecurity/scammers-cash-in-venezuela-earthquake
-
Post #3692868
In the wake of Fortibleed hitting Fortinet firewall users, &quot;Smashing Security&quot; podcast special guest Quentyn Taylor recommends you should be bouncing your credentials.... oh, and you are using passkeys and hardware tokens for your MFA, right? https://www.smashingsecurity.com/474
-
Post #3692867
I didn’t stay up late to watch England play Mexico, but I might stay up tonight for Belgium vs USA… It’ll be a rare moment when most of the world will be united in willing one team to give the other a right thrashing.
-
Post #3692866
Sharing for a friend...
-
Post #3692865
Two arrested over credit card phishing - as the Netherlands is named Europe&#39;s worst for payment fraud. Read more in my article on the Bitdefender blog: https://www.bitdefender.com/en-us/blog/hotforsecurity/two-arrested-credit-card-phishing-netherlands-europe-payment-fraud
-
Post #3692864
Apple&#39;s &quot;Hide My Email&quot; feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year. Thanks to Zoe Rose for joining me on episode 475 of the &quot;Smashing Security&quot; podcast. Find the full episode at https://www.smashingsecurity.com/475
-
Post #3545612
Mullvad VPN's co-CEO has made a sizeable donation to a controversial far-right party in Sweden, advocating “comprehensive re-immigration”. Why is it so damn hard to find a likeable VPN firm? https://www.techradar.com/vpn/vpn-privacy-security/i-dont-like-that-he-made-this-donation-mullvad-ceo-reacts-to-co-founders-donation-to-controversial-swedish-populist-party
-
Post #3538382
Despite their name, there is nothing polite or refined about The Gentlemen ransomware group. Learn more about them in my article on the Fortra blog: https://www.fortra.com/blog/gentlemen-ransomware-what-you-need-know
-
Post #3535001
A new episode of the "Smashing Security" podcast is out! Polymarket claims to predict the future - so how did it fail to spot its own million hack? Plus a Google engineer arrested for insider betting, and someone allegedly caught trying to rig a weather bet with a hairdryer. We also dig into "FortiBleed" - 75,000 Fortinet firewall credentials cracked at industrial scale, with an impact that will last for years. https://www.smashingsecurity.com/474
-
Post #3488012
Counterfeit USB drives carrying China-linked malware sat connected to Japan's military networks for nearly a year. They got in because normal procurement was bypassed during earthquake disaster relief, and nobody can now produce a paper trail showing where they actually came from. https://www.bitdefender.com/en-us/blog/hotforsecurity/usb-drives-carrying-china-linked-malware-infected-japanese-military-networks-for-nearly-a-year
-
Post #3377451
Going to be at Infosecurity Europe next week? Join me, and the experts from Varonis for an exclusive invite‑only panel and buffet lunch where we&#39;ll be discussing how AI is changing attacks, where most breaches really start, and why stopping them is harder than ever. ▶️ https://grahamcluley.com/aipanel
-
Post #3377450
A 14-year-old turned the tram system in the Polish city of Lodz into his own personal train set in 2008, triggering chaos and derailing four vehicles, using a modified a TV remote control. Join me, and special guest Geoff White, on episode 468 of the &quot;Smashing Security&quot; podcast for more stories like this. Find it in all good podcast apps or at https://www.smashingsecurity.com/468
-
Post #3377449
A notorious ransomware gang claims to have stolen MyPillow&#39;s private data, but CEO Mike Lindell calls it a politically motivated &quot;hit job.&quot; With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my article on the Bitdefender blog: https://www.bitdefender.com/en-us/blog/hotforsecurity/mypillow-ransomware-leak-site-denies-breach
-
Post #3377448
Great to have @hacks4pancakes paying a visit to the &quot;Smashing Security&quot; podcast in episode 469, to discuss how the Oura ring fitness tracker transmits unencrypted data... but the company can&#39;t say how often it shares it with law enforcement. Check out the Smashing Security show in all good podcast apps, or at https://www.smashingsecurity.com/469
-
Post #3377447
Hackers have been hijacking Instagram accounts at scale by exploiting Meta&#39;s AI support chatbot. And, as if that weren&#39;t bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog: https://www.fortra.com/blog/metas-own-ai-chatbot-blame-instagram-accounts-being-stolen-seconds
-
Post #3377446
If you&#39;ve ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, MI5 and the FBI have a message for you: be very careful - it might be China trying to recruit you. Read more in my article on the Bitdefender blog: https://www.bitdefender.com/en-us/blog/hotforsecurity/linkedin-recruiter-chinese-intelligence-fbi-mi5
-
Post #3377445
Schools are soft targets for cybercriminals. They hold sensitive data on children, run on tight budgets, and often depend on networked systems for everything from teaching to unlocking the front door. The education sector urgently needs proper funding and expertise to defend itself. Until then, the back-to-school season runs all year round for ransomware gangs. Read more in my article on the Bitdefender blog: https://www.bitdefender.com/en-us/blog/hotforsecurity/why-schools-remain-one-of-cyber...
-
Post #3377444
Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn&#39;t supposed to attack... https://grahamcluley.com/smashing-security-podcast-471/ Thanks to special guest James Ball for joining me on this episode of &a...
-
Post #3377443
Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. https://www.fortra.com/blog/silent-ransom-group-what-you-need-know