Visualização normal
-
Graham Cluley
-
Smashing Security podcast #483: This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a
-
Firewall Daily – The Cyber Express

-
The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown
This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement. From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust. The latest developments also sh
The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown
![]()
The Cyber Express Weekly Roundup
Microsoft Confirms Exploited Entra ID Flaw
Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more...New Zealand Proposes Social Media Ban for Under-16s
New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more...Cyble and DRONA Launch AI Cyber Defense Initiative in India
Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more...AI Agents Could Create New Cybersecurity Risks
Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more...Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute
Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more...Global Crackdown Nets 58 Arrests in West African Crime Networks
An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more...Weekly Cybersecurity Takeaway
This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime. Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring. As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain.-
Graham Cluley
-
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, a
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
-
Malwarebytes
-
What happens to your data when you die? (Lock and Code S07E17)
This week on the Lock and Code podcast… You will die. Your data will not. The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out. As far back as 2007, Facebook was forced to reckon with mass grief when users asked the company to maintain the profile pages of the 32 victims killed by a school shooter at Virginia Tech that year. Those pages became de facto memorials for loved ones to fill with comment
What happens to your data when you die? (Lock and Code S07E17)
This week on the Lock and Code podcast…
You will die. Your data will not.
The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out.
As far back as 2007, Facebook was forced to reckon with mass grief when users asked the company to maintain the profile pages of the 32 victims killed by a school shooter at Virginia Tech that year. Those pages became de facto memorials for loved ones to fill with comments, and today, memorialization has become a full-fledged feature on both Facebook and Instagram. Platforms like YouTube, Pinterest, and LinkedIn—launched with likely zero strategy for a user’s death—now have procedures for next-of-kin to request that a deceased person’s account be deactivated.
Now, think about all the other ways your data can linger after death.
Every year, people accumulate more and digital stuff—email addresses, social media profiles, contact lists, domain names, subscription services, online banking accounts, and the phones, laptops, and tablets that hold it all—and every year, as that digital stuff accumulates, it compounds into ever more problems for someone else to sort out. Here, a small industry of digital estate planners have cropped up, helping families retrieve and preserve anything valuable, no matter how digital, from Spotify playlists, to poignant social media posts that mattered, to the photos stored on a phone.
And where retrieval fails, artificial intelligence has offered an attempt at comfort. The chatbot service Replika launched in 2015 after its founder uploaded a dead friend’s text messages. HereAfter AI reportedly let users upload voice recordings to power a chatbot that sounded and spoke like the deceased. Film studios have pursued the same idea for entertainment, seeking to portray deceased actors in future films.
Surprisingly, almost none of this activity is governed by law, said Tamara Kneese, author of the 2023 book “Death Glitch: How Techno-Solutionism Fails Us in This Life and Beyond.”
“By and large, there is not a great legal mechanism for protecting the privacy rights of the dead,” said Kneese. “It may not be just that a grieving loved one decides to use a bunch of your data from all of your podcasts to create a chatbot to simulate interacting with you after you’re dead, but it may be that a company chooses, in some way, to use an aspect of your personality, of your demeanor, of your voice, of your likeness after your death without anyone really being aware.”
Today, on the Lock and Code podcast with host David Ruiz, we speak with Kneese—Senior Research Scientist at Partnership on AI—about who owns a person’s data after they die, why every platform has invented its own private policy for the dead, and how the technology built to keep the dead close can vanish just as suddenly as they did.
Or worse yet, as Kneese warned for those relying heavily on certain technologies in grief:
“The company gets sold to someone else or disappears, goes bankrupt, and you no longer have that outlet or place for interaction when you’re mourning another time.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Further reading:
Fartein Hauan Nilsen, “Caring for the Algorithm: Care, Love, and the Relational Personhood of Chatbots,” Somatosphere, February 26, 2026
Fartein Hauan Nilsen, “Therapeutic ideology and AI personhood: an anthropological inquiry into AI companionship,” a chapter from “Handbook on Anthropology and Artificial Intelligence,” Edward Elgar Publishing, July 21, 2026
University of Birmingham, “New Model Rules mark meaningful step towards digital inheritance laws,” July 16, 2026
Edina Harbinja, “Governing Digital Immortality: Artificial Intelligence, Deadbots and the Law,” Edward Elgar Publishing, to be published September 2026
Lilian Edwards and Edina Harbinja, “Protecting Post-Mortem Privacy: Reconsidering the Privacy Interests of the Deceased in a Digital World,” May 2013, revised November 2013
Lilian Edwards, Edina Harbinja, and Marisa McVey, “Governing Ghostbots,” Computer Law & Security Review, November 2023
SAG-AFTRA, “SAG-AFTRA Statement on Today’s Passing of California Assembly Bill 1836,” August 31, 2024
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
-
Graham Cluley
-
Smashing Security podcast #481: Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Org
Smashing Security podcast #481: Never say this to a robot dog
-
Firewall Daily – The Cyber Express

-
AI Won’t Replace Cybersecurity Jobs, It’ll Replace the Toil – Harsha Reddy Explains What’s Next
As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question than "should we adopt it" — it's "who's accountable when it goes wrong." To unpack this, The Cyber Express sat down with Harsha Reddy, Head of Information Security at Veterinary Emergency Group (VEG). With nearly two decades in security leadership — including senior roles at Lixil and American Standard before joining VEG — Harsha brings a practitioner's view of where AI is g
AI Won’t Replace Cybersecurity Jobs, It’ll Replace the Toil – Harsha Reddy Explains What’s Next
![]()
As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question than "should we adopt it" — it's "who's accountable when it goes wrong." To unpack this, The Cyber Express sat down with Harsha Reddy, Head of Information Security at Veterinary Emergency Group (VEG).
With nearly two decades in security leadership — including senior roles at Lixil and American Standard before joining VEG — Harsha brings a practitioner's view of where AI is genuinely changing the CISO's job, and where it's mostly just hype and shadow adoption.
Watch the Full Interview:
Harsha Reddy Explains Why AI Will Replace Tasks, Not Defenders
Harsha pushes back on the narrative that AI will hollow out security teams, pointing to Gartner research showing that while most fields are projected to lose jobs to AI, cybersecurity is expected to gain them. In his view, the technology is mainly absorbing the "toil" — log review, alert triage, evidence gathering — that keeps analysts from actually defending.
Also listen to S1 Episode: Awareness and Education at Young Age is the Answer to Cybersecurity Skill Gap
“It's the analyst who refuses to use AI that will get replaced by an analyst who uses it,” he says.
On adoption, Reddy points to a 2024 Microsoft-LinkedIn survey in which most executives called AI critical to their business, yet a majority had no formal plan and most had employees already bringing in their own tools. That gap, he argues, is why so many organizations are now dealing with AI-related data leaks. "Many organizations started onboarding AI like software when they should be onboarding it like staff." His fix isn't more restrictions — blocking AI just pushes it into the shadows — but guardrails, an internal AI enablement committee, and measuring actual business value instead of token consumption.
The conversation also digs into deepfake-driven fraud, why training employees to spot deepfakes is “a losing bet” at machine speed, and how he decides when to greenlight a new AI tool versus telling a business unit “not yet.”
The conversation closes with our newly introduced rapid-fire round "Express Shots" — Claude vs. ChatGPT, passkeys vs. passwords, and Reddy's prediction for the biggest cybersecurity threat of 2030.

-
Graham Cluley
-
Smashing Security podcast #480: This is the AI service you should never sign up to
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off
Smashing Security podcast #480: This is the AI service you should never sign up to
-
Malwarebytes
-
How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood. No, really. In 2012, The Wall Street Journal reported that the travel booking site Orbitz showed Mac users pricier hotel options than PC users, because the company had determined that Mac users spend, on average, 30% more a night on hotels. That same
How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood.
No, really.
In 2012, The Wall Street Journal reported that the travel booking site Orbitz showed Mac users pricier hotel options than PC users, because the company had determined that Mac users spend, on average, 30% more a night on hotels. That same year, The Wall Street Journal (once again) reported that Staples.com showed higher prices to visitors who lived farther away from a competitor like Office Depot. And in 2015, the reporting outfit ProPublica revealed that customers in certain zip codes were shown higher prices for college test prep courses offered by The Princeton Review.
As that investigation found, if customers:
“type some zip codes into the company’s website, they are offered The Princeton Review’s premier course for as little as $6,600. For other zip codes, the same course cost as much as $8,400. One unexpected effect of the company’s geographic approach to pricing is that Asians are almost twice as likely to be offered a higher price than non-Asians.”
This is surveillance pricing put into action.
Under surveillance pricing, companies collect as much data as possible about consumers so that they can alter the literal prices those consumers pay for the exact same goods as everyone else. It is reportedly what caused some customers to see higher prices for televisions in the Target app when those customers were physically located in a Target parking lot. It is also allegedly why Home Depot customers in wealthy neighborhoods oddly paid less. And it is what Delta Airlines walked away from after public backlash.
The near-omnipresence of surveillance pricing is also why so many videos can be found online today that claim that minor alterations to a person’s data trail—like changing an IP address using a VPN or shopping for airline tickets on a public library’s computer—can lead to lower prices online.
The proof behind these claims, however, is harder to test.
Thankfully, one person has already tried.
Video journalist Chris Parr, known on YouTube as Chris the Producer, ran a wild experiment into whether he could “stress-test” surveillance pricing. Far beyond changing his IP address or making online purchases from different locations, Parr started from scratch. By first registering an LLC in the state of Wyoming, Parr granted that LLC both a credit card and a phone, effectively creating a brand new consumer persona to be tracked. But creating a realistic data trail for his LLC would require a little extra help—help that Parr received from an actor he hired for the part.
Today, on the Lock and Code podcast with host David Ruiz, we speak with Parr about his experiment into surveillance pricing, including a high-wire drone act to purchase a White Castle Crave Case in the air space above his home state’s wealthiest neighborhood:
“To the data collectors, they don’t know that this phone is floating in the air, like 200 feet in the air. They just see a geolocation on it.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
-
Graham Cluley
-
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 6
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
-
Graham Cluley
-
Smashing Security podcast #478: This job interview could destroy your company
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised b
Smashing Security podcast #478: This job interview could destroy your company
-
Malwarebytes
-
What’s your data worth on the dark web? (Lock and Code S07E15)
This week on the Lock and Code podcast… Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.” Pithy as the phrase sounds, it is undeniably true. Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.
What’s your data worth on the dark web? (Lock and Code S07E15)
This week on the Lock and Code podcast…
Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”
Pithy as the phrase sounds, it is undeniably true.
Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.
So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?
That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.
These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.
As we wrote on Malwarebytes Labs:
“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”
It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.
And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.
The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.
So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.
Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.
Tune in today to listen to the full episode.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
-
Graham Cluley
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Grah
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
-
Graham Cluley
-
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cyb
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
-
Malwarebytes
-
Trusting your kids online isn’t enough (Lock and Code S07E14)
This week on the Lock and Code podcast… There is a lot going on right now regarding the safety of kids online. In the United States, the majority of state legislatures have passed age verification laws requiring a variety of websites to more rigorously verify the age of their visitors. In the United Kingdom, Canada, Norway, Spain, and Germany, lawmakers are considering bans on social media access for anyone under the age of 16—Australia passed its ban in 2025. In schools across the world,
Trusting your kids online isn’t enough (Lock and Code S07E14)
This week on the Lock and Code podcast…
There is a lot going on right now regarding the safety of kids online.
In the United States, the majority of state legislatures have passed age verification laws requiring a variety of websites to more rigorously verify the age of their visitors. In the United Kingdom, Canada, Norway, Spain, and Germany, lawmakers are considering bans on social media access for anyone under the age of 16—Australia passed its ban in 2025. In schools across the world, smartphones have been removed from classrooms, hallways, and cafeterias. And online, some of the most popular apps and video games with children, such as Discord and Roblox, have implemented default restrictions on what young users can find and who they reach.
But all this activity comes after rising crises at home, as an increasing number of behavioral researchers connect increased social media use with increased rates of depression, isolation, and suicidal thoughts. So, until real, societal change takes place, what is a concerned parent to do?
That’s what we’re trying to answer today.
Today, on the Lock and Code podcast with host David Ruiz, we bring back Anna Brading, editor-in-chief of Malwarebytes Labs and director of content and, perhaps most importantly, mother of three. With a long career in cybersecurity—and an equally long time spent reading, writing, and assigning some of the cybersecurity world’s most pressing headlines—Brading has a unique perspective on what is most dangerous to her children online.
Brading’s list of priorities is long, and includes improper image use, “online nastiness,” and Roblox, but she has a few rules and guidelines to help. She sets a one-hour-a-day video game limit on the weekends, restricts YouTube to a communal and monitored activity, and requests that no one share photos of her children online without her express permission. Importantly, she also reminds parents to trust their guts.
“If the norm now is mental health issues or online grooming or non-consensual porn or constant comparison, then I’m okay without my kids fitting in. I would say be radical, buck the trend, don’t do what everybody else is doing. Say no to things you don’t feel comfortable with.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
-
Graham Cluley
-
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity? Also, Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year. All this and more in this episode of the "Smashing
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
-
Graham Cluley
-
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Meanwhile, "FortiBleed" sees 75,000 Fortinet firewalls thrown wide open - and the real damage is going to roll on for years. All this and more in episode 474 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
-
Malwarebytes
-
This pay gap is programmed (Lock and Code S07E13)
This week on the Lock and Code podcast… Pay is personal for plenty of Americans, but a new distribution model that consumes vast quantities of worker data is turning pay into something else: personalized. For an increasing number of workers in America, the money they can expect to be paid on any given day, week, or month is unknown to them. They could work the same number of hours as they did the shift before. They could help the same number of customers. They could do everything, as near
This pay gap is programmed (Lock and Code S07E13)
This week on the Lock and Code podcast…
Pay is personal for plenty of Americans, but a new distribution model that consumes vast quantities of worker data is turning pay into something else: personalized.
For an increasing number of workers in America, the money they can expect to be paid on any given day, week, or month is unknown to them. They could work the same number of hours as they did the shift before. They could help the same number of customers. They could do everything, as nearly similar as possible, and still be paid less than another worker in the exact same position, or even themselves just last week.
The mechanism behind this pay disparity is called algorithmic wage discrimination and while the term may be new, it’s inner workings could sound quite familiar.
Algorithmic wage discrimination describes the zig-zag pay that is meted out to contract workers by big companies like Uber and Amazon. Whereas many workers in the world rely on salaries, or commissions, or self-determined contract rates, workers at Uber are different.
In the same way that Uber decides what you pay for a ride to the airport, Uber also decides what a driver makes. And the calculus behind that decision is opaque. Location, traffic, the time of day, and the number of drivers on the road all play some role, but not a complete one. And in the same way that Uber incentivizes you with a flash sale or a price so high that you maybe walk a couple blocks in a different direction to get a lower price, Uber incentivizes drivers with bonuses and challenges, keeping them on the road perhaps longer than they intended.
The end result, then, isn’t just unpredictable pay—it’s potentially an attempt to predict and control behavior.
For her 2023 paper, titled “On Algorithmic Wage Discrimination,” professor of law Veena Dubal spoke with many Uber drives who compared this system to “casino culture,” in that the pay is unpredictable but the potential for a jackpot—or, just a good payment on one ride—is enough to convince drivers to stick around, night after night, hour after hour.
As one driver told Dubal:
“It’s like gambling! The house always wins.”
Today, on the Lock and Code podcast with host David Ruiz, we speak with Dubal—professor of law at the UC Irvine School of Law—about how algorithmic wage discrimination works, what data it consumes to function, and the threat it poses as it creeps from gig work into many more industries.
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium Security for Lock and Code listeners.
-
Graham Cluley
-
Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup
A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and TikTok, with a two-week ultimatum to turn themselves in... or else. Meanwhile, a security researcher called Bob DaHacker got her hands on the live broadcast controls for every match of the 2026 FIF
Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup
-
Graham Cluley
-
Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed
What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Meanwhile, someone themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious. Plus don't miss our
Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed
-
Malwarebytes
-
Deepfake porn sites are going offline (re-air) (Lock and Code S07E12)
This week on the Lock and Code podcast… If you weren’t taking deepfakes seriously before, it’s too late now to ignore them. According to new research from Malwarebytes, one in three people who use AI every day said it’s okay to generate pornography of people without their consent. Nearly 10 years ago, “deepfake” technology provided hobbyists and film editors with artificial intelligence (AI) tools to swap the face of one person onto the body of another. In its infancy, this technology
Deepfake porn sites are going offline (re-air) (Lock and Code S07E12)
This week on the Lock and Code podcast…
If you weren’t taking deepfakes seriously before, it’s too late now to ignore them.
According to new research from Malwarebytes, one in three people who use AI every day said it’s okay to generate pornography of people without their consent.
Nearly 10 years ago, “deepfake” technology provided hobbyists and film editors with artificial intelligence (AI) tools to swap the face of one person onto the body of another. In its infancy, this technology brought silly film experiments like swapping Tom Cruise in Mission Impossible with Keanu Reeves. Today, this same technology produces something far more harmful—fake nude images of teenagers.
On the Lock and Code podcast today with host David Ruiz, we are re-visiting an interview from 2024, in which we spoke with a lawyer named David Chiu about his lawsuit against 16 deepfake nude generation websites.
The websites named in that lawsuit often needed just one image of a person to generate fake pornography. And while nearly everyone has at least one image of themselves online, even if they had hundreds, the path towards deletion is somewhat understood—start by deactivating and deleting popular social media accounts. But for teenagers today, raised mostly online, and who share images directly with friends and boyfriends and girlfriends and exes, it’s likely impossible to remove every visual trace of themselves. Also, they shouldn’t have to face this problem alone.
The Lock and Code podcast frequently discusses structural problems that require individual management. You have to skirt corporate data collection. You have to find the automated license plate readers in your hometown. You have to review every single message you get with a certain antagonism, to guard yourself against scams.
So, it’s rare to encounter a solution that benefits more than one person.
Chiu serves as the City Attorney for San Francisco, which means his department can file a lawsuit on behalf of not just the people of San Francisco, but also California, and that’s what his team did in going after the deepfake websites.
Since then, Chiu’s department has shut down 10 deepfake nude websites, and it received a settlement agreement from a company called Briver LLC to no longer operate any website that creates nonconsensual deepfake pornography.
And, as California goes, so goes the nation.
In May of last year, the Take It Down Act became effective as law in the United States, which criminalizes “revenge porn” and AI-generated nonconsensual intimate imagery. The law is not perfect but so far it is being used as intended. Last month, two men in the US were among the first to be charged with violating the Take It Down act for allegedly creating deepfake nudes that, according to the AP, “included both celebrities as well as private women, including recent high school graduates.”
Today, we revisit our conversation with San Francisco City Attorney David Chiu about the important fight against deepfake porn and the clear threat that his department found against the public.
“At least one of these websites specifically promotes the non-consensual nature of this. So, and I’ll just quote, ‘Imagine wasting time taking her out on dates when you can just use website X to get her nudes.'”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium Security for Lock and Code listeners.