Smashing Security
4.6(315)

Smashing Security

by Graham Cluley

478 episodesLatest 6 days agoEN

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

Graham Cluley

Recent reviews on Apple Podcasts (5)
  • Love this show

    … I do miss Carole, thought her voice was just perfect, like Grahams, for presenting the news. Hope she visits.

    ႦυႦႦʅҽɠυɱ Ⴆʅυҽʂ ·

  • Great show for a lighthearted view toward cyber security.

    Appreciate the light tone toward cyber security Graham and Carole (when she was here) have. Keeps it enjoyable and makes me instantly jump to it whenever it shows up on my feed.

    anisali01 ·

  • Quality dropped

    Missing Carole already. Tom had an uninformed take on quantum computing. He drops a bunch of random rants that are distracting and unhelpful trying to be funny but it doesn’t work (printer comments for example). Might be unsubscribing from this soon.

    R1921aaaa ·

  • I learn a lot from this podcast

    Thanks for a great podcast—great information and laughs! Thanks to Carole for the links to “Break” (break dancing) at the 2024 Paris Olympics!

    USA Mknitter ·

  • Really?

    Wow. I would like the time I wasted listening to half of an episode back please. I’m sure SS appeals to someone. I’m just not sure who that would be.

    jd2020 ·

View all reviews on Apple Podcasts

Episodes (478)

  1. Remote-control rickshaws and rogue book marketers

    Jul 15, 202638m#476

    An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all

  2. JadePuffer - the AI that ran a ransomware attack all by itself

    Jul 8, 202646m#475

    A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware

  3. Polymarket can predict the future. So how did it miss this hack?

    Jul 1, 202642m#474

    Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the ai

  4. How a hacker could have Rickrolled the entire World Cup

    Jun 24, 20261h 0m#473

    A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch polic

  5. AI gets hacked, and BitLocker gets bypassed

    Jun 17, 20261h 12m#472

    What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly

  6. This AI worm just rewrote its own rules

    Jun 10, 202646m#471

    Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host

  7. This AI security flaw might be impossible to fix

    Jun 3, 202657m#470

    A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a jou

  8. What your Oura ring won't tell you

    May 27, 202653m#469

    CISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile. Meanwhile, your Ou

  9. High-speed train hacks and homicidal lawnmowers

    May 20, 202655m#468

    A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard

  10. How ShinyHunters hacked the world's biggest universities

    May 13, 20261h 4m#467

    Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced

  11. Meta sees everything, Copy Fail, and a deepfake gets hired

    May 6, 20261h 2m#466

    Meta's smart glasses promise privacy "designed for you" - but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them. Meanwh

  12. This developer wanted to cheat at Roblox. It cost millions

    Apr 29, 20261h 4m#465

    A developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds o

  13. Rockstar got hacked. The data was junk. The secrets it revealed were not

    Apr 22, 202651m#464

    A company that ran anonymous tip lines for 35,000 American schools - handling reports of bullying, weapons, and self-harm - boasted on its website that it had suffered zero security breaches in over 20 years. A hacker ca

  14. This AI company leaked its own code. It's also built something terrifying

    Apr 15, 202650m#463

    A hacking group claims to have broken into the flood defence system protecting Venice's Piazza San Marco - and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthro

  15. LinkedIn is spying on you, and you agreed to nothing

    Apr 8, 202641m#462

    LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you're job hunting, what religion you are, and whether you have ADHD. And none of this

  16. This man hid $400 million in a fishing rod. Then it vanished

    Apr 1, 202645m#461

    A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 - and now sits on a fortune worth $400 million. There's just one small problem: the access codes were tucked insi

  17. Never knock on the door of a nuclear submarine base and ask for a selfie

    Mar 26, 202640m#460

    A disgruntled data analyst decides that the best response to losing his contract is to steal the entire company payroll database and demand $2.5 million in Bitcoin - signing his extortion emails from a company called "Lo

  18. This clever scam nearly hijacked a tech CEO's Apple ID

    Mar 19, 202654m#459

    In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a ph

  19. How not to steal $46 million from the US government

    Mar 12, 202641m#458

    A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn't stirred since 2024 - and within minutes, giant woodpecker images are plastered across the internet's favourite encyclopaedia. Meanwhi

  20. How a cybersecurity boss framed his own employee

    Mar 5, 202649m#457

    When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker... who promptly sent an innocent colleague into

  21. How to lose friends and DDoS people

    Feb 26, 202648m#456

    When the mysterious operator of an internet archiving-service decided to silence a curious Finnish blogger, they didn’t just send a stroppy email - they allegedly weaponised their own CAPTCHA page to launch a DDoS attack

  22. Face off: Meta’s Glasses and America’s internet kill switch

    Feb 19, 202644m#455

    Could America turn off Europe's internet? That’s one of the questions that Graham and special guest James Ball will be exploring as they discuss tech sovereignty. Could Gmail, cloud services, and critical infrastructure

  23. AI was not plotting humanity’s demise. Humans were

    Feb 12, 202640m#454

    AI bots are having existential crises, inventing religions, and allegedly plotting against humanity... or so the internet would have you believe. We dig into Moltbook, the “AI-only” social network that sent Twitter into

  24. The Epstein Files didn’t hide this hacker very well

    Feb 5, 202636m#453

    Supposedly redacted Jeffrey Epstein files can still reveal exactly who they’re talking about - especially when AI, LinkedIn, and a few biographical breadcrumbs do the heavy lifting. Sloppy redaction leads to explosive cl

  25. The dark web's worst assassins, and Pegasus in the dock

    Jan 29, 202645m#452

    In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into