Home Podcasts Smashing Security
Smashing Security

Smashing Security

Graham Cluley 471 Episodes Jul 22, 2026

Smashing Security is a weekly podcast that covers stories from the world of hacking, cybersecurity, and rogue AI. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it delivers tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps with sharp insight and humor. The podcast has won multiple awards for best cybersecurity podcast and has had over ten million downloads. New episodes are released every Wednesday.

Episodes

How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Jul 22, 2026 3035 A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets.Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models.All this and more in episo
Remote-control rickshaws and rogue book marketers
Remote-control rickshaws and rogue book marketers Jul 15, 2026 2291 An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them a
JadePuffer - the AI that ran a ransomware attack all by itself
JadePuffer - the AI that ran a ransomware attack all by itself Jul 8, 2026 2787 A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity?Also, Apple's "Hide My Email" feature turns out to hide rather less than it promi
Polymarket can predict the future. So how did it miss this hack?
Polymarket can predict the future. So how did it miss this hack? Jul 1, 2026 2578 Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer.Meanwhile, "FortiBleed" sees 75,000 Fortinet firewalls thrown wide open - and the real damage is going to roll on for years.All this and more in episode 474
How a hacker could have Rickrolled the entire World Cup
How a hacker could have Rickrolled the entire World Cup Jun 24, 2026 3657 A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards, supermarkets, and TikTok, with a two-week ultimatum to turn themselves in... or else.Meanwhile, a security
AI gets hacked, and BitLocker gets bypassed
AI gets hacked, and BitLocker gets bypassed Jun 17, 2026 4363 What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told.Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of wh
This AI worm just rewrote its own rules
This AI worm just rewrote its own rules Jun 10, 2026 2787 Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack.Meanwhile, Meta's shiny new AI cu
This AI security flaw might be impossible to fix
This AI security flaw might be impossible to fix Jun 3, 2026 3470 A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who responded.Meanwhile, a paper from Cornell suggests that prompt injection - the technique malicious actors use to t
What your Oura ring won't tell you
What your Oura ring won't tell you May 27, 2026 3186 CISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile.Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted - and when one journalist asked the company how often it hands user data to law enforcement, the answer was quite te
High-speed train hacks and homicidal lawnmowers
High-speed train hacks and homicidal lawnmowers May 20, 2026 3357 A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year.Meanwhile, owners of $4,000 robot lawnmowers are discovering that their gadget can be hijacked over the internet, redirected at journalists who foolishly lie down in f
How ShinyHunters hacked the world's biggest universities
How ShinyHunters hacked the world's biggest universities May 13, 2026 3854 Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap.Meanwhile, a famous finance expert's face
Meta sees everything, Copy Fail, and a deepfake gets hired
Meta sees everything, Copy Fail, and a deepfake gets hired May 6, 2026 3762 Meta's smart glasses promise privacy "designed for you" - but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them.Meanwhile, the IT press is in a frenzy over a new Linux bug called "Copy Fail" - complete with logo, dedicated website, and a marketing-friendly name. But is it really

Recommended