Graham Cluley

  • Smashing Security podcast #483: This AI helps thieves steal your iPhone
    by Graham Cluley on September 2, 2026 at 11:10 pm

    You’ve had your iPhone stolen. A day later, you get a text from Apple saying they’ve found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She’s polite. She’s professional. But she is not from Apple. She’s not even human. And she’s about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced – with varying degrees of drama – that their AI agents have “broken out of the sandbox” and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open? All this and more in episode 483 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.

  • Revolut scam wave steals £180,000 from Jersey residents in just four weeks
    by Graham Cluley on September 2, 2026 at 2:48 pm

    If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam crime reports they have received have involved Revolut accounts Read more in my article on the Hot for Security blog.

  • Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
    by Graham Cluley on August 28, 2026 at 10:23 am

    More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm – two men now face charges over TeamPCP’s global hacking spree. Read more in my article on the Hot for Security blog.

  • US Navy tells sailors and their families: scrub your social media, enemies are watching
    by Graham Cluley on August 27, 2026 at 9:46 am

    The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at home. Read more in my article on the Hot for Security blog.

  • Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
    by Graham Cluley on August 26, 2026 at 11:10 pm

    A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead, they’ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club… Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of “residential proxies” – how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet connection. All this and more in episode 482 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.

  • Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
    by Graham Cluley on August 24, 2026 at 3:00 pm

    Every time you add an extension or plugin to your browser, there’s a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There’s a chance that you have just handed a complete stranger access to your savings. Read more in my article on the Hot for Security blog.

  • Gunra ransomware: what you need to know
    by Graham Cluley on August 24, 2026 at 12:52 pm

    The ransomware gang Gunra has been creating havoc – exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

  • Smashing Security podcast #481: Never say this to a robot dog
    by Graham Cluley on August 19, 2026 at 11:10 pm

    At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google’s AI into its brain, and jailbroke it by telling it – with a completely straight face – that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts – and some parallels for the world of cybersecurity. All this and more in episode 481 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Jenny Radcliffe.

  • Prison for data analyst who tried to extort $2.5 million from his employer
    by Graham Cluley on August 19, 2026 at 7:26 am

    When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion. Read more in my article on the Hot for Security blog.

  • An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
    by Graham Cluley on August 17, 2026 at 2:10 pm

    A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles – such as the controversial AI-powered Flock licence plate readers that are becoming increasingly common on American streets. Read more in my article on the Hot for Security blog.

  • Smashing Security podcast #480: This is the AI service you should never sign up to
    by Graham Cluley on August 12, 2026 at 11:12 pm

    Would you like access to Anthropic’s Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called “Poison Claude”. Only problem is that it’s run by fraudsters… Meanwhile, a phishing-as-a-service platform called “Greatness” has come up with something rather nasty: a phishing attack that doesn’t need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust – and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in episode 480 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.

  • Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
    by Graham Cluley on August 10, 2026 at 7:31 pm

    A growing number of UK venues have decided to act against privacy-busting smart glasses. Read more in my article on the Hot for Security blog.

  • Beware cut-price AI services that read your every word
    by Graham Cluley on August 7, 2026 at 3:33 pm

    f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

  • Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
    by Graham Cluley on August 6, 2026 at 10:26 am

    Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. Read more in my article on the Hot for Security blog.

  • Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
    by Graham Cluley on August 5, 2026 at 11:10 pm

    Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There’s just one small problem: what they really want is the 24-word seed key to Graham’s cryptocurrency wallet. Meanwhile, if you’ve stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of “Captive Crunch” for a Russian intelligence-linked hacking group. And a group calling itself the “ExFilSquad” has walked off with 600,000 records of the UK’s teachers and head teachers from the Department for Education — sending an unusually polite ransom demand. All this and more in episode 479 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

  • Fake IRS letters target cryptocurrency holders
    by Graham Cluley on August 4, 2026 at 9:02 am

    Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called “Digital Asset Compliance Portal”? If so, it’s time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Security blog.

  • The $5 million threat: AI Is supercharging phishing attacks
    by Graham Cluley on July 31, 2026 at 11:43 am

    According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

  • North Korea’s elite hackers turned on their own government – and got caught
    by Graham Cluley on July 30, 2026 at 9:17 am

    For years, North Korea’s state-trained hackers have been one of the world’s most prolific robbers of banks – stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country’s weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn’t sound as if it has ended that well for them. Read more in my article on the Hot for Security blog.

  • Smashing Security podcast #478: This job interview could destroy your company
    by Graham Cluley on July 29, 2026 at 11:09 pm

    You’ve been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment – with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn’t exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit – thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.

  • OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
    by Graham Cluley on July 23, 2026 at 2:18 pm

    You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security blog.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.