Graham Cluely

The $5 million threat: AI Is supercharging phishing attacks

Graham Cluely Security Blog - Fri, 07/31/2026 - 7:43am
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.
Categories: Graham Cluely

North Korea’s elite hackers turned on their own government – and got caught

Graham Cluely Security Blog - Thu, 07/30/2026 - 5:17am
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #478: This job interview could destroy your company

Graham Cluely Security Blog - Wed, 07/29/2026 - 7:09pm
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.
Categories: Graham Cluely

OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

Graham Cluely Security Blog - Thu, 07/23/2026 - 10:18am
You can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

Graham Cluely Security Blog - Wed, 07/22/2026 - 7:10pm
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.
Categories: Graham Cluely

Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Graham Cluely Security Blog - Tue, 07/21/2026 - 5:51am
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Google’s Gemini lets strangers send messages from your locked Android phone

Graham Cluely Security Blog - Fri, 07/17/2026 - 6:30pm
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Anubis ransomware: what you need to know

Graham Cluely Security Blog - Thu, 07/16/2026 - 5:05pm
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.
Categories: Graham Cluely

Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

Graham Cluely Security Blog - Thu, 07/16/2026 - 5:02am
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.
Categories: Graham Cluely

The ransomware negotiator who was working for the other side

Graham Cluely Security Blog - Tue, 07/14/2026 - 3:54am
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't expect is that their trusted negotiator might be separately sharing details of the victim's cyber-insurance policy and negotiation strategy directly with the attackers themselves. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Graham Cluely Security Blog - Thu, 07/09/2026 - 9:17am
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

Graham Cluely Security Blog - Wed, 07/08/2026 - 7:19pm
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity? Also, Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year. All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Zoë Rose.
Categories: Graham Cluely

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Graham Cluely Security Blog - Tue, 07/07/2026 - 8:56am
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely