Graham Cluely Security Blog

Subscribe to Graham Cluely Security Blog feed Graham Cluely Security Blog
Cybersecurity keynote speaker
Updated: 45 min 59 sec ago

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

5 hours 44 min ago
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access to your savings. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Gunra ransomware: what you need to know

7 hours 51 min ago
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.
Categories: Graham Cluely

Smashing Security podcast #481: Never say this to a robot dog

Wed, 08/19/2026 - 7:10pm
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of cybersecurity. All this and more in episode 481 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Jenny Radcliffe.
Categories: Graham Cluely

Prison for data analyst who tried to extort $2.5 million from his employer

Wed, 08/19/2026 - 3:26am
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

Mon, 08/17/2026 - 10:10am
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming increasingly common on American streets. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #480: This is the AI service you should never sign up to

Wed, 08/12/2026 - 7:12pm
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in episode 480 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.
Categories: Graham Cluely

Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres

Mon, 08/10/2026 - 3:31pm
A growing number of UK venues have decided to act against privacy-busting smart glasses. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Beware cut-price AI services that read your every word

Fri, 08/07/2026 - 11:33am
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.
Categories: Graham Cluely

Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

Thu, 08/06/2026 - 6:26am
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

Wed, 08/05/2026 - 7:10pm
Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education — sending an unusually polite ransom demand. All this and more in episode 479 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.
Categories: Graham Cluely

Fake IRS letters target cryptocurrency holders

Tue, 08/04/2026 - 5:02am
Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

The $5 million threat: AI Is supercharging phishing attacks

Fri, 07/31/2026 - 7:43am
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.
Categories: Graham Cluely

North Korea’s elite hackers turned on their own government – and got caught

Thu, 07/30/2026 - 5:17am
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #478: This job interview could destroy your company

Wed, 07/29/2026 - 7:09pm
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.
Categories: Graham Cluely