Sophos

Naked Security

We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you! Got questions/suggestions/stories to share? Email: tips@sophos.comTwitter: @NakedSecurityInstagram: @NakedSecurity

Author

Sophos

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

Aug 24, 2023

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

S3 Ep102: Cutting through cybersecurity news hype 29.09.2022

What's the real deal with LAPSUS$ ? How did Optus get hacked? Was there really a WhatsApp 0-day? What if "deleted" data comes back from the dead to haunt you? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity

S3 Ep101: Uber and LastPass - is 2FA all it's cracked up to be? 22.09.2022

Security SOS Week 2022 - check it out ! The very first Android. Firefox 105 is out. Uber hacked... by LAPSUS$ ? LastPass talks about its breach . Are two disks better than one? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep100.5: Uber breach - an expert speaks 17.09.2022

Chester Wisniewski explains what we can learn from Uber's latest cybsecurity crisis : "Just because a big company didn't have the security they should doesn't mean you can't." Original music by Edith Mudge

S3 Ep100: Browser-in-the-Browser hacking – how to spot an attack 14.09.2022

Second Cosmic Rocket (not a band!) Microsoft 0-day . Apple 0-days. Good logging habits. Browser-in-the-browser trickery. DEADBOLT ransomware. Again. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity

S3 Ep99: TikTok "attack" - was there a data breach, or not? 08.09.2022

The bug that was a moth. Was there really a TikTok breach? Peter Eckersley : Code In Peace. Chrome and Edge fix a zero-day . Apple updates iOS 12 for the first time in a year. App icons: the difference between sprockets and cogs. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep98: The LastPass saga - should we stop using password managers? 01.09.2022

The Computer Misuse Act, back in 1990. JavaScript supply-chain bug hunting. Jumping airgaps . "The Sanitizer" comes to Chrome . LastPass breach provokes password manager puzzlement . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep97: A musical crash, ATM skimming, and was your iPhone pwned? 25.08.2022

Start me up. The R&B dance classic that crashed computers. Bitcoin ATM skimming (no malware required). Multiple browser zero-days . Was your iPhone pwned ? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, heathcare security 18.08.2022

Chester attends DEF CON from afar. Zoom fixes an 0-day. An APIC leak that isn't EPIC. $10m for dobbing in Conti criminals. Cybersecurity in hospitals. Ransomware in triplicate . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto 10.08.2022

Memories of the Blaster worm. Slack leaked password hashes for FIVE YEARS. Github showered with malware. Traffic lights and cybersecurity. Post-quantum cryptography. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) 04.08.2022

Queen Victoria goes online. A nasty bug in Samba. Smiles for SysAdmins. A crypto-as-in-cryptography bug. A crypto-as-in-currency disaster. And is $200 million just chump change these days? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep93: Office security, data breach costs, and leisurely patches 28.07.2022

Geosynchronicity. Office security ( on-off-on ). A half-billion-dollar data breach cost . And patch that browser! Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep92: Log4Shell4Ever, summer tips, and scammer timing 21.07.2022

Integrated circuits and Nobel prizes. Log4Shell - forever? Cybersecurity tips for summmer . Scams and coincidence . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep91: Code Red, OpenSSL, Java bugs and Office macros 14.07.2022

Memories of the Code Red worm. OpenSSL fixes two tiny but troublesome bugs. More trouble in Java-land . Office macros off and back on again. Potential perils of paying ransomware demands. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass 07.07.2022

Chrome quashes another zero-day browser bug. Two big-time cybercrime stories . A 2FA phishing scam that arrived PDQ. Chester swarmed by bots on Twitter. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix 30.06.2022

Memories of the iPhone 1. Sextortion scams target LGBTQ+ daters . Yet another blockchain blunder . OpenSSL fixes the bug missed in the last bugfix. And what became of Little Bobby Tables ? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep88: Phone scammers, hacking bust, and data breach fines 23.06.2022

Duck gets behind the Ducks. 2000 phone scammers arrested in Interpol action. A three-year-old hacking case ends in conviction . And a Canadian financial company picks up an enormous data breach fine. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers 15.06.2022

Computer Science in the 1800s. Fixing Follina. AirTag stalking. ID theft site seizure . And the Law of Big Numbers versus SMS scams. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep86: The crooks were in our network for HOW long?! 08.06.2022

The dawn of the x86 era. The Active Adversary Playbook. A sort-of zero day in Windows. A real-life zero-day in Atlassian Confluence. And the registry settings that could keep you in your job. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep85: Now THAT'S what I call a Microsoft Office exploit! 02.06.2022

Why calling a computer after a famous scientist doesn't always help. The wacky but dangerous 0-day hole in Windows. Supply chain attacks and the crooks who orchestrate them. Smishing revisited. And why saying what you really mean makes you better at cybersecurity. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @Naked...

S3 Ep84: Government demand, Mozilla velocity, and Clearview fine 26.05.2022

How network comms caught a murderer back in in 1845. Why the US government said, "Patch, or else!" How Mozilla got a double code-execution bug fixed in 48 hours. And why controversial face-matching company Clearview AI got fined $10m. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns 18.05.2022

What does the word "non-commensurate" mean? When is cracking passwords legal? Why did Firefox get patched ? Which computer needed dropping onto the desk? Why wasn't this 0-day listed in every Apple update? Did Duck get spammed, or was it actually a troll? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) 11.05.2022

Where does the word "radio" come from? RubyGems supply chain rip-and-replace bug. A weird, weird, weird, weird, weird GoogleDocs bug. Colonial Pipeline back in the cybersecurity news. What about built-in password managers? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms 05.05.2022

World Password Day (we still need it), Github authentication tokens , Firefox hits a ton , and a look back at network worms. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java 27.04.2022

The biggest mountain in tne solar system. New ransomware statistics . Trouble with phishing . Bugs in NAS boxes . A giant security hole in Java. And how to get an industrial grade firewall at home for free . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

S3 Ep79: Chrome hole, a bad-choice holiday, and cryptododginess 20.04.2022

Adam Osborne or John Osbourne? Another 0-day in Chrome. How not to choose a cybersecurity holiday destination. The Osbo[u]rne Effect. Cryptododginess that might actually be legal. And the Zilog Z80 versus the Mostech 6502. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity

Listen to the Naked Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.