Sophos
Naked Security
We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you! Got questions/suggestions/stories to share? Email: tips@sophos.comTwitter: @NakedSecurityInstagram: @NakedSecurity
Author
Sophos
Category
Podcast website
Latest episode
Aug 24, 2023
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
S3 Ep33: Eufy camera leak, Afterburner crisis, and AirTags (again) 19.05.2021 38:46
We look into an unnerving case of mixed-up video feeds. We warn you against "going rogue" when you can't get the download you want from the regular place. We explain how Apple's new AirTag product got hacked (again). With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep32: AirTag jailbreak, Dell vulns, and the never-ending scam 12.05.2021 38:33
Apple's brand new AirTag product got hacked already. Things you can learn from Colonial Pipeline's ransomware misfortune . Why Dell patched a bunch of driver bugs going back more than a decade. And the "Is it you in the video?" scam just keeps on coming back . Additional links you will find useful: https://news.sophos.com/en-us/using-sophos-edr-to-identify-endpoints-impacted-by-dell https://nakeds...
S3 Ep31: Apple zero-days, Flubot scammers and PHP supply chain bug 05.05.2021 38:42
We look into Apple's recent emergency updates that closed off four in-the-wild browser bugs. We explain how the infamous "Flubot" home delivery scam works and how to stop it . We investigate a recent security bug that threatened the PHP ecosystem . With Kimberly Truong, Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twi...
S3 Ep30: AirDrop worries, Linux pests and ransomware truths 29.04.2021 47:39
We investigate whether AirDrop is really as dangerous as researchers claimed. We discuss the pestiferous problem of fake Linux bugs submitted as an academic exercise. We review the latest Sophos Ransomware Report and uncover uncomfortable truths about paying up. With Kimberly Truong, Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@...
S3 Ep29: Anti-tracking, rowhammer problems and IoT vulns 21.04.2021 48:44
How Firefox showed the hand to a widely abused online tracking trick. Why reading from one part of your computer's memory can paradoxically (and sneakily) let you write to another part . And yet more IoT bugs, this time a whole slew of them that go by the moniker "name:wreck". With Kimberly Truong, Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to sha...
S3 Ep28.5: Hacking back - is attack an acceptable form of defence? 16.04.2021 19:55
Sophos cybersecurity expert Chester Wisniewski provides excellent, topical and timely commentary on the FBI’s recent use of a malware-like method to forcibly clean up hundreds of servers still infected in the Hafnium aftermath . With Paul Ducklin and Chester Wisniewski Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @...
S3 Ep28: Pwn2Own hacks, dark web hitmen and COVID-19 privacy 14.04.2021 48:00
We look at the big-money hacks from the 2021 Pwn2Own competition. We investigate the difficulties of hiring an assassin via the dark web. We wrestle with some of the privacy issues relating to COVID-19 infection tracking apps . With Kimberly Truong, Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity I...
S3 Ep27: Census scammers, beg bounties and data breach fines 07.04.2021 46:09
How scammers copied a government website almost to perfection . What to do about those fake "bug" hunters who ask for payment for finding "vulnerabilities" that aren't . Why the Dutch data protection authority fined Booking.com for not sending in a data breach disclosure fast enough . Useful podcasts and videos mentioned in this episode: https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-...
S3 Ep26: Apple 0-day, crypto vulnerabilities and PHP backdoor 01.04.2021 37:37
Why Apple had to rush out a security update for iDevices. Two cryptographic security holes patched in OpenSSL. How PHP nearly got backdoored by crooks. With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep25: Drained accounts, ransomware attacks and Linux badware 25.03.2021 47:00
How a social engineer ripped off a victim lured in by one of those "small outstanding fee to pay" home delivery scams. The ransomware crooks targeting networks that still haven’t done their Hafnium patches. And the Linux kernel security holes that lay there undiscovered for 15 years. Related articles that we refer to in the show: https://nakedsecurity.sophos.com/beware-the-dhl-delivery-message htt...
S3 Ep24: How not to get snooped, scammed or hoaxed 17.03.2021 47:26
We discuss an iPhone app that allowed anyone to snoop on anyone's calls - but not in the way you might expect. We investigate a data breach where 150,000 surveillance cameras protecting hundreds or thousands of customers were apparently "secured" by a single password ... that got leaked onto the internet. And we urge you as keenly as we can: " Don't spread hoaxes , folkses." With Kimberly Truong,...
S3 Ep23.5: An interview with cybersecurity expert John Noble CBE 15.03.2021 29:39
John Noble was Director of Incident Management at the UK's National Cyber Security Centre (NCSC) until his retirement in 2018. During his 40 years of Government service, John specialised in operational delivery and strategic business change. For his work in creating effective partnerships in the run up to the London Olympics, he was made a Commander of the British Empire (CBE) in 2012. John helped...
S3 Ep23: Hafnium happenings, I see you, and Pythonic poison 10.03.2021 32:47
Getting to grips with the HAFNIUM gang/vulnerabilities/exploits/webshells/attacks. Why it's important to think before you share those home-based selfies. What you need to know about social engineering. How (not!) to prove a point when you're a programmer. With Kimberly Truong and Paul Ducklin Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @N...
S3 Ep22: Cryptographic escapes and social media scams 04.03.2021 38:05
How to stop security-conscious apps from allowing unencrypted data to escape , and how scammers put social network users under pressure in order to steal their passwords . With Doug Aamoth and Paul Ducklin Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep21: Cryptomining clampdown, the 100-ton man, and ScamClub ads 25.02.2021 45:40
The graphics card that wants you to stick to playing games , the man that didn't weigh 100 tons after all, and the marketing gang that used a browser bug to bombard iPhone users with scammy online surveys. With Kimberly Truong, Doug Aamoth and Paul Ducklin Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep20: Corporate megahacking, true love gone bad, and tax grabs 17.02.2021 53:09
How a bug hunter snuck into the internal networks of 35 megacorporations . Why romance scams are going stronger than ever (and how to avoid them). What to do about those tempting but treacherous "tax refund" messages . And a listener tells us how he got a bit carried away while he was gardening... With Kimberly Truong, Doug Aamoth and Paul Ducklin Original music by Edith Mudge Got questions/sugges...
S3 Ep19.5: How NOT to be a bug bounty hunter 12.02.2021 16:28
In this special mini-episode, Paul Ducklin talks to Sophos cybersecurity expert Chester Wisniewski about bug bounty hunting. How does bug bounty hunting work? What should you do if you get a bug report that doesn't follow established protocol? Chester tells you how to deal with so-called "beg bounties", where self-styled "experts" beg you for money or even threaten you with ill-defined "problems"...
S3 Ep19: Chrome zero-day, coffee hacking and Perl.com stolen 11.02.2021 47:55
We delve into Google's tight-lipped Chrome bugfix , explain how a Belgian researcher awarded himself 111,848 cups of coffee , and discuss the audacious but thankfully temporary theft of the Perl.com domain. With Kimberly Truong, Doug Aamoth and Paul Ducklin Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurit...
S3 Ep18: Apple emergency, crypto blunder and botnet takedown 04.02.2021 43:24
Apple pushed out an iOS update in a hurry to shut down a serious 0-day bug . The GnuPG team scrambled to fix an ironic vulnerability that could be exploited during the very process of checking if the data you just received could be trusted. And Europol reported on a successful takedown operation against the notorious Emotet malware . With Kimberly Truong, Doug Aamoth and Paul Ducklin Original musi...
S3 Ep17: Facemasks, hidden ads and paranormal hacking 28.01.2021 47:30
What's the connection between coronavirus facemasks and fingerprint biometrics ? Who would have expected funky job ads on the White House website? And what would you do if you ran into a deceased former colleague on your network? With Kimberly Truong, Doug Aamoth and Paul Ducklin Original music by Edith Mudge *** Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecur...
S3 Ep16: Darkweb bust, security at home, and browser snoopage 20.01.2021 45:30
Anonymous and private, yet busted! We explain how darkweb sites sometimes keep your secrets ... and sometimes don't. We help you improve your cybersecurity at home . And we tell you the tale of a company with the coolest name but allegedly with the creepiest habits coded into its browser extensions. With Kimberly Truong, Doug Aamoth and Paul Ducklin Original music by Edith Mudge *** Got questions/...
S3 Ep15.5: Home schooling - how to stay secure 19.01.2021 19:07
Thanks to coronavirus lockdown rules in the UK, and the temporary closure of all schools, Sally Adam suddenly found herself responsible for cybersecurity where it mattered more than ever: on a home network that jointly served for home, work and school. Paul Ducklin talks to Sally about how she did it, and how to keep your own family’s digital life safe. https://nakedsecurity.sophos.com/home-school...
S3 Ep15: Titan keys, Mimecast certs and Solarwinds 14.01.2021 49:41
We explain how two French researchers hacked a Google Titan security key (but why you don't need to panic), and dig into the Mimecast certificate compromise story to see what we can all learn from it. With Kimberly Truong, Doug Aamoth and Paul Ducklin Original music by Edith Mudge *** Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep14: Money scams, HTTPS by default, and hardcoded passwords 07.01.2021 46:39
We advise you how to react when a friend suddenly asks for money, explain why Chromium is finally aiming for HTTPS by default , and warn you why you should never, ever hardcode passwords into your software. With Kimberly Truong, Doug Aamoth and Paul Ducklin. Original music by Edith Mudge *** Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSe...
S3 Ep13: A chat with hacker Keren Elazari 31.12.2020 47:49
How did the movie "Hackers" inspire a girl to grow up to become a hacker herself? Find out from security analyst, friendly hacker and TED Talk speaker Keren Elazari. Hear about Keren’s incredible journey, why hackers should be welcomed with open arms, and the inspiration that guided her career. With Kimberly Truong and special guest Keren Elazari ( @k3r3n3 on Twitter), cybersecurity analyst and re...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.