Sophos
Naked Security
We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you! Got questions/suggestions/stories to share? Email: tips@sophos.comTwitter: @NakedSecurityInstagram: @NakedSecurity
Author
Sophos
Category
Podcast website
Latest episode
Aug 24, 2023
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
S3 Ep12: A chat with social engineering hacker Rachel Tobac 24.12.2020 28:05
How do you go from neuroscientist to DEFCON Social Engineering Capture the Flag champ? Find out from hacker and social engineering expert Rachel Tobac. Join us for a fascinating interview with Rachel about her journey, why you should always be “politely paranoid”, and the people who inspired her along the way. With Kimberly Truong and special guest Rachel Tobac ( @RachelTobac on Twitter), hacker a...
S3 Ep11: DIY phishes, sandwich scams and vaccine hacking 17.12.2020 44:59
We look at phishing tricks that really work, investigate a bizarre scam involving Subway sandwiches, and ask whether cybercriminals have lost their interest in the rest of us now they have coronavirus-related targets to go after. With Kimberly Truong, Doug Aamoth and Paul Ducklin. https://nakedsecurity.sophos.com/phishing-tricks-that-really-work https://nakedsecurity.sophos.com/subway-sandwich-sca...
S3 Ep10.5: 20 years of cyberthreats that shaped infosec 14.12.2020 21:24
Naked Security's Paul Ducklin interviews Sophos expert John Shier about his recently published paper, "20 years of cyberthreats that shaped information security." Join John on a dizzying journey all the way from legendary viruses such as ILOVEYOU and Code Red, which flooded the internet in 2000, to present-day ransomware gangs like Ryuk and REvil, who are extorting millions of dollars in blackmail...
S3 Ep10: Hacking iPhones, sunken Enigmas and double scams 10.12.2020 46:45
We dig into research that figured out a way to steal data from iPhones wirelessly, we tell the fascinating story of how environmentalist divers in Germany came across an old Enigma cipher machine at the bottom of the Baltic sea, and we give you advice on how to talk to phone scammers. With Kimberly Truong, Doug Aamoth and Paul Ducklin. https://nakedsecurity.sophos.com/how-to-steal-photos-off-someo...
S3 Ep9: Gift card hacks, dubious doorbells and Wi-Fi tips 03.12.2020 48:56
We look at a network intrusion where the crooks tried to take over dozens of different online accounts from every user, we discuss the potential dangers of digital doorbells, and we give you some handy hints for improving your wireless security at home. With Kimberly Truong, Doug Aamoth and Paul Ducklin. https://nakedsecurity.sophos.com/gift-card-hack-exposed-you-pay-they-play https://nakedsecurit...
S3 Ep8: A conversation with Katie Moussouris 25.11.2020 44:44
How do you go from pentester to creator of Microsoft’s bug bounty program? Find out from hacker and vulnerability disclosure pioneer, Katie Moussouris. Join us for a fascinating interview with Katie about her journey, the bugs in bug bounty programs, and the people who inspired her along the way. With Kimberly Truong and special guest Katie Moussouris ( @k8em0 on Twitter), Founder and CEO of Luta...
S3 Ep7: When ransomware crooks get a big fat zero! 19.11.2020 43:13
In this episode: we say thanks to companies that refuse to pay ransomware hush money, dig into the new Sophos 2021 Threat Report, and take a quick look inside a malicious Linux kernel driver. Also, a sneak preview of our upcoming podcast interview with bug bounty pioneer Katie Moussouris. With Kimberly Truong, Doug Aamoth and Paul Ducklin *** Cult videogame company Capcom pays a big round $0.00 to...
S3 Ep6: How not to get scammed 12.11.2020 47:30
In this episode: When payments go astray, why "just in case" cybersecurity warnings do more harm than good, how to shop safely on Black Friday and beyond, and (oh no!) what to do when all your emails disappear. With Kimberly Truong, Doug Aamoth and Paul Ducklin *** To register for the Sophos Evolve event: https://sophos.com/evolve Smishing attack tells you “mobile payment problem” – don’t fall for...
S3 Ep5: Chrome, Flash and malware for sale 05.11.2020 39:54
In this episode: a zero-day bug in Chrome for Android, the imminent death of Adobe Flash, the evolution of "malware-as-a-service", and the malware risks from image search. Also (oh! no!), why you should take care before you pair. With Kimberly Truong, Doug Aamoth and Paul Ducklin https://nakedsecurity.sophos.com/another-chrome-zero-day-this-time-on-android https://nakedsecurity.sophos.com/adobe-fl...
S3 Ep4.5: FBI "ransomware warning" for healthcare is a warning for everyone 30.10.2020 13:55
On Wednesday, the FBI, CISA and HHS released an unprecedented warning against "an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers." In this quick mini-sode, Chester Wisniewski (Principal Research Scientist at Sophos) discusses what the threat is, what this advisory means, and why this warning is a warning for everyone. With Kimberly Truong and special gues...
S3 Ep4: Facebook scams, vishing, and smartphone privacy tips 30.10.2020 46:09
This week: Facebook scammers trick you with fake copyright notices, voice scammers automate their attacks on the vulnerable, how to tune up your mobile privacy, and (oh! no!) the best/worst IT helpdesk call ever. With Kimberly Truong, Doug Aamoth and Paul Ducklin *** Facebook “copyright violation” tries to get past 2FA – don’t fall for it https://nakedsecurity.sophos.com/facebook-copyright-violati...
S3 Ep3: Breaking crypto, busting hackers and pwning Chrome 22.10.2020 36:40
This week: the DOJ's attempt to reignite the Battle to Break Encryption; the story of the Russian hackers behind the Sandworm Team; a zero-day bug just patched in Chrome; and (oh no!) why your vocabulary needs the word "restore" even more than it needs "backup". With Kimberly Truong, Doug Aamoth and Paul Ducklin *** US Department of Justice reignites the Battle to Break Encryption https://nakedsec...
S3 Ep2: Creepy smartwatches, botnets and Pings of Death 15.10.2020 38:50
In this episode: we investigate a smartwatch for kids with a creepy set of functions, discuss Microsoft's short-lived takedown of Trickbot, explain how to avoid the Windows "Ping of Death" bug, and (oh no!) find the source of mysterious beeping from every computer in the office. With Kimberly Truong, Doug Aamoth and Paul Ducklin *** Creepy covert camera “feature” found in popular smartwatch for ki...
S3 Ep1: Ransomware - is it really OK to pay? 09.10.2020 42:46
Join us for the first episode in our brand new Series 3! This week we wonder whether Cybersecurity Awareness Month is a waste of time, explain the concept of "linkless phishing", ask if it's ever OK to pay a ransomware demand, and advise what to do when the CEO won't stop looking at naughty sites. With Paul Ducklin, Kimberly Truong and Doug Aamoth Tips for National Cybersecurity Awareness Month ht...
S3 Trailer: We're back! 05.10.2020 0:52
Get ready. A brand new season arrives Thursday, October 8th.
S2 Ep42: Apple auth attack, Octopus Scanner, Escobar escapades 05.06.2020 45:53
END OF SERIES SPECIAL: This week Mark shares why Pablo Escobar’s brother is suing Apple for $2.6b, Greg talks about a malicious ‘Octopus Scanner’ targeting developers on Github and Duck discusses the “Sign in with Apple” account takeover flaw. Host Anna Brading is joined by Sophos experts Paul Ducklin, Mark Stockley and Greg Iddon. Related articles: Github uncovers malicious ‘Octopus Scanner’ targ...
S2 Ep41: Super-sized ransomware, FBI v Apple and AirPods hot or not 27.05.2020 50:57
This week Peter shares how Ragnar Locker ransomware deploys a virtual machine to dodge security, Mark discusses the latest in the Apple v FBI saga and Duck talks "MagicPairing." Producer Alice Duckett is joined by Sophos experts Mark Stockley, Paul Ducklin and Peter Mackenzie. Listen now! Related articles: Signal secure messaging can now identify you without a phone number https://nakedsecurity.so...
S2 Ep40: Demonic printers, a sleazy stalker and 10 reasons to patch 20.05.2020 52:57
This week we discuss a customer who went to Subway for a sandwich and left with a stalker, demon printers and the things you should patch now. Producer Alice Duckett is joined by Sophos experts Mark Stockley, Paul Ducklin and Greg Iddon. Related articles: Beware the DHL delivery message email – it could be a package scam https://nakedsecurity.sophos.com/2020/05/13/beware-the-dhl-delivery-message-e...
S2 Ep39: Thunderspy, government encryption, and reply all mistakes 13.05.2020 51:44
In this episode Mark discusses government encryption, Duck tells us why turning your computer off is a cool idea and Greg regales us with his reply all woes. Host Anna Brading is joined by Sophos experts Mark Stockley, Paul Ducklin, Greg Iddon and Producer Alice Duckett. Related articles: Clearview AI won’t sell vast faceprint collection to private companies https://nakedsecurity.sophos.com/2020/0...
S2 Ep38: Crashing iPhones, ransomware tales and human chatbots 06.05.2020 48:18
In this episode Duck discusses the iPhone "word of death", Peter shares a shocking ransomware story and Alice talks about a chatbot that shows empathy. Or so it says. Host Anna Brading is joined by Naked Security regular Paul Ducklin, Threat Response expert Peter Mackenzie and Producer Alice Duckett. Related articles: https://nakedsecurity.sophos.com/godaddy-unauthorized-individual-had-access-to-l...
S2 Ep37: Microsoft fixes, airgap fun and free games for 2FA 30.04.2020 39:50
This week we talk ransomware apologies, whether companies should be pushing 2FA and good vibrations, kind of... We're proud to be nominated for Best Cybersecurity Podcast in the European Cybersecurity Blogger Awards. If you enjoy our show, please vote for us: https://docs.google.com/forms/d/e/1FAIpQLSe8AkYMfAAwJ4JZzYRm8GfsJCDON8q83C9_wu5u10sNAt_CcA/viewform?fbzx=1378805297375984251 Host Anna Bradi...
S2 Ep36: Rogue Chrome extensions, Signal fears and Darth Vader 22.04.2020 42:31
This week we discuss 49 rogue Chrome extensions, Signal fears over the EARN IT Act and how Darth Vader sent someone viral for all the wrong reasons. Host Anna Brading is joined by Sophos experts Paul Ducklin, Mark Stockley and Producer Alice Duckett. Listen now! First three stories: https://nakedsecurity.sophos.com/critical-bug-in-google-chrome-get-your-update-now https://nakedsecurity.sophos.com/...
S2 Ep35: TikTok woes, sextortion scams and passwords vs. single sign-on 15.04.2020 44:19
This week we discuss a TikTok flaw, why sextortion scammers are rearing their heads again and whether single sign-on is better than having loads of different passwords. Host Anna Brading is joined by Sophos experts Mark Stockey, Paul Ducklin and Producer Alice Duckett. Listen now! Related articles: https://nakedsecurity.sophos.com/tiktok-users-beware-hackers-could-swap-your-videos-with-their-own h...
S2 Ep34: Can you trust hackers on how not to get hacked? 08.04.2020 50:17
This week we discuss the hackers' forum that got hacked (lol), how the coronavirus pandemic has deferred a security update, and why jumping to conclusions is always a bad idea. Oh, and we came across plans for a toilet that identifies you by scanning your, errrm... you'll have to listen to find out. Listen now! Related stories: https://nakedsecurity.sophos.com/hackers-forum-hacked-ogusers-database...
S2 Ep33: Ransomware on sale, dark web disaster, dead drops and pillow forts 01.04.2020 52:37
This week we bring you the podcast from our makeshift home studios (pillow forts). We discuss Dharma ransomware, the tour guide who turned out to be a Chinese spy, and why thousands of dark web sites have disappeared. Host Anna Brading is joined by Sophos experts Mark Stockley, Greg Iddon, Peter Mackenzie and Producer Alice Duckett. Listen now! Related articles: https://nakedsecurity.sophos.com/dh...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.