Naked Security - podcast cover

Naked Security

We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you! Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity Instagram: @NakedSecurity
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs

Understanding Log4Shell. Fixing Log4Shell. What criminals are up to with Log4Shell. Apple's latest security fixes. And what (not to) do when your mouse gets stuck. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Dec 16, 202128 minSeason 3Ep. 63

S3 Ep62: The S in IoT stands for security (and much more)

Mozilla's "BigSig" buffer overflow hole. UK to put IoT vendors on notice. The Mother of All Demos. Cryptocurrency company catastrophe . Firefox gets an extra sandbox . And an access point from outer space (OK, from home). Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Dec 09, 202127 minSeason 3Ep. 62

S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness

Call scammers and cryptocoin treachery. Cloud insecurity and yet more cryptocoin treachery . Facial recognition creepiness . And the wannabe wizard that went to school with a trainee Sith. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Dec 02, 202129 minSeason 3Ep. 61

S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public

Cybersecurity tips for the holiday season and beyond . Exchange at risk from public exploit . GoDaddy loses passwords for 1.2m users. Longest-lived Windows version ever. Don't make your cookies public . And the day that umbrellas became an anti-DDoS tool. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Nov 25, 202131 minSeason 3Ep. 60

S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase

The infamous Emotet malware makes a comeback. Crooks smirk at the world with a fake FBI warning. Why tubes are also valves. Samba fixes an intriguing bug . The suitcase that needs no handle . And a virtual-versus-real monitor mixup. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Nov 18, 202134 minSeason 3Ep. 59

S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust

We enjoy the Sophos 2022 Threat Report . The world's {oldest, coolest} continously maintained browser. Facebook folds up its Face Recognition feature. Crooks combine a new social engineering scam with a new way of packaging malware. Kaseya ransomware suspect busted in Poland. Oh! No! How to block radio communications in a land with no hills . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Nov 11, 202132 minSeason 3Ep. 58

S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars

Norbert (huzzah for Norbert!) does tech support. Europol digs into the ransomware scene. Microsoft finds a wacky bug in Apple's shell. The Morris worm turns 33. Edge on Linux phans the phlames . Ola! Gibberish peculiarity textual solvage. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Nov 04, 202129 minSeason 3Ep. 57

S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish

Bliss is a hill in wine country. Lessons from a cryptotrading hamster . Ransomware gang hacked back . Docusign phishers go after 2FA codes . Sleep mode considered harmful. Original music by Edith Mudge Got something to share? Email tips@sophos.com...

Oct 28, 202134 minSeason 3Ep. 56

S3 Ep55.8: Purple teaming - learning to think like your adversaries

Special minisode! Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company. Learn why thinking like an attacker makes you a better defender. Full transcript: https://nakedsecurity.sophos.com/listen-up-4-cybersecurity-first-purple-teaming

Oct 25, 202125 minSeason 3Ep. 55

S3 Ep55.6: Cyberinsurance - help or hindrance?

Special minisode! Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance. Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-cyberinsurance

Oct 25, 202127 minSeason 3Ep. 55

S3 Ep55.4: Supply chain attacks and how to avoid them

Special minisode! Chester Wisniewski, Principal Research Scientist at Sophos, gives you useful and actionable advice to reduce the risk of supply chain attacks. Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-supply-chain-attacks

Oct 25, 202127 minSeason 3Ep. 55

S3 Ep55.2: Malware - the never-ending story

Special Minisode for #Cybermonth! Fraser Howard, Director of Threat Research at Sophos, talks about malware and how to fight it. Fraser's breadth and depth of knowledge in the threat-fighting field is second to none. Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-week4

Oct 25, 202128 minSeason 3Ep. 55

S3 Ep55: Live malware, global encryption, dating scams, and secret emanations

Hook up with our forthcoming Live Malware Demo presentation. Why we think you should celebrate Global Encryption Day. A whole new twist on bogus online "friendships". How to stop your network cables giving you away. And why superglue is NOT a cybersecurity tool! Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Oct 21, 202138 minSeason 3Ep. 55

S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish

Apple (you guessed it!) fixes yet another iPhone 0-day . Apache patches an embarrassing bug and then has to patch the patch . It's Fight The Phish week. The user who got punched right in the nose by a recalcitrant computer. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Oct 14, 202132 minSeason 3Ep. 54

S3 Ep53: Apple Pay, giftcards, cybermonth, and ransomware busts

Apple Pay gets hacked (sort of). DOJ busts four gift card scamming suspects . We give you our top tips for #Cybermonth . Ukrainian Cyberpolice take on ransomware crooks . Oh! No! The user that volunteered to RTFM!? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Oct 07, 202135 minSeason 3Ep. 53

S3 Ep52: Let's Encrypt, Outlook leak, and VMware exploit

Let's Encrypt brings HTTPS to everyone . Researchers rediscover an Outlook data leakage issue . VMware keeps it real . And when the mouse is away, the cat will play. With Paul Ducklin and Doug Aamoth. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 30, 202133 minSeason 3Ep. 52

S3 Ep51: OMIGOD a gaping hole, waybill scams, and Face ID hacked

A scarily exploitable hole in Microsoft open source code. A simpler take on delivery scams. A Face ID bypass hack, patched for the initial release of iOS 15. And how not to get locked in a cabling closet. Coder? Use Sophos Intelix yourself for free: https://sophos.com/intelix With Paul Ducklin and Doug Aamoth. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 22, 202139 minSeason 3Ep. 51

S3 Ep50: Two 0-days plus another 0-day plus a fast food bug

Apple patches two zero-day bugs . Microsoft patches one zero-day bug . A security researcher finds a fast-food bug (non-insect sort). And a touchpad user turns right into left, and vice versa. (See also: Big Office bug squashed for September 2021 Patch Tuesday ) With Paul Ducklin and Doug Aamoth. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 15, 202128 minSeason 3Ep. 50

S3 Ep49: Poison PACs, pointless alarms and phunky bugs

Overlooked security flaw leaves web code vulnerable . A home alarm system that almost anyone can turn off . Some fascinating Firefox bugs fixed. And when you grab your laptop... but it's not yours. With Paul Ducklin and Doug Aamoth. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 09, 202134 minSeason 3Ep. 49

S3 Ep48: Cryptographic bugs, cryptocurrency nightmares, and lots (and lots) of phishing

Security code flushes out security bugs. Recursion: see recursion . Phishing (and lots of it ). And the Windows desktop that got so big it imploded. With Paul Ducklin and Doug Aamoth. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 01, 202137 minSeason 3Ep. 48

S3 Ep47: Daylight robbery, spaghetti trouble, and mousetastic superpowers

More money troubles in cryptotown. Trouble with plastic spaghetti . The mouse that conquered Windows . And the embarrassment when you report one of your very own emails as a phish. With Paul Ducklin and Doug Aamoth. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 26, 202137 minSeason 3Ep. 47

S3 Ep46: Copyright scams, video snooping and Grand Theft Crypto

Copyright infringement scams that beg you to call . An IoT bug that could be exploited for video snooping and more. A hacker steals $600m and then makes a song and dance out of giving it back. And how Doug's PS5 issues could be solved at last. With Paul Ducklin and Chester Wisniewski. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 18, 202129 minSeason 3Ep. 46

S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed

Home and small business routers under attack . A hacking tool favoured by crooks gets hacked . The Navajo Nation's selfless cryptographic contribution to America. A cybercrook gets aggrieved at being ripped off by cybercrooks. With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 12, 202142 minSeason 3Ep. 45

S3 Ep44: Unreported holes, retro computing, and tech support for malware

The latent 0-day that didn't get reported until it was too late . Retro computing: reliving the TRS-80. Crooks that help you install their malware . And a 5-minute billionaire (who ended up with $400). With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 05, 202137 minSeason 3Ep. 44

S3 Ep43: Apple 0-day, pygmy hippos, hive nightmares and Twitter hacker bust

Apple's emergency 0-day fix. Two sorts of Windows nightmare , neither involving printers. Twitter hacker busted . And our very own Doug ruins a brand new TV. With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Jul 28, 202139 minSeason 3Ep. 43

S3 Ep42: Viruses, Nightmares, patches, rewards and scammers

Learning from computer virus history . The PrintNightmare saga continues. Apple puts out a patch, but doesn't say why . Snitch on a crook and earn $10 million . Scammers do grammar . And the Business Email Compromise that wasn't. With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Jul 22, 202128 minSeason 3Ep. 42

S3 Ep41: Crashing iPhones, PrintNightmares, and Code Red memories

We explain how a format string bug could lock your iPhone out of your own network. We revisit the PrintNightmare saga, which is sort-of fixed but not really. We look back at the 20-year-old Code Red virus. We look at what cybercriminals spend money on (hint: more cybercrime). And in this week's "Oh! No!", we learn how farm animals can disrupt your network. With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @N...

Jul 14, 202132 minSeason 3Ep. 41

S3 Ep40: Kaseya breach, PrintNightmare 0-day, and hacking versus the law

The "Independence Day Weekend" ransomware drama. The PrintNightmare nightmare continues . An email hacker gets his conviction overturned. In this week's Oh! No! story, a server room fills with toxic fumes... With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Jul 08, 202135 minSeason 3Ep. 40

S3 Ep39.5: A conversation with Eva Galperin

In this special splintersode, Kimberly Truong talks to Eva Galperin , Director of Security at the Electronic Frontier Foundation. Eva's TED talk mentioned in the podcast: What you need to know about Stalkerware . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Jul 05, 202140 minSeason 3Ep. 39

S3 Ep39: Paying the date, #SocialMediaDay tips, and a special splintersode

When you spend tens of pounds but get billed thousands because the system mistook the date for the amount. Our tips to make #SocialMediaDay your safest day on social media yet. And a clip from a great new privacy splintersode we'll be airing next week. With Kimberly Truong, Doug Aamoth and Paul Ducklin. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Jun 30, 202140 minSeason 3Ep. 39
For the best experience, listen in Metacast app for iOS or Android