Naked Security - podcast cover

Naked Security

We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you! Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity Instagram: @NakedSecurity
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

S3 Ep120: When dud crypto simply won't let go

The mighty CPU that wasn't. Hive ransomware takedown. Dutch data crime suspect busted. Samba finally gets rid of MD5. GitHub admits to an intrusion. Storing passwords securely. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Feb 02, 202316 minSeason 3Ep. 120

S3 Ep119: Breaches, patches, leaks and tweaks!

The programming language almost called Oak. GoTo admits to more breach woes . T-Mobile spills 37 million records. Apple patches everything , even iOS 12. And Google mAkES tYpOs for sECurity.Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Jan 26, 202321 minSeason 3Ep. 119

S3 Ep118: Guess your password? No need if it's stolen already!

The HAPPY99 virus reminds us that less is more. Trouble with JSON Web Tokens . Investment scammers busted in Europe. The LifeLock "breach" that wasn't . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Jan 19, 202318 minSeason 3Ep. 118

S3 Ep117: The crypto crisis that wasn't (and farewell forever to Win 7)

Two stories from the underground. Bank scammers busted. The crypto-crack that wasn't. And the end of two Windows eras at the same time. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Jan 12, 202319 minSeason 3Ep. 117

S3 Ep116: Last straw for LastPass? Is crypto doomed?

The ground-breaking HP-35 digital calculator. Last straw for LastPass? Congress takes on quantum computing . 33 1/3-year-old cybersecurity lessons . Machine learning supply chain attack. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Jan 05, 202324 minSeason 3Ep. 116

S3 Ep115: True crime stories - A day in the life of a cybercrime fighter

Once more unto the breach, dear friends, once more! Paul Ducklin talks to Peter Mackenzie, Director of Incident Response at Sophos, in a cybersecurity session that will alarm, amuse and educate you, all in equal measure. Original music by Edith Mudge Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity

Dec 29, 202219 minSeason 3Ep. 115

S3 Ep114: Preventing cyberthreats - stop them before they stop you!

Join world-renowned Sophos expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode, recorded during our recent Security SOS Week 2022. When it comes to fighting cybercrime, Fraser truly is a "specialist in everything", and he also has the knack of explaining this tricky and treacherous subject in plain English. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Dec 22, 202223 minSeason 3Ep. 114

S3 Ep113: Pwning the Windows kernel: the crooks who hoodwinked Microsoft

The irony of the CAN-SPAM law. When genuine kernel drivers go rogue. Apple patches everything. Stealing data via secret radio waves. E-commerce supply chain drama. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Dec 15, 202221 minSeason 3Ep. 113

S3 Ep112: Beware! Data breaches can haunt you more than once...

The worm that wasn't a Goner. LastPass suffers a sting in the data breach tail. Apple's secretive update. The Ping o' Death . SIM swapping explained . A Beatles-esque 0-day in Chrome and Edge. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Dec 08, 202221 minSeason 3Ep. 112

S3 Ep111: The business risk of a sleazy "nudity unfilter"

Christmas-themed wormage. Prurient malware . Cryptorom busts . Voice call spoofing . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Dec 01, 202220 minSeason 3Ep. 111

S3 Ep110: Spotlight on cyberthreats - an expert speaks

Security specialist John Shier tells you the "news you can really use" - how to boost your cybersecurity based on real-world advice from the 2023 Sophos Threat Report. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity

Nov 24, 202222 min

S3 Ep109: How one leaked email password could drain your business

Microsoft's tilt at the MP3 marketplace. Apple's not-a-zero-day emergency. Cracking the lock on Android phones. Browser-in-the-Browser revisited . The Emmenthal cheese attack. Business Email Compromise and how to prevent it . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Nov 17, 202226 minSeason 3Ep. 109

S3 Ep108: What would YOU do if you found $3 billion in a popcorn tin?

Radio waves so mysterious they're known only as X-Rays. Were there six 0-days or only four? The cops that found $3 billion in a popcorn tin. Blue badge confusion . When URL scanning goes wrong. Tracking down every last unpatched file. Why even unlikely exploits can earn "high" severity levels. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Nov 10, 202220 minSeason 3Ep. 108

S3 Ep107: Eight months to kick out the crooks and you think that's GOOD?

The man who put Boole in Boolean. OpenSSL's bated-breath update. Apple's zero-day finally settled. New Chrome zero-day . SHA-3 code gets a patch . Extreme extortion via stolen medical data . Data breach response the nonchalant way. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Nov 03, 202223 minSeason 3Ep. 107

S3 Ep106: Facial recognition without consent - should it be banned?

Windows XP (fondly?!) remembered. Clearview AI courts controversy again. DEADBOLT ransomware crooks get counterhacked . Women cryptologists commemorated in US. How to measure randomness . Deconstructing Apple's latest security bulletins . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Oct 27, 202221 minSeason 3Ep. 106

S3 Ep105: WONTFIX! The MS Office cryptofail that "isn't a security flaw"

Coolest videogame ever. Zoom thinks everyone's a developer . The Patch Tuesday that wasn't . A data breach coverup . Log4Shell all over again . And the Office cryptofail that Microsoft won't fix. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Oct 20, 202224 minSeason 3Ep. 105

S3 Ep104: Should hospital ransomware attackers be locked up for life?

What goes up... must come down. Ransomware criminal avoids a life sentence . Former CSO convicted over Uber megabreach coverup . WhatsApp fights rip-off rogue apps . The Countess of Computer Science . Could a weird email brick your iPhone ? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Oct 13, 202220 minSeason 3Ep. 104

S3 Ep103.5: OAuth 2 and why Microsoft is forcing you into it

Naked Security meets Sophos X-Ops ! Duck and Chet dig into OAuth 2.0, a well-known protocol for authorization. Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it. Original music by Edith Mudge

Oct 09, 202217 minSeason 3Ep. 103

S3 Ep103: Scammers in the Slammer (and other stories)

A fridge-sized calculator made with transistors (really). ProxyNotShell situation reviewed. Romance and BEC scammer gets 25 years in the slammer. Is there an answer to nuisance callers ? Is the answer voicemail? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Oct 06, 202220 minSeason 3Ep. 103

S3 Ep102.5: "ProxyNotShell" Exchange bugs - an expert speaks

Chester Wisniewski gives you actionable advice on how to deal with two actively exploited Exchange zero-days that suddenly burst into the news. Learn who's affected and how, find out what you can do while waiting for Microsoft's patches, and plan your threat hunting in case the worst happens to you. Original music by Edith Mudge...

Oct 01, 202215 minSeason 3Ep. 102

S3 Ep102: Cutting through cybersecurity news hype

What's the real deal with LAPSUS$ ? How did Optus get hacked? Was there really a WhatsApp 0-day? What if "deleted" data comes back from the dead to haunt you? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Sep 29, 202221 minSeason 3Ep. 102

S3 Ep101: Uber and LastPass - is 2FA all it's cracked up to be?

Security SOS Week 2022 - check it out ! The very first Android. Firefox 105 is out. Uber hacked... by LAPSUS$ ? LastPass talks about its breach . Are two disks better than one? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 22, 202220 minSeason 3Ep. 101

S3 Ep100.5: Uber breach - an expert speaks

Chester Wisniewski explains what we can learn from Uber's latest cybsecurity crisis : "Just because a big company didn't have the security they should doesn't mean you can't." Original music by Edith Mudge

Sep 17, 202213 minSeason 3Ep. 100

S3 Ep100: Browser-in-the-Browser hacking – how to spot an attack

Second Cosmic Rocket (not a band!) Microsoft 0-day . Apple 0-days. Good logging habits. Browser-in-the-browser trickery. DEADBOLT ransomware. Again. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity...

Sep 14, 202226 minSeason 3Ep. 100

S3 Ep99: TikTok "attack" - was there a data breach, or not?

The bug that was a moth. Was there really a TikTok breach? Peter Eckersley : Code In Peace. Chrome and Edge fix a zero-day . Apple updates iOS 12 for the first time in a year. App icons: the difference between sprockets and cogs. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 08, 202220 minSeason 3Ep. 99

S3 Ep98: The LastPass saga - should we stop using password managers?

The Computer Misuse Act, back in 1990. JavaScript supply-chain bug hunting. Jumping airgaps . "The Sanitizer" comes to Chrome . LastPass breach provokes password manager puzzlement . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Sep 01, 202222 minSeason 3Ep. 98

S3 Ep97: A musical crash, ATM skimming, and was your iPhone pwned?

Start me up. The R&B dance classic that crashed computers. Bitcoin ATM skimming (no malware required). Multiple browser zero-days . Was your iPhone pwned ? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 25, 202224 minSeason 3Ep. 97

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, heathcare security

Chester attends DEF CON from afar. Zoom fixes an 0-day. An APIC leak that isn't EPIC. $10m for dobbing in Conti criminals. Cybersecurity in hospitals. Ransomware in triplicate . Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 18, 202229 minSeason 3Ep. 96

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto

Memories of the Blaster worm. Slack leaked password hashes for FIVE YEARS. Github showered with malware. Traffic lights and cybersecurity. Post-quantum cryptography. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 10, 202223 minSeason 3Ep. 95

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!)

Queen Victoria goes online. A nasty bug in Samba. Smiles for SysAdmins. A crypto-as-in-cryptography bug. A crypto-as-in-currency disaster. And is $200 million just chump change these days? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity...

Aug 04, 202223 minSeason 3Ep. 94
For the best experience, listen in Metacast app for iOS or Android