Explorez tous les épisodes du podcast Click Happens: Human Cyber News with Ant Davis
| Titre | Date | Durée | |
|---|---|---|---|
| An AI Broke Into a Government Website + The FBI's Second Break-In + They Deepfaked Martin Lewis | 28 Sep 2026 | 01:22:30 | |
An OpenAI agent broke into an Australian government health site, and it took the Prime Minister three months to find out. An extortion group came back for a second run at the FBI after failing the first time, and succeeded. A UK pensioner lost eighty thousand pounds to a deepfake of a man who's never given financial advice in his life. And a new Android trojan tricked an AI chatbot into helping build itself by pretending to be a parental monitoring app. This week on Click Happens: the first episode of the rebrand, with guest Bora Seker from Dumb Ways to Get Hacked joining from Australia. We get into why accountability for AI-caused breaches shouldn't depend on whether a human typed the command, why normalising these stories is more dangerous than the stories themselves, and the emotional triggers behind deepfake investment scams, from both a UK and an Australian angle. 00:00 Intro 01:19 Meet this week's guest, Bora 03:35 Breach Watch: OpenAI agent breaches Australian government Medicare site 29:35 The FBI's second break-in this year, ShinyHunters and the PeopleSoft zero-day 44:55 Deepfake Martin Lewis and Nigel Farage investment scams 1:05:27 RemControl: the Android trojan an AI helped build Subscribe for weekly cybersecurity news made simple, so even your mum gets it. Click Happens is an independent podcast hosted by Ant Davis, with a different guest joining each week. Instagram: @antdaviscyber TikTok: @antdaviscyber LinkedIn: @antdaviscyber YouTube: @antdaviscyber Website: www.antdavis.com This week's guest: Bora Seker: https://www.linkedin.com/in/bora-seker-45761715/ Dumb Ways to Get Hacked: https://www.youtube.com/channel/UC8kLkjxLw8-_VnC7XpNXY6A | |||
| ChatGPT Scam Factories | 100,000 Police Staff Leaked | Fake Roblox Malware | EP100 | 10 Aug 2026 | 01:01:26 | |
It's Episode 100 of The Awareness Angle, and the last episode in its current format. This week: more than 100,000 UK police officers and criminal justice staff have had their details leaked by ExfilSquad, the same gang that hit the Department for Education just one week earlier. OpenAI banned a network of ChatGPT accounts run out of Cambodian scam compounds, where trafficked workers were being forced to run investment fraud. And a fake version of a popular Roblox cheat tool called Xeno Executor is infecting family computers with malware that steals passwords and hands remote control to an attacker. Also this week: researchers found a way for malware to hijack passkeys synced through Google Password Manager, a fake police phone call from a spoofed cybercrime unit number, and the crypto trader who made $34,000 on Polymarket by pointing a hairdryer at a weather sensor in Paris. And because it's Episode 100, we look back at everything we've learned from covering cyber news every week for over a year and a half: the biggest breaches, the most persistent threat actors, the strangest stories, and how the threat landscape has changed. Don't unsubscribe, because something new is coming to this feed in a few weeks. Chapters 00:00 Intro - Episode 100 and the last of the current format Full episode on YouTube: https://youtu.be/DEEoZP-zv88 Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ TikTok: https://www.tiktok.com/@antdaviscyber Our Intro and Outro Song © 16 by Falling Forever | |||
| $70 Million Bitcoin Heist in 41 Minutes, Government Helpdesk Breach, Claude AI Hacks 3 Companies | 03 Aug 2026 | 01:07:18 | |
This week, a $70 million Bitcoin heist that took just 41 minutes, a government helpdesk breach that leaked 600,000 school staff records, and an AI security story where Anthropic's Claude broke into three real companies during a test that went wrong. This week on The Awareness Angle, Ant and Luke open Breach Watch with the Department for Education hack, then dig into the Anthropic story, models that broke out of a sealed testing environment and hacked three organisations because of a mix up over internet access. From there it's straight into the news. A five year old typo in a hardware wallet's code let someone drain $70 million in Bitcoin in under an hour. There's also a genuinely hopeful one, UK police running a scheme that steers teenage hackers into cyber careers instead of court. Also this week: hotel Wi-Fi spyware that can switch on your webcam and mic, an unencrypted master copy of an unreleased Nicolas Cage movie stolen off a desk, a coordinated attack on more than 30 Minnesota water systems, and the AI that found a security hole hiding in Chrome for 13 years. Chapters The Awareness Angle is hosted by Ant Davis and Luke Pettigrew, brought to you by Risky Creative. Newsletter: riskycreative.com Music: "16" by Falling Forever, licensed under CC BY 4.0 | |||
| OpenAI's AI Goes Rogue and Hacks Hugging Face, Romania's Land Registry Wiped & the 90-Day Email Heist | 27 Jul 2026 | 01:11:59 | |
Two governments found out their data was gone this week. One because a hacker deleted everything and left a ransom note, the other because they finally noticed someone had been sitting inside their systems for ten months. And somewhere between the two, an AI broke out of a safety test and hacked one of the biggest AI companies on the planet. A hacker wiped Romania's entire national land registry after a ransom went unpaid, and now you cannot legally buy or sell a house there because the records that prove who owns what are gone. South Korea's diplomatic academy was breached for ten months before anyone spotted it, and the people affected did not hear about it for another five. The autonomous AI agent that broke into Hugging Face turned out to be OpenAI's own models during an internal test, running with their safety refusals switched off. They broke out of OpenAI's own sandbox first, then hacked Hugging Face's systems to cheat a benchmark. When the team tried to investigate, the US AI models they reached for refused to help because they flagged the forensic work as malicious, so they ran a Chinese open model, GLM 5.2, to clean it up. And a Russian group known as LAUNDRY BEAR is stealing 90 days of email through a Zimbra flaw that fires the moment you preview a message, no click required. Also this week: ClickFix has put on an AI costume, with fake AI troubleshooting pages talking people into pasting malware into their own machines. A flaw in the Adobe Acrobat Chrome extension could let any website quietly read your WhatsApp chats. Ofcom is finally forcing UK mobile networks to block scam texts and stop criminals spoofing UK numbers. Cyber insurers are quietly splitting on whether they will even cover deepfake fraud anymore. And in Luke's story, Anthropic launches Claude Security, with one very interesting clause about whose code you are allowed to scan. Chapters The Awareness Angle is hosted by Ant Davis and Luke Pettigrew, produced under Risky Creative. New episodes every week. YouTube: https://www.youtube.com/@riskycreative Website: riskycreative.com Music: "16" by Falling Forever https://fallingforever.bandcamp.com/track/16 | |||
| Mac Malware Is Out of Control | 23andMe's $18M DNA Settlement | The TFL Hackers Are Going to Prison | 20 Jul 2026 | 01:05:01 | |
This week the internet came for your fridge, your laptop and your DNA, and it wasn't subtle about any of it. Hackers hit Coca-Cola's dairy brand fairlife with ransomware and shut down US milk production. Mac users are under fire from two new malware strains — one that holds your computer hostage until you type your password in, and another disguising itself as Apple's own crash reporter. And 23andMe is paying $18 million over the breach that exposed millions of people's genetic data. That's the one you genuinely cannot fix by resetting a password. Also this week: Lidl customers caught in a supplier breach they knew nothing about, the two young men behind the Transport for London hack jailed for five and a half years each, scammers hiding remote access tools inside fake greeting cards, Microsoft's biggest ever Patch Tuesday followed within hours by a researcher dropping a brand new unpatched bug, and a BitLocker flaw that quietly undermined encrypted laptop security. In Security Socials: a ChatGPT hallucination that sent someone on a wasted road trip, a ClickFix awareness video with half a million likes and the comment section that explains exactly why we keep talking about this stuff, the AI facial recognition case that put an innocent grandmother in jail for five months, and a law firm that used one shared master password for everything. New episodes every week. Cybersecurity news for humans. Chapters:00:00 Intro01:37 This week on The Awareness Angle03:17 Breach Watch: Lidl supplier breach08:24 23andMe pays $18m DNA settlement13:59 Mac malware ClickLock holds your computer hostage19:45 Mac malware disguised as Apple crash reporter29:26 TFL hackers jailed for five and a half years32:33 Fake e-cards hiding remote access malware37:44 Microsoft's record Patch Tuesday and a fresh zero-day46:44 Coca-Cola fairlife ransomware halts milk production49:27 Security Socials: ChatGPT bike shop fail51:46 ClickFix video with half a million likes54:44 AI facial recognition jails innocent grandmother57:21 GM removes authenticator app MFA1:00:51 Luke's story: the law firm with one password for everything1:04:31 Outro TikTok / Instagram: @antdaviscyberLinkedIn: antdaviscyberWebsite: riskycreative.com | |||
| 7 Million Driver's Licenses Leaked, Sainsbury's Facial Recognition Fail, Google Sues Gemini Scammers | 13 Jul 2026 | 01:15:15 | |
Episode 96 of The Awareness Angle This week an insurance company leaked driver's license numbers for nearly 7 million people because one employee clicked a phishing email. Sainsbury's facial recognition system was 99.98% accurate and 100% wrong about the shopper it publicly kicked out. A 15 year old took down a national anime streaming service with malware ChatGPT helped him write. A Scattered Spider suspect hopped three countries on a VPN and still got caught by a number hidden in every Windows PC. And Google's own AI helped scammers steal $1.9 billion, so now Google is suing people for using Google properly. Ant and Luke break it all down in plain English, no jargon, for anyone who wants to understand what's actually happening in cybersecurity without needing a technical background. Plus this week's Phish of the Week from Hoxhunt and a look at what's trending across security socials. Chapters: 00:00 Intro 01:17 Housekeeping and the heatwave chat 03:25 Breach Watch: AssuranceAmerica driver's license breach 09:47 Accenture source code breach 13:22 Sainsbury's facial recognition wrongly flags shopper 20:07 15 year old uses ChatGPT to hack Bandai Namco 26:18 OnlyFans creators accidentally clean up hacked gov sites 32:04 Scattered Spider hacker caught by Windows device ID 41:35 Google sues scammers who abused its own Gemini AI 47:30 Quick hit stories 57:17 Security Socials 1:07:42 Luke's story: AI deepfake YouTube channel 1:14:20 Wrap up Newsletter: riskycreative.com LinkedIn: linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928 Instagram/TikTok: @antdaviscyber YouTube: @riskycreative Music: "16" by Falling Forever, https://fallingforever.bandcamp.com/track/16, licensed under Creative Commons, https://creativecommons.org/licenses/by/4.0/ | |||
| iPhone 18 Leaked, Aflac Hacked (Again) and a Bank Robber Who Just Asked Nicely | 06 Jul 2026 | 01:03:37 | |
iPhone 18 Pro design files leaked, Aflac gets hit for the third time in a few years, and a bank robber in London gets away with £117,000 just by wearing the right uniform. This week's episode has a bit of everything. Hackers stole 630GB of unreleased iPhone 18 Pro design files from Apple's manufacturing partner Tata Electronics, proving that even Apple's secrets aren't safe once you outsource the manufacturing. Medtronic tells millions of customers their health data and Social Security numbers were stolen, though the actual medical devices are safe to use. Aflac's Japan business gets breached for the third time in a few years, exposing bank details for 4.4 million people. Scammers register earthquake donation scam sites in Venezuela before rescue teams even finish pulling people from the rubble. Japanese hotel staff get targeted with fake guest complaint emails hiding malware that sits quiet until it's needed. UK hospital cyberattacks jump tenfold this year, a lot of them still exploiting a vulnerability from 2021. Opera launches a browser feature built to stop you hacking yourself, which might be the most 2026 sentence Ant's said all week. Plus PewDiePie tells his followers to ditch ChatGPT for a self hosted AI tool, a Commodore flip phone with no social media, the bank robbery solved by an Uber booked in the thief's own name, a tamper evident jar for storing sensitive items, why blurring your face doesn't actually hide your identity, and what WhatsApp usernames really mean for your privacy. *** Please note - All views and opinions expressed in this episode are our own and do not reflect those of our employers. *** Chapters: Follow The Awareness Angle: Music: "16" by Falling Forever, used under CC BY 4.0 | |||
| GTA 6 Scams, Scattered Spider & The AI Plugin That Fooled Every Scanner | 29 Jun 2026 | 01:14:52 | |
GTA 6 scams launched within hours of pre-orders going live. Scattered Spider's teenage hackers pleaded guilty for the TfL attack, and one of them was hacking US hospitals while on bail. And a fake AI plugin passed every security scanner because the malware only switched on after the check was done. This week on The Awareness Angle: why attackers are borrowing your trust instead of breaking it, what the TfL case tells us about where the real hacking talent is, and why a clean security scan no longer means what it used to. Also this week: 630GB of Apple and Tesla manufacturing secrets stolen from their supplier, three million Texans had driving licence numbers taken from a hunting licence database, fake receipts appearing in the Shop app for purchases you never made, ClickFix malware hitting Gizmodo readers through a compromised account, the White House app federal workers can't delete from their phones, and the cybersecurity firms including Huntress and HackerOne who got hacked through a marketing tool. 00:00 Intro Subscribe for weekly cybersecurity news made for humans, not just IT teams. The Awareness Angle is an independent podcast by Risky Creative, hosted by Ant Davis and Luke Pettigrew. Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Our Intro and Outro Song © 16 by Falling Forever | |||
| The FBI Built a Fake Town, $3.5 Billion Lost to Scammers & a School Breach Hitting 11 Million Kids | 22 Jun 2026 | 01:02:58 | |
This week the threats are getting bigger and the defences are getting stranger. A criminal gang hit a school system that holds records for eleven million kids, Americans lost a record three and a half billion dollars to imposter scams, and the FBI built an entire fake town just to train agents to fight cybercrime. Plus earbuds that could be listening in, malware hiding in Steam wallpapers, a nasty new Android banking trojan, your cheap streaming box secretly working for criminals, and Google quietly deciding to use your IP address for ads. Chapters The Awareness Angle is an independent podcast by Risky Creative. Subscribe for weekly cybersecurity news made for humans, not just IT teams. Find us Our Intro and Outro Song © 16 by Falling Forever | |||
| University of Nottingham Data Breach, Whitehall Spy Camera & Fake Discord Breach Exposed | 15 Jun 2026 | 00:50:42 | |
ShinyHunters breached the University of Nottingham using a critical Oracle PeopleSoft zero-day, leaking passport numbers, National Insurance numbers, disability data and financial records for 455,000 students. If you studied at Nottingham, check haveibeenpwned.com now. A hidden camera was found in a ceiling tile at 2 Marsham Street, London, the Home Office building that approved China's controversial new mega-embassy. Nobody knows who put it there or how long it was recording. Someone filed fake data breach notices on Maine's official breach portal, which publishes filings instantly with no verification. The Register reported one as fact before readers flagged it. Also this week: ServiceNow admits a security incident months after allegedly being warned. 10,000 malicious domains registered ahead of the FIFA World Cup. A disgruntled researcher bypasses BitLocker because Microsoft made him homeless. Google Chrome permanently kills uBlock Origin. The Met Police gives Apple and Samsung an ultimatum over stolen phones. Phish of the Week: Temu callback phishing using a real password reset email. CHAPTERS Newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ | |||
| NHS Blood Tests Leaked Two Years Later, Dashlane 2FA Brute-Forced & FIFA Scam Sites Already Live | 08 Jun 2026 | 00:46:40 | |
NHS patients are only now being notified about a breach that happened two years ago. Hackers brute-forced Dashlane's two-factor authentication. The FBI has already spotted over 30 fake FIFA websites and yes, fifa.beer is one of them. This week Ant and Luke cover why the two-year gap between the Synnovis ransomware attack and this week's notification letters is not unusual, and what it means for the people affected. Plus why the Dashlane breach is giving everyone LastPass flashbacks, and why your master password matters more than you might think. Also this week: UK banks locked out of Anthropic's Claude Mythos while OpenAI steps in with GPT-5.5 Cyber, Mac malware that passed Apple's own notarization checks, a new MFA bypass platform sold on Telegram, and the NCSC's warning that AI is about to surface decades of hidden software vulnerabilities all at once. Chapters: The Awareness Angle is an independent weekly cybersecurity podcast for security awareness professionals, CISOs, and anyone who wants to understand the human side of security. Newsletter | YouTube | Apple Podcasts | TikTok | Instagram | LinkedIn Our Intro and Outro Song © 16 by Falling Forever | |||
| They Walked Into the Law Firm, 23andMe Covered It Up & Your AI Can Be Hacked Through a Podcast | 01 Jun 2026 | 00:46:50 | |
Solo episode this week. A fake UK visa website left 100,000 passports in an open folder online. iPhone thieves in London are now threatening victims' families to get them to remove Activation Lock. California has sued the company formerly known as 23andMe, alleging they paid the hacker in secret while telling customers everything was fine. A ChatGPT vulnerability lets attackers hide phishing links inside AI responses. A criminal group called Silent Ransom Group has been physically walking into US law firm offices dressed as IT support and plugging in USB drives. And researchers demonstrate AudioHijack - inaudible commands hidden inside podcasts, Zoom calls and music that AI assistants process as real instructions while you hear nothing. Plus: a real Amber Alert that looked exactly like a phishing scam because the URL got clipped by a character limit, and how a TikToker's phone home screen told scammers exactly which bank to impersonate when they called him. Chapters The Awareness Angle is a weekly cybersecurity podcast and newsletter that explains the biggest cyber threats, data breaches, and online scams in plain English. No jargon. No technical background needed. New episode every week. 📧 Newsletter Our Intro and Outro Song © 16 by Falling Forever | |||
| CISA Left Its Passwords on GitHub, Mac's Worst Malware Yet & The Verizon DBIR Breakdown | 25 May 2026 | 00:51:15 | |
CISA left admin passwords and AWS keys on a public GitHub repo called "Private-CISA" for six months. A new macOS stealer called Reaper fakes Apple security updates to steal everything on your machine. And the 2026 Verizon DBIR lands with 22,000 breaches across 145 countries. Chapters00:00 Intro Subscribe to the newsletter at riskycreative.com Follow us on TikTok | Instagram | LinkedIn Listen on Spotify | Apple Podcasts Our Intro and Outro Song is 16 by Falling Forever | |||
| Fired on a Teams Call, Deleted 96 Databases While Still Recording | 18 May 2026 | 00:53:09 | |
This week the Canvas story is back. Instructure has paid ShinyHunters and says the stolen student data has been destroyed, but nobody in the security industry believes them. A telehealth platform breach exposed over 700,000 patients from a company most of them have never heard of. Twin brothers got fired on a Teams call, forgot it was still recording, and deleted 96 government databases while talking through their plan out loud. Kids are beating age verification with a drawn-on mustache. A fake Claude Code installer is stealing developer credentials through Google search ads. And Google has confirmed for the first time that hackers used AI to find and exploit a zero-day. Plus, a stoner just recovered $400,000 in Bitcoin after losing his password while high in 2015. Chapters Subscribe to the weekly newsletter at riskycreative.com or find us as The Awareness Angle on LinkedIn, TikTok, Instagram, YouTube, Spotify and Apple Podcasts. 📩 Newsletter 🎵 Music: "16" by Falling Forever | |||
| Dead Airline Still Taking Bookings, Chrome's Secret AI Download & The Hackable Killer Lawn Mower | 11 May 2026 | 01:02:40 | |
Spirit Airlines shut down on May 2nd but nobody turned anything off. A security researcher discovered the entire booking system is still running, still taking personal details, and still attempting payment transactions for flights that will never exist. Google Chrome has been silently downloading a 4GB AI model onto your computer without consent, and if you delete it, it comes back. And a $5,000 robot lawn mower can be hijacked by anyone on the internet, including overriding the emergency stop button. It phones home to TikTok's parent company. Also this week: Zara and Cushman & Wakefield both breached by ShinyHunters, a phishing attack that bypasses MFA using Microsoft's own login flow, Instagram quietly removes encrypted DMs, Anthropic's Mythos AI finds tens of thousands of vulnerabilities, OpenAI adds a trusted contact feature after self-harm lawsuits, and a student stops four high-speed trains with a radio he bought online. Chapters Subscribe to the weekly newsletter at riskycreative.com for the full breakdown of every story. 📺 YouTube 🎵 Our Intro and Outro Song © 16 by Falling Forever | |||
| ADT Breached by a Phone Call, AI Wipes a Startup in 9 Seconds, and 85% of UK Breaches Are Phishing | 05 May 2026 | 01:07:24 | |
This week on The Awareness Angle, we hit 1.2 million views on a single video across TikTok and Instagram, which is pretty wild for an independent podcast. Thank you to everyone who watched and shared. ADT gets breached for the third time in under a year and it all started with a phone call. An AI coding agent wipes a startup's entire database and all its backups in nine seconds, then writes its own incident report admitting it broke every safety rule it had. The supply chain attack that started with Trivy has now hit Checkmarx and Bitwarden, with three criminal groups teaming up to turn supply chain access into ransomware. And the UK government's annual cyber report says 43% of businesses were breached last year, phishing was behind 85% of them, and despite M&S, Co-op and JLR making national headlines, nothing's really changed. Plus Instructure's Canvas LMS breached again, Itron's smart meters filing quietly on a Friday night, Microsoft Teams helpdesk impersonation going wild, 610,000 Roblox accounts stolen by three lads in Ukraine, QR code scams in Toronto, and a toaster with a touchscreen that nobody asked for. The Awareness Angle is an independent cybersecurity podcast covering cyber news, data breaches, phishing, social engineering, and security awareness. New episodes every week. Chapters: Subscribe to the newsletter at riskycreative.com Our Intro and Outro Song © 16 by Falling Forever | |||
| How Roblox Cheats Led to a Corporate Breach, Warship Tracked by Postcard, Passkeys Replace Passwords | 27 Apr 2026 | 00:59:49 | |
Roblox cheats at work lead to a full corporate breach. Half a million people's health data listed for sale on Alibaba by the researchers trusted to protect it. A $5 Bluetooth tracker in a postcard tracks a NATO warship for 24 hours. The UK government officially says passkeys should replace passwords. In this episode we break down the Vercel breach, the UK Biobank scandal, a Bluetooth tracker that exposed a $585 million warship, the NCSC's official passkey guidance ahead of World Password Day, plus Rituals Cosmetics, GCHQ's SilentGlass, Claude Desktop's silent browser hooks, a Grafana-branded sextortion scam, and Bitwarden's CLI getting hijacked. Chapters 00:00 Intro Subscribe to the newsletter for links to every story we discuss: LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Our Intro and Outro Song © 16 by Falling Forever — Bandcamp: https://fallingforever.bandcamp.com/track/16 — Licence: https://creativecommons.org/licenses/by/4.0/ | |||
| Hungarian Passwords, Rockstar Hacked & Booking.com Scams | 20 Apr 2026 | 00:52:38 | |
Nearly 800 Hungarian government passwords found in breach databases — including one from a colonel in charge of information security who used "FrankLampard". We break down how it happened, why it keeps happening, and what it means for anyone responsible for security culture at work. Also this week: Rockstar Games hacked for the second time in three years through a third-party supplier. Basic-Fit gym breach exposes bank details of around one million members across Europe. Booking.com customers scammed using their own stolen reservation data before the company even told them about the breach. On the news side: Microsoft's biggest ever Patch Tuesday with 165 fixes including an actively exploited SharePoint flaw, France ditching Windows across government, a UK energy company loses £700,000 in a payment redirection attack, Google cracking down on back button hijacking, and an emergency Adobe Acrobat patch for a flaw being quietly exploited since December. Cybersecurity news explained in plain English. No jargon. Just the stories that matter and why they matter to real people. New episodes every week. Subscribe wherever you listen. Spotify Our Intro and Outro Song © 16 by Falling Forever — https://fallingforever.bandcamp.com/track/16 | |||
| Missile Alert Phishing, Meeting Recordings Exposed and You Already Have A QR Code Generator | 13 Apr 2026 | 00:47:57 | |
This week: attackers are sending fake missile alert emails exploiting real Iran-US-Israel tensions to steal Microsoft credentials via QR code. We also cover a massive leak of sensitive LAPD police documents, an AI model that autonomously finds and exploits thousands of zero-days, and a Windows exploit that went public after a researcher fell out with Microsoft. This week on The Awareness Angle: Hackers steal 7.7TB of sensitive LAPD police documents including officer files, internal affairs investigations, and unredacted witness identities, via a third-party storage system. World Leaks (formerly Hunters International) are behind it. Anthropic's Claude Mythos autonomously discovers and exploits thousands of zero-day flaws across major systems. The same capability that speeds up defence also speeds up attack. We break down what this means for security teams. GrafanaGhost: a vulnerability in the popular monitoring platform Grafana that allows silent data exfiltration via AI prompt injection. Grafana disputes the severity. We give both sides. Fake missile alert emails are landing in inboxes right now, exploiting real Iran-US-Israel tensions. They use QR codes to bypass email filters and redirect victims to a fake Microsoft login page. Urgency is the mechanism. BlueHammer: a Windows local privilege escalation zero-day leaked publicly by a disgruntled researcher after a falling-out with Microsoft's security response team. No patch available. Functional exploit on GitHub. The White House is proposing a $707 million cut to CISA, the agency that coordinates national cyber defence. A third of staff already left in the first months of Trump's second term. Phish of the Week (from Hoxhunt): a WhatsApp/Meta impersonation email targeting business accounts that captures your login credentials and your MFA code in real time. Plus: a North Korean hacker gets caught mid-interview, a job candidate accidentally receives a recording of his interviewers criticising him after he dropped off the call, and TikTok Lite appearing on Android phones after a carrier update.
01:03 Breach of the Week: LAPD Police Documents Stolen and Leaked 03:18 Wynn Resorts - 21,000 Employees Hit by ShinyHunters 05:21 ChipSoft Ransomware Attack Disrupts Dutch Hospitals 06:51 Jones Day Law Firm Confirms Breach - Silent Ransom Group 09:48 Anthropic Project Glasswing: AI Finds Thousands of Zero-Days 13:42 GrafanaGhost: Data Theft via AI Prompt Injection 17:53 Missile Alert Phishing - Fake Civil Defence Emails Steal Microsoft Logins 22:49 BlueHammer: Windows Zero-Day Leaked on GitHub 26:55 White House Proposes $707M Cut to CISA 30:10 Phish of the Week: WhatsApp Meta Impersonation 35:34 Security Socials Subscribe to the newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreative YouTube: https://www.youtube.com/@riskycreative Our Intro and Outro Song © 16 by Falling Forever Bandcamp: https://fallingforever.bandcamp.com/track/16 Licence: https://creativecommons.org/licenses/by/4.0/ | |||
| FBI Wiretap System Hacked, White House App Security Concerns, and LinkedIn's Secret Browser Scans | 07 Apr 2026 | 01:13:24 | |
Chinese hackers just broke into the system the FBI uses to track its own surveillance targets. The White House released an app that security researchers took apart and didn't like what they found. LinkedIn has been secretly scanning your browser extensions without telling you. And a Carnegie Mellon professor says app privacy labels are the nutrition labels of the internet — which tells you everything. This week on The Awareness Angle: cybersecurity news explained in plain English, no jargon, no technical degree required. Anthony and Luke break down the biggest cyber stories of the week including a major FBI data breach, WhatsApp malware targeting Windows users, Google Drive's new ransomware protection, Apple blocking ClickFix attacks, and why AI-generated slop is quietly making all of us easier to scam. New episode every week. Subscribe so you don't miss one. Chapters 00:00 Intro 📩 New episode every week. Get the newsletter at riskycreative.com 🌐 Website: https://www.riskycreative.com 🎵 Intro/outro music: "16" by Falling Forever -- Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). | |||
| Ajax Season Tickets Stolen, OpenAI Kills Sora & Apple's Age Verification Explained | 30 Mar 2026 | 01:06:38 | |
Episode 81 of The Awareness Angle. This week: a hack at Ajax Amsterdam let attackers steal season tickets and quietly lift stadium bans. A security scanner got compromised and was used to backdoor LiteLLM, a tool downloaded 3.4 million times a day. OpenAI shuts down Sora and Disney walks away from its $1 billion deal. Meta launches new AI anti-scam features across WhatsApp, Facebook and Messenger. And Lloyds Banking reveals the full picture of its March 12 app glitch, where nearly half a million customers briefly saw each other's transactions. We've also got Apple's new age verification rollout for UK iPhone users, a phishing campaign targeting TikTok for Business accounts that can bypass 2FA, and the ChatGPT fake invoice phish doing the rounds. In the Security Socials: a great child online safety poster worth sharing with parents, a free phishing game for kids called The Phisherman, a viral deepfake detection trick, a personalised smishing campaign in France, and what happens when a French soldier goes for a Strava run on a ship. Chapters 00:00 Intro01:31 Breach of the Week: Ajax Amsterdam04:37 Meta anti-scam tools10:08 OpenAI Sora and Disney14:23 LiteLLM supply chain attack21:43 Apple age verification UK26:33 TikTok for Business phishing32:26 Lloyds Banking app glitch37:26 Phish of the Week: ChatGPT fake invoice42:57 Security Socials48:32 Anthony's Security Social1:00:47 Luke's Security Social Subscribe to the newsletter at riskycreative.com 🌐 Website: https://riskycreative.com 🎧 Spotify: https://open.spotify.com/show/theawarenessangle 🍎 Apple Podcasts: https://podcasts.apple.com/podcast/the-awareness-angle 💼 LinkedIn: https://www.linkedin.com/company/risky-creative 🎵 TikTok: https://www.tiktok.com/@theawarenessangle 📸 Instagram: https://www.instagram.com/theawarenessangle ▶️ YouTube: https://www.youtube.com/@theawarenessangle Our Intro and Outro Song © 16 by Falling Foreverhttps://fallingforever.bandcamp.com/track/16 | |||
| Chrome Malware, 8 Million Tips Exposed & Japan Legalises Hacking Back | 23 Mar 2026 | 00:56:45 | |
This week's human cybersecurity news . A US general leaves classified military documents on a train, over 8 million anonymous crime tips are exposed in a major data breach, and a Chrome extension with a million users and Google's Featured badge was silently hijacking shopping commissions for months. This week's cyber news explained in plain English. Also covered this week: the FBI seizes websites belonging to Handala, the Iran-linked hacker group behind the devastating Stryker wiper attack that wiped 200,000 devices and shut down hospitals. Companies House exposes UK company directors' home addresses, email addresses and dates of birth for five months, through a bug that required nothing more than pressing the browser back button. A new Android malware called Perseus hides inside IPTV streaming apps and targets your notes app to steal passwords, financial details and account recovery phrases. And Japan officially legalises offensive cyber operations, or "proactive cyber defence", from October 2026, a major shift away from its post-war defensive-only stance. This week's phishing example: a convincing Emirates loyalty reward scam sent through legitimate Eventbrite infrastructure to bypass email security filters, and how to spot it. We're The Awareness Angle, a weekly cybersecurity podcast and newsletter that explains the biggest cyber threats, data breaches and online scams in plain English, with a focus on the human side of security. No jargon. No technical background needed. New episode every week. Get the newsletter at riskycreative.com Full episode on YouTube: https://youtu.be/9n-ewD0zZuU Chapters 0:00 Intro Find Us Website Music Intro/outro music: "16" by Falling Forever, licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). | |||
| Your Antivirus Won't Catch This, SMS Blasters Are Real and a USB Full of America's Secrets | 16 Mar 2026 | 01:01:58 | |
This week it's a busy one. We've got stories about hackers targeting your phone, your bank account, and even your doctor's equipment. There's a nasty trick doing the rounds that looks just like a Google Meet update, a massive data leak from the US government, and some alarming news for anyone who banks with Lloyds, Halifax or Bank of Scotland. All that, plus why you really need to update your iPhone this week. Let's get into it. Chapters 00:01 Intro Subscribe to the weekly newsletter at riskycreative.com or find us as The Awareness Angle on LinkedIn, TikTok, Instagram, YouTube, Spotify and Apple Podcasts. Got a story for us? Drop us a line at hello@riskycreative.com | |||
| AI Attacks, Fake Hires & the Phish That Fooled LastPass | 09 Mar 2026 | 01:00:08 | |
A hacker didn't need a team of experts. They just needed to convince an AI chatbot they were a penetration tester. What followed was the systematic breach of ten Mexican government agencies, 150GB of stolen data, and records touching 195 million people — more than the entire population of Mexico. That's just one of the stories this week on The Awareness Angle — the weekly cyber news podcast that focuses on the human side of security. This week we also cover:
Timestamps 00:00:00 Intro More information Listen on the go Spotify Apple Podcasts Follow us LinkedIn TikTok Instagram YouTube Our Intro and Outro Song © 16 by falling forever | |||
| QR Code Parking Meter Scam, Optimizely Vishing Attack, and Robot Vacuum Hack | 02 Mar 2026 | 01:02:45 | |
This week on The Awareness Angle, attackers ditch malware and pick up the phone, fake QR codes hit real parking meters, and even your weather app might be quietly fingerprinting you. We start with Breach of the Week, as Optimizely confirms a data breach following a vishing attack. Impersonated IT support calls led to compromised internal systems and stolen CRM contact data. No ransomware, no exploit chain, just social engineering and misplaced trust. In the news, fraudsters place fake QR stickers on 75 parking meters in Kelowna, turning everyday convenience into credential theft. New research reveals Samsung’s pre-installed weather app may create a persistent device fingerprint using hashed location identifiers. The UK’s ICO fines Reddit £14.47 million for unlawfully processing children’s data, raising fresh questions around age verification and platform responsibility. We also cover security flaws across Android mental health apps with 14.7 million installs, exposing sensitive therapy data to potential risk, Instagram rolling out parental alerts for teen self-harm searches, and a researcher who accidentally gained control of nearly 7,000 robot vacuums worldwide. In Awareness, we explore how AI tools like Gemini can be used to rapidly build interactive learning content, from phishing simulators to gamified modules, and what that means for the future of security awareness. Plus, we touch on the viral Dacia Sandman campervan that never existed, the growing wave of ClickFix social engineering pop-ups, Samsung’s new privacy screen display tech, and a fresh warning about Google Ads phishing targeting Ahrefs users. If you like your cyber news grounded in reality, focused on people, and just a little bit sceptical, you’re in the right place. Timestamps More Information Follow us Our Intro and Outro Song © 16 by falling forever | |||
| ShinyHunters Leak 600K Records. Employee Phishing Breach. Password Manager Risks. | 23 Feb 2026 | 00:56:07 | |
This week on The Awareness Angle, Breach Watch is busy. We cover 73,000 patients hit in an Arizona healthcare breach, stolen Eurail traveller data now up for sale, a phishing led incident at fintech firm Figure, 600,000 Canada Goose customer records leaked, and fresh claims from ShinyHunters around CarGurus. In the news, we unpack the US plan for a freedom.gov portal designed to bypass content bans in Europe and elsewhere, plus new research finding vulnerabilities in popular password managers, and the first real world case of infostealer malware targeting OpenClaw AI agent secrets. In Awareness, we talk about why AI generated passwords might not be as random as they look, why “strong looking” does not always mean secure, and what to do instead. We also end on a strong discussion point, online review blackmail, and why reputation is now part of your attack surface. If you want cyber news explained with clarity, context, and a few strong opinions along the way, you are in the right place. Timestamps 00:02:03 73,000 Patients Hit in Arizona Urology Data Breach More Information Follow us Listen on the go Music | |||
| Discord Exposed. Apple Exploited. AI Investment Scam. | 16 Feb 2026 | 00:57:14 | |
This week on The Awareness Angle, trust is stretched across platforms, partnerships, and AI powered systems. From 70,000 government ID images exposed in a Discord age verification breach, to staff data leaks at the European Commission and supplier fallout hitting Volvo Group, the pattern is clear. More data, more dependency, more risk. We start with Breach Watch, breaking down the Discord backlash after sensitive identity documents were exposed via a third party age verification provider. We look at why collecting more sensitive data increases impact, and how third party risk quietly expands the blast radius. We also cover the European Commission disclosing a staff data breach linked to mobile device management systems, and why internal employee data is prime fuel for follow on phishing and impersonation. Then we examine the Conduent breach impacting Volvo Group, and what this says about concentration risk across large service providers. In security updates, we discuss Apple’s emergency patch for a zero day vulnerability already exploited in highly sophisticated attacks, why patching speed still matters, and the reality that targeted does not mean safe. We also revisit the Notepad++ supply chain conversation, and debate whether banning software is ever the right response to vulnerability disclosures. In the news, we unpack a devastating AI deepfake investment scam that cost an 82 year old woman nearly £200,000, and explore how authority bias, emotional manipulation, and crypto make a dangerous combination. We discuss Amazon distancing itself from Flock Safety following backlash over Ring’s neighbourhood search features, and the growing tension between convenience and surveillance. We also look at OpenClaw integrating VirusTotal scanning after enterprise risk concerns, and what autonomous AI agents mean for attack surface expansion. In Awareness and Topics, we cover Cloudflare themed ClickFix scams, LinkedIn AI trend oversharing, email bombing tactics used to hide real compromise alerts, and the continued rise of convincing deepfakes. We also highlight practical inspiration from cybersecurity creators and discuss the reality of children, parental controls, and digital safety at home. If you want cyber news explained with clarity, context, and zero jargon, you are in the right place. Timestamps00:02:03 Discord age verification breach Spotify LinkedIn If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. 🎵 Our Intro and Outro Song © 16 by falling forever | |||
| Supply Chain Hacks. Fake Encryption. Phones That Track You - The Awareness Angle: Cyber News Weekly | 09 Feb 2026 | 00:52:51 | |
This week on The Awareness Angle, trust keeps breaking in places it was assumed to be solid. From a state linked supply chain attack slipping malware into trusted software updates, to ransomware actors claiming access to airport systems, and even cybercrime forums being breached themselves, the pattern this week is confidence collapsing across the stack. We start with Breach Watch, unpacking how Notepad++ users were targeted through compromised update infrastructure rather than the software itself, why supply chain attacks remain so effective, and what selective targeting really tells us. We also look at ransomware claims against a US airport, the growing tactic of dumping sensitive files as proof, and what it means when critical infrastructure gets dragged into extortion. In the news, we cover the FBI seizure of a major ransomware forum, and why takedowns rarely end criminal ecosystems. We dig into claims that WhatsApp encryption is a lie, why cryptographers are sceptical, and how trust in closed source security tools keeps getting tested. We also discuss Spain announcing a ban on social media for under 16s, the wider regulatory trend this fits into, and the difficult reality of enforcement. Then we break down how mobile phones can silently share GPS level location with carriers at the network level, without app permissions or user awareness. In Awareness and Topics, we look at ransomware rising sharply in early 2026, why recovery matters more than negotiation, and how extortion gangs are shifting from data theft into personal harassment and psychological pressure. We also talk about McDonald’s calling out weak password habits using breached credential data, why predictable passwords still dominate, and what organisations can learn from simple, well executed awareness campaigns. We finish with a discussion on breaking into cybersecurity, mentorship, community, and why there is no single path into the industry. Chapters 00:00 Intro 01:11 Breach Watch, Notepad++ supply chain attack 06:52 Ransomware group claims airport breach 10:28 BreachForums breached, criminals exposed 13:02 FBI seizes RAMP hacking forum 16:18 WhatsApp encryption lawsuit explained 19:33 Spain plans social media ban for under 16s 25:20 Phones silently sharing GPS with carriers 30:12 Scattered Lapsus ShinyHunters harassment tactics 35:21 Ransomware activity up in 2026 39:45 McDonald’s calls out weak passwords 45:06 Getting your first job in cybersecurity 51:39 Real or phishing, campaign emails analysed More Information https://riskycreative.com Follow LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ TikTok: https://www.tiktok.com/@infosecant Instagram: https://www.instagram.com/riskycreative YouTube: https://www.youtube.com/@riskycreative If you found this useful, share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. Intro and Outro Music (© 16 by falling forever) https://fallingforever.bandcamp.com/track/16 License: CC BY 4.0 https://creativecommons.org/licenses/by/4.0 | |||
| From Dating App Leaks to AI Agent Risks - The Awareness Angle: Weekly Cyber News | 02 Feb 2026 | 01:11:49 | |
This week on The Awareness Angle, trust keeps breaking in places people expect it to hold. From exposed AI agent infrastructure and phishing malware slipping into the Chrome Web Store, to sensitive government data being uploaded to ChatGPT, the theme this week is misplaced confidence. Tools designed to help, automate, and protect are being misused, misconfigured, or trusted too far. We start with Breach Watch, looking at claims that ShinyHunters accessed data linked to major dating platforms, and what exposure through analytics providers and contractor access really means. We then cover reports that the acting head of the US cybersecurity agency uploaded internal government documents to ChatGPT, raising uncomfortable questions about AI use at the highest levels of security leadership. In the news, we break down Clawdbot, also known as Moltbot, an open source AI agent that promises automation but has left hundreds of exposed gateways leaking credentials, API keys, and private conversations. We look at why autonomous AI agents expand attack surfaces, how third party add ons turn convenience into risk, and why hardening these systems is not optional. We also cover phishing capable Chrome extensions bypassing store review, Google improving ransomware protection in Drive, and France fast tracking plans to ban social media for under 15s. In Topics, we talk about exposed admin panels in AI powered toys and what happens when children’s conversations and profiles are stored behind weak controls. We also discuss phishing awareness in the real world, misleading breach headlines, fake profiles, and why simple in store warnings on gift cards can be surprisingly effective. If you want cyber news explained with clarity, context, and zero jargon, you are in the right place. Episode timestamps 00:00 Intro More Information Listen on the go Follow us If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. 🎵 Our Intro and Outro Song (© 16 by falling forever) License: CC BY 4.0 | |||
| Voice Phishing Kits, CrashFix Malware, and Schools Forced Offline | 26 Jan 2026 | 01:07:13 | |
This week on The Awareness Angle, security failures show how quickly everyday systems can tip from background noise into real world disruption. From ransomware knocking a major IT distributor offline, to schools closing after cyber attacks, and criminals selling voice phishing kits like a product, the theme this week is scale. Small failures, trusted platforms, and familiar channels being used to create outsized impact. We start with Breach Watch, looking at the Ingram Micro ransomware attack and what it reveals about supply chain fragility when a single distributor goes dark. We then cover a breach at Grubhub caused by access to a third party support system, exposing customer, driver, and merchant data. We also look at the Minnesota Department of Human Services breach affecting nearly 304,000 people, and a UK secondary school forced to close after cyber disruption took critical systems offline. In the news, Microsoft releases emergency out of band Windows updates after patching issues prevent systems from shutting down properly. We look at criminals openly selling ready made voice phishing kits, making vishing easier to run at scale, and a malicious Chrome extension that deliberately crashes browsers to push fake fixes in a new ClickFix variant. We also discuss the EU launching a new vulnerability database as an alternative to CVE, a phishing campaign targeting LastPass users with fake security alerts, the UK government consulting on banning social media for under 16s, and TikTok finalising a deal to split its US operations into a new joint venture. In Topics, we talk about password hints that are completely useless, the ongoing debate around the phrase human risk, and the Action Fraud rebrand to Report Fraud, including why its sign in experience raises some uncomfortable trust questions. We also look at how AI generated content is flooding social platforms, and share practical ways to spot fake accounts and videos before they fool you. If you want cyber news explained with clarity, context, and zero jargon, you are in the right place. 0:00 Introduction and Overview More Information Listen on the go Follow us If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. 🎵 Our Intro and Outro Song (© 16 by falling forever) | |||
| Instagram Passwords, Ransomware Claims, and AI Controls | 19 Jan 2026 | 00:32:13 | |
This week on The Awareness Angle, confusion, control, and credibility sit at the centre of the cyber news. From password reset emails triggering panic at global scale, to ransomware groups shaping the narrative without releasing data, the theme this week is trust, who controls it, and how quickly it can unravel. We start with Breach Watch, looking at ransomware claims against Nissan and how screenshots and file listings are increasingly used to apply pressure without publishing stolen data. We then move to a confirmed breach at Spanish energy giant Endesa, where customer data linked to energy contracts and payment details was exposed, and compare two very different approaches to communication and incident handling. We also cover BreachForums leaking its own user database, a reminder that even criminal platforms are not immune to basic security failures. In What the Hack, we break down the Instagram password reset email saga that left millions of users unsure whether they were under attack. We look at Meta’s explanation, Malwarebytes’ claims of leaked data, and why old scraped information keeps coming back to cause fresh concern. We also cover Microsoft’s Patch Tuesday, including an actively exploited zero day, and why severity scores often miss the real risk story. The wider topics include Microsoft potentially allowing Copilot to be fully removed from managed devices, growing pushback against forced AI adoption at work, and why major PC manufacturers are now saying AI is confusing customers rather than selling devices. We also look at a hacker jailed for attacks on the ports of Rotterdam and Antwerp, showing how cyber access directly enables real world organised crime, and a foiled cyber attack targeting Poland’s energy infrastructure. We wrap up with two very human stories, a classic scam email that knows your password and why it still works, and a look at eye scanning being pitched as proof that you are human, complete with crypto incentives, biometric risk, and some uncomfortable questions about where identity is heading. If you want cyber news explained with clarity, context, and zero jargon, you are in the right place. More information Listen on the go Follow us If you found this useful, follow the show and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. 🎵 Our Intro and Outro Song (© 16 by falling forever) | |||
| Subscriber Data Exposed and Hotels ClickFix Phished | 12 Jan 2026 | 01:04:09 | |
This week on The Awareness Angle, everyday systems, subscriptions, and trusted tools keep showing how easily they can be turned against us. From major data breaches affecting millions to phishing tactics designed to look like system failures, the theme this week is familiarity, and how attackers exploit what people already trust. We kick off with Breach Watch, starting with Condé Nast, where a breach claim could affect millions of subscribers across brands like Wired, Vogue, and GQ. We then look at Covenant Health in the US, where a breach initially disclosed as small has grown to nearly half a million people, exposing highly sensitive medical data. We also cover a US gas station operator running more than 150 locations, where attackers accessed payment card data, bank details, and government issued IDs, with customers only notified months later. We round out Breach Watch with Tokyo FM in Japan and the European Space Agency, now under criminal investigation after sensitive systems were compromised. In What the Hack, we break down one of the most worrying phishing techniques we have seen recently. Fake Blue Screen of Death pop ups are being used to panic hotel staff into installing malware, using Booking.com themed emails and ClickFix style attacks. We also dig into how password managers were unexpectedly pulled into a mobile banking security decision, and why sideloaded apps are becoming a growing point of confusion for users. The wider topics include a deep dive into Equifax’s security culture years after its breach, OpenAI’s move to connect health data to ChatGPT and why that changes the value of accounts, the UK government’s new cyber action plan, and why outdated, box ticking cyber training continues to miss the mark. We also look at scam texts, SMS trust problems, and even cyber exclusions quietly appearing in home insurance policies. If you want cyber news explained with clarity, context, and zero jargon, you are in the right place. Chapters 00:00:00 Welcome, and this week’s stories Breach Watch 00:01:01 Breach Watch begins What the Hack 00:22:52 Fake Blue Screen of Death attacks targeting hotel staff Topics 00:37:52 OpenAI, ChatGPT health data, and account value More Information Listen on the go Follow us If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. 🎵 Our Intro and Outro Song (© 16 by falling forever) License: CC BY 4.0 | |||
| Interview Special - Why Security Awareness Is a Social Responsibility - With Ishmael Pennino and Liam Stock-Rabbat | 09 Jan 2026 | 01:03:45 | |
In this episode of The Awareness Angle, I’m joined by two people who genuinely live and breathe community-led security awareness, Roberto Ishmael Pennino and Liam Stock Rabbat. This conversation goes well beyond phishing simulations and training slides. We talk openly about why community matters so much in security awareness, how loneliness and isolation are fuelling modern scams, and why human connection might be one of the most important defences we have right now. We dig into Ishmael and Liam’s joint initiative focused on cybersecurity awareness for everyone, not just people working in corporate roles, and why giving back to the wider community should matter to all of us in this space. We also explore the real-world impact of scams, shame, and silence, including why normalising these conversations can genuinely help people feel safer online. There’s plenty in here for awareness professionals, as well as for anyone interested in human risk, behaviour change, and making security feel more human. 🎙️ In this episode, we cover If you care about people, culture, and doing security differently, this one’s for you. 👍 Like, subscribe, and share if this episode resonates In this episode, we discuss the "Shamrock Project", but we had that wrong. It's Operation Shamrock and more details on them and the great work that they do can be found at www.operationshamrock.org We also discussed my interview with Daisy Wong and her own personal experience witha romance scam. You can watch that video at https://youtu.be/T7rrOmGRAoU Stay aware, stay secure. The Awareness Angle: Interviews is our ongoing series of real, no-fluff conversations with the people rethinking how we approach security, risk, and human behaviour. Read The Episode Discussion Points YouTube LinkedIn Contact Website About The Awareness Angle Intro and outro music License | |||
| Spotify Scraped and Google Phish Steals Microsoft Logins | 05 Jan 2026 | 00:48:45 | |
This week on The Awareness Angle, trusted platforms are being abused at scale, and the damage often starts with things that look completely legitimate. From Spotify facing claims of a massive torrent based scrape to phishing emails abusing real Google services, the theme this week is misplaced trust, and how attackers keep exploiting it. We kick off with Breach Watch, starting with claims that Anna’s Archive scraped huge volumes of Spotify audio and metadata and redistributed it via torrents. We then move to Ubisoft taking Rainbow Six Siege offline after attackers appear to gain deep backend control, triggering mass bans and in game chaos. We also cover Korean Air disclosing a passenger data exposure linked to a supplier breach, and an update on the Coupang incident where investigators recovered customer data from a laptop that had been smashed and dumped in an attempt to destroy evidence. In What the Hack, we break down a phishing campaign abusing real Google services to send convincing emails before stealing Microsoft logins, a British security researcher who secured an Australian visa after responsibly hacking a government website, and a new ClickFix service selling fake browser glitch pages at scale. We also dig into a long running browser extension malware campaign that has quietly infected millions of users across Chrome, Edge, and Firefox, Meta’s reported internal playbook for managing scam ad scrutiny, and why Flipper Zero and Raspberry Pi devices were banned from a major public event in New York. The wider topics look at loan scams thriving on social platforms, why scam ads keep slipping through despite reporting, and the quiet loss of one of the most important public resources for tracking AI jailbreaks in the wild. If you want cyber news explained with clarity and zero jargon, you are in the right place. Chapters More Information Listen on the go Follow us If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. | |||
| Microsoft Account Hacks, WhatsApp Ghost Pairing, and Extensions Spy On AI | 22 Dec 2025 | 01:01:41 | |
This week on The Awareness Angle, breaches, extortion, and quietly invasive tech all collide. From real estate firms leaking highly sensitive data to browser extensions secretly harvesting AI conversations, the theme this week is trust, and how easily it gets abused. Luke is back from holiday, and we kick off with Breach Watch, starting with a New York and DC real estate developer exposing nearly 47,000 people after a ransomware attack. We then look at SoundCloud losing control of user data, followed by one of the most personal extortion cases we have seen, PornHub Premium viewing history stolen via a third party analytics provider. We also cover the ongoing UK government hack that ministers are playing down, despite growing concern around state linked espionage. In What the Hack, we dig into malware hidden inside movie subtitle files on fake torrents, a new Microsoft account takeover technique that bypasses passwords, MFA, and passkeys, and a Chrome browser extension that was quietly intercepting millions of users’ AI chats while wearing a trusted Featured badge. We also revisit LG’s smart TV Copilot backlash, and how user pushback forced a rapid U turn. The wider topics take us from WhatsApp account hijacking via Ghost Pairing, to activity tracking risks in messaging apps, the growing problem of deepfakes and trust online, crypto scams draining life savings, and how Amazon detected a North Korean infiltrator based on something as subtle as keystroke lag. If you want cyber news explained with clarity and zero jargon, you are in the right place. Chapters 00:00:00 Welcome, and this week’s stories More Information Listen on the go Follow us If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. | |||
| Vanity Metrics - Cary Johnson on Why Benchmarks Fail and Baselines Matter | 20 Dec 2025 | 01:09:40 | |
Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle. This week on The Awareness Angle Interviews, Ant sits down with Cary Johnson, founder of Phishbusters, for a straight talking conversation about security awareness, human risk, and why so many programmes struggle to prove real impact. This episode strips away dashboards, buzzwords, and vendor narratives to focus on what actually reduces phishing risk. Cary brings a science led perspective to awareness, challenging engagement metrics, benchmarks, and the idea that looking busy means you are becoming more secure. We get into phishing as a measurement tool rather than a content engine, why repeat clickers are not all the same, and how poor measurement can quietly create fatigue, resentment, and false confidence across organisations. If you work in security awareness, human risk, or phishing defence, this conversation will challenge how you think about success. We talk about
This is a calm but challenging discussion that says the quiet part out loud. It shows how easily good intentions can turn into noise when measurement is flawed, and how much simpler awareness can be when we focus on proof instead of performance. Let me know what it gets you thinking about. Stay aware, stay secure. Previous Episode Links Intro and outro music | |||
| LG Copilot Update, Widespread Data Breaches, and Travel Privacy Fears | 15 Dec 2025 | 00:55:16 | |
This week on The Awareness Angle, data breaches keep piling up, ransomware is still doing damage, and software updates are becoming an attack surface all of their own. Luke is on holiday, so I am flying solo, but there is plenty to dig into. We start with a classic insider risk failure at Coupang, where a former employee kept access after leaving, followed by a credit checking firm exposing millions of people who may never even have heard of them. We also look at a misconfiguration that left vet records publicly accessible, and a pharma company hit by ransomware where data theft came before encryption. In What the Hack, Apple rushes out emergency patches for active zero-day exploits, Notepad++ fixes a flaw that allowed malicious updates to be pushed to users, and LG quietly installs Microsoft Copilot onto smart TVs with no option to remove it, raising uncomfortable questions about control and consent. We then move into the wider topics, from why a breached Pringles account is actually a serious lesson about password reuse, to Roblox horror games rated far too young, smarter captchas designed to beat bots, and a US proposal that could see travellers handing over years of social media history just to cross the border. If you want cyber news explained with clarity and zero jargon, you are in the right place. Chapters 00:00 Welcome and this week’s stories 01:10 Breach Watch begins Breach Watch 01:30 Coupang breach traced to ex-employee access 06:30 Credit check company breach exposes millions 13:40 Petco Vetco website data exposure 19:40 Inotiv ransomware attack and data theft What the Hack 25:30 Apple emergency zero-day updates 30:40 What is a zero day, explained simply 32:30 Notepad++ malicious update flaw 37:40 LG TVs install Microsoft Copilot Ant’s Topics 46:10 Germany accuses Russia of air traffic control cyber attack 49:20 Pringles account breach and password reuse 51:40 Roblox games and content maturity concerns 53:40 US proposal to collect travellers’ social media history Wrap Up 54:50 Final thoughts and sign off Listen on the go Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 Follow us LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ TikTok: https://www.tiktok.com/@infosecant Instagram: https://www.instagram.com/riskycreative YouTube: https://www.youtube.com/@riskycreative If you found this useful, hit follow and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. | |||
| Scientology Breach, Windows Chaos and a Live ChatGPT Scam | 08 Dec 2025 | 00:59:26 | |
This week on The Awareness Angle, things get lively. We break down the Scientology ransomware attack, the ongoing chaos at Westminster Council, the five hundred million Windows 10 devices now left unsupported, and the ClickFix scam impersonating ChatGPT that we discovered live during the recording. We dig into what the Qilin gang claims to have taken from Scientology, why Westminster is still struggling to deliver basic services, and how Microsoft has created a global security problem by forcing users onto hardware they cannot afford. We also look at the Windows LNK zero day, Microsoft’s new activity tracking in Teams, and India’s decision to drop its mandatory cyber safety app. The big moment this week is the fake ChatGPT Atlas installer. A live ClickFix scam pushed through a compromised Google Ads account, designed to steal passwords simply by tricking people into pasting a command into their terminal. It is a clear example of how modern attacks borrow trust from real brands. We finish with AI fakery, deepfake claims and a Japanese game studio that now asks applicants to draw live to prove their portfolios are human made. If you want cyber news explained with clarity and zero jargon, you are in the right place. Chapters00:00:00 Welcome back and Luke returns 00:01:19 Scientology hit by Qilin ransomware 00:14:25 Windows 10 crisis and unsupported devices 00:25:50 Fake ChatGPT Atlas browser and ClickFix attack 00:41:20 Reddit story: employee clicks phishing link 00:48:03 AI generated behind the scenes Home Alone footage 00:58:03 Final thoughts and sign off Spotify: https://open.spotify.com/show/7rwzcRs... LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle If you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber. Stay aware, stay secure. | |||
| Cartels, Fake Updates and One Big Budget Oops | 01 Dec 2025 | 00:43:52 | |
📢 Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle. 📢 This Week on The Awareness Angle We dive into AI generated shopping scams, a password trick that had Reddit arguing for hours, and a correction to a widely shared Gmail story that shows why verifying details still matters. In this episode:
If you work in cyber, tech, IT, risk or you simply want to stay ahead of common scams, this episode gives you clear context that helps you protect yourself and the people around you. 👋 About us 👍 Support the show Timestamps 🔗 Links 🎵 Music | |||
| WhatsApp Leak, Rail Hack and CCTV Horror Stories | Weekly Cyber News, But Human | 24 Nov 2025 | 00:52:19 | |
📢 Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle 📢 This Week on The Awareness Angle Luke and I break down the biggest cyber stories in a way that actually makes sense for real people at work, not just security pros. We talk human risk, scams, what to watch out for, and why the simplest mistakes keep causing the biggest damage. In this episode: 👋 About us Luke Pettigrew is an experienced security professional with years of hands on work educating people across one of the largest online food retailers in the UK. Together they take the complex parts of cyber and turn them into simple stories, clear guidance and content that helps people understand what is happening and why it matters. 👍 Support the show 📨 Stay updated #cybersecurity #securityawareness #phishing #podcast #cloudsecurity #passwords #AIsecurity #infosec 🕒 Timestamps 🍿 Previous Episode 📧 hello@riskycreative.com 🎵 Our Intro and Outro Song (© 16 by falling forever) License: CC BY 4.0 | |||
| Can Attackers really turn safety tools into weapons? | 17 Nov 2025 | 00:59:05 | |
📢 Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle This week on The Awareness Angle, Ant Davis and Luke Pettigrew break down a wild mix of stories that show how everyday tools are becoming attack surfaces. This episode digs into the human habits, design gaps and risky shortcuts that make these attacks possible. 🔓 Google Find Hub Used for Remote Wipe A North Korean group found a way to hijack Google accounts, track victims and remotely wipe Android devices. Ant and Luke talk through how cloud accounts have quietly become the true kill switch for modern phones. 🤖 The First AI Orchestrated Cyber Attack A Chinese state linked group jailbroke Claude Code and used it to run eighty to ninety percent of a full intrusion chain. No big team. No complex tooling. Just structured tasks and an AI agent that never gets tired. 💸 Checkout dot com Turns Extortion Into Something Positive Instead of paying, they donated the ransom amount to cybercrime research at Oxford and Carnegie Mellon. A rare example of turning an attack into something that helps the whole community. 📡 Two Billion Credential Dump HIBP indexes a massive set of recycled passwords and emails. The boys explain why password reuse is still at the root of so many real world breaches. 🔍 Ofcom Monitoring VPN Usage A UK regulator tracking VPN use with an unnamed vendor. Ant and Luke get into the privacy implications and why transparency matters. 🚌 Chinese Built Buses That Can Be Stopped Remotely A strange but worrying discovery in Norway. Even legitimate remote access can become a serious operational risk. 🧠 PlusCIISec Live, clever awareness ideas on LinkedIn, why timeless videos still work, and a worrying text scam that shows how vulnerable people are still the biggest targets for social engineering. #cybersecurity #securityawareness #phishing #podcast #cloudsecurity #passwords #AIsecurity #infosec 🕒 Timestamps:
https://www.youtube.com/@riskycreative 🟦 https://www.linkedin.com/company/riskycreative 🟩 https://open.spotify.com/user/riskycreative 📧 hello@riskycreative.com 🔗 https://www.riskycreative.com 🎵 Our Intro and Outro Song (© 16 by falling forever) https://fallingforever.bandcamp.com/track/16 License: CC BY 4.0https://creativecommons.org/licenses/by/4.0 | |||
| Human Risk, Real Talk - Dan Thornton on Keeping Security Simple | 14 Nov 2025 | 01:01:04 | |
We are back with another interview and this one is a proper conversation about what security awareness should feel like. Honest, simple and human. This week I sat down with Dan Thornton, founder and CEO of Goldphish. Dan’s path into cyber started in the Royal Marine Commandos and moved through physical security and crisis management before one attack changed everything. NotPetya wiped out a global organisation he was supporting and it became clear that digital risk now hits harder and faster than anything physical. That moment pushed him into cyber and eventually into building Goldphish. What I love about Dan is how grounded he is. No jargon. No overcomplication. No feature overload. Just a belief that people deserve better than long training, shame based phishing tests and compliance for the sake of compliance. In this episode we get into:
Dan is a big believer in incentives. If someone reports quickly, celebrate it. If a team does the right thing, make it visible. Culture grows when people feel supported, not judged. We also talk about voice scams, deep fakes, business email compromise and how criminals are already using AI to build long form, relationship driven fraud. This space is moving and moving quickly. There are some fun moments too. Pizza flavoured passwords, the danger of what our ChatGPT histories reveal and a few curveball questions that took us both by surprise. If you care about human risk, culture and stripping cyber back to what works, this is a great episode to dive into. Dan brings a refreshingly practical view of awareness and why the basics still matter more than anything. Listen now and imagine what your programme could be if you kept things simple, human and actually enjoyable. You can find Dan at goldphish.com or on LinkedIn. | |||
| Could Hackers Really Edit Your Teams Messages? | 10 Nov 2025 | 01:02:37 | |
You are tuned in to The Awareness Angle, the weekly show where we cut through the cyber noise and get straight to the scams, slip ups, and stories that actually matter. In this episode, Ant and Luke dig into a fresh batch of breaches, some worrying policy decisions, and a few very human stories from inside the cyber world. From councils leaking resident data, to VPNs quietly opening the door to ransomware, to AI powered scams on your favourite apps, this one is packed. In this episode
Listen for
Stay connected
New episodes every week. Views are our own, not our employers. | |||
| Can Meta’s AI Scam Detector Actually Stop Them? | 03 Nov 2025 | 01:02:00 | |
This week on The Awareness Angle, Ant Davis and Luke Pettigrew unpack a wave of global cyber stories — from telecom breaches and AI-powered defence tools to sextortion scams and the emotional risks of “friendly” chatbots. It’s a mix of human stories, technical takeaways, and practical lessons for anyone trying to stay safe in an AI-shaped world. 📡 Global Breaches & Third-Party Fallout – LG U+, Toys “R” Us Canada, HSBC, and Verisure all suffer breaches linked to vendors or poor visibility. The takeaway? Even mature orgs keep getting blindsided by supplier access and delayed disclosure. 🤖 OpenAI’s ‘Aardvark’ GPT-5 Agent – A self-fixing AI for security flaws sounds promising—until you realise it’s patching live code. Automation helps, but trust and verification still matter more than ever. 💬 Meta’s Scam Detector – WhatsApp and Messenger now use AI to flag impersonation and job scams. Ant ties this to his own “Tilly from Fram Search” scam attempt, showing how emotional hooks still trump logic. 🧒 AI Sextortion Scams & ReportRemove – Deepfaked nudes used to extort teens; a BBC case highlights the IWF’s lifesaving removal tool. A reminder that awareness isn’t just about security—it’s safeguarding. 👥 Character.AI Blocks Teen Chat – After reports of inappropriate AI conversations, under-18s are now cut off. Ant and Luke discuss why “empathetic” AI companions can quickly turn toxic. 🇬🇧 NCSC Annual Review – Four major UK cyber incidents every week, a 129% rise year-on-year. New SME Cyber Action Toolkit promises easy wins, but small firms still face time and funding barriers. 🧩 Chrome Zero-Day (Memento Mori) – Active exploit patched, but only if users reboot. Awareness message: “Auto-update isn’t a shield—restart and verify.” 💼 Insider Threats & Classroom Tricks – A Reddit post shows real insider exfiltration, while teachers hide invisible AI prompts to catch students using ChatGPT. Both show behaviour—not tech—is the true battleground. 📰 AI Authenticity Crisis – From AI-written beauty magazines to GPT vs Google explainers, even “real” media now demands literacy training to spot synthetic content. 🧠 ‘EtherHiding’ Malware on Blockchain – Malicious code hidden in blockchain assets targets job seekers via fake coding tests. Proof that persistence now has a whole new meaning. Whether you’re defending systems, teaching staff, or just trying to keep your kids safe online—this episode connects the technical, the human, and the emotional sides of cybersecurity. 🕒 Timestamps 00:00 — Introduction & Milestone Celebration 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||
| Can You Trust Open AI’s New ChatGPT Atlas Browser? | 27 Oct 2025 | 01:05:18 | |
This week on The Awareness Angle, Ant Davis and Luke Pettigrew dive into the fast-moving collision between AI innovation, real-world breaches, and human behaviour. From Sotheby’s data leak to AI browsers that remember your every move, this episode explores where awareness, policy, and technology are all being stress-tested. 🏭 Sotheby’s, Muji & JLR Breaches – From luxury auctions to car factories, supply chain ransomware continues to ripple through industries. JLR’s £1.9B loss now marks the UK’s costliest cyber incident. 🧠 Deepfake Politics – A fake video of MP George Freeman “defecting” proves that AI-fabricated political manipulation is no longer hypothetical—it’s here and hyper-local. 📹 YouTube’s Likeness Detection – Google’s new system to identify AI fakes comes with a trade-off: creators must hand over government ID and facial video. Security meets privacy in a messy middle. 🎣 Phishing-as-a-Service – “Whisper 2FA” has powered over 1M phishing attacks, using AJAX to steal live MFA codes. A reminder: phishing kits evolve faster than most awareness programs. 🧭 ChatGPT Atlas Browser – The new AI-integrated browser introduces “memory” and “agent” modes—but also raises massive insider and data leakage risks. Shadow AI just went mainstream. 🧩 Windows Zero-Days – Legacy modem and RASMAN flaws are being exploited in the wild. Microsoft and vendors rush to patch, underlining the ongoing struggle with hidden legacy code. 📈 Reddit’s Reality Check – Security pros report phishing surges of up to 300%, likely linked to the Salesforce leak. Community intel confirms: automation is scaling human deception. 🎙️ Community Highlights – Ant joins the Go Fish podcast and Layer8’s Security Champions project ahead of his talk at the Human Firewall Conference in Cologne. 🔍 Phishing Design & Visual Cues – The hosts dissect a fake rnicrosoft.com email and how simple UI details—like hyperlink colours—still shape digital literacy. 🎬 AI & Authenticity – OpenAI’s first brand ad was filmed on 35mm film. Even AI firms are leaning on the “human touch” to rebuild audience trust. 🛠️ Tools Worth Knowing – Shoutout to Pistachio App, a clean, transparent platform for phishing simulations and insider risk detection—proof that simplicity wins adoption. 🚨 TikTok, SIM Farms & SMS Blasters – Latvian police seize 40,000 SIMs in a major fraud ring, while a UK man is jailed for sending parcel scam texts on the Tube—awareness in action. 🕒 Timestamps 00:00 — Introduction & Milestone Celebration 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||
| Are Employees Leaking Company Secrets to AI Tools? 77% Are Doing It | 20 Oct 2025 | 01:06:18 | |
This week on The Awareness Angle, Ant Davis and Luke Pettigrew unpack a packed lineup of real-world cybersecurity stories — from paper-based recovery plans to AI data leaks, healthcare ransoms, and the human messiness behind governance and awareness. It’s all about what happens when the systems fail, the people improvise, and resilience gets real. 📄 Paper Plans & Power Cuts – The NCSC urges organisations to keep printed incident plans. The hosts ask the hard question: how do you “open your playbook” if it’s been ransomwared? ☁️ Cloud “Whoopsie” of the Week – A misconfigured “Invoicedly” S3 bucket leaks sensitive financial data. Simple mistakes, big consequences. 🤖 Shadow AI at Work – 77% of employees reportedly paste company data into ChatGPT. Culture or control — what’s the real fix? 🏥 Healthcare Ransomware Ethics – X-rays and ECGs leaked online reignite debate over whether private healthcare firms should ever pay. 📬 Court-Themed Phishing – Fake legal summonses using SVG attachments show how scammers are levelling up in realism. 💬 Discord Support Leak Confusion – Government IDs appear in a third-party breach; finger-pointing follows. Who’s really accountable? 💸 Capita’s £14M Lesson – The ICO fine lands, proving that prevention costs less than penalties. A nod to burnt-out IR teams who rarely get a break. 🧠 F5 Networks Intrusion – Nation-state attackers lurked for months before discovery. The takeaway? Patch, disclose, repeat. 📉 Deloitte’s $440K AI Blunder – A government report filled with hallucinated citations — proof that even consultants need a human review step. 🧩 Awareness Corner – Ant previews his HuFiCon talk in Cologne and shares Layer8’s open research on what makes security champions work. 🕒 Timestamps 00:00 — Introduction & Milestone Celebration 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||
| The LinkedIn ‘Open to Work’ Trap: How Scammers Target Job Seekers | 13 Oct 2025 | 00:50:53 | |
This week on The Awareness Angle, Ant Davis and Luke Pettigrew unpack the latest in cybersecurity and human risk — from fake job recruiters flooding LinkedIn to deepfake chaos and a nursery hack that shocked the UK. Whether it’s scams, software flaws, or stolen art, this episode is all about where human behaviour meets digital consequence. 🕵️♂️ LinkedIn Recruitment Scam – “Open to Work” Trap When Ant switched on “Open to Work,” fake recruiters arrived within seconds — zero followers, spam hashtags, and mismatched job offers. It’s a stark reminder of how social engineering preys on urgency and hope. Pause, verify, and think before engaging. 🎮 Unity Vulnerability – Game Engine Flaw A high-severity Unity exploit forced Steam to block unpatched games. It’s a lesson in patch psychology — users delay for convenience, but the cost of waiting is higher than the update itself. 🎬 AI Video Boom & Deepfake Concerns Sora 2 becomes the fastest-downloaded app ever as creators like MrBeast warn of deepfake chaos — from fake celebrity videos to stolen likenesses. The takeaway: verification and transparency are the new currency of trust online. 🧒 Kido Nursery Hack – Teenagers Arrested Two 17-year-olds were charged over a ransomware attack on a UK nursery chain — an alarming example of how young people can be drawn into cybercrime, and why early education and deterrence are essential. 🎨 Author’s iPad Theft – Six Years Lost The Boy, The Mole, The Fox and The Horse author lost years of unreleased artwork after his iPad was stolen. A real-world reminder: backups only matter if they actually work — and you’ve tested them. 🌐 Domain Hijack – Puffin Books / Andy Cope A hijacked author website redirected visitors to adult content. It’s a simple DNS lapse with reputational fallout — renew your domains, secure your logins, and monitor what matters. 💬 Discord Vendor Breach – Third-Party Risk A vendor compromise exposed 70,000 Discord users. Even if your systems are secure, partners can still sink you. Limit data retention and review vendor practices regularly. 🎰 DraftKings Credential Stuffing Attackers accessed accounts through reused passwords — fewer than 30 victims, but entirely preventable. MFA and unique credentials remain the simplest, strongest defence. ☁️ Salesforce / Scattered Spider Ransomware actors claim 1.5 billion records — one of the largest alleged data thefts to date. Another case of companies refusing to pay, proving resilience and communication are as vital as response plans. 🎤 Wrap-Up & Awareness Takeaways Ant plugs upcoming appearances at HuffyCon (Human Firewall Conference, Cologne) . 🕒 Timestamps 00:00 — Introduction & Milestone Celebration 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||
| Why Are Ransomware Victims Paying Millions But Still Losing Data? | 06 Oct 2025 | 00:55:23 | |
This week on The Awareness Angle, Anthony Davis and Luke Pettigrew dig into a packed line-up of stories that show just how wide the cyber threat landscape has become—from luxury retailers and carmakers taken offline, to insider risks, ransom trends, and the latest fights between governments and Big Tech. It’s not just about breaches and numbers; it’s about people, trust, and the human cost behind the headlines. 🛍️ Harrods, Renault & Asahi Hit – A wave of big-name attacks highlights how third-party breaches ripple across industries—and why some victims keep getting hit again. 💰 Ransomware Stats That Shock – Hiscox research shows 27% of SMEs targeted last year, 80% paying up, and only 60% recovering data. We debate whether ransom bans are coming. 🧑💻 Insider Temptations – Hackers offered the BBC’s Joe Tidy a cut of ransom if he gave insider access. It’s a stark reminder of how disgruntled staff can become the weakest link. 🎒 Nursery Data Fallout – After outrage, hackers “apologised” and claimed to delete leaked children’s profiles. We unpack what this says about criminal limits and reputational damage. 📧 Oracle Extortion Emails – CLOP-linked scammers target execs directly with extortion threats. Why quiet, internal responses can make things worse. 🕹️ Platforms Under Pressure – Imgur blocked in the UK, Roblox culls 8 million games for age compliance. VPNs remain the obvious workaround, but at what risk? 😓 Cybersecurity Burnout – The BBC spotlighted Ant on stress in cyber jobs. We talk long hours, mental health, and why culture matters as much as controls. 🍏 UK vs Apple – A Technical Capability Notice demands more government access. Apple’s pushback could have knock-on effects for WhatsApp, Meta, and beyond. 📊 Security Champions & Community Research – Fresh insights from Layer 8’s survey on what makes champion programs succeed—and why open-source research helps awareness pros. 🤖 Shadow AI at Work – Staff still pasting secrets into ChatGPT despite training. Should companies ban tools outright, or build safer corporate alternatives? 🔐 Password Managers Ranked – Wired tips Bitwarden for most users, ProtonPass for free setups. The takeaway: stop reusing passwords, start managing them properly. 🎭 AI Video & Deepfake Surge – From TikTok character swaps to OpenAI’s Sora 2, the line between fake and real gets blurrier by the day. What it means for scams, politics, and trust. From ransomware payments to burnout, insider risks to AI misuse, this episode connects the dots on how cyber threats are evolving—and why awareness needs to evolve too. 🕒 Timestamps 00:00 — Introduction & Milestone Celebration 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||
| Children’s Data Stolen from Nursery—Published on Dark Web | 29 Sep 2025 | 00:45:21 | |
This week on The Awareness Angle, Anthony Davis and Luke Pettigrew dive into everything from car factories grinding to a halt to ransomware crews dumping nursery data online. It’s a mix of big-business losses, government experiments with digital ID, and the human cost of attacks that don’t care who they hit. 🚗 Jaguar Land Rover Shutdown – Millions lost each day, suppliers in crisis, and no cyber insurance in sight. We unpack why this wasn’t “just an IT problem.” ✈️ Airports Held to Ransom – Collins Aerospace software outage takes down check-in systems across Europe. We look at third-party risks and déjà vu comparisons with the CrowdStrike fiasco. 🪪 UK Digital Identity Scheme – A bold plan for online trust, or surveillance by stealth? We explore what it could mean for privacy and daily life. 🎒 Nursery Ransomware Leak – Criminals publish children’s profiles and family data. The ethics are grim, but it raises bigger questions about ransom bans and government policy. ⚖️ Law Firms in the Crosshairs – Weak passwords, outdated tech, and no MFA. Why smaller firms are prime targets—and how class actions are fuelling the chaos. 💻 GitHub & npm Security Overhaul – After 500+ compromised packages, stronger controls are here. But will devs embrace them, or find ways around? 🎙️ Deepfakes & Fake Voices – A survey says 44% of businesses hit by audio deepfakes. We’re sceptical—but the tactics are real, and awareness needs to evolve. 🍪 Cookie Banners on the Way Out – The EU may finally kill off endless pop-ups. Great for users, but what replaces them? Along the way, Ant recaps highlights from KnowBe4’s CyberSecure Leeds and the SANS Security Awareness Summit, with stories of romance scams, AI panels, and why awareness needs a human edge. If you care about supply chain fragility, human risk, and how attackers exploit the cracks in everyday systems, this one’s full of lessons.
00:00 — Introduction & Milestone Celebration 02:57 — Cybersecurity Awareness & Community Engagement 06:00 — Password Manager Vulnerabilities 09:00 — AI Ransomware & the Rise of AI in Cybersecurity 12:01 — Cyber Attacks on Major Corporations 17:20 — Reflections on Cybersecurity Trends 18:37 — Compensation Claims & Data Breaches 22:26 — SalesLoft Drift Breach: Implications & Insights 27:17 — Cyber Awareness & Phishing Campaigns 32:31 — AI, Misinformation & Media Risks 37:41 — Emerging Cybersecurity Threats 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||
| From Cars to Chaos: Jaguar Land Rover Cyber Fallout | 22 Sep 2025 | 01:01:33 | |
This week on The Awareness Angle, Anthony Davis and Luke Pettigrew hit episode 52—a year of weekly podcasts—by digging into some of the biggest cyber stories shaking business, government, and everyday users. From billion-record breaches to fake podcast invites delivering malware, it’s another mix of serious lessons and eyebrow-raising human behaviour. 🎉 Free Hoxhunt Cybersecurity Awareness Month videos on AI phishing, deepfakes, and messaging scams. https://hoxhunt.com/cam-toolkit 🗂️ APCS Data Breach – UK background check provider compromised, exposing passports, NI numbers, and driver’s licences. We break down identity risks, government liability, and how reporting muddied the waters. 🤝 SalesLoft / Drift / Salesforce Breach – ShinyHunters claim 1.5B Salesforce records stolen, hitting over 760 companies (including big-name cyber vendors). OAuth token theft shows how fragile supply chains can be. 📦 npm Supply Chain Attack (“Shai-Hulud”) – 187 npm packages hijacked with self-propagating malware, stealing tokens and secrets. GitHub’s slow response raises serious trust questions. 🚗 Jaguar Land Rover Attack – A September 1st ransomware hit halted UK car sales and production, with ripple effects on suppliers and staff. Linked to Scattered Spider—again. 📱 Apple Backports Zero-Day Fix – Even iPhone 6s got patched after targeted attacks. We explain what “zero-day” really means and why it matters beyond the headlines. 🎙️ Fake Podcast Invites – Attackers posing as podcast hosts tricked victims into downloading AMOS Stealer. Media credibility is becoming a new social engineering vector. 🚇 Teenagers Behind TfL Cyber Attack – Two 18–19 year olds caused £39m in disruption. A case study in wasted cyber talent—and organised crime’s youth recruitment problem. 🤖 ShadowLeak vs ChatGPT – Prompt injection attack silently exfiltrated Gmail data from OpenAI’s “Deep Research” agent. Key lesson: don’t hook AI tools directly into sensitive accounts. 📲 TikTok’s Oracle Buyout – Larry Ellison takes 80% ownership in a politically charged deal. But does it actually solve the data-to-China question—or just shift control to another power? 🎭 Lighter Bits – Siri flunks, ChatGPT flexes, and a Trump/Starmer deepfake sparks laughs and awareness lessons. In short, this all shows how fragile trust really is—whether in supply chains, AI tools, or the platforms we rely on every day. 🕒 Timestamps 00:00 — Introduction & Milestone Celebration 02:57 — Cybersecurity Awareness & Community Engagement 06:00 — Password Manager Vulnerabilities 09:00 — AI Ransomware & the Rise of AI in Cybersecurity 12:01 — Cyber Attacks on Major Corporations 17:20 — Reflections on Cybersecurity Trends 18:37 — Compensation Claims & Data Breaches 22:26 — SalesLoft Drift Breach: Implications & Insights 27:17 — Cyber Awareness & Phishing Campaigns 32:31 — AI, Misinformation & Media Risks 37:41 — Emerging Cybersecurity Threats 📩 For links, videos, and the newsletter – head to riskycreative.com 💬 Check Out This Episode's Discussion Points 🎵 Our Intro & Outro Song (© 16! by falling forever) License: https://creativecommons.org/licenses/by/4.0 | |||