The Awareness Angle: Cyber Security Awareness and Human Risk

Hungarian Passwords, Rockstar Hacked & Booking.com Scams

52 min · 20. Apr. 202652 min
Episode Hungarian Passwords, Rockstar Hacked & Booking.com Scams Cover

Beschreibung

Nearly 800 Hungarian government passwords found in breach databases — including one from a colonel in charge of information security who used "FrankLampard". We break down how it happened, why it keeps happening, and what it means for anyone responsible for security culture at work. Also this week: Rockstar Games hacked for the second time in three years through a third-party supplier. Basic-Fit gym breach exposes bank details of around one million members across Europe. Booking.com customers scammed using their own stolen reservation data before the company even told them about the breach. On the news side: Microsoft's biggest ever Patch Tuesday with 165 fixes including an actively exploited SharePoint flaw, France ditching Windows across government, a UK energy company loses £700,000 in a payment redirection attack, Google cracking down on back button hijacking, and an emergency Adobe Acrobat patch for a flaw being quietly exploited since December. Cybersecurity news explained in plain English. No jargon. Just the stories that matter and why they matter to real people. New episodes every week. Subscribe wherever you listen. Spotify [https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6] Apple Podcasts [https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196] LinkedIn Newsletter [https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/] YouTube [https://www.youtube.com/@riskycreative] Instagram [https://www.instagram.com/riskycreative] TikTok [https://www.tiktok.com/@infosecant] Our Intro and Outro Song © 16 by Falling Forever — https://fallingforever.bandcamp.com/track/16 [https://fallingforever.bandcamp.com/track/16]

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der The Awareness Angle: Cyber Security Awareness and Human Risk-Community!

Kostenlos hören bei Podimo

Starte jetzt und verbinde dich mit deinen Lieblingspodcaster*innen

  • Vertraut von über 1 Mio. deutschen Hörer*innen
  • Über 1.000 lokale Podcasts und Shows – nur bei Podimo
  • Keine Zahlung nötig

Alle Folgen

86 Folgen

Episode ADT Breached by a Phone Call, AI Wipes a Startup in 9 Seconds, and 85% of UK Breaches Are Phishing Cover

ADT Breached by a Phone Call, AI Wipes a Startup in 9 Seconds, and 85% of UK Breaches Are Phishing

This week on The Awareness Angle, we hit 1.2 million views on a single video across TikTok and Instagram, which is pretty wild for an independent podcast. Thank you to everyone who watched and shared. ADT gets breached for the third time in under a year and it all started with a phone call. An AI coding agent wipes a startup's entire database and all its backups in nine seconds, then writes its own incident report admitting it broke every safety rule it had. The supply chain attack that started with Trivy has now hit Checkmarx and Bitwarden, with three criminal groups teaming up to turn supply chain access into ransomware. And the UK government's annual cyber report says 43% of businesses were breached last year, phishing was behind 85% of them, and despite M&S, Co-op and JLR making national headlines, nothing's really changed. Plus Instructure's Canvas LMS breached again, Itron's smart meters filing quietly on a Friday night, Microsoft Teams helpdesk impersonation going wild, 610,000 Roblox accounts stolen by three lads in Ukraine, QR code scams in Toronto, and a toaster with a touchscreen that nobody asked for. The Awareness Angle is an independent cybersecurity podcast covering cyber news, data breaches, phishing, social engineering, and security awareness. New episodes every week. Chapters: 00:00 Intro 01:30 Welcome 01:52 ADT Breached Again by ShinyHunters Vishing Attack 07:23 Instructure / Canvas LMS Hit by Another Cyber Attack 13:38 Critical Infrastructure Giant Itron Confirms Cyberattack 17:56 AI Coding Agent Deletes Startup Database in 9 Seconds 25:28 Supply Chain Attack Hits Checkmarx and Bitwarden 28:40 Roblox Account Theft: 610,000 Accounts Stolen 36:56 UK Cyber Security Breaches Survey 2025-26 43:06 Microsoft Teams Helpdesk Impersonation Attacks 52:21 QR Code Scams in Toronto 57:03 Smart Toasters and Unnecessary IoT 1:01:09 Hannah Fry on AI Agents Going Rogue Subscribe to the newsletter at riskycreative.com Our Intro and Outro Song © 16 by Falling Forever https://fallingforever.bandcamp.com/track/16 [https://fallingforever.bandcamp.com/track/16] Licensed under Creative Commons Attribution 4.0 https://creativecommons.org/licenses/by/4.0/ [https://creativecommons.org/licenses/by/4.0/]

5. Mai 20261 h 7 min
Episode How Roblox Cheats Led to a Corporate Breach, Warship Tracked by Postcard, Passkeys Replace Passwords Cover

How Roblox Cheats Led to a Corporate Breach, Warship Tracked by Postcard, Passkeys Replace Passwords

Roblox cheats at work lead to a full corporate breach. Half a million people's health data listed for sale on Alibaba by the researchers trusted to protect it. A $5 Bluetooth tracker in a postcard tracks a NATO warship for 24 hours. The UK government officially says passkeys should replace passwords. In this episode we break down the Vercel breach, the UK Biobank scandal, a Bluetooth tracker that exposed a $585 million warship, the NCSC's official passkey guidance ahead of World Password Day, plus Rituals Cosmetics, GCHQ's SilentGlass, Claude Desktop's silent browser hooks, a Grafana-branded sextortion scam, and Bitwarden's CLI getting hijacked. Chapters 00:00 [https://youtu.be/hlBFZ76nIBI?t=0] Intro 01:18 [https://youtu.be/hlBFZ76nIBI?t=78] Vercel Breach: Roblox Cheats to Customer Data Exposure 06:38 [https://youtu.be/hlBFZ76nIBI?t=398] Rituals Cosmetics Loyalty Programme Breach 09:46 [https://youtu.be/hlBFZ76nIBI?t=586] UK Biobank Health Data Sold on Alibaba 13:41 [https://youtu.be/hlBFZ76nIBI?t=821] GCHQ SilentGlass: Blocking Malware Over HDMI 16:25 [https://youtu.be/hlBFZ76nIBI?t=985] Claude Desktop Silently Installs Browser Hooks 24:03 [https://youtu.be/hlBFZ76nIBI?t=1443] Sextortion Scam Disguised as Grafana Alert 29:15 [https://youtu.be/hlBFZ76nIBI?t=1755] Bitwarden CLI Hijacked in Supply Chain Attack 31:52 [https://youtu.be/hlBFZ76nIBI?t=1912] $5 Bluetooth Tracker Exposes NATO Warship 35:44 [https://youtu.be/hlBFZ76nIBI?t=2144] NCSC: Passkeys Should Replace Passwords 42:50 [https://youtu.be/hlBFZ76nIBI?t=2570] Security Socials: The HR Hot Take 46:08 [https://youtu.be/hlBFZ76nIBI?t=2768] Security Socials: Spam Caller Rick Astley Script 48:09 [https://youtu.be/hlBFZ76nIBI?t=2889] Security Socials: iPhone 17 Pro Stolen 51:56 [https://youtu.be/hlBFZ76nIBI?t=3116] Security Socials: My Cocoon Airplane Privacy 54:19 [https://youtu.be/hlBFZ76nIBI?t=3259] Security Socials: GPT Image 2 AI Generation 58:57 [https://youtu.be/hlBFZ76nIBI?t=3537] Outro Subscribe to the newsletter for links to every story we discuss: LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Our Intro and Outro Song © 16 by Falling Forever — Bandcamp: https://fallingforever.bandcamp.com/track/16 — Licence: https://creativecommons.org/licenses/by/4.0/

27. Apr. 202659 min
Episode Hungarian Passwords, Rockstar Hacked & Booking.com Scams Cover

Hungarian Passwords, Rockstar Hacked & Booking.com Scams

Nearly 800 Hungarian government passwords found in breach databases — including one from a colonel in charge of information security who used "FrankLampard". We break down how it happened, why it keeps happening, and what it means for anyone responsible for security culture at work. Also this week: Rockstar Games hacked for the second time in three years through a third-party supplier. Basic-Fit gym breach exposes bank details of around one million members across Europe. Booking.com customers scammed using their own stolen reservation data before the company even told them about the breach. On the news side: Microsoft's biggest ever Patch Tuesday with 165 fixes including an actively exploited SharePoint flaw, France ditching Windows across government, a UK energy company loses £700,000 in a payment redirection attack, Google cracking down on back button hijacking, and an emergency Adobe Acrobat patch for a flaw being quietly exploited since December. Cybersecurity news explained in plain English. No jargon. Just the stories that matter and why they matter to real people. New episodes every week. Subscribe wherever you listen. Spotify [https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6] Apple Podcasts [https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196] LinkedIn Newsletter [https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/] YouTube [https://www.youtube.com/@riskycreative] Instagram [https://www.instagram.com/riskycreative] TikTok [https://www.tiktok.com/@infosecant] Our Intro and Outro Song © 16 by Falling Forever — https://fallingforever.bandcamp.com/track/16 [https://fallingforever.bandcamp.com/track/16]

20. Apr. 202652 min
Episode Missile Alert Phishing, Meeting Recordings Exposed and You Already Have A QR Code Generator Cover

Missile Alert Phishing, Meeting Recordings Exposed and You Already Have A QR Code Generator

This week: attackers are sending fake missile alert emails exploiting real Iran-US-Israel tensions to steal Microsoft credentials via QR code. We also cover a massive leak of sensitive LAPD police documents, an AI model that autonomously finds and exploits thousands of zero-days, and a Windows exploit that went public after a researcher fell out with Microsoft. This week on The Awareness Angle: Hackers steal 7.7TB of sensitive LAPD police documents including officer files, internal affairs investigations, and unredacted witness identities, via a third-party storage system. World Leaks (formerly Hunters International) are behind it. Anthropic's Claude Mythos autonomously discovers and exploits thousands of zero-day flaws across major systems. The same capability that speeds up defence also speeds up attack. We break down what this means for security teams. GrafanaGhost: a vulnerability in the popular monitoring platform Grafana that allows silent data exfiltration via AI prompt injection. Grafana disputes the severity. We give both sides. Fake missile alert emails are landing in inboxes right now, exploiting real Iran-US-Israel tensions. They use QR codes to bypass email filters and redirect victims to a fake Microsoft login page. Urgency is the mechanism. BlueHammer: a Windows local privilege escalation zero-day leaked publicly by a disgruntled researcher after a falling-out with Microsoft's security response team. No patch available. Functional exploit on GitHub. The White House is proposing a $707 million cut to CISA, the agency that coordinates national cyber defence. A third of staff already left in the first months of Trump's second term. Phish of the Week (from Hoxhunt): a WhatsApp/Meta impersonation email targeting business accounts that captures your login credentials and your MFA code in real time. Plus: a North Korean hacker gets caught mid-interview, a job candidate accidentally receives a recording of his interviewers criticising him after he dropped off the call, and TikTok Lite appearing on Android phones after a carrier update. 00:00 [https://www.youtube.com/watch?v=B_rxuKB72ow] Introduction 01:03 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=63s] Breach of the Week: LAPD Police Documents Stolen and Leaked 03:18 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=198s] Wynn Resorts - 21,000 Employees Hit by ShinyHunters 05:21 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=321s] ChipSoft Ransomware Attack Disrupts Dutch Hospitals 06:51 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=411s] Jones Day Law Firm Confirms Breach - Silent Ransom Group 09:48 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=588s] Anthropic Project Glasswing: AI Finds Thousands of Zero-Days 13:42 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=822s] GrafanaGhost: Data Theft via AI Prompt Injection 17:53 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=1073s] Missile Alert Phishing - Fake Civil Defence Emails Steal Microsoft Logins 22:49 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=1369s] BlueHammer: Windows Zero-Day Leaked on GitHub 26:55 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=1615s] White House Proposes $707M Cut to CISA 30:10 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=1810s] Phish of the Week: WhatsApp Meta Impersonation 35:34 [https://www.youtube.com/watch?v=B_rxuKB72ow&t=2134s] Security Socials Subscribe to the newsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreative YouTube: https://www.youtube.com/@riskycreative Our Intro and Outro Song © 16 by Falling Forever Bandcamp: https://fallingforever.bandcamp.com/track/16 Licence: https://creativecommons.org/licenses/by/4.0/

13. Apr. 202647 min
Episode FBI Wiretap System Hacked, White House App Security Concerns, and LinkedIn's Secret Browser Scans Cover

FBI Wiretap System Hacked, White House App Security Concerns, and LinkedIn's Secret Browser Scans

Chinese hackers just broke into the system the FBI uses to track its own surveillance targets. The White House released an app that security researchers took apart and didn't like what they found. LinkedIn has been secretly scanning your browser extensions without telling you. And a Carnegie Mellon professor says app privacy labels are the nutrition labels of the internet — which tells you everything. This week on The Awareness Angle: cybersecurity news explained in plain English, no jargon, no technical degree required. Anthony and Luke break down the biggest cyber stories of the week including a major FBI data breach, WhatsApp malware targeting Windows users, Google Drive's new ransomware protection, Apple blocking ClickFix attacks, and why AI-generated slop is quietly making all of us easier to scam. New episode every week. Subscribe so you don't miss one. Chapters 00:00 Intro 01:40 Breach of the Week: Chinese Hackers Breach the FBI's Wiretap System 07:15 Trivy Supply Chain Attack Hits the European Commission 11:45 The White House App Security Concerns Explained 18:15 Apple Blocks ClickFix Paste Attacks in macOS 23:35 App Privacy Labels vs Food Nutrition Labels 28:40 Google Drive Ransomware Detection Now Available 35:51 LinkedIn Secretly Scanning Your Browser Extensions 41:11 WhatsApp Used to Deliver Malware to Windows PCs 44:54 Phish of the Week: QR Code Salary Scam and Device Code Phishing 50:42 SMS Delivery Scam in the Wild 57:06 Sloppypasta and Why AI Content Is a Security Risk 1:02:04 Artemis II Has Two Broken Instances of Outlook in Space 1:03:54 Artemis II is Running Microsoft 365 in Space 1:04:43 Artemis II Astronaut Enters PIN on Live Stream 1:06:43 Apple Passwords App Ad 1:09:58 Nice Looking TikTok Video 📩 New episode every week. Get the newsletter at riskycreative.com [https://www.riskycreative.com] 🌐 Website: https://www.riskycreative.com [https://www.riskycreative.com] 🎙️ Spotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6 [https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6] 🍎 Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196 [https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196] 💼 LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/ [https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/] 🎵 TikTok: @infosecant 📸 Instagram: https://www.instagram.com/riskycreative [https://www.instagram.com/riskycreative] ▶️ YouTube: https://www.youtube.com/@riskycreative [https://www.youtube.com/@riskycreative] 🎵 Intro/outro music: "16" by Falling Forever -- Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). Track: https://fallingforever.bandcamp.com/track/16 [https://fallingforever.bandcamp.com/track/16] License: https://creativecommons.org/licenses/by/4.0/ [https://creativecommons.org/licenses/by/4.0/]

7. Apr. 20261 h 13 min