Naked Security

Naked Security

By SophosTechnology
Download on the App Store

Naked Security episodes

  • S3 Ep28.5: Hacking back - is attack an acceptable form of defence?

    Sophos cybersecurity expert Chester Wisniewski provides excellent, topical and timely commentary on the FBI’s recent use of a malware-like method to forcibly clean up hundreds of servers still infected in the Hafnium aftermath.


    With Paul Ducklin and Chester Wisniewski


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    20 min
  • S3 Ep28: Pwn2Own hacks, dark web hitmen and COVID-19 privacy

    We look at the big-money hacks from the 2021 Pwn2Own competition. We investigate the difficulties of hiring an assassin via the dark web. We wrestle with some of the privacy issues relating to COVID-19 infection tracking apps.


    With Kimberly Truong, Doug Aamoth and Paul Ducklin.


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    48 min
  • S3 Ep27: Census scammers, beg bounties and data breach fines

    How scammers copied a government website almost to perfection. What to do about those fake "bug" hunters who ask for payment for finding "vulnerabilities" that aren't. Why the Dutch data protection authority fined Booking.com for not sending in a data breach disclosure fast enough.


    Useful podcasts and videos mentioned in this episode:

    https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac

    https://nakedsecurity.sophos.com/s3-ep8-a-conversation-with-katie-moussouris

    https://nakedsecurity.sophos.com/what-should-you-say-if-you-have-a-data-breach


    With Kimberly Truong, Doug Aamoth and Paul Ducklin.


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    47 min
  • S3 Ep25: Drained accounts, ransomware attacks and Linux badware

    How a social engineer ripped off a victim lured in by one of those "small outstanding fee to pay" home delivery scams. The ransomware crooks targeting networks that still haven’t done their Hafnium patches. And the Linux kernel security holes that lay there undiscovered for 15 years.

    Related articles that we refer to in the show:

    https://nakedsecurity.sophos.com/beware-the-dhl-delivery-message
    https://nakedsecurity.sophos.com/watch-out-scummy-scammers
    https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac
    https://nakedsecurity.sophos.com/blackkingdom-ransomware
    https://nakedsecurity.sophos.com/serious-security-webshells-explained
    https://nakedsecurity.sophos.com/naked-security-live-hafnium-explained
    https://nakedsecurity.sophos.com/serious-security-the-linux-kernel-bugs


    With Kimberly Truong, Doug Aamoth and Paul Ducklin.


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    47 min
  • S3 Ep24: How not to get snooped, scammed or hoaxed

    We discuss an iPhone app that allowed anyone to snoop on anyone's calls - but not in the way you might expect. We investigate a data breach where 150,000 surveillance cameras protecting hundreds or thousands of customers were apparently "secured" by a single password... that got leaked onto the internet. And we urge you as keenly as we can: "Don't spread hoaxes, folkses."


    With Kimberly Truong, Doug Aamoth and Paul Ducklin.


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    48 min
  • S3 Ep23.5: An interview with cybersecurity expert John Noble CBE

    John Noble was Director of Incident Management at the UK's National Cyber Security Centre (NCSC) until his retirement in 2018. During his 40 years of Government service, John specialised in operational delivery and strategic business change. For his work in creating effective partnerships in the run up to the London Olympics, he was made a Commander of the British Empire (CBE) in 2012.

    John helped to establish the NCSC and led the response to nearly 800 significant cyberincidents. This work has given him unrivalled experience in dealing with and understanding the causes of cyberattacks.

    John is currently a non-executive director at NHS Digital, where he chairs the Information Assurance and Cyber Security Committee. NHS Digital is the national information and technology partner to the health and social care system in England.


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    30 min
  • S3 Ep23: Hafnium happenings, I see you, and Pythonic poison

    Getting to grips with the HAFNIUM gang/vulnerabilities/exploits/webshells/attacks. Why it's important to think before you share those home-based selfies. What you need to know about social engineering. How (not!) to prove a point when you're a programmer.


    With Kimberly Truong and Paul Ducklin


    Original music by Edith Mudge


    Got questions/suggestions/stories to share?

    Twitter @NakedSecurity

    Instagram @NakedSecurity

    33 min

About Naked Security

From the publisher's feed

We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you!