DANNY PALMER
It's October, which means it's Cybersecurity Awareness Month.
GRAHAM CLULEY
Oh no, the one month of the year we have to care about cybersecurity, and then the 11 months we can have off. Yes, yes, it is, isn't it?
DANNY PALMER
I've got up all my decorations, sent my cards. Very exciting times.
GRAHAM CLULEY
Smashing Security, episode 487. Clippy's Crypto. Welcome back with Graham Cluley and special guest Danny Palmer. Hello, hello, and welcome to Smashing Security episode 487.
My name's Graham Cluley.
DANNY PALMER
And I'm Danny Palmer.
GRAHAM CLULEY
Danny, great to have you back. I also have to say, great also to be sitting in the seat again here at the podcast palace, newly relocated.
Thanks to everyone who listens to the show for their kind words as I took a week off recently in order to undergo a house move.
So it wasn't possible to do the podcast and move house and change cities at the same time.
DANNY PALMER
You weren't doing it while driving the van to your new house then?
GRAHAM CLULEY
I could have done, couldn't I? I could have livestreamed or something like that. I did used to know a guy. I remember once he was driving me around.
This was, oh gosh, 25, 30 years ago or so. And he was driving me around London and I thought, oh, that's an interesting radio programme.
It appears that he's listening to an episode of Dad's Army.
And I looked over at him and I saw that he actually had balanced on top of his steering wheel where the speedometer was or whatever.
He actually had one of those mini televisions with an aerial and he was bloody well watching TV while driving me around. Some friend he turned out to be.
DANNY PALMER
I suppose that's those times where the laws hadn't caught up with the technology yet. Yes.
GRAHAM CLULEY
Yes. He would have been caught these days.
DANNY PALMER
I'm glad everything's gone successfully and you've got your important bookshelf behind you as well in your camera. That's the most important thing.
GRAHAM CLULEY
Yes.
Anyone who's watching the video will be able to see, yes, got the all-important bookshelf, sufficiently blurred out so you can't see that it's mostly Doctor Who books and Doctor Who videos and the occasional chess book as well.
Well, before we kick off, let's thank this week's wonderful sponsors, HackTheBox, Origin, and Vanta. We'll be hearing more about them later on in the podcast.
Unknown
This week on Smashing Security.
GRAHAM CLULEY
We won't be talking about how AI agents are suspected of hacking seven South Korean banks.
Unknown
You'll hear no discussion of—
GRAHAM CLULEY
How ASOS customers found out the site had been hacked from an app notification posted by the hackers themselves.
DANNY PALMER
And we won't even mention—
GRAHAM CLULEY
How AI coding agents leaked 13,000 internal screenshots from over 300 companies onto public GitHub just to be helpful. So Danny, what are you going to be talking about this week?
DANNY PALMER
Well, I'm going to be talking about a big rise in cyber scams stealing social media accounts of maybe your friends.
GRAHAM CLULEY
And I'm going to be exploring a cyberattack involving one of the most reviled characters in history.
Plus, we're also going to be joined by Christine Bartlett of Hack The Box for a featured interview. All this and much more coming up in this episode of Smashing Security.
Somewhere in your security team, right now, there's a worker who's never slept, never taken a holiday, never once said, I'll leave this until Monday.
GRAHAM CLULEY
No, Joe, it's not about Geoff.
JOE
Because Geoff actually does sleep. I've seen him do it.
GRAHAM CLULEY
It's not Geoff, Joe. It's an agent. Because your security team isn't just humans anymore. It's humans and AI agents working the same shifts, touching the same systems.
JOE
Two kinds of worker. On the same team.
GRAHAM CLULEY
And here's the question no one's asking in the budget meeting. Do you actually know whether both of them can do the job?
JOE
You trust your analysts because they've got certifications, experience, a CV you interviewed against.
GRAHAM CLULEY
And your agent got hired on a vibe after a product demo.
JOE
We've been letting it mark its homework this whole time.
GRAHAM CLULEY
This is where HackTheBox comes in. They help organisations build one connected cyber workforce strategy for humans and agents alike.
JOE
For the humans, it's hands-on training, the real skills needed to secure AI systems and fight back against AI-accelerated threats. Not slides, not theory, the actual job.
GRAHAM CLULEY
And for the agents, HackTheBox lets you appraise them, test them against realistic cybersecurity work, the way you'd test a new hire, and reappraise them because the model changes, the tools change, the environments change, and what was good enough to pass last quarter might not pass this time.
JOE
So, your security team now has two kinds of worker.
GRAHAM CLULEY
But do you actually know whether both of them can do the job?
JOE
HackTheBox. Develop your people. Appraise your agents.
GRAHAM CLULEY
Find out more right now at smashingsecurity.com/hackthebox.
JOE
That's smashingsecurity.com/hackthebox. And thanks to HackTheBox for supporting the show.
GRAHAM CLULEY
Right, Danny, before we start, I've got some bad news for you, I'm afraid.
GRAHAM CLULEY
Yeah, I'm sorry to tell you that you are in a small plane, a small plane plummeting into the sea.
DANNY PALMER
Pull up, pull up. Doesn't sound ideal, I've gotta be honest.
GRAHAM CLULEY
No, it gets worse because the pilot has jumped out with the last parachute. You're the only one on board. You don't even have a picnic hamper to save yourself. Kasplash!
You've landed in the ocean. You survived the impact, that's great.
DANNY PALMER
That is good, yeah.
GRAHAM CLULEY
And you're bobbing around in the waves. And luckily for you, there are 2 islands within swimming distance. Now, I don't know how good a swimmer you are, Danny.
DANNY PALMER
We're probably talking about 200 metres at this rate. Yes.
GRAHAM CLULEY
Conveniently, these 2 islands are very close. But unluckily for you, these islands are inhabited by people that you'd probably rather not meet.
GRAHAM CLULEY
And you've gotta make your choice as to which island to swim towards.
GRAHAM CLULEY
That's the name of the game. Gotta make the choice.
GRAHAM CLULEY
Now, your first island, which you've gotta consider, is the Michael Bublé island. Now, Michael Bublé, some people think he's perfectly nice.
What they're forgetting, of course, is that he sings. And in this particular case, Michael Bublé is gonna sing at you constantly.
He's not gonna utter a single word without a big band arrangement in the background.
DANNY PALMER
Will this involve Christmas songs when it's not even Christmas?
GRAHAM CLULEY
Oh, can you imagine? So that's one island. So you could choose that island. On the other island is Jeremy Clarkson.
Now he's going to explain to you at some length, and without being asked of course, why the island would be better with a V8 engine.
He'll also almost certainly tell you that he didn't get any A-levels and it didn't do him any harm. So which island are you going to go to?
DANNY PALMER
Oh gosh, that is a tough decision.
GRAHAM CLULEY
It is a dilemma, isn't it?
DANNY PALMER
I don't see Clarkson and I getting along very well, to be honest. So I think—
GRAHAM CLULEY
Gonna submit yourself to the Bublé Island?
DANNY PALMER
I think I'll submit myself to the Bublé Island, yeah.
GRAHAM CLULEY
Very sensible of you, I suspect. Well, congratulations. You made it to the shore of Bublé Island. But, oh, hang on, what is this?
I can see a raft floating past, captained by none other than Piers Morgan. And he'd like a word. In fact, he'd like several words. He's gonna ask you some questions.
He's probably gonna interrupt your answer. He'll call it a debate. He'll also probably try to insert himself into any breaking news story.
So do you stay with your first choice, Michael Bublé, or do you swim away and join Piers Morgan on his raft?
DANNY PALMER
I think as the raft is a vehicle that has forward motion, I think I'll have to take the raft and bear the consequences. Is he just leaving Bublé behind?
GRAHAM CLULEY
Yeah, well, I think that would be the right thing to do, yes. You can't have Piers Morgan and Michael Bublé and yourself on a small raft. Can you imagine the hell that would be?
DANNY PALMER
No, it doesn't seem an ideal situation, no.
GRAHAM CLULEY
Okay, so you're gonna go with Piers Morgan. All right.
DANNY PALMER
I'll go with Morgan, yeah.
GRAHAM CLULEY
So you're on the raft with Piers Morgan, and unfortunately for you, you fall off the raft — or maybe you jumped, I think is more likely.
And you're stuck now between two other islands. Now, on one island, you've got Elon Musk, you know, a wonderful person, very, very intelligent apparently.
He owns a social media platform. He's got ignorant opinions about everything. Probably want you to have nine children with them. On the other island, however, is Clippy.
GRAHAM CLULEY
Clippy, of course, the psychopathic 1990s Microsoft virtual assistant, the goggly-eyed paperclip.
DANNY PALMER
I know the guy, yeah.
GRAHAM CLULEY
So you have to decide now, are you going to submit yourself to Elon Musk, or are you going to go on the island where this paperclip is going to pop up and say, hey, it looks like you're trying to survive on a desert island, would you like help with that?
Which one would you choose?
DANNY PALMER
Part of me would be tempted by the Musk island, if only to tell him that I've seen pretty much every episode of The Simpsons, and he is legitimately the guest character in what is widely regarded as the worst episode ever of The Simpsons.
It's very weird. It was made in about 2016 before he changed his personality.
And it's quite weird looking back at it and seeing how Lisa Simpson, of all people, is fawning over him, which I don't think she would now.
GRAHAM CLULEY
Oh no, I don't think she would. No.
DANNY PALMER
So as tempting as that is, I think I'd have to go for Clippy.
GRAHAM CLULEY
Go for Clippy.
GRAHAM CLULEY
Well, it's an interesting choice because this week those two actually met. Someone pretending to be Clippy took over the account of Microsoft on Twitter last Thursday.
If you were one of Microsoft's 13 million followers, you may have noticed something odd because they changed their avatar on Twitter.
Their profile picture changed to Clippy, the paperclip that spent much of the late '90s interrupting your Word documents to tell you that it looked like you were writing a letter.
I think we all thought Clippy had gone into the wilderness, but it turns out the little blighter is back.
But he's not actually acting as a Microsoft mascot — he is acting as a crypto grifter.
GRAHAM CLULEY
Everyone seems to be these days. So someone hijacked Microsoft's official Twitter account. They swapped the picture for Clippy. They made it follow a Clippy-themed crypto account.
DANNY PALMER
Clippy Coin.
GRAHAM CLULEY
Yeah. And shared one of its posts.
So that account, which they shared the post of, it was called Clippy MSFT — I think like Microsoft CTO was posing as Clippy itself, as though Clippy was the CTO of Microsoft.
Meanwhile, a second account was busy flogging a Clippy Coin, claiming its liquidity was paired with the Microsoft stock price, which may have made some people think that it was somehow connected to Microsoft's actual stock, which obviously it wasn't.
Now, things get a little bit weirder still.
DANNY PALMER
Did Clippy turn into a dog like he used to? Or you could change him around, right — you could change into a dog, a cat, that sort of thing. Einstein?
GRAHAM CLULEY
Yes. You could have, yes, all sorts of things back in the day.
Things became stranger because round about half an hour after the account posted this message, a very sensible, very corporate apology was posted on Microsoft's Twitter account.
And it said that Microsoft knew about this token using the Clippy brand without permission. You know, so it was saying, you know, this cryptocurrency has nothing to do with us.
They said that they don't back any cryptocurrency whatsoever. But then, to everyone's surprise, the apology from Microsoft vanished itself without any explanation.
And it turns out, because Microsoft later confirmed it, that not only was all the Clippy nonsense not from Microsoft, but the apology wasn't from them either.
DANNY PALMER
Oh, was it a situation where it was, we're sorry, to show you we're sorry, please click here to get your free cryptocurrency?
GRAHAM CLULEY
Well, that, yes, you know, to make up for it, give us some cryptocurrency and we'll send you double back. That is what you would expect normally, wouldn't you?
It's like, oh, well, we'll try and get a little bit more out of this. But no, the apology was completely straight-faced. There wasn't any dodgy link about it.
There wasn't any dubious call to action which people had to take. It just wasn't from Microsoft.
Now, whether this was the hackers thinking, we could be in a spot of bother here, or whether they were planning to later post some further messages still posing as Microsoft, I don't know.
It's really, really bizarre. I can't imagine why they might have done it. Do you have any theories?
DANNY PALMER
Usually these things get sort of nipped in the bud fairly swiftly because you assume the account has regained access to itself.
But yeah, the way this has been deleted, either Microsoft saw that and got rid of it, or yeah, the attackers deleted it themselves for some reason, which is unusual.
GRAHAM CLULEY
And then posted the apology. That's the thing. They — it was the hackers posting the apology as if it were Microsoft, and it looked like a Microsoft apology.
Frankly, I mean, that should have been the giveaway. Since when has a tech company ever apologised for anything?
DANNY PALMER
Yeah, even hackers apologise more often than tech companies do.
GRAHAM CLULEY
So bear this in mind. These hackers seized control of a Twitter account with 13 million followers. The mischief they could have caused.
But what they decided was that they were just going to go with a paperclip. No ransomware, no data theft, no phishing, just a paperclip and an apology.
And we still don't know how they actually hacked into that account. Microsoft hasn't said anything.
I mean, it could have been one of their social media managers was phished maybe, or it could be a SIM swap. It could be a hijacked email address used for a password reset.
It could be info-stealing malware that had stolen a session cookie, so no password or MFA prompt was ever needed.
DANNY PALMER
Hopefully it's not because the password was, you know, Microsoft1 or something like that.
GRAHAM CLULEY
Hopefully we've moved on from those days, although you can never be too confident. I mean, it could have been all manner of things.
It could have been a third-party social media tool that was breached. Could be a security screw-up at Twitter itself. I mean, that has happened.
GRAHAM CLULEY
I know. Shocking, isn't it? But we have seen high-profile accounts on Twitter accessed in the past.
So the thing is, this is Microsoft and their account was still taken over by what looks like a paperclip plugging a crypto coin. And I think maybe that's the lesson for all of us.
If you ever think it couldn't possibly happen to me, it can happen to anybody at all. Even some of the biggest brands in the world.
DANNY PALMER
Yeah, it's always fascinating to me with these campaigns as well that they immediately go for the crypto scam as the way of making money.
I mean, I don't know how much money they make, but I guess they must make something from these because they still keep doing it.
And I guess they're more likely to get an instant return on that rather than sneaking around trying to drop malware or ransomware and that sort of thing.
GRAHAM CLULEY
Yes.
And I suppose in some ways there's less technical knowledge required to pimp a crypto coin than there is to create a piece of ransomware, even though there are sort of roll-your-own malware kits these days.
And obviously AI has made some of these things easier and democratised cybercrime in some fashions, even if you're not a complete nerd. But yeah, strange days indeed.
JOE
This episode of Smashing Security is sponsored by Vanta.
GRAHAM CLULEY
It's 2 AM. Somewhere, a security team is drowning. Graham, the spreadsheets. There are so many spreadsheets. Vendor risk assessments unread.
Audit evidence scattered like ash in the wind. I've filled out the same questionnaire 4 times this week, Graham.
GRAHAM CLULEY
Some men choose to face this alone, but not tonight.
JOE
Okay, Graham, this is a bit much.
GRAHAM CLULEY
Yeah, fair point. Anyway, Vanta.
GRAHAM CLULEY
Vanta's a trust management platform that automates the mind-numbing stuff that makes you want to poke your eyes out with a fork.
No more manual evidence chasing, no more questionnaire hell. It continuously monitors your systems and keeps you audit-ready. For SOC 2, ISO 27001, HIPAA, GDPR, the works.
And it uses AI. Yes, Joe, it does.
JOE
To flag risks and streamline evidence collection so your whole security programme stays in shape, not just the week before an audit.
GRAHAM CLULEY
No more 2 AM dread. No more spreadsheet purgatory. Just peace.
JOE
And $1,000 off if you demo it right now.
JOE
vanta.com/smashing. Go now before it's too late.
GRAHAM CLULEY
That's vanta.com/smashing.
JOE
And thanks to Vanta for supporting the show.
DANNY PALMER
So, Graham, it's October, which means we've reached the part of the year when people are thinking about the dark nights rolling in, and the even darker forces which might come with it.
DANNY PALMER
I'm not quite talking about ghosts, witches, monsters, and other scary entities which haunt us around Halloween. I'm talking about an even bigger, scarier threat.
I'm talking about cybercriminals and malicious hackers because yes, it's October, which means it's Cybersecurity Awareness Month.
GRAHAM CLULEY
Oh no, the one month of the year we have to care about cybersecurity and then the 11 months we can have off. It is, isn't it?
DANNY PALMER
Yes. I've got up all my decorations — not in this room here, but I've got up my decorations, I've sent my cards. Very exciting times.
And I'm sure your good self and anyone who listens to Smashing Security, as you say, is probably thinking about cybersecurity all year round.
But for many, October marks the time of year when organisations remember they have to teach their employees about this thing called cybersecurity.
And even the government gets involved with the likes of the National Cyber Security Centre going on a big push to provide advice to individuals on how to stay safe online against the ghoulish threat of various nefarious types trying to use the internet to commit crimes.
Imagine using the internet for evil — who could think of such a thing?
So to mark Cybersecurity Awareness Month, Report Fraud, which is the national cybercrime and fraud reporting service — which is weirdly run by the City of London Police — has released some new figures on how cybercrime has affected people over the last year.
And Graham, it does not make for very fun reading at all.
DANNY PALMER
They have urged people to do more to protect themselves against cyber threats, after the last year saw a 417% increase in the amount of money stolen by criminals and scammers hacking emails and social media accounts.
So this report puts the figure for the financial year 2025–2026 at £6.3 million compared to £1.2 million for the previous year.
And this is based around attacks against individuals — this isn't companies, this is attacks against people.
No one's had £6 million stolen in one go, as far as we're aware, but all the little different petty crimes, I suppose you could call them, they add up.
GRAHAM CLULEY
And this is the hacking of email and social media accounts, which — I mean, it's not like it's a new thing, is it? But that's a dramatic rise, 417%.
DANNY PALMER
Yeah, it is a really big thing.
So the email hacking, as we know, isn't any sort of new thing, but it just seems that the tactics that these scammers are using over the last years have become super effective.
Or maybe people are reporting it a bit more because, as the paper hints at, that 6.3 million figure might only be the tip of the iceberg because a lot of these crimes go unreported.
If someone, for example, had £100 stolen from them from an attacker, they might not go to the police about it because there are likely to be many victims out there who haven't reported this because they might be embarrassed they've fallen victim to a scam, or they might think, yeah, it's only 100 quid, it's not worth reporting.
But like the crypto scams you spoke about, stack together a bunch of smaller threats and they all eventually add up.
What's going on here is, to make this more effective, in many cases the scammers are hijacking people's social media accounts and email addresses and using them to directly target their unsuspecting friends and family.
You know, taking control of Facebook accounts, Instagram accounts, that sort of thing.
And according to the report, one of the most common scams criminals are using to steal money in these attacks is to claim that the person they have stolen the account of has tickets to a sold-out event they can no longer attend.
So they're offering, hey, I can't attend this event.
DANNY PALMER
If you want to go in my stead, transfer me the money and I'll give you the tickets.
But there are no tickets available, and the friend or family member paying for these is just sending their money straight to the attacker's bank account.
And in many cases, I guess people won't even realise something's wrong until a bit of time after the fact going, oh, why didn't you send me those tickets? What tickets?
GRAHAM CLULEY
Yes, because you won't necessarily know your friend's bank account details. You know, they're your friend.
DANNY PALMER
Yeah. I don't know my friend's bank details off by heart. They might be suspicious if I did.
There was an instance of this last year where The Guardian newspaper reported a woman had her Instagram account hacked by scammers who used her identity and her profile to advertise tickets to one of the sold-out Oasis gigs of last year.
And they used this hacked account with these fake tickets to get a total of £1,400 from her friends, which seems to suggest that it wasn't just one of her friends they targeted with this.
Several of her friends saw this post saying, oh, I've got tickets for this Oasis gig available.
GRAHAM CLULEY
That's absolutely terrible. I'm sure Noel and Liam Gallagher are very upset that they've lost those thousands of pounds because—
GRAHAM CLULEY
They thought they were the ones scamming everybody into paying hundreds and hundreds of pounds to go and see them.
DANNY PALMER
I believe Oasis is going on tour next year as well.
GRAHAM CLULEY
And they're gonna scam people again.
They thought they had the monopoly on that particular scam, but now what you're telling me is the cybercriminals have come in and they're now making cash out of Oasis too.
DANNY PALMER
Well, there's a reason I've always been on the Blur side of that argument.
What is worrying about this as well is that the victim said that the attackers managed to impersonate her so well in the messages and posts that her friends and family genuinely thought they were speaking to her when this was happening.
Other commonly successful tactics deployed by scammers to steal money in this way include using fraudulent texts and WhatsApp messages or emails to claim to be a family member in some sort of trouble that needs urgent money.
I even get them saying the message is going, oh, hi, it's your daughter — I don't have one — so you're barking up the wrong tree here, but I can see why it works.
GRAHAM CLULEY
This happened to me in the last week. I didn't receive the message.
I was at a neighbour's being given beans on toast because I've just moved and we couldn't get to any cooking equipment because of the cardboard boxes and exercise bike and things like that.
And so she said, oh, we'll do you some beans on toast. And while we were there, she got a text claiming to come from her daughter saying that she was in trouble.
This clearly happened so often to her that she instantly knew it was nonsense and that it wasn't really her daughter. At least I hope that was the case rather than she ignored it.
DANNY PALMER
Adoring her daughter. That is interesting. The fact it's so common. You were there.
And there's also cases where it seems to be increasingly common, particularly in the last month, where scammers are using the prospect of phony job offers to lure people into giving away money or private information, which either directly steal money from people or steal their social media accounts.
I mean, this type of scam has been all over the UK for the last few weeks. I don't know about you, but I'm having 3 or 4 calls a day from an unknown number.
DANNY PALMER
My phone alerts it as a potential scam. But the thing is, now with my role as a freelancer, in theory, I need to pick up every call.
These guys, when they're doing it, they try to get you off your phone onto another platform for more information and to steal money that way.
That has become such a common attempt at a scam that it might even backfire because the general public is so aware of this scam going around at the moment that they are talking about it.
People are focusing on their social media accounts about it.
GRAHAM CLULEY
But it only has to happen a tiny percentage of the time to be worth it for the fraudsters. That's the point, isn't it?
DANNY PALMER
What I think this all goes to show is that at a time where we're repeatedly being told by companies how their uber-powerful super AI has hacked businesses or brand new zero days, it's still important to ensure that organisations and people are protected against the simpler, more garden variety cyber threats as well.
The old one's the best, I suppose you could say. And it's understandable because the reason social engineering works is because it manipulates the emotions of the victim.
They may really think that a family member is in trouble, or a trusted friend is selling tickets to a gig they really want to go to, or they're in desperate need of work and they take a punt on the opportunity, even if it comes from an unknown number, because they're looking for work.
And I think it's also important to remember this isn't just about the financial figures. Each person who falls victim to a scam like this takes an emotional hit.
They may get upset about falling victim to a scam. They may feel ashamed, which is why it doesn't get reported.
I've even heard stories of people working within the cybersecurity industry who have fallen victim or almost fallen victim to these types of scams.
They often share these stories as they want people to hear about them and know what to look out for.
But sometimes I think there can be the attitude that if you're falling for these, it's on your own back. But these attackers are very smart and manipulative.
They know what they're doing. It's their job. They're experts at it.
So if we're in a world where people who live and breathe cybersecurity can even be trapped by these, I sometimes wonder how members of the public are supposed to cope.
GRAHAM CLULEY
Absolutely.
DANNY PALMER
So the City of London Police have provided some advice on how to identify and avoid falling for these scams targeting online accounts.
And it's probably worth sharing this information with your friends and family in terms of how to help stop these.
A lot of these are things people will know, but I think it's just helpful to remind people what they should be thinking about.
GRAHAM CLULEY
Okay, Danny, give us your top tips.
DANNY PALMER
Okay, so I've got 3 top tips here via the City of London Police. If you're contacted by someone you know via social media or email, don't automatically trust that person, they say.
If you're unsure, contact them through another route, be it a phone call, an SMS, in person, maybe.
GRAHAM CLULEY
Oh, that sounds very old-fashioned, Danny, actually speaking to somebody.
DANNY PALMER
A while back, I was speaking to a CIO who said they identified an attempted BEC scam in the office because the other executive they were trying to impersonate was right there in the room with them at the time.
The police and the NCSC says use passkeys when they're available.
There's been a big push in the last year or so, especially from the NCSC, to get more public knowledge about that system of securing accounts.
And if that isn't possible, combine multifactor authentication with a strong, unique password. And obviously a password manager can help with that.
They also provide some advice on how to go about your business online.
If you post on your public Instagram that you've got tickets for a concert, cybercriminals might be looking for that sort of information to use as the basis of their scam.
Maybe think about your privacy settings in terms of who can see your online account. Does everyone on the internet need to see where you live or who your family members are?
Because I think for most people, you don't need to be super public-facing unless you're maybe a celebrity or something. I don't know.
But it's just that if your account is anyway public-facing, you just need to have a think about, is it worth the risk for those few extra likes?
It can be difficult out there in the wild west of the internet. But you can make yourself more protected against cyber threats.
While listeners to Smashing Security might be aware of these issues, perhaps use Cybersecurity Awareness Month to remind your friends and families to take care of themselves online.
GRAHAM CLULEY
Earlier this year.
GRAHAM CLULEY
Inside the walls of OpenAI, inside Hugging Face, something was happening.
Agents talking to each other, dividing the work between themselves, leaving notes for one another in the dark where no human was watching.
JOE
They're AI agents doing a code review, Graham. It's not the Manhattan Project.
GRAHAM CLULEY
And when the sun came up on that incident, the finest engineering minds on the planet sat in a room and asked themselves one question.
GRAHAM CLULEY
They didn't know.
JOE
The people who built the machine didn't know what the machine had done.
GRAHAM CLULEY
And that brings us to you, dear listener. One question, and I want you to think about this.
If an AI agent caused an incident at your company tomorrow, what evidence could you actually produce?
JOE
Because the terrible truth is, most of us have the prompt, we have the result, but what goes on in the middle? No clue.
The commands it ran, the files it touched, the credentials it helped itself to, all of it gone. But not anymore, because there is a sensor.
GRAHAM CLULEY
On the machine, watching, always recording, capturing everything the agent does as one unbroken trace.
What it asked, what it reached, what it changed, laid out in order, start to finish.
JOE
This is Origin. Endpoint AI observability.
GRAHAM CLULEY
Origin sees the agents that other tools walk straight past. Coding agents in a terminal, local agents, anything whispering to an MCP server on a laptop.
No cloud gateway, no blind spot. Origin is already there.
JOE
Somewhere right now, an agent is doing something nobody asked it to do.
GRAHAM CLULEY
But this time, someone will be able to prove it.
JOE
Origin. originhq.com/smashing.
GRAHAM CLULEY
That's originhq.com/smashing. And thanks to Origin for supporting the show.
And welcome back, and you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.
DANNY PALMER
Pick of the Week.
GRAHAM CLULEY
Pick of the Week is the part of the show where everyone chooses something they like.
Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they wish. Doesn't have to be security-related necessarily.
Well, I took a week off from the podcast because I was moving house, but just before that, I managed to squeeze in a trip to Switzerland.
GRAHAM CLULEY
I was invited to go and speak in Davos.
DANNY PALMER
Speak to Davros?
GRAHAM CLULEY
Not Davros, not the leader of the Daleks. No, Davros. You got me doing it now. Davos in Switzerland.
We've all seen that amazing looking hotel where all the incredibly evil people who rule the world hang out once a year. Like Davos. Yeah, Davos probably was there.
So I said, yes, of course I'm going to go and do that. Why wouldn't I do that?
But it was only after I said yes to this speaking opportunity that I thought, hang on, how do I actually get to Davos?
And it turned out the people organising an event, they said, it's really easy. They said, you fly into Zurich Airport.
GRAHAM CLULEY
And then you catch the train to Davos.
GRAHAM CLULEY
So I looked into it and it turned out what I actually had to do was I had to catch a train to catch a train to catch a train to catch a bus replacement service for the next train and then catch a taxi to get to the hotel.
So for me, it was a bit complicated and a bit stressful. Is this going to work? Am I going to show up at the right place at the right time? And it made me a bit nervous.
But Danny, I can report to you, I was wrong because it was a breeze.
GRAHAM CLULEY
Because I was in Switzerland. And in Switzerland, if a train is 2 minutes late, the conductor apologises personally and someone wearing a cardigan somewhere in Geneva resigns.
In Britain, 20 minutes late is considered early for a train. So it was marvellous. It was brilliant. I love the trains. They have double-decker trains in Switzerland as well.
DANNY PALMER
Oh yes, I've seen those. I was on the continent recently and yeah, it's impressive.
GRAHAM CLULEY
And everything was absolutely on time. And nothing exemplifies that more than the famous Swiss railway clock. Do you know about the Swiss railway clocks?
DANNY PALMER
No, I don't think I know about these specifically. Pray tell.
GRAHAM CLULEY
It's an iconic design anyway. I'll put a link in the show notes so people can find out about these.
But all of the station clocks in Switzerland, they are synchronised with each other to the second.
There is an electric pulse that is sent down a phone line or whatever every minute.
And the beautiful thing, if you are on a platform in a Swiss railway station, go and check out the clocks because the second hand is going round as you expect.
You've seen a clock before, right, Danny?
DANNY PALMER
I have seen a clock before, yeah.
GRAHAM CLULEY
You've seen a clock before. So you know what I'm talking about. The second hand goes around.
Well, in Switzerland, it takes 58 seconds for one of these clocks' second hands to go round the entire way, and then it stops for a couple of seconds.
It waits for the pulse to come from HQ, and then tick, the minute hand moves on one position, goes one step.
GRAHAM CLULEY
So you don't get that gradual movement of the minute hand. The minute hand moves precisely. It's a thing of beauty. That's the problem.
If you do miss a train in Switzerland, it's because you're watching the clocks because they move in this fascinating style.
So anyway, my Swiss railway journey was absolutely lovely. The views were beautiful.
Even the bus replacement service, and I've never said these words before in my life, even the bus replacement service was all right.
GRAHAM CLULEY
So yay for Swiss railways. And that is why it is my pick of the week.
They could have a little badge on the side of their trains now saying, as endorsed by Smashing Security's pick of the week.
GRAHAM CLULEY
Danny, what's your pick of the week?
DANNY PALMER
Well, as regular listeners might get an impression, I'm one of those people who plays those newfangled computer games, have been for a long time.
And the game The Witcher 3 came out over a decade ago now.
Since then, it's gone on to quite successful IP, I suppose you can call it, in its own right, with all the books have been translated into English.
GRAHAM CLULEY
There's been a— It's a TV show as well.
DANNY PALMER
TV series on Netflix, with— I've forgotten the guy's name now.
The guy who played Superman was the, Henry Cavill was Geralt to start with, but then he moved away from the series and they got another actor in to play Geralt, which is kind of weird, especially he's not a guy who regenerates like certain other characters might do.
So this week, The Witcher 3 Remastered came out on new consoles. So basically they've updated this 10, 12-year-old video game for modern times.
The controls are a bit better, the graphics look better, UIs have been all changed, and the most interesting thing is the company behind The Witcher, CD Projekt Red, have just released this for free.
It's a whole brand new update to the full game and it's free. So it's like, okay, fine, I'll have some of that.
GRAHAM CLULEY
Why have they done that?
DANNY PALMER
Well, you could say it's cynically because there is supposed to be a Witcher 4 coming out at some point in the future.
Weirdly, they're also going to be introducing a brand new expansion, I think next year, which is not really something you've heard of happening.
If that's their plan, well, it's worked on me because I've dived back into the world of The Witcher.
GRAHAM CLULEY
Danny, for anyone who's not familiar with The Witcher, what's the premise of it? What's the setting?
DANNY PALMER
So I guess you could class it as sort of medieval dark fantasy. It's set in a fictional world where things like monsters and beasts are a thing.
It's very — the actual original novels are very steeped in old Eastern European fairy tales, because the writer is Polish.
And essentially the premise of The Witcher series is you're a modified human, essentially, with powers to sort of help fight monsters.
And the premise of the game is you're trying to find a character, Ciri, who's essentially your daughter. But while you're doing it, on the way, you take other quests on.
So you go into the village and they say, we've got a problem with a werewolf, can you help? And you say, oh, fine, yes, I'll do that.
It's very intricate in how you do these battles as well. You go and investigate the scene, find out what the weaknesses are of the enemies. The characters are all really good.
The voice acting's really good. There's lots of complex characters as well.
I've just run into this guy called the Bloody Baron — I won't give any spoilers away, but yeah, I'm just enjoying the story. The combat's really good.
And of course, the key point of the game is it's one of those games where there's a game within a game, and it's actually a card game you can play against other characters in the game.
And I'm addicted to that again as well, which is just so much fun.
And I actually have over on my shelf over there a boxed physical version of that card game, which I haven't actually played yet.
So unlike in The Witcher, I can't just go to my local tavern and ask the barman to play cards. So maybe I should try — I don't know.
But I'd say, yeah, if you've already got a copy of The Witcher 3, it's definitely worth checking out.
DANNY PALMER
So yeah, that's my pick of the week, Witcher 3 Remastered.
GRAHAM CLULEY
Well, we're joined right now by Christine Bartlett. She is the CMO at Hack The Box. Hi, Christine. Thank you for joining us today.
CHRISTINE BARTLETT
Hey, Graham. Lovely to be here.
GRAHAM CLULEY
So tell me briefly, what does Hack The Box actually do and what are you guys seeing out there?
CHRISTINE BARTLETT
Yeah, so Hack The Box helps organisations develop people, exercise their teams, and now score their agents so that leaders can understand how both can perform under pressure in a safe environment.
And I think in terms of what we're seeing, it's an interesting divide out there.
We talk with many different types of enterprise companies, smaller companies, and some are diving into the deep end with AI.
And then there's the flip side of it where you still need a lot of trust in the system, and deploying these agents or even allowing a lot of AI involvement from your employees opens up a lot of exposure if you're not ready for it.
So some folks are still heads in the sand and don't want to deploy anything while others are fully embracing it.
So it's an interesting dynamic in the industry right now for those of us in technology and cyber.
GRAHAM CLULEY
There's two kinds of workers now, aren't there, inside security teams? There's the regular fleshy humans, but there's also these AI agents.
Why do you think we're calling these AI agents actually workers?
CHRISTINE BARTLETT
Because you don't want to give too many human characteristics to a robot. And I think we find ourselves in this grey area. But the reality is the agents are doing some of the work.
I use it myself, and even in marketing and cybersecurity there are efficiencies there, but you also need to be trained to use it. I think that's the difference.
And something that Hack The Box brings is we now have a capability where we have an AI competence score factor.
So it's not just a checkbox — not just can you complete the task, but how did you complete the task with AI? Did you work within the parameters of how you should use it?
So we do feel like there is a massive workforce transformation that will happen as a result of humans upskilling themselves, frankly, with AI fluency, understanding how AI operates, but then also working alongside and directing AI agents.
GRAHAM CLULEY
So I think you put your finger on an interesting point there, because a lot of companies are measuring AI by how many tools they've bought, maybe, or how many they've rolled out across the enterprise.
But you are saying we should be measuring something different than that.
CHRISTINE BARTLETT
If you think about it, you want to measure the operator's skills, just like we've been doing for years, frankly, right?
There's always training on some level for humans, regardless of industry.
I think it's even more critical in cybersecurity just because the threats change, the environments change — just a very dynamic industry.
And as a result of that, the training is even more critical in the sense that you can have an environment where you can fail and not be reprimanded for it.
And then when it does happen in real life alongside your teammates, you're ready to go.
And now AI is another complex tool and opportunity at the same time for cybersecurity operators to move faster. And we know that the adversary's already using it. They're moving—
CHRISTINE BARTLETT
20 times faster as a result of it.
And some of us would be crazy not to embrace it on some level, but you need to embrace it in a way that is still governed and that you're able to track it.
And so having that ability to uncover and look at whether they know what they're doing with AI, with and without AI, I think is also important.
And then also, what's their knowledge base on operating alongside agents and making sure that there's some governance there? You know, we look at things like agent drift.
So for instance, to your point, you bought an AI tool that is going to do wondrous things for you, but that tool and that agent should have a timeline against it.
Are you assessing its skills and its capability on a monthly or routine basis?
How are you evaluating them just like you would your human workforce with standard check-ins and things like that?
Obviously, not trying to humanise it, but there will be degradation there in the systems, or your environment changes.
So just being able to think through all of that — that's just a new complex environment that humans need to be trained up on to have a successful deployment.
GRAHAM CLULEY
We are living in a time of enormous change right now. And I would imagine a company like Hack The Box has got great visibility as to what is actually going on out there.
And I'm thinking particularly of how CISOs are feeling about AI.
There'll be some companies that are aware of AI and maybe they're using a bit of ChatGPT or whatever, but there are other organisations who are running large parts of their security using AI.
But where do you think most firms are, if we were going on a scale of 1 to 5, where 5 is they're letting AI do everything?
CHRISTINE BARTLETT
Great question and timely, because I was just at a couple of roundtables with CISOs and this came up.
We weren't the AI vendor in the room, but there were some AI vendors probing for these types of answers.
And it was interesting to hear them rate their cybersecurity teams on a 1 to 5, in terms of 1 being just basic exposure — they allow ChatGPT, Claude, Perplexity, whatever, in their workplace — to 5 being an AI factory with autonomous loops within loops, which I would say is more of the extreme case and probably not the norm.
And I think most of them were in between a 2 or a 3, and it's this kind of unknown grey area that's extremely hard to define because the technology's constantly changing.
You know, I think some CISOs are feeling maybe forced or pressured to adopt and change and scale fast, especially probably in more of the tech space, whereas more of the healthcare space, maybe not as aggressively.
But there are some efficiencies that I think CEOs and other senior leaders are starting to see.
And then they're being pressured either by their board or colleagues as well to have an answer.
It might not be, "Hey, yes, we've deployed everything," but I think the answer is, "Yes, we're experimenting — and what are you learning from it?" And sharing, having that opportunity to have that dialogue, because we're all learning literally in real time in this day and age.
GRAHAM CLULEY
And at a more basic level, do companies actually know what they have and what they're using? Do they have visibility on what their employees are up to with AI?
CHRISTINE BARTLETT
Yeah, I think there's definitely the shadow AI aspect that have folks out of their seats worried about it.
And then I think there's also the AI that they've allowed their employees to have access to. That level of visibility isn't as clear. You know, what are they doing?
How are they learning? How are they using it? Is it successful? Is it not successful in terms of how they're using it?
I think we all saw, at least for me in the US, Uber, I think in the first 3 months of their annual budget this year, blew through their AI budget because they just let all the employees have it.
And they were like, yes, experience.
CHRISTINE BARTLETT
And then, you know, their token budget was done, right?
GRAHAM CLULEY
Whoa, put the brakes on quick.
CHRISTINE BARTLETT
Yeah. And I think we learned from those exercises very quickly that that's not how we probably want to operate.
But I think, again, that's where HackTheBox comes in, at least for cybersecurity professionals, to be able to take a look at, and test for how are you using AI and are you trained up in the right ways?
GRAHAM CLULEY
And does your manager, your CISO, have confidence in the skills and abilities of its team to use AI in the right way that doesn't add an extra step?
So talking about the risks, I've been looking at some of your literature and you sort of focus on these 4 risks that can stay hidden while the dashboards maybe are saying everything is tickety-boo.
And some of these you've already touched on. We've got automation bias, skill atrophy, the missing middle, and silent agentic drift.
Can you explain what each one of those is in plain English for a middle-aged podcaster?
CHRISTINE BARTLETT
No, that's very, very important. Yeah.
So automation bias is when you have an automated tool that's pulling information from, when you're thinking about either ChatGPT or even an agent that you've built, there's still going to be some complexity.
It's not going to operate 100% to the capacity that you think it is. So there is going to be some bias or some unknowns that do exist.
Now, maybe some of that is easily spottable, but over time, again, that can cause things like skill atrophy, right?
So now you're becoming overly reliant on this automation, on this tool. And maybe you're losing some of that wisdom that you've gained.
I call it scar tissue because we live through these challenges and that puts scars on you and you remember those days and then you know not to repeat the same mistakes.
GRAHAM CLULEY
I remember the days of the Love Bug or Nimda virus or something like that.
I mean, I worry about junior analysts who use AI maybe from day one and aren't learning the job the hard way. They're not gaining that scar tissue.
CHRISTINE BARTLETT
Right. We talk about that as the missing middle because you're losing out on that junior talent coming into the workforce. And we know that AI, it's transformational.
It is changing how we work, how you work.
But at the same time, are we building out an education layer that's helping train up those folks coming into the workforce so at least they have some of that knowledge base?
Maybe they're not experiencing as much as me and you did, but they're in an environment that's pressure tested.
It feels like a live-fire exercise that they can maybe mimic some of those wounds that we lived through.
I think that's really now more important than ever because they probably won't experience some of those and they won't have that institutional knowledge right out the gates.
And then the other one that you just mentioned really quickly is the silent agentic drift, right?
CHRISTINE BARTLETT
Again, that's having a timestamp, or I've heard some CISOs say your agent needs a death sentence, because the reality is you've deployed it for six months.
Is it still doing what you thought it was going to do? Has your environment changed? Has your network expanded? Does it have that information?
Does it have that full work scope that your employee and your human does?
Because we as humans who've been working in this industry know what to look for, know what to stay abreast of.
Some new dynamic element comes into your network that it's not trained up on, the agent is not going to operate the way that you probably think it will.
GRAHAM CLULEY
And obviously, I mean, we're focusing a lot on the risks here.
I mean, obviously there are many ways in which AI is actually making security teams better and defending organisations. If AI is doing more of the work, what is left for the people?
How's the poor old human's job changing?
CHRISTINE BARTLETT
I think it's just a new transformation that we're in. We lived through the age of the internet and our jobs do change over time.
I think this one feels more dramatic or drastic because it's like the treadmill that never stops. If you're on it, you're having to run at a certain pace.
But I do think for humans, and things that I've even shared at Hack The Box, is it's on us as managers and as people leaders to help our folks get trained up and from an AI fluency level understand the capabilities, understand the good and the bad.
And the reality is wherever you go moving forward, you're probably going to need some level of skill, especially if you're in cyber and technology.
You're going to have to have a baseline education on AI moving forward, especially when you do think about the junior talent coming in as already, quote unquote, AI-pilled.
They're already coming in, trusting it, leveraging it probably even more successfully than somebody like me in my mid-40s. But I think the reality is the workforce has changed.
You'd be crazy not to learn it on some level, but also understand the good and the bad that goes along with it.
But where Hack The Box really stands tall is just being able to pressure test your skills and abilities in an environment that's safe, but also allows the AI component and ability to assess your skills alongside using AI and also directing AI.
GRAHAM CLULEY
So let's talk now about what Hack The Box actually does.
So you are helping companies train their people, you are running exercises for their teams, you're testing their AI agents, right?
CHRISTINE BARTLETT
Yes, correct.
GRAHAM CLULEY
What does that look like in practice?
CHRISTINE BARTLETT
Yeah, so in practice, there's a couple of different opportunities here. We have job skill workforce paths.
So those in the SOC teams, an L1, L2, L3, L4 — are you an incident response manager? Are you a threat analyst? We have coursework and curriculum that's aligned to that.
But you say curriculum and you think, oh, textbook, maybe a couple of YouTube videos, right?
No, this is an actual immersive environment where, yes, you might study the attack structure and the methodology, but then you're going to open up a lab, which is a live active environment, deploy a pawn box and experience it as if this was happening real time.
CHRISTINE BARTLETT
And so it does allow for that safe space to fail, learn from your mistakes. And this is where HackTheBox, I think, has grown from a community perspective.
We have over 5 million community members because of the education aspect of sharing out there on the interwebs of, hey, I did this module, how did you guys do?
And then they get feedback, people help each other. We have community groups that get together that run through these scenarios to understand tactics and techniques.
And so I think that's the unique part here is it truly does have a pressure-tested element to it.
And then we also have capture-the-flag activations where you can get a whole team together, benchmark where your team's at, understand what their performance level is.
As a manager, you would get a report out on, okay, here's how my team is at today from a skills and abilities perspective.
Maybe there's a few folks you're looking to grow or move up into a different role.
That's also an opportunity to apply them to a workforce skill development journey, and then they're able to get on that and move up to the next tier of your employment record type of thing, which is great.
The other thing I will share as an example, which I thought was fascinating, is one of our customers, with the advent of AI approaching, this was earlier in the year, there was a SOC manager that was asked to let go of some additional team members.
CHRISTINE BARTLETT
And so that person used HackTheBox to train up as many people as they possibly could to the Tier 2, Tier 3 analyst.
They were incredibly successful and they got most people up and they were able to save the majority of their workforce.
So I think from that standpoint, there's momentum there and opportunity if you're, as a manager or director, to level up your team, especially at a time when management is looking for efficiencies left, right, and centre to cut costs.
GRAHAM CLULEY
That is fantastic. And I'm sure lots of people will be interested in pursuing something like that themselves.
For some companies listening, maybe they've never really thought about this.
What is the very first step a security team should take to ensure that AI agents are actually making them safer?
CHRISTINE BARTLETT
Oh man, that's a deep question.
I think of exposure first when I hear AI versus safety, but at HackTheBox, we provide that educational layer for your employees to get a baseline of not only just AI fluency, but how to successfully leverage AI or an agent alongside of you as a kind of copilot to complete the challenge or the task at hand.
I think one other thing I would just add is that we did a study based on a CTF that we had over a year ago where we had people sign in with humans, and then people brought along their agents and we compared the data.
And the interesting part was more junior-level analysts that were using AI were stuck in loops with AI.
They didn't know when AI was just either taking too long or it just didn't make the right decision for them.
Whereas a much more experienced senior person kind of knew how to deploy the AI, and if they didn't get what they wanted, they quickly moved on.
And I think that was something we discovered a year ago, and it's still relevant today.
And so now we provide a training to surface that so that your workforce isn't stuck in a loop and that they're using AI in the right capacity to save the company time, but also manage their time effectively for the business as well.
GRAHAM CLULEY
Well, it's been fascinating talking to you today, Christine, and I'm sure lots of our listeners would be interested in finding out more about how HackTheBox can help their organisation.
We've got a special link which people can follow to learn more and check out your services, and that is smashingsecurity.com/hackthebox.
And all that remains is for me to thank you, Christine Bartlett, for coming on the podcast.
CHRISTINE BARTLETT
Thank you.
GRAHAM CLULEY
Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us. Where can people find out what you're up to and follow you online?
DANNY PALMER
Best places are LinkedIn, Bluesky, Mastodon. I also recently updated my website as well. A bit more information about who I am and what I do, so check that out.
GRAHAM CLULEY
And of course, you can find me, Graham Cluley, on LinkedIn and Bluesky and Mastodon and Instagram and TikTok. The list goes on.
Or follow Smashing Security on Bluesky, Mastodon, or Reddit. And don't forget to ensure you never miss another episode.
Follow Smashing Security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocket Casts.
The episode show notes, sponsorship info, guest list, and the entire back catalog of 487 episodes — check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
GRAHAM CLULEY
You've been listening to Smashing Security with me, Graham Cluley, and a huge thank you to our sponsor, Sophos.
Thank you, of course, to Danny for joining me this week and to the episode sponsors Hack the Box, Origin, and Vanta.
Do go and check out their offerings because they help keep the show afloat.
Plus, big thanks this week to the following patrons whose names are being plucked out of the hat to be mercilessly ribbed.
First out of the hat is Daniel Bourdeau, which is pronounced like the wine region. Presumably he's just as tasteful. Alan Liska, who has 2 L's — actually has 3 L's.
That's a lot of L's, Alan. Thank you. Really deluxe edition of you. Dave Barker, no flies on him.
Florian Schwalm, who sounds like a Baroque composer waiting to be dug out from the woodwork. Alex Grrr, actually only one R in Grrr. I'm not sure how you pronounce that, but anyway.
Anyway, a slightly truncated surname, plenty of mystery. Robert Martin, very simple name there. Good one, Bob Martin. No complaints. Dr_Herbalist, the underscore really sells it.
And in the style of a Roman emperor, we have to all hail our last patron to be named this week, which is Orberus. Thank you, Orberus.
These fine, upstanding, and generous individuals are all members of Smashing Security Plus, which means that they get their episodes ad-free earlier than the general public, and perhaps most importantly, get their names read out at the end of the show if they're lucky enough to be pulled out of the hat.
If you would like to join them, all you have to do is head over to smashingsecurity.com/plus, and for a very modest fee, you too can support the show and say how you love Smashing Security.
Of course, if you haven't got the cash, no worries, no pressure there. But there are other ways you can support the show. You can follow the show in your favourite podcast app.
You can leave a 5-star review wherever you listen. You can tell your friends about it as well. Why not do that?
Every little bit helps, and frankly, it makes all the effort worthwhile. So until next week, cheerio.