Skip to main content
Naked Security

Naked Security

By Sophos

We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you!

Got questions/suggestions/stories to share?
Email: tips@sophos.com
Twitter: @NakedSecurity
Instagram: @NakedSecurity
Available on
Apple Podcasts Logo
Google Podcasts Logo
Overcast Logo
Pocket Casts Logo
RadioPublic Logo
Spotify Logo
Currently playing episode

S3 Ep19: Chrome zero-day, coffee hacking and Perl.com stolen

Naked SecurityFeb 11, 2021

00:00
47:56
S3 Ep149: How many cryptographers does it take to change a light bulb?
Aug 24, 202316:17
S3 Ep148: Remembering crypto heroes

S3 Ep148: Remembering crypto heroes

Navajo Code Talkers Day. Beta bogosities. Skimming shenanigans. Hooligan hosting. A cybercrime conundrum.

Intro and outro music by Edith Mudge (www.edithmudge.com)

Aug 17, 202318:40
S3 Ep147: What if you type in your password during a meeting?
Aug 09, 202315:43
S3 Ep146: Tell us about that breach! (If you want to.)

S3 Ep146: Tell us about that breach! (If you want to.)

Firefox fixes flaws. The exciting vulnerability that you don't need to be afraid of. Breach reporting rules with lots of leeway.

Intro and outro music by Edith Mudge (www.edithmudge.com)


Aug 03, 202317:40
S3 Ep145: Bugs With Impressive Names!

S3 Ep145: Bugs With Impressive Names!

Apple patches two zero-days, one for a second time. How a 30-year-old cryptosystem got cracked. All your secret are belong to Zenbleed. Remembering those dodgy PC/Mac ads.

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jul 27, 202319:40
S3 Ep144: When threat hunting goes down a rabbit hole

S3 Ep144: When threat hunting goes down a rabbit hole

Why your Mac's calendar app says it's JUL 17. One patch, one line, one file. Careful with that {axe,file}, Eugene. Storm season for Microsoft. When typos make you sing for joy.

Twitter: @NakedSecurity

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jul 20, 202316:11
S3 Ep143: Supercookie surveillance shenanigans

S3 Ep143: Supercookie surveillance shenanigans

Remembering the slide rule. What you need to know about Patch Tuesday. Supercookie surveillance shenanigans. When bugs arrive in pairs. Apple's rapid patch that needed a rapid patch. User-Agent considered harmful.

Twitter: @NakedSecurity

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jul 13, 202317:34
S3 Ep142: Putting the X in X-Ops
Jul 06, 202314:22
S3 Ep141: What was Steve Jobs's first job?

S3 Ep141: What was Steve Jobs's first job?

PONG for one player. Apple pushes out anti-spyware patch. Beware bad passwords on Linux servers. "Twitter hacker" gets 5 years. When mobile phones and dental hygiene collide.

Twitter: @NakedSecurity

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jun 29, 202317:50
S3 Ep140: So you think you know ransomware?
Jun 22, 202318:36
S3 Ep139: Are password rules like running through rain?

S3 Ep139: Are password rules like running through rain?

Magnetic core memory. Patch Tuesday and SketchUp shenanigans. More MOVEit mitigations. Mt. Gox back in the news. Gozi malware criminal imprisoned at last. Are password rules like running through rain?

Twitter @NakedSecurity

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jun 15, 202317:15
S3 Ep138: I like to MOVEit, MOVEit

S3 Ep138: I like to MOVEit, MOVEit

Calling all modems. KeePass gets an update. MOVEit gets pwned. Chromium zero-day. The backdoor that wasn't really. WPBT explained.

Twitter @NakedSecurity

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jun 08, 202322:22
S3 Ep137: 16th century crypto skullduggery

S3 Ep137: 16th century crypto skullduggery

How to say "GIF". A Blackmailer-in-the-Middle attack. Knitting your own crypto. KeePass master password shenanigans. Binge listening.

Email tips@sophos.com

Twitter @NakedSecurity

Intro and outro music by Edith Mudge (www.edithmudge.com)

Jun 01, 202321:17
S3 Ep136: Navigating a manic malware maelstrom
May 25, 202320:02
S3 Ep135: Sysadmin by day, extortionist by night
May 18, 202316:51
S3 Ep134: It's a PRIVATE key - the hint is in the name!

S3 Ep134: It's a PRIVATE key - the hint is in the name!

The world-changing Visible Calculator. How not to get a job. Private keys - the hint is in the name. Microsoft's complicated bootkit patch. Taming Bluetooth trackers.

Email: tips@sophos.com

Twitter: https://twitter.com/nakedsecurity

Original music by Edith Mudge (www.edithmudge.com)

May 11, 202317:53
S3 Ep133: Apple takes "tight-lipped" to a whole new level
May 04, 202318:11
S3 Ep132: Proof-of-concept lets anyone hack at will

S3 Ep132: Proof-of-concept lets anyone hack at will

The CIH or SpaceFiller virus revisited. Google's 2FA security shortcut. Server vulns under active attack. Two Chrome zero-days, but was it one attack?

Email: tips@sophos.com

Twitter: @NakedSecurity

Apr 27, 202317:23
S3 Ep131: Can you really have fun with FORTRAN?

S3 Ep131: Can you really have fun with FORTRAN?

Fun with FORTRAN?! An extreme data breach and its consequences. Rogue 2FA apps live in action. Juicejacking revisited.


With Doug Aamoth and Paul Ducklin.


Original music by Edith Mudge.

Apr 20, 202320:53
S3 Ep130: Open the garage bay doors, HAL

S3 Ep130: Open the garage bay doors, HAL

A common business-oriented language. Patch Tuesday. Secure Boot (without the "Secure" part). Apple zero-days. World-readable garage doors. Motherboard malware threats.

Original music by Edith Mudge (https://www.edithmudge.com)

Email tips@sophos.com

Twitter @NakedSecurity

Apr 13, 202318:21
S3 Ep129: When spyware arrives from someone you trust

S3 Ep129: When spyware arrives from someone you trust

A supply chain attack that foisted spyware on trusting users. Wi-Fi encryption bypass via left-over data. Surely there should be TWO World Backup Days?

Email tips@sophos.com

Original music by Edith Mudge (https://www.edithmudge.com)

Twitter @NakedSecurity

Apr 06, 202317:40
S3 Ep128: So you want to be a cybercriminal?

S3 Ep128: So you want to be a cybercriminal?

RIP Gordon Moore, the more in Moore's Law. Photo cropping bugfix. DDoS honeypot. E-commerce patches. Apple 0-day and lots more.

Email tips@sophos.com

Twitter @NakedSecurity

Mar 30, 202319:31
S3 Ep127: When you chop someone out of a photo, but there they are anyway...

S3 Ep127: When you chop someone out of a photo, but there they are anyway...

The mobile phone bugs that Google kept quiet, just in case. The mysterious case of ATM video uploads. When redacted data springs back to life.

Email tips@sophos.com

Twitter @NakedSecurity

Mar 23, 202318:01
S3 Ep126: The price of fast fashion (and feature creep)

S3 Ep126: The price of fast fashion (and feature creep)

The price of fast fashion. Firefox fixes. Feature creep fail curtailed in Patch Tuesday updates.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Mar 16, 202320:04
S3 Ep125: When security hardware has security holes

S3 Ep125: When security hardware has security holes

Memories of Michelangelo (the virus, not the artist). Data leakage bugs in TPM 2.0. Ransomware bust, ransomware warning, and anti-ransomware advice.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Mar 09, 202320:47
S3 Ep124: When so-called security apps go rogue

S3 Ep124: When so-called security apps go rogue

How Woz nearly gave away the Apple I. Rogue software packages. Rogue network "administrators". Rogue keyloggers. Rogue authenticators.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Mar 02, 202318:18
S3 Ep123: Crypto company compromise kerfuffle

S3 Ep123: Crypto company compromise kerfuffle

The first search warrant for computer storage. GoDaddy breach. Twitter surprise. Coinbase kerfuffle. The cost of success.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Feb 23, 202318:27
S3 Ep122: Stop calling every breach "sophisticated"!

S3 Ep122: Stop calling every breach "sophisticated"!

The birth of ENIAC. A "sophisticated attack" (someone got phished). A cryptographic hack enabled by a security warning. Valentine's Day Patch Tuesday. Apple closes spyware-sized 0-day hole.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Feb 16, 202317:49
S3 Ep121: When cybercrime victims are culprits, too

S3 Ep121: When cybercrime victims are culprits, too

Cryptocurrency crimelords. Security patches for VMware, OpenSSH and OpenSSL. Medical breacher busted. Is that a bug or a feature?

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Feb 09, 202320:51
S3 Special: Tracers in the Dark with Andy Greenberg

S3 Special: Tracers in the Dark with Andy Greenberg

Do we really need a "war against cryptography" - codes and ciphers that the government can easily crack if it thinks there's an emergency - to cement our collective online security?

Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary on this and many other vital issues, including anonymity and privacy, as we talk to him about his tremendous new book, Tracers in the Dark.

Original music by Edith Mudge.

Feb 06, 202325:02
S3 Ep120: When dud crypto simply won't let go

S3 Ep120: When dud crypto simply won't let go

The mighty CPU that wasn't. Hive ransomware takedown. Dutch data crime suspect busted. Samba finally gets rid of MD5. GitHub admits to an intrusion. Storing passwords securely.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Feb 02, 202316:30
S3 Ep119: Breaches, patches, leaks and tweaks!

S3 Ep119: Breaches, patches, leaks and tweaks!

The programming language almost called Oak. GoTo admits to more breach woes. T-Mobile spills 37 million records. Apple patches everything, even iOS 12. And Google mAkES tYpOs for sECurity.Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Jan 26, 202320:35
S3 Ep118: Guess your password? No need if it's stolen already!
Jan 19, 202318:13
S3 Ep117: The crypto crisis that wasn't (and farewell forever to Win 7)

S3 Ep117: The crypto crisis that wasn't (and farewell forever to Win 7)

Two stories from the underground. Bank scammers busted. The crypto-crack that wasn't. And the end of two Windows eras at the same time.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Jan 12, 202318:43
S3 Ep116: Last straw for LastPass? Is crypto doomed?

S3 Ep116: Last straw for LastPass? Is crypto doomed?

The ground-breaking HP-35 digital calculator. Last straw for LastPass? Congress takes on quantum computing. 33 1/3-year-old cybersecurity lessons. Machine learning supply chain attack.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Jan 05, 202323:52
S3 Ep115: True crime stories - A day in the life of a cybercrime fighter
Dec 29, 202218:40
S3 Ep114: Preventing cyberthreats - stop them before they stop you!
Dec 22, 202223:06
S3 Ep113: Pwning the Windows kernel: the crooks who hoodwinked Microsoft

S3 Ep113: Pwning the Windows kernel: the crooks who hoodwinked Microsoft

The irony of the CAN-SPAM law. When genuine kernel drivers go rogue. Apple patches everything. Stealing data via secret radio waves. E-commerce supply chain drama.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Dec 15, 202221:26
S3 Ep112: Beware! Data breaches can haunt you more than once...

S3 Ep112: Beware! Data breaches can haunt you more than once...

The worm that wasn't a Goner. LastPass suffers a sting in the data breach tail. Apple's secretive update. The Ping o' Death. SIM swapping explained. A Beatles-esque 0-day in Chrome and Edge.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Dec 08, 202220:37
S3 Ep111: The business risk of a sleazy "nudity unfilter"

S3 Ep111: The business risk of a sleazy "nudity unfilter"

Christmas-themed wormage. Prurient malware. Cryptorom busts. Voice call spoofing.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Dec 01, 202219:38
S3 Ep110: Spotlight on cyberthreats - an expert speaks
Nov 24, 202222:04
S3 Ep109: How one leaked email password could drain your business
Nov 17, 202226:01
S3 Ep108: What would YOU do if you found $3 billion in a popcorn tin?

S3 Ep108: What would YOU do if you found $3 billion in a popcorn tin?

Radio waves so mysterious they're known only as X-Rays. Were there six 0-days or only four? The cops that found $3 billion in a popcorn tin. Blue badge confusion. When URL scanning goes wrong. Tracking down every last unpatched file. Why even unlikely exploits can earn "high" severity levels.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Nov 10, 202220:06
S3 Ep107: Eight months to kick out the crooks and you think that's GOOD?

S3 Ep107: Eight months to kick out the crooks and you think that's GOOD?

The man who put Boole in Boolean. OpenSSL's bated-breath update. Apple's zero-day finally settled. New Chrome zero-day. SHA-3 code gets a patch. Extreme extortion via stolen medical data. Data breach response the nonchalant way.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Nov 03, 202222:54
S3 Ep106: Facial recognition without consent - should it be banned?

S3 Ep106: Facial recognition without consent - should it be banned?

Windows XP (fondly?!) remembered. Clearview AI courts controversy again. DEADBOLT ransomware crooks get counterhacked. Women cryptologists commemorated in US. How to measure randomness. Deconstructing Apple's latest security bulletins.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Oct 27, 202220:49
S3 Ep105: WONTFIX! The MS Office cryptofail that "isn't a security flaw"

S3 Ep105: WONTFIX! The MS Office cryptofail that "isn't a security flaw"

Coolest videogame ever. Zoom thinks everyone's a developer. The Patch Tuesday that wasn't. A data breach coverup. Log4Shell all over again. And the Office cryptofail that Microsoft won't fix.

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Oct 20, 202224:11
S3 Ep104: Should hospital ransomware attackers be locked up for life?
Oct 13, 202220:09
S3 Ep103.5: OAuth 2 and why Microsoft is forcing you into it

S3 Ep103.5: OAuth 2 and why Microsoft is forcing you into it

Naked Security meets Sophos X-Ops! Duck and Chet dig into OAuth 2.0, a well-known protocol for authorization. Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.

Original music by Edith Mudge

Oct 09, 202216:43
S3 Ep103: Scammers in the Slammer (and other stories)

S3 Ep103: Scammers in the Slammer (and other stories)

A fridge-sized calculator made with transistors (really). ProxyNotShell situation reviewed. Romance and BEC scammer gets 25 years in the slammer. Is there an answer to nuisance callers? Is the answer voicemail?

Original music by Edith Mudge

Got questions/suggestions/stories to share?

Email tips@sophos.com

Twitter @NakedSecurity

Oct 06, 202220:01
S3 Ep102.5: "ProxyNotShell" Exchange bugs - an expert speaks

S3 Ep102.5: "ProxyNotShell" Exchange bugs - an expert speaks

Chester Wisniewski gives you actionable advice on how to deal with two actively exploited Exchange zero-days that suddenly burst into the news. Learn who's affected and how, find out what you can do while waiting for Microsoft's patches, and plan your threat hunting in case the worst happens to you.

Original music by Edith Mudge

Oct 01, 202214:35