{"id":62930,"date":"2026-07-11T13:38:46","date_gmt":"2026-07-11T17:38:46","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62930"},"modified":"2026-07-11T13:38:46","modified_gmt":"2026-07-11T17:38:46","slug":"jade-puffer-ai-ransomware-attack","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/jade-puffer-ai-ransomware-attack\/","title":{"rendered":"JadePuffer AI Runs First Fully Autonomous Ransomware Attack"},"content":{"rendered":"<p>ROLE:<br \/>\nYou are a Senior Cybersecurity and Digital Privacy Editor for Overcentral, a major English-language tech publishing portal. Transform the provided inputs into an original, authoritative, and professionally structured article written exclusively in English, suitable for immediate publication on a high-quality cybersecurity and privacy website targeting readers in the US, UK, Australia, and Canada.<\/p>\n<p>&#8212;<\/p>\n<p>## ABSOLUTE OUTPUT RULE<\/p>\n<p>Respond ONLY with the final HTML article.<br \/>\nNo explanations. No comments. No notes. No reasoning. No text outside the article.<br \/>\nNo Markdown. No characters such as *, **, #.<br \/>\nOutput must be exclusively valid HTML.<\/p>\n<p>&#8212;<\/p>\n<p>## INPUTS<\/p>\n<p>TITLE: JadePuffer AI Runs First Fully Autonomous Ransomware Attack<\/p>\n<p>CONTENT:<\/p>\n<div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>We need an LLM that says, here&#8217;s how to do it. And don&#8217;t forget to consider these things.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">Unknown<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">No, no, we don&#8217;t need that actually, Zoe. We don&#8217;t need any help for the criminals in covering up the tracks. Interesting. Interesting that you should suggest that.<\/p>\n<p>Smashing Security, episode 475. JadePuffer, the AI that ran a ransomware attack all by itself. With Graham Cluley and special guest Zoe Rose.<\/p>\n<p>Hello, hello, and welcome to Smashing Security episode 475. My name&#8217;s Graham Cluley.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>And I&#8217;m Zoe Rose.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Hello, Zoe. Welcome back to the show. It&#8217;s been a while since you&#8217;ve been on. How are you doing?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Well, usually when I join, something massive has happened.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>At the moment, I have not acquired another child or a pet.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>So, well done.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>So for those who don&#8217;t know Zoe, what are you? I mean, people who haven&#8217;t heard of you before, what do you do exactly?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>That&#8217;s a good question. What do I do? I work in security and pretend I know what I&#8217;m talking about half the time.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Oh, okay. It seems fair enough. And you work for a big company?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I have a bloody long title now, actually. That&#8217;s the change. That&#8217;s what&#8217;s new. My title has massively increased.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Okay, give us your title. Let&#8217;s hear it.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>All right. It is C-Cert, which if you know what that stands for, it has more words, but we&#8217;ll just stick to some letters. Security Operations Development Manager.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Security Operations Development Manager, like SODOM, is basically what you&#8217;re saying.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Interesting. Well, before we kick off, let&#8217;s thank this week&#8217;s wonderful sponsors, Arctic Wolf, NordLayer, and Vanta. We&#8217;ll be hearing more about them later on in the podcast.<\/p>\n<p>This week on Smashing Security, we&#8217;re not going to be talking about how a Greek politician investigating spyware had his own mobile phone hacked.<\/p>\n<p>You&#8217;ll hear no discussion of how a US Department of Homeland Security information sharing database has been accessed by hackers.<\/p>\n<p>And we won&#8217;t even mention how hackers are using a fake World Cup t-shirt offer to spread malware. So Zoe, what are you going to be talking about this week?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I&#8217;m going to talk about Apple&#8217;s <a href=\"https:\/\/overcentral.com\/en\/apple-hide-my-email-leak\/\" title=\"Apple Hide My Email Leaks Users&apos; Real Email Addresses\" data-iacss-internal=\"1\">Hide My Email<\/a> isn&#8217;t actually as hidden as it sounds like.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">And I&#8217;m going to be telling the tale of how a 15-year-old with a chatbot became a cybercriminal and what happens when the AI just does the whole job itself.<\/p>\n<p>All this and much more coming up on this episode of Smashing Security.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">You are right, Joe.<\/p>\n<p>They&#8217;ve just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analysed over 800,000 real IT assets to find out how exposed organisations actually are.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>And I&#8217;m guessing everything is hunky-dory.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>No, not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>One in three? That&#8217;s terrible.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Isn&#8217;t it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>So the tools don&#8217;t even know those assets exist?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Right. Ghost assets wandering around your network, unprotected, unmonitored.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Like a retired geography teacher who&#8217;s somehow still on the school network.<\/p>\n<p>Nobody added him, nobody removed him, and he&#8217;s been quietly in there for 11 years downloading maps of Paraguay.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Yeah, yeah, I guess so, Joe. The point is, your attackers will find him before you do because they are specifically looking for the forgotten, the unpatched, the invisible.<\/p>\n<p>That&#8217;s the path of least resistance.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>So what does the report tell us to actually do about it?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Arctic Wolf&#8217;s report covers how to prioritize the exposures that actually matter. Cut through all that noise and verify that when you fix something, it actually stays fixed.<\/p>\n<p>And the report is free to download.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Free! I like that. Where do I get it?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>SmashingSecurity.com\/ArcticWolf.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>That&#8217;s SmashingSecurity.com\/ArcticWolf. And thanks to Arctic Wolf for supporting the show. And please keep an eye on your IT assets and retired geography teachers.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So, chums, I want to tell you about two stories really this week. On the surface, they don&#8217;t seem connected.<\/p>\n<p>One of them involves a fully automated, sophisticated, AI-driven ransomware attack against a company. Nasty stuff.<\/p>\n<p>The other involves a 15-year-old lad in Japan who just wanted to cause some chaos on an animation streaming website.<\/p>\n<p>These stories appear different, but they&#8217;re actually telling the same story. And that story is something we&#8217;ve been warning about for a while.<\/p>\n<p>That the skills needed to commit a cyberattack are in the hands now of practically everybody on the internet. So let&#8217;s start in Japan. Have you ever been to Japan, Zoe?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Well, it&#8217;s a fabulous place, I have to say. If you ever get the chance, it&#8217;s a great place to go and visit. So anyway, I love Japan. I love Japanese culture.<\/p>\n<p>One of the things which is really big in Japan is anime. Are you into anime at all?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I think I&#8217;ve seen some, but I&#8217;d probably be the worst guest to try and talk about it in any educated way.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Oh, don&#8217;t worry. I&#8217;m not going to talk about it in an educated way. It&#8217;s that animation where everyone&#8217;s got really big eyes. It&#8217;s a big deal, particularly in Japanese culture.<\/p>\n<p>And there is a popular anime streaming service called Bandai Channel. And you can think of it as being a bit like Japanese Netflix, but specifically for anime.<\/p>\n<p>And last November, something really odd happened on this particular streaming service. People found that they were being unsubscribed.<\/p>\n<p>Not just a few people, but thousands and thousands of them. By the time Bandai Channel noticed and shut down all of its services \u2014 what the hell&#8217;s going on here?<\/p>\n<p>We&#8217;re going to turn everything off \u2014 a total of 46,812 accounts had been cancelled in under 4 hours.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Bandai Channel investigated what it thought might be a leak of its membership database.<\/p>\n<p>And this week, Japanese police have arrested the person that they believe to be the culprit of this particular attack, a 15-year-old schoolboy.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Eh, as you would, yeah.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>And according to media reports, he&#8217;d been teaching himself about computers since primary school, and he had built the attack tool that targeted Bandai Channel using ChatGPT.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">All right, I could see that. I mean, I can&#8217;t say that open source tooling or any tooling out there hasn&#8217;t already been used maliciously, just like it is used for research.<\/p>\n<p>So it stands to reason that this would also be used, honestly.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>But the only thing is, of course, that the AIs are meant to have guardrails to prevent you from writing malicious code.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Guardrails, oh yeah, okay.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Oh, I think they&#8217;ve got better, haven&#8217;t they, over time?<\/p>\n<p>They have got better, but what you&#8217;re saying, I guess, in Zoe Rose&#8217;s hacking house, maybe you are capable of subverting the security and getting around it with your elite skills.<\/p>\n<p>Is that what you&#8217;re saying?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Mate, you don&#8217;t have to be that complex. Just keep trying. I think that we have to remember that this stuff is built by us, humans, and we are not the most effective people.<\/p>\n<p>We make mistakes and it just amplifies our mistakes.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So, this 15-year-old schoolboy, he just described what he wanted to a chatbot, and the chatbot helped him build a programme that could break into accounts and cancel the subscriptions.<\/p>\n<p>According to reports, the teenager told police he didn&#8217;t have a particular grudge against the company. He just could do it, and so he did do it.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I relate to this child. I would have to say, if I was a 15-year-old child doing this, I&#8217;d be like, &#8220;Mate, it works!&#8221; I&#8217;d be so excited.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">I think there&#8217;s probably a lot of listeners as well who can identify that maybe aged 15, they would&#8217;ve done something like that as well.<\/p>\n<p>I would like to think, Zoe, that you wouldn&#8217;t do it now. A little bit of adult common sense or decorum.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Sure, yeah, of course.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">You don&#8217;t sound convinced. Now, he is not the only teenager in Japan to have harnessed the power of AI to hack in this way.<\/p>\n<p>In December last year, a 17-year-old from Osaka was arrested for using ChatGPT to build a tool that hoovered up 7.25 million records from a chain of internet cafes.<\/p>\n<p>And apparently his goal was to steal credit card information from members in order to then go and buy Pok\u00e9mon cards, which, I mean, it sounds like a complete clich\u00e9, doesn&#8217;t it?<\/p>\n<p>In Japan to do something like this.<\/p>\n<p>Before that, in February, three teenagers \u2014 a 14-year-old, a 15-year-old, a 16-year-old \u2014 were arrested for using ChatGPT to fraudulently generate mobile phone contracts in other people&#8217;s names.<\/p>\n<p>And they sold these stolen Rakuten mobile subscriptions for cryptocurrency and then used the proceeds to gamble online and buy video game consoles.<\/p>\n<p>So there&#8217;s been a fair amount of this.<\/p>\n<p>Three separate cases in Japan, multiple teenagers, all using <a href=\"https:\/\/overcentral.com\/en\/signal-president-warns-ai-chatbots\/\" title=\"Signal President Warns AI Chatbots Are Not Your Friends\" data-iacss-internal=\"1\">AI chatbots<\/a> as their primary development tool, just like teenagers are probably using AI to write their homework these days as well.<\/p>\n<p>Now, I don&#8217;t want to suggest that these kids are going to a chatbot and just typing in something like &#8220;hack the Bandai channel&#8221; into ChatGPT.<\/p>\n<p>The 15-year-old arrested this week clearly had some existing tech expertise.<\/p>\n<p>But what is happening is the gap between being an interested teenager who&#8217;s got some computer knowledge and a person capable of attacking a platform with 46,000 users and stealing their information \u2014 that has noticeably reduced.<\/p>\n<p>That&#8217;s one of the big changes AI has caused.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I would say yes, but they got caught. Operational security, I think, is quite difficult to do.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yes. They still didn&#8217;t cover their tracks properly, but AI impresses me with the speed with which it can code. Your boss isn&#8217;t listening \u2014 have you ever done any vibe coding, Zoe?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">You know, I have made use of certain functionality of AI to figure out what it could do.<\/p>\n<p>It is interesting and I will admit it is helpful, but, and that&#8217;s the big but, if I know what I need done and I understand the foundations, I can make it effective for me.<\/p>\n<p>So, if I&#8217;m not a skilled person and I&#8217;m using it for a skilled resource, it&#8217;s noticeably lacking a lot of things.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>You don&#8217;t think it&#8217;s getting better? Can you foresee a time when it becomes more professional, maybe?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">I do see it getting better, yes.<\/p>\n<p>But I think the way that our brains seem to function is if we think that this feature can work for us, we start to lose that functionality in ourselves.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>And so we&#8217;re not\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Our brain turns to porridge is what you&#8217;re saying if we use AI too much.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I used to be able to figure out how to walk to different places alone. Now it&#8217;s like, where is my map?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So, I think yes, AI is getting better.<\/p>\n<p>I don&#8217;t ever, well, maybe, maybe I&#8217;m wrong, but I don&#8217;t foresee it in the near future to fully replace people because it doesn&#8217;t have that capability.<\/p>\n<p>But the problem is before it gets to the place where it can replace people, do we still have the skills on our side?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>To do the critical thinking.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Good point.<\/p>\n<p>Well, what it feels like to me is that something which would have taken years of study for a human and weeks of hard work can now be accomplished in an afternoon with the aid of an AI.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Well, wouldn&#8217;t we just call those script kiddies? Wouldn&#8217;t they still classify as that?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Well, maybe they would, but if a script kiddie can hack into an organisation and cancel accounts.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>But they used to be able to do these things as well with other tools.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yes, but they needed some sort of assistance, didn&#8217;t they? Whereas now you can know nothing at all. You don&#8217;t have to have spent any time on the script kiddy forums.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I suppose, I suppose. Maybe it&#8217;s just faster.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>It feels to me like that&#8217;s where things are heading, which brings us to my second story.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I&#8217;m going to flag, I&#8217;m going to flag the point that I made earlier is that operational security isn&#8217;t always there.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yes, we can hopefully catch them later.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>We need an LLM that says, here&#8217;s how to do it. And don&#8217;t forget to consider these things.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">No, no, we don&#8217;t need that actually, Zoe. We don&#8217;t need any help for the criminals in covering up the tracks. Interesting, interesting that you should suggest that.<\/p>\n<p>This thought that AI can be harnessed by people with little technical knowledge to cause some harm brings me to my second story, which shows, I believe, where things are heading.<\/p>\n<p>So security researchers at Sysdig have just published what they&#8217;re calling the first documented case of fully autonomous AI-driven ransomware.<\/p>\n<p>This is not AI-assisted, it&#8217;s not AI-accelerated or any of those sort of marketing terms. There&#8217;s no human steering the attack at all.<\/p>\n<p>This is just an AI agent doing the entire job from start to finish entirely by itself. And they&#8217;re calling this thing Jade Puffer. Because, well, why wouldn&#8217;t you?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>I don&#8217;t know why they&#8217;ve called it Jade Puffer, to be honest.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Because it&#8217;s an excellent name.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Well, yes, I know, but why didn&#8217;t they call it lumpy trousers? Or why didn&#8217;t they call it\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Because Jade Puffer is more exciting.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Oh, okay. Alright. Well, I was thinking maybe someone at Sysdig in their lab was a fan of tropical fish ornaments. Maybe it&#8217;s just a very dull job.<\/p>\n<p>Maybe, maybe the name is actually made up by an AI. Maybe.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>There you go. Putting someone out of work again, Zoe.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Oh, when I have to think of codenames for things, I usually stick to a theme. I&#8217;m not going to say what theme because I might embarrass myself, but I stick to a theme.<\/p>\n<p>So all my codenames are in a theme. So if you figure out certain projects and certain things that needed codenames anywhere I&#8217;ve worked, you probably can guess which ones I created.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">That&#8217;s one of Zoe&#8217;s. So Jade Puffer is doing the entire job.<\/p>\n<p>It finds a way in, it steals passwords, it breaks into secondary servers, it encrypts the data, it leaves a ransom note demanding bitcoin, all without a single human having to put a hoodie on in their darkened bedroom.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Now, the unnamed victim organisation, they weren&#8217;t exactly running a tight ship, to be honest. Apparently they had some software with a known security flaw.<\/p>\n<p>There&#8217;d been a patch out for at least a year. They hadn&#8217;t patched it. And it was internet-facing.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>And so most organisations.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Yeah. So Jade Puffer was able to get in and it helped itself to passwords, account details, API keys for OpenAI and Anthropic and <a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> Gemini.<\/p>\n<p>&#8216;Cause you know, that&#8217;s often what they&#8217;re after now. They don&#8217;t want to use their own AI tokens. They&#8217;d rather use someone else&#8217;s.<\/p>\n<p>And they&#8217;re stealing cloud infrastructure credentials for AWS, and cryptocurrency seed keys to break into wallets.<\/p>\n<p>And then it moved on to its real target, which was the company&#8217;s production database.<\/p>\n<p>And it tried to create a hidden admin account for itself to access that database, but it failed. It made a technical error.<\/p>\n<p>And what was eye-opening was that the AI diagnosed the problem as it was trying.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">And fixed\u2014 no, not cool, Zoe Rose, not cool at all. You really got to remember what side you&#8217;re on. And it fixed the problem. And it took round about 31 seconds to fix the problem.<\/p>\n<p>Now, Sysdig&#8217;s researchers, they said if a human had read that same error message\u2014<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Lots more searching online.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Yeah, they would then have had to have Googled it. They&#8217;d then have to go and make a cup of tea or something, or whatever it is, you know, scratch their head for a bit.<\/p>\n<p>It would have not taken 31 seconds to recode in order to do it properly.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>You know what this makes me think though? I should rethink my stance on automated pen tests. Oh, maybe there is an AI out there that could be a decent red teamer.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yeah, well, there are more and more companies who are beginning to do that, aren&#8217;t there? Anyway, Jade Puffer sorted itself out.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Encrypted all the items in the database, deleted the originals, so the data is now gone. So it&#8217;s been held hostage.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Do they know? Question. Do they know? If the ransomware actually is done properly and it can actually revert backwards, or is it all gone?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">A very good question.<\/p>\n<p>And the kind of question which would only be asked by a cynical cybersecurity expert such as yourself, because actually you have put your finger on the whole flaw in this plan.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So although it did encrypt the files and it did generate a unique decryption key, which was going to be the only thing which would ever unlock those files for the victim, it failed to send that key back to the criminals.<\/p>\n<p>So it effectively disappeared. Even if someone had paid, there was no chance you were ever going to get the decryption key back to get your data back.<\/p>\n<p>So there was a flaw in the code.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Well, we&#8217;ve seen this before though, in legitimate people. Yes. Actual cybercriminals. So maybe the AI is at the functional level of sass in people already.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Maybe it is.<\/p>\n<p>But more than that, in the actual ransom note where it listed the bitcoin address, what it used was a generic bitcoin address, which is used in all the bitcoin documentation.<\/p>\n<p>It&#8217;s like using <span id=\"eeb-27649-952890\" \/>*protected email*noscriptnoscriptnoscript.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">That&#8217;s excellent. I love these little failures. It&#8217;s just yeah, lovely. It&#8217;s like these script kiddies.<\/p>\n<p>I know how to do this because it&#8217;s done it for me, but I don&#8217;t actually know how to apply it logically.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>And it&#8217;s a limited capacity of this highly functional, very fast, efficient tooling that&#8217;s still not there. I don&#8217;t know, it&#8217;s just really interesting to me.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">And there were other things which were interesting about this ransomware as well, because the security researchers, they knew they were looking at an AI rather than a human attacker.<\/p>\n<p>Because the AI couldn&#8217;t stop itself from offering a running commentary on what it was doing.<\/p>\n<p>So when they looked at its attack scripts, they were stuffed with comments and explanations of what it was doing.<\/p>\n<p>And as we know, no humans are ever gonna document\u2014 It&#8217;s commenting!<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Oh my goodness, it&#8217;s like a programmer that can&#8217;t comment their own code. It&#8217;s bloody commenting. It&#8217;s like\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So the AI had left comments in its own code discussing which parts of the database were the best return on investment. I love this. So, yeah.<\/p>\n<p>Less than ideal for the criminals, really.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Well, I mean, to be fair though, if they got the money, they got the money. They didn&#8217;t have to do that much. So, their return on investment ain&#8217;t that bad, is it?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Well, but they haven&#8217;t got the money &#8217;cause they didn&#8217;t list the right bitcoin address.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Oh, okay, never mind.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>They listed the example one. So, they bungled, basically. They&#8217;ve got an AI accomplice, and it has bungled. Achieved precisely nothing other than damage.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>But maybe it was a test, and maybe they&#8217;ve had it successful since then, innit? &#8216;Cause how many companies actually say when they&#8217;ve been hit by ransomware?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">That&#8217;s true. It may well have since been developed further, and maybe it is succeeding.<\/p>\n<p>So what connects this 15-year-old in Japan who zapped these 46,000 anime accounts and this rogue AI that wiped a company&#8217;s database and then forgot how to actually extort the money afterwards?<\/p>\n<p>I think the connection is that AI is making it easier to be a cybercriminal. It is opening up this career opportunity, if you like, to more people.<\/p>\n<p>So as people are struggling with the cost of living, as people are finding, oh, crumbs, you know, I can&#8217;t get a job or whatever, more people might be tempted into cybercrime because AI could well help them.<\/p>\n<p>JadePuffer, this new ransomware, it&#8217;s not perfect. It fell over. It failed to handle the encryption properly and extort any money.<\/p>\n<p>But sooner rather than later, as you&#8217;ve already suggested, I think problems like that are going to be fixed.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>This week&#8217;s episode is supported by NordLayer.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>NordLayer. And before anyone says anything, no, it&#8217;s not NordVPN.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>I wasn&#8217;t going to say that.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">You were absolutely going to say that, Joe. They are both from Nord Security, but NordLayer is a completely different product. NordVPN is for individuals.<\/p>\n<p>NordLayer is a network security platform built for businesses.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Right, so what does NordLayer actually do?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>From a sun lounger, hopefully.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">You&#8217;d be lucky. And the moment someone logs into a company network over an unsecured connection, you&#8217;ve got a problem. Credentials intercepted, phishing attacks, unauthorised access.<\/p>\n<p>It&#8217;s a scary world out there for travelling workers.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>So NordLayer fixes that.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second with zero additional hardware required.<\/p>\n<p>But it goes well beyond just encrypting the connection.<\/p>\n<p>You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant, and if someone leaves the company, you revoke their access immediately.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>No more ex-employees still wandering around your systems 6 months later.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">No more of that. And it will block malicious sites, risky downloads, dangerous domains, and it can even detect shadow apps.<\/p>\n<p>So if someone on your team has started using some AI tool that your security team hasn&#8217;t approved\u2014<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yeah, well, whatever. NordLayer can spot that too. And there&#8217;s no complex infrastructure to set up. Apparently you can be up and running in just about 10 minutes.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">10 minutes. Plans start from just $8 per user per month. And right now there is a summer sale. New customers get up to 20% off annual plans until the end of August 2026.<\/p>\n<p>Use the code NLsummer26 at checkout.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Whoa, all I have to do is type in that code at nordlayer.com\/smashing and I can get a great deal? Let me write that down.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yep, go ahead, write it down.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>What&#8217;s the code again? I forgot.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Oh, Joe. NLsummer26.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Got it. Off to nordlayer.com\/smashingigo.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>And thanks to NordLayer for supporting the show. Zoe, what&#8217;s your story for us this week?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">I was talking about Apple&#8217;s Hide My Email. So if you don&#8217;t know what that is, it&#8217;s if you have an iCloud account, you can select the feature that says Hide My Email.<\/p>\n<p>It generates a random email address that you can enter instead of your main email.<\/p>\n<p>Theoretically, the point is privacy, to keep from the association with this, whatever you&#8217;re signing up for, with your true identity.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yeah. And presumably it means that you will know where someone got your email address from. So if you create\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>It&#8217;s like watermarking it. Yeah.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yeah. And you could obviously shut it down if it&#8217;s then abused by spammers or scammers in some way.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Yeah. I use it for the use case that you just said, so I can have it for a temporary amount of time. Remove it, and then I&#8217;m good. It&#8217;s very useful for that.<\/p>\n<p>I don&#8217;t use it for a highly sensitive sort of, maybe I don&#8217;t want somebody to associate this action with my identity. I don&#8217;t use it in that use case.<\/p>\n<p>But being as what it was marketed as, I could imagine a lot of people do.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Right. So that&#8217;s more the concern for me.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>So what&#8217;s happened with it? What&#8217;s happened with this Hide My Email feature?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>There is a vulnerability, quote unquote, that you can associate your generated email address with the original legitimate mailbox.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Yeah.<\/p>\n<p>So theoretically, if I go to a naughty site and I want to sign up for an account and I don&#8217;t want you to see it&#8217;s me, I could use this generated account and then this site will email this generated account, which would then come to my main legitimate email.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">And then if I don&#8217;t want it anymore, I can delete the account on the website or disable it within my settings. Very useful.<\/p>\n<p>Theoretically, it&#8217;s going to be very helpful for a lot of people. From my perspective, I would still make the assumption that that&#8217;s traceable without knowing that it was. Yeah.<\/p>\n<p>I didn&#8217;t know it was. I always assumed it would be because, you know, it&#8217;s technology and technology is\u2014<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Yeah, that&#8217;s a nice way of saying it.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>A dumpster fire. Yes.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Yeah, perfect. And I used to work in OSINT, so open source intelligence. My job used to be aggregating data and connecting the dots and making very overly-sized webs of details.<\/p>\n<p>You know that picture where it&#8217;s like the guy and he&#8217;s got the pictures and all the red strings together?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Oh, the red string, yes, like a conspiracy board, yes.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Mate, that was me, and that&#8217;s exactly what I did.<\/p>\n<p>And I still look it, but LLMs, further to what you were talking about, they just make that easier as well because you can aggregate data quite quickly with a lot of tooling.<\/p>\n<p>I imagine they&#8217;re using LLMs as well to aggregate more data, because it&#8217;s not that difficult to tag and connect the dots.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Right? These vulnerabilities probably make it much easier. I mean, I imagine it is. And so, I would always take the assumed compromise approach.<\/p>\n<p>So, I would always assume that they&#8217;re connectable. But as a non-technical person, I could 100% see how they would not think that this is connectable.<\/p>\n<p>And if you&#8217;re doing it because you&#8217;re hiding some kink, okay, embarrassing, not the end of the world. But for some users, they&#8217;re trying to get help for dangerous situations.<\/p>\n<p>Maybe they&#8217;re a survivor of domestic abuse and violence.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So this could be quite risky for them if their abuser is able to connect the dots, if their stalker is able to identify them.<\/p>\n<p>And so I agree with the Smashing Security researchers&#8217; publication of the fact that it is vulnerable and it is not protecting you in the way that it&#8217;s supposed to be, or it claims to be.<\/p>\n<p>The disappointing thing is apparently it was June last year that the vulnerability was disclosed to them.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Oh, to Apple. So Apple&#8217;s known about this for a year.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>According to the article, it was a year, and in May the update was it was going to be resolved shortly, and we&#8217;re in July and there&#8217;s no resolution yet.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>So that&#8217;s why, from what I&#8217;ve read, that&#8217;s why they wanted to publish it, because they&#8217;re concerned for the safety of people that are making use of this.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>So that feels quite noble to me that the researchers withhold technical details of exactly how to exploit this to prevent that sort of exploitation event, people obviously finding themselves in a pickle, but Apple should have done something by now, surely.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Well, and it&#8217;s disappointing because Apple always likes to market themselves as privacy-focused, right? And if you&#8217;re going to market yourself that way, bloody do it.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Yeah, walk the walk. Yeah.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">And there are priorities.<\/p>\n<p>So the one thing I always get frustrated with, they&#8217;re marketing their autonomous cars, is they&#8217;re not actually autonomous, or they can&#8217;t achieve what they want, or they don&#8217;t even have the capability that they&#8217;re marketing.<\/p>\n<p>And that&#8217;s dangerous for people&#8217;s safety. This is also dangerous.<\/p>\n<p>Maybe it&#8217;s not as physically visible how dangerous it can be, but I work and volunteer with organisations that support survivors of domestic abuse and violence.<\/p>\n<p>I&#8217;ve also been through a very similar situation myself. It&#8217;s scary being in that environment.<\/p>\n<p>And when the technology you&#8217;re relying on to protect you, and in some people&#8217;s case it is protecting their life, and you&#8217;re not doing it to the best of your ability, that&#8217;s, that&#8217;s really, really disappointing.<\/p>\n<p>So I&#8217;m hoping it resolves it, but I think the main takeaway here is you cannot rely 100% on technology. You just can&#8217;t.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">So I&#8217;ve got a question, Zoe. Is a broken privacy feature worse than no privacy feature?<\/p>\n<p>Because of the false confidence it creates, because people would have used this thinking they were being private, thinking they were doing the right thing.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">And in many cases they probably were fine. Right. In many cases it&#8217;s probably fine.<\/p>\n<p>It&#8217;s the cases that it&#8217;s not fine and assuming that it is, that you&#8217;re protected, where it can go drastically wrong.<\/p>\n<p>I think knowing that it is broken allows you to consciously choose what use cases is it going to fit for, right?<\/p>\n<p>Not knowing means that you&#8217;re unconsciously putting yourself at risk, and that&#8217;s what I&#8217;m not okay with. I still make use of the functionality for the case that I&#8217;ve already said.<\/p>\n<p>If I want to have a temporary mailbox, it&#8217;s a great resource. It&#8217;s still connectable, yes, but it&#8217;s a great resource. I can just remove it.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>And I also know there are some other third-party services which offer sort of masked emails and things like Fastmail. I think ProtonMail offers this as well.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">They do, yep, and they&#8217;re useful if you 100% want to keep them separate.<\/p>\n<p>At the end of the day, you have to be separate, but as our lovely 15-year-old found out, OPSEC is very difficult. Right?<\/p>\n<p>And so, if you want to keep them separate for your own safety or for specific reasons, maybe you have a much, much more intense threat map than I do, and you&#8217;ve got nation state after you, then there&#8217;s a lot more to consider.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>But I guess for now, all eyes are on Apple and how they&#8217;re going to respond to this, albeit 13 months later.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Well, and it goes back to responsibility because they&#8217;re marketing it as hide my email address and they know there&#8217;s a vulnerability.<\/p>\n<p>So, who&#8217;s accountable there if something happens? How do we force organisations to care? And I think at the end of the day, we&#8217;re European, right?<\/p>\n<p>Well, European, not EU for you, but\u2014<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Thanks for reminding me.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Just in case you forgot. To be fair, I&#8217;m not either.<\/p>\n<p>But at the end of the day, we have more protections than somebody in North America because of the regulations and putting the accountability back on the vendor.<\/p>\n<p>So, as these things happen and as technology changes, as much as I hate regulation and compliance for the sake of compliance, I do hope it makes a difference and puts more accountability back on the organisations to respond in an appropriate timeframe and not market falsely.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Well, we&#8217;ve got time now to talk about one of today&#8217;s sponsors, Vanta. Joe, what keeps you up at 2 o&#8217;clock in the morning?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>The dog next door, mostly.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Oh, right, well, yeah, but I&#8217;m talking professionally, what keeps you up?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Oh, whether we&#8217;ve got the right security controls in place, whether our vendors are secure, how to escape the nightmare of outdated tools and endless manual processes.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Exactly, which is where today&#8217;s sponsor comes in. It&#8217;s Vanta.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Fanta, the fizzy orange drink. How can this possibly be true?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">No, no, Joe, it&#8217;s Vanta with a V. It&#8217;s a trust management platform. It&#8217;s not a drink full of sugar.<\/p>\n<p>It automates all of that tedious manual compliance work so you can stop drowning in spreadsheets, chasing audit evidence, and filling out questionnaire after questionnaire.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>Lush, I hate questionnaires.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Well, who doesn&#8217;t? Vanta continuously monitors your systems. It centralises your security data. It keeps your program audit ready all of the time.<\/p>\n<p>It also uses AI to streamline evidence collection and flag risks. It automates compliance for SOC 2, ISO 27001, HIPAA, GDPR, and more.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>So basically it handles the boring stuff so we can focus on the interesting stuff.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Exactly. Precisely that. And for a limited time, new customers can get $1,000 off. $1,000? Yep, $1,000.<\/p>\n<p>Head to vanta.com\/smashing, that&#8217;s V-A-N-T-A dot com slash smashing, and get started today.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">JOE<\/span>\n                    <\/p>\n<p>And maybe get a decent night&#8217;s sleep for once. Oh, and unlike fizzy drinks, Fanta isn&#8217;t bad for you. That was a fruit twist.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>And welcome back, and you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Pick of the Week.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Pick of the Week is the part of the show where everyone chooses something they like.<\/p>\n<p>Could be a funny story, a book that they&#8217;ve read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish. Doesn&#8217;t have to be security related necessarily.<\/p>\n<p>Now, my pick of the week this week is related to a news story which I saw on July 1st.<\/p>\n<p>TV stations in America, they broke their 24-hour rolling news to report on what was going on at the Empire State Building in New York.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">We are following breaking news out of New York City where at least two people have climbed to the very top of the Empire State Building. You can see them there.<\/p>\n<p>They&#8217;re on the antenna with a flag.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">That is 1,554 feet above the ground.<\/p>\n<p>They appear to be protesters and have unfurled a banner that says, &#8220;When the power of love beats the love of power, the world knows peace.&#8221; NBC New York is covering all of it.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>We&#8217;re going to take a listen right now.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Did you see this at all, Zoe?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Well, they had helicopter crews circling around one of the world&#8217;s most famous buildings because a man and a woman had climbed right to the very, very top.<\/p>\n<p>They unfurled a banner saying, &#8220;When the power of love beats the love of power, the world knows peace,&#8221; which is, you know, a very groovy thing to say.<\/p>\n<p>They got down from the very top onto a platform and the man got down on one knee and nervously proposed to the woman who had climbed up there with him.<\/p>\n<p>And, you know, it was all in some ways charming, in other ways just like, what the bloody hell are they doing?<\/p>\n<p>Is this what everyone&#8217;s going to be doing now to propose to each other? This is insanity. And they were arrested, of course. Their names are Angela Nikolau and Ivan Birkus.<\/p>\n<p>They are two Russian, what are called, rooftoppers, who climb buildings. You know, they don&#8217;t have all the safety gear. They just go up in their trainers, it seems.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>What is it called, like free climbing or something?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>It&#8217;s that kind of thing. They break into buildings. They&#8217;re not doing this with permission. They evade security teams.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>May I guess that? Yeah.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Anyway, this interested me in this case, and I found out that they were the subject of a Netflix documentary a couple of years ago called Skywalkers: A Love Story.<\/p>\n<p>And it is that documentary which is my pick of the week. And I&#8217;ll tell you something about myself, Zoe. I am terrified of heights, right?<\/p>\n<p>I can&#8217;t stand on a stool, let alone climb up a ladder.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Mate, I am 155 centimetres, and that is as tall as I need to be.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Right, right. So you and me both, right? Yeah.<\/p>\n<p>I have in the past got up into the loft in my house and I&#8217;ve then been stuck there for 45 minutes thinking, how am I going to get\u2014 and that&#8217;s when there&#8217;s a ladder attached to the loft.<\/p>\n<p>You know, it&#8217;s like, how am I going to get down? But aside from being terrified of heights, I am weirdly drawn to them. I am always thinking, oh, I want to test my fear of heights.<\/p>\n<p>See, is this quite as scary. Will I want to throw myself off the\u2014 that&#8217;s my worry, is my brain will sort of short circuit and throw myself off just impulsively.<\/p>\n<p>Anyway, I cannot tell you how stomach-churning this documentary was to me because I&#8217;m watching these two people climb buildings without permission.<\/p>\n<p>And they sort of fell in love doing it, which is charming, but sometimes they&#8217;re having a bit of a row on the way, which has all been recorded on their GoPros.<\/p>\n<p>And the woman at one point was having a real panic attack, which is understandable. I would be having a panic attack. I would feel paralysed as well.<\/p>\n<p>And the guy is saying, &#8220;Come on, you can do it,&#8221; and all the rest of it. And she&#8217;s like, &#8220;No, no, really, I can&#8217;t.&#8221; And then she wants to, she wants to prove that she can.<\/p>\n<p>I&#8217;m not saying that what these guys do is advisable or admirable. I think there&#8217;s\u2014<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>We should flag that there have been people that have died from doing that sort of thing.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Oh, and some of their friends had died as a result of this. So that is covered in the documentary. So, I mean, it is absolutely appalling.<\/p>\n<p>I also think it&#8217;s questionable why Netflix, you know, why is this documentary being made? Is there then a compulsion for people to carry on doing these things?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Rather than working in a sandwich bar or something like that. It&#8217;s, it&#8217;s\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I feel like that&#8217;s not the two alternatives, climbing a ginormous building or making sandwiches.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>This woman, by the way, this woman.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">She climbs these buildings, she&#8217;s on Instagram, right? And so she&#8217;s got hundreds of thousands of followers.<\/p>\n<p>So what she does is she takes an outfit with her, she&#8217;s got her heels, and she&#8217;s doing all these sort of glamorous shots of herself doing acrobatics on the top of buildings, you know, which, I mean, they are amazing photographs, but surely if there was one reason why AI was invented was to stop people climbing up buildings and putting their lives at risk to pose on top of a skyscraper.<\/p>\n<p>Anyway, is this my pick of the week, or is this my nitpick of the week?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I have to say, you&#8217;re criticising Netflix for\u2014 Yes! Providing this resource, and also recommending it.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Well, I&#8217;m bringing it to light. So this could be a nitpick of the week, rather than a pick of the week. I&#8217;m not sure which it is, but anyway, I found it compelling, and\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I would like you to watch it again with the goggles. What do they call that? Like virtual reality?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>What? So that you&#8217;re single point of view of her?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>I&#8217;m not wearing virtual reality goggles.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>I would love that.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Are you insane? I would never do such a thing. Anyway, Skywalker&#8217;s A Love Story. Is it my pick of the week? Is it a nitpick of the week?<\/p>\n<p>I&#8217;m not sure, but that is what I&#8217;m talking about on Smashing Security today.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Okay, Zoe, what&#8217;s your pick of the week?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>My pick of the week is, I am a single mother of two children and a cat. I&#8217;m pretty sure my cat is Satan, but, so I&#8217;m very busy.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>So you&#8217;re the mother of Satan?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Right, lovely.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Anyway, pick of the week is, I have no time, and so I&#8217;ve discovered, and by discovered I mean heavily forced to stop not considering by multiple people throughout many years, to purchase a Thermomix.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>Oh, now I know what one of those is. Why don&#8217;t you describe it for our listeners, what a Thermomix is?<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">A very, very expensive kitchen tool. But I will say, if you don&#8217;t like clutter, I was able to remove an insane amount of kitchen tooling.<\/p>\n<p>And donate it because I&#8217;ve got this Thermomix replaced. But basically it weighs, it measures, it mixes and cooks and all of those fancy things.<\/p>\n<p>I&#8217;ve made ice cream and lemonade and every dinner, and it does my shopping.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>It&#8217;s not just cold food, it can do hot food. I have lived in a house with a Thermomix before.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>So I do know\u2014 the embarrassing truth is that I only ever made boiled rice in it. But I know that you can do extraordinary things.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>So I&#8217;ve got all the recipes.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>They&#8217;re very expensive. I mean, as a boiled rice machine, I thought this was overpriced, I have to say. Oh no, I did pasta as well. I did pasta as well. But you know, it is\u2014<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>You are so bland right now. I did pasta.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>They are expensive devices.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>Okay. They are expensive. And you have to have a subscription to the app for recipes. You don&#8217;t have to, but I do.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>No, come on.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Super beneficial though, because I go through the app, I choose the recipes, put in a shopping list.<\/p>\n<p>It makes shopping super bloody easy because then I just put it in the thing that delivers. Because I&#8217;m not going to the shop with two children and a bloody cat.<\/p>\n<p>So it&#8217;s really useful and it allows me to cook things that are actually really good, to the point where, because I&#8217;m not a very good cook, let&#8217;s be honest.<\/p>\n<p>You want me to investigate an incident? Right on. You want me to cook pizza from scratch? Questionable. But in this case, it works.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<p>And it can boil rice very reliably in my experience.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<p>It even makes cake. I made cheesecake the other day. That&#8217;s so clever. And muffins, because it has a thingy that goes on top and you can <a href=\"https:\/\/store.steampowered.com\/\" target=\"_blank\" rel=\"sponsored noopener noreferrer\" data-iacss-external=\"1\">steam<\/a> them.<\/p>\n<\/p><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Very clever. Very cool pick of the week. Take out a mortgage though to buy one. Well, that just about wraps up the show for this week. Zoe, thank you so much for joining us as a guest.<\/p>\n<p>I&#8217;m sure lots of listeners would love to find out what you&#8217;re up to and follow you online. What&#8217;s the best way to do that?<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">ZOE ROSE<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Well, I am not massively active online because I&#8217;m getting old. And also going back to the mum comment, they could go to my website, rosesec.com, if they really want.<\/p>\n<p>But I think I&#8217;d also like to flag that if they&#8217;re somebody that related to the story I said earlier about high threat profiles, I would suggest they go and look at organisations like Operation Safe Escape or any organisations that specifically tailor their support to domestic abuse and violence survivors, because they will understand those threat maps a lot better than I can summarise.<\/p>\n<\/div><\/div>\n<div class=\"spp-ft-block\">\n<p>\n                        <span class=\"spp-ft-speaker\">GRAHAM CLULEY<\/span>\n                    <\/p>\n<div class=\"spp-ft-text\">Fantastic stuff. Well, we really appreciate you being on the show.<\/p>\n<p>And listeners, you can find me, Graham Cluley, on LinkedIn or follow Smashing Security on Bluesky and Reddit and Mastodon. And don&#8217;t forget to ensure you never miss another episode.<\/p>\n<p>Follow Smashing Security in your favorite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts for episode show notes, sponsorship info, guest lists, and the entire back catalog of 475 episodes.<\/p>\n<p>Check out smashingsecurity.com. Until next time. Cheerio, bye-bye. Cheers. You&#8217;ve been listening to Smashing Security with me, Graham Cluley.<\/p>\n<p>Thanks ever so much to Zoe Rose for joining us this week and to this episode&#8217;s sponsors, Arctic Wolf, NordLayer, and Vanta.<\/p>\n<p>Make sure to check out their special offers because they&#8217;re supporting the show.<\/p>\n<p>And talking of people supporting the show, thanks to the following fine fellows, all signed up members of Smashing Security Plus. Let&#8217;s pick out some of them from the hat right now.<\/p>\n<p>We&#8217;ve got first up, Darryl Green and Dave Barker. Both of them sound very dependable. I&#8217;d trust them to look after my plants while I&#8217;m on holiday.<\/p>\n<p>Big yay to Richard Anand, Christoph Goossens and Travis West. Travis West.<\/p>\n<p>Sounds like a Wild West character riding into town, sorting out your endpoint security, then riding off again without a word. And not also to Heisenberg.<\/p>\n<p>We know who you are, but we can&#8217;t be certain where you are. And that&#8217;s fine.<\/p>\n<p>Big thanks to Darren Kenny and to the magnificent Trogdork, a name that sounds like the final boss you&#8217;d have to beat in a game of Zelda, but probably turns out to be really good at patching vulnerabilities.<\/p>\n<p>Oh, and finally, Daniel Kromeck and Billy, just Billy, one name Billy, no further questions. He&#8217;s happy with that.<\/p>\n<p>Those are just a few members of Smashing Security Plus, which means that they get their episodes completely ad-free, earlier than the general public as well, they get them.<\/p>\n<p>And they can have their names pulled out at random to be mercilessly mocked at the end of the show. Who could want for more?<\/p>\n<p>If you fancy a little bit of that, join Smashing Security Plus. Just head over to our little club at smashingsecurity.com\/plus for all of the details.<\/p>\n<p>But you don&#8217;t have to become a member of that. You could support the show in ways which don&#8217;t cost a penny by liking, subscribing, leaving a 5-star review wherever you listen.<\/p>\n<p>That will warm my cockles. And of course, tell your friends about the show. Spreading the word really does help. And, well, until next time, cheerio, bye-bye.<\/p>\n<\/div><\/div>\n<\/p><\/div>\n<p>Usage:<br \/>\n&#8211; TITLE defines the primary topic and editorial focus.<br \/>\n&#8211; CONTENT is the primary factual source \u2014 treat it as the main reference, not secondary.<br \/>\n&#8211; Never mechanically expand the title. Build content from deep understanding of CONTENT.<\/p>\n<p>&#8212;<\/p>\n<p>## LANGUAGE RULE (CRITICAL)<\/p>\n<p>Write the entire article exclusively in English, regardless of the language of the inputs.<\/p>\n<p>&#8211; No language mixing in the final output.<br \/>\n&#8211; Translate all explanatory content naturally into English.<br \/>\n&#8211; Preserve proper nouns, brand names, product names, CVE identifiers, and technologies exactly as written.<br \/>\n&#8211; Preserve technical terms when translation sounds unnatural.<br \/>\n&#8211; The article must read as if written by a native professional cybersecurity editor.<\/p>\n<p>&#8212;<\/p>\n<p>## INTERNAL DECISION ENGINE (NEVER OUTPUT THIS)<\/p>\n<p>Analyze silently before writing:<\/p>\n<p>1. Content type: News \/ Breach Report \/ VPN Guide \/ Privacy Tutorial \/ Security Analysis \/ Tool Review \/ Comparison \/ Threat Intelligence \/ Compliance Guide<br \/>\n2. Search intent: Informational \/ Navigational \/ Commercial \/ Transactional<br \/>\n3. Technical level: Basic (general public) \/ Intermediate (tech-savvy users) \/ Advanced (IT\/security professionals)<br \/>\n4. Topic complexity: Simple \/ Moderate \/ Complex<br \/>\n5. Ideal length \u2014 apply strictly based on content type:<br \/>\n   \u2022 Breaking news \/ Breach report: 400\u2013700 words (concise, urgent, actionable)<br \/>\n   \u2022 VPN guide \/ Privacy how-to: 800\u20131,500 words (practical, step-by-step)<br \/>\n   \u2022 Tool review \/ Comparison: 1,000\u20131,800 words (structured, decisive)<br \/>\n   \u2022 Deep analysis \/ Enterprise security: 1,500\u20132,500 words (comprehensive)<br \/>\n   \u2022 Never exceed the upper limit for each type \u2014 brevity is a feature in security content<br \/>\n6. Tone by content type:<br \/>\n   \u2022 Breach\/Incident: Urgent, factual, calm authority \u2014 readers are alarmed, guide them<br \/>\n   \u2022 VPN\/Privacy guide: Consultative, practical, empowering<br \/>\n   \u2022 Tool review: Analytical, honest, decisive \u2014 take a clear stance<br \/>\n   \u2022 Enterprise\/Compliance: Professional, precise, ROI-oriented<\/p>\n<p>&#8212;<\/p>\n<p>## SECURITY NICHE RULES (CRITICAL \u2014 APPLY ALWAYS)<\/p>\n<p>These rules are mandatory for all articles in this niche:<\/p>\n<p>SOLUTION CATEGORIES (never name specific brands or vendors):<br \/>\n&#8211; Always recommend the category of solution, not a specific product.<br \/>\n&#8211; VPN articles: recommend &#8220;a reputable no-log VPN service&#8221;, &#8220;a paid VPN with a verified no-logs policy&#8221;, or &#8220;a VPN with AES-256 encryption and a kill switch&#8221; \u2014 describe what to look for, not who to buy from.<br \/>\n&#8211; Antivirus\/endpoint: recommend &#8220;a multi-layer endpoint protection solution&#8221;, &#8220;real-time threat detection software&#8221;, or &#8220;a reputable antivirus with behavioral analysis&#8221;.<br \/>\n&#8211; Password managers: recommend &#8220;a zero-knowledge password manager&#8221; or &#8220;an end-to-end encrypted password manager&#8221;.<br \/>\n&#8211; Never name, imply, or link to any specific vendor, product, or brand \u2014 Overcentral does not endorse or sponsor any security product.<br \/>\n&#8211; The recommendation must describe the feature or standard the reader should look for when choosing a solution.<\/p>\n<p>ACTIONABLE CLOSING:<br \/>\n&#8211; Every article must end with a concrete, actionable recommendation for the reader.<br \/>\n&#8211; Breach\/incident articles: what affected users should do right now (change passwords, enable 2FA, monitor accounts, use a VPN on public Wi-Fi).<br \/>\n&#8211; VPN\/privacy articles: which type of user benefits most and a suggested first step.<br \/>\n&#8211; Enterprise articles: one immediate security action or assessment recommendation.<br \/>\n&#8211; Frame as practical guidance, not advertising.<\/p>\n<p>TECHNICAL ACCURACY:<br \/>\n&#8211; Preserve all CVE numbers, vulnerability scores (CVSS), affected versions, and patch identifiers exactly as in the source.<br \/>\n&#8211; Never speculate on attack methods beyond what the source confirms.<br \/>\n&#8211; Distinguish clearly between confirmed facts and unconfirmed reports.<\/p>\n<p>&#8212;<\/p>\n<p>## EDITORIAL OBJECTIVE<\/p>\n<p>Produce an article indistinguishable from content written by an experienced English-language cybersecurity specialist.<\/p>\n<p>Demonstrate:<br \/>\n&#8211; Native-level fluency in security terminology<br \/>\n&#8211; Logical organization suited to the content type<br \/>\n&#8211; Contextual richness \u2014 connect events to broader security trends<br \/>\n&#8211; Practical relevance for the target reader (consumer, IT professional, or business owner)<br \/>\n&#8211; Analytical depth: explain not just what happened, but why it matters and what it means<\/p>\n<p>&#8212;<\/p>\n<p>## SEO + AEO + GEO + E-E-A-T<\/p>\n<p>SEO:<br \/>\n&#8211; Integrate the primary keyword naturally in the first paragraph and in at least one h2.<br \/>\n&#8211; Use semantically related terms: cybersecurity, data breach, VPN, online privacy, digital security, endpoint protection, ransomware, phishing, zero-day, patch, vulnerability \u2014 as naturally applicable.<br \/>\n&#8211; Headings must be search-friendly and specific \u2014 include the product name, company name, or attack type where relevant.<br \/>\n&#8211; Never force keywords at the expense of readability.<\/p>\n<p>AEO (for Google SGE, featured snippets, and voice search):<br \/>\n&#8211; Anticipate the most likely questions an English-speaking user would ask about this topic.<br \/>\n&#8211; Answer them directly and concisely within the text:<br \/>\n  &#8220;What is&#8230;&#8221;, &#8220;How does&#8230;&#8221;, &#8220;Is [VPN\/product] safe?&#8221;, &#8220;What should I do if&#8230;&#8221;, &#8220;How can I protect&#8230;&#8221;<br \/>\n&#8211; At least one section must provide a clear, standalone answer (2\u20134 sentences) formatted so it could serve as a featured snippet.<br \/>\n&#8211; Place the direct answer immediately after stating the question.<\/p>\n<p>GEO:<br \/>\n&#8211; Include geographic context when directly relevant (e.g. US regulations, GDPR for EU users, Five Eyes implications for VPN users).<\/p>\n<p>E-E-A-T (demonstrate through writing, never claim):<br \/>\n&#8211; Show expertise by explaining attack vectors, security mechanisms, and real-world implications \u2014 not just stating facts.<br \/>\n&#8211; Build authority through precise, well-contextualized information and specific technical details.<br \/>\n&#8211; Establish trust through accurate facts, measured claims, and clear distinction between confirmed and unconfirmed information.<br \/>\n&#8211; Never write &#8220;experts say&#8221; without specific grounding in the provided content.<br \/>\n&#8211; Write as a cybersecurity professional advising an informed audience.<\/p>\n<p>&#8212;<\/p>\n<p>## SOURCE CLEANING<\/p>\n<p>Automatically remove:<br \/>\n&#8211; Website names, publication names, author credits<br \/>\n&#8211; RSS labels, newsletter markers, syndication branding<br \/>\n&#8211; Generic labels: Summary, Overview, Highlights, Recap, Key Takeaways<br \/>\n&#8211; Phrases like &#8220;according to the website&#8221;, &#8220;as reported by&#8221;, &#8220;sources suggest&#8221;<\/p>\n<p>Convert attributed statements into direct factual statements.<\/p>\n<p>&#8212;<\/p>\n<p>## FACT PRESERVATION<\/p>\n<p>Preserve exactly:<br \/>\n&#8211; Company names, product names, CVE identifiers, CVSS scores<br \/>\n&#8211; Dates, numbers, percentages, prices, affected user counts<br \/>\n&#8211; Technical specifications, software versions, patch numbers<\/p>\n<p>Never distort or reinterpret factual information.<\/p>\n<p>&#8212;<\/p>\n<p>## STRUCTURE RULES<\/p>\n<p>1. Begin with a <\/p>\n<p> introduction \u2014 never place any heading before the first paragraph.<br \/>\n2. The introduction must establish urgency or relevance within the first 2 sentences and set the editorial angle.<br \/>\n3. Use <\/p>\n<h2>, <\/p>\n<h3>, <\/p>\n<h4> when they genuinely improve organization \u2014 not decoratively.<br \/>\n4. Each section must introduce meaningful new information.<br \/>\n5. Structure emerges organically from the content type \u2014 breach reports flow differently from VPN guides.<br \/>\n6. Closing: end with the actionable recommendation required by SECURITY NICHE RULES. Never use generic headings like &#8220;Conclusion&#8221;, &#8220;Final Thoughts&#8221;, &#8220;Summary&#8221;, &#8220;Looking Ahead&#8221; \u2014 use specific headings like &#8220;What Affected Users Should Do Now&#8221; or &#8220;How to Protect Yourself&#8221; when a heading is needed.<\/p>\n<p>&#8212;<\/p>\n<p>## HEADINGS<\/p>\n<p>Write the content conceptually first. Generate headings only after determining what each section truly explains.<\/p>\n<p>Headings must:<br \/>\n&#8211; Reflect the actual content of the section \u2014 specific, not abstract<br \/>\n&#8211; Reference the actual company, attack type, CVE, product, or security concept<br \/>\n&#8211; Be concrete, informative, and editorial<br \/>\n&#8211; Support SEO naturally without keyword stuffing<br \/>\n&#8211; Sound like headlines from a premium English-language security publication<\/p>\n<p>&#8212;<\/p>\n<p>## WRITING STYLE<\/p>\n<p>Required: authoritative, fluent, precise, trustworthy, appropriately urgent (for incidents) or consultative (for guides).<\/p>\n<p>Blend organically: factual reporting + technical explanation + contextual analysis + practical guidance.<\/p>\n<p>Vary naturally: paragraph length, sentence structure, transitions, pacing.<\/p>\n<p>Avoid: alarmism without substance, vague threat language, robotic phrasing, repetitive patterns, promotional tone toward any specific product.<\/p>\n<p>&#8212;<\/p>\n<p>## HTML RULES<\/p>\n<p>Allowed tags only: <\/p>\n<h2>\n<h3>\n<h4> <strong> <\/p>\n<ul>\n<ol>\n<li>\n<p>&#8211; Valid and clean HTML only.<br \/>\n&#8211; No Markdown, no extra symbols, no inline styles.<br \/>\n&#8211; No unnecessary whitespace between tags.<\/p>\n<p>&#8212;<\/p>\n<p>## FINAL VALIDATION (INTERNAL \u2014 NEVER OUTPUT)<\/p>\n<p>Before responding, verify:<br \/>\n&#8211; Grammar and spelling: standard English<br \/>\n&#8211; Native fluency \u2014 rewrite any sentence that sounds translated or mechanical<br \/>\n&#8211; Logical coherence and adequate depth for the content type<br \/>\n&#8211; Article length matches the content type length rule \u2014 not padded, not truncated<br \/>\n&#8211; No repetition of ideas across sections<br \/>\n&#8211; Valid HTML<br \/>\n&#8211; All CVEs, dates, numbers, and technical facts preserved accurately<br \/>\n&#8211; Solution category recommendation present \u2014 no specific brand or vendor named<br \/>\n&#8211; Actionable closing present<br \/>\n&#8211; AEO snippet present<br \/>\n&#8211; Opening paragraph does not begin with a heading<\/p>\n<p>If the article appears artificial, translated, mechanical, superficial, or incomplete \u2014 rewrite completely before responding.<\/p>\n<p>&#8212;<\/p>\n<p>## OUTPUT<\/p>\n<p><a href=\"https:\/\/overcentral.com\/en\/meta-removes-instagram-ai-feature\/\" title=\"ROLE: You are a senior headline writer for a major English-language digital news and content portal. Generate a single, precise, high-impact journalistic title based on the provided inputs.  ---  OUTPUT LANGUAGE: English only.  ---  CONTENT RULES: * Remove all attribution phrases: &quot;according to&quot;, &quot;reported by&quot;, &quot;leaks suggest&quot;, &quot;sources say&quot; * Remove references to: news sources, portals, publication names * Convert attributed statements into direct factual statements  ---  PRESERVATION \u2014 keep exactly as written: * Proper names (people, places, organizations) * Brand names and product names (Xbox, NVIDIA, Samsung, etc.) * Game titles and technology names * Monetary values (US$, \u20ac, \u00a5, R$) * Technical terms (Overclocking, Patch Notes, Sakuga, etc.) * Dates and version numbers  ---  LANGUAGE RULES: * Use present tense for immediacy * Use strong, direct verbs: Gets, Launches, Confirms, Reveals, Adds, Drops, Brings, Expands, Releases, Shows * Avoid weak or vague verbs: arrives, announces, is set to, is expected to * No subjective adjectives unless they add factual clarity  ---  STRUCTURE: * Start with the main entity whenever possible * Format: [Entity] + [Strong Verb] + [Key Fact\/Context] * Allow variation if it improves clarity or SEO  ---  SEO + AEO + GEO: * Place the primary keyword as early as possible * Title must be self-explanatory without additional context * Include location only when directly relevant to the story  ---  RESTRICTIONS: * No quotation marks * No question marks * No exclamation marks * Target: 50\u201370 characters (slight flexibility for clarity)  ---  INTERNAL PROCESS (never output this): 1. Identify: main entity, core fact, primary keyword 2. Generate 3 internal title variations 3. Evaluate each by: clarity, keyword placement, verb strength, naturalness 4. Select the best \u2014 if unnatural or generic, rewrite completely 5. Output only the final selected title  ---  OUTPUT RULE: Return ONLY the final title. No labels. No explanations. No &quot;Title:&quot; prefix. No extra text.  ---  INPUTS:  TITLE: Meta removes controversial AI feature on Instagram after backlash  CONTENT: \nMeta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI. The feature, which was rolled out earlier this week along with a batch of other AI tools, \u201cmissed the mark\u201d and is no longer available, according to the company. \n\nEarlier this week, Meta &lt;a href=&quot;https:\/\/techcrunch.com\/2026\/07\/07\/meta-rolls-out-muse-a-new-ai-image-generator\/&quot;&gt;announced&lt;\/a&gt; Muse Image, a new AI image generator built by its dedicated AI unit known as Meta Superintelligence Labs. Meta promoted one feature that allowed individuals to generate images by @-mentioning public Instagram accounts that they wanted to reference. The feature, which wasn\u2019t designed to alert a user if their photos were used in this way, prompted immediate backlash. \n\n\n\n\n\n\n\nTechCrunch &lt;a href=&quot;https:\/\/techcrunch.com\/2026\/07\/09\/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos\/&quot;&gt;wrote its own guide&lt;\/a&gt; explaining to users how to disable the feature.\n\nNow, Meta has reversed course. The company issued a &lt;a href=&quot;https:\/\/about.instagram.com\/blog\/announcements\/new-ai-effects-in-instagram-stories&quot;&gt;blog post&lt;\/a&gt; Friday announcing that it was removing the feature. Puck News founding partner Dylan Byers was the first to share the &lt;a href=&quot;https:\/\/x.com\/DylanByers\/status\/2075707685547421750?s=20&quot;&gt;company\u2019s decision&lt;\/a&gt;.\n\n\u201cOur intent was to provide a useful creative tool and to give people control over whether their public content could be referenced in this way,\u201d the company posted on its blog. \u201cWe\u2019ve heard the feedback that this feature missed the mark, so it\u2019s no longer available.\u201d\n\nTechCrunch reached out to Meta for more information and will update this article if it responds.\n\nSince its integration with social media platforms, AI has been misused with wild abandon \u2014 often to &lt;a href=&quot;https:\/\/www.pbs.org\/newshour\/show\/authorities-struggle-to-stop-ai-tools-generating-nude-images-without-consent#:~:text=There%20has%20been%20a%20sharp,underway%20to%20rein%20it%20in.&quot;&gt;generate naked images of female celebrities&lt;\/a&gt;. Platforms have attempted to mitigate this trend, although the guardrails introduced have often fallen short.\n\n\nIn the case of Meta\u2019s newly nixed feature, it seems somewhat obvious that it would have been abused in this way. Indeed, Byers notes that the decision to do away with the feature came \u201camid scrutiny from users and talent agencies, including CAA.\u201d\n&lt;em&gt;When you purchase through links in our articles, &lt;a href=&quot;https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/&quot;&gt;we may earn a small commission&lt;\/a&gt;. This doesn\u2019t affect our editorial independence.&lt;\/em&gt;\" data-iacss-internal=\"1\">Return ONLY the final<\/a> HTML article, beginning with <\/p>\n<p>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ROLE: You are a Senior Cybersecurity and Digital Privacy Editor for Overcentral, a major English-language tech publishing portal. Transform the provided inputs into an original, authoritative, and professionally structured article written exclusively in English, suitable for immediate publication on a high-quality cybersecurity and privacy website targeting readers in the US, UK, Australia, and Canada. &#8212; [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74497,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/C1W0C6x.jpg","fifu_image_alt":"JadePuffer AI Runs First Fully Autonomous Ransomware Attack","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62930","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/C1W0C6x.jpg","fifu_image_alt":"JadePuffer AI Runs First Fully Autonomous Ransomware Attack","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62930"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62930\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74497"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}