WEBVTT

1
00:00:01.457 --> 00:00:08.958
<v James Ball>What's the security analogy?</v>

2
00:00:08.958 --> 00:00:16.457
<v James Ball>It's a Swiss cheese.</v>

3
00:00:16.457 --> 00:00:23.957
<v James Ball>The idea being that Swiss cheese has holes in it, but you get more and more layers of it in the hopes that the holes won't line up.</v>

4
00:00:23.957 --> 00:00:31.457
<v James Ball>This is like 4 layers of Swiss cheese lining up and just something dropping straight through, isn't it?</v>

5
00:00:44.825 --> 00:00:57.814
<v James Ball>It cost millions.</v>

6
00:00:57.814 --> 00:01:07.813
<v Unknown>With Graham Cluley and special guest James Ball.</v>

7
00:01:07.813 --> 00:01:17.813
<v Unknown>Hello, hello, and welcome to Smashing Security episode 465.</v>

8
00:01:17.813 --> 00:01:27.813
<v Unknown>My name's Graham Cluley.</v>

9
00:01:22.768 --> 00:01:29.475
<v Graham Cluley>James, welcome back on the show. Lovely to have you on yet again.</v>

10
00:01:29.475 --> 00:01:36.183
<v Graham Cluley>What have you been up to?</v>

11
00:01:36.183 --> 00:01:46.183
<v James Ball>I've been running around all over the place. I spend about half my week being a political journalist and the other half working on tech.</v>

12
00:01:46.183 --> 00:01:56.183
<v James Ball>And the political half is really creeping up. It's not staying contained at the moment.</v>

13
00:01:56.183 --> 00:02:06.183
<v James Ball>And so I'd like to put it on the record, I am the greatest victim of the world's political situation right now.</v>

14
00:02:30.306 --> 00:02:40.306
<v Graham Cluley>And the world of technology has become so huge that the people in charge</v>

15
00:02:40.306 --> 00:02:50.306
<v Graham Cluley>of these technological companies have an enormous amount of influence over our politicians.</v>

16
00:02:50.306 --> 00:03:00.306
<v Graham Cluley>How can you extricate them? I don't know that you can.</v>

17
00:03:00.461 --> 00:03:06.768
<v Graham Cluley>One thing I will say to any other listeners who are concerned about this as well is if they're doing the wrong thing, I'm gonna have a go at them regardless of what side of the political chamber they might be on. Well, before we kick off, let's thank this week's wonderful sponsors, CoreView, Elastic, and Vanta. We'll be hearing more about them later on in the podcast. This week on Smashing Security, we won't be talking about how home security firm ADT has been burgled by the Shiny Hunters gang.</v>

18
00:03:06.768 --> 00:03:13.074
<v Graham Cluley>You'll hear no discussion of how ransomware negotiator has pleaded guilty to helping hackers by leaking victims' insurance details. And we won't even mention how Elon Musk's Grok chatbot told researchers pretending to be delusional that there was indeed a doppelganger in their mirror and they should drive an iron nail through the glass while reciting a psalm backwards. So James, what are you going to be talking about this week?</v>

19
00:03:13.074 --> 00:03:23.074
<v James Ball>So this week I want to talk about how wronguns are</v>

20
00:03:23.074 --> 00:03:33.074
<v James Ball>still tracking us on our mobile phones and why this is</v>

21
00:03:30.787 --> 00:03:40.787
<v Unknown>Smashing Security, episode 465.</v>

22
00:03:33.074 --> 00:03:43.074
<v James Ball>proving so intractably difficult to sort out.</v>

23
00:03:40.787 --> 00:03:50.787
<v Unknown>Smashing Security 465.</v>

24
00:03:43.579 --> 00:03:54.165
<v Joe>This episode of Smashing Security is</v>

25
00:03:50.787 --> 00:04:00.787
<v Unknown>This developer wanted to cheat at Roblox.</v>

26
00:03:54.165 --> 00:04:04.753
<v Joe>brought to you with support from CoreView.</v>

27
00:04:04.753 --> 00:04:12.064
<v Graham Cluley>Now, Joe, quick question.</v>

28
00:04:12.064 --> 00:04:19.375
<v Graham Cluley>If someone broke into your Microsoft 365 tenant right now and quietly disabled your conditional access policies, grabbed global admin rights, turned off Bitdefender, would you even notice?</v>

29
00:04:18.636 --> 00:04:48.636
<v James Ball>And I'm James Ball.</v>

30
00:04:19.375 --> 00:04:35.103
<v Joe>I'd like to say yes.</v>

31
00:04:35.103 --> 00:04:52.338
<v Graham Cluley>Well, that's the spirit, Joe.</v>

32
00:04:52.338 --> 00:05:12.653
<v James Ball>Good job.</v>

33
00:05:12.653 --> 00:05:22.910
<v Graham Cluley>But here's the uncomfortable reality. 63% of Microsoft 365 tenants hand out admin rights like they're going out of fashion.</v>

34
00:05:22.910 --> 00:05:33.166
<v Graham Cluley>One compromised account and an attacker can quietly reshape your entire tenant. No alerts, no noise, just someone systematically dismantling your defenses while you're none the wiser.</v>

35
00:05:33.166 --> 00:05:51.677
<v Joe>So wait, restore from backup doesn't fix that?</v>

36
00:05:51.677 --> 00:06:00.485
<v Graham Cluley>No, no, no. Backups protect your data. They don't restore tenant-level configurations.</v>

37
00:06:00.485 --> 00:06:09.293
<v Graham Cluley>There's no native rollback for that. You could be rebuilding your tenant settings from scratch for weeks.</v>

38
00:06:09.293 --> 00:06:28.355
<v Joe>And who's doing that?</v>

39
00:06:28.355 --> 00:06:37.783
<v Graham Cluley>Exactly. Who wants to do that? Well, CoreView have written a white paper called Total Tenant Takeover: The Microsoft 365 Disaster No One's Ready For.</v>

40
00:06:37.783 --> 00:06:47.211
<v Graham Cluley>It's actually a really practical read. It covers how these attacks unfold step by step, where your existing tools are leaving gaps, and what it actually takes to recover control once it's been lost.</v>

41
00:06:38.223 --> 00:06:45.723
<v Graham Cluley>It's a crazy world politically.</v>

42
00:06:45.723 --> 00:06:53.223
<v Graham Cluley>You know, I had some feedback from a listener just in the last couple of days actually saying, you love the podcast, been listening to the podcast forever, but oh my God, Graham, can you stop talking about politics?</v>

43
00:06:47.211 --> 00:06:55.507
<v Joe>So less detect and panic, more here's how to actually get</v>

44
00:06:53.223 --> 00:07:00.723
<v Graham Cluley>And my reaction was, look, thank you very much for listening and all the rest of it, but it feels to me that technology and politics are more intertwined than ever before.</v>

45
00:06:55.507 --> 00:07:03.802
<v Joe>your tenant back.</v>

46
00:07:00.723 --> 00:07:08.223
<v Graham Cluley>You can't really extract them from each other, can you?</v>

47
00:07:03.802 --> 00:07:10.110
<v Graham Cluley>That's it. Exactly.</v>

48
00:07:10.110 --> 00:07:16.418
<v Graham Cluley>And you can download this paper for free right now. You can learn more at smashingsecurity.com/coreview and maybe do it before someone else does something bad to your organization.</v>

49
00:07:16.418 --> 00:07:23.240
<v Joe>That's smashingsecurity.com/coreview.</v>

50
00:07:21.218 --> 00:07:24.363
<v James Ball>I mean, horribly so. It feels a bit like a monkey's paw thing. You know, I've been interested in tech since I was a kid. I've sort of always gone, I wish people would pay more attention to this. This is transformative. I sort of came of age with the internet. You're kind of going, no, we need to look at this. This is really huge. And now tech and politics have merged so much and are in the discourse so much and are crashing together in so many ways. It's I was really stupid to want this. Why can't this go back to being in its nice own lovely corner where I can just think about how the technology works or, you know, the principles of it instead of what stupid way is this going to be used to upend our politics yet again?</v>

51
00:07:23.240 --> 00:07:30.062
<v Joe>And thanks to Coreview for supporting the show.</v>

52
00:07:24.363 --> 00:07:54.363
<v Unknown>Yeah.</v>

53
00:07:30.062 --> 00:07:38.711
<v Graham Cluley>So James, I want to tell you a story today. It's a story about a cloud software company called Vercel, which I imagine many people won't have heard of. They are at the heart of all kinds of stuff which is going on on the internet. Hundreds of thousands of organizations use them because they're a cloud company. You know, they're a properly grown-up company.</v>

54
00:07:30.543 --> 00:07:40.543
<v James Ball>I mean, we haven't had this kind of dominance really since you look back at the Gilded Age. It's when the railway monopolies were there or the early oil monopolies, because the biggest companies and the biggest tech companies is synonymous. 9 of the world's 10 biggest listed companies are tech companies.</v>

55
00:07:38.711 --> 00:07:47.360
<v Graham Cluley>And on the 19th of April, Vercel put out a security bulletin. I'll summarize it. They basically said, we've been hacked, customer data has gone missing. We'd quite like to tell you about it before the Russian hackers selling it on a darkweb forum get there before us. So we're going to get out there ahead of the bad news.</v>

56
00:07:40.543 --> 00:07:50.543
<v James Ball>Essentially, this domination by one sector is pretty much unheard of in either of our lifetimes. And so politics is going to be weird until tech is kind of normal again. And that might be bad for someone who reports on and covers tech, but might be good for the world.</v>

57
00:07:47.360 --> 00:07:57.360
<v James Ball>So we will</v>

58
00:07:50.543 --> 00:08:00.543
<v James Ball>It might be good for our blood pressure and it might be good for your listener. I promise I haven't brought a load of political things this week. Well, not very political, small p political.</v>

59
00:07:57.360 --> 00:08:07.360
<v James Ball>give them some</v>

60
00:08:07.360 --> 00:08:17.360
<v James Ball>points for that, you know.</v>

61
00:08:14.524 --> 00:08:21.341
<v James Ball>Proactive disclosure, tick. I mean, better not to get hacked, but if you're going to, yeah, I don't know where this is going, but I'm giving marks out early.</v>

62
00:08:21.341 --> 00:08:28.160
<v James Ball>You know, that's a win.</v>

63
00:08:28.160 --> 00:08:38.159
<v Graham Cluley>Yeah, I would say so. I mean, obviously a bad situation, but they're trying to respond appropriately.</v>

64
00:08:38.159 --> 00:08:48.159
<v Graham Cluley>Now, normally at this point, I'll be telling you about a clever zero-day vulnerability or sophisticated nation-state campaign or even a simple phishing email, right? Normally, that's the kind of thing which I'm— not this week, however.</v>

65
00:08:48.159 --> 00:08:58.159
<v Graham Cluley>No, this week, James, the story really begins with someone wanting to play Roblox.</v>

66
00:08:52.201 --> 00:08:59.701
<v Graham Cluley>And I'm going to be talking about a corporate hack that all started because someone wanted to cheat at Roblox.</v>

67
00:08:59.701 --> 00:09:07.201
<v Graham Cluley>Plus, we're going to be talking to Rob Edmondson of CoreView.</v>

68
00:09:03.663 --> 00:09:17.865
<v Graham Cluley>Have you ever played Roblox?</v>

69
00:09:07.201 --> 00:09:14.701
<v Graham Cluley>He'll be joining us as we take a look at how hackers have been turning essential tools like Microsoft 365 against their targets and what you can do to lock down your environments before it's too late.</v>

70
00:09:14.701 --> 00:09:22.201
<v Graham Cluley>All this and much more coming up on this episode of Smashing Security.</v>

71
00:09:17.865 --> 00:09:25.365
<v James Ball>I've gone into it basically to try it out because I was going to write about it, and I try not to write about a game I haven't played.</v>

72
00:09:23.203 --> 00:09:53.203
<v Graham Cluley>Yes.</v>

73
00:09:25.365 --> 00:09:32.865
<v James Ball>I am less terrible at Roblox than I am at Minecraft.</v>

74
00:09:32.865 --> 00:09:40.365
<v James Ball>I think really it's not for adults, it's for teenagers.</v>

75
00:09:40.365 --> 00:09:47.865
<v James Ball>It's kind of even for tweens, really.</v>

76
00:10:37.030 --> 00:10:47.030
<v James Ball>I mean, look, I sympathize. It's not quite my</v>

77
00:10:40.903 --> 00:10:50.903
<v Graham Cluley>Anyway, as I said, so Roblox is part of this story. Someone wanted to play Roblox and I'm going to explain exactly what happened.</v>

78
00:10:44.019 --> 00:10:44.581
<v Graham Cluley>Yes.</v>

79
00:10:44.581 --> 00:10:54.581
<v James Ball>You know, I think if</v>

80
00:10:47.030 --> 00:10:57.030
<v James Ball>favorite game, but it's quite diverting.</v>

81
00:10:50.903 --> 00:11:00.903
<v Graham Cluley>So there is a small AI startup called Context AI. They're not the Context AI which was acquired by OpenAI.</v>

82
00:10:54.581 --> 00:11:04.581
<v James Ball>you're over 18, you'll rot</v>

83
00:10:57.030 --> 00:11:07.030
<v James Ball>I can see why they might want to go.</v>

84
00:11:00.903 --> 00:11:10.903
<v Graham Cluley>It's a different Context AI, which I think really suggests that, you know, maybe people shouldn't have relied upon AI to dream up their company name.</v>

85
00:11:04.581 --> 00:11:14.581
<v James Ball>your brain there.</v>

86
00:11:56.714 --> 00:12:06.714
<v Graham Cluley>And of course, there have been</v>

87
00:12:03.053 --> 00:12:16.198
<v Graham Cluley>They've never been checked.</v>

88
00:12:06.714 --> 00:12:16.714
<v Graham Cluley>concerns in the past that people</v>

89
00:12:16.198 --> 00:12:22.514
<v James Ball>Yeah, it's basically just typing in illegal music downloads into Google and clicking the first link you see.</v>

90
00:12:16.714 --> 00:12:26.714
<v Graham Cluley>might be grooming young people via Roblox.</v>

91
00:12:22.514 --> 00:12:28.831
<v James Ball>Or, you know, trustworthy.exe from a Nigerian prince, Derby Dragons stuff.</v>

92
00:12:28.831 --> 00:12:36.331
<v Graham Cluley>So for anyone who doesn't know, an auto-farming script is a cheat which helps you rack up in-game currency without any of that tedious business of actually playing the game.</v>

93
00:12:36.331 --> 00:12:43.831
<v Graham Cluley>But you'll get the in-game currency so you can then buy things, you know, add-ons and so forth.</v>

94
00:12:43.831 --> 00:12:51.331
<v Graham Cluley>And it's dodgy software, as you said, James, downloaded from dodgy websites.</v>

95
00:12:51.331 --> 00:12:58.831
<v Graham Cluley>But people have already decided the rules don't apply to them and they're encouraging it.</v>

96
00:13:08.197 --> 00:13:16.626
<v Graham Cluley>They shouldn't have been able to do it. And unfortunately, this particular script came bundled with the Lumma, I believe it's pronounced, Info Stealer, which rifles through your browser, grabs your passwords, every cookie, every session token, every OAuth credential it can find.</v>

97
00:13:16.626 --> 00:13:25.057
<v Graham Cluley>Bundles it up, sends it to a complete stranger afterwards. So in February, this guy downloaded this Roblox cheat.</v>

98
00:13:25.057 --> 00:13:33.486
<v Graham Cluley>He got infected. Lumma quietly stealthed its way into the browser, grabbed the database of information, including Google Workspace credentials, including the keys to Context AI's AWS environment, including— and this is the crucial part, really, I suppose— including the OAuth tokens belonging to Context AI's customers.</v>

99
00:13:29.532 --> 00:13:39.532
<v James Ball>Yeah, I mean, any platform that's got kids, that's a risk.</v>

100
00:13:30.274 --> 00:13:40.274
<v James Ball>I mean, Googling before you name it, I think is pretty much</v>

101
00:13:33.486 --> 00:13:39.807
<v James Ball>Ah, yeah. I mean, we're really stacking problem on problem here, aren't we? You know, this is all sort of, well, this shouldn't have been able to happen. Well, this certainly shouldn't have been able to happen.</v>

102
00:13:39.532 --> 00:13:49.532
<v James Ball>I'm sure there are adults who enjoy Roblox completely legitimately, but it has been slower to act</v>

103
00:13:39.807 --> 00:13:46.128
<v James Ball>Oh, oh, this is great. I mean, this is sort of building an incredibly elaborate safe door with all of this sort of stuff and then just leaving the code on a Post-it on it, isn't it? Graham, this is not great.</v>

104
00:13:40.274 --> 00:13:50.274
<v James Ball>crucial, isn't it? Clearly they were using an old version of a</v>

105
00:13:46.128 --> 00:13:56.128
<v Graham Cluley>It's not great. Very good.</v>

106
00:13:49.532 --> 00:13:59.532
<v James Ball>on those concerns than almost any other platform as well. I hear they have improved of late.</v>

107
00:13:50.274 --> 00:14:00.274
<v James Ball>model there because that is quite important context, ironically.</v>

108
00:13:56.128 --> 00:14:06.128
<v Graham Cluley>That is the headline I can imagine you writing.</v>

109
00:14:03.456 --> 00:14:10.956
<v Graham Cluley>Yes. So Context AI, they flog an AI office suite. So it's something which plugs into your Google Workspace and you grant it sweeping permissions and it can go ahead and read your email and your documents, helpfully does all kinds of wonderful AI things to them.</v>

110
00:14:06.128 --> 00:14:16.128
<v Graham Cluley>Breach not great, says James Ball.</v>

111
00:14:10.956 --> 00:14:18.456
<v Graham Cluley>It sounds absolutely gorgeous. You know the kind of thing, people get it all the time. A consent screen will pop up.</v>

112
00:14:13.363 --> 00:14:29.761
<v Graham Cluley>They're very good at headlines, aren't they?</v>

113
00:14:18.456 --> 00:14:25.956
<v Graham Cluley>You know, a sensible person reading the terms and conditions go, ha ha ha ha ha, no way. Eh, eh, it's a big fat no. But many people will just hit the approve button instead in order to allow it to do that.</v>

114
00:14:25.956 --> 00:14:33.456
<v Graham Cluley>And apparently one of Context AI's own employees, someone who works at the company, a company which has asked its customers to trust them with the keys to their corporate Google accounts, effectively, they, on apparently a work laptop, decided what they really needed in their life was a Roblox auto-farming script. Are you familiar with auto?</v>

115
00:14:29.761 --> 00:14:43.628
<v James Ball>They're much better than I am, yes.</v>

116
00:14:43.628 --> 00:14:49.568
<v Graham Cluley>So for anyone who doesn't know, OAuth tokens, they're like those little keycards you get in hotels. They let you in. So when you click allow, you are giving an app, for instance, access to your Google account. They don't need your password.</v>

117
00:14:49.568 --> 00:14:55.509
<v Graham Cluley>They don't trigger your two-factor authentication. And once a thief has your OAuth token, they don't need to break in because as far as Google's concerned, they are you. And the scary thing, I think, for many people, and they don't realize this, is if they actually check their Google account right now and have a look at what apps they have granted access to their account over the years, they're probably going to be surprised. There's probably things in there that you don't remember doing, or you may have just done on one particular day, and you've granted them access to stuff, and you should revoke it.</v>

118
00:14:55.509 --> 00:15:02.245
<v James Ball>Yeah, I think that's quite alarming because you sort of see things that were old social media add-ons or this kind of stuff. You know, I think there were several on Twitter, as it was back in the day, that would give you a score for your social standing or your clout.</v>

119
00:15:02.245 --> 00:15:08.980
<v James Ball>But these old apps that you'd granted access to for one purpose would get bought by someone else or the domain would get taken over and they could hijack the thing. And so even things that were completely sensible to grant access to, suddenly became terrible.</v>

120
00:15:08.980 --> 00:15:16.480
<v Graham Cluley>And lots of people can get— I mean, I'm going to put my hands up, right? I've suffered because of this. I remember back in the days of when I was on Twitter, as was, there was a third-party app or something or service which I think was doing some kind of ego-stroking examination of my followers, right? So I could think I was doing really, really well in terms of Twitter followers.</v>

121
00:15:16.480 --> 00:15:23.980
<v Graham Cluley>And what happened was that particular service got hacked which means the hackers then had access to my Twitter account, not just me, but also Justin Bieber and whoever else. And my account started posting Nazi spam to people. And you just think, oh no, no, no, I don't, you know, I don't want this. So it can happen to everyone.</v>

122
00:15:23.980 --> 00:15:31.480
<v Graham Cluley>You always need to look and revoke permissions wherever possible. So one of Vercel's employees had at some point signed up for the Context AI office suite using their Vercel Enterprise Google Workspace account. And when the permission screen came up, they clicked on Allow All. So now our hacker, our attacker, who started his day off poisoning Roblox hacks, is sitting on an OAuth token that gives him read access to a Vercel employee's entire Enterprise Google Workspace.</v>

123
00:15:31.480 --> 00:15:38.980
<v Graham Cluley>So you've got different companies here, but it has cascaded through to grant a huge amount of permission to access data.</v>

124
00:15:54.027 --> 00:16:00.297
<v James Ball>And the idea being that Swiss cheese has holes in it, but you get more and more layers of it in the hopes that the holes won't line up. This is like 4 layers of Swiss cheese lining up and just something dropping straight through, isn't it? Have you not come across this analogy?</v>

125
00:16:00.297 --> 00:16:06.567
<v James Ball>I didn't just make it up. I haven't.</v>

126
00:16:00.932 --> 00:16:08.432
<v James Ball>Oh no. So I should say, genuinely, my head as it went further and further in my hand as Graham just kept talking there, just because I grimly see where this would go. I mean, just the fact anyone working in any tech-related sector would do this.</v>

127
00:16:06.567 --> 00:16:28.780
<v Graham Cluley>I like that. Yeah.</v>

128
00:16:08.432 --> 00:16:15.932
<v James Ball>Gaming add-ons are notorious. You know, approved add-ons, fine, great. I've modded almost every game I've ever played.</v>

129
00:16:15.932 --> 00:16:23.432
<v James Ball>That's the fun of it. You know, Baldur's Gate 3, absolute delight and amazing mods on that and some slightly horrifying ones involving Withers that I won't get into. If you've played the game, you know.</v>

130
00:16:23.432 --> 00:16:30.932
<v James Ball>But any mod that sort of claims to let you do something a bit against the rules tends to be incredibly dodgy because they never go through the official stores, which means—</v>

131
00:16:28.780 --> 00:16:43.780
<v James Ball>Yeah. Because every slice of Swiss cheese will have a hole in, you know, you'll never get rid of those.</v>

132
00:16:43.780 --> 00:16:58.780
<v James Ball>And so you just get more and more of them on top of each other and you reduce the chance of them lining up. This is like a hole through 5 slices, just straight there. Bumpf.</v>

133
00:16:56.067 --> 00:17:26.067
<v Joe>Yes.</v>

134
00:16:56.552 --> 00:17:04.053
<v James Ball>Yeah, and of course, this means that you're more vulnerable. You know that you have to look out of the store.</v>

135
00:17:04.053 --> 00:17:11.553
<v James Ball>You know that you don't really want to have to admit it. I mean, it always sounds daft getting something to play the game for you, but any sort of massively multiplayer game has bits that basically involve grinding.</v>

136
00:17:04.471 --> 00:17:14.471
<v James Ball>This is why</v>

137
00:17:04.471 --> 00:17:09.619
<v James Ball>This is sort of the nightmare, isn't it? What's the security analogy?</v>

138
00:17:09.619 --> 00:17:14.767
<v James Ball>Is it the Swiss cheese? Yes.</v>

139
00:17:11.553 --> 00:17:19.053
<v James Ball>You know, it's a bit if you could pay someone to go to the gym for you and you got the results, which, you know, the dream. I mean, look, no company IT server setup should ever have let someone be able to install this, really, should they?</v>

140
00:17:14.471 --> 00:17:24.471
<v James Ball>I don't work</v>

141
00:17:14.767 --> 00:17:44.767
<v Graham Cluley>Yeah.</v>

142
00:17:19.053 --> 00:17:26.553
<v James Ball>I mean, this is a bit of a disaster. You know, the user is stupid here, let us stress, but they shouldn't have been able to make this mistake, should they?</v>

143
00:17:24.471 --> 00:17:34.471
<v James Ball>for The Register, isn't it?</v>

144
00:17:29.551 --> 00:17:39.551
<v Graham Cluley>So the hacker was able to pivot into Vercel's internal systems, help themselves to secrets and API keys that Vercel customers store on their platform to make their websites work, which meant database credentials, cloud</v>

145
00:17:39.551 --> 00:17:49.551
<v Graham Cluley>keys, source control tokens, all of this stuff was now grabbed. Now, Vercel says that some of these were marked as sensitive and therefore protected, but the ones which weren't marked as sensitive, which apparently</v>

146
00:17:49.551 --> 00:17:59.551
<v Graham Cluley>were most of them, because that wasn't the default, duh, once again, they've changed that default now, by the way, funny that.</v>

147
00:18:02.311 --> 00:18:05.046
<v James Ball>You shock me.</v>

148
00:18:05.046 --> 00:18:15.046
<v Graham Cluley>So this hacker claims to be a member of the infamous Shiny Hunters hacking group, although the actual Shiny Hunters say it wasn't anything to do with them, which is a typical story on the net, isn't it? Yeah.</v>

149
00:18:15.046 --> 00:18:25.046
<v Graham Cluley>Regardless, this data is now listed for sale for $2 million, all because someone at Context AI wanted to cheat at Roblox, downloaded malware, the malware stole the tokens.</v>

150
00:18:25.046 --> 00:18:35.046
<v Graham Cluley>Those tokens belonged to a Vercel employee who had secured his unsanctioned AI tool to their corporate Google account and clicked allow all.</v>

151
00:18:43.662 --> 00:18:50.330
<v James Ball>I mean, did he at least manage to run his auto farmer? You know, did he get his Roblox bucks?</v>

152
00:18:50.330 --> 00:18:53.585
<v Graham Cluley>Let's hope he got his Robux at the end of it all.</v>

153
00:18:53.585 --> 00:18:57.352
<v James Ball>I hope he got a lot of them because I can't imagine he kept his job after this.</v>

154
00:18:57.352 --> 00:19:03.242
<v Graham Cluley>No, well, I don't know what the conversion rate is from Robux into genuine dollars.</v>

155
00:19:03.242 --> 00:19:09.134
<v Graham Cluley>I doubt he's managed to create himself $2 million though to go and buy the data for himself to prevent it falling into the hands of anybody else.</v>

156
00:19:09.134 --> 00:19:12.355
<v James Ball>No, but wouldn't it be lovely if he had?</v>

157
00:19:12.355 --> 00:19:16.186
<v Joe>Time for a quick word from one of our sponsors today, Elastic.</v>

158
00:19:16.186 --> 00:19:24.482
<v Graham Cluley>So here's a familiar scenario: something suspicious hits your network. You need answers fast.</v>

159
00:19:24.482 --> 00:19:32.778
<v Graham Cluley>So your team logs into tool 1 and then maybe tool 2, then into the thing that doesn't quite talk to either of them. By which point, whatever was happening has—</v>

160
00:19:32.778 --> 00:19:33.259
<v James Ball>oh—</v>

161
00:19:33.259 --> 00:19:35.359
<v Graham Cluley>happened.</v>

162
00:19:35.359 --> 00:19:41.133
<v Joe>Elastic unifies your security data so analysts can focus on detecting and responding to threats, not herding dashboards, which is probably why over</v>

163
00:19:41.133 --> 00:19:46.906
<v Joe>half of Fortune 500 companies use them.</v>

164
00:19:46.906 --> 00:19:54.473
<v Graham Cluley>Find out more at smashingsecurity.com/elastic, because security should secure, not tax your team.</v>

165
00:19:54.473 --> 00:19:58.480
<v Joe>And thanks to Elastic for supporting the show.</v>

166
00:19:58.480 --> 00:20:00.605
<v Graham Cluley>James, what have you got for us this week?</v>

167
00:20:00.605 --> 00:20:10.605
<v James Ball>So I've got mobile phone security, but this is very much the other end of it. And CitizenLab, they're a sort of Canadian-based, not-for-profit research grouping, and they do some really impressive work on security and surveillance.</v>

168
00:20:10.605 --> 00:20:20.605
<v James Ball>And they've had quite a long interest in people who expose phone networks. So this isn't the News of the World hacking your phone, but this also isn't some of the Black Cube or the Israeli-type security companies hacking your individual handset so much.</v>

169
00:20:20.605 --> 00:20:30.605
<v James Ball>This is about people using the actual architecture of phone networks to track your location, to track your SIM card, sometimes to try and put tools on your device. And one of the key ways they're doing this is basically either posing as a mobile phone company and getting access to the towers that way, or working with some unscrupulous mobile phone companies to sort of get in.</v>

170
00:21:03.125 --> 00:21:03.365
<v Graham Cluley>Oh!</v>

171
00:21:03.365 --> 00:21:09.630
<v James Ball>And the UK famously has a bit of a vulnerability on this through Jersey.</v>

172
00:21:09.630 --> 00:21:15.894
<v James Ball>Jersey's telecoms are, I'm going to be blunt, not very well regulated, but get you inside the +44 space.</v>

173
00:21:15.894 --> 00:21:16.358
<v Graham Cluley>Oh, really?</v>

174
00:21:16.358 --> 00:21:22.089
<v James Ball>And so you can start requesting information.</v>

175
00:21:22.089 --> 00:21:27.821
<v James Ball>And this is an absolute bugbear to— so for most people, this is not, you know, your mobile phone location data isn't super interesting.</v>

176
00:21:27.821 --> 00:21:28.559
<v Graham Cluley>How dare you?</v>

177
00:21:28.559 --> 00:21:31.910
<v James Ball>But really bad things have happened to people because of it.</v>

178
00:21:31.910 --> 00:21:32.166
<v Unknown>Yes.</v>

179
00:21:32.166 --> 00:21:40.752
<v James Ball>So the famous case is an Emirati princess had essentially managed to escape from her father and from her country and was tracked down via a private intelligence company using this kind of exploit, using the mobile phone networks.</v>

180
00:21:40.752 --> 00:21:49.339
<v James Ball>And they managed to get her phone geolocated and raided the boat she was on and recaptured her.</v>

181
00:21:49.339 --> 00:21:57.925
<v James Ball>And she's basically never been seen in public since.</v>

182
00:21:57.925 --> 00:21:58.358
<v Graham Cluley>Terrific.</v>

183
00:21:58.358 --> 00:22:05.858
<v James Ball>This was through a private security company and through international mobile phone networks. And so activists get tracked. Journalists can get tracked.</v>

184
00:22:05.858 --> 00:22:13.358
<v James Ball>People sort of look at political enemies and exiles overseas. It is quite bad. And there's always talk about regulating the companies that do it.</v>

185
00:22:13.358 --> 00:22:20.858
<v James Ball>But the reason it irritates me so much, and the reason that I brought it, is because I commissioned an investigation on this years ago when I worked at the Bureau of Investigative Journalism. There's a guy called Crofton Black who has been doing reporting on this for more than a decade now. Look up his work, look up Citizen Lab.</v>

186
00:22:20.858 --> 00:22:28.358
<v James Ball>They are the experts here. And I should stress, I am not an expert on mobile phone infrastructure, so please take mine as a hopefully roughly correct explanation of this. And if people want the proper stuff, look at the Citizen Lab report because they are much better than me.</v>

187
00:22:55.686 --> 00:22:59.133
<v Graham Cluley>Yeah, we'll link to it in the show notes so people can read more about this.</v>

188
00:22:59.133 --> 00:23:08.381
<v James Ball>Basically, we have more modern 4G and 5G architecture that phones use, and it has some security awareness built into it from the get-go.</v>

189
00:23:08.381 --> 00:23:17.627
<v James Ball>But when that's not available or you have low signal, your phone reverts to 2G or 3G.</v>

190
00:23:17.627 --> 00:23:26.875
<v James Ball>And you may have found that sometimes if you're out in the sticks or frankly sometimes in central London, you don't get data, but you can make a phone call or you can get a text.</v>

191
00:23:26.875 --> 00:23:30.792
<v Graham Cluley>Yeah.</v>

192
00:23:30.792 --> 00:23:38.292
<v James Ball>And that's because the old network is still running. And that's a protocol called SS7. And SS7 is absolutely hopeless for security. It basically assumes pretty much anyone who's got a tower, who's in that backend network is trusted.</v>

193
00:23:38.292 --> 00:23:45.792
<v James Ball>And it will let people hand over metadata, let people take location information. It will let them query this stuff and pull it through with absolutely minimal security. This protocol is, I think, about 30 years old, and it was set up for when phone networks were quite basic, when they were quite early. This is the classic story of internet protocols not being secure by design.</v>

194
00:23:45.792 --> 00:23:53.292
<v James Ball>Look at Border Gateway Protocol, look at until fairly recently, DNS, look at whatever you like. It is very much from that tradition. But the issue is because global rollout of 4G and 5G has been quite slow, because people need fallbacks for things like emergency access, emergency numbers for disaster recovery efforts, SS7 is still built into almost everything. It's only now being deprecated anywhere.</v>

195
00:23:53.292 --> 00:24:00.792
<v James Ball>And so at a protocol level, mobile phones are just fundamentally insecure. And everyone in this very niche world has known about this for at least 10 years.</v>

196
00:24:50.490 --> 00:24:51.037
<v Graham Cluley>Yes.</v>

197
00:24:51.037 --> 00:25:00.314
<v James Ball>And no one has really been putting any urgency on doing anything about it. It's sort of very slowly getting fixed, but no one— this is the opposite complaint to earlier. There's no political attention on it.</v>

198
00:25:00.314 --> 00:25:09.590
<v James Ball>There's very little media attention on it. It's quite complicated. And it kind of only affects particular people who would be targeted.</v>

199
00:25:09.590 --> 00:25:18.867
<v James Ball>But it puts all of us at risk. It is incredibly dumb. And I do not know why it's been tolerated for so long.</v>

200
00:25:18.867 --> 00:25:25.758
<v Graham Cluley>That's what I'm wondering, because SS7, it's been practically a laughingstock, hasn't it, in terms of security for telecoms for at least a decade.</v>

201
00:25:25.758 --> 00:25:26.303
<v James Ball>Yeah.</v>

202
00:25:26.303 --> 00:25:32.633
<v Graham Cluley>Why on earth is it still the backbone of how our phones talk to each other now in 2026?</v>

203
00:25:32.633 --> 00:25:40.133
<v James Ball>I mean, I'd love to ask you that question. I mean, the honest answer is it's hard to replace for a bunch of reasons. And it's because everyone likes having that 2G, 3G layer to fall back on. Because it's not used very much, it's reliable, it's basic, it's dependable.</v>

204
00:25:40.133 --> 00:25:47.633
<v James Ball>It can work on much lower levels of signal than some of the modern ones. It's been quite useful to have it sitting there for things like reliability, for emergency, for fallback. And rather than replace or fix it or go, well, why don't we use this spectrum but with a better protocol? People have just gone, well, obviously, you know, we can't fix SS7.</v>

205
00:25:47.633 --> 00:25:55.133
<v James Ball>Why pay attention to that? Why don't we look at 6G? Why don't we look at, you know, 5G+ et cetera? And so everyone acknowledges it should be fixed, but I don't think anyone thinks it's their job to fix it.</v>

206
00:25:55.133 --> 00:26:02.633
<v James Ball>Or this has been my impression. There's been very little political or regulatory pressure on it. There have been a lot of actors who want to exploit and use it. And it's not been the top of anyone's agenda because ministers want to say, "I'm going to get you ultra-fast, you know, new mobile broadband, and that will boost GDP." No one wants to go, "Hey, that creaking old bit of the phone network that no one's heard of, I fixed that." No, not so sexy, is it?</v>

207
00:26:12.819 --> 00:26:22.819
<v Graham Cluley>You know when someone wants to break into a building, they put</v>

208
00:26:22.819 --> 00:26:32.819
<v Graham Cluley>on a high-vis jacket and hold a clipboard walk around looking important,</v>

209
00:26:32.819 --> 00:26:42.819
<v Graham Cluley>you know, it's like, I can't be interrupted.</v>

210
00:27:08.299 --> 00:27:12.074
<v James Ball>I think for legal reasons, I have to say no, I had no idea anyone—</v>

211
00:27:12.074 --> 00:27:19.093
<v Graham Cluley>But it feels to me that what CitizenLab are describing with these sort of ghost surveillance vendors, they're dressing themselves up as legitimate telecoms companies to sneak in as well.</v>

212
00:27:19.093 --> 00:27:26.113
<v Graham Cluley>I mean, you've already mentioned this sort of Jersey way of breaking into +44.</v>

213
00:27:26.113 --> 00:27:33.132
<v Graham Cluley>Which is the UK's country code.</v>

214
00:27:33.132 --> 00:27:38.875
<v James Ball>And there's a bunch of these, and this is a little bit different. So, there's lots of ways people pose like that in mobile phones.</v>

215
00:27:38.875 --> 00:27:44.618
<v James Ball>I think people listening to this have probably heard of Stingrays.</v>

216
00:27:44.618 --> 00:27:45.101
<v Graham Cluley>Yes.</v>

217
00:27:45.101 --> 00:27:52.601
<v James Ball>Which are a sort of surveillance tool where you sort of bring a van along and it pretends to be a phone mast, and it collects lots of location information that way. That's the kind of technical way of pretending to be a phone mast. This is like a business way of pretending. You sort of say, hey, I'm a new virtual mobile phone provider. I'm a new virtual network.</v>

218
00:27:52.601 --> 00:28:00.101
<v James Ball>I'm going to have phone customers. And you sort of team up with a real phone network to get their infrastructure, and they have to data share so that you could work a network. And then they actually use it to make these inquiries that they shouldn't be doing. And I think one of the issues that came up was very few people actually log how people were using these queries and whether they were restricting them only to their own customers, et cetera, because it never occurred to them to put it in, you know, and I think it was possible to audit this for various reasons. You just can't fix SS7 as a protocol.</v>

219
00:28:00.101 --> 00:28:07.601
<v James Ball>It's not like you could just do a patch, but this you could have done and just gone, well, if anyone's querying more than X times a day relative to their customer numbers, you know, we cut them off or we investigate. I think you could have put quite a lot of exceptions in. And I think that's what the bigger companies do. I think that's why you need these little backdoors. But for as long as there are little jurisdictions that can get you into bigger ones, as long as there are smaller phone companies that don't care very much, this will remain very vulnerable.</v>

220
00:28:07.601 --> 00:28:15.101
<v James Ball>And this is quite bad. There is a roaring trade in exploiting this. You know, there are security companies getting quite rich off this.</v>

221
00:29:22.813 --> 00:29:23.791
<v Graham Cluley>Yeah.</v>

222
00:29:23.791 --> 00:29:35.486
<v James Ball>People don't pay a lot of money to track this stuff unless they're using it. You know, the fact that there is a roaring trade in this tells you that there is a vulnerability and tells you that there is a problem here.</v>

223
00:29:35.486 --> 00:29:47.180
<v James Ball>If this was just academic, companies wouldn't be trading off it in this way, you know? And as I say, the getting snatched off a boat while trying to escape your dictatorial father is the extreme limit.</v>

224
00:29:47.180 --> 00:29:47.517
<v Graham Cluley>Yeah.</v>

225
00:29:47.517 --> 00:30:02.345
<v James Ball>But we know, you know, in the early days of the Syrian Civil War, when people were still trying to overthrow through activism, we know that mobile phone geolocation was used to sort of target opposition activists and either kill them with bombs or get them raided by the secret police. You know, we know the ways that this stuff can be exploited and it can be absolutely brutal.</v>

226
00:30:02.345 --> 00:30:17.173
<v James Ball>And so it's fairly unforgivable that it's not been fixed in so long. Sorry, this is a lot less fun than your topic.</v>

227
00:30:17.173 --> 00:30:27.321
<v Graham Cluley>No, no, no, that's right. I mean, it feels like there's quite a contrast here between this and spyware like Pegasus, which impacts individual phones, because</v>

228
00:30:27.321 --> 00:30:37.470
<v Graham Cluley>this is surveillance you're talking about happening at a network level, meaning even a perfectly secure handset can be tracked, one that's properly locked down.</v>

229
00:30:37.470 --> 00:30:48.064
<v James Ball>Certainly to an extent, because this is about what the network is doing and not what you are doing. Right.</v>

230
00:30:48.064 --> 00:30:58.659
<v James Ball>And that's worrying. I mean, especially, I don't know where you quite land on Mythos, but I sort of land to thinking ultimately it's going to be a defensive advantage because we've known that everything's had zero days in it since forever.</v>

231
00:30:58.659 --> 00:30:59.285
<v Graham Cluley>Yeah.</v>

232
00:30:59.285 --> 00:31:07.778
<v James Ball>When the NSA or GCHQ discover one, they are as likely to not tell us so they can exploit it as they are so we could use it to defend.</v>

233
00:31:07.778 --> 00:31:08.340
<v Graham Cluley>Yes.</v>

234
00:31:08.340 --> 00:31:15.357
<v James Ball>This is going to change that equilibrium because they're all much easier to expose and they will all be exposed quite quickly. I think you actually got to get a defensive equilibrium.</v>

235
00:31:15.357 --> 00:31:22.375
<v James Ball>I think things like Pegasus are going to suffer in the Mythos era.</v>

236
00:31:22.375 --> 00:31:22.695
<v Graham Cluley>Right.</v>

237
00:31:22.695 --> 00:31:29.826
<v James Ball>But that means that people will be looking for these network exploitations that can't just be patched, that aren't just about finding and getting rid of zero days that have gone missing for years.</v>

238
00:31:29.826 --> 00:31:36.955
<v James Ball>And so it's going to become more urgent to address these things.</v>

239
00:31:36.955 --> 00:31:44.086
<v James Ball>And that's a shame because we could have done this at any point in the last 10, 15 years.</v>

240
00:31:44.086 --> 00:31:53.663
<v Graham Cluley>Yeah, we've heard that story before, haven't we? I'm just wondering, for the average listener, their biggest threat is probably their nan rather than Mossad. Should they actually care about this?</v>

241
00:31:53.663 --> 00:32:03.241
<v Graham Cluley>Is this really only a problem if you're a journalist or a dissident or a high-profile target? What's your feeling on that?</v>

242
00:32:03.241 --> 00:32:12.566
<v James Ball>It kind of is only really a problem if you're a high-profile target, but you might be mistaken for a high-profile target. Yes.</v>

243
00:32:12.566 --> 00:32:21.891
<v James Ball>There are some people who have had some very unpleasant emails or some odd things because they have the same name as me. And I have at various times been tracked and surveilled by various governments for my sins.</v>

244
00:32:21.891 --> 00:32:31.214
<v James Ball>And if you happen to be called James Ball and you've done nothing wrong in your life and suddenly you're exploited because of this, that's not great. So mistaken identity can get you.</v>

245
00:32:31.214 --> 00:32:36.376
<v Graham Cluley>No, hang on, James. It feels to me like you are actually the problem there. You're a troublemaker.</v>

246
00:32:36.376 --> 00:32:39.790
<v James Ball>My fault for having a very common name as well. There are thousands of us.</v>

247
00:32:39.790 --> 00:32:46.378
<v Graham Cluley>Could you not rename yourself by deed poll, James Troublemaker Ball, just to protect the innocent James Balls which are out there?</v>

248
00:32:46.378 --> 00:32:52.157
<v James Ball>Why don't I go for a name like Graham Cluley? But the other thing is, a lot of people who become activists didn't plan to. A pal of mine, Hassan Akkad, was a schoolteacher in Syria, and he taught English in schools until the civil war started, and he started seeing people get disappeared and tortured. And he started filming that, and he was then himself detained and tortured and managed to escape.</v>

249
00:32:52.157 --> 00:32:57.936
<v James Ball>He's a British citizen these days. I've even seen him streak at cricket. How's that for naturalisation?</v>

250
00:32:57.936 --> 00:33:10.296
<v Graham Cluley>Naturalisation, I</v>

251
00:33:10.296 --> 00:33:22.655
<v Graham Cluley>think you'll find.</v>

252
00:33:22.655 --> 00:33:24.595
<v James Ball>Yes, there's context, I promise. Yeah, he was sort of saying it's not like he spent years training and preparing for how to be an activist and how to do it right. He had a very normal middle-class life in Syria until he suddenly didn't. And we sort of see how the world is changing and all these things are happening. And yeah, this stuff is all very far away from you until very suddenly it isn't. And so look, for most people listening to this, the thing you should worry about is actually, have you done the software update? On your phone, because if your apps are up to date and your software is up to date, that is way better than anything else you can do.</v>

253
00:33:24.595 --> 00:33:54.595
<v Graham Cluley>Yeah.</v>

254
00:33:57.932 --> 00:34:05.816
<v James Ball>But suddenly the world can shift.</v>

255
00:34:05.816 --> 00:34:13.699
<v James Ball>Hopefully it never becomes a problem for anyone listening, but it could.</v>

256
00:34:13.699 --> 00:34:21.472
<v Graham Cluley>Well, we've got time now to talk about one of today's sponsors, Vanta. Joe, what keeps you up at 2 o'clock in the morning?</v>

257
00:34:21.472 --> 00:34:23.268
<v Joe>The dog next door, mostly.</v>

258
00:34:23.268 --> 00:34:33.090
<v Graham Cluley>Oh, right.</v>

259
00:34:33.090 --> 00:34:42.914
<v Graham Cluley>Well, yeah, but I'm talking professionally.</v>

260
00:34:42.914 --> 00:34:52.735
<v Graham Cluley>What keeps you up?</v>

261
00:34:52.735 --> 00:35:02.983
<v Joe>Oh, whether we've got the right security controls in place, whether our vendors are</v>

262
00:35:02.983 --> 00:35:13.231
<v Joe>secure, how to escape the nightmare of outdated tools and endless manual processes.</v>

263
00:35:13.231 --> 00:35:32.773
<v Graham Cluley>Exactly, which is where today's sponsor comes in. It's Vanta.</v>

264
00:35:32.773 --> 00:35:42.773
<v Joe>Fanta, the fizzy orange drink.</v>

265
00:35:42.773 --> 00:35:52.773
<v Joe>How can this</v>

266
00:35:52.773 --> 00:36:02.773
<v Joe>possibly be true?</v>

267
00:36:10.958 --> 00:36:23.614
<v Joe>Lush, I hate questionnaires.</v>

268
00:36:23.614 --> 00:36:30.311
<v Graham Cluley>Well, who doesn't? Vanta continuously monitors your systems. It centralises your security data.</v>

269
00:36:29.405 --> 00:36:36.905
<v Graham Cluley>No, no, Joe, it's Vanta with a V.</v>

270
00:36:30.311 --> 00:36:37.007
<v Graham Cluley>It keeps your program audit ready all of the time. It also uses AI to streamline evidence collection and flag risks. It automates compliance for SOC 2, ISO 27001, HIPAA, GDPR, and more.</v>

271
00:36:36.905 --> 00:36:44.405
<v Graham Cluley>It's a trust management platform.</v>

272
00:36:37.007 --> 00:36:49.442
<v Joe>So basically it handles the boring stuff so we can focus on the interesting stuff. Exactly.</v>

273
00:36:44.405 --> 00:36:51.905
<v Graham Cluley>It's not a drink full of sugar.</v>

274
00:36:49.442 --> 00:36:56.268
<v Graham Cluley>Precisely that. And for a limited time, new customers can get $1,000 off. $1,000?</v>

275
00:36:51.905 --> 00:36:59.405
<v Graham Cluley>It automates all of that tedious manual compliance work so you can stop drowning in spreadsheets, chasing audit evidence, and filling out questionnaire after questionnaire.</v>

276
00:36:56.268 --> 00:37:03.096
<v Graham Cluley>Yep. $1,000. Head to vanta.com/smashing That's vanta.com/smashing and get started today.</v>

277
00:37:03.096 --> 00:37:12.849
<v Joe>And maybe get a decent night's sleep for once. Oh, and unlike fizzy drinks, Vanta isn't bad for you.</v>

278
00:37:12.849 --> 00:37:22.603
<v Joe>That was a fruit twist.</v>

279
00:37:22.603 --> 00:37:31.380
<v Graham Cluley>And welcome back, and you join us at our favourite part of the show, the part of the show that</v>

280
00:37:31.380 --> 00:37:40.155
<v Graham Cluley>we to call Pick of the Week.</v>

281
00:37:40.155 --> 00:37:54.875
<v James Ball>Pick of the Week.</v>

282
00:37:54.875 --> 00:38:04.875
<v Graham Cluley>Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app.</v>

283
00:38:04.875 --> 00:38:14.875
<v Graham Cluley>Whatever they wish. It doesn't have to be security related necessarily.</v>

284
00:38:14.875 --> 00:38:24.875
<v Graham Cluley>Now, James, do you remember a TV show called Name That Tune?</v>

285
00:38:24.556 --> 00:38:46.740
<v Graham Cluley>You're such a child.</v>

286
00:38:46.740 --> 00:38:58.762
<v James Ball>Am I too old for this?</v>

287
00:38:47.719 --> 00:38:57.719
<v James Ball>I don't think I do.</v>

288
00:38:57.719 --> 00:39:07.719
<v James Ball>Am I too</v>

289
00:38:58.762 --> 00:39:04.733
<v Graham Cluley>No, no. I think it's from my youth.</v>

290
00:39:04.733 --> 00:39:10.704
<v Graham Cluley>Anyway, you had battling contestants and they'd be given a clue about a song. And they'd have to bet in how few notes, you know, plonked out on the piano, they would be able to name that tune in.</v>

291
00:39:07.719 --> 00:39:17.719
<v James Ball>young for this?</v>

292
00:39:10.704 --> 00:39:21.126
<v James Ball>Oh, so like the intros</v>

293
00:39:21.126 --> 00:39:31.550
<v James Ball>around at a pub quiz?</v>

294
00:39:31.550 --> 00:39:37.550
<v Graham Cluley>Exactly so. And it was always very exciting because sometimes someone would say, I can name that tune in one. And it's like, ooh, it's going to be really exciting now.</v>

295
00:39:37.550 --> 00:39:43.550
<v Graham Cluley>And someone goes, donk, and they'd say it's whatever it is, you know. Now, James, I know that you love people sharing their musical tastes on social media.</v>

296
00:39:43.550 --> 00:39:53.521
<v James Ball>It's my absolute favourite thing.</v>

297
00:39:53.521 --> 00:40:03.492
<v James Ball>I love nothing more.</v>

298
00:40:03.492 --> 00:40:13.507
<v Graham Cluley>You love a Spotify Wrapped, don't you? I was reading one of your articles on</v>

299
00:40:13.507 --> 00:40:23.521
<v Graham Cluley>the New World, where you basically say you couldn't give a fuck about people's Spotify Wrapped.</v>

300
00:40:23.521 --> 00:40:29.985
<v James Ball>I should say in my own defence, we have an unofficial Christmas tradition at the New World where I ruin something that people love.</v>

301
00:40:29.985 --> 00:40:36.451
<v James Ball>And so one year I did why I hate It's a Wonderful Life.</v>

302
00:40:36.451 --> 00:40:53.440
<v Graham Cluley>Oh, wow.</v>

303
00:40:53.440 --> 00:41:00.298
<v James Ball>Because George should have died in prison. And Pottersville was much nicer in his town. And I'm sorry, your wife becoming a librarian and having a career is not a fate worse than death.</v>

304
00:41:00.298 --> 00:41:07.157
<v James Ball>But that was one year. And I think this was last Christmas I did, "Your Spotify rap is not interesting, so please shut up about it." So yeah, every Christmas I try and ruin something.</v>

305
00:41:07.157 --> 00:41:14.697
<v Graham Cluley>Well, it's my show, James, so I'm gonna have some fun.</v>

306
00:41:14.697 --> 00:41:22.237
<v Graham Cluley>Now, listeners know I'm a bit of a fan of the Beatles, and they released 213 tracks during their active career during those seven years.</v>

307
00:41:22.237 --> 00:41:28.306
<v James Ball>Sorry, the Beatles, were they that band that</v>

308
00:41:28.306 --> 00:41:34.375
<v James Ball>competed against Oasis?</v>

309
00:41:34.375 --> 00:41:44.795
<v Graham Cluley>I thought you were going to out yourself as</v>

310
00:41:44.795 --> 00:41:55.215
<v Graham Cluley>an Osmonds fan for a second there or something like that.</v>

311
00:41:55.215 --> 00:42:02.757
<v James Ball>I've seen the Rolling Stones. Actually, I've seen McCartney as well.</v>

312
00:42:02.757 --> 00:42:10.300
<v James Ball>So yeah, fine, fine.</v>

313
00:42:10.300 --> 00:42:17.282
<v Graham Cluley>Okay, okay. So I reckon I can name just about every Beatles song based upon only the first second of the track.</v>

314
00:42:17.282 --> 00:42:24.264
<v Graham Cluley>And hence, I have been having a lot of fun playing a game online called Think for Yourself at thinkforyourself.live. And I thought, James, I don't know if you know any Beatles tunes at all.</v>

315
00:42:24.264 --> 00:42:38.454
<v James Ball>Maybe about three.</v>

316
00:42:38.454 --> 00:42:45.954
<v Graham Cluley>Maybe about three. Okay, so I'll do this game.</v>

317
00:42:45.954 --> 00:42:53.454
<v Graham Cluley>I'm going to do it right now. I'm going to put myself to the test live.</v>

318
00:42:53.454 --> 00:43:00.954
<v Graham Cluley>So I'm going to run this, thinkforyourself.live. Okay, and I'm going to play a second and see if I can name the songs just to demonstrate.</v>

319
00:43:00.954 --> 00:43:08.454
<v Graham Cluley>And hopefully also won't be copyright infringing.</v>

320
00:43:07.023 --> 00:43:12.813
<v Graham Cluley>Okay, all right, we're going to try it. Okay, what's it going to do?</v>

321
00:43:12.813 --> 00:43:18.603
<v Graham Cluley>Oh, did you hear that?</v>

322
00:43:18.603 --> 00:43:33.617
<v James Ball>I did.</v>

323
00:43:33.617 --> 00:43:41.114
<v Graham Cluley>I'm going to play it again.</v>

324
00:43:41.114 --> 00:43:48.610
<v Graham Cluley>Okay, it's definitely a George Harrison one.</v>

325
00:43:41.331 --> 00:43:56.331
<v James Ball>I think one</v>

326
00:43:48.610 --> 00:43:55.675
<v James Ball>It's not early, is it?</v>

327
00:43:55.675 --> 00:44:02.737
<v James Ball>I mean, that's later.</v>

328
00:43:56.331 --> 00:44:11.331
<v James Ball>second counts as fair use.</v>

329
00:44:02.737 --> 00:44:07.181
<v Graham Cluley>No. Da da da da. No, it's not The Inner Light. It's not Within You Without You.</v>

330
00:44:07.181 --> 00:44:28.597
<v Unknown>You.</v>

331
00:44:28.597 --> 00:44:35.733
<v Graham Cluley>It's not, oh, oh, oh, oh, oh. I think it's Love U Too. I think it's called Love U Too from Revolver.</v>

332
00:44:35.733 --> 00:44:42.869
<v Graham Cluley>Let's see. I have to type in the name and it'll tell me if I got it correct.</v>

333
00:44:42.869 --> 00:45:12.869
<v James Ball>Correct. Well done.</v>

334
00:45:19.536 --> 00:45:27.556
<v James Ball>I was going to say, you ought to get</v>

335
00:45:27.556 --> 00:45:35.576
<v James Ball>that paused fast.</v>

336
00:45:35.576 --> 00:45:45.576
<v Graham Cluley>Oh, yes.</v>

337
00:45:45.576 --> 00:45:55.576
<v Graham Cluley>Okay, next one. Next one.</v>

338
00:45:55.576 --> 00:46:05.576
<v Graham Cluley>Oh, that's easy.</v>

339
00:46:08.885 --> 00:46:15.994
<v Graham Cluley>Everyone knows that.</v>

340
00:46:15.543 --> 00:46:45.543
<v Graham Cluley>Right.</v>

341
00:46:15.994 --> 00:46:23.101
<v Graham Cluley>Strawberry Fields Forever.</v>

342
00:46:23.101 --> 00:46:33.101
<v James Ball>I was going</v>

343
00:46:33.101 --> 00:46:43.101
<v James Ball>to say Strawberry</v>

344
00:46:43.101 --> 00:46:53.101
<v James Ball>Fields, isn't it?</v>

345
00:47:12.717 --> 00:47:20.891
<v Graham Cluley>So identifiable. Okay. Next.</v>

346
00:47:20.891 --> 00:47:29.068
<v Graham Cluley>Yeah. Okay. And let's move on.</v>

347
00:47:29.068 --> 00:47:42.592
<v James Ball>She's not.</v>

348
00:47:42.592 --> 00:47:49.610
<v Graham Cluley>Ah, she's not. Now that is the opening line of a song on The White Album called Happiness Is a Warm Gun.</v>

349
00:47:49.610 --> 00:47:56.628
<v Graham Cluley>The line is, she's not a girl who misses much. Oh, press confirm.</v>

350
00:47:55.329 --> 00:48:25.329
<v James Ball>Yeah.</v>

351
00:47:55.329 --> 00:48:25.329
<v Graham Cluley>Yeah.</v>

352
00:47:55.329 --> 00:48:25.329
<v James Ball>Yeah.</v>

353
00:47:56.628 --> 00:48:06.628
<v James Ball>She's not a</v>

354
00:48:06.628 --> 00:48:16.628
<v James Ball>girl who misses</v>

355
00:48:16.628 --> 00:48:26.628
<v James Ball>much. There we go.</v>

356
00:48:26.041 --> 00:48:39.972
<v James Ball>Go on. Go on. One more.</v>

357
00:48:39.972 --> 00:48:47.875
<v Graham Cluley>See if you can get this one.</v>

358
00:48:47.875 --> 00:48:55.777
<v Graham Cluley>Let's see what this is going to be.</v>

359
00:48:48.565 --> 00:48:58.565
<v Graham Cluley>This is fun, guys.</v>

360
00:48:55.777 --> 00:49:18.143
<v James Ball>Did you hear that?</v>

361
00:48:58.565 --> 00:49:08.565
<v Graham Cluley>Now, I could carry on for</v>

362
00:49:08.565 --> 00:49:18.565
<v Graham Cluley>a while, but should we do one more?</v>

363
00:49:18.143 --> 00:49:48.143
<v Graham Cluley>Play it again.</v>

364
00:49:48.663 --> 00:49:56.074
<v Graham Cluley>This isn't a very well-known song, but I know</v>

365
00:49:56.074 --> 00:50:03.485
<v Graham Cluley>what it is.</v>

366
00:50:03.485 --> 00:50:17.010
<v James Ball>No, I'm not going to get that.</v>

367
00:50:17.010 --> 00:50:23.717
<v Graham Cluley>It's an instrumental from the Magical Mystery Tour</v>

368
00:50:23.717 --> 00:50:30.425
<v Graham Cluley>EP called Fly.</v>

369
00:50:30.425 --> 00:50:37.811
<v James Ball>It gave me "I am the Eggman, I am the walrus" vibe. I could have got you that far, but I knew it wasn't that song.</v>

370
00:50:37.811 --> 00:50:45.197
<v James Ball>You know where you're meh.</v>

371
00:50:45.197 --> 00:50:55.197
<v Graham Cluley>Anyway, if you're me, I love a pub quiz as well. And if you the Beatles and you want to put yourself to the test, you can give yourself more seconds if you need more seconds.</v>

372
00:50:55.197 --> 00:51:05.197
<v Graham Cluley>It's all good fun. thinkforyourself.live is my pick of the week.</v>

373
00:51:04.284 --> 00:51:34.284
<v James Ball>Did.</v>

374
00:51:05.197 --> 00:51:15.197
<v Graham Cluley>James, what's your pick of the week?</v>

375
00:51:27.367 --> 00:51:33.789
<v James Ball>It's called nodesgame.com, and there's a little hyphen between nodes and game. And if you ever played Vertex on New York Times, it's technically a puzzle, but it's almost a paint-by-numbers.</v>

376
00:51:33.789 --> 00:51:40.211
<v James Ball>I encourage you to open it, Graham, as I sort of say it.</v>

377
00:51:40.211 --> 00:52:10.211
<v Graham Cluley>I'm trying it now.</v>

378
00:52:42.494 --> 00:52:49.318
<v Graham Cluley>I'm doing it right now. I mean, it is rather hard to describe to our audio listeners.</v>

379
00:52:49.318 --> 00:52:56.141
<v Graham Cluley>And I seem to have done it wrong because I've now got stuck. I have to work out how to reset or something.</v>

380
00:52:56.141 --> 00:53:03.333
<v James Ball>So if you double-click a dot where you've got it wrong,</v>

381
00:53:03.333 --> 00:53:10.525
<v James Ball>it goes back.</v>

382
00:53:10.525 --> 00:53:25.525
<v Graham Cluley>Ah, thank you.</v>

383
00:53:25.525 --> 00:53:40.525
<v Graham Cluley>Okay, now I'll do that.</v>

384
00:53:39.380 --> 00:53:45.947
<v Graham Cluley>Oh, I've created a diamond—okay, so I did a triangle and I've now created a diamond. Oh, this looks quite—yeah, okay.</v>

385
00:53:45.947 --> 00:53:52.512
<v Graham Cluley>Oh, and there's an app as well. You can get it for Android or iOS by the look of things.</v>

386
00:53:52.512 --> 00:53:58.655
<v James Ball>It is much better on a touchscreen. Yes. The triangles sort of compound to make big pictures. So some of them are recreations of Renaissance art, etc. Sometimes it's just a cute dog or something, or a plant.</v>

387
00:53:58.655 --> 00:54:04.797
<v James Ball>The plants are a nightmare because all of the stems are really hard to predict. But it's just a very therapeutic little corner of the internet that I really enjoy. I think I'm on a 130-day streak or something, which I try not to think about because the whole point is that it's quite restful and relaxing. And so I try not to care. It's just, I haven't missed a day.</v>

388
00:53:59.744 --> 00:54:09.744
<v James Ball>So, I feel obliged just to go, there's a new season of Taskmaster. I always feel quite happy when Taskmaster's on.</v>

389
00:54:04.797 --> 00:54:18.264
<v Graham Cluley>I'm looking right now at some of the images you can actually create with this. They're incredible.</v>

390
00:54:09.744 --> 00:54:19.744
<v James Ball>It sparks joy. It's very formulaic.</v>

391
00:54:18.264 --> 00:54:31.376
<v James Ball>They're genuinely quite pretty.</v>

392
00:54:19.744 --> 00:54:29.744
<v James Ball>It's very familiar, and I enjoy it a great deal when it's there. But I thought I would bring something else, and sadly, this one is visual rather than audio, but—</v>

393
00:54:31.376 --> 00:54:44.351
<v Graham Cluley>Yes.</v>

394
00:54:44.351 --> 00:54:52.380
<v James Ball>Today's, on the day we're recording, is a peacock and it's lovely. It also will let you produce a little vector video at the end of the order you solved it.</v>

395
00:54:52.380 --> 00:55:00.409
<v James Ball>So you get to see a video of it drawing it exactly as you drew it, which again is just very charming.</v>

396
00:55:00.409 --> 00:55:18.902
<v Graham Cluley>It looks very nice.</v>

397
00:55:18.902 --> 00:55:25.969
<v James Ball>By the way, I received no sponsorship from them for this.</v>

398
00:55:25.969 --> 00:55:33.036
<v James Ball>I pay them money, not the other way around.</v>

399
00:55:33.036 --> 00:55:43.036
<v Graham Cluley>It looks like it's free, but I guess</v>

400
00:55:43.036 --> 00:55:53.036
<v Graham Cluley>it's ad-supported or something. So you can pay</v>

401
00:55:48.112 --> 00:56:18.112
<v Graham Cluley>Okay.</v>

402
00:55:53.036 --> 00:56:03.036
<v Graham Cluley>them some money to—</v>

403
00:56:01.112 --> 00:56:19.967
<v Graham Cluley>Okay.</v>

404
00:56:19.967 --> 00:56:27.108
<v James Ball>But it's, I think it's one guy or</v>

405
00:56:27.108 --> 00:56:34.246
<v James Ball>two people, so.</v>

406
00:56:34.246 --> 00:56:50.527
<v Graham Cluley>Yeah, support them.</v>

407
00:56:35.528 --> 00:56:45.528
<v James Ball>And you essentially get a dot puzzle, and it's not quite join the dots, it's form the triangles. And if you make it right, the triangle colours in, and it tells you how many lines come from each dot.</v>

408
00:56:45.528 --> 00:56:55.528
<v James Ball>And so each day there is one correct picture that you're drawing by joining up the dots correctly. And it is incredibly soothing.</v>

409
00:56:50.527 --> 00:56:57.072
<v James Ball>I chucked them some money on Patreon. Because it's lovely.</v>

410
00:56:55.528 --> 00:57:05.528
<v James Ball>I do it first thing in the morning or last thing at night as a bit of zen. And they've got some little tutorials which are quite basic, but then the smallest puzzles you tend to see are about 200 lines.</v>

411
00:56:57.072 --> 00:57:03.615
<v James Ball>It's nice. It's calm.</v>

412
00:57:03.615 --> 00:57:09.005
<v Graham Cluley>So the game you can find in your app stores, it's called Nodes: Connect Dots to Relax. Or you can go and check it out on the web at nodes-game.com. Very cool. Well, Iranian hackers are actively targeting US critical infrastructure. They're disrupting power and water systems, ransomware systems, and they're simultaneously going after Microsoft 365 environments that keep those type of organizations running.</v>

413
00:57:09.005 --> 00:57:14.393
<v Graham Cluley>They're doing all this at a moment when America's main cyber defense agency, CISA, is operating at reportedly just 40% capacity. So the timing could not be worse. Here to talk about what energy and utilities companies need to do about it is Rob Edmondson from CoreView. Hello, Rob. Welcome back to the show, Joe.</v>

414
00:57:14.393 --> 00:57:22.054
<v Rob Edmondson>Hi, Graham. Always great to be with you.</v>

415
00:57:22.054 --> 00:57:29.715
<v Rob Edmondson>How you doing today?</v>

416
00:57:29.715 --> 00:57:38.121
<v Graham Cluley>I'm not too bad at all. Thanks for joining us.</v>

417
00:57:38.121 --> 00:57:46.527
<v Graham Cluley>So 6 federal agencies have now confirmed that Iranian hackers are actively disrupting energy and water systems. How alarmed do you think we should be about that?</v>

418
00:57:46.527 --> 00:57:54.027
<v Rob Edmondson>I think that it's a big deal. It's representative of a big strategy.</v>

419
00:57:54.027 --> 00:58:01.527
<v Rob Edmondson>I think if you look at the Western economies, which components of those economies can you hit to have the biggest impact? And the grid, our energy is a huge thing because the dominoes fall quite quickly if you can hit those.</v>

420
00:58:01.527 --> 00:58:09.027
<v Rob Edmondson>So I think it might be a case of flexing on the one hand, right, to kind of say, this is what we're able to do, watch out. But if things progress, then that can progress as well.</v>

421
00:58:09.027 --> 00:58:16.527
<v Rob Edmondson>It can escalate. And like I said, the dominoes can fall quite quickly when it comes to energy.</v>

422
00:58:14.847 --> 00:58:20.896
<v Rob Edmondson>Gosh, it all depends on escalation, right? But I think there is a possibility if things keep escalating, then we should assume that these energy companies will be hit and we absolutely shouldn't assume that it's gonna be small. I think one of the things when it comes to nation-state cybersecurity is these countries will have people and have access ready to roll for situations when they need them. We shouldn't assume that every single time North Korea, Iran, Russia gets inside your environment, they're gonna hit the button right away.</v>

423
00:58:20.896 --> 00:58:26.943
<v Rob Edmondson>Actually having access ready to use in the moments when they want it is extremely useful. So we should assume that there's been a lot of preparation for a moment like this to ensure that they've got leverage. And the implications in terms of energy and the grid can be quite major. You know, if the grid goes down, things start to collapse pretty quickly.</v>

424
00:58:26.943 --> 00:58:34.112
<v Graham Cluley>And it's not just critical infrastructure we need to be worried about this. It's all kinds of business. These hackers are password spraying Microsoft 365 environments, aren't they?</v>

425
00:58:34.112 --> 00:58:41.282
<v Graham Cluley>I mean, it feels like this is connected. This is a way in.</v>

426
00:58:41.282 --> 00:58:49.061
<v Rob Edmondson>Yeah, absolutely. You've obviously got the physical infrastructure, which is a great target. But then you've got the digital workspace and the sort of flip sides of the same coin. Microsoft 365 has become this kind of central component to the work the economy is trying to do, right? Every organization now relies on this platform and all of its small components to do everything.</v>

427
00:58:49.061 --> 00:58:56.840
<v Rob Edmondson>So again, if you want to do a rug pull, focusing on that is a fantastic area to cause serious damage. You know, password spraying is going on all the time. The fact that it's targeting Microsoft 365 is nothing new, but as things start to escalate, we should assume it's gonna happen more and more. So it's definitely concerning.</v>

428
00:58:56.840 --> 00:59:03.208
<v Graham Cluley>Now, the most recent high-profile victim of one of these attacks is one of the world's largest medical tech companies, a company called Stryker, and they make surgical equipment and all kinds of stuff like that. It's supplied to hospitals worldwide. And this is a company with big resources, $25 billion of revenue, and they still got hit.</v>

429
00:59:03.208 --> 00:59:09.577
<v Graham Cluley>And what we've been reading in recent weeks is that it was Microsoft Intune, which was basically turned against itself. And as a consequence, that admin tool effectively was used to wipe out 200,000 devices across that organization. So that's a bit of a wake-up call, isn't it?</v>

430
00:59:09.577 --> 00:59:16.628
<v Rob Edmondson>Yeah, it's a huge, huge wake-up call. Also, the way you framed it, I think, is so correct. It's this idea that the tools that we're relying on, right? I'm using Intune to manage my devices. And thank goodness I have Intune because otherwise I wouldn't be able to do it.</v>

431
00:59:16.628 --> 00:59:23.677
<v Rob Edmondson>But that same tool is turned against us now because the moment it's compromised, I can use that centralized control to cause mass mayhem. And it's interesting because we tend to think of identity as this core layer, but actually these components of your Microsoft 365 environment, like Intune, they have such huge power, such huge centralized control. So yes, 200,000 devices wiped and a lot of chaos. And I think it was 2 to 3 weeks before they felt they could say the business was getting back up to where it was. So, you know, it's a long time.</v>

432
00:59:23.677 --> 00:59:30.255
<v Graham Cluley>Yeah. It is something I think which stops people in their tracks because it's not malware being used.</v>

433
00:59:25.842 --> 00:59:55.842
<v Graham Cluley>Oh my goodness.</v>

434
00:59:30.255 --> 00:59:36.833
<v Graham Cluley>It's a legitimate program, which many organizations do use to manage not only their own devices, but sometimes there will be employees who've enrolled their own personal devices.</v>

435
00:59:36.833 --> 01:00:06.833
<v James Ball>Yes.</v>

436
01:00:02.940 --> 01:00:10.840
<v Rob Edmondson>Yeah, that's a real nightmare, isn't it? It's this sort of entanglement of devices altogether. Even your own private property can be impacted. I think one thing I found quite interesting was, like you said, there is no malware or ransomware involved here. This wasn't some sort of sophisticated hacking in to get this or that. One thing that was involved was they recently announced there was a malicious phishing, which is different to malware or ransomware, which was deployed in the environment, which was executing commands in a sort of a hidden way, which is quite interesting. It's interesting for two reasons. Number one, when they first came out, they were very keen to say no malware, no ransomware.</v>

437
01:00:09.507 --> 01:00:19.507
<v James Ball>And the bigger ones are about 1,000. So it can take a good half hour.</v>

438
01:00:10.840 --> 01:00:18.739
<v Rob Edmondson>Later on, as they did more investigations, they keep finding new things. So, you know, every day when news comes out, we think we understand what's happened, but the company themselves have to keep updating what it is that they're saying. So, you know, they don't necessarily have all the information on day one. And so we're all constantly learning together, but that malicious file may well have been making changes in the environment, which went undetected, which is another issue. Do we have visibility of all the changes that are going on in our environments? Because when cyber attackers attack, they want to make changes. They want to change your security posture to suit their needs, so you need to have a way to detect that.</v>

439
01:00:18.739 --> 01:00:27.023
<v Graham Cluley>Yeah. And these configurations, they can over time drift, can't they? You know, things can become insecure without you noticing just through normal work.</v>

440
01:00:19.507 --> 01:00:29.507
<v James Ball>But if you're just looking for something quite therapeutic and quite chill, it is one of the most enjoyable little phone sort of games that I play. And there's only about 1,000 people a day do it.</v>

441
01:00:20.423 --> 01:00:50.423
<v James Ball>That.</v>

442
01:00:27.023 --> 01:00:35.306
<v Graham Cluley>It's sometimes hard to lock these things down. How fast does configuration drift actually happen?</v>

443
01:00:29.507 --> 01:00:39.507
<v James Ball>So it's quite niche.</v>

444
01:00:35.306 --> 01:00:41.565
<v Rob Edmondson>Well, it depends what kind of drift you're talking about, because, you know, there's loud configuration drift, which is just where someone makes a change and immediately everyone knows about it, right? You know, you've been locked out of your tenant or you've opened the floodgates and suddenly you're surging with spam. But then there's quiet configuration changes, and this goes back to the nation-state point. When someone gets into your environment, whether it's the digital operation environment, whatever it is, if they're gonna try and just make a footprint and stay there, they're not gonna be making the loud configuration changes that you notice before it's too late. It'll be the quiet ones in preparation for whatever it is that they're going to do. So most people out there, when they hear about configuration tampering in this context may say, well, we're not experiencing that.</v>

445
01:00:41.565 --> 01:00:47.827
<v Rob Edmondson>But the key thing is how many of your platforms are designed to tell you when it happens, right? And if someone's in there making those quiet changes in preparation for something else, you know, do you have visibility over that? So whether you're looking at your Microsoft 365 tenant or any other environment, being able to have visibility of how configurations change is critical because it does happen quite a lot, sometimes accidentally as well. I mean, sometimes it'll be an administrator who accidentally makes a change, which leads to a breach, or it can even be Microsoft rolling out an update, which actually leads to your configuration state being changed because we live in the cloud now, right? Microsoft rolls updates out and quite often there's an impact on that, which organizations just have to deal with.</v>

446
01:00:47.827 --> 01:00:55.235
<v Graham Cluley>And one of the issues is there are so many configuration settings, aren't there? It's like you won't necessarily know what has and hasn't been changed and it might be easiest to go to a backup, you know, if you've got a backup of your configuration to roll it back.</v>

447
01:00:55.235 --> 01:01:02.643
<v Graham Cluley>But how easy is that to do?</v>

448
01:01:01.922 --> 01:01:11.922
<v James Ball>You can do the daily puzzle for free, or they've got</v>

449
01:01:02.643 --> 01:01:12.528
<v Rob Edmondson>Yeah, it's a really good point. I mean, there are so many configurations now across all of our environments and for good reason, because actually we need to be able to fine-tune these services to meet our own needs, right? I want to be able to set things up so that I have enough openness so I can collaborate in the specific way my organization needs to. But I also need to make sure it's secure despite that in a way that makes sense for my business. And so for me to build that customized experience, there needs to be a lot of configurations. So monitoring them all is a nightmare. I can't just go in and check them every morning. You know, we sometimes work with organizations, we'll go in there and they have a team of people who go in every couple of weeks. They're going in and reviewing everything in detail for 2 to 3 weeks to have confidence. So this is a mammoth task.</v>

450
01:01:11.922 --> 01:01:21.922
<v James Ball>hundreds in the archives. And to do those, you pay them,</v>

451
01:01:12.528 --> 01:01:22.414
<v Rob Edmondson>And, you know, one of the biggest challenges they have when they first start doing this is they don't even know what their configuration state should be. And so, this comes back to what you were saying, Graham. Do you have a record of what your ideal configuration state is? Could you even classify that as a backup? And if it's a real backup, does that mean you can recover your configurations rapidly after an incident? Those kinds of questions are questions we must be asking, given how high the stakes are right now, given that these cybercriminals aren't just attacking, you know, the grid, although some people listening may be working on the cybersecurity for various energy companies. The general goal seems to be to demonstrate the leverage they have, the access they have to ensure that they can push negotiations in their favor. We should assume that as negotiations proceed, there's going to be more and more of this kind of stuff happening to say, hey, look, actually we have a lot of leverage over you and it might be your organization that's targeted. So configuration backups, configuration drift detection, these are going to be really important things.</v>

452
01:01:21.922 --> 01:01:31.922
<v James Ball>I think, about £3 a month.</v>

453
01:01:22.414 --> 01:01:28.429
<v Graham Cluley>So Rob, what can CoreView do</v>

454
01:01:28.429 --> 01:01:34.445
<v Graham Cluley>about all this?</v>

455
01:01:34.445 --> 01:01:41.369
<v Rob Edmondson>Well, you know, given how much is going on, no one can solve everything. Okay, we're not going to make huge promises here, but there are certain things that we've described that you need certain types of capabilities to deal with them.</v>

456
01:01:41.369 --> 01:01:48.295
<v Rob Edmondson>You know, the example you talked about there about Intune is huge.</v>

457
01:01:48.295 --> 01:02:01.269
<v James Ball>Yeah.</v>

458
01:02:01.269 --> 01:02:10.759
<v Rob Edmondson>Because it points out that an organization can set up best practice endpoint management and everything's smooth and slick, but it's still overprivileged. And by default in Microsoft 365, the privileged accounts that you use are extraordinarily privileged. And that's why that attack was able to happen. So, we've all invested in the last 10 years in identity security, privileged access management. Frankly, some of the people listening probably will have spent over 7 figures in terms of time, investment, software licenses. Some organizations have spent so much more than that. And so, there's this question, which is, well, it's 2026, and you are telling me that one of my most important environments is still massively overprivileged despite the investments we've made. There's a big issue here, which is the traditional tool sets are designed to manage privileges, not to reduce them. We need to be super clear about this. A privileged access management tool, traditionally what it does is it takes that Intune account and it puts it in a vault. And then, Graham, when it's time for you to do your administration, I force you to authenticate to get access to it. And, you know, we've got a little audit trail showing that you're using it, et cetera. The problem with that is, for all of its benefits, it doesn't drive down the amount of privilege that you have. Which means that if someone with the wrong ideas, whether it's you or someone else, gets access to that power, it could be game over. So what we need to do is we need to complement our existing identity and privilege plans with a true plan to reduce the amount of privileges associated with these accounts. So in this case, if someone gets control of an Intune admin account, yeah, they could wipe the devices, but maybe it would only be 500 devices. Yeah, because that admin account would be designed for that specific sub-region of the organization because the individual who uses it very rarely needs to manage 200,000 devices. And if they do, they need to have a little holiday because it's too much work, right?</v>

459
01:02:07.001 --> 01:02:14.501
<v Graham Cluley>And the group which appears to be playing with those dominoes is this CyberAvengers group who've been linked to the Iranian state.</v>

460
01:02:10.759 --> 01:02:20.246
<v Rob Edmondson>This is, it's unnecessary. What you want to have is fine-grained privileges. So CoreView can do something really cool here. What we do is we create a management layer for your Microsoft 365 tenant. So this is an enhanced interface, which is all in one place. It's a CoreView, right? You don't have to jump between Intune, Azure, SharePoint, all these different things. It's one experience. But what we do is we give you the ability to create virtual tenants and a virtual tenant. It's, it's, well, you know, Graham, you've just joined my IT team and I'm training you up. I'm gonna give you access to 5 devices and 3 mailboxes or, you know, 2 identities, whatever it is. I can basically drop those into the virtual tenant and then I can assign you to it and I can even then control your privileges further. I can say, well, you can only do these sorts of things in this environment. What this does is it massively reduces the privilege associated with each administrator. And the kicker here is once I've assigned you that admin access through the portal, I can deprovision the Intune or Entra or whatever account it was you were using before, which had those absurd levels of privileges. Now you're still going to need some break glass accounts, which you can put in a vault and you can add rigorous levels of security to it. So if anyone ever wants that incredibly powerful break glass account, you know, there's now extra levels of security and it's really highly monitored because there's only a few of them. But day-to-day administration is done through this more least privileged framework.</v>

461
01:02:14.501 --> 01:02:22.001
<v Graham Cluley>They've been at this for a few years now.</v>

462
01:02:20.246 --> 01:02:29.735
<v Rob Edmondson>So that's one area where if people have seen what's happened here and they're thinking, oh my gosh, we really can't let that happen to us. We also have a massively overprivileged Intune or whatever part of the 365 tenant it is. There are ways you can actually achieve least privilege. So it's no longer a pipe dream using CoreView, you can actually achieve true least privilege. There's another component as well, which is sometimes people still need to manage those actual Microsoft 365 portals once in a while. They want to go in, or even if they're not supposed to be in there and somehow they get in, what are they going to do? Well, they're going to change configurations and do things, right? So you need a mechanism that can detect when changes are occurring and allows you to get quick visibility and to determine whether or not those changes are okay. So configuration drift detection, configuration tampering. And the other component here is, do you have your configurations backed up? Are you able to rewind them after an incident as well? Because as these attacks go on, one of the ways that cybercriminals can show their muscle is by deleting huge parts of your identity infrastructure, your distribution groups, changing all your configurations or deleting them, or taking your entire tenant away from you and forcing you to start again. These are all things that we see happen at CoreView. We work with large organizations around the world. You would be blown away how often this stuff happens. It's not announced in the press. It's not talked about in the media because people don't want to share quite how embarrassing the situation is. But we should assume it's going to happen more because the native controls don't give you that visibility or backup.</v>

463
01:02:22.001 --> 01:02:29.501
<v Graham Cluley>There's been attacks on water authorities, there's been custom malware built for industrial control systems, Rockwell controllers.</v>

464
01:02:29.501 --> 01:02:37.001
<v Graham Cluley>Where do you think this is gonna end?</v>

465
01:02:29.735 --> 01:02:47.197
<v James Ball>Okay.</v>

466
01:02:47.197 --> 01:02:57.760
<v Graham Cluley>Well, I'm sure you've piqued many people's interest today, and if people want to follow up, you can go and download Total Tenant Takeover, a whitepaper about The Microsoft 365 Disaster That No One Appears to Be Ready For. To go and grab your copy, go to smashingsecurity.com/coreview.</v>

467
01:02:57.760 --> 01:03:08.320
<v Graham Cluley>Well, thank you very much, Rob, for joining us today. Fascinating as always, and we appreciate you coming on and sharing your expertise.</v>

468
01:03:08.320 --> 01:03:15.155
<v Rob Edmondson>Thanks, Graham.</v>

469
01:03:15.155 --> 01:03:21.989
<v Rob Edmondson>Always good to speak with you.</v>

470
01:03:21.989 --> 01:03:28.824
<v Rob Edmondson>See you again.</v>

471
01:03:28.824 --> 01:03:35.846
<v Graham Cluley>Excellent stuff. And that just about wraps up the show for this week. Thank you so much, James, for joining us.</v>

472
01:03:35.846 --> 01:03:42.867
<v Graham Cluley>I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way for people to do that?</v>

473
01:03:41.019 --> 01:03:51.019
<v Graham Cluley>And they will</v>

474
01:03:42.867 --> 01:03:50.043
<v James Ball>So I am @JamesRBUK on X, but I very rarely post there.</v>

475
01:03:50.043 --> 01:03:57.219
<v James Ball>I'm @JamesBall.com on Bluesky, and I am around on LinkedIn and all the other various things under my real name.</v>

476
01:03:51.019 --> 01:04:01.019
<v Graham Cluley>have been wiped</v>

477
01:03:57.219 --> 01:04:04.175
<v Graham Cluley>Smashing. And you can find me, Graham Cluley, on LinkedIn or follow Smashing Security on Bluesky or Mastodon and all the usual places. And don't forget to ensure you never miss another episode, follow Smashing Security in your favorite podcast app such as Apple Podcasts, Spotify, and Pocket Casts for episode show notes, sponsorship info, guest lists, and the entire back catalog of 465 episodes.</v>

478
01:04:01.019 --> 01:04:11.019
<v Graham Cluley>as well as a consequence.</v>

479
01:04:04.175 --> 01:04:11.132
<v Graham Cluley>Check out smashingsecurity.com. Until next time, cheerio. Bye-bye.</v>

480
01:04:11.132 --> 01:04:27.277
<v James Ball>Goodbye.</v>

481
01:04:27.277 --> 01:04:27.599
<v Graham Cluley>You've been listening to Smashing Security with me, Graham Cluley. I'm ever so grateful to James Ball for joining us this week and to this episode's sponsors, Elastic, Vanta, and CoreView. And also to the following fine folks: Matt, who spells it with one T, is therefore statistically unique in our Patreon list, which contains an alarming number of Matts with two Ts. Philip Brannigan, a fine and upstanding name, I have to say. Robert Odegaard, a name I pronounce with great confidence and probably zero accuracy. Corey Jason B., keeping his last name there redacted, very on brand. Orberus, sounds like an upmarket hair color. Maya McDonald. Sonke von Repel, who not only has an umlaut in his name, he also has a von, therefore automatically the most aristocratic person on our Patreon. Daniel Kromeck, and Dave Ellefson, who shares a name with the bassist from Megadeth. I really hope it's the same person. Anyway, thank you all so much. You are absolute stars. Those are just a few members of Smashing Security Plus, which means that they get episodes ad-free earlier than the general public, and they can have their names pulled out at random to be mocked at the end of the show. If you'd like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details. You can become a patron, but you can also support the show in plenty of ways that don't cost a penny. You can like, subscribe, leave a 5-star review wherever you listen, and tell your friends about the show. Simply spread the word. That's what I'd encourage you all to do. Go on, tell someone, because every little bit helps, and it makes all the effort worthwhile. Well, I hope you have enjoyed this week's show and you will tune in next week when we plan to have yet another spectacular guest join us to hear all about the crazy stories from the world of cybersecurity. Until then, cheerio, bye-bye, toodle-oo.</v>
