WEBVTT

1
00:00:03.454 --> 00:00:10.954
<v Unknown>I have to say, despite the fact that I have used it, I do feel completely dirty and appalled at myself for having used it. And my opinion on that has strengthened only over time.</v>

2
00:00:10.954 --> 00:00:18.454
<v Unknown>So I do think it's completely reprehensible of me. Yes.</v>

3
00:00:18.454 --> 00:00:25.954
<v Unknown>Smashing Security, episode 477. How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.</v>

4
00:00:25.954 --> 00:00:33.454
<v Unknown>Hello, hello, and welcome to Smashing Security episode 477. My name's Graham Cluley.</v>

5
00:00:45.664 --> 00:00:46.548
<v James Ball>And I'm James Ball.</v>

6
00:00:46.548 --> 00:00:54.411
<v Graham Cluley>James, welcome back to the show. Always a pleasure to have you.</v>

7
00:00:54.411 --> 00:01:02.276
<v Graham Cluley>Now, I was following you on Blue Sky and I saw that you had an unusual way of handling the extreme heat which we were experiencing a couple of weeks ago. Many people have been caught out by those scam adverts on YouTube for things which claim to be able to air condition your room.</v>

8
00:01:02.276 --> 00:01:10.140
<v Graham Cluley>But what did you do?</v>

9
00:01:10.140 --> 00:01:13.506
<v James Ball>I mean, the good news is I didn't fall for any scams.</v>

10
00:01:13.506 --> 00:01:14.371
<v Graham Cluley>Good, well done.</v>

11
00:01:14.371 --> 00:01:20.992
<v James Ball>The bad news is I went insane and booked myself flights right up to the Arctic Circle. And so I spent a week up in Tromsø in northern Norway.</v>

12
00:01:20.992 --> 00:01:27.612
<v James Ball>Norway goes a long way up.</v>

13
00:01:27.612 --> 00:01:27.837
<v Graham Cluley>Yes.</v>

14
00:01:27.837 --> 00:01:34.606
<v James Ball>And Tromsø is right at the top. It's the gateway to the Arctic.</v>

15
00:01:34.606 --> 00:01:41.376
<v James Ball>24-hour sunshine this time of year, but crucially never got above 15 degrees. Truly delightful.</v>

16
00:01:41.376 --> 00:01:45.878
<v Graham Cluley>And was this an intentional reaction to the weather situation we were suffering from?</v>

17
00:01:45.878 --> 00:01:55.844
<v James Ball>It was fully 100% a reaction to the heatwave. I booked the travel, I think, 30 hours before I got the plane.</v>

18
00:01:55.844 --> 00:01:56.721
<v Graham Cluley>Right.</v>

19
00:01:56.721 --> 00:02:09.066
<v James Ball>And it was genuinely a result of Googling, where can I go that's cold? And there were lots of sort of things where it's like, well, about £20, or this place is also in the heatwave.</v>

20
00:02:09.066 --> 00:02:21.411
<v James Ball>Northern Scotland was really expensive. And it turned out that actually going up to the Arctic — I mean, I spent a week there and including the flights, it cost me less than £1,000.</v>

21
00:02:21.411 --> 00:02:25.567
<v Graham Cluley>And you got to see the England-Norway World Cup game as well, I think.</v>

22
00:02:25.567 --> 00:02:33.067
<v James Ball>Yes, in Norway, they had screens up in the town square full of very drunk Norwegians who — yeah, I don't think they were cheering on England, you know. Although the nice thing was the day after, I was sort of worried I'd have to try and put on a really terrible American accent or something. And they did all sort of say, look, just beat Argentina.</v>

23
00:02:33.067 --> 00:02:40.567
<v James Ball>We don't want Argentina to win. And I heard that from 3 or 4 different people. So they were kind of okay with it.</v>

24
00:02:40.567 --> 00:02:48.067
<v James Ball>They were cooler than they could have been. But strongly recommend it. Tromsø is great.</v>

25
00:02:48.067 --> 00:02:55.567
<v James Ball>Just don't get a curry there. Norway does not do spice. I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.</v>

26
00:03:06.812 --> 00:03:16.812
<v Graham Cluley>Well, before we kick off, let's thank this week's wonderful sponsors, Arctic Wolf, NordLayer, and Vanta. We'll be hearing about them later on in the podcast.</v>

27
00:03:16.812 --> 00:03:26.812
<v Graham Cluley>This week on Smashing Security, we won't be talking about how a man in India has been accused of using an AI chatbot to help him plan a triple murder. You'll hear no discussion of how the July 2026 patch update from Microsoft comes with security updates for a record-breaking 570 vulnerabilities.</v>

28
00:03:26.812 --> 00:03:36.812
<v Graham Cluley>And we won't even mention how plugging in an LG monitor can automatically install adware on your Windows PC that bombards you with McAfee pop-ups without ever asking your permission. So James, what are you going to be talking about this week?</v>

29
00:03:57.653 --> 00:04:02.848
<v James Ball>I am going to be talking about the Suno hack because I think there's quite a lot in there.</v>

30
00:04:02.848 --> 00:04:09.736
<v Graham Cluley>And I'm going to be discussing why ordering McNuggets may not be good for your online privacy, particularly if you're a hacker.</v>

31
00:04:09.736 --> 00:04:16.624
<v Graham Cluley>All this and much more coming up in this episode of Smashing Security.</v>

32
00:04:16.624 --> 00:04:23.512
<v Graham Cluley>Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today's sponsors, Vanta.</v>

33
00:04:23.512 --> 00:04:30.293
<v Joe>We've got a question for you. What's the thing that keeps you staring at the ceiling at 2 AM when it comes to your company's security?</v>

34
00:04:30.293 --> 00:04:37.682
<v Graham Cluley>Is it wondering whether you've actually got the right controls in place? Whether one of your suppliers has been quietly compromised, or is it the truly soul-destroying one?</v>

35
00:04:37.682 --> 00:04:45.072
<v Graham Cluley>Why on earth are we still running our entire security program out of a spreadsheet?</v>

36
00:04:45.072 --> 00:04:51.596
<v Joe>If any of that hit a little too close to home, that's where Vanta comes in.</v>

37
00:04:51.596 --> 00:04:58.122
<v Joe>Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.</v>

38
00:04:58.122 --> 00:05:12.846
<v Graham Cluley>Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place and keeps your security programme audit-ready around the clock.</v>

39
00:05:12.846 --> 00:05:27.571
<v Graham Cluley>Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on. The upshot of this is you move faster, scale without the usual headaches, and maybe, just maybe, actually get a decent night's sleep.</v>

40
00:05:27.571 --> 00:05:32.860
<v Joe>Sounds lush. Find out more and get started at vanta.com/smashing.</v>

41
00:05:32.860 --> 00:05:40.360
<v Graham Cluley>That's vanta.com/smashing, and a big thank you to Vanta for supporting the show. Now, chums, chums, imagine if you can that you are a spy working for the Russians, all right?</v>

42
00:05:40.360 --> 00:05:47.860
<v Graham Cluley>What's the worst thing that could possibly occur if you were actually working for the Russians? Would your biggest threat be having your identity exposed, being found out by the FBI?</v>

43
00:05:47.860 --> 00:05:55.360
<v Graham Cluley>Would it be about Western intelligence agencies finding out where you're based, locating your identity and extraditing you? Or would the biggest threat actually be about Chicken McNuggets?</v>

44
00:05:55.360 --> 00:06:02.860
<v Graham Cluley>That is the thing we're going to be exploring. Do you stand anywhere in particular on Chicken McNuggets, James?</v>

45
00:06:20.913 --> 00:06:28.052
<v James Ball>I'm actually a big fan of them. For a long time as a kid, I ate very little else.</v>

46
00:06:28.052 --> 00:06:35.189
<v James Ball>And so I've travelled in many, many countries in the world and every single one that had a McDonald's, I've been to the McDonald's in that country.</v>

47
00:06:35.189 --> 00:06:36.230
<v Graham Cluley>Oh my goodness, James.</v>

48
00:06:36.230 --> 00:06:44.709
<v James Ball>I've had McNuggets in India, in China, in Australia, and in Norway. Indian McNuggets are the best, by the way.</v>

49
00:06:44.709 --> 00:06:48.709
<v Graham Cluley>Oh, there's a difference, is there, between McNuggets? I can't believe we're having this conversation, but—</v>

50
00:06:48.709 --> 00:06:53.069
<v James Ball>I should stress, I eat in normal, good restaurants as well. This isn't expensive.</v>

51
00:06:53.069 --> 00:06:55.269
<v Graham Cluley>Oh, good, okay. That's reassuring, at least.</v>

52
00:06:55.269 --> 00:06:57.730
<v James Ball>So this would be bad news for me.</v>

53
00:06:57.730 --> 00:07:05.230
<v Graham Cluley>Well, back in September 2024, Dutch cybersecurity experts discovered that someone had burrowed into the computer systems of the Netherlands National Police Force and they had accessed the email account of a staff member there. And via that account, they had then grabbed the data of tens of thousands — I think over 64,000 — officers in the force.</v>

54
00:07:05.230 --> 00:07:12.730
<v Graham Cluley>Officers' names, addresses, identities, also of their informants. The Dutch intelligence agency at the time described it as the first time that the country had fallen victim to deliberate sabotage by a Russian-backed hacking group.</v>

55
00:07:12.730 --> 00:07:20.230
<v Graham Cluley>It caused a big furore in the press, as you can expect, and they didn't break in to plant ransomware or extort money — this was all about stealing intelligence, gathering intel in order to exploit it later. So this was effectively a police force's entire contact database — you know who the police are, who they're talking to, who talks to them.</v>

56
00:07:20.230 --> 00:07:27.730
<v Graham Cluley>And Microsoft, working with Dutch intelligence, publicly named the hacking group responsible for this back in May 2025 as Void Blizzard. I love the names which are sometimes given to these groups.</v>

57
00:08:13.101 --> 00:08:17.509
<v James Ball>It sounds like a World of Warcraft patch, doesn't it?</v>

58
00:08:17.509 --> 00:08:24.963
<v Graham Cluley>Yes. I mean, they called it Void Blizzard. There was another group of researchers who I believe called them Laundry Bear.</v>

59
00:08:24.963 --> 00:08:31.096
<v James Ball>Well, that would probably be the official US designation, wouldn't it? Because everything that's believed to be Russian state-linked is always given bear.</v>

60
00:08:31.096 --> 00:08:37.226
<v James Ball>So Fancy Bear is the GRU.</v>

61
00:08:37.226 --> 00:08:38.028
<v Graham Cluley>And we've got Crazy Bear.</v>

62
00:08:38.028 --> 00:08:41.315
<v James Ball>Military Bear will be a different military intelligence unit.</v>

63
00:08:41.315 --> 00:08:49.571
<v Graham Cluley>Yeah, I know, but Laundry Bear — you'd almost be embarrassed to be a member of Laundry Bear compared to Fancy Bear, wouldn't you, I think?</v>

64
00:08:49.571 --> 00:08:55.581
<v James Ball>It does suggest where you are in the pecking order, doesn't it?</v>

65
00:08:55.581 --> 00:09:01.592
<v James Ball>Which, given this is a pretty good hack, actually getting 64,000 officers and the contact database, I think maybe they deserve a promotion — Laundry, maybe to Scullery, Scullery Bear.</v>

66
00:09:01.592 --> 00:09:09.092
<v Graham Cluley>I think they're being trolled, basically. So anyway, Microsoft and the Dutch intelligence agency said that this attack hadn't just targeted the police, it turns out, but other sectors — defence, healthcare, government — not just the Netherlands as well, but also countries across NATO and Ukraine as well, of course. So you can all kind of guess where this attack is likely to be coming from, and the typical attack would come in the form of a personal invitation via email.</v>

67
00:09:09.092 --> 00:09:16.592
<v Graham Cluley>You might get invited to a European Defence Summit, and if you click on the link or you scan the QR code sent in the PDF which you've been sent, you get taken to a login page. Looks like Microsoft Teams you're logging into, and of course it's the usual story — they're grabbing your username and password so that they can then log into your account and steal your information. So this was fairly standard state-sponsored cyber espionage directed at Western security infrastructure.</v>

68
00:09:16.592 --> 00:09:24.092
<v Graham Cluley>And at the heart of it, according to US prosecutors, is a chap called Denis Obrezhko. He is a 36-year-old Russian IT nerd, and at the end of October 2025, he made possibly a worse mistake than you going up to the Arctic Circle — he chose to go to Phuket in Thailand. He grabbed himself a ticket there, he fancied a little break, a little holiday, and less than a week later, Thai police were knocking on his door, seizing his laptop and his mobile phone and probably a digital wallet as well, and placing him under arrest, believing him to be a hacker involved in this attack.</v>

69
00:09:24.092 --> 00:09:31.592
<v Graham Cluley>And of course, the first rule, if you are a Russian hacker, is you shouldn't leave Russia. If you're in Russia and you're only attacking organisations outside, stay in Russia.</v>

70
00:10:55.232 --> 00:11:03.340
<v James Ball>You'll get promoted, you'll get a nice home, you'll do great. I mean, I guess you could go on holiday to Belarus — that would probably be fine.</v>

71
00:11:03.340 --> 00:11:05.071
<v Graham Cluley>Yes, they'll probably be fine with you as well.</v>

72
00:11:05.071 --> 00:11:10.958
<v James Ball>It's probably quite a short travel list, thinking about it.</v>

73
00:11:10.958 --> 00:11:16.846
<v James Ball>Maybe bits of Central Africa, but I think anywhere with a US extradition treaty should probably not be on the destination list, right?</v>

74
00:11:16.846 --> 00:11:26.846
<v Graham Cluley>And Russia's foreign ministry, they instantly leapt into action. They issued a warning to their citizens saying, do not travel to Thailand — there is a threat of you being arrested at the request of the United States.</v>

75
00:11:26.846 --> 00:11:36.846
<v Graham Cluley>They said, we strongly advise Russian citizens who have even the slightest reason to suspect they might be subject to criminal prosecution by US authorities to refrain from travelling to Thailand. So this Denis chap, Denis Obrezhko, he has since been extradited to the United States.</v>

76
00:11:36.846 --> 00:11:46.846
<v Graham Cluley>This month he's appeared in a federal court in Boston, he's pled not guilty to hacking charges, and if he is found guilty, he could be facing, I don't know, 10 years in prison maybe. And now the thing is about Denis Obrezhko — I tried to find him on LinkedIn, which is my standard.</v>

77
00:12:05.043 --> 00:12:08.254
<v James Ball>Your research tool, you know, that's your spy intel, is it?</v>

78
00:12:08.254 --> 00:12:22.091
<v Graham Cluley>And to be honest, it is surprising just how many people will leave their dodgy past employments up on LinkedIn. I couldn't find him, but he is alleged to have had quite an interesting job history.</v>

79
00:12:22.091 --> 00:12:35.927
<v Graham Cluley>So according to the FBI, for 5 years between 2012 and 2017, he was working for the FSB. And for anyone who doesn't know, the FSB is like New Labour to Old Labour — it's the rebranded version of the KGB.</v>

80
00:12:35.927 --> 00:12:40.255
<v James Ball>The cuddly, kindly, non-Soviet KGB, yes. Yes.</v>

81
00:12:40.255 --> 00:12:48.793
<v Graham Cluley>And after the FSB, according to Reuters, who spoke to a former colleague and saw some documents, he spent 2 years as a senior member of staff at a well-known Russian company, which probably a lot</v>

82
00:12:48.793 --> 00:12:57.330
<v Graham Cluley>of our listeners have heard of, called, hmm, let me just— Kaspersky.</v>

83
00:12:57.330 --> 00:12:58.945
<v James Ball>Ooh.</v>

84
00:12:58.945 --> 00:13:11.679
<v Graham Cluley>Now Kaspersky, as I'm sure most of our listeners know, is of course a very well-known Russian antivirus company, cybersecurity company, who has had a rotten few years, quite frankly,</v>

85
00:13:11.679 --> 00:13:24.414
<v Graham Cluley>particularly since the war in Ukraine began. Because there've been so many stories about them being linked to the Kremlin and to the FSB, and they've had to shut down their operations.</v>

86
00:13:24.414 --> 00:13:30.347
<v James Ball>Have you ever talked to anyone there about the whole Russia connection or this kind of thing? Have you ever had that chat?</v>

87
00:13:30.347 --> 00:13:30.716
<v Graham Cluley>I have, yes.</v>

88
00:13:30.716 --> 00:13:42.124
<v James Ball>Because they get quite— I mean, there are some very, very good security researchers at Kaspersky. They've helped me out on stories before and sort of talked me through things.</v>

89
00:13:42.124 --> 00:13:53.532
<v James Ball>You know, they have some real pros. And they get incredibly awkward about it because of course most people who work there just work and have a job, don't they?</v>

90
00:13:53.532 --> 00:14:23.532
<v Graham Cluley>Yeah.</v>

91
00:13:53.532 --> 00:13:53.919
<v Joe>Yeah.</v>

92
00:13:53.919 --> 00:14:04.889
<v James Ball>Yeah. But when you start to look at Eugene Kaspersky and the realities of operating in Russia and all of that, it's hard not to wonder.</v>

93
00:14:04.889 --> 00:14:15.860
<v James Ball>Even before everyone was saying it, people either very enthusiastically deny that they've ever seen anything or done anything with it, or try and move the conversation on, in my experience. What's it been like for you?</v>

94
00:14:15.860 --> 00:14:25.120
<v Graham Cluley>So I have a close friend who has worked at Kaspersky for many— he doesn't work there any longer because effectively their UK operations are dead now. They're only selling online, their offices are shut down, they've laid off their staff.</v>

95
00:14:25.120 --> 00:14:34.381
<v Graham Cluley>I think it's actually illegal to sell it at all in America now, even to consumers, not just to government organisations.</v>

96
00:14:34.381 --> 00:14:35.230
<v James Ball>Yeah, I think you're right.</v>

97
00:14:35.230 --> 00:14:47.203
<v Graham Cluley>So I mean, it has been catastrophic for them business-wise. My friend's a very nice chap and he's not a spy, and it happened that he got a job 25 years ago or whatever it was for an antivirus company which happened to be based in Russia.</v>

98
00:14:47.203 --> 00:14:59.177
<v Graham Cluley>And I've known Eugene for many, many years. I haven't seen him for quite a few years, to be honest, but I know him — seems like a very nice guy.</v>

99
00:14:59.177 --> 00:15:01.246
<v James Ball>I think I've interviewed him. Yeah, he's very, very clever.</v>

100
00:15:01.246 --> 00:15:12.073
<v Graham Cluley>Yeah, extremely clever. Like many of these guys who've set up these antivirus companies.</v>

101
00:15:12.073 --> 00:15:22.902
<v Graham Cluley>But you do have to wonder, would it be possible to be a successful businessman — and he was an extremely successful businessman in Russia — without kowtowing to what the Russian authorities want? Because they would make your life extremely difficult, if not impossible.</v>

102
00:15:22.902 --> 00:15:30.402
<v James Ball>I mean, it isn't possible. You have to at least be friendly and cooperative, and given the importance of hacking to Russia's soft power and how it conducts diplomacy and sort of information operations, I just don't think you could be in a job as sensitive as that and not do that. I mean, let's be honest, the eight biggest cybersecurity companies that operate in the UK coordinate with NCSC and with the intelligence agencies.</v>

103
00:15:30.402 --> 00:15:37.902
<v James Ball>There are certain companies, if you're on critical national infrastructure, there's an approved list. And I'm not saying anyone does anything out of line with the law. We are a Western democracy.</v>

104
00:15:37.902 --> 00:15:45.402
<v James Ball>Everything is in the statute and above board to that level. But we cooperate with them in that way. It's not weird to say, would a company with a similar stature and a similar reach and scope that's headquartered in Russia have a relationship with the Kremlin?</v>

105
00:15:45.402 --> 00:15:52.902
<v James Ball>Of course it would. It'd be impossible for it not to.</v>

106
00:16:24.630 --> 00:16:39.630
<v Graham Cluley>Yeah. I feel like Kaspersky found itself in an impossible position, and obviously there were accusations that maybe their software could be used to sabotage companies or to steal information from companies, with a malicious update at the behest of the Kremlin.</v>

107
00:16:39.630 --> 00:16:54.630
<v Graham Cluley>I don't think I've ever seen any evidence whatsoever that that was something which was planned to do, but obviously you only need a certain amount of doubt, a small amount of doubt, and that's enough to convince people, well, maybe we shouldn't use that product, maybe we should use this other one instead. So unfortunately world events sort of overtook things, which is a shame because it was in many ways a good product. Yeah.</v>

108
00:17:02.947 --> 00:17:06.064
<v James Ball>Geopolitics has always got a win in that one though, isn't it?</v>

109
00:17:06.064 --> 00:17:16.064
<v Graham Cluley>Yeah, absolutely. Anyway, the guys at Kaspersky, they say that whatever Abrezco is accused of now, had nothing to do with his time working for them.</v>

110
00:17:16.064 --> 00:17:26.064
<v Graham Cluley>They say that the alleged hacking activity didn't happen until after he had left. But it gets more interesting than that.</v>

111
00:17:26.064 --> 00:17:36.064
<v Graham Cluley>Five years ago in 2021, Abrezko gave a guest lecture at the Moscow Technical University of Communications and Informatics, and he was introduced as the Deputy Director of the Information and Analytical Center of Russia's Ministry of Emergency Situations. Imagine working at the Ministry of Emergency Situations.</v>

112
00:17:43.700 --> 00:17:53.378
<v James Ball>It's a great job title. I hope Andy Burnham sets that one up, a Ministry of Emergency Situations. It feels like we need one, doesn't it? I'd love that.</v>

113
00:17:53.378 --> 00:18:03.378
<v Graham Cluley>Anyway, so this is a Russian government institution which he was working for. And the prosecutors then say he became a deputy director at a Russian tech firm called UTECH.NN, which is alleged to have been a cover organisation for Void Blizzard's hacking campaign.</v>

114
00:18:03.378 --> 00:18:13.378
<v Graham Cluley>So this isn't actually that unusual, in that companies will be set up appearing to do one thing — in this case, it was IT consultancy and project management, product development, all very dull. But when you look into the public records, apparently they show that that company holds an FSB-issued licence for what is described as the covert acquisition of information.</v>

115
00:18:13.378 --> 00:18:23.378
<v Graham Cluley>So you get your licence from the Russian government saying, yes, you are allowed to secretly, without other people's knowledge, acquire information. It seems a little bit unusual, but again, it makes you think, what does this company actually do?</v>

116
00:18:47.809 --> 00:18:52.971
<v James Ball>It's sort of like a digital PI's licence, isn't it? You know, I sort of feel like it's your sort of hacking fedora or something.</v>

117
00:18:52.971 --> 00:18:58.133
<v James Ball>I kind of like this.</v>

118
00:18:58.133 --> 00:19:10.324
<v Graham Cluley>Anyway, this company, UTECHNN, their founder is a guy called Mikhail Dudin, and it turned out he was listed — there's a caller ID app called GetContact where you can find out</v>

119
00:19:10.324 --> 00:19:22.515
<v Graham Cluley>what people's common nickname is, or they can set themselves a name. He'd chosen the name Ethan Hunt, which is from a movie I've seen, Mission: Impossible, the Thom Cruise character.</v>

120
00:19:22.515 --> 00:19:31.893
<v James Ball>I mean, how's that for cultural hegemony though? You know, the extent to which American culture is everywhere, that even the Russians are picking Ethan Hunt as their name.</v>

121
00:19:31.893 --> 00:19:39.393
<v Graham Cluley>Anyway, Microsoft published their report into Void Blizzard apparently on that very same day. Obrezhko allegedly emailed Ethan Hunt in quotes, suggesting that they have a meeting to discuss developments. So it's quite a tangled dark web, which the courts are obviously going to have to unknot to see if this guy is guilty or not. He obviously denies it. But I was interested in knowing how the investigators have pieced this all together. How had it come to the situation where the US had asked the Thai police to arrest this guy if he ever turned up in Phuket?</v>

122
00:19:39.393 --> 00:19:46.893
<v Graham Cluley>And it's rather interesting. So what happens, it seems, is he had reused the same username and his real Russian phone number across multiple email accounts and social media platforms and financial apps, things like that. And he'd used the same Google account for cryptocurrency transactions as he'd used to create accounts on Twitter and Instagram and PayPal. So same username, same avatar, same phone number, same date of birth over and over again. It's like, guys, if you're going to be criminals, have in your back pocket a whole list of different dates of birth, of different names, of different email addresses — don't make it easy to triangulate who you are. And the investigators say that they've traced cryptocurrency payments used to fund Void Blizzard, and they followed transactions back through an internet provider.</v>

123
00:19:46.893 --> 00:19:54.393
<v Graham Cluley>Eventually they found an email account registered in Obrezhko's own name. And this is where it becomes really interesting, because independent threat intelligence firm Control Alt Intel took the email address and phone numbers that the FBI had published in their affidavit, and they cross-referenced them with Russian leak databases. So these are databases of leaked information which have spilled out over time through criminal activity. And it's not just the criminals who use these — sometimes the threat intel people use them as well. And what they were able to find was, by going through this data, they got information from banks and social networks and courier companies, food delivery apps, anything like that, which is obviously horrendous from the point of view of if you're a Russian citizen, but great if you're a threat intel researcher. They were able to search for Denis Obrezhko's email address and phone number, and they kept on popping up in these leak databases, including that he had ordered, on the 1st of March 2021, at half past 3 in the afternoon, a Lipton iced tea, 9 Chicken McNuggets, and a McChicken burger to be delivered to him at the Russian Ministry of Emergency Situations on that particular date.</v>

124
00:19:54.393 --> 00:20:01.893
<v Graham Cluley>And they found 13 other separate orders, all delivered to that ministry address, all on weekdays, early in the afternoon. Loved his Chicken McNuggets. And it's tangled him even more into — yes, this is the ministry you were working in. You were working for the Russian government, despite any claims you may try and make later on.</v>

125
00:22:41.711 --> 00:22:50.419
<v James Ball>I do find this stuff really interesting because listeners are probably aware that I was one of the reporters who worked on the Edward Snowden story.</v>

126
00:22:50.419 --> 00:22:50.980
<v Graham Cluley>Yes.</v>

127
00:22:50.980 --> 00:22:58.480
<v James Ball>And that meant 18 months of us knowing that we were under surveillance, sort of from the US, from the UK, but possibly also sort of hostile agencies. We were flying between the US, the UK, Brazil. We were sort of trying to communicate about classified documents all of the time, and we were trying to be quite sort of cautious about that. But you also have to live.</v>

128
00:22:58.480 --> 00:23:05.980
<v James Ball>You're staying in hotels, you're trying to sort of spend on credit cards or company cards because my bank account was emptied by the first week. I was sort of having to get prepaid Visa cards, not for OPSEC, but because I had no money. But you know, you needed to get a McDonald's at 2 AM or you needed to get a taxi to get back and you were jet lagged. And so you're trying to do good security, but if you can't remember a password at 2 AM when you haven't slept for 30 hours and you don't know what time zone you're in, there's no point having the password.</v>

129
00:23:05.980 --> 00:23:13.480
<v James Ball>And so the compromise between where your kind of normal mundane accounts sort of reach and where your sort of uber ones reach are incredibly complicated to keep up. And you know, maybe for a week someone can do it, but 3 months in, 6 months in, when it's your everyday life, the things that look very silly when you see them in an indictment or when you see them in a security research, it is that thing where it's like, well, how do you live otherwise? How do you remember which date of birth you used for your Uber account versus which one you used for your other one? So all of these details are there, and if you don't use as many real ones as possible, you mess it up.</v>

130
00:23:13.480 --> 00:23:20.980
<v James Ball>You know, I remember LulzSec got caught because the leader, Sabu, turned on the other ones. He got caught because he forgot to change one thing and needed to log back in, and it was about half 3 in the morning, and he'd done everything properly, and he logged in without his VPN once.</v>

131
00:24:51.218 --> 00:24:51.522
<v Graham Cluley>Yeah.</v>

132
00:24:51.522 --> 00:25:01.522
<v James Ball>And from the fuzzed IP location, they then just basically manually surveilled that little block in New York until they worked out which flat it was and whose activity pattern it matched. And they got him that way, from one failure to use his VPN.</v>

133
00:25:01.522 --> 00:25:11.522
<v James Ball>And so, you know, this looks shoddy. I mean, this is poor.</v>

134
00:25:11.522 --> 00:25:21.522
<v James Ball>For a sort of security professional, this is dismal. But having lived like this, having tried to do it, I can say it is more difficult than you think.</v>

135
00:25:24.440 --> 00:25:31.336
<v Graham Cluley>I accept that, James, but was the canteen in the Ministry of Emergency Situations so poor that he was having to order Chicken McNuggets in instead?</v>

136
00:25:31.336 --> 00:25:38.232
<v Graham Cluley>I mean, that's an indictment in itself, isn't it?</v>

137
00:25:38.232 --> 00:25:45.717
<v James Ball>Have you eaten in post-Soviet universities or public institutions?</v>

138
00:25:45.717 --> 00:25:53.201
<v James Ball>Because if you have, I suspect you might have more sympathy for the McDonald's orders.</v>

139
00:25:53.201 --> 00:25:57.461
<v Joe>Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?</v>

140
00:25:57.461 --> 00:26:05.462
<v Graham Cluley>You are right, Joe. They've just published a new report, 2026 State of the Cybersecurity Attack Surface.</v>

141
00:26:05.462 --> 00:26:13.463
<v Graham Cluley>They analysed over 800,000 real IT assets to find out how exposed organisations actually are.</v>

142
00:26:13.463 --> 00:26:16.548
<v Joe>And I'm guessing everything is hunky-dory.</v>

143
00:26:16.548 --> 00:26:24.403
<v Graham Cluley>Not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.</v>

144
00:26:24.403 --> 00:26:26.877
<v Joe>One in three. That's terrible.</v>

145
00:26:26.877 --> 00:26:36.542
<v Graham Cluley>Isn't it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.</v>

146
00:26:36.542 --> 00:26:39.640
<v Joe>So the tools don't even know those assets exist?</v>

147
00:26:39.640 --> 00:26:45.415
<v Graham Cluley>Right. Ghost assets wandering around your network, unprotected, unmonitored.</v>

148
00:26:45.415 --> 00:26:50.549
<v Joe>Like a retired geography teacher who's somehow still on the school network.</v>

149
00:26:50.549 --> 00:26:55.684
<v Joe>Nobody added him, nobody removed him, and he's been quietly in there for 11 years downloading maps of Paraguay.</v>

150
00:26:55.684 --> 00:27:03.515
<v Graham Cluley>Yeah, yeah, yeah, I guess so, Joe. The point is, your attackers will find him before you do, because they are specifically looking for the forgotten, the unpatched, the invisible.</v>

151
00:27:03.515 --> 00:27:11.345
<v Graham Cluley>That's the path of least resistance.</v>

152
00:27:11.345 --> 00:27:14.374
<v Joe>So what does the report tell us to actually do about it?</v>

153
00:27:14.374 --> 00:27:27.298
<v Graham Cluley>Arctic Wolf's report covers how to prioritise the exposures that actually matter, cut through all that noise, and verify that when you fix something, it actually stays fixed. And the report is free to download. Free.</v>

154
00:27:27.298 --> 00:27:29.178
<v Joe>I like that. Where do I get it?</v>

155
00:27:29.178 --> 00:27:32.358
<v Graham Cluley>SmashingSecurity.com/ArcticWolf.</v>

156
00:27:32.358 --> 00:27:39.200
<v Joe>That's SmashingSecurity.com/ArcticWolf. And thanks to Arctic Wolf for supporting the show.</v>

157
00:27:39.200 --> 00:27:41.595
<v Graham Cluley>James, what have you got for us this week?</v>

158
00:27:41.595 --> 00:27:50.394
<v James Ball>So it's a real sort of who's the good guys, who's the bad guys here, but have you come across Suno, the AI music generator?</v>

159
00:27:50.394 --> 00:27:57.440
<v Graham Cluley>I have, and what's more, I'm ashamed to say I have used it to generate AI music.</v>

160
00:27:57.440 --> 00:28:00.279
<v James Ball>What AI music did you generate?</v>

161
00:28:00.279 --> 00:28:07.893
<v Graham Cluley>Well, I generated the theme tune for The AI Fix, which was a podcast. I'm no longer involved in The AI Fix, but it was a weekly podcast about AI developments, which I did for a couple of years. And it did it.</v>

162
00:28:07.893 --> 00:28:15.507
<v Graham Cluley>I mean, it was a fantastic song. The AI Fix, a digital zoo. Smart machines, bots with brains, what will they do?</v>

163
00:28:15.507 --> 00:28:23.119
<v Graham Cluley>Fly us to Mars or bake a bad cake? World domination, a silly mistake.</v>

164
00:28:23.119 --> 00:28:33.250
<v James Ball>Bots with brains.</v>

165
00:28:33.250 --> 00:28:38.630
<v Graham Cluley>It was very catchy. In fact, we had so many people who said they loved the song that we ended up putting it on Spotify.</v>

166
00:28:38.630 --> 00:28:44.009
<v Graham Cluley>And so far, I think I've made the sum total of 4 pence out of it.</v>

167
00:28:44.009 --> 00:28:49.323
<v James Ball>I saw you in the top 10% of earners then. So yes, it is quite fun to play with. You can sort of give it pretty much any lyrics or any genre and ask it to mix things up. It tends to make very middle-of-the-road, very sort of basic composition, but it's quite a fun thing to play with. But inevitably quite contentious in the same way as if you post any AI art, people say, well, you've just taken a job from an illustrator. If you use Suno music, people say, you know, you're killing music.</v>

168
00:28:49.323 --> 00:29:19.323
<v Joe>Yes.</v>

169
00:29:22.522 --> 00:29:29.510
<v James Ball>And in some cases, people absolutely are. In others, if you would never go to pay a musician anyway, you know, if that budget wasn't there, it's just creating something that wouldn't otherwise exist.</v>

170
00:29:29.510 --> 00:29:36.499
<v James Ball>There are all sorts of views on this, but—</v>

171
00:29:36.499 --> 00:29:42.228
<v Graham Cluley>I have to say, by the way, despite the fact that I have used it, I do feel completely dirty and appalled at myself for having used it.</v>

172
00:29:42.228 --> 00:29:47.957
<v Graham Cluley>And my opinion on that has strengthened only over time.</v>

173
00:29:47.957 --> 00:29:49.498
<v Joe>Yes.</v>

174
00:29:49.498 --> 00:29:58.311
<v Graham Cluley>So I do think it's completely reprehensible of me. Like I said, I'm not involved in the podcast anymore, but I have made 4 pence out of it.</v>

175
00:29:58.311 --> 00:30:08.311
<v James Ball>So, well, I hope that you donate that to an artist support charity or to someone campaigning for reforms to the copyright law for the AI era. But it means essentially Suno is in the middle of very similar lawsuits to a lot of the other AI companies.</v>

176
00:30:08.311 --> 00:30:18.311
<v James Ball>What it generates, there's always a bit of contention — is that original, et cetera? But the real row is over how they were trained and have they improperly accessed the training material, have they sort of violated that?</v>

177
00:30:18.311 --> 00:30:28.311
<v James Ball>I think the best known lawsuit over all of this at the moment is the Anthropic one.</v>

178
00:30:34.174 --> 00:30:34.511
<v Graham Cluley>Yeah.</v>

179
00:30:34.511 --> 00:30:42.011
<v James Ball>Which essentially found that if they bought books secondhand, very cheaply ingested them and churned them through, that's fine. They could do it a dollar a pop, cheaper. That's okay.</v>

180
00:30:42.011 --> 00:30:49.511
<v James Ball>But they didn't bother doing that. They just downloaded a load of pirated books. And so they've had to do an out-of-court settlement.</v>

181
00:30:49.511 --> 00:30:57.011
<v James Ball>I have to do a disclosure here. Two of my books are in that settlement. If that goes through, Anthropic owe me, I think, about $5,000.</v>

182
00:30:57.011 --> 00:31:04.511
<v James Ball>I'm not a party to the case otherwise.</v>

183
00:31:04.931 --> 00:31:12.363
<v Graham Cluley>The irony is though that Anthropic themselves don't like the idea of, for instance, Chinese AI companies stealing their resources and their knowledge to better their own.</v>

184
00:31:12.363 --> 00:31:19.795
<v Graham Cluley>You know, they seem to have thought it was all right for them to take stuff without asking.</v>

185
00:31:19.795 --> 00:31:27.227
<v Graham Cluley>But if anyone takes anything from Anthropic without asking, they're not quite so pleased about that.</v>

186
00:31:27.227 --> 00:31:34.727
<v James Ball>Yes, but you see, it's very different because when you take from one model to train your model, they call it distillation. And because they give it a different name, it's obviously entirely different morally and legally. It is not. They are really genuinely kicking off at the Chinese companies for exactly the conduct they did. I mean, exactly right down to a lot of it ends up centring on whether it comes to terms of service violations mean that you accessed unlawfully, etc.</v>

187
00:31:34.727 --> 00:31:42.227
<v James Ball>There's lots of very fine points of IP law in this. Now, Suno are right in the middle of all of this. And to be honest, I think they're in a trickier position than Anthropic and OpenAI, not necessarily because their conduct's any different. If you want to produce a lot of music, you need to ingest a lot of music. And they have more or less now admitted that they scraped off YouTube, Genius, Deezer, all of these things.</v>

188
00:31:42.227 --> 00:31:49.727
<v James Ball>They took a lot of music. Their difficulty is that they're not really up against a bunch of authors who are, you know, generally pretty poor and not that well-resourced. They're up against big music and big music basically fought this and won this once before. You know, they beat Napster, they beat LimeWire, they beat all of those, they have a much smaller group who are much more aggressive pursuing them a lot more. And so Anthropic has got off fairly cheaply for using pirated material.</v>

189
00:31:49.727 --> 00:31:57.227
<v James Ball>The question is going to be, if you grab stuff off YouTube and use it to train an AI, that is not in line with how you're supposed to use YouTube. It is very, very dubious. And they had been dancing around in discovery about whether they'd done this, and now Suno has been hacked and it's been hacked by someone who's put an awful lot of the material online. And it pretty much categorically seems to show not just that they did train off YouTube, etc., which we kind of knew, but things like exactly how much they've ingested into different parts because it's annotated code.</v>

190
00:33:37.009 --> 00:33:37.430
<v Graham Cluley>Yeah.</v>

191
00:33:37.430 --> 00:33:44.930
<v James Ball>So people can check the code and they can check the annotations, but there's things like 113,879 hours of YouTube Music, 12,287 hours of Deezer, 3,722 of Jamendo. What I like is that there was one site that had some copyright-free sound and there's only 410 hours from that one. So it sort of tells you some issues.</v>

192
00:33:44.930 --> 00:33:52.430
<v James Ball>You know, there is decades and decades and decades worth of original music. And so if they were ever trying to go, well, prove it, or, you know, you have no evidence of that, this looks dubious. They'd largely helped themselves to the back catalogue of every musician in the world, and now a hacker has helped themselves to their code.</v>

193
00:33:52.430 --> 00:33:59.930
<v James Ball>Now, legally, they're not quite the same status, but morally, that's got to look very similar to a lot of people, isn't it? It's, on one level, a fairly basic hack. They got in through one programmer using a 2025 worm, Shaihulud.</v>

194
00:33:59.930 --> 00:34:07.430
<v James Ball>I don't know much about Shai Hulud. Do you?</v>

195
00:35:56.655 --> 00:36:03.650
<v Graham Cluley>Yes, Shai Hulud was a worm that hit the npm JavaScript package registry. I think it was in late 2025. We spoke about it in an earlier episode of Smashing Security.</v>

196
00:36:03.650 --> 00:36:10.646
<v Graham Cluley>Basically, a developer inside your company would install a booby-trap package and the malware would quietly steal their credentials and then use them to infect other packages that they maintained. So it would spread itself automatically across your ecosystem. And to make matters worse, it also dumped all the things it had stolen into a public GitHub repository under the victim's own account, so sort of broadcasting credentials to the world.</v>

197
00:36:10.646 --> 00:36:17.641
<v Graham Cluley>So yeah, a real supply chain menace, that one. An unusual worm, but was affecting a large number of organisations potentially and causing quite a big problem. But once they're in, of course, yeah, the data which can be extracted.</v>

198
00:36:17.641 --> 00:36:25.141
<v James Ball>The hacker says they've got the customer list, the customer emails, phone numbers, Stripe payment details. They provided 404 a sample of those, which looked legitimate. But what seems to have been used for the interesting stuff is this is all the GitHub submits and back and forth.</v>

199
00:36:25.141 --> 00:36:32.641
<v James Ball>What I found particularly interesting here was I started all sorts of musing about whether this was a sort of Hacker Wars 2.0 and whether this was a sort of revenge for the creative industries type thing. I also wondered if there was a bit of — it is known that corporates hack each other sometimes for various reasons, because it's useful if material can hit the public domain, and you can kind of launder it if you get a third-party hacker. It's not legal, but a company could, in theory, get a third-party hacker to get some sensitive information, get that third party to disclose it to a journalist, and that journalist, if they run it in a major outlet, they can then use that journalist's reporting to subpoena the information that was hacked and use it in a court case or similar.</v>

200
00:36:32.641 --> 00:36:40.141
<v James Ball>Now, I should stress this is illegal. I'm using this as a general example of something that lawyers and others have talked me through and said, this is something that everyone thinks other people are doing, and everyone says they, of course, would never touch and never do. Which is what phone hacking was like in journalism back in the day.</v>

201
00:36:40.141 --> 00:36:47.641
<v James Ball>Everyone said they didn't do it, but they knew people who did.</v>

202
00:37:15.750 --> 00:37:23.250
<v Graham Cluley>But even if it wasn't us, even if it wasn't a Suno rival who was behind this, it could be simply someone who doesn't like the slop which Suno is producing, is against the taking away of work from legitimate musicians and creative types, and wants to have an impact.</v>

203
00:37:23.250 --> 00:37:30.750
<v Graham Cluley>And I'm sure you, like myself, have been approached by hacking gangs in the past who've said, we've got this data, we've stolen this information, can you publicise this?</v>

204
00:37:30.750 --> 00:37:38.250
<v Graham Cluley>We think this is a good story.</v>

205
00:37:38.250 --> 00:37:45.750
<v Graham Cluley>And there are many —</v>

206
00:37:48.581 --> 00:37:56.081
<v James Ball>I've used it sometimes. I mean, essentially you test the public interest of the disclosure versus the fact you don't know the source and the source's motivations. This was the thing I kind of thought, well, is this some corporate espionage?</v>

207
00:37:56.081 --> 00:38:03.581
<v James Ball>It doesn't look state to me. Is this exactly that kind of ideological hack? Supposedly not, though.</v>

208
00:38:03.581 --> 00:38:11.081
<v James Ball>In a sort of fairly underwhelming line, buried quite deep in the story, the hacker told 404 Media they had no specific motivation for hacking Suno, and said, "I like to hack anything and everything." Now maybe that's true, or maybe that's cover, you know. It is a clever hack, they've used their access, etc., but they've largely used something off the shelf that someone could grab and play with, you know. There's not a reason that this has to be super sophisticated or a large number of people, but they're not claiming any ideological motivation here.</v>

209
00:38:11.081 --> 00:38:18.581
<v James Ball>But I thought it was a particularly interesting one because it trod on several red buttons all at once. So I think as well, whatever their motivation, it will end up pulled into the ongoing lawsuits because how could it not?</v>

210
00:39:05.384 --> 00:39:11.219
<v Graham Cluley>Well, that's the thing, isn't it? Is this going to be further bad news for Suno, this been released, do you think?</v>

211
00:39:11.219 --> 00:39:20.623
<v James Ball>Yes, I mean, I assume that they have known that this kind of lawsuit will come from the get-go. And it's all about fight the case to try and get the best terms you can and then use it to cut a deal for your future relationship.</v>

212
00:39:20.623 --> 00:39:30.027
<v James Ball>You know, do they take an ownership stake? Do you come up with licensing terms?</v>

213
00:39:30.027 --> 00:39:39.431
<v James Ball>Because presumably your eventual model will be Suno Music getting distributed alongside traditional artists.</v>

214
00:39:39.431 --> 00:39:52.152
<v Graham Cluley>But this is a rubbish way to do business, isn't it? Is to commit what some of us would consider to be a crime or to commit something which appears unethical, you know, which is grabbing someone else's music and using it to feed and create your own music.</v>

215
00:39:52.152 --> 00:40:04.871
<v Graham Cluley>And then, well, we'll do that now because in the future sometime we'll come to some business relationship or we'll come to some understanding which will make it acceptable. But by that time we'll have built our business up enough.</v>

216
00:40:04.871 --> 00:40:10.978
<v James Ball>Yeah, but it is how the entire AI industry has built itself. So, you know, we can say it's skeezy and it's unethical, but yeah, it's morally dubious.</v>

217
00:40:10.978 --> 00:40:17.085
<v James Ball>There's maybe no good guys in this story.</v>

218
00:40:17.085 --> 00:40:18.097
<v Joe>Sorry.</v>

219
00:40:18.097 --> 00:40:23.585
<v James Ball>Maybe the good guys are the big record companies. Everyone loves them. They've never done anything dodgy.</v>

220
00:40:23.585 --> 00:40:28.539
<v Graham Cluley>Oh yeah, they're great.</v>

221
00:40:28.539 --> 00:40:31.173
<v Joe>This week's episode is supported by NordLayer.</v>

222
00:40:31.173 --> 00:40:36.112
<v Graham Cluley>NordLayer. And before anyone says anything, no, it's not NordVPN.</v>

223
00:40:36.112 --> 00:40:37.322
<v Joe>I wasn't going to say that.</v>

224
00:40:37.322 --> 00:40:38.905
<v Graham Cluley>You were absolutely going to say that.</v>

225
00:40:38.905 --> 00:40:39.483
<v James Ball>Joe.</v>

226
00:40:39.483 --> 00:40:45.512
<v Graham Cluley>They are both from Nord Security, but NordLayer is a completely different product. NordVPN is for individuals.</v>

227
00:40:45.512 --> 00:40:51.539
<v Graham Cluley>NordLayer is a network security platform built for businesses. Right.</v>

228
00:40:51.539 --> 00:40:53.931
<v Joe>So what does NordLayer actually do?</v>

229
00:40:53.931 --> 00:41:02.005
<v Graham Cluley>Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.</v>

230
00:41:02.005 --> 00:41:03.869
<v Joe>From a sun lounger, hopefully.</v>

231
00:41:03.869 --> 00:41:10.572
<v Graham Cluley>You'd be lucky. And the moment someone logs into a company network over an unsecured connection, you've got a problem.</v>

232
00:41:10.572 --> 00:41:17.273
<v Graham Cluley>Credentials intercepted, phishing attacks, unauthorised access. It's a scary world out there for travelling workers.</v>

233
00:41:17.273 --> 00:41:18.798
<v Joe>So NordLayer fixes that.</v>

234
00:41:18.798 --> 00:41:30.157
<v Graham Cluley>It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second, with zero additional hardware required. But it goes well beyond just encrypting the connection.</v>

235
00:41:30.157 --> 00:41:41.516
<v Graham Cluley>You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant. And if someone leaves the company, you revoke their access immediately.</v>

236
00:41:41.516 --> 00:41:51.516
<v Joe>No more ex-employees</v>

237
00:41:41.516 --> 00:41:50.552
<v Graham Cluley>No more of that. And it will block malicious sites, risky downloads, dangerous domains, and it can even detect shadow apps.</v>

238
00:41:50.552 --> 00:41:59.588
<v Graham Cluley>So if someone on your team has started using some AI tool that your security team hasn't approved—</v>

239
00:41:51.516 --> 00:42:01.516
<v Joe>still wandering around</v>

240
00:41:59.588 --> 00:42:00.552
<v Joe>I'd never do that.</v>

241
00:42:00.552 --> 00:42:09.460
<v Graham Cluley>Yeah, well, whatever. NordLayer can spot that too. And there's no complex infrastructure to set up. Apparently you can be up and running in just about 10 minutes.</v>

242
00:42:01.516 --> 00:42:11.516
<v Joe>your systems 6 months later.</v>

243
00:42:09.460 --> 00:42:39.460
<v Joe>10 minutes?</v>

244
00:42:09.460 --> 00:42:19.014
<v Graham Cluley>10 minutes. Plans start from just $8 per user per month. And right now there is a summer sale.</v>

245
00:42:19.014 --> 00:42:28.570
<v Graham Cluley>New customers get up to 20% off annual plans until the end of August 2026. Use the code NLSUMMER26 at checkout.</v>

246
00:42:28.570 --> 00:42:35.188
<v Joe>Whoa, all I have to do is type in that code at nordlayer.com/smashing and I can get a great deal? Let me write that down.</v>

247
00:42:35.188 --> 00:42:36.494
<v Graham Cluley>Yep, go ahead, write it down.</v>

248
00:42:36.494 --> 00:42:37.849
<v Joe>What's the code again? I forgot.</v>

249
00:42:37.849 --> 00:42:40.992
<v Graham Cluley>Oh, Joe. NLSUMMER26.</v>

250
00:42:40.992 --> 00:42:45.440
<v Joe>Got it. Off to nordlayer.com/smashing I go.</v>

251
00:42:45.440 --> 00:42:54.646
<v Graham Cluley>And thanks to NordLayer for supporting the show. And welcome back, and you join us for our favourite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.</v>

252
00:42:54.646 --> 00:43:24.646
<v James Ball>Pick of the Week.</v>

253
00:42:54.646 --> 00:43:02.146
<v Graham Cluley>Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish. It doesn't have to be security related necessarily.</v>

254
00:43:02.146 --> 00:43:09.646
<v Graham Cluley>Well, my Pick of the Week this week is not security related. This last weekend I had the chance to see a one-woman play at the Bristol Old Vic, and it so happens I am a big fan of Nina Simone, the music of Nina Simone. I think she was incredible.</v>

255
00:43:09.646 --> 00:43:17.146
<v Graham Cluley>Incredible, and her music continues to be. And the play I saw was a one-woman play called Black Is the Colour of My Voice. And an American actor called Afia Campbell is the writer and performer of the show, which sees her as Nina Bordeaux.</v>

256
00:43:17.146 --> 00:43:24.646
<v Graham Cluley>She's not Nina Simone. She's Nina Bordeaux, possibly for legal reasons.</v>

257
00:43:47.356 --> 00:43:49.538
<v James Ball>A legally distinct person, yes.</v>

258
00:43:49.538 --> 00:43:57.038
<v Graham Cluley>Yes, so it appears the performance was inspired by Nina Simone. It's about this woman who is very skilled at playing the piano from a young age. It's a life shaped by racism and civil rights and Martin Luther King and all these things are crossing over into her life. Anyway, Afia Campbell, she doesn't play the piano, but she sings, and there is a musical accompaniment as well during the performance.</v>

259
00:43:57.038 --> 00:44:04.538
<v Graham Cluley>She weaves in some of Nina Simone's really beautiful, haunting songs. I Loves You Porgy, Wild Is the Wind. They're all in the narrative as well. It's about an hour and a quarter long.</v>

260
00:44:04.538 --> 00:44:12.038
<v Graham Cluley>I really, really liked it. It was spellbinding. It got your attention. The music obviously was band-bloody-tastic.</v>

261
00:44:12.038 --> 00:44:19.538
<v Graham Cluley>It's on tour. And if that sounds like your kind of thing, go and check it out. Link in the show notes. So, Black Is the Colour of My Voice is my pick of the week.</v>

262
00:44:40.070 --> 00:44:47.570
<v James Ball>That sounds rather wonderful. Mine's possibly a little more lowbrow.</v>

263
00:44:47.570 --> 00:44:55.070
<v James Ball>But I'm not ashamed of that. Netflix have launched the second season of their live-action Avatar: The Last Airbender.</v>

264
00:44:55.070 --> 00:45:02.570
<v James Ball>Oh yes. Which has had very mixed reviews from fans.</v>

265
00:45:02.570 --> 00:45:10.070
<v James Ball>There was famously a terrible Avatar movie about 10, 15 years ago that I think is one of the most panned movies of all time. The fandom hated it, the casuals hated it too.</v>

266
00:45:21.606 --> 00:45:26.273
<v Graham Cluley>This isn't the James Cameron Avatar movie. This is The Last Airbender. The Last Airbender.</v>

267
00:45:26.273 --> 00:45:33.773
<v James Ball>Yes. Right. So it's based on this 3 seasons animated. It was kind of in the Pokémon era where everyone was very into anime. And it was sort of widely regarded as one of the best sort of kids anime series of all time. So this live action season, everyone praises the actors. You know, these are real children acting. And apparently the SFX are good, but, you know, it's different.</v>

268
00:45:33.773 --> 00:45:41.273
<v James Ball>It's live action. It's trying to be a bit more adult. I think it's trying to get people who watched the cartoon as a kid. And so they've been fairly mixed. Anyway, all of this made me realise I'd never watched the actual original series. Oh, okay. You know, I was a little bit old for it when it was out. But I love that kind of thing.</v>

269
00:45:41.273 --> 00:45:48.773
<v James Ball>I was too old for the Pokémon cartoon. They were sort of fun background if you're working or whatever. And so I've been working my way through these, the original animated Avatar: The Last Airbender. And honestly, if you've got a sort of 8, 9, 10-year-old, sit down and watch it with them. Or if you've just got the brain of a child like I do, have it on while you do something else. It is not emotionally taxing, but they are well plotted. They are well structured. They are 20 minutes long an episode.</v>

270
00:45:48.773 --> 00:45:56.273
<v James Ball>You know that the story completes, it's 3 seasons and done. It's lovely. And I can see why people loved it. It's a really good show. So Avatar: The Last Airbender, the latest recommendation anyone will give you for that, I'm sure.</v>

271
00:46:59.199 --> 00:47:05.054
<v Graham Cluley>Okay, but you are recommending the animated series, not the live action. Not the live action.</v>

272
00:47:05.054 --> 00:47:11.987
<v James Ball>I will probably try the live action, but I thought, you know what, why don't I go to the one everyone agrees is good? And I'll make my own judgment about the live action later.</v>

273
00:47:11.987 --> 00:47:18.920
<v James Ball>But yeah, I can see why people fell in love with the animated one.</v>

274
00:47:18.920 --> 00:47:28.791
<v Graham Cluley>Fantastic. Well, that just about wraps up the show for this week. Thank you so much, James, for coming along. I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way to do that?</v>

275
00:47:28.791 --> 00:47:34.516
<v James Ball>I am @jamesrball.com on Bluesky. I'm at the same web address.</v>

276
00:47:34.516 --> 00:47:40.242
<v James Ball>You can find me in the New World Magazine or the i Newspaper or about 6 other places.</v>

277
00:47:40.242 --> 00:47:53.735
<v Graham Cluley>And Smashing Security is on social media as well. You can follow it on Blue Sky, on Reddit, on Mastodon. You can also find me, Graham Cluley, on those places or on LinkedIn.</v>

278
00:47:53.735 --> 00:48:07.228
<v Graham Cluley>And don't forget to ensure you never miss another episode of Smashing Security. Find it in your favourite podcast apps such as Spotify, Pocket Casts, and Apple Podcasts. For episode show notes, sponsorship info, guest list, and the entire back catalogue of 477 episodes, check out smashingsecurity.com.</v>

279
00:48:07.228 --> 00:48:20.722
<v Graham Cluley>Until next time, cheerio, bye-bye, farewell. You've been listening to Smashing Security with me, Graham Cluley. A big, big thanks to James Ball for joining us this week and to this episode's sponsors, NordLayer, Vanta, and Arctic Wolf.</v>

280
00:48:20.722 --> 00:48:34.215
<v Graham Cluley>Go and check out their services and products, why don't you? And also to the following fine folks who are amongst our fantastic Smashing Security patrons. So picking some out of the hat at random, we start with Matt H and Alvin.</v>

281
00:48:34.215 --> 00:48:47.710
<v Graham Cluley>Also big thanks to Yuri Taraday and to the letter J, just the letter J, single letter. Most efficient patron we have ever encountered. Extraordinary commitment to brevity there.</v>

282
00:48:47.710 --> 00:49:01.204
<v Graham Cluley>Thank you, Jay. Thank you also to Jessica Orth and Alboros, who remains as delightfully mysterious as ever. And to Lisa, who continues to prove that one name is more than sufficient.</v>

283
00:49:01.204 --> 00:49:14.697
<v Graham Cluley>Cheers also to Dan H, who got slightly further than a single letter like Jay, but also kept things admirably concise. And to David Smythe, or is it Smith? I don't know.</v>

284
00:49:14.697 --> 00:49:28.190
<v Graham Cluley>Either way, it's a solid sounding name if I ever heard one. And finally for this week, Marvin 71. Marvin, we are still wondering about the other 70 Marvins.</v>

285
00:49:28.190 --> 00:49:41.684
<v Graham Cluley>Maybe you can get them to sign up as well. Those are just a few members of Smashing Security Plus, which means that they get their episodes ad-free and earlier than the general public. And of course, they can have names pulled out at random to be mercilessly mocked at the end of the show.</v>

286
00:49:41.684 --> 00:49:55.177
<v Graham Cluley>If you would like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details. Now, you can also support the show in other ways. You can like, you can subscribe, you can leave a 5-star review.</v>

287
00:49:55.177 --> 00:50:08.670
<v Graham Cluley>All that is really appreciated. And do tell your friends about the podcast too. Go on, go and bash them on the head with a balloon.</v>

288
00:50:08.670 --> 00:50:22.164
<v Graham Cluley>That's pretty painless because every little bit helps, and you spreading the word really does help me. Until next time, cheerio, bye-bye.</v>
