DiscoverThe Awareness Angle: Cyber News Weekly
The Awareness Angle: Cyber News Weekly

The Awareness Angle: Cyber News Weekly

Author: Risky Creative

Subscribed: 8Played: 79
Share

Description

The Awareness Angle makes cybersecurity make sense. Hosted by Anthony and Luke, we break down the biggest cyber stories of the week. From phishing scams and AI fraud to major data breaches and the sneaky ways people get hacked, we explain what’s going on and why it matters.

But this isn’t just another tech podcast. We focus on the human side of cybersecurity. How scams actually work, why people fall for them, and what we can all do to stay safer online.

You’ll get practical tips, real-world examples, and relatable stories that show how cyber threats affect everyday people, not just big busin
72 Episodes
Reverse
This week on The Awareness Angle, security failures show how quickly everyday systems can tip from background noise into real world disruption. From ransomware knocking a major IT distributor offline, to schools closing after cyber attacks, and criminals selling voice phishing kits like a product, the theme this week is scale. Small failures, trusted platforms, and familiar channels being used to create outsized impact.We start with Breach Watch, looking at the Ingram Micro ransomware attack and what it reveals about supply chain fragility when a single distributor goes dark. We then cover a breach at Grubhub caused by access to a third party support system, exposing customer, driver, and merchant data. We also look at the Minnesota Department of Human Services breach affecting nearly 304,000 people, and a UK secondary school forced to close after cyber disruption took critical systems offline.In the news, Microsoft releases emergency out of band Windows updates after patching issues prevent systems from shutting down properly. We look at criminals openly selling ready made voice phishing kits, making vishing easier to run at scale, and a malicious Chrome extension that deliberately crashes browsers to push fake fixes in a new ClickFix variant. We also discuss the EU launching a new vulnerability database as an alternative to CVE, a phishing campaign targeting LastPass users with fake security alerts, the UK government consulting on banning social media for under 16s, and TikTok finalising a deal to split its US operations into a new joint venture.In Topics, we talk about password hints that are completely useless, the ongoing debate around the phrase human risk, and the Action Fraud rebrand to Report Fraud, including why its sign in experience raises some uncomfortable trust questions. We also look at how AI generated content is flooding social platforms, and share practical ways to spot fake accounts and videos before they fool you.If you want cyber news explained with clarity, context, and zero jargon, you are in the right place.0:00 Introduction and Overview1:25 Ingram Micro Ransomware Attack5:38 Grubhub Third Party Breach9:41 Minnesota Department of Human Services Data Breach12:39 UK School Forced to Close After Cyber Attack18:52 Microsoft Emergency Windows Updates20:45 Voice Phishing Kits for Sale25:25 Malicious Chrome Extension and ClickFix Variant30:34 EU Vulnerability Database Alternative to CVE34:19 LastPass Phishing Campaign39:29 UK Consultation on Social Media Ban for Under 16s45:10 TikTok Splits US Operations48:30 Password Hints and Human Risk Discussion53:19 Action Fraud Rebrand and Trust Issues1:01:26 AI Generated Content and Spotting FakesMore Informationhttps://riskycreative.comListen on the goSpotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196Follow usLinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreativeYouTube: https://www.youtube.com/@riskycreativeIf you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.🎵 Our Intro and Outro Song (© 16 by falling forever)https://fallingforever.bandcamp.com/track/16License: https://creativecommons.org/licenses/by/4.0
This week on The Awareness Angle, confusion, control, and credibility sit at the centre of the cyber news. From password reset emails triggering panic at global scale, to ransomware groups shaping the narrative without releasing data, the theme this week is trust, who controls it, and how quickly it can unravel.We start with Breach Watch, looking at ransomware claims against Nissan and how screenshots and file listings are increasingly used to apply pressure without publishing stolen data. We then move to a confirmed breach at Spanish energy giant Endesa, where customer data linked to energy contracts and payment details was exposed, and compare two very different approaches to communication and incident handling. We also cover BreachForums leaking its own user database, a reminder that even criminal platforms are not immune to basic security failures.In What the Hack, we break down the Instagram password reset email saga that left millions of users unsure whether they were under attack. We look at Meta’s explanation, Malwarebytes’ claims of leaked data, and why old scraped information keeps coming back to cause fresh concern. We also cover Microsoft’s Patch Tuesday, including an actively exploited zero day, and why severity scores often miss the real risk story.The wider topics include Microsoft potentially allowing Copilot to be fully removed from managed devices, growing pushback against forced AI adoption at work, and why major PC manufacturers are now saying AI is confusing customers rather than selling devices. We also look at a hacker jailed for attacks on the ports of Rotterdam and Antwerp, showing how cyber access directly enables real world organised crime, and a foiled cyber attack targeting Poland’s energy infrastructure.We wrap up with two very human stories, a classic scam email that knows your password and why it still works, and a look at eye scanning being pitched as proof that you are human, complete with crypto incentives, biometric risk, and some uncomfortable questions about where identity is heading.If you want cyber news explained with clarity, context, and zero jargon, you are in the right place.More informationhttps://riskycreative.comListen on the goSpotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196Follow usLinkedIn: The Awareness Angle NewsletterTikTok: @infosecantInstagram: @riskycreativeYouTube: @riskycreativeIf you found this useful, follow the show and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.🎵 Our Intro and Outro Song (© 16 by falling forever)https://fallingforever.bandcamp.com/track/16License: CC BY 4.0
This week on The Awareness Angle, everyday systems, subscriptions, and trusted tools keep showing how easily they can be turned against us. From major data breaches affecting millions to phishing tactics designed to look like system failures, the theme this week is familiarity, and how attackers exploit what people already trust.We kick off with Breach Watch, starting with Condé Nast, where a breach claim could affect millions of subscribers across brands like Wired, Vogue, and GQ. We then look at Covenant Health in the US, where a breach initially disclosed as small has grown to nearly half a million people, exposing highly sensitive medical data. We also cover a US gas station operator running more than 150 locations, where attackers accessed payment card data, bank details, and government issued IDs, with customers only notified months later. We round out Breach Watch with Tokyo FM in Japan and the European Space Agency, now under criminal investigation after sensitive systems were compromised.In What the Hack, we break down one of the most worrying phishing techniques we have seen recently. Fake Blue Screen of Death pop ups are being used to panic hotel staff into installing malware, using Booking.com themed emails and ClickFix style attacks. We also dig into how password managers were unexpectedly pulled into a mobile banking security decision, and why sideloaded apps are becoming a growing point of confusion for users.The wider topics include a deep dive into Equifax’s security culture years after its breach, OpenAI’s move to connect health data to ChatGPT and why that changes the value of accounts, the UK government’s new cyber action plan, and why outdated, box ticking cyber training continues to miss the mark. We also look at scam texts, SMS trust problems, and even cyber exclusions quietly appearing in home insurance policies.If you want cyber news explained with clarity, context, and zero jargon, you are in the right place.Chapters00:00:00 Welcome, and this week’s storiesBreach Watch00:01:01 Breach Watch begins00:01:22 Condé Nast breach claims and subscriber data risk00:04:41 Covenant Health breach grows to nearly half a million people00:07:18 Tokyo FM breach and why radio stations hold so much data00:10:13 US gas station operator breach, payment cards and delayed notification00:12:31 European Space Agency breach under criminal investigationWhat the Hack00:22:52 Fake Blue Screen of Death attacks targeting hotel staff00:26:37 ClickFix techniques and why panic keeps working00:34:49 HSBC, Bitwarden, sideloaded apps, and mobile trust decisionsTopics00:37:52 OpenAI, ChatGPT health data, and account value00:42:03 UK government cyber action plan00:44:48 NCSC cyber training for school staff and why delivery matters00:49:00 Parking fine scams, bank texts, and SMS trust issues00:57:07 Cyber events appearing in home insurance policies01:02:54 Closing thoughts and wrap upMore Informationhttps://riskycreative.comListen on the goSpotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196Follow usLinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreativeYouTube: https://www.youtube.com/@riskycreativeIf you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.🎵 Our Intro and Outro Song (© 16 by falling forever)https://fallingforever.bandcamp.com/track/16License: CC BY 4.0https://creativecommons.org/licenses/by/4.0
In this episode of The Awareness Angle, I’m joined by two people who genuinely live and breathe community-led security awareness, Roberto Ishmael Pennino and Liam Stock Rabbat.This conversation goes well beyond phishing simulations and training slides. We talk openly about why community matters so much in security awareness, how loneliness and isolation are fuelling modern scams, and why human connection might be one of the most important defences we have right now.We dig into Ishmael and Liam’s joint initiative focused on cybersecurity awareness for everyone, not just people working in corporate roles, and why giving back to the wider community should matter to all of us in this space. We also explore the real-world impact of scams, shame, and silence, including why normalising these conversations can genuinely help people feel safer online.There’s plenty in here for awareness professionals, as well as for anyone interested in human risk, behaviour change, and making security feel more human.🎙️ In this episode, we cover• Why community work matters in security awareness• The human cost of scams, beyond just financial loss• How awareness can genuinely help people feel safer• AI as both a challenge and an enabler for awareness teams• What needs to change to improve online safety for everyoneIf you care about people, culture, and doing security differently, this one’s for you.👍 Like, subscribe, and share if this episode resonates💬 Let us know your thoughts in the commentsIn this episode, we discuss the "Shamrock Project", but we had that wrong. It's Operation Shamrock and more details on them and the great work that they do can be found at www.operationshamrock.orgWe also discussed my interview with Daisy Wong and her own personal experience witha romance scam. You can watch that video at https://youtu.be/T7rrOmGRAoUStay aware, stay secure.The Awareness Angle: Interviews is our ongoing series of real, no-fluff conversations with the people rethinking how we approach security, risk, and human behaviour.Read The Episode Discussion Pointshttps://www.riskycreative.comYouTubehttps://www.youtube.com/@riskycreativeLinkedInhttps://www.linkedin.com/company/riskycreativeContacthello@riskycreative.comWebsitehttps://www.riskycreative.comAbout The Awareness AngleA CYBERSECURITY PODCAST where we talk about SECURITY AWARENESS and security education. We are professionals in HUMAN RISK and Information Security Awareness. We know PHISHING CAMPAIGNS. We know PHISH. We have done annual SECURITY TRAINING. We have sent NEWSLETTERS and made videos. We have created security awareness CULTURE STUDIES and are passionate about HUMAN BEHAVIOURS. Whether you're a Cyber Security Awareness professional or simply curious about human risk, this podcast is your go-to resource for fresh perspectives and creative solutions.Intro and outro music16! by falling foreverhttps://fallingforever.bandcamp.com/track/16LicenseCreative Commons Attribution 4.0https://creativecommons.org/licenses/by/4.0
This week on The Awareness Angle, trusted platforms are being abused at scale, and the damage often starts with things that look completely legitimate. From Spotify facing claims of a massive torrent based scrape to phishing emails abusing real Google services, the theme this week is misplaced trust, and how attackers keep exploiting it.We kick off with Breach Watch, starting with claims that Anna’s Archive scraped huge volumes of Spotify audio and metadata and redistributed it via torrents. We then move to Ubisoft taking Rainbow Six Siege offline after attackers appear to gain deep backend control, triggering mass bans and in game chaos. We also cover Korean Air disclosing a passenger data exposure linked to a supplier breach, and an update on the Coupang incident where investigators recovered customer data from a laptop that had been smashed and dumped in an attempt to destroy evidence.In What the Hack, we break down a phishing campaign abusing real Google services to send convincing emails before stealing Microsoft logins, a British security researcher who secured an Australian visa after responsibly hacking a government website, and a new ClickFix service selling fake browser glitch pages at scale. We also dig into a long running browser extension malware campaign that has quietly infected millions of users across Chrome, Edge, and Firefox, Meta’s reported internal playbook for managing scam ad scrutiny, and why Flipper Zero and Raspberry Pi devices were banned from a major public event in New York.The wider topics look at loan scams thriving on social platforms, why scam ads keep slipping through despite reporting, and the quiet loss of one of the most important public resources for tracking AI jailbreaks in the wild.If you want cyber news explained with clarity and zero jargon, you are in the right place.Chapters00:00:00 Welcome, and this week’s storiesBreach Watch00:01:16 Spotify scrape claims and torrent distribution00:05:25 Rainbow Six Siege hack forces Ubisoft shutdown00:10:57 Korean Air passenger data exposed via supplier breach00:12:59 Coupang update, smashed laptop data recoveredWhat the Hack00:15:53 Google services abused for phishing Microsoft logins00:20:47 British hacker wins Australian visa after responsible disclosure00:23:34 ClickFix attacks sold via fake browser glitch pages00:28:46 Browser extensions infect millions over seven years00:34:28 NYC bans Flipper Zero and Raspberry Pi devicesTopics00:39:02 Loan scams spreading through social platforms00:42:10 Meta and the management of scam ad scrutiny00:44:59 Reddit bans r slash ChatGPTJailbreak and why it matters00:48:06 Closing thoughtsMore Informationhttps://riskycreative.comListen on the goSpotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=1bbe58c9be6c462bApple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196Follow usLinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreativeYouTube: https://www.youtube.com/@riskycreativeIf you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.
This week on The Awareness Angle, breaches, extortion, and quietly invasive tech all collide. From real estate firms leaking highly sensitive data to browser extensions secretly harvesting AI conversations, the theme this week is trust, and how easily it gets abused.Luke is back from holiday, and we kick off with Breach Watch, starting with a New York and DC real estate developer exposing nearly 47,000 people after a ransomware attack. We then look at SoundCloud losing control of user data, followed by one of the most personal extortion cases we have seen, PornHub Premium viewing history stolen via a third party analytics provider. We also cover the ongoing UK government hack that ministers are playing down, despite growing concern around state linked espionage.In What the Hack, we dig into malware hidden inside movie subtitle files on fake torrents, a new Microsoft account takeover technique that bypasses passwords, MFA, and passkeys, and a Chrome browser extension that was quietly intercepting millions of users’ AI chats while wearing a trusted Featured badge. We also revisit LG’s smart TV Copilot backlash, and how user pushback forced a rapid U turn.The wider topics take us from WhatsApp account hijacking via Ghost Pairing, to activity tracking risks in messaging apps, the growing problem of deepfakes and trust online, crypto scams draining life savings, and how Amazon detected a North Korean infiltrator based on something as subtle as keystroke lag.If you want cyber news explained with clarity and zero jargon, you are in the right place.Chapters00:00:00 Welcome, and this week’s storiesBreach Watch00:01:36 NYC and DC real estate developer data breach00:04:27 SoundCloud breach and VPN disruption00:08:15 PornHub extortion and leaked viewing history00:13:27 UK government hack investigationWhat the Hack00:16:49 Malware hidden in movie subtitle files00:21:55 Microsoft account takeover surge and ConsentFix00:28:47 Chrome extensions harvesting AI chats00:34:54 LG backtracks on Copilot for smart TVsTopics00:38:09 WhatsApp Ghost Pairing account hijack00:41:48 WhatsApp and Signal activity tracking risks00:47:50 Deepfakes, content credentials, and trust online00:49:43 Idris Elba waxwork and biometric security limits00:53:32 Do we actually need AI00:54:40 Crypto scam victim loses 1.8 million dollars00:57:32 North Korean infiltrator caught via keystroke lagMore Informationhttps://riskycreative.comListen on the goSpotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196Follow usLinkedIn: The Awareness Angle NewsletterTikTok: @infosecantInstagram: @riskycreativeYouTube: @riskycreativeIf you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.
Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle.This week on The Awareness Angle Interviews, Ant sits down with Cary Johnson, founder of Phishbusters, for a straight talking conversation about security awareness, human risk, and why so many programmes struggle to prove real impact.This episode strips away dashboards, buzzwords, and vendor narratives to focus on what actually reduces phishing risk. Cary brings a science led perspective to awareness, challenging engagement metrics, benchmarks, and the idea that looking busy means you are becoming more secure.We get into phishing as a measurement tool rather than a content engine, why repeat clickers are not all the same, and how poor measurement can quietly create fatigue, resentment, and false confidence across organisations.If you work in security awareness, human risk, or phishing defence, this conversation will challenge how you think about success.We talk about Why engagement does not equal impact Benchmarks versus baselines, and why the difference really matters Phishing as the number one human risk Repeat clickers, learners, and where risk actually sits Why overtraining creates fatigue and resentment Verification skills and keeping awareness simple Compliance theatre and the danger of vanity metrics Vendors marking their own homework How to test whether your programme is genuinely workingThis is a calm but challenging discussion that says the quiet part out loud. It shows how easily good intentions can turn into noise when measurement is flawed, and how much simpler awareness can be when we focus on proof instead of performance.Let me know what it gets you thinking about.Stay aware, stay secure.Previous Episodehttps://www.youtube.com/watch?v=EntRmhcDOBM&list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRfLinksYouTube: https://www.youtube.com/@riskycreativeLinkedIn: https://www.linkedin.com/company/riskycreativeSpotify: https://open.spotify.com/user/riskycreativeWebsite: https://www.riskycreative.comContact: hello@riskycreative.comIntro and outro music16! by falling foreverhttps://fallingforever.bandcamp.com/track/16License: CC BY 4.0https://creativecommons.org/licenses/by/4.0
This week on The Awareness Angle, data breaches keep piling up, ransomware is still doing damage, and software updates are becoming an attack surface all of their own. Luke is on holiday, so I am flying solo, but there is plenty to dig into.We start with a classic insider risk failure at Coupang, where a former employee kept access after leaving, followed by a credit checking firm exposing millions of people who may never even have heard of them. We also look at a misconfiguration that left vet records publicly accessible, and a pharma company hit by ransomware where data theft came before encryption.In What the Hack, Apple rushes out emergency patches for active zero-day exploits, Notepad++ fixes a flaw that allowed malicious updates to be pushed to users, and LG quietly installs Microsoft Copilot onto smart TVs with no option to remove it, raising uncomfortable questions about control and consent.We then move into the wider topics, from why a breached Pringles account is actually a serious lesson about password reuse, to Roblox horror games rated far too young, smarter captchas designed to beat bots, and a US proposal that could see travellers handing over years of social media history just to cross the border.If you want cyber news explained with clarity and zero jargon, you are in the right place.Chapters00:00 Welcome and this week’s stories01:10 Breach Watch beginsBreach Watch01:30 Coupang breach traced to ex-employee access06:30 Credit check company breach exposes millions13:40 Petco Vetco website data exposure19:40 Inotiv ransomware attack and data theftWhat the Hack25:30 Apple emergency zero-day updates30:40 What is a zero day, explained simply32:30 Notepad++ malicious update flaw37:40 LG TVs install Microsoft CopilotAnt’s Topics46:10 Germany accuses Russia of air traffic control cyber attack49:20 Pringles account breach and password reuse51:40 Roblox games and content maturity concerns53:40 US proposal to collect travellers’ social media historyWrap Up54:50 Final thoughts and sign offListen on the goSpotify: https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6Apple Podcasts: https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196Follow usLinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/TikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreativeYouTube: https://www.youtube.com/@riskycreativeIf you found this useful, hit follow and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.
This week on The Awareness Angle, things get lively. We break down the Scientology ransomware attack, the ongoing chaos at Westminster Council, the five hundred million Windows 10 devices now left unsupported, and the ClickFix scam impersonating ChatGPT that we discovered live during the recording.We dig into what the Qilin gang claims to have taken from Scientology, why Westminster is still struggling to deliver basic services, and how Microsoft has created a global security problem by forcing users onto hardware they cannot afford. We also look at the Windows LNK zero day, Microsoft’s new activity tracking in Teams, and India’s decision to drop its mandatory cyber safety app.The big moment this week is the fake ChatGPT Atlas installer. A live ClickFix scam pushed through a compromised Google Ads account, designed to steal passwords simply by tricking people into pasting a command into their terminal. It is a clear example of how modern attacks borrow trust from real brands.We finish with AI fakery, deepfake claims and a Japanese game studio that now asks applicants to draw live to prove their portfolios are human made.If you want cyber news explained with clarity and zero jargon, you are in the right place.Chapters00:00:00 Welcome back and Luke returns00:00:29 Overview of this week’s stories00:01:19 Breach Watch beginsBreach Watch00:01:19 Scientology hit by Qilin ransomware00:03:28 Westminster Council attack update00:07:03 Freedom Mobile breach in Canada00:09:08 Brsk breach in the UK00:11:38 Marquis breach impacts seventy four US banks00:13:24 Wrap up of this week’s Breach WatchWhat the Hack00:14:25 Windows 10 crisis and unsupported devices00:16:07 Windows LNK zero day explained00:20:30 Teams location and activity reporting backlash00:22:20 India scraps mandatory cyber safety appClickFix Discovery00:25:50 Fake ChatGPT Atlas browser and ClickFix attack00:31:10 Live discovery of active scam through Google Ads00:33:54 Reporting the malicious ad and account takeoverAnt’s Topics00:41:20 Reddit story: employee clicks phishing link00:43:03 Why reporting quickly matters more than the click00:45:33 AI used to fake street footage and misinformationLuke’s Topics00:48:03 AI generated behind the scenes Home Alone footage00:53:52 Debunking viral AI content and misinformation00:55:14 Japanese studio now testing applicants live to stop AI cheatingWrap Up00:58:03 Final thoughts and sign off00:58:51 OutroListen on the goSpotify: https://open.spotify.com/show/7rwzcRs...Apple Podcasts: https://podcasts.apple.com/us/podcast...Follow usLinkedIn: https://www.linkedin.com/newsletters/the-awareness-angleTikTok: https://www.tiktok.com/@infosecantInstagram: https://www.instagram.com/riskycreativeYouTube: https://www.youtube.com/@riskycreativeIf you found this useful, hit subscribe and share it with someone who cares about cyber but does not speak cyber.Stay aware, stay secure.
📢 Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle.📢 This Week on The Awareness AngleA council incident affecting thousands of residents, emergency alerts taken offline, a vishing breach at Harvard, fake Windows updates, AI voice scam stories, and an industrial scale Black Friday campaign tricking shoppers everywhere. Luke is off sick, so Ant takes you through a busy week in cyber on his own.We dive into AI generated shopping scams, a password trick that had Reddit arguing for hours, and a correction to a widely shared Gmail story that shows why verifying details still matters.In this episode: London councils hit by a cyber incident that slowed services Emergency alert systems in the United States disrupted after a cyber attack Harvard alumni data exposed after a vishing breach A SIM swap case that led to financial loss and emotional pressure The UK budget leak caused by a predictable URL Fake Windows update screens used to deliver malware through ClickFix Black Friday and Cyber Monday scams using hundreds of fake brand sites AI voice scams and how criminals can copy a voice with seconds of audio AI generated shopping scams and fake Etsy style listings A password trick involving colons that confused stealer logs The Gmail smart features correction and what really happened A preview of Ant’s session with Layer Eight on Champions programmesIf you work in cyber, tech, IT, risk or you simply want to stay ahead of common scams, this episode gives you clear context that helps you protect yourself and the people around you.👋 About usAnt Davis helps people make sense of the human side of cybersecurity through Kindred Cyber, a people centred security service that focuses on behaviour, culture and clear communication.Luke Pettigrew is an experienced security professional with a strong background in user education for one of the UK’s largest online retailers. Together they turn complex cyber news into simple stories and practical advice.👍 Support the showIf you enjoy the episode, follow the podcast, rate it, and share it with someone who would find it useful.Timestamps00:00 Intro and Luke is off sick01:02 London Councils cyber incident03:15 OnSolve Code Red emergency alert breach06:55 Harvard vishing breach10:25 What the Hack SIM swap case from Joe Tidy16:33 OBR Budget leak caused by a predictable URL21:18 ClickFix fake Windows update malware27:55 Black Friday fake brand giveaways35:40 CIISec Live event recap42:38 TikTok default password coffee machine44:18 TikTok AI kidnap scam voice cloning48:35 Corridor Crew AI shopping scams52:00 Password tip using a colon53:02 Gmail smart features correction55:10 Layer 8 champions report preview56:30 Closing🔗 LinksYouTube: https://www.youtube.com/@riskycreativeLinkedIn: https://www.linkedin.com/company/riskycreativeSpotify: https://open.spotify.com/user/riskycreativeWebsite: https://www.riskycreative.com🎵 MusicIntro and outro song: https://fallingforever.bandcamp.com/track/16
📢 Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness Angle📢 This Week on The Awareness AngleRail hacks, WhatsApp risks, CCTV horror stories, teenage cyber gangs, and a staffing breach that leaked over a hundred thousand CVs. It has been a busy week.Luke and I break down the biggest cyber stories in a way that actually makes sense for real people at work, not just security pros. We talk human risk, scams, what to watch out for, and why the simplest mistakes keep causing the biggest damage.In this episode:• The Italian rail supplier breach with 2.3 TB of stolen data• Salesforce customer data stolen through a Gainsight integration• Cornerstone Staffing and the leak of more than one hundred thousand CVs• A WhatsApp flaw exposing 3.5 billion phone numbers• A nationwide CCTV hack in India involving maternity wards and schools• Australia’s new under sixteen ban and what it means for social platforms• TfL’s 2024 cyber attack and the trial ahead• Plus our own stories, scams we spotted, and awareness topics making the rounds this week👋 About usAnt Davis helps people make sense of the human side of cybersecurity. He runs Kindred Cyber, a people centred security service that gives organisations real world guidance, support and better engagement.Luke Pettigrew is an experienced security professional with years of hands on work educating people across one of the largest online food retailers in the UK. Together they take the complex parts of cyber and turn them into simple stories, clear guidance and content that helps people understand what is happening and why it matters.👍 Support the showSubscribe, drop a like, and leave a comment. It helps more than you think.If you prefer short form content, follow us on TikTok, YouTube Shorts, and Instagram for daily clips.📨 Stay updatedJoin the weekly newsletter for extra context, stories we did not cover, and links to everything we discuss.#cybersecurity #securityawareness #phishing #podcast #cloudsecurity #passwords #AIsecurity #infosec🕒 Timestamps00:00 Intro and welcome00:19 Quick catch up00:32 Ant starting Kindred Cyber01:24 Moving into the breach report02:03 Italian rail group breach03:15 Salesforce and Gainsight breach05:18 Cornerstone Staffing ransomware attack08:32 WhatsApp flaw exposes 3.5 billion numbers12:28 UK, US and Australia sanction Russian cyber firms14:45 Australia adds Twitch to teen social media ban19:52 CCTV hack in Indian maternity wards27:43 TfL cyber attack court update30:59 CIISEC Live and Ant’s appearance32:17 Launch of Kindred Cyber34:30 Lost Phone Passcode Social Engineering Scam37:19 The AI data paste incident from Reddit41:34 Flight scam and Google ads abuse49:11 Bob's Business - Scams and AI made scam sites51:33 Wrap up and closing thoughts🍿 Previous Episodehttps://youtu.be/qsS5wWZTLrg🟥 YouTube🟦 LinkedIn🟩 Spotify📧 hello@riskycreative.com🔗 https://www.riskycreative.com🎵 Our Intro and Outro Song (© 16 by falling forever)https://fallingforever.bandcamp.com/track/16License: CC BY 4.0https://creativecommons.org/licenses/by/4.0/
📢 Subscribe on your favourite platforms and visit https://linktr.ee/riskycreative for more of ∠The Awareness AngleThis week on The Awareness Angle, Ant Davis and Luke Pettigrew break down a wild mix of stories that show how everyday tools are becoming attack surfaces. This episode digs into the human habits, design gaps and risky shortcuts that make these attacks possible.🔓 Google Find Hub Used for Remote WipeA North Korean group found a way to hijack Google accounts, track victims and remotely wipe Android devices. Ant and Luke talk through how cloud accounts have quietly become the true kill switch for modern phones.🤖 The First AI Orchestrated Cyber AttackA Chinese state linked group jailbroke Claude Code and used it to run eighty to ninety percent of a full intrusion chain. No big team. No complex tooling. Just structured tasks and an AI agent that never gets tired.💸 Checkout dot com Turns Extortion Into Something PositiveInstead of paying, they donated the ransom amount to cybercrime research at Oxford and Carnegie Mellon. A rare example of turning an attack into something that helps the whole community.📡 Two Billion Credential DumpHIBP indexes a massive set of recycled passwords and emails. The boys explain why password reuse is still at the root of so many real world breaches.🔍 Ofcom Monitoring VPN UsageA UK regulator tracking VPN use with an unnamed vendor. Ant and Luke get into the privacy implications and why transparency matters.🚌 Chinese Built Buses That Can Be Stopped RemotelyA strange but worrying discovery in Norway. Even legitimate remote access can become a serious operational risk.🧠 PlusCIISec Live, clever awareness ideas on LinkedIn, why timeless videos still work, and a worrying text scam that shows how vulnerable people are still the biggest targets for social engineering.#cybersecurity #securityawareness #phishing #podcast #cloudsecurity #passwords #AIsecurity #infosec🕒 Timestamps:​00:00 Intro and catch up​01:52 Breach Watch begins​02:27 Doctor Alliance healthcare breach​04:02 Synnovis NHS ransomware investigation​07:06 DoorDash social engineering breach​08:56 Checkout dot com extortion attempt​10:10 Synthient credential stuffing dump​13:25 Ofcom monitoring VPN usage​16:20 Chinese built buses can be remotely stopped​21:59 Google Find Hub remote wipe attack​25:55 AI orchestrated espionage using Claude Code​29:55 Scotland launches cyber observatory​31:00 UK Cyber Security and Resilience Bill​35:06 Quantum Route Redirect phishing kit​38:11 Awareness Awareness​40:59 Think and Share challenge​44:34 Right Hand Cyber Halloween posters​47:07 Jimmy Kimmel password clip​50:16 Leanne Potter on language shaping cyber and AI​52:48 Luke’s topic, Lloyds Bank text scam​54:40 Ant’s topic, suspicious car finance email example​58:20 Wrap up https://www.youtube.com/@riskycreative🟦 https://www.linkedin.com/company/riskycreative🟩 https://open.spotify.com/user/riskycreative📧 hello@riskycreative.com🔗 https://www.riskycreative.com🎵 Our Intro and Outro Song (© 16 by falling forever)https://fallingforever.bandcamp.com/track/16License: CC BY 4.0https://creativecommons.org/licenses/by/4.0
We are back with another interview and this one is a proper conversation about what security awareness should feel like. Honest, simple and human.This week I sat down with Dan Thornton, founder and CEO of Goldphish. Dan’s path into cyber started in the Royal Marine Commandos and moved through physical security and crisis management before one attack changed everything. NotPetya wiped out a global organisation he was supporting and it became clear that digital risk now hits harder and faster than anything physical. That moment pushed him into cyber and eventually into building Goldphish.What I love about Dan is how grounded he is. No jargon. No overcomplication. No feature overload. Just a belief that people deserve better than long training, shame based phishing tests and compliance for the sake of compliance.In this episode we get into: Why phishing is smarter, faster and more convincing How attackers use AI to personalise at scale Why shame stops people reporting Why SMEs struggle to run awareness properly Why simple, entertaining content is still the thing most companies get wrongDan is a big believer in incentives. If someone reports quickly, celebrate it. If a team does the right thing, make it visible. Culture grows when people feel supported, not judged.We also talk about voice scams, deep fakes, business email compromise and how criminals are already using AI to build long form, relationship driven fraud. This space is moving and moving quickly.There are some fun moments too. Pizza flavoured passwords, the danger of what our ChatGPT histories reveal and a few curveball questions that took us both by surprise.If you care about human risk, culture and stripping cyber back to what works, this is a great episode to dive into. Dan brings a refreshingly practical view of awareness and why the basics still matter more than anything.Listen now and imagine what your programme could be if you kept things simple, human and actually enjoyable.You can find Dan at goldphish.com or on LinkedIn.
You are tuned in to The Awareness Angle, the weekly show where we cut through the cyber noise and get straight to the scams, slip ups, and stories that actually matter.In this episode, Ant and Luke dig into a fresh batch of breaches, some worrying policy decisions, and a few very human stories from inside the cyber world. From councils leaking resident data, to VPNs quietly opening the door to ransomware, to AI powered scams on your favourite apps, this one is packed.In this episodeGlobal breach round up Hyundai AutoEver America, Nikkei’s Slack compromise, and South Gloucestershire Council accidentally publishing residents’ personal data. What happened, what was exposed, and what it says about everyday cyber hygiene.The Louvre robbery and terrible passwords The reported CCTV password that matched the museum name, ignored audits, and what happens when reputation gives people a false sense of security.Australia’s social media ban for under 16s Reddit and others join the list. Safety, surveillance, and whether bans really help children, or just push them into darker corners of the internet.FCC rolls back telecom cyber rules Why stripping mandatory requirements after major hacks is a bad look, and what it tells us about politics and security.Apple’s monster patch day More than 100 vulnerabilities fixed across iOS, macOS, iPadOS and more, but very little clarity on severity. Patch fatigue, transparency, and WebKit as the quiet weak point.Firewalls, VPNs, and hidden complexity New data that links complex Cisco and Citrix VPN setups to a much higher ransomware risk, and why “do everything” security boxes often end up poorly maintained.Microsoft Teams message manipulation Flaws that allowed attackers to alter messages, spoof identities, and fake calls. What this means for trust in internal chat tools and executive impersonation.M&S profits almost wiped out by a cyber attack A single incident that slashed profits by 99 percent, disrupted shelves and click and collect, and showed just how fast cyber risk becomes business risk.When the good guys go bad Two former cyber professionals accused of running ALPHV ransomware attacks on the side. Insider knowledge, trust, and the reality of cyber crime as a business.HuFiCon trip and human risk in the wild Ant’s debrief from the Human Firewall Conference in Cologne, why SoSafe impressed, and a few live examples of herd mentality and social proof you can use in your own awareness work.ChatGPT’s “improve the model for everyone” setting Why you should check that toggle if you are using personal accounts for work data, and why business or enterprise plans matter.Meta, scam ads, and shameless profit A look at reports that Meta is earning serious money from obviously fraudulent adverts, and what that means for ordinary users trying to stay safe.AI image fraud and DoorDash style scams Using AI tools to fake photos for refund claims and how app design could shut some of this down.ClickFix in the wild A real world example of the copy and paste into the run box attack, why it works, and the simple message you need people to remember.Recruitment rants and candidate experience Ghosting, broken promises, and what sloppy hiring processes say about culture inside security teams.Listen forReal stories you can reuse in your own awareness or training sessions.Plain language explanations of complex attacks, from VPN misuse to Teams abuse.Honest chat about what is and is not working in the world of human risk.Stay connectedSubscribe to The Awareness Angle Newsletter for story links and extra commentary.Watch full episodes and clips on YouTube, search for Risky Creative or The Awareness Angle.New episodes every week. Views are our own, not our employers.
This week on The Awareness Angle, Ant Davis and Luke Pettigrew unpack a wave of global cyber stories — from telecom breaches and AI-powered defence tools to sextortion scams and the emotional risks of “friendly” chatbots. It’s a mix of human stories, technical takeaways, and practical lessons for anyone trying to stay safe in an AI-shaped world.📡 Global Breaches & Third-Party Fallout – LG U+, Toys “R” Us Canada, HSBC, and Verisure all suffer breaches linked to vendors or poor visibility. The takeaway? Even mature orgs keep getting blindsided by supplier access and delayed disclosure.🤖 OpenAI’s ‘Aardvark’ GPT-5 Agent – A self-fixing AI for security flaws sounds promising—until you realise it’s patching live code. Automation helps, but trust and verification still matter more than ever.💬 Meta’s Scam Detector – WhatsApp and Messenger now use AI to flag impersonation and job scams. Ant ties this to his own “Tilly from Fram Search” scam attempt, showing how emotional hooks still trump logic.🧒 AI Sextortion Scams & ReportRemove – Deepfaked nudes used to extort teens; a BBC case highlights the IWF’s lifesaving removal tool. A reminder that awareness isn’t just about security—it’s safeguarding.👥 Character.AI Blocks Teen Chat – After reports of inappropriate AI conversations, under-18s are now cut off. Ant and Luke discuss why “empathetic” AI companions can quickly turn toxic.🇬🇧 NCSC Annual Review – Four major UK cyber incidents every week, a 129% rise year-on-year. New SME Cyber Action Toolkit promises easy wins, but small firms still face time and funding barriers.🧩 Chrome Zero-Day (Memento Mori) – Active exploit patched, but only if users reboot. Awareness message: “Auto-update isn’t a shield—restart and verify.”💼 Insider Threats & Classroom Tricks – A Reddit post shows real insider exfiltration, while teachers hide invisible AI prompts to catch students using ChatGPT. Both show behaviour—not tech—is the true battleground.📰 AI Authenticity Crisis – From AI-written beauty magazines to GPT vs Google explainers, even “real” media now demands literacy training to spot synthetic content.🧠 ‘EtherHiding’ Malware on Blockchain – Malicious code hidden in blockchain assets targets job seekers via fake coding tests. Proof that persistence now has a whole new meaning.Whether you’re defending systems, teaching staff, or just trying to keep your kids safe online—this episode connects the technical, the human, and the emotional sides of cybersecurity.🕒 Timestamps00:00 — Introduction & Milestone Celebration📩 For links, videos, and the newsletter – head to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠💬 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Check Out This Episode's Discussion Points⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠📧 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hello@riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🔗⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🎵 Our Intro & Outro Song (© ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠16! by ⁠falling forever⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠)License: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://creativecommons.org/licenses/by/4.0⁠⁠⁠
This week on The Awareness Angle, Ant Davis and Luke Pettigrew dive into the fast-moving collision between AI innovation, real-world breaches, and human behaviour. From Sotheby’s data leak to AI browsers that remember your every move, this episode explores where awareness, policy, and technology are all being stress-tested.🏭 Sotheby’s, Muji & JLR Breaches – From luxury auctions to car factories, supply chain ransomware continues to ripple through industries. JLR’s £1.9B loss now marks the UK’s costliest cyber incident.🧠 Deepfake Politics – A fake video of MP George Freeman “defecting” proves that AI-fabricated political manipulation is no longer hypothetical—it’s here and hyper-local.📹 YouTube’s Likeness Detection – Google’s new system to identify AI fakes comes with a trade-off: creators must hand over government ID and facial video. Security meets privacy in a messy middle.🎣 Phishing-as-a-Service – “Whisper 2FA” has powered over 1M phishing attacks, using AJAX to steal live MFA codes. A reminder: phishing kits evolve faster than most awareness programs.🧭 ChatGPT Atlas Browser – The new AI-integrated browser introduces “memory” and “agent” modes—but also raises massive insider and data leakage risks. Shadow AI just went mainstream.🧩 Windows Zero-Days – Legacy modem and RASMAN flaws are being exploited in the wild. Microsoft and vendors rush to patch, underlining the ongoing struggle with hidden legacy code.📈 Reddit’s Reality Check – Security pros report phishing surges of up to 300%, likely linked to the Salesforce leak. Community intel confirms: automation is scaling human deception.🎙️ Community Highlights – Ant joins the Go Fish podcast and Layer8’s Security Champions project ahead of his talk at the Human Firewall Conference in Cologne.🔍 Phishing Design & Visual Cues – The hosts dissect a fake rnicrosoft.com email and how simple UI details—like hyperlink colours—still shape digital literacy.🎬 AI & Authenticity – OpenAI’s first brand ad was filmed on 35mm film. Even AI firms are leaning on the “human touch” to rebuild audience trust.🛠️ Tools Worth Knowing – Shoutout to Pistachio App, a clean, transparent platform for phishing simulations and insider risk detection—proof that simplicity wins adoption.🚨 TikTok, SIM Farms & SMS Blasters – Latvian police seize 40,000 SIMs in a major fraud ring, while a UK man is jailed for sending parcel scam texts on the Tube—awareness in action.🕒 Timestamps00:00 — Introduction & Milestone Celebration📩 For links, videos, and the newsletter – head to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠💬 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Check Out This Episode's Discussion Points⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠📧 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hello@riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🔗⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🎵 Our Intro & Outro Song (© ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠16! by ⁠falling forever⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠)License: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://creativecommons.org/licenses/by/4.0⁠⁠⁠
This week on The Awareness Angle, Ant Davis and Luke Pettigrew unpack a packed lineup of real-world cybersecurity stories — from paper-based recovery plans to AI data leaks, healthcare ransoms, and the human messiness behind governance and awareness. It’s all about what happens when the systems fail, the people improvise, and resilience gets real.📄 Paper Plans & Power Cuts – The NCSC urges organisations to keep printed incident plans. The hosts ask the hard question: how do you “open your playbook” if it’s been ransomwared?☁️ Cloud “Whoopsie” of the Week – A misconfigured “Invoicedly” S3 bucket leaks sensitive financial data. Simple mistakes, big consequences.🤖 Shadow AI at Work – 77% of employees reportedly paste company data into ChatGPT. Culture or control — what’s the real fix?🏥 Healthcare Ransomware Ethics – X-rays and ECGs leaked online reignite debate over whether private healthcare firms should ever pay.📬 Court-Themed Phishing – Fake legal summonses using SVG attachments show how scammers are levelling up in realism.💬 Discord Support Leak Confusion – Government IDs appear in a third-party breach; finger-pointing follows. Who’s really accountable?💸 Capita’s £14M Lesson – The ICO fine lands, proving that prevention costs less than penalties. A nod to burnt-out IR teams who rarely get a break.🧠 F5 Networks Intrusion – Nation-state attackers lurked for months before discovery. The takeaway? Patch, disclose, repeat.📉 Deloitte’s $440K AI Blunder – A government report filled with hallucinated citations — proof that even consultants need a human review step.🧩 Awareness Corner – Ant previews his HuFiCon talk in Cologne and shares Layer8’s open research on what makes security champions work.🕒 Timestamps00:00 — Introduction & Milestone Celebration📩 For links, videos, and the newsletter – head to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠💬 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Check Out This Episode's Discussion Points⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠📧 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hello@riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🔗⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🎵 Our Intro & Outro Song (© ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠16! by ⁠falling forever⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠)License: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://creativecommons.org/licenses/by/4.0⁠⁠
This week on The Awareness Angle, Ant Davis and Luke Pettigrew unpack the latest in cybersecurity and human risk — from fake job recruiters flooding LinkedIn to deepfake chaos and a nursery hack that shocked the UK. Whether it’s scams, software flaws, or stolen art, this episode is all about where human behaviour meets digital consequence.🕵️‍♂️ LinkedIn Recruitment Scam – “Open to Work” TrapWhen Ant switched on “Open to Work,” fake recruiters arrived within seconds — zero followers, spam hashtags, and mismatched job offers. It’s a stark reminder of how social engineering preys on urgency and hope. Pause, verify, and think before engaging.🎮 Unity Vulnerability – Game Engine FlawA high-severity Unity exploit forced Steam to block unpatched games. It’s a lesson in patch psychology — users delay for convenience, but the cost of waiting is higher than the update itself.🎬 AI Video Boom & Deepfake ConcernsSora 2 becomes the fastest-downloaded app ever as creators like MrBeast warn of deepfake chaos — from fake celebrity videos to stolen likenesses. The takeaway: verification and transparency are the new currency of trust online.🧒 Kido Nursery Hack – Teenagers ArrestedTwo 17-year-olds were charged over a ransomware attack on a UK nursery chain — an alarming example of how young people can be drawn into cybercrime, and why early education and deterrence are essential.🎨 Author’s iPad Theft – Six Years LostThe Boy, The Mole, The Fox and The Horse author lost years of unreleased artwork after his iPad was stolen. A real-world reminder: backups only matter if they actually work — and you’ve tested them.🌐 Domain Hijack – Puffin Books / Andy CopeA hijacked author website redirected visitors to adult content. It’s a simple DNS lapse with reputational fallout — renew your domains, secure your logins, and monitor what matters.💬 Discord Vendor Breach – Third-Party RiskA vendor compromise exposed 70,000 Discord users. Even if your systems are secure, partners can still sink you. Limit data retention and review vendor practices regularly.🎰 DraftKings Credential StuffingAttackers accessed accounts through reused passwords — fewer than 30 victims, but entirely preventable. MFA and unique credentials remain the simplest, strongest defence.☁️ Salesforce / Scattered SpiderRansomware actors claim 1.5 billion records — one of the largest alleged data thefts to date. Another case of companies refusing to pay, proving resilience and communication are as vital as response plans.🎤 Wrap-Up & Awareness TakeawaysAnt plugs upcoming appearances at HuffyCon (Human Firewall Conference, Cologne) .🕒 Timestamps00:00 — Introduction & Milestone Celebration📩 For links, videos, and the newsletter – head to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠💬 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Check Out This Episode's Discussion Points⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠📧 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hello@riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🔗⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🎵 Our Intro & Outro Song (© ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠16! by ⁠falling forever⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠)License: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://creativecommons.org/licenses/by/4.0⁠⁠
This week on The Awareness Angle, Anthony Davis and Luke Pettigrew dig into a packed line-up of stories that show just how wide the cyber threat landscape has become—from luxury retailers and carmakers taken offline, to insider risks, ransom trends, and the latest fights between governments and Big Tech. It’s not just about breaches and numbers; it’s about people, trust, and the human cost behind the headlines.🛍️ Harrods, Renault & Asahi Hit – A wave of big-name attacks highlights how third-party breaches ripple across industries—and why some victims keep getting hit again.💰 Ransomware Stats That Shock – Hiscox research shows 27% of SMEs targeted last year, 80% paying up, and only 60% recovering data. We debate whether ransom bans are coming.🧑‍💻 Insider Temptations – Hackers offered the BBC’s Joe Tidy a cut of ransom if he gave insider access. It’s a stark reminder of how disgruntled staff can become the weakest link.🎒 Nursery Data Fallout – After outrage, hackers “apologised” and claimed to delete leaked children’s profiles. We unpack what this says about criminal limits and reputational damage.📧 Oracle Extortion Emails – CLOP-linked scammers target execs directly with extortion threats. Why quiet, internal responses can make things worse.🕹️ Platforms Under Pressure – Imgur blocked in the UK, Roblox culls 8 million games for age compliance. VPNs remain the obvious workaround, but at what risk?😓 Cybersecurity Burnout – The BBC spotlighted Ant on stress in cyber jobs. We talk long hours, mental health, and why culture matters as much as controls.🍏 UK vs Apple – A Technical Capability Notice demands more government access. Apple’s pushback could have knock-on effects for WhatsApp, Meta, and beyond.📊 Security Champions & Community Research – Fresh insights from Layer 8’s survey on what makes champion programs succeed—and why open-source research helps awareness pros.🤖 Shadow AI at Work – Staff still pasting secrets into ChatGPT despite training. Should companies ban tools outright, or build safer corporate alternatives?🔐 Password Managers Ranked – Wired tips Bitwarden for most users, ProtonPass for free setups. The takeaway: stop reusing passwords, start managing them properly.🎭 AI Video & Deepfake Surge – From TikTok character swaps to OpenAI’s Sora 2, the line between fake and real gets blurrier by the day. What it means for scams, politics, and trust.From ransomware payments to burnout, insider risks to AI misuse, this episode connects the dots on how cyber threats are evolving—and why awareness needs to evolve too.🕒 Timestamps00:00 — Introduction & Milestone Celebration📩 For links, videos, and the newsletter – head to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠💬 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Check Out This Episode's Discussion Points⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠📧 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hello@riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🔗⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🎵 Our Intro & Outro Song (© ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠16! by ⁠falling forever⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠)License: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://creativecommons.org/licenses/by/4.0⁠⁠
This week on The Awareness Angle, Anthony Davis and Luke Pettigrew dive into everything from car factories grinding to a halt to ransomware crews dumping nursery data online. It’s a mix of big-business losses, government experiments with digital ID, and the human cost of attacks that don’t care who they hit.🚗 Jaguar Land Rover Shutdown – Millions lost each day, suppliers in crisis, and no cyber insurance in sight. We unpack why this wasn’t “just an IT problem.”✈️ Airports Held to Ransom – Collins Aerospace software outage takes down check-in systems across Europe. We look at third-party risks and déjà vu comparisons with the CrowdStrike fiasco.🪪 UK Digital Identity Scheme – A bold plan for online trust, or surveillance by stealth? We explore what it could mean for privacy and daily life.🎒 Nursery Ransomware Leak – Criminals publish children’s profiles and family data. The ethics are grim, but it raises bigger questions about ransom bans and government policy.⚖️ Law Firms in the Crosshairs – Weak passwords, outdated tech, and no MFA. Why smaller firms are prime targets—and how class actions are fuelling the chaos.💻 GitHub & npm Security Overhaul – After 500+ compromised packages, stronger controls are here. But will devs embrace them, or find ways around?🎙️ Deepfakes & Fake Voices – A survey says 44% of businesses hit by audio deepfakes. We’re sceptical—but the tactics are real, and awareness needs to evolve.🍪 Cookie Banners on the Way Out – The EU may finally kill off endless pop-ups. Great for users, but what replaces them?Along the way, Ant recaps highlights from KnowBe4’s CyberSecure Leeds and the SANS Security Awareness Summit, with stories of romance scams, AI panels, and why awareness needs a human edge.If you care about supply chain fragility, human risk, and how attackers exploit the cracks in everyday systems, this one’s full of lessons.🕒 Timestamps00:00 — Introduction & Milestone Celebration02:57 — Cybersecurity Awareness & Community Engagement06:00 — Password Manager Vulnerabilities09:00 — AI Ransomware & the Rise of AI in Cybersecurity12:01 — Cyber Attacks on Major Corporations17:20 — Reflections on Cybersecurity Trends18:37 — Compensation Claims & Data Breaches22:26 — SalesLoft Drift Breach: Implications & Insights27:17 — Cyber Awareness & Phishing Campaigns32:31 — AI, Misinformation & Media Risks37:41 — Emerging Cybersecurity Threats📩 For links, videos, and the newsletter – head to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠💬 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Check Out This Episode's Discussion Points⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠📧 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hello@riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🔗⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ riskycreative.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠🎵 Our Intro & Outro Song (© ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠16! by ⁠falling forever⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠)License: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://creativecommons.org/licenses/by/4.0⁠⁠
loading
Comments