<turbo-stream action="append" target="posts_list"><template><turbo-frame class="main-list__list-item" data-testid="Post" id="post_158364">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/158364/watch_times"
  data-youtube-player-video-id-value="Qfwq2z7EyFs"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/j5juqukfry10439bq71w8xvo2s54" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/158364">
          Sep 8, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/158364">
            700+ Companies Hit by SalesLoft Drift Hack, Are You At Risk?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<span><img class="m_3316789177683667046img CToWUd a6T" alt="The Awareness Angle - The Newsletter" src="https://ci3.googleusercontent.com/meips/ADKq_Na4Zs85_a5rns91PttcAdYstlZjjOiWIJ-825IQQA4Ucbw3DKFq6CNNGXP41CxV5YY0cNDanX6vJo6SNSAs_k1RCEeCx2edb5c1dbhtjJsW1whNhdhcFNoqH7RzqCsN8SiWm8nQF01-l5pIERyQsfSw=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/t7HYs5fUyFMiwJKs8KXMHtnvxzKXHrGF1jAM0JLr.jpg" width="640" onerror="this.style.display='none'"></span>






















<h1>700+ Companies Hit by SalesLoft Drift Hack, Are You At Risk?</h1>
<p>This week’s news takes us from password managers with a hidden flaw to the first glimpse of AI-powered ransomware, and from Jaguar Land Rover’s production lines grinding to a halt to hackers pushing ultimatums at Google. Add in fallout from the Salesloft breach rippling across big-name security vendors, and it’s a week packed with stories that hit close to home.</p>
<p><span><img class="an1" alt="🎧" src="https://fonts.gstatic.com/s/e/notoemoji/16.0/1f3a7/72.png" onerror="this.style.display='none'"></span><span> </span>Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="m_3316789177683667046img CToWUd" height="150" src="https://ci3.googleusercontent.com/meips/ADKq_NYyJ897MxEIKYezSqSnlim4ZNM6N3bUZ7fupyC71dU_GWTIgfoWQuFTs1PKx3VZHtq-YtoX2BiRrAV8tdGEVnLCCeYIxR6dRj_PcffgQEIBCqsCFeWYwBN34Wngpj9Ak-OBfHrs0Nym7JwPhGGjjysS=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="m_3316789177683667046img CToWUd" height="48" src="https://ci3.googleusercontent.com/meips/ADKq_NbegVyQ56xtGMctwI74KZUXXlu4FCa4ZVpt9mf_dVpie72SAytX5gzqQ1cyHC0WMueAFjuViZ6rNbTU8wFPNkZ52dXkruu8oml5nlLsSYow0A=s0-d-e1-ft#https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>


































































<h2>New Hoxhunt Videos for Cyber Awareness Month 2025 </h2>






















<span><img class="m_3316789177683667046img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NbSFiumEesF1bmHSBN-EWWGC5aOunxJYs3-fQAbYQ2zIHsBePms4fUNWMrjKG6lgpxYMUOm3ucra2KxD0pceKeAnhnffUKWjPToVTMJ5EWJ2yq4-Eyir9b1ZkxS3nBiOjlqeV7z_awJ1YNW3lpxW31p=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/QeZOmw4AARaixUZSRujyjDYBI6mkhan7hgJYRGK0.png" width="540" onerror="this.style.display='none'"></span>

























<p>We’ve teamed up with Hoxhunt again to create a fresh set of short videos for their<span> </span><strong>2025 Cyber Awareness Month Toolkit</strong>. From spotting deepfakes to understanding social engineering in chat apps, these 1–2 minute clips are designed to be shared widely and spark awareness conversations.</p>
<p><br>Get the toolkit here - <a href="https://hoxhunt.com/cybersecurity-awareness-month-toolkit-2025#awareness-angle" target="_blank" rel="noopener">https://hoxhunt.com/cybersecurity-awareness-month-toolkit-2025</a></p>



























































<h2>This week's stories...</h2>
<p></p>
<h2>Password Managers Under Attack</h2>
<p>Watch the discussion - <a href="https://youtu.be/Qfwq2z7EyFs?t=367" target="_blank" rel="noopener">https://youtu.be/Qfwq2z7EyFs?t=367</a></p>
<p>A new report has revealed a clickjacking flaw in major password manager browser extensions, including 1Password, Bitwarden, Dashlane, LastPass, NordPass and ProtonPass. The bug could expose sensitive details from up to 40 million users by tricking autofill into handing over data through invisible page overlays. Experts are stressing this isn’t a reason to ditch password managers, which remain one of the strongest defences against password reuse, but it is a reminder to tweak how you use them.</p>
<p><strong>Read more -<span> </span><a href="https://www.pcworld.com/article/2887955/password-managers-vulnerable-40-million-users-at-risk-of-stolen-data.html" target="_blank" rel="noopener">https://www.pcworld.com/article/2887955/password-managers-vulnerable-40-million-users-at-risk-of-stolen-data.html</a></strong></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<p><strong>Autofill off</strong><span> </span>– Turn off automatic autofill in your password manager and switch to manual “on-click” mode.</p>
</li>
<li>
<p><strong>MFA everywhere</strong><span> </span>– Keep two-factor authentication on for all accounts, especially your password manager.</p>
</li>
<li>
<p><strong>Don’t panic</strong><span> </span>– Password managers are still one of the best tools to keep your accounts secure. </p>
</li>
</ul>






















<h2>AI Ransomware Arrives: Meet PromptLock</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/Qfwq2z7EyFs?t=653" target="_blank" rel="noopener">https://youtu.be/Qfwq2z7EyFs?t=653</a></p>
<p>Researchers have discovered<span> </span><strong>PromptLock</strong>, believed to be the first ransomware powered by artificial intelligence. Instead of relying on fixed malicious code, it runs an AI model locally on the victim’s machine to generate attack scripts on the fly. This makes it harder for traditional security tools to detect and block. For now, it looks more like a proof-of-concept than a widespread threat, but it shows how AI is being weaponised to make attacks smarter, faster and more adaptable.</p>
<p>Read more - <a href="https://cybersecuritynews.com/first-ai-ransomware/" target="_blank" rel="noopener">https://cybersecuritynews.com/first-ai-ransomware/</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Proof of concept today</strong><span> </span>– PromptLock isn’t widespread yet, but it’s a sign of what’s coming.</li>
<li>
<p><strong>AI arms race</strong><span> </span>– Criminals are experimenting with AI just as much as defenders are.</p>
</li>
<li>
<p><strong>Stay prepared</strong><span> </span>– Basics like patching, backups, and detection tools remain the first line of defence.</p>
</li>
</ul>






















<h2>Cyber Attack Stalls Jaguar Land Rover</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/Qfwq2z7EyFs?t=776" target="_blank" rel="noopener">https://youtu.be/Qfwq2z7EyFs?t=776</a></p>
<p>Jaguar Land Rover’s production was severely disrupted after a cyber attack forced systems offline on one of the busiest new car registration days in the UK. Employees were told not to return to work until systems were restored, and dealers had to fall back on manually phoning the DVLA to register new cars. Hackers claiming links to groups like Scattered Spider and ShinyHunters say they exploited a flaw in SAP NetWeaver, raising questions over patching and whether attackers had ever fully left the network after earlier incidents.</p>
<p>Read more - <a href="https://www.autocar.co.uk/car-news/new-cars/police-and-cyber-experts-brought-jlr-remains-crippled-hack" target="_blank" rel="noopener">https://www.autocar.co.uk/car-news/new-cars/police-and-cyber-experts-brought-jlr-remains-crippled-hack</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Business impact</strong><span> </span>– Cyber attacks don’t just steal data, they can stop production lines in their tracks.</li>
<li>
<p><strong>Patch management</strong><span> </span>– Known vulnerabilities remain one of the most common entry points.</p>
</li>
<li>
<p><strong>Persistence matters</strong><span> </span>– Attackers may already be inside, even after a previous breach is “fixed.”</p>
</li>
</ul>
<ul></ul>






















<h2>Salesloft Breach Ripples Across Big Vendors</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/Qfwq2z7EyFs?t=1320" target="_blank" rel="noopener">https://youtu.be/Qfwq2z7EyFs?t=1320</a></p>
<p>A breach at Salesloft’s Drift chatbot platform has spilled over into some of the biggest names in cybersecurity. Attackers stole authentication tokens that connected Drift with tools like Salesforce, Google Workspace, AWS and Slack. So far, victims include Zscaler, Cloudflare, Palo Alto Networks, and more, and the list is still growing. Salesloft revoked all access and rotated tokens, while Google’s threat team linked the activity to a group known as UNC6395 (aka “Grub One”). For any business using Drift, the advice is simple: treat all tokens as compromised, rotate credentials, and review integrations for unusual activity.</p>
<p>Read more - <a href="https://www.crn.com/news/security/2025/5-cybersecurity-vendors-impacted-in-salesloft-drift-breach" target="_blank" rel="noopener">https://www.crn.com/news/security/2025/5-cybersecurity-vendors-impacted-in-salesloft-drift-breach</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Third-party risk</strong><span> </span>– Integrations add value, but also open cracks in your defences.</li>
<li>
<p><strong>Token takeover</strong><span> </span>– Authentication tokens are as valuable as passwords to attackers.</p>
</li>
<li>
<p><strong>Reset and review</strong><span> </span>– Revoke, rotate, and investigate whenever a connected service is hit.</p>
</li>
</ul>
<ul></ul>
<ul></ul>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>This Week's Discussion Points...</h2>
<p>Password managers vulnerable: 40 million users at risk<br><a href="https://youtu.be/Qfwq2z7EyFs?t=367" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.pcworld.com/article/2887955/password-managers-vulnerable-40-million-users-at-risk-of-stolen-data.html" target="_blank" rel="noopener">Read</a></p>
<p>First AI ransomware ‘PromptLock’ discovered<br><a href="https://youtu.be/Qfwq2z7EyFs?t=653" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://cybersecuritynews.com/first-ai-ransomware/" target="_blank" rel="noopener">Read</a></p>
<p>Jaguar Land Rover hit by cyber attack<br><a href="https://youtu.be/Qfwq2z7EyFs?t=776" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.autocar.co.uk/car-news/new-cars/hackers-who-hit-ms-claim-responsibility-jlr-cyber-attack" target="_blank" rel="noopener">Read</a></p>
<p>Salesloft breach grows bigger<br><a href="https://youtu.be/Qfwq2z7EyFs?t=1320" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.crn.com/news/security/2025/5-cybersecurity-vendors-impacted-in-salesloft-drift-breach" target="_blank" rel="noopener">Read</a></p>
<p>Reddit: Cyber Awareness Month phishing campaign ideas<br><a href="https://youtu.be/Qfwq2z7EyFs?t=1605" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.reddit.com/r/cybersecurity/s/d6pJem7UtW" target="_blank" rel="noopener">Read</a></p>
<p>Joe Rogan tricked by AI video<br><a href="https://youtu.be/Qfwq2z7EyFs?t=1805" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.reddit.com/r/JoeRogan/s/5WKEwDbyxF" target="_blank" rel="noopener">Read</a></p>
<p>Gemini photo prompt exploit<br><a href="https://youtu.be/Qfwq2z7EyFs?t=2020" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNdVb9qoW/" target="_blank" rel="noopener">Read</a></p>
<p><a href="https://vm.tiktok.com/ZNdVb9qoW/" target="_blank" rel="noopener"></a></p>
<p></p>
<p><strong><span><img class="an1" alt="📬" src="https://fonts.gstatic.com/s/e/notoemoji/16.0/1f4ec/72.png" onerror="this.style.display='none'"></span><span> </span>Subscribe to the Newsletter</strong></p>
<p></p>
<p><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">https://www.riskycreative.com</a></p>
<ul></ul>
 
<p><a href="https://www.instagram.com/reel/DH6DhqNorAj/?igsh=cm54OHh0dXVkMTh1" target="_blank" rel="noopener"></a></p>


























<h3>Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at<span> </span><span><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></span>. We’re always learning, and your input helps shape future episodes.</h3>


























<h2>Guest Spot: AI Experience Podcast</h2>






















<span><img class="m_3316789177683667046img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NZazPBOwWhO77Vnp7jObfGd6LHXIGQIRcq0BDJlv4EsG810CdGccJXCz8Z7Yp8D_NchjK0WBS4U0K9VfIuu7GKNXyiYNSGn9MzAS_93cqw7Rxikf1zaJhYKE1-ar_xFIAoFYy0eZm9WHxQwsQgh6GXQ=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/eSn2JX6meaNTRFSzEKGhERekbld1Ao46WfPesLbb.png" width="540" onerror="this.style.display='none'"></span>

























<p><span><a href="https://smartlink.ausha.co/ai-experience-eng/ai-scams-are-here-can-cybersecurity-keep-up" target="_blank" rel="noopener"></a></span>Ant recently joined Julien Redelsperger on the<span> </span><strong>AI Experience podcast</strong><span> </span>to talk about how AI is reshaping cybersecurity. From deepfake voices to flawless phishing emails, scams are getting harder to spot, and yet sometimes the best defence still comes down to analogue checks and trusting your instincts.</p>
<p>The episode is available on all major podcast platforms.  Click<span> </span><span><a href="https://smartlink.ausha.co/ai-experience-eng/ai-scams-are-here-can-cybersecurity-keep-up" target="_blank" rel="noopener">here</a></span><span> </span>to listen.</p>











</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/158364?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/158364?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F158364%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F158364%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_156603">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/156603/watch_times"
  data-youtube-player-video-id-value="v64EH9pK_w8"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/9jkvcg679f1bdozerw1349mpl51k" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/156603">
          Sep 1, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/156603">
            Grok Chatbot Leaks 370,000 Private Conversations
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week we’ve got leaks, lawsuits, and legislation. From Elon’s Grok chatbot spilling hundreds of thousands of private chats into Google search results, to Mac users being tricked by a fake “fix” that hides an info-stealer, to a developer jailed for sabotaging his ex-employer with a kill switch. Add in a major telecoms breach, Android’s new plan to verify every app developer, and Denmark pushing bold new deepfake laws, and there’s plenty to talk about.</p>
<p>Listen on your favourite podcast platform - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyMTc1NjI4NzYsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI1ZDllYTNlZDVmOTljYjMyIn0" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyMjI4MDU3NTgsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJmOTdkYTcxNGQ0NmUxMzk1In0" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyMjgwNDg2NDAsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIyNGUyNzI2Yzg4Yzc4NTdjIn0" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyMzMyOTE1MjIsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIwNTZhMjQ5Njk4MWUxNjY3In0" target="_blank" rel="noopener"><span><img class="m_6615620331083099690img CToWUd" height="150" src="https://ci3.googleusercontent.com/meips/ADKq_NYyJ897MxEIKYezSqSnlim4ZNM6N3bUZ7fupyC71dU_GWTIgfoWQuFTs1PKx3VZHtq-YtoX2BiRrAV8tdGEVnLCCeYIxR6dRj_PcffgQEIBCqsCFeWYwBN34Wngpj9Ak-OBfHrs0Nym7JwPhGGjjysS=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyMzg1MzQ0MDMsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIxMWFmNWYzMzNlMzkzN2NlIn0" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyNDI3Mjg3MTAsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJjYmFkNWJkOTVhODVlODFiIn0" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyNDc5NzE1OTIsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI0MzYyOTkzZWMzODhlZTg0In0" target="_blank" rel="noopener"><span><img class="m_6615620331083099690img CToWUd" height="48" src="https://ci3.googleusercontent.com/meips/ADKq_NbegVyQ56xtGMctwI74KZUXXlu4FCa4ZVpt9mf_dVpie72SAytX5gzqQ1cyHC0WMueAFjuViZ6rNbTU8wFPNkZ52dXkruu8oml5nlLsSYow0A=s0-d-e1-ft#https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>




































<h2>Hundreds of thousands of Grok chats exposed in Google results</h2>
<p>Watch the discussion - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyNTMyMTQ0NzQsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIyODYwMzgzYWRhYWExY2RhIn0" target="_blank" rel="noopener">https://youtu.be/v64EH9pK_w8?t=127</a></p>
<p>Elon Musk’s Grok chatbot was caught up in a major privacy incident after more than 370,000 user conversations were found in Google search results. A flaw in the Share button meant chats that were supposed to be private were being indexed, making them accessible to anyone searching. The leaked conversations were not harmless either. They included medical information, passwords, and even instructions on making explosives. It follows similar incidents with other AI platforms earlier this year, raising serious questions about how much we can trust these tools with sensitive information.</p>
<p>Read more - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyNTc0MDg3NzksXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIwYTU1YzYyZmUyNThmM2FjIn0" target="_blank" rel="noopener">https://www.bbc.co.uk/news/articles/cdrkmk00jy0o</a></p>
<p><strong>∠T</strong><strong>he Awareness Angle<br></strong></p>
<ul>
<li>
<strong>Privacy is not guaranteed</strong><span> </span>– AI chats may appear private but unless privacy is designed into the platform, they can leak just like a public post.</li>
<li>
<p><strong>Sensitive data at risk</strong><span> </span>– Health details, credentials, and personal secrets were all exposed, showing how valuable this information is.</p>
</li>
<li>
<p><strong>Think before you share</strong><span> </span>– Treat AI chats like social media and never share anything you would not want to end up online.</p>
</li>
</ul>






















<h2>Fake Mac fixes trick users into installing new Shamos infostealer</h2>
<p>Watch the discussion -<span> </span><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyNjc4OTQ1NDEsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI5MTBhMTBmNjJhZjNjZGIxIn0" target="_blank" rel="noopener">https://youtu.be/v64EH9pK_w8?t=267</a></p>
<p>A new malware strain called Shamos is targeting Mac users by posing as a system fix. Attackers are using malvertising and fake websites like<span> </span><a href="http://mac-safer.com/" target="_blank" rel="noopener">mac-safer.com</a><span> </span>to trick people into pasting commands into Terminal. Instead of solving a problem, the code installs an infostealer that grabs browser data, passwords, Keychain items, Apple Notes, and even crypto wallets. Since June more than 300 Mac environments have been hit.</p>
<p>Read more - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyNzUyMzQ1NzQsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJmMDEwZWY0ZDhmYTllN2UwIn0" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Looks helpful, ends harmful</strong><span> </span>– Fake fixes prey on people desperate to solve a problem quickly.</li>
<li>
<p><strong>High-value data stolen</strong><span> </span>– Shamos can access passwords, notes, and financial accounts, making it highly damaging.</p>
</li>
<li>
<p><strong>Safe support routes</strong><span> </span>– Never run commands from random sites. Always go directly to Apple’s official support channels.</p>
</li>
</ul>






















<h2>Dev gets 4 years for creating kill switch on ex-employer’s systems</h2>
<p>Watch the discussion -<span> </span><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyODI1NzQ2MDgsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhYmZmMTMzZGJlMGUwNTAzIn0" target="_blank" rel="noopener">https://youtu.be/v64EH9pK_w8?t=548</a></p>
<p>Former software developer Davis Lu was sentenced to four years in prison after sabotaging his ex-employer’s network. Lu had secretly embedded malicious code into Eaton Corporation’s systems that triggered when his account was disabled. The “kill switch” crashed servers, deleted profiles, and locked out thousands of users, costing the company hundreds of thousands of dollars.</p>
<p>Read more - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyODk5MTQ2NDEsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJiYzY0Y2RmZGExYWIzMTYwIn0" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/dev-gets-4-years-for-creating-kill-switch-on-ex-employers-systems/</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Insider risk is real</strong><span> </span>– While most insider incidents are accidental, malicious acts can cause devastating damage.</li>
<li>
<p><strong>Planned sabotage</strong><span> </span>– Lu named his code after himself, showing how brazen and deliberate insider threats can be.</p>
</li>
<li>
<p><strong>Controls matter</strong><span> </span>– Monitoring for unusual code, enforcing separation of duties, and regular audits can reduce this risk.</p>
</li>
</ul>
<ul></ul>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>This Week's Discussion Points...<strong></strong>
</h2>
<p>Hundreds of thousands of Grok chats exposed in Google results<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUyOTcyNTQ2NzQsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhOWIwZjYxMzM0NjE5MjEzIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzMDQ1OTQ3MDgsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIwMTQwYzNkYjNmNzU4MGMxIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>Fake Mac fixes trick users into installing new Shamos infostealer<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzMTE5MzQ3NDEsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJiNTY1ODVlN2I3OGE5MGEyIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzMTcxNzc2MjUsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI1YThmMzg2MmE4ODNhMzk4In0" target="_blank" rel="noopener">Read</a></strong></p>
<p>Dev gets 4 years for creating kill switch on ex-employer's systems<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzMjQ1MTc2NTksXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJlOWZkZGU2OWZjZmU1YjgzIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzMjk3NjA1NDEsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhNTM3YzYxNzc4ODIwYTJjIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>Orange Belgium discloses data breach impacting 850,000 customers<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzMzUwMDM0MjMsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJjN2FmYzBhNWM5Zjc4OTRhIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNDAyNDYzMDUsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJmMmI5MTA4NTVjNTM3NTFmIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>You Won’t Be Able to Install Apps from Unverified Android Developers Soon<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNDY1Mzc3NjMsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI3YzdkYWQ0NTAwZjE0MDY0In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNTM4Nzc3OTcsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI3NjhmZWQzNzE2ZTcyMDEwIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>4chan launches legal case against Ofcom in US federal court<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNTkxMjA2ODAsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhN2JkNTA4ZjAzZTU1MTM3In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNjU0MTIxMzgsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJmNmVmMGRkMzAwZTc2YmNmIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>How 16 billion becomes 231 million, then 9 million<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNzA2NTUwMjEsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIxOTc3ZjMwNmYwNmIxODI0In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTUzNzU4OTc5MDMsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI4MzJiYzM0MDM4OGYzMzk3In0" target="_blank" rel="noopener">Read</a></strong></p>
<p>MoD staff warned not to share hidden data before Afghan leak<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0MTI1OTgwNzYsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI0NDQ2OTJkZTIyMjJjODgwIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0MTk5MzgxMTIsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI3MDM0NzU5NDk5NTQ1NGRkIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>Denmark’s bold move to protect citizens from deepfakes<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0MjcyNzgxNDcsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhYzc3YzFlOGU3ZjlkZGEzIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0MzU2NjY3NTksXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIzNzIwZGFkMDU2OWI0MDJiIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>Why are hackers always shown in hoodies?<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0NDMwMDY3OTUsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIxYmFiYzViYTlmNmVjZjkwIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0NTI0NDM5ODQsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJiN2ViZTUwOTdlNzBjNjkzIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>WiFi signals reveal human movement indoors<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0NjE4ODExNzAsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIzZDdhOTgwNjBjODUzMDIzIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0NzM0MTU1MDgsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI1ODk4YWM2MjQ4YmFmYTVmIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p>Gmail unsubscribe hack<br><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0Nzg2NTgzOTAsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiIwYWYxYmU4NTcxZmM3MDA4In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0ODQ5NDk4NTAsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJiMmIyOWI0ZWM4MDI3MWEyIn0" target="_blank" rel="noopener">Read</a></strong><br><br></p>
<p><strong><span> </span>Subscribe to the Newsletter</strong></p>
<p><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0OTEyNDEzMDgsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhYjBlYTM3M2JiOWU5MDBiIn0" target="_blank" rel="noopener">https://www.riskycreative.com</a><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU0OTc1MzI3NjYsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJmZmI1MGI1Yzc5YzllNTc4In0" target="_blank" rel="noopener"></a></p>
<ul></ul>






















<h2>The Gmail unsubscribe hack you might not know about</h2>
<p>Watch - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU1MDM4MjQyMjMsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiI5ZjM2MzVmMzI5YWExZmJhIn0" target="_blank" rel="noopener">https://youtu.be/v64EH9pK_w8?t=2418</a><a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU1MTAxMTU2ODEsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJhYjU1NzNjMzc4NTFjZDA5In0" target="_blank" rel="noopener"></a></p>






















<span><img class="m_6615620331083099690img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NYp22YO9PtHkMaYVCqrMfcA-45yz7npYeCtz4DLq_FVWK56yFaPnOQUYFXVYsqL8Xght28gkQktf0QMT2SZa9XzQtxGL6rPJ006ocQywUBSbJ3ZMrExvbDGyM1fY1jop7x1cxqBLyHM7855sCAacLYd=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/b5mqJ6HYUytrF9fCXbnxTDKLmPv8YIoJxSOI3uaz.png" width="540" onerror="this.style.display='none'"></span>

























<p>A TikTok clip revealed a simple Gmail trick to clear out unwanted emails. In the left-hand menu under “More,” there’s a<span> </span><strong>Manage Subscriptions</strong><span> </span>option. It lists every newsletter and marketing email you’re signed up to, with a one-click unsubscribe button. It even shows how often you receive them, making it much easier to tidy your inbox.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Hidden feature</strong><span> </span>– Gmail has a built-in tool to manage and cancel subscriptions in bulk.</li>
<li>
<p><strong>Time saver</strong><span> </span>– Instead of hunting through emails, you can unsubscribe directly in one place.</p>
</li>
<li>
<p><strong>Inbox hygiene</strong><span> </span>– Keeping clutter under control reduces the risk of missing important security messages.</p>
</li>
</ul>
 
<p>Watch it at - <a href="https://dzxlpg.clicks.mlsend.com/td/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjQzMTQ4NTU1MTc0NTU3MTUsXCJyXCI6MTY0MzE0OTAxODQ2Njg5MjA5fSIsInMiOiJiODNiODVkY2U5NjdlMTcyIn0" target="_blank" rel="noopener">https://vm.tiktok.com/ZNd4NNg1V/</a></p>


























<h3>Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at<span> </span><span><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></span>. We’re always learning, and your input helps shape future episodes.</h3>











</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/156603?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/156603?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F156603%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F156603%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_154454">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/154454/watch_times"
  data-youtube-player-video-id-value="Vcol4c93Eg8"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/xtiuqvratung1dihqigr104laxe6" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/154454">
          Aug 24, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/154454">
            Your VPN Extension Might Be Watching You Right Now!
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<h1>Your VPN Extension Might Be Watching You Right Now!</h1>
<p>This week’s episode is packed with cyber scams, shady extensions, and even hackers opening floodgates at a dam in Norway. We’re talking about how censorship laws could reshape the internet, the UK quietly backing down in its Apple privacy fight, and a new infostealer campaign disguised as copyright warnings. Add in PayPal credential dumps, Workday’s social engineering breach, and Chrome extensions spying on users, and there’s plenty to dive into. Plus, we take a look at the latest SANS 2025 Security Awareness Report and what it means for awareness teams everywhere.</p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>





























<h2>Fake Copyright Emails Delivering Malware</h2>
<p>Watch the discussion - <a href="https://youtu.be/Vcol4c93Eg8?t=670" target="_blank" rel="noopener">https://youtu.be/Vcol4c93Eg8?t=670</a></p>
<p>Attackers are sending out spear-phishing emails that pretend to be legal threats from law firms over copyright or IP infringement. The emails look convincing, mentioning details like Facebook page IDs or company names, and urge recipients to download a file. That “PDF” is actually a disguised archive carrying the<span> </span><em>Noodlophile</em><span> </span>infostealer, which steals cookies, saved cards, and login credentials while hiding on the system.</p>
<p>Read more - <a href="https://www.helpnetsecurity.com/2025/08/18/noodlophile-infostealer-spear-phishing-campaign-copyright-infingement/" target="_blank" rel="noopener">https://www.helpnetsecurity.com/2025/08/18/noodlophile-infostealer-spear-phishing-campaign-copyright-infingement/</a></p>
<p><strong>∠T</strong><strong>he Awareness Angle</strong></p>
<ul>
<li>
<strong>Fear as a Trigger</strong><span> </span>– Legal threats create panic, pushing people to click quickly without questioning.</li>
<li>
<p><strong>Malware Masquerade</strong><span> </span>– The file looks like a PDF but is really an installer that sideloads malware into trusted apps.</p>
</li>
<li>
<p><strong>Expanding Threat</strong><span> </span>– This isn’t just hitting small creators anymore, it’s now targeting businesses worldwide.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<h2>Workday Breach via Social Engineering</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/Vcol4c93Eg8?t=1251" target="_blank" rel="noopener">https://youtu.be/Vcol4c93Eg8?t=1251</a></p>
<p>Workday, the HR and enterprise software provider, disclosed a breach after attackers posed as HR or IT staff over phone and text to trick employees into handing over credentials. The attackers accessed a connected CRM platform, exposing business contact details like names, emails, and phone numbers. While no sensitive HR or financial data was taken, those details can be weaponised in phishing and social engineering campaigns.</p>
<p>Read more - <span><a href="https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html" target="_blank" rel="noopener">https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html</a></span></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Social Engineering Wins</strong><span> </span>– A simple call or text can bypass strong technical controls if trust isn’t questioned.</li>
<li>
<p><strong>Small Data, Big Risk</strong><span> </span>– Even “just” names and emails can fuel convincing phishing or extortion attempts.</p>
</li>
<li>
<p><strong>Third-Party Weakness</strong><span> </span>– Breach came through a connected CRM, highlighting supply chain and SaaS risks.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<h2>PayPal Credentials for Sale</h2>
<p>Watch the discussion -<span> </span><span class="ml-rte-link-wrapper"><a href="https://youtu.be/Vcol4c93Eg8?t=1250" target="_blank" rel="noopener">https://youtu.be/Vcol4c93Eg8?t=1250</a></span></p>
<p>A cybercriminal claims to be selling 15.8 million PayPal logins in plain text for just $750. While researchers say it’s unlikely PayPal itself was breached, the data probably comes from infostealer malware logs that harvested credentials from infected devices. Even if many accounts are fake or outdated, the inclusion of PayPal login URLs makes it easier for attackers to launch automated credential stuffing and fraud attempts.</p>
<p>Read more - <span class="ml-rte-link-wrapper"><a href="https://hackread.com/threat-actor-selling-plain-text-paypal-credentials/" target="_blank" rel="noopener">https://hackread.com/threat-actor-selling-plain-text-paypal-credentials/</a></span></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Not a PayPal Breach</strong><span> </span>– The danger comes from malware stealing credentials on personal devices, not PayPal’s systems.</li>
<li>
<p><strong>Password Reuse Problem</strong><span> </span>– Recycled passwords could expose accounts on other services, not just PayPal.</p>
</li>
<li>
<p><strong>MFA is Essential</strong><span> </span>– Multi-factor authentication remains the best defence if passwords are compromised.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>






















<h2>Pro-Russian Hackers Breach Norwegian Dam</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/Vcol4c93Eg8?t=1929" target="_blank" rel="noopener">https://youtu.be/Vcol4c93Eg8?t=1929</a></p>
<p>Norway’s Police Security Service confirmed that pro-Russian hackers briefly seized control of a hydropower dam earlier this year. Attackers remotely opened floodgates, releasing 500 litres of water per second for four hours before being stopped. No damage occurred, but the hackers later posted video proof of the breach on Telegram to amplify fear. The attack highlights how critical infrastructure can be manipulated as part of hybrid influence campaigns rather than outright destruction.</p>
<p>Read more - <a href="https://securityaffairs.com/181143/hacktivism/norway-confirms-dam-intrusion-by-pro-russian-hackers.html" target="_blank" rel="noopener">https://securityaffairs.com/181143/hacktivism/norway-confirms-dam-intrusion-by-pro-russian-hackers.html</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Not a PayPal Breach</strong><span> </span>– The danger comes from malware stealing credentials on personal devices, not PayPal’s systems.</li>
<li>
<p><strong>Password Reuse Problem</strong><span> </span>– Recycled passwords could expose accounts on other services, not just PayPal.</p>
</li>
<li>
<p><strong>MFA is Essential</strong><span> </span>– Multi-factor authentication remains the best defence if passwords are compromised.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>This Week's Discussion Points...</h2>
<p><strong>Censorship is going to destroy the internet</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=231" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://mashable.com/article/age-verification-is-going-to-destroy-the-entire-internet" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>UK backs down in Apple privacy row</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=446" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/articles/cdj2m3rrk74o" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Noodlophile infostealer behind fake copyright notices</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=639" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.helpnetsecurity.com/2025/08/18/noodlophile-infostealer-spear-phishing-campaign-copyright-infingement/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>15.8M PayPal credentials for sale</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=1247" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://hackread.com/threat-actor-selling-plain-text-paypal-credentials/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Workday data breach via social engineering</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=1447" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Android–iPhone messaging security upgrade</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=1589" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.androidauthority.com/apple-ios-26-rcs-end-to-end-encryption-mls-protocol-3588258/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Norway dam intrusion by pro-Russian hackers</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=1928" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://securityaffairs.com/181143/hacktivism/norway-confirms-dam-intrusion-by-pro-russian-hackers.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Chrome VPN extension spying on users</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=2168" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://cyberinsider.com/chrome-vpn-extension-with-100k-installs-screenshots-all-sites-users-visit/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Google patches critical Chrome flaw</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=2350" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://cyberpress.org/google-patches-high-severity-chrome-vulnerability-allowing-code-execution/?amp=1" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>SANS 2025 Security Awareness Report</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=2480" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.sans.org/mlp/ssa-security-awareness-report" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>NowTV anti-piracy ad</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=3114" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.reddit.com/u/NOWTV/s/w25iEaEagE" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Chipotle phishing simulation backlash</strong><br><a href="https://youtu.be/Vcol4c93Eg8?t=3314" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.instagram.com/reel/DNd3fDrxBGG/?igsh=MWt1ZWN1MHdreTUxaQ==" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p></p>
<p><strong>📬 Subscribe to the Newsletter</strong></p>
<p></p>
<p><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">https://www.riskycreative.com</a></p>
<ul></ul>
<p><a href="https://www.instagram.com/reel/DH6DhqNorAj/?igsh=cm54OHh0dXVkMTh1" target="_blank" rel="noopener"></a></p>






















<h2>Free Chipotle? It’s a Phish</h2>
<p>Watch - <a href="https://youtu.be/Vcol4c93Eg8?t=3296" target="_blank" rel="noopener">https://youtu.be/Vcol4c93Eg8?t=3296</a><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/ubWaWkiphfQATC2jNH5bWwTS4faTIRHjsK2q6sz3.png" width="540" onerror="this.style.display='none'"></span>

























<p>A viral Instagram video shows an employee falling for a simulated phishing email offering free Chipotle. She clicked the link, filled in her order, and turned up at work expecting lunch — only to discover it was a test. Instead of burritos, she got three hours of mandatory phishing training. While it makes for a funny video, it raises serious questions about how organisations run phishing campaigns. Humiliating staff and punishing them harshly for one mistake can backfire, creating resentment instead of awareness.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Humour or Harm?</strong><span> </span>– Funny to watch, but heavy-handed training risks damaging trust with employees.</li>
<li>
<p><strong>Punishment vs Learning</strong><span> </span>– Phishing simulations should build awareness, not embarrass staff.</p>
</li>
<li>
<p><strong>Better Approaches</strong><span> </span>– Supportive feedback, coaching, and bite-sized training are more effective than punitive measures.</p>
</li>
</ul>
<p>Watch it at - <a href="https://www.instagram.com/p/DNkKhYssbRW/" target="_blank" rel="noopener">https://www.instagram.com/p/DNkKhYssbRW/</a></p>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>


























<h3>Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at<span> </span><span><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></span>. We’re always learning, and your input helps shape future episodes.</h3>


























<h2>Next podcast episode...</h2>

























<span><img src="https://static.mailerlite.com/cbuilder/timer/2025-09-01%2006%3A00%3A00/light/Europe%2FLondon" width="354" onerror="this.style.display='none'"></span>











Days









Hours









Minutes









Seconds






















</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/154454?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/154454?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F154454%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F154454%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_153566">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/153566/watch_times"
  data-youtube-player-video-id-value="Ce8cjxsYXDY"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/87xzwrufiw7nwafpuo7kq08xte03" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/153566">
          Aug 18, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/153566">
            Could Your Webcam Be Spying on You?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week, we’re bringing you a mix of Chicago heat, cyber scares, and a bit of nostalgia. I’ve just wrapped up an incredible few days at the SANS Security Awareness Summit, where 350 awareness pros (and over 5,000 virtually) came together to share stories, strategies, and yes, a few laughs. From romance scam keynotes to Champions Network chats, it was packed. You can catch our two live streams (plus a brilliant bonus bit) from the summit on YouTube if you missed them.</p>
<p>Back in the news, we dig into a wild Lenovo webcam flaw that turns cameras into hacking tools, a scam piggybacking on car finance compensation, and fresh zero-days cracking open password vaults. Plus, there’s a telecom breach, a city hit with ransomware has breached data made available, and a reminder that even “strong” passwords aren’t always as strong as we think.</p>
<p>And because we like to balance the serious with the fun, we also talk AOL dial-up (RIP after 30 years), calendar spam scams, and the rise of “Major Data Breach” as a military rank.</p>
<p><span><img class="an1" alt="🎧" src="https://fonts.gstatic.com/s/e/notoemoji/16.0/1f3a7/32.png" onerror="this.style.display='none'"></span><span> </span>Listen on your favourite podcast platform - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjc5NzQ1NTk2OTAsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI3M2NhNjZhZWU4MDQxMWIzIn0" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjc5Nzg3NTM5OTYsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIwMzdmYWIyNzk2MzkzYmIxIn0" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjc5ODM5OTY4NzksXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJlNGY5ZjAxNzA5ODY4NDQ5In0" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjc5ODkyMzk3NjEsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIzMzMwNTNhOTNkMGQ3Mjg5In0" target="_blank" rel="noopener"><span><img class="m_8967029074684832580img CToWUd" height="150" src="https://ci3.googleusercontent.com/meips/ADKq_NYyJ897MxEIKYezSqSnlim4ZNM6N3bUZ7fupyC71dU_GWTIgfoWQuFTs1PKx3VZHtq-YtoX2BiRrAV8tdGEVnLCCeYIxR6dRj_PcffgQEIBCqsCFeWYwBN34Wngpj9Ak-OBfHrs0Nym7JwPhGGjjysS=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjc5OTM0MzQwNzAsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIxZDcxMjQxNDMwNTc5Zjk4In0" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjc5OTk3MjU1MzAsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI1NjFkZGNlZDQzMDYwYTE2In0" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMDM5MTk4MzgsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI4NjFlODYzYjFlZGQ1MWIzIn0" target="_blank" rel="noopener"><span><img class="m_8967029074684832580img CToWUd" height="48" src="https://ci3.googleusercontent.com/meips/ADKq_NbegVyQ56xtGMctwI74KZUXXlu4FCa4ZVpt9mf_dVpie72SAytX5gzqQ1cyHC0WMueAFjuViZ6rNbTU8wFPNkZ52dXkruu8oml5nlLsSYow0A=s0-d-e1-ft#https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>





























<h2>Conversations From The Summit</h2>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMDkxNjI3MjMsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJmMmMzYjUyM2I0ZGE4MzZlIn0" target="_blank" rel="noopener"></a></p>






















<span><img class="m_8967029074684832580img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NapIYV1UrmMNb9xlevh0MO3ooGaRk860wTz6BWn9B60LLD31pHj0RzVIVsJBZD8Gr5GvmPU3gzk3Z_WiTenDuZAlsImANqo44GTUQUP2N35_U41cXnnoNuonaL7bbfewlPKy_3meI1gH_ukhYkEhd7x=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/FRlWeaWx4Fwr4nOG4g10oRwTQi8r9495GuYLSIqN.png" width="540" onerror="this.style.display='none'"></span>






















<p>The SANS Security Awareness Summit is the biggest gathering of people who live and breathe security awareness, human risk, and culture. This year, more than 350 professionals met in Chicago, with thousands more joining online. For two days the focus was on one thing: how to make security stick with people.</p>
<p>Here are some of the big takeaways from the conversations and sessions:</p>
<ul>
<li>
<p><strong>Stories make it stick</strong><span> </span>– time and again, people highlighted that storytelling is one of the most powerful tools we have in awareness. A good story is remembered years later, while a policy or slide deck is often forgotten.</p>
</li>
<li>
<p><strong>Words matter</strong><span> </span>– the language we use can either build trust or shut people down. Some traditional buzzwords are starting to feel stale or even negative, and many are turning towards warmer, more human messaging.</p>
</li>
<li>
<p><strong>Culture over compliance</strong><span> </span>– the strongest programs are moving away from box-ticking exercises and instead building genuine relationships across the business. It’s about nurturing behaviours, not policing them.</p>
</li>
<li>
<p><strong>Champions need investment</strong><span> </span>– security champions and ambassador networks are widely seen as one of the best ways to influence culture, but they only thrive when they have proper support, budget, and dedicated people running them.</p>
</li>
<li>
<p><strong>Community is everything</strong><span> </span>– awareness professionals are learning as much from each other as they are from the talks. Peer-to-peer sharing, whether at the summit or in ongoing practice groups, is driving new ideas and confidence.</p>
</li>
<li>
<p><strong>Human risk is front and centre</strong><span> </span>– the conversation is shifting from “awareness training” to measuring and reducing actual behaviours that create risk, supported by better data and behavioural science.</p>
</li>
<li>
<p><strong>The power of in-person</strong><span> </span>– many said the real magic of the summit is in the connections: the chats over coffee, the sense of community, and the reassurance that you’re not the only one facing these challenges.</p>
</li>
</ul>
<span>You can watch both LinkedIn Lives and a bonus session on YouTube.<br></span>
<p><span>Watch here - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMTQ0MDU2MDgsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI0MDg4Mzg5ZDlhODE4NDI5In0" target="_blank" rel="noopener">https://www.youtube.com/playlist?list=PLEsOj51Q0PfBp55nkDIS0S3sA8cTJFJkk</a></span></p>



























































<h2>Lenovo Webcams Can Be Turned Into BadUSB Devices</h2>
<p>Watch the discussion - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMjE3NDU2NDUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI4ZmM3MWJlZDAwOTNmMzliIn0" target="_blank" rel="noopener">https://youtu.be/Ce8cjxsYXDY?t=527</a></p>
<p>Researchers have found a serious flaw in certain Lenovo webcams (CVE-2025-4371) that allows attackers to remotely reprogram them into so-called<span> </span><em>BadUSB</em><span> </span>devices. Originally demonstrated back in 2014, this attack takes advantage of USB firmware itself, turning what looks like an innocent webcam into a malicious tool. Once compromised, the camera can inject keystrokes, deliver payloads, or log data.  What's even more worrying is that it can survive a full operating system reinstall.</p>
<p>Lenovo has released firmware updates to fix the issue, but it’s a reminder that even everyday accessories like webcams aren’t always as simple as they seem. These devices often run their own operating systems and can be weaponised without the user ever realising.</p>
<p>Read more - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMjY5ODg1MjgsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIxYjUyYzY1MGQyOGZmZjNlIn0" target="_blank" rel="noopener">https://thehackernews.com/2025/08/linux-based-lenovo-webcams-flaw-can-be.html</a></p>
<p><strong>∠T</strong><strong>he Awareness Angle</strong></p>
<ul>
<li>
<strong>Peripheral Trust Risks</strong><span> </span>– Even “innocent” devices like webcams can run their own OS and be remotely weaponised.</li>
<li>
<p><strong>Persistence Beyond OS Wipe</strong><span> </span>– Firmware-level malware survives reinstallation, requiring hardware-level fixes.</p>
</li>
<li>
<p><strong>Supply Chain &amp; Physical Access Threats</strong><span> </span>– Malicious devices could be shipped to targets or swapped in by insiders.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMzMyNzk5ODksXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIwMWE3NTY1YTQ4NzM4MzkxIn0" target="_blank" rel="noopener"></a></p>






















<h2>uBlock Origin Lite Finally Comes to Safari</h2>
<p>Watch the discussion -<span> </span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwMzg1MjI4NzUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI2NDBjYmIwOTUzNTEwZDcxIn0" target="_blank" rel="noopener">https://youtu.be/Ce8cjxsYXDY?t=763</a></p>
<p>Safari users have been missing a reliable ad blocker for years, but that gap is now filled. uBlock Origin Lite is a lightweight, privacy-friendly version of the popular ad blocker and is finally available on macOS, iOS, and iPadOS. Unlike the original extension, it uses Safari’s “declarative rules API,” which means the browser handles all the blocking natively, without draining CPU or memory.</p>
<p>Why does this matter? Malicious Advertising (or Malvertising) is still a common infection route, and a good ad blocker doesn’t just clean up your browsing experience. It also helps protect against malicious ads. For Apple users who’ve been stuck without proper options, this is a welcome (and safer) addition.</p>
<p>Read more - <span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNDQ4MTQzMzUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIyZWRmNDQ0ZDExMWNiYTI4In0" target="_blank" rel="noopener">https://www.howtogeek.com/ublock-origin-lite-is-finally-available-on-safari/</a></span></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Lightweight Privacy Tool</strong><span> </span>– Blocks ads and trackers without draining device resources.</li>
<li>
<p><strong>Apple Ecosystem Gap Filled</strong><span> </span>– Safari users on iPhone and iPad finally get official support.</p>
</li>
<li>
<p><strong>Declarative Security Model</strong><span> </span>– Reduces attack surface by letting the browser handle blocking logic natively.</p>
</li>
</ul>
<ul></ul>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNTAwNTYxOTUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI2OGUxNTA5MmYxYTU0MzU4In0" target="_blank" rel="noopener"></a></p>






















<h2>Scammers Jump on Fake Car Finance Payouts</h2>
<p>Watch the discussion -<span> </span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNTYzNDc2NTYsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJmNGVlOTI1MGIzY2E2OTlhIn0" target="_blank" rel="noopener">https://youtu.be/Ce8cjxsYXDY?t=963</a></p>
<p>The UK’s Financial Conduct Authority (FCA) has warned motorists about scam calls offering fake compensation for mis-sold car finance deals. Real compensation of up to £950 per driver is being considered, but the scheme isn’t live yet. Fraudsters are exploiting the publicity by posing as lenders and tricking people into handing over personal and banking details.</p>
<p>The FCA has been clear: it will<span> </span><em>never</em><span> </span>ask for PINs or passwords. If someone calls about a payout, it’s a scam. Hang up immediately and report it. With so much publicity around the genuine legal cases, these scams are only likely to grow.</p>
<p>Read more - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNjI2MzkxMTUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIyNjcwODgyM2M3MDY1ZTg2In0" target="_blank" rel="noopener">https://www.bbc.co.uk/news/articles/c860021w3g8o</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>No Scheme Yet</strong><span> </span>– Any compensation offers right now are fake as the FCA is still in consultation.</li>
<li>
<p><strong>Data Theft Risk</strong><span> </span>– Scammers aim to harvest bank and personal details under the guise of claims.</p>
</li>
<li>
<p><strong>Avoid Middlemen</strong><span> </span>– Claims firms may take up to 30% of payouts unnecessarily.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNjc4ODE5OTgsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI2YzQ0NTBkZjQ5Yzg4ODA1In0" target="_blank" rel="noopener"></a></p>






















<h2>Google Calendar Spam Invites Trick Users Into Scams</h2>
<p>Watch the discussion -<span> </span><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNzMxMjQ4ODIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJhOTM3ZjlhYWE0OGE0YThmIn0" target="_blank" rel="noopener">https://youtu.be/Ce8cjxsYXDY?t=2531</a></p>
<p>A sneaky scam is making its way into people’s schedules, literally. Attackers are sending fake Google Calendar invites that look like business opportunities, complete with WhatsApp numbers and vague “partnership” offers. Because Calendar is often set to automatically add invitations, these bogus meetings appear right in your diary even if the invite goes to spam.</p>
<p>The hook is simple: reply to the WhatsApp number and they’ll try to extract personal details, bank info, or upfront payments for a fake deal. Several versions are circulating, all using different email addresses but the same WhatsApp contact.</p>
<p>The fix is straightforward:</p>
<ul>
<li>
<p>In Google Calendar, go to<span> </span><strong>Settings → Event settings → Automatically add invitations → No, only show invitations I’ve responded to.</strong></p>
</li>
<li>
<p>Under<span> </span><strong>View options</strong>, uncheck<span> </span><strong>Show declined events</strong>.</p>
</li>
</ul>
<p>This is basically phishing delivered through your calendar instead of your inbox, and it’s a reminder that spam can slip in from unexpected places.</p>
<p>Read more - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwNzk0MTYzNDAsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJiZmZkM2ZkMGIxYzdkMzEyIn0" target="_blank" rel="noopener">https://www.bitdefender.com/en-gb/blog/hotforsecurity/use-google-calendar-heres-the-one-change-that-can-protect-your-business-from-scams</a></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Calendar Phishing</strong><span> </span>– Scams don’t just arrive by email anymore; invites and reminders can be weaponised too.</li>
<li>
<p><strong>Default Settings Risk</strong><span> </span>– “Automatically add” gives attackers a free pass to your schedule.</p>
</li>
<li>
<p><strong>Simple Fix</strong><span> </span>– Changing one setting shuts down this entire attack vector.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwODQ2NTkyMjEsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJjNTk3NmVkNjY4MGI3MmQ5In0" target="_blank" rel="noopener"></a></p>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>This Week's Discussion Points...</h2>
<p><strong>Linux-Based Lenovo Webcams' Flaw Can Be Remotely Exploited for BadUSB Attacks</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwODk5MDIxMDIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIwMjFkMDAzOGUyODk5ODg0In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgwOTQwOTY0MDcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJiOGMxZGI1NzI5MDE2ZDdlIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>uBlock Origin Lite Is Finally Available on Safari</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMDU2MzA3NDQsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI4ODUyYjBiMjFlODdkZmY2In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMTA4NzM2MjUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJmMzQ0YTlhYjIxMWVhNTUxIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Drivers warned about scam car finance payout calls</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMTUwNjc5MzAsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJhNWZhYjE2NDMzMDI1Mzk4In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMjEzNTkzODcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIwYzUwYTg1MzcwMTZkYzc1In0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Critical Zero-Days Crack Open CyberArk Password Vaults</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMjU1NTM2OTIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI3NzM2NTgyNmUyYWVlZDc3In0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMjk3NDc5OTcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJlODQyYmFlMjJkN2YzZjBhIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Bouygues Telecom Hit by Cyberattack, 6.4 Million Customers Affected</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxMzQ5OTA4NzgsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJhNTBiYThiZmQzOGMwZWFmIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNDEyODIzMzUsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIwYmQ1NjVmODBiMjE1ZGY3In0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Interlock Ransomware Group Leaks 43GB of Data in City of St. Paul Cyberattack</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNDY1MjUyMTYsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJhZTFjYWUzMmY4NmU5NDBjIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNTA3MTk1MjEsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIyZTYzYzM3MWVjNGI1MGVjIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Reddit: Strong Passwords Weaker Than Weak Ones</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNTU5NjI0MDIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJlMjViYmQxZTU0NmIwNmEyIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNjAxNTY3MDcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJmN2JjODY1MWM1ZTQwYzQ5In0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Reddit Meme: Age Verification Scam Ads</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNjQzNTEwMTIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIxNjFhNTNiNDU2MmMyY2NhIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNjg1NDUzMTcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJlZTBjMWZhODY3MjNiNzc0In0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Password Power – CyberHerd Awareness Game</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNzI3Mzk2MjIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI1ZDc3MGFmYWU5NmM2ZjVlIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxNzY5MzM5MjcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJmYTU2ZDI3ZmRhMDczYWFmIn0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>AOL Ends Dial-Up Service After More Than 30 Years</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxODAwNzk2NTYsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI2NzZiZjk2NGU3MDNjYmIyIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxODYzNzExMTMsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI4MjlkZTAzNmE5MmJjYTk4In0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Major Data Breach Meme (Major Data Breach Reporting for Duty)</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxODk1MTY4NDIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI5ZWExZDQ0ZjQ2ZDEzZTUzIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxOTM3MTExNDcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIyZmIzMWQ3YjU1NzQ4YjM3In0" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Google Calendar Spam Scam</strong><br><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgxOTc5MDU0NTIsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJiY2E4NTI5MTFiOGZlOTIxIn0" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgyMDIwOTk3NTcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJiYWVhNzI3OThmNGRhYzI1In0" target="_blank" rel="noopener">Read</a></strong><br><br></p>
<p><strong><span><img class="an1" alt="📬" src="https://fonts.gstatic.com/s/e/notoemoji/16.0/1f4ec/32.png" onerror="this.style.display='none'"></span><span> </span>Subscribe to the Newsletter</strong></p>
<p></p>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgyMDYyOTQwNjMsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJiMTNhNTAxOTM4Mjc0MWFmIn0" target="_blank" rel="noopener">https://www.riskycreative.com</a></p>
<ul></ul>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgyMTI1ODU1MjAsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiJhMDMzMWQ0ZjVhZWY1MjhmIn0" target="_blank" rel="noopener"></a></p>






















<h2>Major Data Breach… Reporting for Duty</h2>
<p>Watch - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgyMTc4Mjg0MDEsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI5OTg1ZWZiOTU3ZTVlMThkIn0" target="_blank" rel="noopener">https://youtu.be/Ce8cjxsYXDY?t=2361</a></p>
<p><a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgyMjIwMjI3MDYsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiI5MjY2NmI3ZjE4MDNjMGE2In0" target="_blank" rel="noopener"></a></p>






















<span><img class="m_8967029074684832580img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NbnzBtR78GZxhyd1JaNhh_yvb7u2D9UpwrCqWfbMeDbQULm0rP1nbKTKqUt74lWasbGdV-x75oUFcCXbMx9_NfxZ8y9Z2rA0J_dGmmrU2udD_c8Fk7z4gFoUSVBAVDk7UoiCyvjqXGZ6bpKTQB60NzR=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/cKvfpqacc1j9pEb6Xct3E6VBdaxA3rDGOSJISVtd.png" width="540" onerror="this.style.display='none'"></span>

























<p>Sometimes security awareness doesn’t need a 50-page whitepaper, it just needs a good laugh. On an Australian news broadcast, the words<span> </span><em>“Major Data Breach”</em><span> </span>flashed up on screen while a military officer in uniform stood perfectly in frame. The unintentional mash-up looked like the officer’s name badge was literally “Major Data Breach.”</p>
<p>The clip from the Toni and Jon Podcast last year has since gone viral and for good reason. It’s a reminder that humour can break down barriers when talking about cyber. Sharing memes, light-hearted clips, and cultural moments like this in your workplace can spark conversations that stick far longer than another all-staff email.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Humour Works</strong><span> </span>– A funny clip can start the security conversation better than another warning.</li>
<li>
<p><strong>Front of Mind</strong><span> </span>– Little viral moments keep “cyber” relevant in everyday chatter.</p>
</li>
<li>
<p><strong>Relatable Training Tool</strong><span> </span>– Sharing memes in newsletters, chats, or town halls can make security feel human and approachable.</p>
</li>
</ul>
<br>
<p>Watch it at - <a href="https://dzxlpg.clicks.mlsend.com/tb/cl/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNjMwNjEyMjgyMjcyNjU1ODcsXCJyXCI6MTYzMDYxMjM5MzUyNjU3NjgwfSIsInMiOiIxZmRiN2RjMjY0MTgyYjhkIn0" target="_blank" rel="noopener">https://www.instagram.com/reel/DNPuMmOsQC0/?igsh=MTZpNmViaW8xNGl3</a></p>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/153566?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/153566?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F153566%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F153566%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_149256">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/149256/watch_times"
  data-youtube-player-video-id-value="c9CzNOszjxI"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/iwvb26ahoycyj4alyufus322n0hz" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/149256">
          Aug 11, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/149256">
            Microsoft Recall Is Still Saving Your Passwords?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week on The Awareness Angle, we’re digging into the UK’s Online Safety Act again, but this time looking at the hidden privacy risks of handing your most sensitive data to unregulated overseas firms. From facial scans to passport details, we ask whether the cure is worse than the disease.</p>
<p>We also unpack Microsoft Recall’s ongoing privacy failings, with tests still showing it can capture credit cards, passwords and other sensitive details, even with filters supposedly in place. And in Canada, the City of Hamilton’s $5M cyber insurance claim has been denied after skipping a basic security control, multi-factor authentication.</p>
<p>Elsewhere, scammers are faking endorsements with AI, the UK's Liberal Democrats want tighter vetting of YouTube ads, Google joins the list of Salesforce breach victims, and Pandora confirms a third-party attack. Plus, a staggering 6.8 million WhatsApp scam accounts taken down, and the strange world of North Korea’s undercover IT workforce.</p>
<p>And finally, Ant is getting ready for two LinkedIn Lives from the SANS Security Awareness Summit in Chicago, so if you can’t be there, you can still soak up the atmosphere from wherever you are.</p>
<p><strong>New Website Now Live!</strong></p>
<p>This week saw us launch our new website.  It's now easier than ever to view past episodes. You can also now sign up to become a member and buy Awareness Angle merchandise.  We've got new items coming to the store in the coming weeks, so keep your eyes peeled.  Check out the site at<span> </span><span class="ml-rte-link-wrapper"><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a></span></p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>





























<h2>SANS Security Awareness Summit - A Different Remote Experience</h2>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/DXUHmqQQaUoo70vv8FByGXMox1NXGQGW4k7IQYfl.jpg" width="540" onerror="this.style.display='none'"></span>






















<p><span class="ml-rte-link-wrapper"><a href="https://riskycreative.com/podcast/aj_king_on_phishing_present_bias_and_purple_cows" target="_blank" rel="noopener"></a></span><strong>🎙️ Live From Chicago...</strong></p>
<p>This week, Ant will be bringing the energy of the SANS Security Awareness Summit straight to you with two live LinkedIn broadcasts direct from the community area in Chicago.</p>
<p>On<span> </span><strong>Thursday, 14th August</strong><span> </span>and<span> </span><strong>Friday, 15th August</strong><span> </span>(12:15–13:30 Chicago time, 18:15–19:30 UK), he'll be chatting with awareness professionals, vendors and other attendees to capture the buzz of the summit. You can already watch the official talks online, but these lunchtime lives will give you the conversations, atmosphere and insights from the floor, including the bits you don’t usually see.</p>
<p>It’s a chance to meet some of the people driving change in the awareness space, hear what’s hot in the industry right now and maybe even spot some of our new podcast merchandise making their debut.</p>
<p><strong>Register for the live streams below:</strong></p>
<p><strong>Thursday's Event - <span class="ml-rte-link-wrapper"><a href="https://www.linkedin.com/events/7359692338895503361/" target="_blank" rel="noopener">https://www.linkedin.com/events/7359692338895503361/</a></span><br>Friday's Event - <span class="ml-rte-link-wrapper"><a href="https://www.linkedin.com/events/7359693582628196353/" target="_blank" rel="noopener">https://www.linkedin.com/events/7359693582628196353/</a></span><br></strong></p>






















<h2>Online Safety Act or Privacy Risk?</h2>
<p>Watch the discussion - <span class="ml-rte-link-wrapper"><a href="https://youtu.be/c9CzNOszjxI?t=248" target="_blank" rel="noopener">https://youtu.be/c9CzNOszjxI?t=248</a></span><span class="ml-rte-link-wrapper"></span></p>
<p>Under the UK’s new Online Safety Act, people now have to verify their age to use platforms like X, Reddit and Bluesky. That means millions are handing over biometric data, ID documents and even financial information to third-party companies outside the UK. Many of these firms have poor or unknown privacy track records, and some have ties to controversial figures or former intelligence officers.<br><br>Critics warn there’s no public oversight, no register of approved providers and no enforced privacy standards. The result is a system where your most sensitive data could end up in the hands of the cheapest bidder, stored in a country with weaker protections, with little way to know if it will ever be deleted. For most users, the choice is stark. Share the data or accept a censored internet.</p>
<p>A big thank you to Matt Gordon-Smith for messaging us and raising this point! Ant meant to give a shout-out in the episode but forgot!</p>
<p>Read more - <span class="ml-rte-link-wrapper"><a href="https://bylinetimes.com/2025/07/31/the-online-safety-act-is-forcing-brits-to-hand-over-personal-data-to-unregulated-overseas-corporations-with-questionable-privacy-records/" target="_blank" rel="noopener">https://bylinetimes.com/2025/07/31/the-online-safety-act-is-forcing-brits-to-hand-over-personal-data-to-unregulated-overseas-corporations-with-questionable-privacy-records/</a></span></p>
<p><strong>∠T</strong><strong>he Awareness Angle</strong></p>
<ul>
<li>
<strong>Privacy by Compulsion</strong><span> </span>– UK users are being forced to give facial scans, passport details and other sensitive data to unregulated foreign companies to access mainstream platforms.</li>
<li>
<p><strong>Trusting the Untrustworthy</strong><span> </span>– Some providers have a history of breaches or links to surveillance groups, with vague privacy policies that allow data reuse and AI training.</p>
</li>
<li>
<p><strong>No Real Oversight</strong><span> </span>– Without approved provider lists or mandatory standards, platforms can choose cost over safety when it comes to handling user data.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<h2>Microsoft Recall Still Spying on Your Screen</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/c9CzNOszjxI?t=587" target="_blank" rel="noopener">https://youtu.be/c9CzNOszjxI?t=587</a></p>
<p>Microsoft’s Recall feature on Copilot+ PCs is still capturing sensitive information, despite the company’s promises and new security filters. Tests by The Register showed that Recall can record credit card numbers, usernames and passwords if they appear on screen without obvious labels. Once saved, these screenshots can be accessed by anyone with the device’s PIN, even via remote access tools,  making it possible to bypass Microsoft’s security claims.</p>
<p>While Microsoft encrypts Recall data and ties access to Windows Hello, these measures are undermined by weak entry points like PIN access. Critics warn that the feature poses a significant privacy risk for everyday users, especially those in vulnerable situations. With Recall still in testing but expected to roll out widely, there are growing concerns it could quietly become the default on millions of devices before its flaws are fixed.</p>
<p>Read more - <span class="ml-rte-link-wrapper"><a href="https://www.theregister.com/2025/08/01/microsoft_recall_captures_credit_card_info/" target="_blank" rel="noopener">https://www.theregister.com/2025/08/01/microsoft_recall_captures_credit_card_info/</a></span></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Security Bypassed by Simplicity</strong><span> </span>– Encryption means little if someone can unlock Recall with just your PIN, locally or remotely.</li>
<li>
<p><strong>Sensitive Data Still Slipping Through</strong><span> </span>– Credit cards, passwords and other personal info are still being stored, showing Recall’s detection logic is far from reliable.</p>
</li>
<li>
<p><strong>Privacy Implications for Vulnerable Users</strong><span> </span>– Once captured, private moments and personal data are permanently logged with little control over what’s kept or shared.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<h2>No MFA, No Coverage: Hamilton’s Costly Cyber Mistake</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/c9CzNOszjxI?t=892" target="_blank" rel="noopener">https://youtu.be/c9CzNOszjxI?t=892</a></p>
<p>In 2024, the City of Hamilton was hit by a ransomware attack that paralysed 80% of its systems. Hackers demanded $18.5 million, which the city refused to pay. Recovery costs have since exceeded $20 million and will continue into 2026.</p>
<p>City officials expected their $5 million cyber insurance policy to soften the blow, but the claim was denied. The reason? Many departments had failed to implement multi-factor authentication (MFA), a requirement clearly stated in the policy. Staff resistance to MFA slowed its rollout, and the insurer cited the lack of it as a “root cause” of the breach. Despite the scale of the incident, no individuals have been held accountable, leaving residents to foot the bill.</p>
<p>Read more - <span class="ml-rte-link-wrapper"><a href="https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713" target="_blank" rel="noopener">https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713</a></span></p>
<p><span class="ml-rte-link-wrapper"></span><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>MFA Neglect Has Real Costs</strong><span> </span>– Ignoring a basic security control didn’t just make the attack possible. It also voided insurance coverage.</li>
<li>
<p><strong>Resistance to Security = Vulnerability</strong><span> </span>– Internal pushback left critical systems exposed, showing that security culture matters as much as technology.</p>
</li>
<li>
<p><strong>Accountability Gap</strong><span> </span>– Leadership indecision and lack of ownership can multiply the damage from cyber incidents, both operationally and financially.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>This Week's Discussion Points...</h2>
<p><strong></strong><strong></strong><strong>UK Online Safety Act, age verification &amp; privacy risks</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=238" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://bylinetimes.com/2025/07/31/the-online-safety-act-is-forcing-brits-to-hand-over-personal-data-to-unregulated-overseas-corporations-with-questionable-privacy-records/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Microsoft Recall still capturing sensitive data</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=595" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.theregister.com/2025/08/01/microsoft_recall_captures_credit_card_info/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>City of Hamilton ransomware &amp; MFA insurance refusal</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=881" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Proton launches free cross-platform authenticator app</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=1109" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bleepingcomputer.com/news/security/proton-launches-free-standalone-cross-platform-authenticator-app/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>“Ghost store” scams selling fake weight-loss treatments</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=1304" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://cybernews.com/cybercrime/online-ghost-stores-target-shoppers-with-weight-loss-treatment-scam/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Calls to vet YouTube ads like TV ads</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=1582" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bbc.co.uk/news/articles/ckge5xdwjx5o" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Google Salesforce breach via vishing, ShinyHunters</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=1851" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bleepingcomputer.com/news/security/google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Pandora cyberattack &amp; possible ShinyHunters link</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=2136" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.forbes.com/sites/daveywinder/2025/08/05/pandora-confirms-cyberattackwhat-you-need-to-know/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>WhatsApp deletes 6.8m scam accounts</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=2375" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bbc.co.uk/news/articles/ce35q2ly1w5o" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>North Korean IT workers funding regime</strong><br><strong><a href="https://youtu.be/c9CzNOszjxI?t=2532" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bbc.co.uk/news/articles/c15wk77zxngo" target="_blank" rel="noopener">Read</a></strong><a href="https://www.bbc.co.uk/news/articles/c15wk77zxngo" target="_blank" rel="noopener"><strong></strong></a></p>
<p><a href="https://vm.tiktok.com/ZNdHwxPn3" target="_blank" rel="noopener"><strong></strong></a></p>
<p><strong>📬 Subscribe to the Newsletter</strong></p>
<p></p>
<p><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">https://www.riskycreative.com</a></p>
<ul></ul>
<p><a href="https://www.instagram.com/reel/DH6DhqNorAj/?igsh=cm54OHh0dXVkMTh1" target="_blank" rel="noopener"></a></p>






















<h2>Instagram’s New Location Feature</h2>
<p>Watch - <span class="ml-rte-link-wrapper"><a href="https://youtu.be/c9CzNOszjxI?t=3872" target="_blank" rel="noopener">https://youtu.be/c9CzNOszjxI?t=3872</a></span></p>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/ubJFcJtNxAUUHg0bsuDxzJWirYiPo8Wmgbb7a88x.png" width="540" onerror="this.style.display='none'"></span>

























<p>Instagram has added a location-sharing feature in the inbox that can show your followers where you last posted from. If location permissions are on, this might be enabled by default.</p>
<p>That might sound harmless, but think about it! The people who follow you on Instagram aren’t always close friends. They could be old acquaintances, casual contacts, or even people you barely know. Do you really want all of them to know your current or recent location?</p>
<p><strong>How to switch it off</strong></p>
<ol>
<li>
<p>Open Instagram and go to your<span> </span><strong>Inbox</strong>.</p>
</li>
<li>
<p>Tap the<span> </span><strong>pin/Friends Map</strong><span> </span>banner above Notes.</p>
</li>
<li>
<p>Select<span> </span><strong>Location settings</strong>.</p>
</li>
<li>
<p>Turn off<span> </span><strong>Share location</strong><span> </span>and<span> </span><strong>Show on map</strong>. If you see<span> </span><strong>Visibility</strong>, set it to<span> </span><strong>No one</strong>.</p>
</li>
</ol>
<p>For extra privacy, you can also remove Instagram’s location permission in your phone’s settings.</p>
<p>⚠️ Some users report this feature may not be available in the UK or EU yet, but it’s worth checking so you’re ready if or when it arrives.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Assumed Trust</strong><span> </span>– Just because someone follows you on Instagram does not mean you want them to know where you are. Location sharing blurs the line between friendly connection and personal exposure.</li>
<li>
<p><strong>Default On, Default Risk</strong><span> </span>– If you have location permissions enabled, this feature may be switched on without you realising, making it easy to overshare.</p>
</li>
<li>
<p><strong>Check Before It Spreads</strong><span> </span>– Even if it is not live in your region yet, keep checking your settings so you will not be caught off guard when it rolls out.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>


























<h3>Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at<span> </span><span class="ml-rte-link-wrapper"><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></span>. We’re always learning, and your input helps shape future episodes.</h3>











</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/149256?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/149256?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F149256%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F149256%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_147608">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/147608/watch_times"
  data-youtube-player-video-id-value="J3qw0NvSTgc"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/wj65qotzxoaxd6h1ot7z1ffanu2d" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/147608">
          Aug 3, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/147608">
            Is the UK Online Safety Act Flawed?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week on<span> </span><em>The Awareness Angle</em>, we discuss the knock-on effects of the UK’s Online Safety Act, from free VPNs topping the app charts, to Sims characters and AI face-swapping being used to fool age checks. It’s a fascinating look at what happens when compliance meets real-world behaviour.</p>
<p>We also talk about a viral Reddit post where a new starter is facing the sack after failing phishing simulations that were so aggressive, they blurred the line between awareness and sabotage. And we run through<span> </span><em>four</em><span> </span>major breaches, Allianz Life, NASCAR, Orange France, and the city of St. Paul, all showing different shades of third-party risk and response failure.</p>
<p>Also: QR code suspicion, awareness tools with no sales pitch, intimate tech privacy leaks, and Ant’s ongoing confusion over his new bin schedule.</p>
<p>Plus, a quick plug, Ant will be heading to Chicago for the SANS Security Awareness Summit. If you're there or joining online, keep an eye out for the LinkedIn Lives.</p>
<p><strong>New Website Now Live!</strong></p>
<p>This week saw us launch our new website.  It's now easier than ever to view past episodes. You can also now sign up to become a member and buy Awareness Angle merchandise.  We've got new items coming to the store in the coming weeks so keep your eyes peeled.  Check out the site at<span> </span><span class="ml-rte-link-wrapper"><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a></span></p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>





























<h2>Magic, Mindset, and Metrics - Harley Sugarman on Rethinking Training<a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a>
</h2>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>






















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/mXlaqw9XbAN0dUMxU3uRBWW5mXZvAAdUcjqbkF5z.jpg" width="540" onerror="this.style.display='none'"></span>






















<p><span class="ml-rte-link-wrapper"><a href="https://riskycreative.com/podcast/aj_king_on_phishing_present_bias_and_purple_cows" target="_blank" rel="noopener"></a></span><strong>🎙️ Out Now On</strong><strong> The Awareness Angle Interviews!</strong></p>
<p>Security awareness is often full of smoke and mirrors, and not always in a good way.</p>
<p>In this episode, Ant chats with Harley Sugarman, founder of Anagram Security, about why traditional training falls flat, how bad metrics lead us astray, and what it really takes to change behaviour. They get into mindset shifts, nudge fatigue, and why calling people “risks” might be the worst move of all.</p>
<p>People’s journeys into security awareness are rarely straightforward, and Harley’s has a twist that makes his whole approach make sense (you’ll see what we mean).</p>
<p>If you want awareness that sticks (and maybe even amazes), don’t miss this one.</p>
<p>🎧 This episode is available at <span class="ml-rte-link-wrapper"><a href="https://riskycreative.com/supporters/video_embeds/146832" target="_blank" rel="noopener">https://riskycreative.com/supporters/video_embeds/146832</a></span>, and wherever you get your podcasts and on YouTube.</p>
<p><strong>Previous Episodes - </strong></p>
<p>To catch our previous episodes of The Awareness Angle Interviews - visit<span> </span><span class="ml-rte-link-wrapper"><a href="https://riskycreative.com/supporters/videos" target="_blank" rel="noopener">https://riskycreative.com/supporters/videos</a></span>. </p>
<p><span class="ml-rte-link-wrapper"><em>If you’ve got a story to tell, a lesson to share, or a perspective you think more people should hear, get in touch. We’d love to hear from you. Email us at<span> </span><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></em></span></p>





























<h2>VPN Chaos as UK Age Checks Go Live</h2>
<p>Watch the discussion - <span class="ml-rte-link-wrapper"><a href="https://youtu.be/J3qw0NvSTgc?t=188" target="_blank" rel="noopener">https://youtu.be/J3qw0NvSTgc?t=188</a></span></p>
<p>The UK’s Online Safety Act is now in force, requiring age verification for access to adult content. Predictably, VPN downloads have skyrocketed, with free apps topping the App Store charts. But experts warn these apps often come with serious risks, from shady data practices to outright malware.</p>
<p>The new law has triggered a wave of workarounds, from VPN use to AI-generated facial spoofing. Meanwhile, platforms like Spotify are threatening to delete accounts that fail to verify, and YouTube is testing AI that estimates your age based on your watch history.</p>
<p><strong>∠T</strong><strong>he Awareness Angle</strong></p>
<ul>
<li>
<strong>Free VPNs Are Risk Magnets</strong><span> </span>– Popular free VPNs are often insecure, ad-supported, or even malicious. And now they’re being used by kids.</li>
<li>
<p><strong>Tech Controls Are Being Bypassed</strong><span> </span>– AI facial spoofing, game characters, and loophole-sharing on social media show how quickly people find ways around policy.</p>
</li>
<li>
<p><strong>Compliance ≠ Safety</strong><span> </span>– Platforms risk promoting tools that undermine the very rules they’re trying to follow. Time to focus on real outcomes, not just box-ticking.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<p><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>






















<h2>Phishing Fail? You're Fired.</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/J3qw0NvSTgc?t=3308" target="_blank" rel="noopener">https://youtu.be/J3qw0NvSTgc?t=3308</a></p>
<p>A Reddit user shared their experience of joining a new company, only to be told months later that they were<span> </span><em>one phishing fail away from being terminated</em>. They’d already failed five, but the real issue? The tests were borderline unfair. They used real branding, copied genuine internal emails (like PTO requests), and were sent from legitimate-looking addresses. One arrived on their<span> </span><strong>first day</strong>. No warnings until failure number four. No support. No clarity. Just a countdown to being fired.</p>
<p>The user was new to MS Outlook had never even worked in a company that<span> </span><em>ran</em><span> </span>phishing simulations before. They were flagging genuine threats and excelling in their role otherwise, but that didn’t matter. They now live in fear of their inbox.</p>
<p>Read more - <span class="ml-rte-link-wrapper"><a href="https://www.reddit.com/r/cybersecurity/comments/1mbwp26/are_my_companys_phishing_tests_in_bad_faith_or_am/" target="_blank" rel="noopener">https://www.reddit.com/r/cybersecurity/comments/1mbwp26/are_my_companys_phishing_tests_in_bad_faith_or_am/</a></span></p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Is This Really What “Awareness” Looks Like</strong><span> </span>– If your phishing tests are causing fear, silence, or people gaming the system just to avoid punishment, your programme has failed, no matter what your dashboard says.</li>
<li>
<p><strong>Simulations Should Teach, Not Trap</strong><span> </span>– First-day tests? Mimicking HR processes with no prior context? That’s not training. That’s entrapment. Especially for new joiners who don’t yet know what “normal” looks like.</p>
</li>
<li>
<p><strong>You're Measuring Fear, Not Resilience</strong><span> </span>– You can scare people into compliance, but it doesn’t build better behaviour. It builds resentment, disengagement, and a toxic relationship with security.</p>
</li>
</ul>
<p><strong>Ant's Take - </strong></p>
<p>I'm not a fan of phishing simulations but they have their place.  I feel that while phishing simulations aren't the enemy, badly designed ones are. The goal isn’t to "catch people out." It’s to help them<span> </span><em>catch themselves</em><span> </span>before clicking next time.</p>
<p>As I said in this episode:</p>
<blockquote>
<p><strong>"Phishing simulations should support people — not entrap them."</strong><br><strong>"If your first experience at a company is being tricked by a phishing test on day one, something’s gone wrong."</strong></p>
</blockquote>
<p>We’re supposed to be building confidence and culture, not testing whether someone can read minds under pressure.</p>
<p>And it’s not just me. Simon Sinek is often quoted as saying,<span> </span><strong>“A culture is strong when people work with each other, for each other.”</strong><span> </span>I also hear<span> </span><em>Maxime Cartier</em><span> </span>from<span> </span><em>Hoxhunt</em><span> </span>speak often about the importance of psychological safety, and how fear-based training undermines it.</p>
<p>Fear doesn’t create better behaviour. It creates silence. It isolates people. And it makes security feel like a trap, not a support system.</p>
<p>If your programme relies on shame, secrecy, or silence, are you really managing risk or are you creating it.<a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>






















<h2>Four Breaches, One Theme?</h2>
<p>Watch the discussion -<span> </span><a href="https://youtu.be/J3qw0NvSTgc?t=1626" target="_blank" rel="noopener">https://youtu.be/J3qw0NvSTgc?t=1626</a></p>
<p>It’s been a rough week for security teams. Allianz Life, the city of St. Paul, NASCAR, and Orange France were all hit by serious breaches, exposing everything from Social Security numbers to city infrastructure.</p>
<ul>
<li>
<p><strong>Allianz Life</strong><span> </span>lost personal and financial data of most US customers. The entry point? A third-party CRM tool.</p>
</li>
<li>
<p><strong>St. Paul, Minnesota</strong><span> </span>was hit so hard by ransomware, the National Guard had to step in to restore city operations.</p>
</li>
<li>
<p><strong>NASCAR</strong><span> </span>was extorted for $4 million after attackers accessed contracts, ID documents, and health data via a third-party vendor.</p>
</li>
<li>
<p><strong>Orange France</strong><span> </span>confirmed attackers accessed customer contracts and ID info through an IT services provider.</p>
</li>
</ul>
<p><span class="ml-rte-link-wrapper"></span><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Third-Party Risk Isn’t Abstract</strong><span> </span>– Three of these breaches involved external systems or suppliers. If someone else has access to your data, their breach is your breach.</li>
<li>
<p><strong>It’s Not Just Data, It’s Disruption</strong><span> </span>– From payroll freezes to city-wide outages, the impact is more than reputational. Real people and services were affected.</p>
</li>
<li>
<p><strong>Basic Access Still Gets Exploited</strong><span> </span>– Weak passwords, slow detection, and social engineering continue to be the entry points. This is not advanced cyber-wizardry. It’s the same old doors left unlocked.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>Awareness Awareness</h2>
<p>🎤<span> </span><strong>SANS Security Awareness Summit – Ant’s Heading to Chicago</strong></p>
<p>The<span> </span><strong>SANS Security Awareness Summit</strong><span> </span>is happening<span> </span><strong>August 14–15</strong>, live in Chicago and online, and<span> </span><strong>Ant will be there in person</strong>, learning, and livestreaming bits of it from the floor.</p>
<p>Expect a couple of <strong>LinkedIn Lives</strong>, some behind-the-scenes moments, and maybe a few chats with awareness pros as they come out of sessions. If you’re joining online, definitely hop into the SANS Slack, the conversation there is always lively.</p>
<p>This summit is one of the best for anyone working on the human side of security. It’s all about behaviour, culture, and communication, not just policy and platforms.</p>
<p>🔗<span> </span><a href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2025" target="_blank" rel="noopener">Check out the Summit</a></p>
<p><strong>SebDB 4.0 is live</strong><br>Oz Alashe announced the latest CybSafe update to their Security Behaviour Database, now aligned to MITRE, NIST, and more. It’s open-source, and free to use.<br>🔗<span> </span><a href="https://www.linkedin.com/posts/activity-7356245997703888896-fbQr" target="_blank" rel="noopener">See the announcement</a></p>
<p><strong>A Free Maturity Model That Doesn’t Sell You Stuff</strong><br>Jason Hoenich’s new tool at<span> </span><a href="https://humanrisk.com/" target="_blank" rel="noopener">humanrisk.com</a><span> </span>gives you a benchmark across strategy, engagement, assessment, and training.  The best part is that there is no sales pitch attached (but you can reach out to Jason for guidance and support if you wish!!)<br>🔗<span> </span><a href="https://humanrisk.com/" target="_blank" rel="noopener">Try it now</a></p>
<p>FYI - Jason has made a bunch of updates since we recorded this, so it will have only gotten better!</p>
<p>🧪<span> </span><strong>Fable Comes Out of Stealth</strong><br>There’s a new human risk startup on the scene.<span> </span><strong>Fable Security</strong><span> </span>just launched publicly, with big investment and even bigger promises around "agentic AI" for behaviour change. Think bite-sized nudges, deepfake detection, and phishing defence, all delivered with a sleek interface and some very polished branding.</p>
<p>It’s early days, but the pitch is bold: smarter, scalable human risk intervention with less noise and more action. We’ll be keeping an eye on it to see how it stands out in a rapidly growing space.</p>
<p>🔗<span> </span><a href="https://www.fablesecurity.com/" target="_blank" rel="noopener">Check out Fable</a><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>






















<h2>This Week's Discussion Points...</h2>
<p><strong>VPN Use Surges After UK Age Checks</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=188" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.biometricupdate.com/202507/uk-age-verification-is-here-ofcom-set-to-begin-enforcing-online-safety-act" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Labour Rules Out VPN Ban, Warns Households</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=333" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.birminghammail.co.uk/news/uk-news/labour-rules-out-vpn-ban-uk-29356342" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Loopholes Used to Bypass Online Safety Act</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=537" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.thetab.com/uk/2025/07/25/online-safety-act-loopholes-viral-videos-359432" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Spotify Threatens to Delete Unverified Accounts</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=670" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.reddit.com/r/technology/comments/1mdbhuw/spotify_threatens_to_delete_accounts_that_fail" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>YouTube Using AI to Guess Your Age</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=968" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.techspot.com/news/101808-youtube-using-ai-guess-age-based-your-watch.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Google AI Search Launches in UK</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=1046" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/articles/cd1e7z3z0g5o" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Lovense App Flaw Leaks User Emails</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=1290" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/lovense-app-flaws-exposed-user-email-addresses-allowed-account-takeovers" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Microsoft Edge Adds ‘Copilot Mode’ AI Assistant</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=1428" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://techcrunch.com/2025/07/29/microsoft-edge-copilot-mode-ai" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Allianz Life Breach – Personal Data Stolen</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=1625" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://techcrunch.com/2025/07/26/allianz-life-says-majority-of-customers-personal-data-stolen-in-cyberattack" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>City of St. Paul Hit by Ransomware, National Guard Deployed</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=1768" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://arstechnica.com/security/2025/07/st-paul-mn-was-hacked-so-badly-that-the-national-guard-has-been-deployed" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>NASCAR Data Breach – $4M Ransom Demanded</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=1973" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.comparitech.com/news/nascar-notifies-data-breach-victims-after-cybercriminals-demand-4-million-ransom" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Orange France Cyberattack via IT Supplier</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=2131" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://therecord.media/orange-telecom-france-cyberattack" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Reddit Story – Harsh Phishing Test Penalties</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=3308" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.reddit.com/r/cybersecurity/s/NApyoaMjfF" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Hertfordshire Bin Chaos</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=3669" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/articles/cx2gx28815wo" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>TikTok Clip – Hidden Messages in Birdsong</strong><br><a href="https://youtu.be/J3qw0NvSTgc?t=3880" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNdHwxPn3" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>📬 Subscribe to the Newsletter</strong></p>
<p><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">https://www.riskycreative.com</a><a href="https://www.instagram.com/reel/DH6DhqNorAj/?igsh=cm54OHh0dXVkMTh1" target="_blank" rel="noopener"></a></p>
<ul></ul>






















<h2>Bin Watch 2025</h2>
<p>Watch - <span class="ml-rte-link-wrapper"><a href="https://youtu.be/J3qw0NvSTgc?t=3647" target="_blank" rel="noopener">https://youtu.be/J3qw0NvSTgc?t=3647</a></span><a href="https://securityonline.info/cve-2025-1240-winzip-vulnerability-opens-door-to-remote-code-execution/" target="_blank" rel="noopener"></a></p>

























<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/Itq8ZOkVeLh6F3G4TIgEbuGaancEASZSjhC2T1Jq.png" width="540" onerror="this.style.display='none'"></span>

























<p>Ant recently found himself navigating a new local bin system. Five bins. Three different collection cycles. Two separate letters from the council, each giving different instructions. </p>
<p>It’s a small thing, but it stuck with him, because it’s exactly what happens when security controls get too complex.</p>
<p>If people don’t know what’s expected, or the rules keep changing, they don’t follow the system, they work around it. Not out of laziness, but survival. They’re just trying not to get it wrong.</p>
<p>In awareness, we talk a lot about risk, but<span> </span><strong>confusion is its own kind of risk</strong>. If your policies feel like bin day maths, don’t be surprised when people stop engaging with them.</p>
<p>Simplicity isn’t a shortcut. It’s the strategy.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Complexity Kills Compliance</strong><span> </span>– When people can’t understand or remember the rules, they stop following them. Confusion creates risk, even if your policy is technically sound.</li>
<li>
<p><strong>Intent Doesn’t Equal Clarity</strong><span> </span>– Just because you’ve communicated something doesn’t mean it landed. Conflicting instructions, like conflicting security messages, erode trust fast.</p>
</li>
<li>
<p><strong>Simplicity Builds Behaviour</strong><span> </span>– Clear, consistent guidance makes it easier for people to do the right thing. If security is intuitive, people won’t need a calendar, chart, or cheat sheet to follow it.</p>
</li>
</ul>
<ul></ul>
<ul></ul>


























<h3>Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at<span> </span><span class="ml-rte-link-wrapper"><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></span>. We’re always learning, and your input helps shape future episodes.</h3>











</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/147608?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/147608?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F147608%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F147608%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_147088">
    <div class="post" access="public">
  <div class="post__inner">
    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/posts/147088">
          Aug 1, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/posts/147088">
            Chicago, We’re Coming In Hot!
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;">In two weeks, I’ll be heading to the SANS Security Awareness Summit in Chicago, and I’m bringing The Awareness Angle with me.</p>
<p style="font:12.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;min-height:13.8px;"><span style="font-family:'Times New Roman';font-size:12.00px;font-style:normal;font-weight:normal;"></span></p>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;"><span style="font-family:'Times New Roman';font-size:20.00px;font-style:normal;font-weight:normal;">I’ll be doing two live streams from the event, plus recording a special episode of the podcast with Luke while I’m there. Expect real-time reactions, honest takes, and plenty of behind-the-scenes moments from one of the biggest events in the awareness calendar.</span></p>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;"><span style="font-family:'Times New Roman';font-size:20.00px;font-style:normal;font-weight:normal;"></span></p>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;"><span style="font-family:'Times New Roman';font-size:20.00px;font-style:normal;font-weight:normal;">Ill be catching up with some familiar faces in the awareness industry, founders, leaders and other pros finding out their thoughts of the event and getting some great insights.</span></p>
<p style="font:12.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;min-height:13.8px;"><span style="font-family:'Times New Roman';font-size:12.00px;font-style:normal;font-weight:normal;"></span></p>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;"><span style="font-family:'Times New Roman';font-size:20.00px;font-style:normal;font-weight:normal;">Stream are planned for Thursday 14th and Friday 15th. Keep an eye out for stream times and podcast drops. It’s going to be a good one.<br><br></span></p>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;"><span style="font-family:'Times New Roman';font-size:20.00px;font-style:normal;font-weight:normal;">See you stateside!</span></p>
<p style="font:20.0px 'Times New Roman';margin:0.0px 0.0px 12.0px 0.0px;"><span style="font-family:'Times New Roman';font-size:20.00px;font-style:normal;font-weight:normal;">Ant</span></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/posts/147088?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/posts/147088?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fposts%2F147088%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fposts%2F147088%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146832">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146832/watch_times"
  data-youtube-player-video-id-value="hZL97cdULZs"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/y4rxnzhxaf16vkd6tkrn8eszfzu7" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146832">
          Jul 31, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146832">
            Magic, Mindset, and Metrics – Harley Sugarman from Anagram Security
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>When it comes to security awareness, most tools are solving the wrong problem. That’s the starting point for this conversation with Harley Sugarman, founder of Anagram Security – and from there, we go deep.</p>
<p>Harley’s background isn’t your typical cybersecurity CV. Before launching Anagram, he worked in engineering and security, often wondering why awareness was treated as an afterthought. Despite being labelled the biggest risk in most organisations, people rarely get the investment or attention they deserve. And training? Too often it’s just a compliance box ticked once a year.</p>
<p>In this episode, Harley talks about how that disconnect pushed him to start building something different. Something that treats behaviour change as a core goal – not a side effect. Anagram’s approach? Short, engaging content, interactive puzzles, and mindset shifts that help people<span> </span><em>think</em><span> </span>like attackers. The result is more than knowledge. It’s habit-building.</p>
<p>We dig into:</p>
<ul>
<li>
<p>Why phishing click rates can be gamed – and why they don’t tell the full story</p>
</li>
<li>
<p>What makes a good “nudge” (and what just becomes noise)</p>
</li>
<li>
<p>How AI could enable contextual, real-time awareness – if used right</p>
</li>
<li>
<p>The real reason security awareness gets such a small slice of the budget</p>
</li>
<li>
<p>And why vague compliance standards might actually be a hidden opportunity</p>
</li>
</ul>
<p>One of the most interesting parts of the conversation is around metrics. We’ve all been asked to prove impact. But most of the metrics we rely on – completions, clicks, reports – are poor proxies for real behaviour. Harley argues that many CISOs already<span> </span><em>know</em><span> </span>who their riskiest users are. The challenge is moving from identification to actual change. And doing it in a way that feels human, not punishing.</p>
<p>There’s also a brilliant moment where Harley talks about how much of today’s awareness training would be considered totally unacceptable in a classroom. If we taught children the way we teach adults about cyber, there’d be protests. He’s not wrong.</p>
<p>Oh, and somewhere in the second half of the episode, there’s a small detail about Harley’s earlier career that explains a lot about how he sees behaviour, storytelling, and audience engagement. Let’s just say it involves a certain flair for the unexpected. You’ll spot it when it comes.</p>
<p>Whether you work in security awareness, lead a team, or are just trying to make your organisation care a bit more about human risk, this episode offers a refreshing take on what’s possible – and a reminder that we can do better than "click here to complete your annual training."</p>
<p><strong>Listen now</strong><span> </span>and start thinking about what your awareness programme could be if you reimagined it from the ground up.</p>
<p>You can find Harley at<span> </span><a href="https://anagramsecurity.com/" target="_blank" rel="noopener">anagramsecurity.com</a><span> </span>or connect with him on<span> </span><a href="https://www.linkedin.com/in/harleysugarman" target="_blank" rel="noopener">LinkedIn</a>.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146832?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146832?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146832%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146832%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146119">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146119/watch_times"
  data-youtube-player-video-id-value="bYMm9NsSHNQ"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/0yfq9yhpqudhq8phrsnl74rs6l22" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146119">
          Jul 28, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146119">
            Hackers Asked for a Password... and Got It?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>Episode 43</strong></p>
<p>This week’s cybersecurity stories aren’t about elite hackers or advanced tools. They’re about people making very human mistakes. A helpdesk that handed over access without checking. A single weak password that brought down a century-old company. A startup selling stolen data like it’s just another subscription service. And tech giants pushing privacy boundaries in the name of progress.</p>
<p>Let’s start with Clorox. They’ve filed a lawsuit after being breached by the Scattered Spider hacking group. The attackers didn’t use malware. They didn’t exploit a vulnerability. They just called the helpdesk and asked for a password reset. That was it. According to the court documents, the support agent said, “Let me provide a password to you,” and handed it over. The result was $380 million in damages. Product shelves sat empty, systems were disrupted, and everything ground to a halt. It’s a perfect example of how dangerous it can be when frontline teams aren’t supported with the right training or processes. Social engineering is alive and well, and it’s often as easy as picking up the phone.</p>
<p>Then there’s the story of KNP Logistics, a UK transport company that had been operating for over 150 years. It shut down after ransomware hit their systems. The attackers got in using a single weak employee password. Once inside, they encrypted everything and demanded a ransom the company couldn’t pay. Hundreds of jobs were lost. The director said he knows whose account was used but hasn’t told them. And honestly, what good would it do? The damage was already done. These aren’t hypothetical risks. This is what a single password can cost.</p>
<p>Meanwhile, a US startup called Farnsworth Intelligence is selling data stolen from infected machines. Through their site, anyone can pay fifty dollars to search through browser autofill data, login credentials, and saved passwords. It’s marketed as “open-source intelligence” for debt collectors and investigators, but there are no real checks. This isn’t public data. It’s the result of infostealer malware pulling private information straight from people’s devices. If your system has ever been compromised, your data could be in there. No dark web, no hidden forums. Just a clean, modern website and a checkout page.</p>
<p>On the tech front, Microsoft is pushing forward with Copilot Vision. It’s a new feature in Windows 11 that takes continuous screenshots of your screen and sends them to Microsoft servers for AI processing. It’s opt-in, they say. It’s not used for advertising, they say. But the idea of your screen being watched in real time doesn’t sit well with many users. Especially in a business setting, where sensitive information is always at risk. For anyone with a bring-your-own-device policy, this could quietly introduce a serious problem.</p>
<p>Old software is also in the spotlight. Microsoft’s older, on-premise versions of SharePoint are being actively targeted after a flawed patch left them vulnerable. The exploit had already been shown publicly, yet many organisations remained exposed. Some even applied the patch and still got hit. This is what happens when patching is treated as a checkbox instead of a process. Older systems are harder to manage and often get ignored, but that just makes them more attractive to attackers.</p>
<p>And while the future is meant to be passwordless, passkeys still aren’t delivering the seamless experience they promise. Users are running into vague error messages, mismatched devices, and confusing prompts. Recovery is a nightmare if you change or lose your device. Until companies like Google and Apple improve the user experience, passkeys will remain a source of frustration. And when people get locked out of their accounts, it’s the IT teams who have to clean up the mess.</p>
<p>Put all these stories together and you see the same pattern. The biggest risks aren’t coming from some shadowy cybercrime syndicate. They’re coming from poor password practices, rushed technology rollouts, and simple, preventable human errors. A phone call. A missed patch. A forgotten process. That’s all it takes. And if you work in cybersecurity, these stories should be more than headlines. They’re warnings.</p>
<p></p>
<p><strong>US Startup Sells Stolen Data for $50</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=293" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.pcworld.com/article/2854343/a-u-s-startup-is-selling-your-hacked-stolen-data-to-anyone-with-50.html" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Weak Password Sinks 158-Year-Old Company</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=523" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bbc.co.uk/news/articles/cx2gx28815wo" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Clorox Hackers Got In Just by Asking</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=833" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.nbcnews.com/business/business-news/lawsuit-says-clorox-hackers-got-passwords-simply-asking-rcna220313" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Hackers Exploit Old SharePoint Patch</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=1140" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.wired.com/story/microsoft-sharepoint-hack-china-end-of-life-updates/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Copilot Vision Watches Your Screen</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=1378" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.computing.co.uk/news/2025/ai/windows-11s-copilot-vision-watches-your-screen-in-real-time" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Passkeys Still a Mess for Users</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=1577" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.zdnet.com/article/passkeys-wont-be-ready-for-primetime-until-google-and-other-companies-fix-this/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>UK Age Verification Now Enforced</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=1880" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.biometricupdate.com/202507/uk-age-verification-is-here-ofcom-set-to-begin-enforcing-online-safety-act" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>AI Tool Deletes Company Database</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=2063" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>The Login Alliance Rant (ft. Lance Spitzner)</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=2480" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.linkedin.com/posts/lancespitzner_securityculture-securityawareness-passwordmanagers-activity-7353438636656209920-Ry5C?utm_source=share&amp;utm_medium=member_ios&amp;rcm=ACoAABFpm9kBai-lb9afNEVVo9TlxsPHJv7qgik" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Reddit is Running Malware Ads</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=2763" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.reddit.com/r/cybersecurity/s/FDqmu0eJAF" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>QR Code Link Switched to an Ad</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=2974" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.reddit.com/r/techsupport/s/yJRKbzuPsA" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Scammer Uses Netstat Scam with ISP Ruse</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=3131" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.reddit.com/r/techsupport/s/Ke21m9deHx" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Voting Email from East Herts Council</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=3297" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><em>(No external source)</em></p>
<p><strong>Scout Leader’s Email Compromised</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=3510" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><em>(No external source)</em></p>
<p><strong>Luggage Tags Could Expose Your Info</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=3615" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://vm.tiktok.com/ZNdurr7XJ/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Jason Street Finds… Fake IDs</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=3710" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.linkedin.com/posts/jstreet_rememberthekittens-activity-7353834794763390978-oxO1?utm_source=share&amp;utm_medium=member_android&amp;rcm=ACoAAC2r9I4BBjRoYMjPtC3A2t3ZmU1ciMTn5uM" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Did Ring Get Hacked or Was It Just a Bug?</strong><br><strong><a href="https://youtu.be/bYMm9NsSHNQ?t=3882" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.facebook.com/ring/posts/pfbid035K35t5tYBDisTyAz32uZhNhYPith1WT31XgbU7UZsEZWCfYaL8AMikztRqPwKYFVl/" target="_blank" rel="noopener">Read</a></strong></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146119?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146119?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146119%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146119%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_145972">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/145972/watch_times"
  data-youtube-player-video-id-value="gTfEUDny_es"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/03w0vdonecab32nv4sinwywsdt5u" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/145972">
          Jul 21, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/145972">
            Why Was an Elevator Held Hostage by Windows?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This episode is packed with privacy fails, phishing scams, and one very unfortunate elevator ride. We kick things off with Fitify, a fitness app that left over 370,000 files exposed online, including 138,000 user progress pics and body scans. These were stored in an unprotected Google Cloud bucket and were accessible to anyone with a link. Many of the images were uploaded for Fitify’s AI coach, often featuring users in minimal clothing. It’s a sharp reminder that encryption in transit isn’t the same as being safe at rest. Hardcoded secrets in code can open up serious risks. Users trusted the app with personal data, and it let them down.</p>
<p>Then we talked about WeTransfer’s AI terms-of-service drama. After a wave of backlash from creatives, the company clarified that it wouldn’t use files to train AI models, just to help moderate harmful content. It’s a lesson in clear language, user trust, and why reviewing the fine print still matters. CapCut and Dropbox have faced similar scrutiny. Everyone’s watching where their data might end up next.</p>
<p>From there we moved into national security. A breach by Salt Typhoon forced US military networks to assume they were fully compromised. The espionage group reportedly accessed conversations from senior officials and spent nearly a year inside the National Guard’s systems. If Zero Trust wasn’t on your radar before, it should be now.</p>
<p>Closer to home, Reddit rolled out age verification in the UK ahead of new Online Safety Act rules. Users now have to upload selfies or government ID to access adult content, verified by a third-party firm called Persona. While it’s meant to protect kids, it raises fresh questions around online anonymity, privacy trade-offs, and whether VPNs will simply sidestep it all.</p>
<p>Pet owners weren’t spared either. Thousands received fake microchip renewal emails, even though microchips don’t expire. The scam messages were personalised, using real chip numbers, breeds, and names. Some pet databases allow you to search details without any real rate-limiting or security checks, meaning attackers could scrape info in bulk. This one blends phishing, poor platform security, and good old-fashioned oversharing.</p>
<p>In India, police raided a tech support scam call centre after an 18-month joint investigation with the NCA, FBI, and Microsoft. The centre had duped UK victims out of hundreds of thousands of pounds by using fake virus pop-ups and impersonating Microsoft. These scams are global, evolving, and still preying on fear.</p>
<p>We also discussed the UK data breach that forced a secret Afghan relocation scheme. Nearly 19,000 people had their details leaked when a British official emailed a sensitive file to the wrong recipients. So far, over 4,500 have been relocated under a programme that was kept quiet until a High Court judge lifted the super injunction. It’s one of the most extreme examples of real-world harm from a simple mistake, and a wake-up call for better systems that don’t rely on human perfection.</p>
<p>Louis Vuitton confirmed that UK customer data had been stolen in a cyberattack. No financial info was taken, but names, emails, and purchase history were. That’s more than enough for phishing. With similar breaches in their Korean, Italian, and Swedish operations, this seems to be a coordinated campaign, likely tied to the ShinyHunters group behind the Ticketmaster and Santander breaches.</p>
<p>We wrapped up with a few wildcards. A lift stuck mid-ride because of a Windows update, and a reminder that some companies are putting critical infrastructure on connected touchscreens. Not ideal. And finally, Luke brought a phishing scam that used white-on-white text to trick Google Gemini into producing fake warnings. Simple trick, big risk. AI tools are powerful, but they still fall for very old-school tactics.</p>
<p>This week’s Awareness Awareness focused on new hire phishing stats from Keepnet. New starters are 44 percent more likely to fall for phishing attempts, especially in their first 90 days. If you don’t show people what normal looks like when they join, they’re left guessing, and that’s a risky game.<br><br></p>
<p><strong>Fitify Leaks 138K Progress Photos</strong><br><a href="https://youtu.be/gTfEUDny_es?t=214" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://cybernews.com/security/fitify-app-data-leak-user-photos-exposed/" target="_blank" rel="noopener">Read</a></p>
<p><strong>WeTransfer AI Terms Backlash and Retraction</strong><br><a href="https://youtu.be/gTfEUDny_es?t=541" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.theregister.com/2025/07/18/llm_products_terms_of_service/" target="_blank" rel="noopener">Read</a></p>
<p><strong>US Military Told to Assume Network Compromise</strong><br><a href="https://youtu.be/gTfEUDny_es?t=872" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.itpro.com/security/us-military-cybersecurity-breach-salt-typhoon" target="_blank" rel="noopener">Read</a></p>
<p><strong>Reddit Introduces Age Verification in the UK</strong><br><a href="https://youtu.be/gTfEUDny_es?t=1062" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/technology-68814579" target="_blank" rel="noopener">Read</a></p>
<p><strong>Fake Pet Microchip Renewal Scams Target UK Owners</strong><br><a href="https://youtu.be/gTfEUDny_es?t=1554" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.pentestpartners.com/security-blog/uk-pet-owners-targeted-by-microchip-renewal-scams/" target="_blank" rel="noopener">Read</a></p>
<p><strong>Indian Police Raid Tech Support Scam Call Centre</strong><br><a href="https://youtu.be/gTfEUDny_es?t=1893" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.infosecurity-magazine.com/news/indian-police-raid-tech-support/" target="_blank" rel="noopener">Read</a></p>
<p><strong>Secret Afghan Relocation Scheme After MoD Breach</strong><br><a href="https://youtu.be/gTfEUDny_es?t=2303" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/uk-politics-68816498" target="_blank" rel="noopener">Read</a></p>
<p><strong>Louis Vuitton Customer Data Breach</strong><br><a href="https://youtu.be/gTfEUDny_es?t=2684" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.securityweek.com/louis-vuitton-data-breach-hits-customers-in-several-countries/" target="_blank" rel="noopener">Read</a></p>
<p><strong>New Hires More Likely to Fall for Phishing (Keepnet Report)</strong><br><a href="https://youtu.be/gTfEUDny_es?t=2882" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://keepnetlabs.com/resources/reports/new-hires-phishing-susceptibility-2025" target="_blank" rel="noopener">Read</a></p>
<p><strong>Experiences of Victims of Cybercrime (Shared by Listener Boris)</strong><br><a href="https://youtu.be/gTfEUDny_es?t=3200" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.gov.uk/government/publications/experiences-of-victims-of-fraud-and-cyber-crime" target="_blank" rel="noopener">Read</a></p>
<p><strong>Anti-Phishing Training Might Be Making Things Worse</strong><br><a href="https://youtu.be/gTfEUDny_es?t=3510" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.pcmag.com/news/your-companys-anti-phishing-training-might-be-making-things-worse" target="_blank" rel="noopener">Read</a></p>
<p><strong>Windows Update Traps Someone in a Lift</strong><br><a href="https://youtu.be/gTfEUDny_es?t=3783" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.reddit.com/r/mildlyinfuriating/comments/1d67e3a/my_building_spent_all_year_redoing_the_elevators/" target="_blank" rel="noopener">Read</a></p>
<p><strong>Google Gemini Phishing Risk Discovered (Luke’s Topic)</strong><br><a href="https://youtu.be/gTfEUDny_es?t=4395" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNdaCGjBe" target="_blank" rel="noopener">Read</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

          <span class="post-actions__item-number">
            1
          </span>
    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/145972?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/145972?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F145972%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F145972%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame></template></turbo-stream>

<turbo-stream action="remove" target="posts_load_more"></turbo-stream>

  <turbo-stream action="append" target="posts_list"><template><turbo-frame id="posts_load_more">
  <a data-turbo-stream="true" data-controller="infinite-scroll" href="/supporters/load_more?last_id=145972&amp;last_live_at=2025-07-21T11%3A06%3A00.000%2B00%3A00&amp;order=desc"></a>
  <div class="loader">
  <svg class="loader__icon" viewBox="0 0 100 100">
    <circle class="loader__circle" cx="50" cy="50" r="45" />
  </svg>
</div>
</turbo-frame>
</template></turbo-stream>
