**Zoë Rose** (0:03)
We need an LLM that says here's how to do it, and don't forget to consider these things.
**Graham Cluley** (0:09)
No, we don't need that, actually, Zoe. We don't need any help for the criminals in covering up the tracks. Interesting, interesting that you should suggest that.
**SPEAKER_3** (0:27)
Smashing Security, episode 475, JadePuffer, the AI that ran a ransomware attack all by itself, with Graham Cluley and special guest, Zoë Rose.
**Graham Cluley** (0:39)
Hello, hello, and welcome to Smashing Security, episode 475, my name's Graham Cluley.
**Zoë Rose** (0:43)
And I'm Zoë Rose.
**Graham Cluley** (0:45)
Hello, Zoë, welcome back to the show. It's been a while since you've been on, how are you doing?
**Zoë Rose** (0:50)
Well, usually when I join, something massive has happened.
**Graham Cluley** (0:54)
Right.
**Zoë Rose** (0:54)
At the moment, I have not acquired another child or a pet.
**Graham Cluley** (0:58)
So well done.
**Zoë Rose** (1:00)
Yeah.
**Graham Cluley** (1:00)
So for those who don't know, Zoë, what are you? I mean, people who haven't heard of you before, what do you do exactly?
**Zoë Rose** (1:07)
That's a good question.
What do I do? I work in security and pretend I know what I'm talking about half the time.
**Graham Cluley** (1:15)
Okay. It seems fair enough. And you work for a big company.
**Zoë Rose** (1:19)
I have a bloody long title now actually. That's the change. That's what's new. My title has massively increased.
**Graham Cluley** (1:25)
Give us your title. Let's hear it.
**Zoë Rose** (1:27)
All right. It is CSERT, which if you know what that sounds like, it has more words, but we'll just stick to some letters. Security Operations Development Manager.
**Graham Cluley** (1:36)
Wow. Security Operations Development Manager, like SODM is basically what you're saying.
**Zoë Rose** (1:42)
Yeah, sure.
**Graham Cluley** (1:44)
Interesting. Well, before we kick off, let's thank this week's wonderful sponsors, Arctic Wolf, NordLayer and Vanta. We'll be hearing more about them later on in the podcast.
**Zoë Rose** (1:56)
This week on Smashing Security.
**Graham Cluley** (1:58)
We're not going to be talking about how a Greek politician investigating spyware had his own mobile phone hacked. You'll hear no discussion of how a US Department of Homeland Security information sharing database has been accessed by hackers. And we won't even mention how hackers are using a fake World Cup T-shirt offer to spread malware.
So, Zoë, what are you going to be talking about this week?
**Zoë Rose** (2:27)
I'm going to talk about Apple's Hide My Email isn't actually as hidden as it sounds like.
**Graham Cluley** (2:33)
And I'm going to be telling the tale of how a 15-year-old with a chatbot became a cyber criminal and what happens when the AI just does the whole job itself. All this and much more coming up on this episode of Smashing Security.
**Joe** (2:51)
Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?
**Graham Cluley** (2:55)
You are right, Jo. They've just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analyzed over 800,000 real IT assets to find out how exposed organizations actually are.
**Joe** (3:11)
And? I'm guessing everything is hunky-dory?
**Graham Cluley** (3:14)
No, not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.
**Joe** (3:22)
1 in 3? That's terrible.
**Graham Cluley** (3:24)
Isn't it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.
**Joe** (3:34)
So the tools don't even know those assets exist?
**Graham Cluley** (3:37)
Right, ghost assets wandering around your network, unprotected, unmonitored.
**Joe** (3:43)
Like a retired geography teacher who's somehow still on the school network. Nobody added him, nobody removed him and he's been quietly in there for 11 years downloading maps of Paraguay.
**Graham Cluley** (3:54)
Yeah, yeah, I guess so, Joe, but the point is, your attackers will find him before you do because they are specifically looking for the forgotten, the unpatched, the invisible. That's the path of least resistance.
**Joe** (4:09)
So what does the report tell us to actually do about it?
**Graham Cluley** (4:12)
Arctic Wolf's report covers how to prioritize the exposures that actually matter, cut through all that noise and verify that when you fix something, it actually stays fixed and the report is free to download.
**Joe** (4:24)
Free. I like that. Where do I get it?
**Graham Cluley** (4:27)
smashingsecurity.com/arcticwolf.
**Joe** (4:30)
That's smashingsecurity.com/arcticwolf. And thanks to Arctic Wolf for supporting the show. And please keep an eye on your IT assets and retired geography teachers.
38 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000775846352