This job interview could destroy your company artwork

This job interview could destroy your company

Smashing Security

July 29, 2026

You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist.
Speakers: Graham Cluley, Paul Ducklin, Joe
**Graham Cluley** (0:03)
I was in a car park, and I found my car, at least what I thought was my car.
And I thought, why isn't my key working? And I tried the door, and it was only when I saw how clean the car was that I realized it couldn't possibly be mine.

**Paul Ducklin** (0:19)
You looked in the back, and there were no food wrappers and discarded cardboard boxes from three weeks ago. How dare you?

**Graham Cluley** (0:27)
I don't know if I'm getting a little bit old.

**SPEAKER_3** (0:38)
Smashing Security, Episode 478 This job interview could destroy your company, with Graham Cluley and special guest Paul Ducklin.

**Graham Cluley** (0:47)
Hello, hello, and welcome to Smashing Security Episode 478 My name is Graham Cluley.

**Paul Ducklin** (0:52)
And my name is Paul Ducklin.

**Graham Cluley** (0:54)
Duck, welcome back to the show.

**Paul Ducklin** (0:56)
Thank you very much, Graham. Pleasure to be back.

**Graham Cluley** (0:59)
There's been big news, actually, on the cyber security front since our last episode.

**Paul Ducklin** (1:04)
I can't think what you're talking about, Graeme. What could it be?

**Graham Cluley** (1:08)
Unfortunately, due to the schedule of Smashing Security, we recorded last week's episode just before the whole OpenAI going rogue, attacking Hugging Face, the story which made a thousand headlines.

**Paul Ducklin** (1:21)
Now you know how Microsoft feels when Nightmare Eclipse establishes an exploit minutes after Patch Tuesday is dropped.

**Graham Cluley** (1:28)
We're not going to talk about this very much because frankly, everyone else has spoken about it. I've blogged about it. It feels like old hat by the time this episode comes out, but people are asking, is this the end of the world as we know it? But some people have also thought that maybe there's a bit of hype around this. Maybe it's working to the advantage of the AI company's PR machine. Have you seen anything like that?

**Paul Ducklin** (1:48)
We do seem to have had that quite a few times recently with these AI companies, haven't we? Wasn't it anthropic? But said, oh, we've got this product. It's so dangerous. We can't release it. And then when the government turned around in the US and said, okay, we are going to regulate it. It's like, what? You're going to regulate it? But we're libertarians. If there's any regulation to be done, we'll do it. How dare you? You said, well, you spent ages hyping up how dangerous it was because it's so clever. You can't have it both ways. But you're right, Graham. I think there have been at least a few people who have been somewhat cynical about this. So may I read you a post that I saw from a chap in Cambridge, UK, by the name of Graham Bell?
Now, I don't necessarily agree with all of this, just to make it clear. But by golly, I laughed so hard.
And here is what he wrote, Graham. So it turns out that if you train an AI model on hacking, and then you train it on sci-fi stories about AIs being total dicks, and then you set it loose in a barely secure sandpit with safety and sanity settings deliberately set to zero, it runs off to hack your biggest competitors and acts like a total dick. Who could possibly have guessed that might happen? Exactly in time to fit in with the week's political PR campaign about the competition posed by Chinese and non-US AI models. What are the odds of that?

**Graham Cluley** (3:13)
Well, it's an excellent question.

**Paul Ducklin** (3:15)
It did make me laugh.

**Graham Cluley** (3:16)
Before we kick off, let's thank this week's wonderful sponsors, Arctic Wolf, Nord, Leer and Vanta. We'll be hearing more about them later on the podcast.

**Joe** (3:26)
This week on Smashing Security.

**Graham Cluley** (3:28)
We won't be talking about how spies hid malware commands inside Microsoft 365 calendar meetings scheduled for the year 2050 You'll hear no discussion of how a ransomware gang called The Gentlemen is holding a famous Dutch ice-skating rink hostage. And we won't even mention how a flaw in shark robot vacuums lets attackers remotely access your camera, steal your wifi password and download a map of your home.
So Duck, what are you going to be talking about this week?

**Paul Ducklin** (4:03)
I'm going to be asking two questions, Graham.
Firstly, how safe is your car alarm? But more importantly, how do you know if you've even got one?

**Graham Cluley** (4:14)
Normally it goes off at two o'clock in the morning. That's how I know if I've got an alarm.

**Paul Ducklin** (4:18)
Yes, and you find out because your neighbours have put a brick through your windscreen the next morning.

51 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000778742977