
Free Daily Podcast Summary
by Risky Creative
The Awareness Angle makes cybersecurity make sense. Hosted by Anthony and Luke, we break down the biggest cyber security news of the week. From phishing scams and AI fraud to major data breaches and the sneaky ways people get hacked, we explain what’s going on and why it matters.But this isn’t just another tech podcast. We focus on the human side of cybersecurity. How scams actually work, why people fall for them, and what we can all do to stay safer online.You’ll get practical tips, real-world examples, and relatable stories that show how cyber threats affect everyday people.
The most recent episodes — sign up to get AI-powered summaries of each one.
ShinyHunters breached the University of Nottingham using a critical Oracle PeopleSoft zero-day, leaking passport numbers, National Insurance numbers, disability data and financial records for 455,000 students. If you studied at Nottingham, check haveibeenpwned.com now.A hidden camera was found in a ceiling tile at 2 Marsham Street, London, the Home Office building that approved China's controversial new mega-embassy. Nobody knows who put it there or how long it was recording.Someone filed fake data breach notices on Maine's official breach portal, which publishes filings instantly with no verification. The Register reported one as fact before readers flagged it.Also this week: ServiceNow admits a security incident months after allegedly being warned. 10,000 malicious domains registered ahead of the FIFA World Cup. A disgruntled researcher bypasses BitLocker because Microsoft made him homeless. Google Chrome permanently kills uBlock Origin. The Met Police gives Apple and Samsung an ultimatum over stolen phones.Phish of the Week: Temu callback phishing using a real password reset email.CHAPTERS0:01 Intro3:45 Breach of the Week: University of Nottingham data breach and Oracle PeopleSoft zero-day8:41 Hidden camera found in Whitehall building that approved China's mega-embassy13:54 ServiceNow security incident: customer data accessed16:36 FIFA World Cup 2026: 10,000 malicious domains21:33 Nightmare Eclipse drops eighth Windows zero-day, bypasses BitLocker27:39 Fake data breach notices posted to Maine's official portal33:19 Google Chrome permanently kills uBlock Origin37:51 Met Police urges Apple and Samsung to make stolen phones unusable39:40 Apple Passwords auto-change feature42:07 Phish of the Week: Temu password reset misuse46:19 Security Socials: Police use AI to enhance CCTV imageNewsletter: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/Music: "16" by Falling Forever. https://fallingforever.bandcamp.com/track/16. CC BY 4.0: https://creativecommons.org/licenses/by/4.0/
NHS patients are only now being notified about a breach that happened two years ago. Hackers brute-forced Dashlane's two-factor authentication. The FBI has already spotted over 30 fake FIFA websites and yes, fifa.beer is one of them.This week Ant and Luke cover why the two-year gap between the Synnovis ransomware attack and this week's notification letters is not unusual, and what it means for the people affected. Plus why the Dashlane breach is giving everyone LastPass flashbacks, and why your master password matters more than you might think.Also this week: UK banks locked out of Anthropic's Claude Mythos while OpenAI steps in with GPT-5.5 Cyber, Mac malware that passed Apple's own notarization checks, a new MFA bypass platform sold on Telegram, and the NCSC's warning that AI is about to surface decades of hidden software vulnerabilities all at once.Chapters:00:00 Intro02:53 Breach of the Week — NHS Blood Test Results06:03 AI Banking — Claude Mythos vs GPT-5.5 Cyber10:38 Dashlane Password Manager Breach16:49 Apple Mac Malware — Operation FlutterBridge21:59 Fake FIFA Websites — The FBI List26:37 NCSC — Patch Flood Warning31:43 Kali365 — MFA Bypass via Microsoft 36535:46 Phish of the Week — Claude Ads Impersonation39:38 Security Socials — Same Ingredient Different Delivery42:38 Security Socials — Call of Duty VulnerabilitiesThe Awareness Angle is an independent weekly cybersecurity podcast for security awareness professionals, CISOs, and anyone who wants to understand the human side of security.Newsletter | YouTube | Apple Podcasts | TikTok | Instagram | LinkedInOur Intro and Outro Song © 16 by Falling Foreverhttps://fallingforever.bandcamp.com/track/16Licence: Creative Commons CC BY 4.0
Solo episode this week. A fake UK visa website left 100,000 passports in an open folder online. iPhone thieves in London are now threatening victims' families to get them to remove Activation Lock. California has sued the company formerly known as 23andMe, alleging they paid the hacker in secret while telling customers everything was fine. A ChatGPT vulnerability lets attackers hide phishing links inside AI responses. A criminal group called Silent Ransom Group has been physically walking into US law firm offices dressed as IT support and plugging in USB drives. And researchers demonstrate AudioHijack - inaudible commands hidden inside podcasts, Zoom calls and music that AI assistants process as real instructions while you hear nothing.Plus: a real Amber Alert that looked exactly like a phishing scam because the URL got clipped by a character limit, and how a TikToker's phone home screen told scammers exactly which bank to impersonate when they called him.Chapters00:00 Intro01:04 SANS Security Awareness Summit - Official Media Partner Announcement02:15 Flying Solo This Week02:45 Breach of the Week - UK Visa Portal Leaks 100,000 Passports04:34 London iPhone Theft - Thieves Are Now Threatening Your Family09:42 23andMe - California Sues Over the Cover-Up, Not Just the Breach15:47 ChatGPhish - Attackers Hiding Phishing Links Inside ChatGPT21:31 Silent Ransom Group - Criminals Walking Into Law Firm Offices27:36 AudioHijack - The AI Commands Hidden in Sounds You Can't Hear34:50 Amber Alert Accidental Phishing (Ant's Topic)39:41 Tom the Tech Chap - Your Phone Screen Tells Scammers Which Bank to Impersonate (Luke's Topic)The Awareness Angle is a weekly cybersecurity podcast and newsletter that explains the biggest cyber threats, data breaches, and online scams in plain English. No jargon. No technical background needed. New episode every week.📧 Newsletter🌐 riskycreative.com🎙️ Spotify🎙️ Apple Podcasts▶️ YouTube: @riskycreative📱 TikTok: @antdaviscyber📱 Instagram: @antdaviscyber💼 LinkedIn: antdaviscyberOur Intro and Outro Song © 16 by Falling Foreverhttps://fallingforever.bandcamp.com/track/16Licence: CC BY 4.0 https://creativecommons.org/licenses/by/4.0/
CISA left admin passwords and AWS keys on a public GitHub repo called "Private-CISA" for six months. A new macOS stealer called Reaper fakes Apple security updates to steal everything on your machine. And the 2026 Verizon DBIR lands with 22,000 breaches across 145 countries.Chapters00:00 Intro01:30 Breach Watch: 7-Eleven / ShinyHunters04:20 Breach Watch: Portugal postal service leak07:12 CISA left passwords on public GitHub12:32 Iran-linked attacks on US fuel monitors17:54 Reaper macOS stealer22:43 Discord end-to-end encryption27:01 The 2026 Verizon DBIR breakdown33:26 Newsletter and socials34:30 Security SocialsSubscribe to the newsletter at riskycreative.comFollow us on TikTok | Instagram | LinkedInListen on Spotify | Apple PodcastsOur Intro and Outro Song is 16 by Falling ForeverListen on BandcampLicensed under Creative Commons Attribution 4.0
This week the Canvas story is back. Instructure has paid ShinyHunters and says the stolen student data has been destroyed, but nobody in the security industry believes them. A telehealth platform breach exposed over 700,000 patients from a company most of them have never heard of.Twin brothers got fired on a Teams call, forgot it was still recording, and deleted 96 government databases while talking through their plan out loud. Kids are beating age verification with a drawn-on mustache. A fake Claude Code installer is stealing developer credentials through Google search ads. And Google has confirmed for the first time that hackers used AI to find and exploit a zero-day.Plus, a stoner just recovered $400,000 in Bitcoin after losing his password while high in 2015.Chapters00:00 Intro01:42 Breach Watch: Canvas Pays ShinyHunters05:56 Breach Watch: OpenLoop Health Breach10:20 Twin Brothers Delete 96 Government Databases14:03 Kids Bypass Age Verification With a Fake Mustache19:18 Fake Claude Code Installer24:34 Hackers Used AI to Find a Zero-Day30:20 Stoner Recovers $400K Bitcoin With AI33:57 Audi VIN Vulnerability40:32 Security Socials47:24 UK Banks Storing Biometric Data51:47 Waymo Cars Driving Into FloodsSubscribe to the weekly newsletter at riskycreative.com or find us as The Awareness Angle on LinkedIn, TikTok, Instagram, YouTube, Spotify and Apple Podcasts.📩 Newsletter🎧 Spotify🎧 Apple Podcasts📸 Instagram🎵 TikTok: @infosecant▶️ YouTube🎵 Music: "16" by Falling ForeverCreative Commons Attribution 4.0
Spirit Airlines shut down on May 2nd but nobody turned anything off. A security researcher discovered the entire booking system is still running, still taking personal details, and still attempting payment transactions for flights that will never exist. Google Chrome has been silently downloading a 4GB AI model onto your computer without consent, and if you delete it, it comes back. And a $5,000 robot lawn mower can be hijacked by anyone on the internet, including overriding the emergency stop button. It phones home to TikTok's parent company.Also this week: Zara and Cushman & Wakefield both breached by ShinyHunters, a phishing attack that bypasses MFA using Microsoft's own login flow, Instagram quietly removes encrypted DMs, Anthropic's Mythos AI finds tens of thousands of vulnerabilities, OpenAI adds a trusted contact feature after self-harm lawsuits, and a student stops four high-speed trains with a radio he bought online.Chapters00:00 Intro01:43 Breach Watch: Zara Data Breach via Third-Party Vendor03:43 Breach Watch: Cushman & Wakefield Vishing Attack08:34 ConsentFix v3 Bypasses MFA via Microsoft OAuth12:18 Spirit Airlines Zombie Infrastructure Still Taking Bookings19:04 Google Chrome Secretly Installs 4GB AI Model24:31 Instagram Drops End-to-End Encryption on DMs29:22 Anthropic Mythos Exposes Thousands of Vulnerabilities35:25 OpenAI Trusted Contact Feature40:14 Student Hacks Taiwan High-Speed Rail44:25 Yarbo Robot Lawn Mower Hack51:20 Security Socials1:00:00 OutroSubscribe to the weekly newsletter at riskycreative.com for the full breakdown of every story.📺 YouTube🎧 Spotify🎧 Apple Podcasts📰 Newsletter📸 Instagram📱 TikTok: @infosecant🌐 Website🎵 Our Intro and Outro Song © 16 by Falling ForeverLicensed under CC BY 4.0
This week on The Awareness Angle, we hit 1.2 million views on a single video across TikTok and Instagram, which is pretty wild for an independent podcast. Thank you to everyone who watched and shared.ADT gets breached for the third time in under a year and it all started with a phone call. An AI coding agent wipes a startup's entire database and all its backups in nine seconds, then writes its own incident report admitting it broke every safety rule it had. The supply chain attack that started with Trivy has now hit Checkmarx and Bitwarden, with three criminal groups teaming up to turn supply chain access into ransomware. And the UK government's annual cyber report says 43% of businesses were breached last year, phishing was behind 85% of them, and despite M&S, Co-op and JLR making national headlines, nothing's really changed. Plus Instructure's Canvas LMS breached again, Itron's smart meters filing quietly on a Friday night, Microsoft Teams helpdesk impersonation going wild, 610,000 Roblox accounts stolen by three lads in Ukraine, QR code scams in Toronto, and a toaster with a touchscreen that nobody asked for.The Awareness Angle is an independent cybersecurity podcast covering cyber news, data breaches, phishing, social engineering, and security awareness. New episodes every week.Chapters:00:00 Intro01:30 Welcome01:52 ADT Breached Again by ShinyHunters Vishing Attack07:23 Instructure / Canvas LMS Hit by Another Cyber Attack13:38 Critical Infrastructure Giant Itron Confirms Cyberattack17:56 AI Coding Agent Deletes Startup Database in 9 Seconds25:28 Supply Chain Attack Hits Checkmarx and Bitwarden28:40 Roblox Account Theft: 610,000 Accounts Stolen36:56 UK Cyber Security Breaches Survey 2025-2643:06 Microsoft Teams Helpdesk Impersonation Attacks52:21 QR Code Scams in Toronto57:03 Smart Toasters and Unnecessary IoT1:01:09 Hannah Fry on AI Agents Going RogueSubscribe to the newsletter at riskycreative.comOur Intro and Outro Song © 16 by Falling Foreverhttps://fallingforever.bandcamp.com/track/16Licensed under Creative Commons Attribution 4.0https://creativecommons.org/licenses/by/4.0/
Roblox cheats at work lead to a full corporate breach. Half a million people's health data listed for sale on Alibaba by the researchers trusted to protect it. A $5 Bluetooth tracker in a postcard tracks a NATO warship for 24 hours. The UK government officially says passkeys should replace passwords.In this episode we break down the Vercel breach, the UK Biobank scandal, a Bluetooth tracker that exposed a $585 million warship, the NCSC's official passkey guidance ahead of World Password Day, plus Rituals Cosmetics, GCHQ's SilentGlass, Claude Desktop's silent browser hooks, a Grafana-branded sextortion scam, and Bitwarden's CLI getting hijacked.Chapters00:00 Intro01:18 Vercel Breach: Roblox Cheats to Customer Data Exposure06:38 Rituals Cosmetics Loyalty Programme Breach09:46 UK Biobank Health Data Sold on Alibaba13:41 GCHQ SilentGlass: Blocking Malware Over HDMI16:25 Claude Desktop Silently Installs Browser Hooks24:03 Sextortion Scam Disguised as Grafana Alert29:15 Bitwarden CLI Hijacked in Supply Chain Attack31:52 $5 Bluetooth Tracker Exposes NATO Warship35:44 NCSC: Passkeys Should Replace Passwords42:50 Security Socials: The HR Hot Take46:08 Security Socials: Spam Caller Rick Astley Script48:09 Security Socials: iPhone 17 Pro Stolen51:56 Security Socials: My Cocoon Airplane Privacy54:19 Security Socials: GPT Image 2 AI Generation58:57 OutroSubscribe to the newsletter for links to every story we discuss:LinkedIn: https://www.linkedin.com/newsletters/the-awareness-angle-newsletter-7274932363787132928/Our Intro and Outro Song © 16 by Falling Forever — Bandcamp: https://fallingforever.bandcamp.com/track/16 — Licence: https://creativecommons.org/licenses/by/4.0/
The Awareness Angle makes cybersecurity make sense. Hosted by Anthony and Luke, we break down the biggest cyber security news of the week. From phishing scams and AI fraud to major data breaches and the sneaky ways people get hacked, we explain what’s going on and why it matters.But this isn’t just another tech podcast. We focus on the human side of cybersecurity. How scams actually work, why people fall for them, and what we can all do to stay safer online.You’ll get practical tips, real-world examples, and relatable stories that show how cyber threats affect everyday people.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from The Awareness Angle in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of The Awareness Angle as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by Risky Creative.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
The Awareness Angle covers topics including News. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.