6 C
Canberra
Thursday, July 23, 2026

How 14 orders of rooster McNuggets helped nail a suspected Russian hacker • Graham Cluley


Unknown

I’ve to say, even supposing I’ve used it, I do really feel utterly soiled and appalled at myself for having used it. And my opinion on that has strengthened solely over time.

So I do assume it is utterly reprehensible of me. Sure. Smashing Safety, episode 477.

How 14 orders of Hen McNuggets helped nail a suspected Russian hacker with Graham Cluley and particular visitor James Ball.

Whats up, hiya, and welcome to Smashing Safety episode 477. My title’s Graham Cluley.

JAMES BALL

And I am James Ball.

GRAHAM CLULEY

James, welcome again to the present. All the time a pleasure to have you ever.

Now, I used to be following you on Blue Sky and I noticed that you just had an uncommon means of dealing with the acute warmth which we have been experiencing a few weeks in the past.

Many individuals have been caught out by these rip-off adverts on YouTube for issues which declare to have the ability to air situation your room. However what did you do?

JAMES BALL

I imply, the excellent news is I did not fall for any scams.

GRAHAM CLULEY

Good, effectively completed.

JAMES BALL

The unhealthy information is I went insane and booked myself flights proper as much as the Arctic Circle. And so I spent per week up in Tromsø in northern Norway. Norway goes a good distance up.

JAMES BALL

And Tromsø is correct on the prime. It is the gateway to the Arctic. 24-hour sunshine this time of 12 months, however crucially by no means acquired above 15 levels. Really pleasant.

GRAHAM CLULEY

And was this an intentional response to the climate scenario we have been affected by?

JAMES BALL

It was absolutely 100% a response to the heatwave. I booked the journey, I feel, 30 hours earlier than I acquired the aircraft.

JAMES BALL

And it was genuinely a results of Googling, the place can I am going that is chilly?

And there have been a lot of type of issues the place it is like, effectively, about £20, or this place can be within the heatwave. Northern Scotland was actually costly.

And it turned out that really going as much as the Arctic — I imply, I spent per week there and together with the flights, it value me lower than £1,000.

GRAHAM CLULEY

And you bought to see the England-Norway World Cup recreation as effectively, I feel.

JAMES BALL

Sure, in Norway, that they had screens up within the city sq. filled with very drunk Norwegians who — yeah, I do not assume they have been cheering on England, you already know.

Though the good factor was the day after, I used to be type of apprehensive I might should try to placed on a very horrible American accent or one thing.

And so they did all type of say, look, simply beat Argentina. We do not need Argentina to win. And I heard that from 3 or 4 totally different folks. In order that they have been type of okay with it.

They have been cooler than they may have been. However strongly advocate it. Tromsø is nice. Simply do not get a curry there. Norway doesn’t do spice.

I had a vindaloo, Graham Cluley, and I do not assume it ever touched capsicum.

GRAHAM CLULEY

Nicely, earlier than we kick off, let’s thank this week’s fantastic sponsors, Arctic Wolf, NordLayer, and Vanta. We’ll be listening to about them in a while within the podcast.

This week on Smashing Safety, we can’t be speaking about how a person in India has been accused of utilizing an AI chatbot to assist him plan a triple homicide.

You will hear no dialogue of how the July 2026 patch replace from Microsoft comes with safety updates for a record-breaking 570 vulnerabilities.

And we can’t even point out how plugging in an LG monitor can robotically set up adware in your Home windows PC that bombards you with McAfee pop-ups with out ever asking your permission.

So James, what are you going to be speaking about this week?

JAMES BALL

I’m going to be speaking concerning the Suno hack as a result of I feel there’s rather a lot in there.

GRAHAM CLULEY

And I will be discussing why ordering McNuggets is probably not good on your on-line privateness, significantly in the event you’re a hacker.

All this and rather more developing on this episode of Smashing Safety.

Proper, earlier than we crack on any additional, Joe and I need to take a second to let you know about one in all right now’s sponsors, Vanta.

JOE

We have got a query for you. What is the factor that retains you staring on the ceiling at 2 AM with regards to your organization’s safety?

GRAHAM CLULEY

Is it questioning whether or not you’ve got really acquired the best controls in place? Whether or not one in all your suppliers has been quietly compromised, or is it the actually soul-destroying one?

Why on earth are we nonetheless working our complete safety program out of a spreadsheet?

JOE

If any of that hit just a little too near residence, that is the place Vanta is available in.

Vanta takes all that tedious guide safety grind — chasing down proof, wrestling with questionnaires, updating the identical cells for the thousandth time — and automates the entire thing.

GRAHAM CLULEY

Their belief administration platform retains a steady eye in your methods. It pulls all the things into one central place and retains your safety programme audit-ready across the clock.

Sure, it makes use of AI, however the genuinely helpful sort, flagging dangers, streamlining proof assortment, and slotting into the instruments your workforce already depends on.

The upshot of that is you progress sooner, scale with out the standard complications, and perhaps, simply perhaps, really get an honest evening’s sleep.

JOE

Sounds lush. Discover out extra and get began at vanta.com/smashing.

GRAHAM CLULEY

That is vanta.com/smashing, and an enormous thanks to Vanta for supporting the present. Now, friends, friends, think about in the event you can that you’re a spy working for the Russians, all proper?

What is the worst factor that might presumably happen in the event you have been really working for the Russians?

Would your greatest risk be having your identification uncovered, being came upon by the FBI?

Wouldn’t it be about Western intelligence businesses discovering out the place you are based mostly, finding your identification and extraditing you?

Or would the largest risk really be about Hen McNuggets? That’s the factor we’ll be exploring. Do you stand anyplace particularly on Hen McNuggets, James?

JAMES BALL

I am really an enormous fan of them. For a very long time as a child, I ate little or no else.

And so I’ve travelled in lots of, many nations on this planet and each single one which had a McDonald’s, I have been to the McDonald’s in that nation.

GRAHAM CLULEY

Oh my goodness, James.

JAMES BALL

I’ve had McNuggets in India, in China, in Australia, and in Norway. Indian McNuggets are the most effective, by the best way.

GRAHAM CLULEY

Oh, there is a distinction, is there, between McNuggets? I can not imagine we’re having this dialog, however—

JAMES BALL

I ought to stress, I eat in regular, good eating places as effectively. This is not costly.

GRAHAM CLULEY

Oh, good, okay. That is reassuring, at the least.

JAMES BALL

So this could be unhealthy information for me.

GRAHAM CLULEY

Nicely, again in September 2024, Dutch cybersecurity consultants found that somebody had burrowed into the pc methods of the Netherlands Nationwide Police Pressure they usually had accessed the e-mail account of a workers member there.

And by way of that account, that they had then grabbed the information of tens of 1000’s — I feel over 64,000 — officers within the power.

Officers’ names, addresses, identities, additionally of their informants.

The Dutch intelligence company on the time described it as the primary time that the nation had fallen sufferer to deliberate sabotage by a Russian-backed hacking group.

It precipitated an enormous furore within the press, as you may anticipate, they usually did not break in to plant ransomware or extort cash — this was all about stealing intelligence, gathering intel as a way to exploit it later.

So this was successfully a police power’s complete contact database — you already know who the police are, who they’re speaking to, who talks to them.

And Microsoft, working with Dutch intelligence, publicly named the hacking group chargeable for this again in Might 2025 as Void Blizzard.

I really like the names that are typically given to those teams.

JAMES BALL

It feels like a World of Warcraft patch, would not it?

GRAHAM CLULEY

Sure. I imply, they known as it Void Blizzard. There was one other group of researchers who I imagine known as them Laundry Bear.

JAMES BALL

Nicely, that might most likely be the official US designation, would not it? As a result of all the things that is believed to be Russian state-linked is at all times given bear. So Fancy Bear is the GRU.

GRAHAM CLULEY

And we have Loopy Bear.

JAMES BALL

Army Bear can be a distinct navy intelligence unit.

GRAHAM CLULEY

Yeah, I do know, however Laundry Bear — you’d nearly be embarrassed to be a member of Laundry Bear in comparison with Fancy Bear, would not you, I feel?

JAMES BALL

It does recommend the place you’re within the pecking order, would not it?

Which, given this can be a fairly good hack, really getting 64,000 officers and the contact database, I feel perhaps they deserve a promotion — Laundry, perhaps to Scullery, Scullery Bear.

GRAHAM CLULEY

I feel they’re being trolled, mainly.

So anyway, Microsoft and the Dutch intelligence company stated that this assault hadn’t simply focused the police, it seems, however different sectors — defence, healthcare, authorities — not simply the Netherlands as effectively, but additionally nations throughout NATO and Ukraine as effectively, in fact.

So you may all type of guess the place this assault is more likely to be coming from, and the standard assault would come within the type of a private invitation by way of e mail.

You may get invited to a European Defence Summit, and in the event you click on on the hyperlink otherwise you scan the QR code despatched within the PDF which you’ve got been despatched, you get taken to a login web page.

Appears to be like like Microsoft Groups you are logging into, and naturally it is the standard story — they’re grabbing your username and password in order that they’ll then log into your account and steal your info.

So this was pretty customary state-sponsored cyber espionage directed at Western safety infrastructure.

And on the coronary heart of it, in accordance with US prosecutors, is a chap known as Denis Obrezhko.

He’s a 36-year-old Russian IT nerd, and on the finish of October 2025, he made presumably a worse mistake than you going as much as the Arctic Circle — he selected to go to Phuket in Thailand.

He grabbed himself a ticket there, he fancied just a little break, just a little vacation, and fewer than per week later, Thai police have been knocking on his door, seizing his laptop computer and his cell phone and doubtless a digital pockets as effectively, and putting him below arrest, believing him to be a hacker concerned on this assault.

And naturally, the primary rule, if you’re a Russian hacker, is you should not go away Russia. Should you’re in Russia and also you’re solely attacking organisations exterior, keep in Russia.

JAMES BALL

You will get promoted, you may get a pleasant residence, you may do nice. I imply, I suppose you can go on vacation to Belarus — that might most likely be wonderful.

GRAHAM CLULEY

Sure, they will most likely be wonderful with you as effectively.

JAMES BALL

It is most likely fairly a brief journey checklist, serious about it.

Possibly bits of Central Africa, however I feel anyplace with a US extradition treaty ought to most likely not be on the vacation spot checklist, proper?

GRAHAM CLULEY

And Russia’s overseas ministry, they immediately leapt into motion.

They issued a warning to their residents saying, don’t journey to Thailand — there’s a risk of you being arrested on the request of the US.

They stated, we strongly advise Russian residents who’ve even the slightest cause to suspect they is perhaps topic to prison prosecution by US authorities to chorus from travelling to Thailand.

So this Denis chap, Denis Obrezhko, he has since been extradited to the US.

This month he is appeared in a federal court docket in Boston, he is pled not responsible to hacking prices, and if he’s discovered responsible, he could possibly be dealing with, I do not know, 10 years in jail perhaps.

And now the factor is about Denis Obrezhko — I attempted to search out him on LinkedIn, which is my customary.

JAMES BALL

Your analysis device, you already know, that is your spy intel, is it?

GRAHAM CLULEY

And to be sincere, it’s stunning simply how many individuals will go away their dodgy previous employments up on LinkedIn.

I could not discover him, however he’s alleged to have had fairly an fascinating job historical past. So in accordance with the FBI, for five years between 2012 and 2017, he was working for the FSB.

And for anybody who would not know, the FSB is like New Labour to Previous Labour — it is the rebranded model of the KGB.

JAMES BALL

The cuddly, kindly, non-Soviet KGB, sure. Sure.

GRAHAM CLULEY

And after the FSB, in accordance with Reuters, who spoke to a former colleague and noticed some paperwork, he spent 2 years as a senior member of workers at a well known Russian firm, which most likely quite a lot of our listeners have heard of, known as, hmm, let me simply— Kaspersky.

GRAHAM CLULEY

Now Kaspersky, as I am positive most of our listeners know, is in fact a really well-known Russian antivirus firm, cybersecurity firm, who has had a rotten few years, fairly frankly, significantly because the conflict in Ukraine started.

As a result of there’ve been so many tales about them being linked to the Kremlin and to the FSB, they usually’ve needed to shut down their operations.

JAMES BALL

Have you ever ever talked to anybody there about the entire Russia connection or this type of factor? Have you ever ever had that chat?

GRAHAM CLULEY

I’ve, sure.

JAMES BALL

As a result of they get fairly— I imply, there are some very, superb safety researchers at Kaspersky. They’ve helped me out on tales earlier than and type of talked me via issues.

You recognize, they’ve some actual professionals. And so they get extremely awkward about it due to course most individuals who work there simply work and have a job, do not they?

JAMES BALL

Yeah. However while you begin to have a look at Eugene Kaspersky and the realities of working in Russia and all of that, it is exhausting to not marvel.

Even earlier than everybody was saying it, folks both very enthusiastically deny that they’ve ever seen something or completed something with it, or try to transfer the dialog on, in my expertise.

What’s it been like for you?

GRAHAM CLULEY

So I’ve a detailed good friend who has labored at Kaspersky for a lot of— he would not work there any longer as a result of successfully their UK operations are useless now.

They’re solely promoting on-line, their workplaces are shut down, they’ve laid off their workers.

I feel it is really unlawful to promote it in any respect in America now, even to shoppers, not simply to authorities organisations.

JAMES BALL

Yeah, I feel you are proper.

GRAHAM CLULEY

So I imply, it has been catastrophic for them business-wise.

My good friend’s a really good chap and he is not a spy, and it occurred that he acquired a job 25 years in the past or no matter it was for an antivirus firm which occurred to be based mostly in Russia.

And I’ve recognized Eugene for a lot of, a few years. I have never seen him for fairly just a few years, to be sincere, however I do know him — looks as if a really good man.

JAMES BALL

I feel I’ve interviewed him. Yeah, he is very, very intelligent.

GRAHAM CLULEY

Yeah, extraordinarily intelligent. Like many of those guys who’ve arrange these antivirus corporations.

However you do should marvel, wouldn’t it be doable to be a profitable businessman — and he was a particularly profitable businessman in Russia — with out kowtowing to what the Russian authorities need?

As a result of they’d make your life extraordinarily troublesome, if not unattainable.

JAMES BALL

I imply, it is not doable.

You must at the least be pleasant and cooperative, and given the significance of hacking to Russia’s smooth energy and the way it conducts diplomacy and type of info operations, I simply do not assume you can be in a job as delicate as that and never do this.

I imply, let’s be sincere, the eight greatest cybersecurity corporations that function within the UK coordinate with NCSC and with the intelligence businesses.

There are specific corporations, in the event you’re on important nationwide infrastructure, there’s an accepted checklist. And I am not saying anybody does something out of line with the regulation.

We’re a Western democracy. Every little thing is within the statute and above board to that stage. However we cooperate with them in that means.

It isn’t bizarre to say, would an organization with an analogous stature and an analogous attain and scope that is headquartered in Russia have a relationship with the Kremlin? In fact it will.

It might be unattainable for it to not.

GRAHAM CLULEY

Yeah.

I really feel like Kaspersky discovered itself in an unattainable place, and clearly there have been accusations that perhaps their software program could possibly be used to sabotage corporations or to steal info from corporations, with a malicious replace on the behest of the Kremlin.

I do not assume I’ve ever seen any proof in any respect that that was one thing which was deliberate to do, however clearly you solely want a certain quantity of doubt, a small quantity of doubt, and that is sufficient to persuade folks, effectively, perhaps we should not use that product, perhaps we must always use this different one as a substitute.

So sadly world occasions type of overtook issues, which is a disgrace as a result of it was in some ways a superb product. Yeah.

JAMES BALL

Geopolitics has at all times acquired a win in that one although, is not it?

GRAHAM CLULEY

Yeah, completely. Anyway, the blokes at Kaspersky, they are saying that no matter Abrezco is accused of now, had nothing to do along with his time working for them.

They are saying that the alleged hacking exercise did not occur till after he had left. However it will get extra fascinating than that.

5 years in the past in 2021, Abrezko gave a visitor lecture on the Moscow Technical College of Communications and Informatics, and he was launched because the Deputy Director of the Info and Analytical Middle of Russia’s Ministry of Emergency Conditions.

Think about working on the Ministry of Emergency Conditions.

JAMES BALL

It is an important job title. I hope Andy Burnham units that one up, a Ministry of Emergency Conditions. It appears like we’d like one, would not it? I might love that.

GRAHAM CLULEY

Anyway, so this can be a Russian authorities establishment which he was working for.

And the prosecutors then say he grew to become a deputy director at a Russian tech agency known as UTECH.NN, which is alleged to have been a canopy organisation for Void Blizzard’s hacking marketing campaign.

So this is not really that uncommon, in that corporations can be arrange showing to do one factor — on this case, it was IT consultancy and challenge administration, product growth, all very uninteresting.

However while you look into the general public data, apparently they present that that firm holds an FSB-issued licence for what’s described because the covert acquisition of knowledge.

So that you get your licence from the Russian authorities saying, sure, you’re allowed to secretly, with out different folks’s data, purchase info.

It appears just a little bit uncommon, however once more, it makes you assume, what does this firm really do?

JAMES BALL

It is type of like a digital PI’s licence, is not it? You recognize, I type of really feel prefer it’s your type of hacking fedora or one thing. I type of like this.

GRAHAM CLULEY

Anyway, this firm, UTECHNN, their founder is a man known as Mikhail Dudin, and it turned out he was listed — there is a caller ID app known as GetContact the place you’ll find out what folks’s widespread nickname is, or they’ll set themselves a reputation.

He’d chosen the title Ethan Hunt, which is from a film I’ve seen, Mission: Unattainable, the Thom Cruise character.

JAMES BALL

I imply, how’s that for cultural hegemony although? You recognize, the extent to which American tradition is in every single place, that even the Russians are choosing Ethan Hunt as their title.

GRAHAM CLULEY

Anyway, Microsoft revealed their report into Void Blizzard apparently on that exact same day.

Obrezhko allegedly emailed Ethan Hunt in quotes, suggesting that they’ve a gathering to debate developments.

So it is fairly a tangled darkish internet, which the courts are clearly going to should unknot to see if this man is responsible or not. He clearly denies it.

However I used to be occupied with understanding how the investigators have pieced this all collectively.

How had it come to the scenario the place the US had requested the Thai police to arrest this man if he ever turned up in Phuket? And it is moderately fascinating.

So what occurs, it appears, is he had reused the identical username and his actual Russian cellphone quantity throughout a number of e mail accounts and social media platforms and monetary apps, issues like that.

And he’d used the identical Google account for cryptocurrency transactions as he’d used to create accounts on Twitter and Instagram and PayPal.

So similar username, similar avatar, similar cellphone quantity, similar date of start time and again.

It is like, guys, if you are going to be criminals, have in your again pocket an entire checklist of various dates of start, of various names, of various e mail addresses — do not make it straightforward to triangulate who you’re.

And the investigators say that they’ve traced cryptocurrency funds used to fund Void Blizzard, they usually adopted transactions again via an web supplier.

Finally they discovered an e mail account registered in Obrezhko’s personal title.

And that is the place it turns into actually fascinating, as a result of impartial risk intelligence agency Management Alt Intel took the e-mail handle and cellphone numbers that the FBI had revealed of their affidavit, they usually cross-referenced them with Russian leak databases.

So these are databases of leaked info which have spilled out over time via prison exercise.

And it is not simply the criminals who use these — typically the risk intel folks use them as effectively.

And what they have been capable of finding was, by going via this information, they acquired info from banks and social networks and courier corporations, meals supply apps, something like that, which is clearly horrendous from the viewpoint of in the event you’re a Russian citizen, however nice in the event you’re a risk intel researcher.

They have been in a position to seek for Denis Obrezhko’s e mail handle and cellphone quantity, they usually saved on popping up in these leak databases, together with that he had ordered, on the first of March 2021, at half previous 3 within the afternoon, a Lipton iced tea, 9 Hen McNuggets, and a McChicken burger to be delivered to him on the Russian Ministry of Emergency Conditions on that exact date.

And so they discovered 13 different separate orders, all delivered to that ministry handle, all on weekdays, early within the afternoon. Liked his Hen McNuggets.

And it is tangled him much more into — sure, that is the ministry you have been working in. You have been working for the Russian authorities, regardless of any claims it’s possible you’ll try to make in a while.

JAMES BALL

I do discover these things actually fascinating as a result of listeners are most likely conscious that I used to be one of many reporters who labored on the Edward Snowden story.

JAMES BALL

And that meant 18 months of us understanding that we have been below surveillance, type of from the US, from the UK, however presumably additionally type of hostile businesses.

We have been flying between the US, the UK, Brazil.

We have been type of making an attempt to speak about categorised paperwork the entire time, and we have been making an attempt to be fairly type of cautious about that. However you additionally should stay.

You are staying in accommodations, you are making an attempt to type of spend on bank cards or firm playing cards as a result of my checking account was emptied by the primary week.

I used to be type of having to get pay as you go Visa playing cards, not for OPSEC, however as a result of I had no cash.

However you already know, you wanted to get a McDonald’s at 2 AM otherwise you wanted to get a taxi to get again and also you have been jet lagged.

And so that you’re making an attempt to do good safety, however if you cannot keep in mind a password at 2 AM when you have not slept for 30 hours and you do not know what time zone you are in, there is no level having the password.

And so the compromise between the place your type of regular mundane accounts type of attain and the place your type of uber ones attain are extremely sophisticated to maintain up.

And you already know, perhaps for per week somebody can do it, however 3 months in, 6 months in, when it is your on a regular basis life, the issues that look very foolish while you see them in an indictment or while you see them in a safety analysis, it’s that factor the place it is like, effectively, how do you reside in any other case?

How do you keep in mind which date of start you used on your Uber account versus which one you used on your different one?

So all of those particulars are there, and in the event you do not use as many actual ones as doable, you mess it up.

You recognize, I keep in mind LulzSec acquired caught as a result of the chief, Sabu, turned on the opposite ones.

He acquired caught as a result of he forgot to alter one factor and wanted to log again in, and it was about half 3 within the morning, and he’d completed all the things correctly, and he logged in with out his VPN as soon as.

JAMES BALL

And from the fuzzed IP location, they then simply mainly manually surveilled that little block in New York till they labored out which flat it was and whose exercise sample it matched.

And so they acquired him that means, from one failure to make use of his VPN. And so, you already know, this appears to be like shoddy. I imply, that is poor. For a type of safety skilled, that is dismal.

However having lived like this, having tried to do it, I can say it’s harder than you assume.

GRAHAM CLULEY

I settle for that, James, however was the canteen within the Ministry of Emergency Conditions so poor that he was having to order Hen McNuggets in as a substitute?

I imply, that is an indictment in itself, is not it?

JAMES BALL

Have you ever eaten in post-Soviet universities or public establishments? As a result of if in case you have, I think you may need extra sympathy for the McDonald’s orders.

JOE

Graham, am I proper in pondering that Arctic Wolf are sponsoring the present this week?

GRAHAM CLULEY

You might be proper, Joe. They’ve simply revealed a brand new report, 2026 State of the Cybersecurity Assault Floor.

They analysed over 800,000 actual IT property to learn the way uncovered organisations really are.

JOE

And I am guessing all the things is hunky-dory.

GRAHAM CLULEY

Not a lot. The fact is that they discovered 1 in 3 IT property is lacking at the least one important safety management.

JOE

One in three. That is horrible.

GRAHAM CLULEY

Is not it simply? 10% of property don’t have any endpoint safety in any respect. 17% are utterly invisible to the instruments which might be imagined to be monitoring them.

JOE

So the instruments do not even know these property exist?

GRAHAM CLULEY

Proper. Ghost property wandering round your community, unprotected, unmonitored.

JOE

Like a retired geography trainer who’s by some means nonetheless on the varsity community.

No person added him, no one eliminated him, and he is been quietly in there for 11 years downloading maps of Paraguay.

GRAHAM CLULEY

Yeah, yeah, yeah, I suppose so, Joe. The purpose is, your attackers will discover him earlier than you do, as a result of they’re particularly on the lookout for the forgotten, the unpatched, the invisible.

That is the trail of least resistance.

JOE

So what does the report inform us to really do about it?

GRAHAM CLULEY

Arctic Wolf’s report covers easy methods to prioritise the exposures that really matter, reduce via all that noise, and confirm that while you repair one thing, it really stays mounted.

And the report is free to obtain. Free.

JOE

I like that. The place do I get it?

GRAHAM CLULEY

SmashingSecurity.com/ArcticWolf.

JOE

That is SmashingSecurity.com/ArcticWolf. And because of Arctic Wolf for supporting the present.

GRAHAM CLULEY

James, what have you ever acquired for us this week?

JAMES BALL

So it is an actual type of who’s the nice guys, who’s the unhealthy guys right here, however have you ever come throughout Suno, the AI music generator?

GRAHAM CLULEY

I’ve, and what’s extra, I am ashamed to say I’ve used it to generate AI music.

JAMES BALL

What AI music did you generate?

GRAHAM CLULEY

Nicely, I generated the theme tune for The AI Repair, which was a podcast.

I am now not concerned in The AI Repair, however it was a weekly podcast about AI developments, which I did for a few years. And it did it. I imply, it was a incredible tune.

The AI Repair, a digital zoo. Good machines, bots with brains, what’s going to they do? Fly us to Mars or bake a nasty cake? World domination, a foolish mistake.

JAMES BALL

Bots with brains.

GRAHAM CLULEY

It was very catchy. In reality, we had so many individuals who stated they cherished the tune that we ended up placing it on Spotify.

And to date, I feel I’ve made the sum complete of 4 pence out of it.

JAMES BALL

I noticed you within the prime 10% of earners then. So sure, it’s fairly enjoyable to play with. You’ll be able to type of give it just about any lyrics or any style and ask it to combine issues up.

It tends to make very middle-of-the-road, very type of fundamental composition, however it’s fairly a enjoyable factor to play with.

However inevitably fairly contentious in the identical means as in the event you put up any AI artwork, folks say, effectively, you’ve got simply taken a job from an illustrator.

Should you use Suno music, folks say, you already know, you are killing music.

JAMES BALL

And in some circumstances, folks completely are.

In others, in the event you would by no means go to pay a musician anyway, you already know, if that finances wasn’t there, it is simply creating one thing that would not in any other case exist.

There are all kinds of views on this, however—

GRAHAM CLULEY

I’ve to say, by the best way, even supposing I’ve used it, I do really feel utterly soiled and appalled at myself for having used it.

And my opinion on that has strengthened solely over time.

GRAHAM CLULEY

So I do assume it is utterly reprehensible of me. Like I stated, I am not concerned within the podcast anymore, however I’ve made 4 pence out of it.

JAMES BALL

So, effectively, I hope that you just donate that to an artist help charity or to somebody campaigning for reforms to the copyright regulation for the AI period.

However it means primarily Suno is in the midst of very related lawsuits to quite a lot of the opposite AI corporations.

What it generates, there’s at all times a little bit of rivalry — is that authentic, et cetera?

However the actual row is over how they have been educated and have they improperly accessed the coaching materials, have they type of violated that?

I feel the most effective recognized lawsuit over all of this in the intervening time is the Anthropic one.

JAMES BALL

Which primarily discovered that in the event that they purchased books secondhand, very cheaply ingested them and churned them via, that is wonderful. They might do it a greenback a pop, cheaper. That is okay.

However they did not trouble doing that. They simply downloaded a load of pirated books. And they also’ve needed to do an out-of-court settlement. I’ve to do a disclosure right here.

Two of my books are in that settlement. If that goes via, Anthropic owe me, I feel, about $5,000. I am not a celebration to the case in any other case.

GRAHAM CLULEY

The irony is although that Anthropic themselves do not like the thought of, as an illustration, Chinese language AI corporations stealing their assets and their data to raised their very own.

You recognize, they appear to have thought it was all proper for them to take stuff with out asking.

But when anybody takes something from Anthropic with out asking, they don’t seem to be fairly so happy about that.

JAMES BALL

Sure, however you see, it’s extremely totally different as a result of while you take from one mannequin to coach your mannequin, they name it distillation.

And since they provide it a distinct title, it is clearly completely totally different morally and legally. It isn’t.

They’re actually genuinely kicking off on the Chinese language corporations for precisely the conduct they did.

I imply, precisely proper all the way down to quite a lot of it finally ends up centring on whether or not it involves phrases of service violations imply that you just accessed unlawfully, and many others.

There’s a lot of very wonderful factors of IP regulation on this. Now, Suno are proper in the midst of all of this.

And to be sincere, I feel they’re in a trickier place than Anthropic and OpenAI, not essentially as a result of their conduct’s any totally different.

If you wish to produce quite a lot of music, you have to ingest quite a lot of music. And so they have kind of now admitted that they scraped off YouTube, Genius, Deezer, all of this stuff.

They took quite a lot of music. Their issue is that they are not likely up in opposition to a bunch of authors who’re, you already know, typically fairly poor and never that well-resourced.

They’re up in opposition to massive music and large music mainly fought this and received this as soon as earlier than.

You recognize, they beat Napster, they beat LimeWire, they beat all of these, they’ve a a lot smaller group who’re rather more aggressive pursuing them much more.

And so Anthropic has acquired off pretty cheaply for utilizing pirated materials.

The query goes to be, in the event you seize stuff off YouTube and use it to coach an AI, that’s not in step with the way you’re supposed to make use of YouTube. It is vitally, very doubtful.

And so they had been dancing round in discovery about whether or not they’d completed this, and now Suno has been hacked and it has been hacked by somebody who’s put an terrible lot of the fabric on-line.

And it just about categorically appears to indicate not simply that they did practice off YouTube, and many others., which we type of knew, however issues like precisely how a lot they’ve ingested into totally different components as a result of it is annotated code.

JAMES BALL

So folks can test the code they usually can test the annotations, however there’s issues like 113,879 hours of YouTube Music, 12,287 hours of Deezer, 3,722 of Jamendo.

What I like is that there was one website that had some copyright-free sound and there is solely 410 hours from that one. So it type of tells you some points.

You recognize, there’s many years and many years and many years price of authentic music.

And so in the event that they have been ever making an attempt to go, effectively, show it, or, you already know, you don’t have any proof of that, this appears to be like doubtful.

They’d largely helped themselves to the again catalogue of each musician on this planet, and now a hacker has helped themselves to their code.

Now, legally, they don’t seem to be fairly the identical standing, however morally, that is acquired to look similar to lots of people, is not it? It is, on one stage, a reasonably fundamental hack.

They acquired in via one programmer utilizing a 2025 worm, Shaihulud. I do not know a lot about Shai Hulud. Do you?

GRAHAM CLULEY

Sure, Shai Hulud was a worm that hit the npm JavaScript package deal registry. I feel it was in late 2025. We spoke about it in an earlier episode of Smashing Safety.

Principally, a developer inside your organization would set up a booby-trap package deal and the malware would quietly steal their credentials after which use them to contaminate different packages that they maintained.

So it will unfold itself robotically throughout your ecosystem.

And to make issues worse, it additionally dumped all of the issues it had stolen right into a public GitHub repository below the sufferer’s personal account, so type of broadcasting credentials to the world.

So yeah, an actual provide chain menace, that one. An uncommon worm, however was affecting numerous organisations doubtlessly and inflicting fairly an enormous drawback.

However as soon as they’re in, in fact, yeah, the information which might be extracted.

JAMES BALL

The hacker says they have the client checklist, the client emails, cellphone numbers, Stripe fee particulars. They supplied 404 a pattern of these, which seemed legit.

However what appears to have been used for the fascinating stuff is that is all of the GitHub submits and backwards and forwards.

What I discovered significantly fascinating right here was I began all kinds of musing about whether or not this was a type of Hacker Wars 2.0 and whether or not this was a type of revenge for the inventive industries kind factor.

I additionally puzzled if there was a little bit of — it’s recognized that corporates hack one another typically for numerous causes, as a result of it is helpful if materials can hit the general public area, and you’ll type of launder it in the event you get a third-party hacker.

It isn’t authorized, however an organization may, in principle, get a third-party hacker to get some delicate info, get that third celebration to reveal it to a journalist, and that journalist, in the event that they run it in a significant outlet, they’ll then use that journalist’s reporting to subpoena the knowledge that was hacked and use it in a court docket case or related.

Now, I ought to stress that is unlawful.

I am utilizing this as a basic instance of one thing that legal professionals and others have talked me via and stated, that is one thing that everybody thinks different persons are doing, and everybody says they, in fact, would by no means contact and by no means do.

Which is what cellphone hacking was like in journalism again within the day. Everybody stated they did not do it, however they knew individuals who did.

GRAHAM CLULEY

However even when it wasn’t us, even when it wasn’t a Suno rival who was behind this, it could possibly be merely somebody who would not just like the slop which Suno is producing, is in opposition to the taking away of labor from legit musicians and inventive varieties, and needs to have an effect.

And I am positive you, like myself, have been approached by hacking gangs prior to now who’ve stated, we have this information, we have stolen this info, are you able to publicise this?

We predict this can be a good story. And there are a lot of —

JAMES BALL

I’ve used it typically. I imply, primarily you take a look at the general public curiosity of the disclosure versus the very fact you do not know the supply and the supply’s motivations.

This was the factor I type of thought, effectively, is that this some company espionage? It would not look state to me. Is that this precisely that type of ideological hack? Supposedly not, although.

In a type of pretty underwhelming line, buried fairly deep within the story, the hacker instructed 404 Media that they had no particular motivation for hacking Suno, and stated, “I prefer to hack something and all the things.” Now perhaps that is true, or perhaps that is cowl, you already know.

It’s a intelligent hack, they’ve used their entry, and many others., however they’ve largely used one thing off the shelf that somebody may seize and play with, you already know.

There’s not a cause that this needs to be tremendous subtle or numerous folks, however they don’t seem to be claiming any ideological motivation right here.

However I assumed it was a very fascinating one as a result of it trod on a number of pink buttons all of sudden.

So I feel as effectively, no matter their motivation, it would find yourself pulled into the continuing lawsuits as a result of how may it not?

GRAHAM CLULEY

Nicely, that is the factor, is not it? Is that this going to be additional unhealthy information for Suno, this been launched, do you assume?

JAMES BALL

Sure, I imply, I assume that they’ve recognized that this type of lawsuit will come from the get-go.

And it is all about battle the case to try to get the most effective phrases you may after which use it to chop a deal on your future relationship. You recognize, do they take an possession stake?

Do you give you licensing phrases? As a result of presumably your eventual mannequin can be Suno Music getting distributed alongside conventional artists.

GRAHAM CLULEY

However this can be a garbage technique to do enterprise, is not it?

Is to commit what a few of us would think about to be against the law or to commit one thing which seems unethical, you already know, which is grabbing another person’s music and utilizing it to feed and create your individual music.

After which, effectively, we’ll do this now as a result of sooner or later someday we’ll come to some enterprise relationship or we’ll come to some understanding which is able to make it acceptable.

However by that point we’ll have constructed our enterprise up sufficient.

JAMES BALL

Yeah, however it’s how the whole AI trade has constructed itself. So, you already know, we are able to say it is skeezy and it is unethical, however yeah, it is morally doubtful.

There’s perhaps no good guys on this story.

JAMES BALL

Possibly the nice guys are the large file corporations. Everybody loves them. They’ve by no means completed something dodgy.

GRAHAM CLULEY

Oh yeah, they’re nice.

JOE

This week’s episode is supported by NordLayer.

GRAHAM CLULEY

NordLayer. And earlier than anybody says something, no, it is not NordVPN.

JOE

I wasn’t going to say that.

GRAHAM CLULEY

You have been completely going to say that.

GRAHAM CLULEY

They’re each from Nord Safety, however NordLayer is a very totally different product. NordVPN is for people. NordLayer is a community safety platform constructed for companies. Proper.

JOE

So what does NordLayer really do?

GRAHAM CLULEY

Nicely, take into consideration how your workforce works right now. Folks logging in from residence, from resort Wi-Fi, from espresso retailers, from wherever.

JOE

From a solar lounger, hopefully.

GRAHAM CLULEY

You would be fortunate. And the second somebody logs into an organization community over an unsecured connection, you’ve got acquired an issue. Credentials intercepted, phishing assaults, unauthorised entry.

It is a scary world on the market for travelling staff.

JOE

So NordLayer fixes that.

GRAHAM CLULEY

It offers you encrypted connectivity on your entire workforce from anyplace, as much as 1 gigabyte per second, with zero further {hardware} required.

However it goes effectively past simply encrypting the connection.

You get centralised management over who can entry what based mostly on their identification, their system, whether or not their system is definitely compliant.

And if somebody leaves the corporate, you revoke their entry instantly.

JOE

No extra ex-employees nonetheless wandering round your methods 6 months later.

GRAHAM CLULEY

No extra of that. And it’ll block malicious websites, dangerous downloads, harmful domains, and it may well even detect shadow apps.

So if somebody in your workforce has began utilizing some AI device that your safety workforce hasn’t accepted—

GRAHAM CLULEY

Yeah, effectively, no matter. NordLayer can spot that too. And there is no advanced infrastructure to arrange. Apparently you might be up and working in nearly 10 minutes.

GRAHAM CLULEY

10 minutes. Plans begin from simply $8 per consumer monthly. And proper now there’s a summer time sale. New prospects rise up to twenty% off annual plans till the tip of August 2026.

Use the code NLSUMMER26 at checkout.

JOE

Whoa, all I’ve to do is kind in that code at nordlayer.com/smashing and I can get an important deal? Let me write that down.

GRAHAM CLULEY

Yep, go forward, write it down.

JOE

What is the code once more? I forgot.

GRAHAM CLULEY

Oh, Joe. NLSUMMER26.

JOE

Obtained it. Off to nordlayer.com/smashingigo.

GRAHAM CLULEY

And because of NordLayer for supporting the present. And welcome again, and also you be part of us for our favorite a part of the present, the a part of the present that we prefer to name Choose of the Week.

Choose of the Week.

JAMES BALL

Choose of the Week.

GRAHAM CLULEY

Choose of the Week is the a part of the present the place everybody chooses one thing they like.

Could possibly be a shaggy dog story, a ebook that they’ve learn, a TV present, a film, a file, a podcast, an internet site, or an app, no matter they want.

It would not should be safety associated essentially. Nicely, my Choose of the Week this week is just not safety associated.

This final weekend I had the prospect to see a one-woman play on the Bristol Previous Vic, and it so occurs I’m an enormous fan of Nina Simone, the music of Nina Simone.

I feel she was unbelievable. Unbelievable, and her music continues to be. And the play I noticed was a one-woman play known as Black Is the Color of My Voice.

And an American actor known as Afia Campbell is the author and performer of the present, which sees her as Nina Bordeaux. She’s not Nina Simone.

She’s Nina Bordeaux, presumably for authorized causes.

JAMES BALL

A legally distinct particular person, sure.

GRAHAM CLULEY

Sure, so it seems the efficiency was impressed by Nina Simone. It is about this lady who may be very expert at taking part in the piano from a younger age.

It is a life formed by racism and civil rights and Martin Luther King and all this stuff are crossing over into her life.

Anyway, Afia Campbell, she would not play the piano, however she sings, and there’s a musical accompaniment as effectively in the course of the efficiency.

She weaves in a few of Nina Simone’s actually stunning, haunting songs. I Loves You Porgy, Wild Is the Wind. They’re all within the narrative as effectively. It is about an hour and 1 / 4 lengthy.

I actually, actually favored it. It was spellbinding. It acquired your consideration. The music clearly was band-bloody-tastic. It is on tour.

And if that feels like your type of factor, go and test it out. Hyperlink within the present notes. So, Black Is the Color of My Voice is my decide of the week.

JAMES BALL

That sounds moderately fantastic. Mine’s presumably just a little extra lowbrow. However I am not ashamed of that.

Netflix have launched the second season of their live-action Avatar: The Final Airbender. Oh sure. Which has had very combined critiques from followers.

There was famously a horrible Avatar film about 10, 15 years in the past that I feel is among the most panned films of all time. The fandom hated it, the casuals hated it too.

GRAHAM CLULEY

This is not the James Cameron Avatar film. That is The Final Airbender. The Final Airbender.

JAMES BALL

Sure. Proper. So it is based mostly on this 3 seasons animated. It was type of within the Pokémon period the place everybody was very into anime.

And it was type of broadly considered top-of-the-line type of youngsters anime collection of all time. So this stay motion season, everybody praises the actors.

You recognize, these are actual kids appearing. And apparently the SFX are good, however, you already know, it is totally different. It is stay motion. It is making an attempt to be a bit extra grownup.

I feel it is making an attempt to get individuals who watched the cartoon as a child. And they also’ve been pretty combined.

Anyway, all of this made me realise I might by no means watched the precise authentic collection. Oh, okay. You recognize, I used to be just a little bit outdated for it when it was out. However I really like that type of factor.

I used to be too outdated for the Pokémon cartoon. They have been type of enjoyable background in the event you’re working or no matter.

And so I have been working my means via these, the unique animated Avatar: The Final Airbender.

And actually, in the event you’ve acquired a type of 8, 9, 10-year-old, sit down and watch it with them.

Or in the event you’ve simply acquired the mind of a kid like I do, have it on when you do one thing else. It isn’t emotionally taxing, however they’re effectively plotted. They’re effectively structured.

They’re 20 minutes lengthy an episode. You recognize that the story completes, it is 3 seasons and completed. It is beautiful. And I can see why folks cherished it. It is a actually good present.

So Avatar: The Final Airbender, the newest advice anybody provides you with for that, I am positive.

GRAHAM CLULEY

Okay, however you’re recommending the animated collection, not the stay motion. Not the stay motion.

JAMES BALL

I’ll most likely strive the stay motion, however I assumed, you already know what, why do not I am going to the one everybody agrees is nice? And I am going to make my very own judgment concerning the stay motion later.

However yeah, I can see why folks fell in love with the animated one.

GRAHAM CLULEY

Improbable. Nicely, that almost wraps up the present for this week. Thanks a lot, James, for coming alongside.

I am positive a lot of our listeners would love to search out out what you are as much as and observe you on-line. What’s one of the simplest ways to try this?

JAMES BALL

I’m @jamesrball.com on Bluesky. I am on the similar internet handle. You could find me within the New World Journal or the i Newspaper or about 6 different locations.

GRAHAM CLULEY

And Smashing Safety is on social media as effectively. You’ll be able to observe it on Blue Sky, on Reddit, on Mastodon. It’s also possible to discover me, Graham Cluley, on these locations or on LinkedIn.

And remember to make sure you by no means miss one other episode of Smashing Safety. Discover it in your favorite podcast apps akin to Spotify, Pocket Casts, and Apple Podcasts.

For episode present notes, sponsorship information, visitor checklist, and the whole again catalogue of 477 episodes, take a look at smashingsecurity.com. Till subsequent time, cheerio, bye-bye, farewell.

You’ve got been listening to Smashing Safety with me, Graham Cluley.

A giant, massive due to James Ball for becoming a member of us this week and to this episode’s sponsors, NordLayer, Vanta, and Arctic Wolf.

Go and take a look at their providers and merchandise, why do not you? And likewise to the next wonderful people who’re amongst our incredible Smashing Safety patrons.

So choosing some out of the hat at random, we begin with Matt H and Alvin. Additionally massive due to Yuri Taraday and to the letter J, simply the letter J, single letter.

Best patron we’ve ever encountered. Extraordinary dedication to brevity there. Thanks, Jay.

Thanks additionally to Jessica Orth and Alboros, who stays as delightfully mysterious as ever. And to Lisa, who continues to show that one title is greater than enough.

Cheers additionally to Dan H, who acquired barely additional than a single letter like Jay, but additionally saved issues admirably concise. And to David Smythe, or is it Smith? I do not know.

Both means, it is a strong sounding title if I ever heard one. And at last for this week, Marvin 71. Marvin, we’re nonetheless questioning concerning the different 70 Marvins.

Possibly you may get them to enroll as effectively.

These are only a few members of Smashing Safety Plus, which signifies that they get their episodes ad-free and sooner than most of the people.

And naturally, they’ll have names pulled out at random to be mercilessly mocked on the finish of the present.

If you want to affix Smashing Safety Plus, simply head over to smashingsecurity.com/plus for the entire particulars. Now, you can even help the present in different methods.

You’ll be able to like, you may subscribe, you may go away a 5-star evaluation. All that’s actually appreciated. And do inform your folks concerning the podcast too.

Go on, go and bash them on the pinnacle with a balloon. That is fairly painless as a result of each little bit helps, and also you spreading the phrase actually does assist me.

Till subsequent time, cheerio, bye-bye.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles