Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft’s Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn’t from Microsoft either.
Meanwhile, UK losses from hacked email and social media accounts have rocketed by 417%, as scammers pose as your friends to flog you tickets to gigs that don’t exist.
Plus, Hack The Box’s Christine Bartlett joins us for a featured interview to ask what happens when AI agents join your security team, and whether anyone has thought to give them a performance review.
All this and more in episode 487 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.
0:00
0:00
Show full transcript
▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
My name’s Graham Cluley.
Thanks to everyone who listens to the show for their kind words as I took a week off recently in order to undergo a house move.
So it wasn’t possible to do the podcast and move house and change cities at the same time.
This was, oh gosh, 25, 30 years ago or so. And he was driving me around London and I thought, oh, that’s an interesting radio programme.
It appears that he’s listening to an episode of Dad’s Army.
And I looked over at him and I saw that he actually had balanced on top of his steering wheel where the speedometer was or whatever.
He actually had one of those mini televisions with an aerial and he was bloody well watching TV while driving me around. Some friend he turned out to be.
Anyone who’s watching the video will be able to see, yes, got the all-important bookshelf, sufficiently blurred out so you can’t see that it’s mostly Doctor Who books and Doctor Who videos and the occasional chess book as well.
Well, before we kick off, let’s thank this week’s wonderful sponsors, HackTheBox, Origin, and Vanta. We’ll be hearing more about them later on in the podcast.
Plus, we’re also going to be joined by Christine Bartlett of Hack The Box for a featured interview. All this and much more coming up in this episode of Smashing Security.
Somewhere in your security team, right now, there’s a worker who’s never slept, never taken a holiday, never once said, I’ll leave this until Monday.
You’ve landed in the ocean. You survived the impact, that’s great.
What they’re forgetting, of course, is that he sings. And in this particular case, Michael Bublé is gonna sing at you constantly.
He’s not gonna utter a single word without a big band arrangement in the background.
Now he’s going to explain to you at some length, and without being asked of course, why the island would be better with a V8 engine.
He’ll also almost certainly tell you that he didn’t get any A-levels and it didn’t do him any harm. So which island are you going to go to?
I can see a raft floating past, captained by none other than Piers Morgan. And he’d like a word. In fact, he’d like several words. He’s gonna ask you some questions.
He’s probably gonna interrupt your answer. He’ll call it a debate. He’ll also probably try to insert himself into any breaking news story.
So do you stay with your first choice, Michael Bublé, or do you swim away and join Piers Morgan on his raft?
And you’re stuck now between two other islands. Now, on one island, you’ve got Elon Musk, you know, a wonderful person, very, very intelligent apparently.
He owns a social media platform. He’s got ignorant opinions about everything. Probably want you to have nine children with them. On the other island, however, is Clippy.
Which one would you choose?
It’s very weird. It was made in about 2016 before he changed his personality.
And it’s quite weird looking back at it and seeing how Lisa Simpson, of all people, is fawning over him, which I don’t think she would now.
If you were one of Microsoft’s 13 million followers, you may have noticed something odd because they changed their avatar on Twitter.
Their profile picture changed to Clippy, the paperclip that spent much of the late ’90s interrupting your Word documents to tell you that it looked like you were writing a letter.
I think we all thought Clippy had gone into the wilderness, but it turns out the little blighter is back.
But he’s not actually acting as a Microsoft mascot — he is acting as a crypto grifter.
So that account, which they shared the post of, it was called Clippy MSFT — I think like Microsoft CTO was posing as Clippy itself, as though Clippy was the CTO of Microsoft.
Meanwhile, a second account was busy flogging a Clippy Coin, claiming its liquidity was paired with the Microsoft stock price, which may have made some people think that it was somehow connected to Microsoft’s actual stock, which obviously it wasn’t.
Now, things get a little bit weirder still.
Things became stranger because round about half an hour after the account posted this message, a very sensible, very corporate apology was posted on Microsoft’s Twitter account.
And it said that Microsoft knew about this token using the Clippy brand without permission. You know, so it was saying, you know, this cryptocurrency has nothing to do with us.
They said that they don’t back any cryptocurrency whatsoever. But then, to everyone’s surprise, the apology from Microsoft vanished itself without any explanation.
And it turns out, because Microsoft later confirmed it, that not only was all the Clippy nonsense not from Microsoft, but the apology wasn’t from them either.
It’s like, oh, well, we’ll try and get a little bit more out of this. But no, the apology was completely straight-faced. There wasn’t any dodgy link about it.
There wasn’t any dubious call to action which people had to take. It just wasn’t from Microsoft.
Now, whether this was the hackers thinking, we could be in a spot of bother here, or whether they were planning to later post some further messages still posing as Microsoft, I don’t know.
It’s really, really bizarre. I can’t imagine why they might have done it. Do you have any theories?
But yeah, the way this has been deleted, either Microsoft saw that and got rid of it, or yeah, the attackers deleted it themselves for some reason, which is unusual.
Frankly, I mean, that should have been the giveaway. Since when has a tech company ever apologised for anything?
But what they decided was that they were just going to go with a paperclip. No ransomware, no data theft, no phishing, just a paperclip and an apology.
And we still don’t know how they actually hacked into that account. Microsoft hasn’t said anything.
I mean, it could have been one of their social media managers was phished maybe, or it could be a SIM swap. It could be a hijacked email address used for a password reset.
It could be info-stealing malware that had stolen a session cookie, so no password or MFA prompt was ever needed.
It could have been a third-party social media tool that was breached. Could be a security screw-up at Twitter itself. I mean, that has happened.
So the thing is, this is Microsoft and their account was still taken over by what looks like a paperclip plugging a crypto coin. And I think maybe that’s the lesson for all of us.
If you ever think it couldn’t possibly happen to me, it can happen to anybody at all. Even some of the biggest brands in the world.
I mean, I don’t know how much money they make, but I guess they must make something from these because they still keep doing it.
And I guess they’re more likely to get an instant return on that rather than sneaking around trying to drop malware or ransomware and that sort of thing.
And I suppose in some ways there’s less technical knowledge required to pimp a crypto coin than there is to create a piece of ransomware, even though there are sort of roll-your-own malware kits these days.
And obviously AI has made some of these things easier and democratised cybercrime in some fashions, even if you’re not a complete nerd. But yeah, strange days indeed.
Audit evidence scattered like ash in the wind. I’ve filled out the same questionnaire 4 times this week, Graham.
No more manual evidence chasing, no more questionnaire hell. It continuously monitors your systems and keeps you audit-ready. For SOC 2, ISO 27001, HIPAA, GDPR, the works.
And it uses AI. Yes, Joe, it does.
I’m talking about cybercriminals and malicious hackers because yes, it’s October, which means it’s Cybersecurity Awareness Month.
And I’m sure your good self and anyone who listens to Smashing Security, as you say, is probably thinking about cybersecurity all year round.
But for many, October marks the time of year when organisations remember they have to teach their employees about this thing called cybersecurity.
And even the government gets involved with the likes of the National Cyber Security Centre going on a big push to provide advice to individuals on how to stay safe online against the ghoulish threat of various nefarious types trying to use the internet to commit crimes.
Imagine using the internet for evil — who could think of such a thing?
So to mark Cybersecurity Awareness Month, Report Fraud, which is the national cybercrime and fraud reporting service — which is weirdly run by the City of London Police — has released some new figures on how cybercrime has affected people over the last year.
And Graham, it does not make for very fun reading at all.
So this report puts the figure for the financial year 2025–2026 at £6.3 million compared to £1.2 million for the previous year.
And this is based around attacks against individuals — this isn’t companies, this is attacks against people.
No one’s had £6 million stolen in one go, as far as we’re aware, but all the little different petty crimes, I suppose you could call them, they add up.
So the email hacking, as we know, isn’t any sort of new thing, but it just seems that the tactics that these scammers are using over the last years have become super effective.
Or maybe people are reporting it a bit more because, as the paper hints at, that 6.3 million figure might only be the tip of the iceberg because a lot of these crimes go unreported.
If someone, for example, had £100 stolen from them from an attacker, they might not go to the police about it because there are likely to be many victims out there who haven’t reported this because they might be embarrassed they’ve fallen victim to a scam, or they might think, yeah, it’s only 100 quid, it’s not worth reporting.
But like the crypto scams you spoke about, stack together a bunch of smaller threats and they all eventually add up.
What’s going on here is, to make this more effective, in many cases the scammers are hijacking people’s social media accounts and email addresses and using them to directly target their unsuspecting friends and family.
You know, taking control of Facebook accounts, Instagram accounts, that sort of thing.
And according to the report, one of the most common scams criminals are using to steal money in these attacks is to claim that the person they have stolen the account of has tickets to a sold-out event they can no longer attend.
So they’re offering, hey, I can’t attend this event.
But there are no tickets available, and the friend or family member paying for these is just sending their money straight to the attacker’s bank account.
And in many cases, I guess people won’t even realise something’s wrong until a bit of time after the fact going, oh, why didn’t you send me those tickets? What tickets?
There was an instance of this last year where The Guardian newspaper reported a woman had her Instagram account hacked by scammers who used her identity and her profile to advertise tickets to one of the sold-out Oasis gigs of last year.
And they used this hacked account with these fake tickets to get a total of £1,400 from her friends, which seems to suggest that it wasn’t just one of her friends they targeted with this.
Several of her friends saw this post saying, oh, I’ve got tickets for this Oasis gig available.
They thought they had the monopoly on that particular scam, but now what you’re telling me is the cybercriminals have come in and they’re now making cash out of Oasis too.
What is worrying about this as well is that the victim said that the attackers managed to impersonate her so well in the messages and posts that her friends and family genuinely thought they were speaking to her when this was happening.
Other commonly successful tactics deployed by scammers to steal money in this way include using fraudulent texts and WhatsApp messages or emails to claim to be a family member in some sort of trouble that needs urgent money.
I even get them saying the message is going, oh, hi, it’s your daughter — I don’t have one — so you’re barking up the wrong tree here, but I can see why it works.
I was at a neighbour’s being given beans on toast because I’ve just moved and we couldn’t get to any cooking equipment because of the cardboard boxes and exercise bike and things like that.
And so she said, oh, we’ll do you some beans on toast. And while we were there, she got a text claiming to come from her daughter saying that she was in trouble.
This clearly happened so often to her that she instantly knew it was nonsense and that it wasn’t really her daughter. At least I hope that was the case rather than she ignored it.
And there’s also cases where it seems to be increasingly common, particularly in the last month, where scammers are using the prospect of phony job offers to lure people into giving away money or private information, which either directly steal money from people or steal their social media accounts.
I mean, this type of scam has been all over the UK for the last few weeks. I don’t know about you, but I’m having 3 or 4 calls a day from an unknown number.
These guys, when they’re doing it, they try to get you off your phone onto another platform for more information and to steal money that way.
That has become such a common attempt at a scam that it might even backfire because the general public is so aware of this scam going around at the moment that they are talking about it.
People are focusing on their social media accounts about it.
The old one’s the best, I suppose you could say. And it’s understandable because the reason social engineering works is because it manipulates the emotions of the victim.
They may really think that a family member is in trouble, or a trusted friend is selling tickets to a gig they really want to go to, or they’re in desperate need of work and they take a punt on the opportunity, even if it comes from an unknown number, because they’re looking for work.
And I think it’s also important to remember this isn’t just about the financial figures. Each person who falls victim to a scam like this takes an emotional hit.
They may get upset about falling victim to a scam. They may feel ashamed, which is why it doesn’t get reported.
I’ve even heard stories of people working within the cybersecurity industry who have fallen victim or almost fallen victim to these types of scams.
They often share these stories as they want people to hear about them and know what to look out for.
But sometimes I think there can be the attitude that if you’re falling for these, it’s on your own back. But these attackers are very smart and manipulative.
They know what they’re doing. It’s their job. They’re experts at it.
So if we’re in a world where people who live and breathe cybersecurity can even be trapped by these, I sometimes wonder how members of the public are supposed to cope.
And it’s probably worth sharing this information with your friends and family in terms of how to help stop these.
A lot of these are things people will know, but I think it’s just helpful to remind people what they should be thinking about.
If you’re unsure, contact them through another route, be it a phone call, an SMS, in person, maybe.
The police and the NCSC says use passkeys when they’re available.
There’s been a big push in the last year or so, especially from the NCSC, to get more public knowledge about that system of securing accounts.
And if that isn’t possible, combine multifactor authentication with a strong, unique password. And obviously a password manager can help with that.
They also provide some advice on how to go about your business online.
If you post on your public Instagram that you’ve got tickets for a concert, cybercriminals might be looking for that sort of information to use as the basis of their scam.
Maybe think about your privacy settings in terms of who can see your online account. Does everyone on the internet need to see where you live or who your family members are?
Because I think for most people, you don’t need to be super public-facing unless you’re maybe a celebrity or something. I don’t know.
But it’s just that if your account is anyway public-facing, you just need to have a think about, is it worth the risk for those few extra likes?
It can be difficult out there in the wild west of the internet. But you can make yourself more protected against cyber threats.
While listeners to Smashing Security might be aware of these issues, perhaps use Cybersecurity Awareness Month to remind your friends and families to take care of themselves online.
Agents talking to each other, dividing the work between themselves, leaving notes for one another in the dark where no human was watching.
If an AI agent caused an incident at your company tomorrow, what evidence could you actually produce?
The commands it ran, the files it touched, the credentials it helped itself to, all of it gone. But not anymore, because there is a sensor.
What it asked, what it reached, what it changed, laid out in order, start to finish.
No cloud gateway, no blind spot. Origin is already there.
And welcome back, and you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.
Could be a funny story, a book that they’ve read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they wish. Doesn’t have to be security-related necessarily.
Well, I took a week off from the podcast because I was moving house, but just before that, I managed to squeeze in a trip to Switzerland.
We’ve all seen that amazing looking hotel where all the incredibly evil people who rule the world hang out once a year. Like Davos. Yeah, Davos probably was there.
So I said, yes, of course I’m going to go and do that. Why wouldn’t I do that?
But it was only after I said yes to this speaking opportunity that I thought, hang on, how do I actually get to Davos?
And it turned out the people organising an event, they said, it’s really easy. They said, you fly into Zurich Airport.
So for me, it was a bit complicated and a bit stressful. Is this going to work? Am I going to show up at the right place at the right time? And it made me a bit nervous.
But Danny, I can report to you, I was wrong because it was a breeze.
In Britain, 20 minutes late is considered early for a train. So it was marvellous. It was brilliant. I love the trains. They have double-decker trains in Switzerland as well.
But all of the station clocks in Switzerland, they are synchronised with each other to the second.
There is an electric pulse that is sent down a phone line or whatever every minute.
And the beautiful thing, if you are on a platform in a Swiss railway station, go and check out the clocks because the second hand is going round as you expect.
You’ve seen a clock before, right, Danny?
Well, in Switzerland, it takes 58 seconds for one of these clocks’ second hands to go round the entire way, and then it stops for a couple of seconds.
It waits for the pulse to come from HQ, and then tick, the minute hand moves on one position, goes one step.
If you do miss a train in Switzerland, it’s because you’re watching the clocks because they move in this fascinating style.
So anyway, my Swiss railway journey was absolutely lovely. The views were beautiful.
Even the bus replacement service, and I’ve never said these words before in my life, even the bus replacement service was all right.
They could have a little badge on the side of their trains now saying, as endorsed by Smashing Security’s pick of the week.
And the game The Witcher 3 came out over a decade ago now.
Since then, it’s gone on to quite successful IP, I suppose you can call it, in its own right, with all the books have been translated into English.
The guy who played Superman was the, Henry Cavill was Geralt to start with, but then he moved away from the series and they got another actor in to play Geralt, which is kind of weird, especially he’s not a guy who regenerates like certain other characters might do.
So this week, The Witcher 3 Remastered came out on new consoles. So basically they’ve updated this 10, 12-year-old video game for modern times.
The controls are a bit better, the graphics look better, UIs have been all changed, and the most interesting thing is the company behind The Witcher, CD Projekt Red, have just released this for free.
It’s a whole brand new update to the full game and it’s free. So it’s like, okay, fine, I’ll have some of that.
Weirdly, they’re also going to be introducing a brand new expansion, I think next year, which is not really something you’ve heard of happening.
If that’s their plan, well, it’s worked on me because I’ve dived back into the world of The Witcher.
It’s very — the actual original novels are very steeped in old Eastern European fairy tales, because the writer is Polish.
And essentially the premise of The Witcher series is you’re a modified human, essentially, with powers to sort of help fight monsters.
And the premise of the game is you’re trying to find a character, Ciri, who’s essentially your daughter. But while you’re doing it, on the way, you take other quests on.
So you go into the village and they say, we’ve got a problem with a werewolf, can you help? And you say, oh, fine, yes, I’ll do that.
It’s very intricate in how you do these battles as well. You go and investigate the scene, find out what the weaknesses are of the enemies. The characters are all really good.
The voice acting’s really good. There’s lots of complex characters as well.
I’ve just run into this guy called the Bloody Baron — I won’t give any spoilers away, but yeah, I’m just enjoying the story. The combat’s really good.
And of course, the key point of the game is it’s one of those games where there’s a game within a game, and it’s actually a card game you can play against other characters in the game.
And I’m addicted to that again as well, which is just so much fun.
And I actually have over on my shelf over there a boxed physical version of that card game, which I haven’t actually played yet.
So unlike in The Witcher, I can’t just go to my local tavern and ask the barman to play cards. So maybe I should try — I don’t know.
But I’d say, yeah, if you’ve already got a copy of The Witcher 3, it’s definitely worth checking out.
And I think in terms of what we’re seeing, it’s an interesting divide out there.
We talk with many different types of enterprise companies, smaller companies, and some are diving into the deep end with AI.
And then there’s the flip side of it where you still need a lot of trust in the system, and deploying these agents or even allowing a lot of AI involvement from your employees opens up a lot of exposure if you’re not ready for it.
So some folks are still heads in the sand and don’t want to deploy anything while others are fully embracing it.
So it’s an interesting dynamic in the industry right now for those of us in technology and cyber.
Why do you think we’re calling these AI agents actually workers?
I use it myself, and even in marketing and cybersecurity there are efficiencies there, but you also need to be trained to use it. I think that’s the difference.
And something that Hack The Box brings is we now have a capability where we have an AI competence score factor.
So it’s not just a checkbox — not just can you complete the task, but how did you complete the task with AI? Did you work within the parameters of how you should use it?
So we do feel like there is a massive workforce transformation that will happen as a result of humans upskilling themselves, frankly, with AI fluency, understanding how AI operates, but then also working alongside and directing AI agents.
But you are saying we should be measuring something different than that.
There’s always training on some level for humans, regardless of industry.
I think it’s even more critical in cybersecurity just because the threats change, the environments change — just a very dynamic industry.
And as a result of that, the training is even more critical in the sense that you can have an environment where you can fail and not be reprimanded for it.
And then when it does happen in real life alongside your teammates, you’re ready to go.
And now AI is another complex tool and opportunity at the same time for cybersecurity operators to move faster. And we know that the adversary’s already using it. They’re moving—
And some of us would be crazy not to embrace it on some level, but you need to embrace it in a way that is still governed and that you’re able to track it.
And so having that ability to uncover and look at whether they know what they’re doing with AI, with and without AI, I think is also important.
And then also, what’s their knowledge base on operating alongside agents and making sure that there’s some governance there? You know, we look at things like agent drift.
So for instance, to your point, you bought an AI tool that is going to do wondrous things for you, but that tool and that agent should have a timeline against it.
Are you assessing its skills and its capability on a monthly or routine basis?
How are you evaluating them just like you would your human workforce with standard check-ins and things like that?
Obviously, not trying to humanise it, but there will be degradation there in the systems, or your environment changes.
So just being able to think through all of that — that’s just a new complex environment that humans need to be trained up on to have a successful deployment.
And I’m thinking particularly of how CISOs are feeling about AI.
There’ll be some companies that are aware of AI and maybe they’re using a bit of ChatGPT or whatever, but there are other organisations who are running large parts of their security using AI.
But where do you think most firms are, if we were going on a scale of 1 to 5, where 5 is they’re letting AI do everything?
We weren’t the AI vendor in the room, but there were some AI vendors probing for these types of answers.
And it was interesting to hear them rate their cybersecurity teams on a 1 to 5, in terms of 1 being just basic exposure — they allow ChatGPT, Claude, Perplexity, whatever, in their workplace — to 5 being an AI factory with autonomous loops within loops, which I would say is more of the extreme case and probably not the norm.
And I think most of them were in between a 2 or a 3, and it’s this kind of unknown grey area that’s extremely hard to define because the technology’s constantly changing.
You know, I think some CISOs are feeling maybe forced or pressured to adopt and change and scale fast, especially probably in more of the tech space, whereas more of the healthcare space, maybe not as aggressively.
But there are some efficiencies that I think CEOs and other senior leaders are starting to see.
And then they’re being pressured either by their board or colleagues as well to have an answer.
It might not be, “Hey, yes, we’ve deployed everything,” but I think the answer is, “Yes, we’re experimenting — and what are you learning from it?” And sharing, having that opportunity to have that dialogue, because we’re all learning literally in real time in this day and age.
And then I think there’s also the AI that they’ve allowed their employees to have access to. That level of visibility isn’t as clear. You know, what are they doing?
How are they learning? How are they using it? Is it successful? Is it not successful in terms of how they’re using it?
I think we all saw, at least for me in the US, Uber, I think in the first 3 months of their annual budget this year, blew through their AI budget because they just let all the employees have it.
And they were like, yes, experience.
But I think, again, that’s where HackTheBox comes in, at least for cybersecurity professionals, to be able to take a look at, and test for how are you using AI and are you trained up in the right ways?
So talking about the risks, I’ve been looking at some of your literature and you sort of focus on these 4 risks that can stay hidden while the dashboards maybe are saying everything is tickety-boo.
And some of these you’ve already touched on. We’ve got automation bias, skill atrophy, the missing middle, and silent agentic drift.
Can you explain what each one of those is in plain English for a middle-aged podcaster?
So automation bias is when you have an automated tool that’s pulling information from, when you’re thinking about either ChatGPT or even an agent that you’ve built, there’s still going to be some complexity.
It’s not going to operate 100% to the capacity that you think it is. So there is going to be some bias or some unknowns that do exist.
Now, maybe some of that is easily spottable, but over time, again, that can cause things like skill atrophy, right?
So now you’re becoming overly reliant on this automation, on this tool. And maybe you’re losing some of that wisdom that you’ve gained.
I call it scar tissue because we live through these challenges and that puts scars on you and you remember those days and then you know not to repeat the same mistakes.
I mean, I worry about junior analysts who use AI maybe from day one and aren’t learning the job the hard way. They’re not gaining that scar tissue.
It is changing how we work, how you work.
But at the same time, are we building out an education layer that’s helping train up those folks coming into the workforce so at least they have some of that knowledge base?
Maybe they’re not experiencing as much as me and you did, but they’re in an environment that’s pressure tested.
It feels like a live-fire exercise that they can maybe mimic some of those wounds that we lived through.
I think that’s really now more important than ever because they probably won’t experience some of those and they won’t have that institutional knowledge right out the gates.
And then the other one that you just mentioned really quickly is the silent agentic drift, right?
Is it still doing what you thought it was going to do? Has your environment changed? Has your network expanded? Does it have that information?
Does it have that full work scope that your employee and your human does?
Because we as humans who’ve been working in this industry know what to look for, know what to stay abreast of.
Some new dynamic element comes into your network that it’s not trained up on, the agent is not going to operate the way that you probably think it will.
I mean, obviously there are many ways in which AI is actually making security teams better and defending organisations. If AI is doing more of the work, what is left for the people?
How’s the poor old human’s job changing?
I think this one feels more dramatic or drastic because it’s like the treadmill that never stops. If you’re on it, you’re having to run at a certain pace.
But I do think for humans, and things that I’ve even shared at Hack The Box, is it’s on us as managers and as people leaders to help our folks get trained up and from an AI fluency level understand the capabilities, understand the good and the bad.
And the reality is wherever you go moving forward, you’re probably going to need some level of skill, especially if you’re in cyber and technology.
You’re going to have to have a baseline education on AI moving forward, especially when you do think about the junior talent coming in as already, quote unquote, AI-pilled.
They’re already coming in, trusting it, leveraging it probably even more successfully than somebody like me in my mid-40s. But I think the reality is the workforce has changed.
You’d be crazy not to learn it on some level, but also understand the good and the bad that goes along with it.
But where Hack The Box really stands tall is just being able to pressure test your skills and abilities in an environment that’s safe, but also allows the AI component and ability to assess your skills alongside using AI and also directing AI.
So you are helping companies train their people, you are running exercises for their teams, you’re testing their AI agents, right?
So those in the SOC teams, an L1, L2, L3, L4 — are you an incident response manager? Are you a threat analyst? We have coursework and curriculum that’s aligned to that.
But you say curriculum and you think, oh, textbook, maybe a couple of YouTube videos, right?
No, this is an actual immersive environment where, yes, you might study the attack structure and the methodology, but then you’re going to open up a lab, which is a live active environment, deploy a pawn box and experience it as if this was happening real time.
We have over 5 million community members because of the education aspect of sharing out there on the interwebs of, hey, I did this module, how did you guys do?
And then they get feedback, people help each other. We have community groups that get together that run through these scenarios to understand tactics and techniques.
And so I think that’s the unique part here is it truly does have a pressure-tested element to it.
And then we also have capture-the-flag activations where you can get a whole team together, benchmark where your team’s at, understand what their performance level is.
As a manager, you would get a report out on, okay, here’s how my team is at today from a skills and abilities perspective.
Maybe there’s a few folks you’re looking to grow or move up into a different role.
That’s also an opportunity to apply them to a workforce skill development journey, and then they’re able to get on that and move up to the next tier of your employment record type of thing, which is great.
The other thing I will share as an example, which I thought was fascinating, is one of our customers, with the advent of AI approaching, this was earlier in the year, there was a SOC manager that was asked to let go of some additional team members.
They were incredibly successful and they got most people up and they were able to save the majority of their workforce.
So I think from that standpoint, there’s momentum there and opportunity if you’re, as a manager or director, to level up your team, especially at a time when management is looking for efficiencies left, right, and centre to cut costs.
For some companies listening, maybe they’ve never really thought about this.
What is the very first step a security team should take to ensure that AI agents are actually making them safer?
I think of exposure first when I hear AI versus safety, but at HackTheBox, we provide that educational layer for your employees to get a baseline of not only just AI fluency, but how to successfully leverage AI or an agent alongside of you as a kind of copilot to complete the challenge or the task at hand.
I think one other thing I would just add is that we did a study based on a CTF that we had over a year ago where we had people sign in with humans, and then people brought along their agents and we compared the data.
And the interesting part was more junior-level analysts that were using AI were stuck in loops with AI.
They didn’t know when AI was just either taking too long or it just didn’t make the right decision for them.
Whereas a much more experienced senior person kind of knew how to deploy the AI, and if they didn’t get what they wanted, they quickly moved on.
And I think that was something we discovered a year ago, and it’s still relevant today.
And so now we provide a training to surface that so that your workforce isn’t stuck in a loop and that they’re using AI in the right capacity to save the company time, but also manage their time effectively for the business as well.
We’ve got a special link which people can follow to learn more and check out your services, and that is smashingsecurity.com/hackthebox.
And all that remains is for me to thank you, Christine Bartlett, for coming on the podcast.
Or follow Smashing Security on Bluesky, Mastodon, or Reddit. And don’t forget to ensure you never miss another episode.
Follow Smashing Security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocket Casts.
The episode show notes, sponsorship info, guest list, and the entire back catalog of 487 episodes — check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
Thank you, of course, to Danny for joining me this week and to the episode sponsors Hack the Box, Origin, and Vanta.
Do go and check out their offerings because they help keep the show afloat.
Plus, big thanks this week to the following patrons whose names are being plucked out of the hat to be mercilessly ribbed.
First out of the hat is Daniel Bourdeau, which is pronounced like the wine region. Presumably he’s just as tasteful. Alan Liska, who has 2 L’s — actually has 3 L’s.
That’s a lot of L’s, Alan. Thank you. Really deluxe edition of you. Dave Barker, no flies on him.
Florian Schwalm, who sounds like a Baroque composer waiting to be dug out from the woodwork. Alex Grrr, actually only one R in Grrr. I’m not sure how you pronounce that, but anyway.
Anyway, a slightly truncated surname, plenty of mystery. Robert Martin, very simple name there. Good one, Bob Martin. No complaints. Dr_Herbalist, the underscore really sells it.
And in the style of a Roman emperor, we have to all hail our last patron to be named this week, which is Orberus. Thank you, Orberus.
These fine, upstanding, and generous individuals are all members of Smashing Security Plus, which means that they get their episodes ad-free earlier than the general public, and perhaps most importantly, get their names read out at the end of the show if they’re lucky enough to be pulled out of the hat.
If you would like to join them, all you have to do is head over to smashingsecurity.com/plus, and for a very modest fee, you too can support the show and say how you love Smashing Security.
Of course, if you haven’t got the cash, no worries, no pressure there. But there are other ways you can support the show. You can follow the show in your favourite podcast app.
You can leave a 5-star review wherever you listen. You can tell your friends about it as well. Why not do that?
Every little bit helps, and frankly, it makes all the effort worthwhile. So until next week, cheerio.
Host:
Graham Cluley:
Guest:
Danny Palmer
Episode links:
Sponsored by:
- Hack The Box – Develop, exercise and measure the capabilities of your human operators and AI agents.
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
- Origin – Endpoint AI observability. Put your AI agent on the record, and request a demo.
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Join Smashing Security PLUS for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.

