Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
ID: 487d9df6-bd6c-5b19-8ee9-e8b0c0c5141c
STIX ID: report--487d9df6-bd6c-5b19-8ee9-e8b0c0c5141c
Feed Name: Graham Cluley
This podcast episode reviews three distinct security concerns: (1) targeted social-engineering calls impersonating police to extract cryptocurrency seed phrases from hardware-wallet users; (2) Microsoft/ReliaQuest-reported APT29 'Captive Crunch' campaign that compromises hotel Wi‑Fi captive portals/DNS to serve ClickFix social-engineering lures and deploy Cornflake RAT and ChocoShell info‑stealer (exfiltrating M365 tokens and credentials); and (3) a data-exfiltration/extortion incident against the UK Department for Education by a group called Exfil Squad, exposing ~600,000 help-desk records and demanding payment. The episode mixes incident descriptions, impacted sectors (diplomats, government, education), and mitigation advice (use full-tunnel VPNs, avoid installing unknown software, treat captive-portal prompts with suspicion).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
