logo

Smashing Security podcast #469: What your Oura ring won’t tell you

ID: 8bcf99a8-618e-5318-bba4-56d64387d337

STIX ID: report--8bcf99a8-618e-5318-bba4-56d64387d337

Feed Name: Graham Cluley

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Graham Cluley

...
...

This podcast episode reviews several security issues: a significant CISA-related data leak where a contractor publicly posted plaintext credentials (including privileged AWS GovCloud tokens) on a GitHub account after disabling secret-scanning, raising supply-chain and credential-rotation concerns; reporting on unencrypted or potentially exposed data from Oura wearable devices and attendant privacy/government-request transparency issues; and brief mentions of active malware campaigns (HimWolf IoT botnet, Ghost CMS compromises). The hosts emphasize operational failures, cultural and staffing problems at security agencies, and the importance of deterministic protections (e.g., content sanitization/CDR) to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.