TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    Hacking Humans

    Deception, influence, and social engineering in the world of cyber crime.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    OWASP security logging and monitoring failures (noun) [Word Notes] May 27, 2025
    Show notes

    Please enjoy this encore of Word Notes.

    The absence of telemetry that could help network defenders detect and respond to hostile attempts to compromise a system.


    Scam me once. May 22, 2025
    Show notes

    This week, our three hosts ⁠⁠Dave Bittner⁠⁠, ⁠⁠Joe Carrigan⁠⁠, and ⁠⁠Maria Varmazis⁠⁠ (also host of the ⁠⁠T-Minus⁠⁠ Space Daily show) are sharing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Listener Jim notes that money launderers and couriers mentioned in recent episodes are often scam victims themselves, unknowingly processing fraudulent payments or delivering items, sometimes with tragic consequences like an innocent Uber driver being shot. Dave shares two close calls with scams this week: one where a bank employee saved a 75-year-old customer from losing $9,000 to a Facebook crypto scam, and another where a scammer impersonating “Officer Shane Kitchens” nearly tricked his mom into sending $3,500 for fake bail and ankle monitor fees after a family member was arrested. Joe's got three short stories this week—one is on how someone tried scamming his wife, another about a DoorDash driver who admitted to stealing $2.5 million in a delivery scam, and the last on a warning to billions of Gmail users to remain vigilant over a terrifying new phishing scheme. Maria sits down with Alex Hall, Trust and Safety Architect at Sift, to discuss the rise of job scams. Our catch of the day comes from Jonathan who writes in with a fake PayPal invoice.

    Resources and links to stories:

    • You all saved my customer today
    • Loved one got arrested, next day got a call from a “Sergeant” at the county jail.
    • DoorDash driver admits to stealing $2.5M in delivery scam
    • Billions of Gmail users warned to 'remain vigilant' over terrifying scam

    Have a Catch of the Day you'd like to share? Email it to us at ⁠⁠⁠⁠hackinghumans@n2k.com⁠⁠⁠⁠.


    OWASP identification and authentication failures (noun) [Word Notes] May 20, 2025
    Show notes

    Please enjoy this encore of Word Notes.

    Ineffectual confirmation of a user's identity or authentication in session management.

    CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/owasp-identification-and-authentication-failure⁠

    Audio reference link: “⁠Mr. Robot Hack - Password Cracking - Episode 1⁠.” YouTube Video. YouTube, September 21, 2016.


    The band is finally back together. May 15, 2025
    Show notes

    And....we're back! This week, our three hosts Dave Bittner, Joe Carrigan, and Maria Varmazis (also host of the T-Minus Space Daily show) are all back to share the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. The team shares three bits of follow-up and then breaks into their stories. Joe starts off sharing some stories about influencer fakery on fake private jet sets and a scam taking advantage of the RealID requirements coming into effect. Maria talks about "Scam Survivor Day" (it's a real thing). She also talks about a former Facebooker's tell-all "Careless People." Dave shares a story about fake Social Security statements. Our Catch of Day comes from Richard about a truck win.


    Resources and links to stories:

    • Private Executive Jet
    • Private Jet Set for exhibitions, events and photo opportunities
    • REAL ID scams surge with arrival of deadline Wednesday
    • Don't Blame the Victim: 'Fraud Shame' and Cybersecurity
    • Facebook Allegedly Detected When Teen Girls Deleted Selfies So It Could Serve Them Beauty Ads
    • Beware of Fake Social Security Statement That Tricks Users to Install Malware

    Have a Catch of the Day you'd like to share? Email it to us at ⁠⁠⁠hackinghumans@n2k.com⁠⁠⁠.


    Log4j vulnerability (noun) [Word Notes] May 13, 2025
    Show notes

    Please enjoy this encore of Word Notes.

    An open source Java-based software tool available from the Apache Software Foundation designed to log security and performance information.

    CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/log4j⁠

    Audio reference link: “⁠CISA Director: The LOG4J Security Flaw Is the ‘Most Serious’ She’s Seen in Her Career⁠,” by Eamon Javers (CNBC) and Jen Easterly (Cybersecurity and Infrastructure Security Director) YouTube, 20 December 20 2021.


    What’s inside the mystery box? Spoiler: It’s a scam! May 08, 2025
    Show notes

    As Dave Bittner is at the RSA Conference this week, our hosts ⁠⁠Maria Varmazis and ⁠⁠Joe Carrigan⁠⁠, are sharing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow-up from José on episode 335, sharing how UK banking features like Faster Payments and the “Check Payee” function might have helped prevent a scam involving fake banking apps—and he even tells a wild tale of someone using a fake app to reverse-scam a bike thief. Joe covers the House’s overwhelming passage of the SHIELD Act to ban revenge porn—including deepfakes—and why critics say it could threaten encryption. He also shares a strong warning about trust and the real risks of sharing intimate images. Maria has the story of a surge in sophisticated subscription scams, where cybercriminals use fake “mystery box” websites, social media ads, and influencer impersonations to trick users into handing over credit card data and signing up for hidden recurring payments. Bitdefender researchers warn these polished scams are part of a broader evolution in social engineering, designed to bypass skepticism and evade detection. Our Catch of the Day comes from listener Rick, who received a suspicious email that appears to be from Harbor Freight—a popular U.S. retailer known for affordable tools and equipment—offering a “free gift” to the recipient… classic bait for a likely scam.

    Resources and links to stories:

    • ⁠House Passes Bill to Ban Sharing of Revenge Porn, Sending It to Trump
    • TAKE IT DOWN Act
    • Trump’s hasty Take It Down Act has “gaping flaws” that threaten encryption
    • Congress Passes TAKE IT DOWN Act Despite Major Flaws
    • Mystery Box Scams Deployed to Steal Credit Card Data

    Have a Catch of the Day you'd like to share? Email it to us at ⁠⁠hackinghumans@n2k.com⁠⁠.


    The RMM protocol: Remote, risky, and ready to strike. [OMITB] May 06, 2025
    Show notes

    Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠Selena Larson⁠, ⁠Proofpoint⁠ intelligence analyst and host of their podcast ⁠DISCARDED⁠. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by ⁠N2K Networks⁠ ⁠Dave Bittner⁠ and our newest co-host, Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Quintel.

    Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, our hosts discuss the growing trend of cybercriminals using legitimate remote monitoring and management (RMM) tools in email campaigns as a first-stage payload. They explore how these tools are being leveraged for data theft, financial fraud, and lateral movement within networks. With the decline of traditional malware delivery methods, including loaders and botnets, the shift toward RMMs marks a significant change in attack strategies. Tune in to learn more about this evolving threat landscape and how to stay ahead of these tactics.


    OWASP broken access control (noun) [Word Notes] May 06, 2025
    Show notes

    Please enjoy this encore of Word Notes.

    Software users are allowed access to data or functionality contrary to the defined zero trust policy by bypassing or manipulating the installed security controls.


    The prince, the pretender, and the PSA. May 01, 2025
    Show notes

    As Maria is on vacation this week, our hosts ⁠Dave Bittner⁠ and ⁠Joe Carrigan⁠, are sharing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Joe and Dave are joined by guest Rob Allen from ThreatLocker who shares a story on how a spoofed call to the help desk unraveled into a full-blown cyber siege on MGM Resorts. Joe’s story is on a new FBI warning: scammers are impersonating the Internet Crime Complaint Center (IC3), the very site where people go to report online fraud. Dave's got the story of a so-called “Nigerian prince” scammer who turned out to be a 67-year-old man from Louisiana, now facing 269 counts of wire fraud for helping funnel money to co-conspirators in Nigeria. Our catch of the day comes from a scams subreddit, and is on a message received from the Department of Homeland Security reaching out to a user to share that they are a victim of fraud.

    Resources and links to stories:

    • Investigating the MGM Cyberattack – How social engineering and a help desk put the whole strip at risk.
    • Brian Krebs LinkedIn
    • FBI Warns of Scammers Impersonating the IC3
    • IC3 2024 Report
    • 'Nigerian prince' scammer was 67-year-old from Louisiana, police say

    Have a Catch of the Day you'd like to share? Email it to us at ⁠hackinghumans@n2k.com⁠.


    OWASP security misconfiguration (noun) [Word Notes] Apr 29, 2025
    Show notes

    Please enjoy this encore of Word Notes.

    The state of a web application when it's vulnerable to attack due to an insecure configuration.

    CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/owasp-security-misconfiguration⁠

    Audio reference link: ⁠“What Is the Elvish Word for Friend?”⁠ Quora, 2021.


    Previous 1 14 15 16 17 18 82 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights