In the latest episode of the Smashing Security podcast, hosts Graham Cluley and Danny Palmer discuss an unusual hijack: Microsoft’s X account, which has 13 million followers, was taken over by a paperclip—specifically, Clippy. The attack involved no ransomware or data theft; instead, the intruders used the account to push a dodgy cryptocurrency and later posted a corporate apology that apparently did not come from Microsoft.

The episode also highlights a sharp rise in account-takeover scams in the UK. Losses from hacked email and social media accounts have jumped 417%, with scammers impersonating victims’ friends to sell tickets to concerts that don’t exist. The trend shows how trust in social connections is being weaponised for financial fraud.

In a featured interview, Hack The Box’s Christine Bartlett raises a question for security teams now incorporating AI agents: should these autonomous workers receive performance reviews like human hires? The discussion suggests that as AI agents handle the same systems and shifts as people, organisations need to appraise them against realistic cybersecurity work—and reassess as models, tools, and environments change.