The Cybersecurity Podcast with Fexingo: Hacks, Breaches, and Digital Defense Conversations

The Cybersecurity Podcast with Fexingo: Hacks, Breaches, and Digital Defense Conversations

By FexingoBusiness
Download on the App Store

The Cybersecurity Podcast with Fexingo: Hacks, Breaches, and Digital Defense Conversations episodes

  • How Hackers Abuse Cloud APIs to DDoS Your Business

    Lucas and Luna dive into a fast-growing threat: API-based distributed denial-of-service attacks. They explain how attackers weaponize cloud APIs to amplify traffic, using real cases like a 2025 attack hitting 2.5 Tbps, and why companies like Cloudflare and Amazon are scrambling to respond. The hosts link this to market moves: SentinelOne up 1.3% this week, Cloudflare surging 11% over five days, and Palo Alto Networks down 8.9% — a signal that the security landscape is shifting. They also break down why traditional DDoS defenses fail against API-specific 'low-and-slow' floods. Specific, grounded, no fluff.

    #APIsecurity #DDoS #CloudSecurity #Cybersecurity #Technology #Cloudflare #SentinelOne #PaloAltoNetworks #AWS #CloudAPIs #LowAndSlow #TrafficAmplification #NetworkSecurity #FexingoBusiness #BusinessPodcast #Hacking #ZeroDay #ThreatIntel

    Keep every episode free: buymeacoffee.com/fexingo

    9 min
  • How AI Deepfakes Are Hijacking Your Trusted Contacts

    Lucas and Luna investigate a growing threat in 2026: deepfake voice and video cloning used to impersonate trusted contacts—colleagues, family members, even CEOs. Lucas explains how attackers scrape voicemail, social media clips, and conference recordings to generate convincing impersonations in real time, then uses them to bypass verbal verification and authorization. He cites a recent incident where a finance manager approved a transfer after hearing what sounded exactly like the CFO's voice on a call. Luna notes that traditional MFA and security training don't cover this vector, and they discuss why tools like digital signing and pre-arranged verbal passphrases are becoming necessary. Lucas ties it to the broader market trend: shares of identity-focused cybersecurity firms like Okta and Cloudflare have jumped over 8% in the last week as investors price in this new attack surface. The episode closes with practical advice on establishing a simple family code word for out-of-band verification.

    #Deepfake #VoiceCloning #SocialEngineering #CyberAttack #CFOImpersonation #MFA #Okta #Cloudflare #CybersecurityPodcast #Technology #FexingoBusiness #BusinessPodcast #ZeroTrust #DigitalSigning #Verification #Passphrase #InBand #OutOfBand

    Keep every episode free: buymeacoffee.com/fexingo

    9 min
  • How a Stolen Session Cookie Beat Your MFA

    Lucas and Luna dig into the session cookie hijacking that's making multi-factor authentication almost useless. With Palo Alto Networks down 1.2% while Zscaler jumps 5.9% and Cloudflare 9.6% this week, the market is betting hard on zero-trust architecture — but most companies still rely on cookie-based sessions that a single phishing link can steal. Lucas walks through how an August 2025 breach at a major identity provider exposed 14 million session tokens, why Okta's 8.8% gain this week reflects investor panic around a different vulnerability, and what 'token binding' actually means. Luna asks the obvious question: if MFA is broken, what replaces it? They cover passkeys, device-bound sessions, and the uncomfortable truth that users are still the weakest link.

    #SessionHijacking #MFABypass #CookieTheft #ZeroTrust #Cybersecurity #Technology #Infostealers #TokenBinding #Passkeys #Cloudflare #Zscaler #PaloAltoNetworks #Okta #IdentitySecurity #CyberInsurance #FexingoBusiness #BusinessPodcast #TheCybersecurityPodcast

    Keep every episode free: buymeacoffee.com/fexingo

    9 min
  • How Hackers Are Using Stolen Session Cookies to Bypass MFA

    Episode 96 of The Cybersecurity Podcast with Fexingo. Lucas and Luna dive into the rising threat of session cookie theft — a technique that lets attackers bypass multi-factor authentication entirely. They break down how a recent attack on a major tech firm used infostealer malware to grab active browser cookies, then replay them to hijack cloud accounts. Lucas explains why this is different from traditional credential theft, how tools like 'cookie cleaner' scripts offer partial defense, and why companies like CrowdStrike and Okta are racing to implement 'token binding' standards. With Okta shares up 13% in the past week and CrowdStrike gaining 7.4%, the market is pricing in a shift toward identity-centric security. Luna questions whether the industry is over-relying on MFA as a silver bullet. The episode ends with a brief, sincere note about listener support.

    #SessionCookies #CookieTheft #MFA #MultiFactorAuthentication #Infostealer #TokenBinding #Okta #CrowdStrike #CyberAttack #IdentitySecurity #CloudSecurity #Technology #Cybersecurity #IdentityTheft #FexingoBusiness #BusinessPodcast #TheCybersecurityPodcast #DigitalDefense

    Keep every episode free: buymeacoffee.com/fexingo

    8 min
  • How Hackers Are Weaponizing Your Calendar Invites

    Lucas and Luna dive into a fast-growing attack vector that most professionals overlook: calendar-based phishing. They break down how attackers are exploiting calendar invites from services like Google Calendar, Outlook, and Calendly to bypass email security filters and trick victims into clicking malicious links. Lucas shares a recent case from a mid-sized law firm that lost $340,000 after a partner accepted a fake meeting request. Luna points to data showing a 240% increase in calendar-based phishing since mid-2025, citing research from a security firm. They connect the trend to the broader rise in API-based attacks and discuss what individuals and IT teams can do to defend against it. The conversation is grounded in the current market environment, with mentions of strong cybersecurity stock performance including CrowdStrike, Palo Alto Networks, and Okta.

    #CalendarPhishing #CyberAttack #Phishing #GoogleCalendar #Outlook #Calendly #CyberSecurity #APIExploit #SocialEngineering #Ransomware #CrowdStrike #PaloAltoNetworks #Okta #IncidentResponse #ZeroTrust #Technology #FexingoBusiness #BusinessPodcast

    Keep every episode free: buymeacoffee.com/fexingo

    8 min
  • How Hackers Turn Your Abandoned Subdomain Into a Weapon

    Episode 94 of The Cybersecurity Podcast examines the growing threat of subdomain takeover attacks, where hackers register expired domains linked to legitimate companies and use them to deploy malware, phishing pages, and credential theft. Lucas and Luna break down how this works, why it's surging in 2026, and why recent security stock gains in CrowdStrike, Palo Alto Networks, and Zscaler reflect investor fear over attack surface expansion. They discuss a real-world case where a Fortune 500 energy company's forgotten subdomain led to a ransomware deployment, and explain why average enterprises have thousands of subdomains they can't track. The episode also ties in how the Trump memecoin collapse and Amazon's Mechanical Turk shutdown signal broader internet hygiene problems. A concrete, actionable look at a vulnerability that's cheap for attackers and expensive for defenders.

    #SubdomainTakeover #CyberAttack #DNSHijacking #AttackSurface #CyberSecurity #Technology #CrowdStrike #PaloAltoNetworks #Zscaler #Fortinet #Okta #Cloudflare #Ransomware #DanglingDNS #InfrastructureSecurity #FexingoBusiness #BusinessPodcast #CyberDefense

    Keep every episode free: buymeacoffee.com/fexingo

    12 min
  • How Hackers Are Using QR Codes to Empty Bank Accounts

    QR codes are everywhere – restaurant menus, parking meters, event tickets. But in 2026, they've become a primary vector for a new wave of phishing attacks. Cybersecurity researchers at Zimperium report a 340% increase in 'quishing' attacks since January, with over 45,000 unique malicious QR code campaigns detected globally in Q2 alone. Lucas and Luna break down how a single scan can compromise your phone's data, bypassing traditional email filters and SMS authentication. They examine the technical exploit – malicious QR codes that redirect to fake login pages mimicking major banks and payment apps – and explain why even security-conscious professionals are falling victim. The episode also covers what the cybersecurity industry is doing to counter this threat, including new browser-level protections and real-time URL scanning in camera apps. Plus, a look at how stocks like CrowdStrike and Palo Alto Networks have surged as enterprises rush to deploy next-gen endpoint protection against these attacks. A practical episode for anyone who's ever scanned a code without thinking.

    #Quishing #QRCodePhishing #Cybersecurity #Zimperium #CrowdStrike #PaloAltoNetworks #Phishing #CyberAttack #EndpointProtection #MobileSecurity #Technology #Business #CyberDefense #SecurityAwareness #2026 #FexingoBusiness #BusinessPodcast #CybersecurityPodcast

    Keep every episode free: buymeacoffee.com/fexingo

    8 min
  • How Hackers Are Using Your Smart TV to Breach Your Home Network

    Episode 92 of The Cybersecurity Podcast examines a growing threat: hackers exploiting smart TVs as entry points into home networks. Lucas and Luna break down how attackers leverage vulnerabilities in apps, firmware, and outdated protocols to pivot from your TV to your laptop or phone. With recent market surges for cybersecurity stocks like CrowdStrike (up 10.7% in five days) and Palo Alto Networks (up 14.4%), they discuss whether the smart home security market is ready for the challenge. They also explore real-world examples from 2026, including a hotel chain breach traced to smart TVs in guest rooms, and offer practical tips for securing your connected devices. Plus, a brief note on why listener support keeps the show ad-free.

    #SmartTV #Cybersecurity #HomeNetwork #IoT #Hacking #CyberAttack #CrowdStrike #PaloAltoNetworks #Zscaler #OKTA #Technology #Podcast #FexingoBusiness #BusinessPodcast #Episode92 #NetworkSecurity #SmartHome #Privacy

    Keep every episode free: buymeacoffee.com/fexingo

    7 min
  • Hackers Are Co-opting Your Neighbor's Wi-Fi for Crimes

    Episode 91 of The Cybersecurity Podcast digs into a rising trend: residential proxy hijacking. Lucas and Luna break down how attackers are using compromised home routers and IoT devices to route illicit traffic through unsuspecting homeowners' IP addresses. The episode anchors on the 14.4% weekly surge in Palo Alto Networks stock, tying the market move to growing enterprise demand for botnet detection tools. Lucas explains the technical mechanics — from default credentials to malware that co-opts smart bulbs — while Luna challenges whether vendors are doing enough to secure consumer gear. A concrete case: a 2025 attack on a Midwest credit union traced back to 40 home routers in a single suburb. The hosts debate liability, regulation, and the uncomfortable reality that your neighbor's unsecured device might be laundering cybercrime. No alarmism, just the facts and what they mean for network defenders.

    #ResidentialProxy #Botnet #HomeRouterSecurity #IoTSecurity #CyberCrime #PaloAltoNetworks #PANW #Cybersecurity #NetworkSecurity #ProxyHijacking #SmartHome #CyberAttack #FexingoBusiness #BusinessPodcast #Technology #ThreatDetection #Infosec #SecurityOperations

    Keep every episode free: buymeacoffee.com/fexingo

    7 min
  • Hackers Are Exploiting the Internet of Medical Things to Access Hospital Networks

    Episode 90 of The Cybersecurity Podcast dives into the rapidly growing threat of medical device hacking. Lucas and Luna explore how attackers are targeting connected hospital equipment—from infusion pumps to MRI machines—to gain entry into healthcare networks. They discuss the 2025 ransomware attack on a major US hospital chain that started with a compromised blood gas analyzer, and the unique challenges of securing devices that can't be patched during the day. With cybersecurity stocks like CrowdStrike and Palo Alto Networks up double digits this week, they examine why healthcare remains a prime target and what the industry is doing about it. Specific examples include the FDA's new cybersecurity guidance for medical device manufacturers and the role of network segmentation in containing breaches. A must-listen for anyone interested in the intersection of healthcare and cybersecurity.

    #MedicalDeviceHacking #HealthcareCybersecurity #IoMT #Ransomware #HospitalSecurity #InfusionPumpHack #FDA #CrowdStrike #PaloAltoNetworks #CRWD #PANW #NetworkSegmentation #Hackers #DataBreach #Technology #Cybersecurity #FexingoBusiness #BusinessPodcast

    Keep every episode free: buymeacoffee.com/fexingo

    8 min

About The Cybersecurity Podcast with Fexingo: Hacks, Breaches, and Digital Defense Conversations

From the publisher's feed

Every week, Lucas and Luna sit inside a dimly lit security operations centre — Lucas at a bank of monitors crawling with packet-by-packet traffic maps, Luna leaning in from the shadows — to parse the most consequential cyber events of the past seven days. They do not chase headlines for their own sake. Instead they isolate a single breach, vulnerability disclosure, or regulatory action and walk through the technical root cause, the financial damage (named companies, actual dollar figures), and the organisational failure that allowed it. When a ransomware attack hits a hospital chain, they trace the initial access vector, the ransom demand, the insurance payout, and the post-incident SEC filing. When a zero-day surfaces in a widely deployed VPN appliance, they explain which types of organisations are exposed and what the patch cycle actually looks like from a CISO's perspective. The show is built for cybersecurity professionals who want analysis that respects their expertise, for investors who need to understand cyber risk in their portfolio, and for executives who are tired of being sold fear and want calibrated, data-backed context. Each episode ends with Lucas and Luna disagreeing on a single point — the cost of non-compliance, the effectiveness of a particular framework, the likelihood of the vulnerability being exploited at scale — and they leave that tension unresolved. The question you'll carry away: what did the CISO in that breached company know, and when did she know it?