The Hackle Box

The Hackle Box

By The InfoSec MissionTechnology
Download on the App Store

The Hackle Box episodes

  • Incident Response Horror Stories
    The guys are back for a special, Friday the 13th episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

    This time around, we're getting in the spooky spirit and telling scary stories from real-life IR cases. 🎃

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    55 min
  • Scattered Spider - The MGM Hackers, InfoSec News
    Oscar and Pinky are back for this month's session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

    DISCUSSED THIS MONTH:
    Scattered Spider (MGM attack)
    https://hackdojo.io/articles/E59P05LKQ/-scattered-spider-behind-mgm-cyberattack-targets-casinos

    Caesers confirms ransomware
    https://hackdojo.io/articles/73WL5VP9N/caesars-confirms-ransomware-hack-stolen-loyalty-program-database

    MGM hackers branching out
    https://hackdojo.io/articles/AEWED5DK7/mgm-hackers-broadening-targets-monetization-strategies

    UNC3944 Smishing Ransomware
    https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware

    LastPass iOS vulnerability (BLASTPASS)
    https://hackdojo.io/articles/AEWEDLDK7/blastpass-government-agencies-told-to-secure-iphones-against-spyware-attacks

    Follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    59 min
  • DEFCON 31, EvilProxy, QR Code Credential Theft, AI Stealing Passwords
    Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

    Discussed this month
    • DEFCON Recap

    • EvilProxy campaign
      • https://www.techrepublic.com/article/evilproxy-phishing-attack/

    • QR Codes used for credential theft
      • https://www.darkreading.com/attacks-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company

    • AI stealing passwords, listening to keystrokes
      • https://www.darkreading.com/attacks-breaches/ai-model-can-replicate-password-listening-to-keystrokes

    Follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    1 hr
  • Hacklebox/Unsecurity Crossover: MOVEit, Microsoft Patch Tuesday, and Fortinet Infinity
    This month, we're doing a crossover episode with the Unsecurity Podcast!

    For those who are not yet aware, Unsecurity is another FRSecure podcast focused on the business impact of current events and happenings within the security industry. It's hosted several times a month by Oscar and Brad Nigh, FRSecure's Principal Information Security Consultant.

    Discussed this month:
    • MOVEit Attacks
    • Microsoft Patch Tuesday: Six 0-Days
    • Fortinet Infinity
    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    54 min
  • Dragos Incident, Do's and Don'ts of SIEM Implementation
    Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

    Discussed this month
    Do's and don'ts of SIEM implementation

    The recent Dragos incident
    https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/



    Please follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    58 min
  • 3CX Supply Chain Attack, Windows 0-Day, Yum! Brands
    Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

    Discussed this month:

    Windows zero-day exploited in the wild https://projecthyphae.com/threat/windows-zero-day-being-exploited-in-ransomware-attacks/

    3CX Supply Chain Attack https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html

    No evidence of…oh wait, your data was stolen (Yum! Brands breach) https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/

    Patch quick hits

    Adobe: https://www.cisa.gov/news-events/alerts/2023/04/11/adobe-releases-security-updates-multiple-products

    Apple: https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-update-iphones-macs-by-may-1st/

    Cisco: https://www.cisa.gov/news-events/alerts/2023/03/23/cisco-releases-security-advisories-multiple-products

    Fortinet: https://www.cisa.gov/news-events/alerts/2023/04/11/fortinet-releases-april-2023-vulnerability-advisories

    Microsoft: https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/

    SAP: https://www.bleepingcomputer.com/news/security/sap-releases-security-updates-for-two-critical-severity-flaws/

    Follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    48 min
  • Security News Roundup
    This week, Oscar and Brad sit down to catch up on all the latest in security news.

    Links:

    The Sound of Silence Critical Microsoft Outlook Vulnerability https://projecthyphae.com/threat/the-sound-of-silence-critical-microsoft-outlook-vulnerability/

    Fastest Ransomware Encryption in History
    https://gbhackers.com/rorschach/

    'Operation Cookie Monster': International police action seizes dark web market https://www.reuters.com/world/uk/operation-cookie-monster-international-police-action-seizes-dark-web-market-2023-04-05/

    Check your hack
    https://www.politie.nl/en/information/checkyourhack.html

    Send any questions, comments, or feedback to [email protected]. Don't forget to like and subscribe!
    35 min
  • The Rise of Exfil-Only Ransom Attacks, & New Threats
    Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

    Discussed this month:

    Microsoft Word vulnerability goes public
    https://projecthyphae.com/threat/microsoft-word-vulnerability-goes-public-users-wondering-if-a-rtf-means-risky-text-file/

    Emotet is back (again) after another hiatus
    https://www.darkreading.com/threat-intelligence/emotet-resurfaces-yet-again-after-three-month-hiatus

    Security concerns over employees feeding ChatGPT sensitive data
    https://www.darkreading.com/risk/employees-feeding-sensitive-business-data-chatgpt-raising-security-fears

    Follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    1 hr
  • Developer Pleads Guilty to Hacking His Own Company
    Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

    Discussed this month:

    Developer pleads guilty to hacking his own company https://www.theverge.com/2023/2/3/23584414/ubiquiti-developer-guilty-extortion-hack-security-breach-bitcoin-ransom

    Google plagued with 'malvertisers' in January 2023 https://arstechnica.com/information-technology/2023/02/until-further-notice-think-twice-before-using-google-to-download-software/

    Follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    58 min
  • Rackspace Ransomware, 98 Microsoft Patches, & More
    Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, security breaches, and exploits.

    Discussed this month:
    Rackspace Ransomware Incident Highlights Risks of Relying on Mitigation Alone https://www.darkreading.com/vulnerabilities-threats/rackspace-ransomware-incident-highlights-risks-mitigation-alone

    Attackers Are Already Exploiting ChatGPT to Write Malicious Code https://www.darkreading.com/attacks-breaches/attackers-are-already-exploiting-chatgpt-to-write-malicious-code

    98 Patches: Microsoft Greets New Year With Zero-Day Security Fixes https://www.darkreading.com/vulnerabilities-threats/microsoft-new-year-patches-98-security-fixes

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecureofficial/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    54 min

About The Hackle Box

From the publisher's feed

The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security…