The Hackle Box

The Hackle Box

By The InfoSec MissionTechnology
Download on the App Store

The Hackle Box episodes

  • New CISA Reporting Rule, Russian Attacks on Ukrainian Orgs, & More.
    Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    Discussed this month:

    Russian Actors Use Compromised Healthcare Networks Against Ukrainian Orgs
    https://www.darkreading.com/threat-intelligence/russian-actors-compromised-healthcare-networks-ukrainian-orgs

    Malware Authors Inadvertently Take Down Own Botnet
    https://www.darkreading.com/attacks-breaches/malware-authors-inadvertently-takdown-own-botnet

    All You Need to Know About Emotet in 2022
    https://thehackernews.com/2022/11/all-you-need-to-know-about-emotet-in.html

    What the CISA Reporting Rule Means for Your IT Security Protocol
    https://thehackernews.com/2022/12/what-cisa-reporting-rule-means-for-your.html

    Rackspace Ransomware Attack Outage
    https://www.bleepingcomputer.com/news/security/rackspace-confirms-outage-was-caused-by-ransomware-attack/

    Report: Air-Gapped Networks Vulnerable to DNS Attacks
    https://www.darkreading.com/attacks-breaches/report-air-gapped-networks-vulnerable-dns-attacks

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    56 min
  • VMware Bugs & Remote Workspaces, Long Island Midterms Delayed, & More.
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    Discussed this month:

    Critical Citrix, VMware Bugs threaten remote workspaces
    https://www.darkreading.com/vulnerabilities-threats/patch-asap-critical-citrix-vmware-bugs-remote-workspaces-takeover

    Long Island midterm votes delayed due to cyberattack
    https://www.darkreading.com/attacks-breaches/long-island-midterm-votes-delayed-due-to-cyberattack-after-effects

    Microsoft Exchange vulnerability update

    Healthcare sector: Security threat landscape update

    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    1 hr 1 min
  • Fortinet Authentication Bypass, ProxyShell 2 (or 3?), and More!
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    Discussed this month:

    Fortinet Authentication Bypass
    ZeroDay: ProxyShell 2 (or 3?)
    Microsoft Addresses Zero-Days, Exchange Server Exploit Chain Remains Unpatched
    Phishing Attacks Improving Dramatically
    Emotet is Back

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    1 hr 1 min
  • Defcon Recap, EvilProxy, TeslaGun, Broken Ice Cream Machines
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month's episode includes:
    Defcon Recap
    EvilProxy
    TeslaGun
    Broken Ice Cream Machines and McDonalds

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    54 min
  • The Hackle Box July 2022: NPM All Over the News, APT Targeting Healthcare Sector, and More
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month's episode includes:

    NPM supply chain attack impacts hundreds of websites and apps
    https://www.bleepingcomputer.com/news/security/npm-supply-chain-attack-impacts-hundreds-of-websites-and-apps/

    PyPi sending stolen AWS keys to unsecured sites
    https://www.bleepingcomputer.com/news/security/pypi-python-packages-caught-sending-stolen-aws-keys-to-unsecured-sites/

    NPM packages involved in crypto mining
    https://thehackernews.com/2022/07/over-1200-npm-packages-found-involved.html

    CISA alert for North Korean APT targeting the healthcare sector
    https://www.cisa.gov/uscert/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware

    https://thehackernews.com/2022/07/north-korean-maui-ransomware-actively.html

    Microsoft Edge WebView2 manipulated for cookie theft
    https://projecthyphae.com/threat/microsoft-edge-webview2-manipulated-for-theft-of-cookies/

    Criminals are filling job applicant pools with deepfakes
    https://projecthyphae.com/threat/criminals-are-filling-tech-job-applicant-pools-with-deepfakes/

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    55 min
  • The Hackle Box June 2022: Atlassian Confluence, Follina, Chinese Attackers Breach Telcos, and More
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month's episode includes:

    02:14 Atlassian Confluence – CVE-2022-26134
    https://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html

    13:25 Follina
    https://threatpost.com/follina-exploited-by-state-sponsored-hackers/179890/

    32:40 Paid a ransom? Now you’re a target.
    https://threatpost.com/paying-ransomware-bullseye-back/179915/

    47:30 Chinese State Attackers Breached Telcos
    https://www.bleepingcomputer.com/news/security/us-chinese-govt-hackers-breached-telcos-to-snoop-on-network-traffic/

    52:50 Kali team offering free penetration testing course on Twitch!
    https://www.bleepingcomputer.com/news/security/kali-linux-team-to-stream-free-penetration-testing-course-on-twitch/

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    57 min
  • The Hackle Box May 2022: F5-Big IP, Fileless Malware Hides Shellcode in Windows Event Logs, and More
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    56 min
  • The Hackle Box April 2022: Fake Emergency Data Requests, Critical Spring4Shell Vulnerability, & More
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month's episode includes:

    - Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests”
    - Forged Signatures: Not Just For Troubled Youths Anymore. #Nvidia
    - Sophos firewalls require an URGENT new flame shield
    - CISA Warns of Active Exploitation of Critical Spring4Shell Vulnerability

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    54 min
  • The Hackle Box March 2022: AutoWarp Vulnerability, APC Burning Down, Dirty Pipe Exploit
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month's episode includes:

    - AutoWarp vulnerability in Microsoft Azure
    - APC's Burning Down
    - Dirty Pipe
    - Russian Attack on Ukraine

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    1 hr
  • The Hackle Box February 2022: EyeMed Breach, Data Exfil Using PowerAutomate, Google MFA.
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month's episode includes:

    - EyeMed fined $600k in data breach
    - Attackers reviving a 20-year-old tactic in Microsoft 365 phishing campaigns
    - Google auto-enables two-step verification for more than 150 Million users
    - A new tactic for data exfil using Power Automate in Microsoft 365

    Please like, subscribe, and follow us on social!

    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    59 min

About The Hackle Box

From the publisher's feed

The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security…