The Hackle Box

The Hackle Box

By The InfoSec MissionTechnology
Download on the App Store

The Hackle Box episodes

  • The Hackle Box January 2022: Log4j, Russian Cyber Threat, AV Cryptominers, Patch Tuesday
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month, the trio dives into:

    • Log4j Overview and updates
    • CSA advisory on Russian Cyber Threat to US Critical Infrastructure.
    • Norton and Cryptominers in your AV
    • Patch Tuesday: 96 patches to start 2022

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure/
    Twitter: https://twitter.com/frsecure/
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure/
    57 min
  • The Hackle Box December 2021: Microsoft Exchange Exploit, FBI Website Hack, QuakNightmare
    Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

    This month, the trio dives into:

    • Cyber Actors Exploiting Microsoft Exchange in Furtherance of Malicious Activities
    • FBI Website exploited resulting in hoax email blast
    • Quakbot strikes again with QuakNightmare Exploitation

    In addition to the newsworthy topics, they also have a couple of recurring segments:

    Phishing Report - ACH Fraud in Proxylogon attack chain
    Hacker Tip of the Month

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure
    Twitter: https://twitter.com/FRSecure
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frse...
    1 hr
  • The Hackle Box November 2021: Holiday Phishing Scams, SolarWinds Fallout, Microsoft Exchange, Ryuk
    Oscar, Eric, and Pinky are back with another session of the Hackle Box, a series where they break down current cybersecurity threats, breaches, vulnerabilities, and more. This month, the trio discusses:

    Phishing Report – Holiday Phishing Trends
    Hacker Tip of the Month

    News Topics:

    ‘Trojan Source’ Bug Threatens the Security of All Code
    https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/

    FBI Raids Chinese Point-of-Sale Giant PAX Technology
    https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/

    Microsoft Fixes Exchange Server Zero-Day
    https://www.darkreading.com/vulnerabilities-threats/microsoft-s-nov-security-update-contains-fix-for-exchange-server-0-day

    SolarWinds Vulnerability Exploited in First Stage of Clop Ransomware Attacks
    https://www.darkreading.com/attacks-breaches/rise-in-clop-ransomware-attacks-tied-to

    Researcher Details Vulnerabilities Found in AWS API Gateway
    https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway

    RYUK is back!
    https://thedfirreport.com/2020/10/08/ryuks-return/
    https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/

    QR Codes Help Attackers Sneak Emails Past Security Controls
    https://www.darkreading.com/attacks-breaches/qr-codes-help-attackers-sneak-emails-past-security-controls

    Please like, subscribe, and follow us on social!
    Facebook: https://www.facebook.com/frsecure
    Twitter: https://twitter.com/FRSecure
    Instagram: https://www.instagram.com/frsecure/
    LinkedIn: https://www.linkedin.com/company/frsecure
    57 min
  • The Hackle Box October 2021: REBOL Yell, Microsoft Going Password-less, OMIGOD, Microsoft Azure
    Team Ambush members Oscar, Eric, and Pinky are back with another session of the Hackle Box—a series where they break down new and noteworthy breaches, vulnerabilities, exploits, and more over the last month.

    This month's topics:

    Microsoft going “passwordless”
    https://arstechnica.com/gadgets/2021/09/starting-today-you-can-remove-your-password-from-your-microsoft-account/

    OMIGOD—an exploitable hole in Microsoft open-source code
    https://nakedsecurity.sophos.com/2021/09/16/omigod-an-exploitable-hole-in-microsoft-open-source-code/

    New Azure Active Directory password brute-forcing flaw has no fix
    https://arstechnica.com/information-technology/2021/09/new-azure-active-directory-password-brute-forcing-flaw-has-no-fix/?amp=1

    Does your organization have a Security.txt file?
    https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/

    CISA releases tool to help orgs fend off insider threat risks
    https://www.bleepingcomputer.com/news/security/cisa-releases-tool-to-help-orgs-fend-off-insider-threat-risks/?utm_content=182136940&utm_medium=social&utm_source=twitter&hss_channel=tw-71605818

    The REBOL Yell—novel exploit using REBOL for command-and-control
    https://frsecure.com/blog/the-rebol-yell-new-rebol-exploit/

    Teasing Project Hyphae

    As always, the session ends with the Hacker Tip of the Month from Eric and the Phishing Report with Pinky.

    Give this session a watch or listen, and feel free to send any comments, questions, or topic suggestions to [email protected].

    And please like and subscribe!
    1 hr 2 min
  • The Hackle Box September 2021: IDN Phishing, Razer Mouse, T-Mobile, Cobalt Strike, and OAuth 2.0
    The boys are back with another session of the Hackle Box. This month features in-depth discussion on four vulnerabilities/exploits that have gained the attention of Oscar, Pinky, and Eric over the last month or so.

    IDN Phishing — Outlook emails showing legitimate contact cards from lookalike domains
    https://arstechnica.com/information-technology/2021/09/microsoft-outlook-shows-real-persons-contact-info-for-idn-phishing-emails/

    Razer Mouse Bug — The bug allows admin privileges in Windows 10
    https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/

    T-Mobile Breach — 48 million social security numbers accessed from a pool of 50 million affected customers
    https://www.zdnet.com/article/t-mobile-hack-everything-you-need-to-know/

    Hacking the Hackers — New exploit available for download lets hackers crash Cobalt Strike team servers
    https://arstechnica.com/gadgets/2021/08/critical-cobalt-strike-bug-leaves-botnet-servers-vulnerable-to-takedown/

    As always, the session ends with the Hacker Tip of the Month from Eric and the Phishing Report with Pinky.

    Give this session a watch or listen, and feel free to send any comments, questions, or topic suggestions to [email protected].

    And please like and subscribe!
    59 min

About The Hackle Box

From the publisher's feed

The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security…