<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>The Hackle Box</title><link>https://frsecure.com/cyber-threat-intel-series/</link><description><![CDATA[The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques, vulnerabilities, exploits, and more.]]></description><atom:link href="https://www.spreaker.com/show/5101210/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Technology</category><copyright>Copyright The InfoSec Mission</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg</url><title>The Hackle Box</title><link>https://frsecure.com/cyber-threat-intel-series/</link></image><lastBuildDate>Fri, 08 May 2026 16:56:42 +0000</lastBuildDate><itunes:author>The InfoSec Mission</itunes:author><itunes:owner><itunes:name>The InfoSec Mission</itunes:name><itunes:email>hacklebox@frsecure.com</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:subtitle>The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques,...</itunes:subtitle><itunes:summary><![CDATA[The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques, vulnerabilities, exploits, and more.]]></itunes:summary><itunes:category text="Technology"/><itunes:explicit>false</itunes:explicit><itunes:type>episodic</itunes:type><item><title>The Hackle Box April 2026: EvilTokens, Vuln Management for IoT, FBI Surveillance Breach</title><link>https://www.spreaker.com/episode/the-hackle-box-april-2026-eviltokens-vuln-management-for-iot-fbi-surveillance-breach--71926732</link><description><![CDATA[We're BACK with another live Hackle Box episode to break down what's trending in cyber attacks and incident response. This month, the crew discussed:<br /><ul><li>New Evil Tokens attack and its implications for cybersecurity</li><li>The importance of comprehensive vulnerability management programs for IoT devices</li><li>Insights into the FBI surveillance system breach and what it means for global cybersecurity</li><li>The rise of phishing-as-a-service and how attackers are evolving</li><li>A special shout-out to Matthew Owens for discovering a CVE in IDrive for Windows</li></ul>Tune in for insights on these topics, and the latest trends, tactics, lures, and fixes that our expert cybersecurity team is seeing in real-world exploits and incidents.<br /><ul><li>The Catch of the Month</li><li>The Phishing Report</li><li>Live Q&amp;A</li><li>Guest Speakers</li><li>And more!</li></ul>If you've got burning questions or feedback, we'd be happy to hear from you: <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbnhxeGlVdWNETFN5cU05RW5pOV9NSkFmY2VkZ3xBQ3Jtc0tsM1JGdjZ1V2JvdmRoVVhqcEdOUWxKMnhnR2JpamhWdUJOc1hndGpQUnY4R2d0VUZEeXZWcVFaR3pHX0tITFdmMEtGN0xxSFp4aHN1ejYtbm1MUlFSMjV5VDhwYUszV1lXTWNDMnYxUS1DZVlYTnY3OA&amp;q=https%3A%2F%2Fwww.surveymonkey.com%2Fr%2Fhacklebox&amp;v=BRH1cE6NsiE" target="_blank" rel="noreferrer noopener">https://www.surveymonkey.com/r/hacklebox</a><br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbnNqRlhxX1NTN213UUVTVlVGRGpXRWhzZTVzUXxBQ3Jtc0tsOVdaX3FLUGVmb0U0cDkwaU1GZ3hvRDFmVzhMVzJ2NUJXUnBybjI5THlEU0paZzJQWkRtaWVkQzlLV0syRkFBaXJWUnAtdjV2c3ZkcDljbXRjOXVuVXlkVk9ZSWQwZkpBc2JpR01fYjZSOHlVZGkxaw&amp;q=https%3A%2F%2Ffrsecure.com%2Fcyber-threat-intel-series%2F&amp;v=BRH1cE6NsiE" target="_blank" rel="noreferrer noopener">https://frsecure.com/cyber-threat-int...</a><br /><br />Please like, subscribe, and follow us on social!<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />Facebook: https://www.facebook.com/frsecure/<br />BlueSky: https://bsky.app/profile/frsecure.bsky.social<br /><br />About FRSecure:<br /><a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa0xOajNpcDN4ZXdXa3N0Ri05ekh0Q2VSWkJ3d3xBQ3Jtc0tsbXNWSVd3ejNCY3loSlVtNzVIcGhyaTNsVU5lTUU1ZEtzLXdmWTljbjVoUXAxVHVCWWZ2c1V6ajNCSFhTOFhxR0ctTlRpTXNGMmRyd3RVam1KR0QwQk9QRTdLQnc5ajVrWHNDaWFPdGlsU2lpcE9KOA&amp;q=https%3A%2F%2Ffrsecure.com%2F&amp;v=BRH1cE6NsiE" target="_blank" rel="noreferrer noopener">https://frsecure.com/</a><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br /><br /><br /><br /><br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71926732</guid><pubDate>Fri, 08 May 2026 16:55:59 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71926732/the_hacklebox_april_2026.mp3" length="82873310" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We're BACK with another live Hackle Box episode to break down what's trending in cyber attacks and incident response. This month, the crew discussed:

- New Evil Tokens attack and its implications for cybersecurity
- The importance of comprehensive...</itunes:subtitle><itunes:summary><![CDATA[We're BACK with another live Hackle Box episode to break down what's trending in cyber attacks and incident response. This month, the crew discussed:<br /><ul><li>New Evil Tokens attack and its implications for cybersecurity</li><li>The importance of comprehensive vulnerability management programs for IoT devices</li><li>Insights into the FBI surveillance system breach and what it means for global cybersecurity</li><li>The rise of phishing-as-a-service and how attackers are evolving</li><li>A special shout-out to Matthew Owens for discovering a CVE in IDrive for Windows</li></ul>Tune in for insights on these topics, and the latest trends, tactics, lures, and fixes that our expert cybersecurity team is seeing in real-world exploits and incidents.<br /><ul><li>The Catch of the Month</li><li>The Phishing Report</li><li>Live Q&amp;A</li><li>Guest Speakers</li><li>And more!</li></ul>If you've got burning questions or feedback, we'd be happy to hear from you: <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbnhxeGlVdWNETFN5cU05RW5pOV9NSkFmY2VkZ3xBQ3Jtc0tsM1JGdjZ1V2JvdmRoVVhqcEdOUWxKMnhnR2JpamhWdUJOc1hndGpQUnY4R2d0VUZEeXZWcVFaR3pHX0tITFdmMEtGN0xxSFp4aHN1ejYtbm1MUlFSMjV5VDhwYUszV1lXTWNDMnYxUS1DZVlYTnY3OA&amp;q=https%3A%2F%2Fwww.surveymonkey.com%2Fr%2Fhacklebox&amp;v=BRH1cE6NsiE" target="_blank" rel="noreferrer noopener">https://www.surveymonkey.com/r/hacklebox</a><br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbnNqRlhxX1NTN213UUVTVlVGRGpXRWhzZTVzUXxBQ3Jtc0tsOVdaX3FLUGVmb0U0cDkwaU1GZ3hvRDFmVzhMVzJ2NUJXUnBybjI5THlEU0paZzJQWkRtaWVkQzlLV0syRkFBaXJWUnAtdjV2c3ZkcDljbXRjOXVuVXlkVk9ZSWQwZkpBc2JpR01fYjZSOHlVZGkxaw&amp;q=https%3A%2F%2Ffrsecure.com%2Fcyber-threat-intel-series%2F&amp;v=BRH1cE6NsiE" target="_blank" rel="noreferrer noopener">https://frsecure.com/cyber-threat-int...</a><br /><br />Please like, subscribe, and follow us on social!<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />Facebook: https://www.facebook.com/frsecure/<br />BlueSky: https://bsky.app/profile/frsecure.bsky.social<br /><br />About FRSecure:<br /><a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa0xOajNpcDN4ZXdXa3N0Ri05ekh0Q2VSWkJ3d3xBQ3Jtc0tsbXNWSVd3ejNCY3loSlVtNzVIcGhyaTNsVU5lTUU1ZEtzLXdmWTljbjVoUXAxVHVCWWZ2c1V6ajNCSFhTOFhxR0ctTlRpTXNGMmRyd3RVam1KR0QwQk9QRTdLQnc5ajVrWHNDaWFPdGlsU2lpcE9KOA&amp;q=https%3A%2F%2Ffrsecure.com%2F&amp;v=BRH1cE6NsiE" target="_blank" rel="noreferrer noopener">https://frsecure.com/</a><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br /><br /><br /><br /><br />]]></itunes:summary><itunes:duration>3450</itunes:duration><itunes:keywords>breach,business,cyber,cybersecurity,data,eric_hanson,eviltokens,fbi,frsecure,hacklebox,infosec,iot,management,oscar_minks,phishing,pinky_thompson,privacy,security,surveillance,vulnerabilities</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box March 2026: .arpa, Cybersecurity Strategy for America, Seedworm &amp; Iran, AI Red Team</title><link>https://www.spreaker.com/episode/the-hackle-box-march-2026-arpa-cybersecurity-strategy-for-america-seedworm-iran-ai-red-team--70610413</link><description><![CDATA[We're BACK with another live Hackle Box episode to break down what's trending in cyber attacks and incident response.<br /><br />This month, we're discussing:<br /><ul><li>Hackers abusing .arpa domain to evade phishing detection</li><li>President Trump's Cybersecurity Strategy for America</li><li>Seedworm and Iranian APTs</li><li>Armadin Series A Funding</li></ul>Tune in for insights on these topics, and the latest trends, tactics, lures, and fixes that our expert cybersecurity team is seeing in real-world exploits and incidents.<br /><ul><li>The Catch of the Month</li><li>The Phishing Report</li><li>Live Q&amp;A</li><li>Guest Speakers</li><li>And more!</li></ul>If you've got burning questions or feedback, we'd be happy to hear from you: https://www.surveymonkey.com/r/hacklebox<br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/<br /><br />Please like, subscribe, and follow us on social!<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />Facebook: https://www.facebook.com/frsecure/<br />BlueSky: https://bsky.app/profile/frsecure.bsky.social<br /><br />About FRSecure:<br />https://frsecure.com/<br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br /><br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70610413</guid><pubDate>Thu, 12 Mar 2026 16:10:23 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70610413/the_hacklebox_template_march_2026.mp3" length="82232716" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We're BACK with another live Hackle Box episode to break down what's trending in cyber attacks and incident response.

This month, we're discussing:

- Hackers abusing .arpa domain to evade phishing detection
- President Trump's Cybersecurity Strategy...</itunes:subtitle><itunes:summary><![CDATA[We're BACK with another live Hackle Box episode to break down what's trending in cyber attacks and incident response.<br /><br />This month, we're discussing:<br /><ul><li>Hackers abusing .arpa domain to evade phishing detection</li><li>President Trump's Cybersecurity Strategy for America</li><li>Seedworm and Iranian APTs</li><li>Armadin Series A Funding</li></ul>Tune in for insights on these topics, and the latest trends, tactics, lures, and fixes that our expert cybersecurity team is seeing in real-world exploits and incidents.<br /><ul><li>The Catch of the Month</li><li>The Phishing Report</li><li>Live Q&amp;A</li><li>Guest Speakers</li><li>And more!</li></ul>If you've got burning questions or feedback, we'd be happy to hear from you: https://www.surveymonkey.com/r/hacklebox<br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/<br /><br />Please like, subscribe, and follow us on social!<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />Facebook: https://www.facebook.com/frsecure/<br />BlueSky: https://bsky.app/profile/frsecure.bsky.social<br /><br />About FRSecure:<br />https://frsecure.com/<br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br /><br />]]></itunes:summary><itunes:duration>3424</itunes:duration><itunes:keywords>ai,apts,armadin,.arpa,business,cyber,cyberattack,cybersecurity,exfiltration,frsecure,hacking,hacklebox,infosec,iran,minks,netsec,phishing,seedworm,strategy,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/00658c95057336110ddf50f4c2e4f099.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box Feb. 2026: Notepad++, Microsoft Phishing, Solarwinds, &amp; Ring</title><link>https://www.spreaker.com/episode/the-hackle-box-feb-2026-notepad-microsoft-phishing-solarwinds-ring--70049692</link><description><![CDATA[2026 is off to quite the start! After a New Year's break, we're BACK with another Hackle Box episode to discuss what we've seen so far in the offensive services and incident response sides of the infosec industry! <br /><br />This month, Oscar, Eric, and special guest Matt Findlay discussed:<br /><ul><li>Notepad++ Vulnerabilities</li><li>Phishing from legitimate Microsoft inboxes</li><li>Solarwinds Remote Code Execution</li><li>Ring's New Surveillance Feature</li></ul>Tune in every month for insights on similar topics and the latest trends, tactics, lures, and fixes that our expert cybersecurity team is seeing in the real-world:<br /><ul><li>The Catch of the Month</li><li>The Phishing Report</li><li>Live Q&amp;A</li><li>Guest Speakers</li><li>And more!</li></ul>If you've got burning questions or feedback, we'd be happy to hear from you: https://www.surveymonkey.com/r/hacklebox<br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/<br /><br />Please like, subscribe, and follow FRSecure on social!<br /><br /><br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70049692</guid><pubDate>Fri, 13 Feb 2026 21:36:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70049692/the_hacklebox_mixdown_21126.mp3" length="70561760" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>2026 is off to quite the start! After a New Year's break, we're BACK with another Hackle Box episode to discuss what we've seen so far in the offensive services and incident response sides of the infosec industry! 

This month, Oscar, Eric, and...</itunes:subtitle><itunes:summary><![CDATA[2026 is off to quite the start! After a New Year's break, we're BACK with another Hackle Box episode to discuss what we've seen so far in the offensive services and incident response sides of the infosec industry! <br /><br />This month, Oscar, Eric, and special guest Matt Findlay discussed:<br /><ul><li>Notepad++ Vulnerabilities</li><li>Phishing from legitimate Microsoft inboxes</li><li>Solarwinds Remote Code Execution</li><li>Ring's New Surveillance Feature</li></ul>Tune in every month for insights on similar topics and the latest trends, tactics, lures, and fixes that our expert cybersecurity team is seeing in the real-world:<br /><ul><li>The Catch of the Month</li><li>The Phishing Report</li><li>Live Q&amp;A</li><li>Guest Speakers</li><li>And more!</li></ul>If you've got burning questions or feedback, we'd be happy to hear from you: https://www.surveymonkey.com/r/hacklebox<br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/<br /><br />Please like, subscribe, and follow FRSecure on social!<br /><br /><br />]]></itunes:summary><itunes:duration>2937</itunes:duration><itunes:keywords>bi,breaches,business,camera,cve,cybersecurity,frsecure,hacklebox,infosec,kev,microsoft,notepad++,phishing,privacy,rce,ring,solarwinds,supplychain,surveillance,vulnerabilities</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/00658c95057336110ddf50f4c2e4f099.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>June 2025: Q&amp;A Session, CISA Updates</title><link>https://www.spreaker.com/episode/june-2025-q-a-session-cisa-updates--66481599</link><description><![CDATA[In this quarterly live Q&amp;A session, the gang dives into the recent CISA budget cuts and hands it over to the audience for discussion. Tune in to get your updates, hear what folks are talking about, and a little on boats! <br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/ <br /><br />Please like, subscribe, and follow us on social! <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/ <br />Facebook: https://www.facebook.com/frsecure/ <br />BlueSky: https://bsky.app/profile/frsecure.bsky.social <br /><br />About FRSecure: https://frsecure.com/ <br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/66481599</guid><pubDate>Tue, 10 Jun 2025 15:14:22 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66481599/the_hackle_box_june_2025_edited.mp3" length="69412235" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>In this quarterly live Q&amp;amp;A session, the gang dives into the recent CISA budget cuts and hands it over to the audience for discussion. Tune in to get your updates, hear what folks are talking about, and a little on boats! 

To stay updated on all...</itunes:subtitle><itunes:summary><![CDATA[In this quarterly live Q&amp;A session, the gang dives into the recent CISA budget cuts and hands it over to the audience for discussion. Tune in to get your updates, hear what folks are talking about, and a little on boats! <br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/ <br /><br />Please like, subscribe, and follow us on social! <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/ <br />Facebook: https://www.facebook.com/frsecure/ <br />BlueSky: https://bsky.app/profile/frsecure.bsky.social <br /><br />About FRSecure: https://frsecure.com/ <br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>2889</itunes:duration><itunes:keywords>cisa,cyber,cybersecurity,ethical,frsecure,hacking,incident,information,infosec,intelligence,oscarminks,phishing,pinkythompson,response,security,threat,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Vibe Coding, Malicious AI Models, &amp; More</title><link>https://www.spreaker.com/episode/vibe-coding-malicious-ai-models-more--66075426</link><description><![CDATA[Join us for our May Hackle Box session! The crew explores the emerging concept of "vibe coding", also known as vulnerability as a service, and unpacks its implications for cybersecurity. The team discusses how large language models (LLMs) may unknowingly import malicious code, raising critical concerns about training data integrity and AI trustworthiness. <br /><br /><b>Links:</b><br /><a href="https://www.bleepingcomputer.com/news/security/ai-hallucinated-code-dependencies-become-new-supply-chain-risk/" target="_blank" rel="noreferrer noopener">"AI-Hallucinated Code Dependencies Become New Supply Chain Risk"</a> <br /><br />"Vehicles Face 45% More Attacks, 4 Times More Hackers" https://www.darkreading.com/vulnerabilities-threats/vehicles-45-more-attacks-4-times-more-hackers <br /><br />"'Venom Spider' Targets Hiring Managers in Phishing Scheme" <br />https://www.darkreading.com/cyber-risk/venom-spider-phishing-scheme <br /><br />"CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation" https://www.darkreading.com/threat-intelligence/two-sonicwall-vulnerabilities-under-exploitation <br /><br />"Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach" https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html <br /><br /><b>Be sure to submit your questions for our quarterly Q&amp;A Episodes!</b> <br /><a href="https://www.surveymonkey.com/r/hacklebox" target="_blank" rel="noreferrer noopener">Ask Our Security Experts Anything!</a><br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/ <br /><br />Please like, subscribe, and follow us on social! <br /><br /><b>LinkedIn:</b> <a href="https://www.linkedin.com/company/frsecure/" target="_blank" rel="noreferrer noopener">frsecure</a> <br /><b>Instagram:</b> <a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener">@frsecureofficial</a><br /><b>Facebook:</b> <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">frsecure</a><b>BlueSky:</b> <a href="https://bsky.app/profile/frsecure.bsky.social" target="_blank" rel="noreferrer noopener">@frsecure</a><br /><br /><b>About FRSecure:</b> <br /><a href="https://frsecure.com/" target="_blank" rel="noreferrer noopener">https://frsecure.com/</a><br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/66075426</guid><pubDate>Tue, 13 May 2025 19:19:59 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66075426/the_hackle_box_may_2025.mp3" length="86611751" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Join us for our May Hackle Box session! The crew explores the emerging concept of "vibe coding", also known as vulnerability as a service, and unpacks its implications for cybersecurity. The team discusses how large language models (LLMs) may...</itunes:subtitle><itunes:summary><![CDATA[Join us for our May Hackle Box session! The crew explores the emerging concept of "vibe coding", also known as vulnerability as a service, and unpacks its implications for cybersecurity. The team discusses how large language models (LLMs) may unknowingly import malicious code, raising critical concerns about training data integrity and AI trustworthiness. <br /><br /><b>Links:</b><br /><a href="https://www.bleepingcomputer.com/news/security/ai-hallucinated-code-dependencies-become-new-supply-chain-risk/" target="_blank" rel="noreferrer noopener">"AI-Hallucinated Code Dependencies Become New Supply Chain Risk"</a> <br /><br />"Vehicles Face 45% More Attacks, 4 Times More Hackers" https://www.darkreading.com/vulnerabilities-threats/vehicles-45-more-attacks-4-times-more-hackers <br /><br />"'Venom Spider' Targets Hiring Managers in Phishing Scheme" <br />https://www.darkreading.com/cyber-risk/venom-spider-phishing-scheme <br /><br />"CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation" https://www.darkreading.com/threat-intelligence/two-sonicwall-vulnerabilities-under-exploitation <br /><br />"Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach" https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html <br /><br /><b>Be sure to submit your questions for our quarterly Q&amp;A Episodes!</b> <br /><a href="https://www.surveymonkey.com/r/hacklebox" target="_blank" rel="noreferrer noopener">Ask Our Security Experts Anything!</a><br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/ <br /><br />Please like, subscribe, and follow us on social! <br /><br /><b>LinkedIn:</b> <a href="https://www.linkedin.com/company/frsecure/" target="_blank" rel="noreferrer noopener">frsecure</a> <br /><b>Instagram:</b> <a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener">@frsecureofficial</a><br /><b>Facebook:</b> <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">frsecure</a><b>BlueSky:</b> <a href="https://bsky.app/profile/frsecure.bsky.social" target="_blank" rel="noreferrer noopener">@frsecure</a><br /><br /><b>About FRSecure:</b> <br /><a href="https://frsecure.com/" target="_blank" rel="noreferrer noopener">https://frsecure.com/</a><br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3606</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>AI-Driven Attack Platforms, Record-Breaking Ransoms, Neptune RAT, &amp; More!</title><link>https://www.spreaker.com/episode/ai-driven-attack-platforms-record-breaking-ransoms-neptune-rat-more--65569964</link><description><![CDATA[In this month's edition of the Hackle Box, the guys are joined by Kevin Gunter, a penetration tester at FRSecure, to discuss "Xanthorox AI," a record-breaking $75M ransomware demand, a US Treasury breach going back to 2023, and Neptune RAT.<br /><br />Links:<br /><ul><li>"Autonomous, GenAI-Driven Attacker Platform Enters the Chat"<ul><li>https://www.darkreading.com/threat-intelligence/autonomous-genai-attacker-platform-chat </li></ul></li><li>"Fortune 50 Co. Pays Record-Breaking $75M Ransomware Demand"<ul><li>https://www.darkreading.com/threat-intelligence/fortune-50-company-pays-record-breaking-75m-ransomware-demand</li></ul></li><li>"Hackers lurked in Treasury OCC’s systems since June 2023 breach"<ul><li>https://www.bleepingcomputer.com/news/security/hackers-lurked-in-treasury-occs-systems-since-june-2023-breach/</li></ul></li><li>"NEPTUNE RAT : An advanced Windows RAT with System Destruction Capabilities and Password Exfiltration from 270+ Applications"<ul><li>https://www.cyfirma.com/research/neptune-rat-an-advanced-windows-rat-with-system-destruction-capabilities-and-password-exfiltration-from-270-applications/</li></ul></li></ul>To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/<br /><br />Please like, subscribe, and follow us on social!<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />Facebook: https://www.facebook.com/frsecure/<br />BlueSky: https://bsky.app/profile/frsecure.bsky.social<br /><br />About FRSecure:<br />https://frsecure.com/<br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/65569964</guid><pubDate>Mon, 14 Apr 2025 19:55:43 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65569964/hackle_box_april_2025_prod.mp3" length="83411009" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>In this month's edition of the Hackle Box, the guys are joined by Kevin Gunter, a penetration tester at FRSecure, to discuss "Xanthorox AI," a record-breaking $75M ransomware demand, a US Treasury breach going back to 2023, and Neptune RAT.

Links:

-...</itunes:subtitle><itunes:summary><![CDATA[In this month's edition of the Hackle Box, the guys are joined by Kevin Gunter, a penetration tester at FRSecure, to discuss "Xanthorox AI," a record-breaking $75M ransomware demand, a US Treasury breach going back to 2023, and Neptune RAT.<br /><br />Links:<br /><ul><li>"Autonomous, GenAI-Driven Attacker Platform Enters the Chat"<ul><li>https://www.darkreading.com/threat-intelligence/autonomous-genai-attacker-platform-chat </li></ul></li><li>"Fortune 50 Co. Pays Record-Breaking $75M Ransomware Demand"<ul><li>https://www.darkreading.com/threat-intelligence/fortune-50-company-pays-record-breaking-75m-ransomware-demand</li></ul></li><li>"Hackers lurked in Treasury OCC’s systems since June 2023 breach"<ul><li>https://www.bleepingcomputer.com/news/security/hackers-lurked-in-treasury-occs-systems-since-june-2023-breach/</li></ul></li><li>"NEPTUNE RAT : An advanced Windows RAT with System Destruction Capabilities and Password Exfiltration from 270+ Applications"<ul><li>https://www.cyfirma.com/research/neptune-rat-an-advanced-windows-rat-with-system-destruction-capabilities-and-password-exfiltration-from-270-applications/</li></ul></li></ul>To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/<br /><br />Please like, subscribe, and follow us on social!<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />Facebook: https://www.facebook.com/frsecure/<br />BlueSky: https://bsky.app/profile/frsecure.bsky.social<br /><br />About FRSecure:<br />https://frsecure.com/<br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></itunes:summary><itunes:duration>3473</itunes:duration><itunes:keywords>ai,bcp,blueteam,breaches,cyber,cybersecurity,dr,exfiltration,frsecure,hacklebox,incident,infosec,ir,neptunerat,netsec,ransomware,redteam,threat,treasury,xanthorox</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>March 2025: Q &amp; A Open Call</title><link>https://www.spreaker.com/episode/march-2025-q-a-open-call--64959621</link><description><![CDATA[Approaching the end of Q1, this special-edition episode answers questions from the audience including the U.S. Cyber Command's suspended operations against Russia and some essential beard maintenance. Security Analyst Tim Boyer sits in for Pinky to fill the blue team perspective. <br /><br />Now happening quarterly, listeners can ask all things security to our expert crew! The next Q &amp; A Session will be held June 13th. Submit questions to our survey here: https://www.surveymonkey.com/r/thehacklebox <br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: <a href="https://frsecure.com/cyber-threat-intel-series/" target="_blank" rel="noreferrer noopener">https://frsecure.com/cyber-threat-intel-series/</a> <br /><br />Please like, subscribe, and follow us on social! <br /><br />LinkedIn: <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">https://www.facebook.com/frsecure/</a> <br />Instagram:<a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener"> https://www.instagram.com/frsecureofficial/</a> <br />Facebook: <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">https://www.facebook.com/frsecure/</a> <br />BlueSky: <a href="https://bsky.app/profile/frsecure.bsky.social" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/frsecure.bsky.social</a> <br /><br /><b>About FRSecure: </b><br />https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/64959621</guid><pubDate>Tue, 18 Mar 2025 18:35:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64959621/the_hackle_box_march_2025.mp3" length="78475309" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Approaching the end of Q1, this special-edition episode answers questions from the audience including the U.S. Cyber Command's suspended operations against Russia and some essential beard maintenance. Security Analyst Tim Boyer sits in for Pinky to...</itunes:subtitle><itunes:summary><![CDATA[Approaching the end of Q1, this special-edition episode answers questions from the audience including the U.S. Cyber Command's suspended operations against Russia and some essential beard maintenance. Security Analyst Tim Boyer sits in for Pinky to fill the blue team perspective. <br /><br />Now happening quarterly, listeners can ask all things security to our expert crew! The next Q &amp; A Session will be held June 13th. Submit questions to our survey here: https://www.surveymonkey.com/r/thehacklebox <br /><br />To stay updated on all things The Hackle Box, sign up to receive our newsletters: <a href="https://frsecure.com/cyber-threat-intel-series/" target="_blank" rel="noreferrer noopener">https://frsecure.com/cyber-threat-intel-series/</a> <br /><br />Please like, subscribe, and follow us on social! <br /><br />LinkedIn: <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">https://www.facebook.com/frsecure/</a> <br />Instagram:<a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener"> https://www.instagram.com/frsecureofficial/</a> <br />Facebook: <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">https://www.facebook.com/frsecure/</a> <br />BlueSky: <a href="https://bsky.app/profile/frsecure.bsky.social" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/frsecure.bsky.social</a> <br /><br /><b>About FRSecure: </b><br />https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3267</itunes:duration><itunes:keywords>box,cisa,cyber,cybersecurity,ethical,frsecure,hacking,hackle,incident,information,infosec,intelligence,response,security,threat,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>DeepSeek, Ransomware Decline, New Exploited Vulnerabilities, &amp; More</title><link>https://www.spreaker.com/episode/deepseek-ransomware-decline-new-exploited-vulnerabilities-more--64440848</link><description><![CDATA[Oscar, Pinky, and Eric dive into DeepSeek, the downward trend of Ransomware extortions, and new, actively exploited vulnerabilities.<br /><br />Links:<br />"DeepSeek App Transmits Sensitive User and Device Data Without Encryption" <a href="https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html </a><br /><br />"DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked" <a href="https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html </a><br /><br />"Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023" <a href="https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html </a><br /><br />"CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25" <a href="https://thehackernews.com/2025/02/cisa-adds-four-actively-exploited.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/cisa-adds-four-actively-exploited.html </a><br /><br />"Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software" <a href="https://thehackernews.com/2025/02/palo-alto-networks-patches.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/palo-alto-networks-patches.html </a><br /><br />Please like, subscribe, and follow us on social! <br /><ul><li>Facebook: <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">https://www.facebook.com/frsecure/ </a></li><li>Twitter: <a href="https://twitter.com/frsecure/" target="_blank" rel="noreferrer noopener">https://twitter.com/frsecure/ </a></li><li>Instagram: <a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener">https://www.instagram.com/frsecureofficial/  </a></li><li>LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/company/frsecure/ </a></li></ul><br /><br /><b>About FRSecure: </b><br />https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/64440848</guid><pubDate>Tue, 18 Feb 2025 22:25:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64440848/the_hackle_box_feb_2025.mp3" length="78474819" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric dive into DeepSeek, the downward trend of Ransomware extortions, and new, actively exploited vulnerabilities.

Links:
"DeepSeek App Transmits Sensitive User and Device Data Without Encryption"...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric dive into DeepSeek, the downward trend of Ransomware extortions, and new, actively exploited vulnerabilities.<br /><br />Links:<br />"DeepSeek App Transmits Sensitive User and Device Data Without Encryption" <a href="https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html </a><br /><br />"DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked" <a href="https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html </a><br /><br />"Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023" <a href="https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html </a><br /><br />"CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25" <a href="https://thehackernews.com/2025/02/cisa-adds-four-actively-exploited.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/cisa-adds-four-actively-exploited.html </a><br /><br />"Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software" <a href="https://thehackernews.com/2025/02/palo-alto-networks-patches.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/02/palo-alto-networks-patches.html </a><br /><br />Please like, subscribe, and follow us on social! <br /><ul><li>Facebook: <a href="https://www.facebook.com/frsecure/" target="_blank" rel="noreferrer noopener">https://www.facebook.com/frsecure/ </a></li><li>Twitter: <a href="https://twitter.com/frsecure/" target="_blank" rel="noreferrer noopener">https://twitter.com/frsecure/ </a></li><li>Instagram: <a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener">https://www.instagram.com/frsecureofficial/  </a></li><li>LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/company/frsecure/ </a></li></ul><br /><br /><b>About FRSecure: </b><br />https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3267</itunes:duration><itunes:keywords>box,cisa,cyber,cybersecurity,ethical,frsecure,hacking,hackle,incident,information,infosec,intelligence,minks,oscar,pinky,response,security,thompson,threat,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>RCS, AuthQuake, &amp; "The Night before Breachmas"</title><link>https://www.spreaker.com/episode/rcs-authquake-the-night-before-breachmas--63478740</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  This special holiday episode, Pinky shares a reading of "The Night Before Breachmas", the gang talks encrypted texting, Microsoft's MFA flaw - aka "AuthQuake", and hackers bypassing AntiVirus protections with BYOVD. <br /><br />Links:<br />"FBI Warns iPhone And Android Users—Stop Sending Texts" https://www.forbes.com/sites/zakdoffman/2024/12/06/fbi-warns-iphone-and-android-users-stop-sending-texts/ <br /><br />"Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts" https://thehackernews.com/2024/12/microsoft-mfa-authquake-flaw-enabled.html?m=1 <br /><br />"Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections" https://thehackernews.com/2024/11/researchers-uncover-malware-using-byovd.html?m=1 <br /><br />Please like, subscribe, and follow us on social!  <br /><br />Facebook: https://www.facebook.com/frsecure/  <br />Twitter: https://twitter.com/frsecure/  <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/  <br /><br />About FRSecure: <br />https://frsecure.com/  <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/63478740</guid><pubDate>Thu, 26 Dec 2024 17:46:50 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63478740/hackle_box_december_2024.mp3" length="85374908" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  This special holiday episode, Pinky shares a reading of "The Night Before Breachmas", the gang...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  This special holiday episode, Pinky shares a reading of "The Night Before Breachmas", the gang talks encrypted texting, Microsoft's MFA flaw - aka "AuthQuake", and hackers bypassing AntiVirus protections with BYOVD. <br /><br />Links:<br />"FBI Warns iPhone And Android Users—Stop Sending Texts" https://www.forbes.com/sites/zakdoffman/2024/12/06/fbi-warns-iphone-and-android-users-stop-sending-texts/ <br /><br />"Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts" https://thehackernews.com/2024/12/microsoft-mfa-authquake-flaw-enabled.html?m=1 <br /><br />"Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections" https://thehackernews.com/2024/11/researchers-uncover-malware-using-byovd.html?m=1 <br /><br />Please like, subscribe, and follow us on social!  <br /><br />Facebook: https://www.facebook.com/frsecure/  <br />Twitter: https://twitter.com/frsecure/  <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/  <br /><br />About FRSecure: <br />https://frsecure.com/  <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3555</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>SolarWinds Attack Disclosures, OWASP's AI Security Guidance, &amp; More</title><link>https://www.spreaker.com/episode/solarwinds-attack-disclosures-owasp-s-ai-security-guidance-more--62710236</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This month, Oscar and the crew focus on SolarWinds cyber attack and the resulting charges from the SEC, guidance from OWASP on AI Security, and CISCO's security patch.<br /><br />Links: "Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGdlRjFMYldRVnFJV1pmUUl2ZU1LVnBZaFNHUXxBQ3Jtc0ttMWJRdk5WUERGYk52Ui1qMTJPUjVwYnJreGh4YlZtRVg2WmN4emlUZHNjOXc5YkVIOE1ZNHB1czl0U1d0aHlmQklqZG1PTkRXdVUtT3FuSG1pVTcwU3pNdWdTdW90bE1kQzNTM1hrMU4xd3R1M0YyZw&amp;q=https%3A%2F%2Fthehackernews.com%2F2024%2F11%2Fgoogle-cloud-to-enforce-multi-factor.html&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2024/11/goo...</a><br /><br />"SEC Charges 4 Companies Over Misleading SolarWinds Cyber Attack Disclosures" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa0NNSXZVb0c5TnpIXzZ6SWN1c3VZVmY2LUItZ3xBQ3Jtc0ttY2NuaHRlNTdRNFM5QVdJZWE1cUtzR3h5V2lLMWlLTlNKa1hVLVZFa1ZwaUNLTTk4T3lKRVJQRXVVeGcyMWwxTkJmMDYwRUp1TWUzd1JSX2wxRXZJYkx4Y3ZLMjFCd0YzMDM1ZWtUeWZrVjA4bmk1bw&amp;q=https%3A%2F%2Fthehackernews.com%2F2024%2F10%2Fsec-charges-4-companies-over-misleading.html%3Fm%3D1&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2024/10/sec...</a><br /><br />"OWASP Releases AI Security Guidance" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa3ZoV1oxN2x3RWs2a1Z2eFBYaTNjTkFkblhRZ3xBQ3Jtc0tteVBBQ3dEX1RZTFlHdlNwcVlibTBVaHlmcS1LSV96SzN2LUIyUTRFaDlIT3F0TmxmanlmdXVQa096OHB5Q01URERwSjRSNHBHS0FYZmZtR2hJVVJFMld0YXJkcXRJVEZRMkFrVnh0SXlRZWpQalEwZw&amp;q=https%3A%2F%2Fwww.darkreading.com%2Fapplication-security%2Fowasp-releases-ai-security-guidance&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/applicati...</a><br /><br />"Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa1hWQl9SdGdoejJGU2pWUVk2VXN5QXR0QnE0UXxBQ3Jtc0tsOGtNN2FwREhEaEpmdUdIZVB5MnNrcktuMGNJbnhJcTZ2SXlZdG5WYzdMS3VvUWJIcGd1blVadExIcGtyR21fcWEyWkFHMHJ5eEVFVzJfLTRvZEhZSVVuM1g4WW54UWVLT0hYZ3NCTmgwTUdVTnpURQ&amp;q=https%3A%2F%2Fthehackernews.com%2F2024%2F11%2Fcisco-releases-patch-for-critical-urwb.html&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2024/11/cis...</a><br /><br />Please like, subscribe, and follow us on social! <br />Facebook: <a href="https://www.facebook.com/frsecure/events/?_rdr" target="_blank" rel="noreferrer noopener">FRSecure LLC</a><br />Twitter: <a href="https://x.com/FRSecure?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor" target="_blank" rel="noreferrer noopener">@FRSecure</a><br /><a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFJKQ1BnY1gxWkpuUDAzTDZLWmVvbDFUZ25ad3xBQ3Jtc0ttSVNZa2RTUmVCdGFWZzREV2xmbW53aVlCRWI2dEFXRjQ5ck1sOW5BZEdWMUd5eGhwRmZma3g3c1dSU29DMHNKS21CbzVVRjBpOFVSVTVyUlVXZUhManh3ck50OXpKYjE2NGVGcnRMU2NaRFJvMkdDcw&amp;q=https%3A%2F%2Ftwitter.com%2Ffrsecure%2F%C2%A0&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener"></a>Instagram: <a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener">@FRSecureofficial</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure" target="_blank" rel="noreferrer noopener">FRSecure</a><br /><br /><br />About FRSecure: <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbHBxdzdTTXhLWHRMUHJRSVBvc2xrUHBHRFFvd3xBQ3Jtc0ttZUFmbFdKVk9MZnBqQlI5eHVQZ2ZYVXVtWC1aSENkX09GajJuYUcweEtoOGVRVkJTZ0VKQjRtOTRJMi02MmxUMG5NU1BqQTJ5SG0tYi1GWDBuaHFyU1VGY0h6Nk1penhuUjYxRnlXTXpBRWRiZERYQQ&amp;q=https%3A%2F%2Ffrsecure.com%2F%C2%A0&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://frsecure.com/</a> <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br /><br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/62710236</guid><pubDate>Wed, 13 Nov 2024 16:29:19 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62710236/the_hackle_box_episode_36.mp3" length="82552095" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This month, Oscar and the crew focus on SolarWinds cyber attack and the resulting charges from the...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This month, Oscar and the crew focus on SolarWinds cyber attack and the resulting charges from the SEC, guidance from OWASP on AI Security, and CISCO's security patch.<br /><br />Links: "Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGdlRjFMYldRVnFJV1pmUUl2ZU1LVnBZaFNHUXxBQ3Jtc0ttMWJRdk5WUERGYk52Ui1qMTJPUjVwYnJreGh4YlZtRVg2WmN4emlUZHNjOXc5YkVIOE1ZNHB1czl0U1d0aHlmQklqZG1PTkRXdVUtT3FuSG1pVTcwU3pNdWdTdW90bE1kQzNTM1hrMU4xd3R1M0YyZw&amp;q=https%3A%2F%2Fthehackernews.com%2F2024%2F11%2Fgoogle-cloud-to-enforce-multi-factor.html&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2024/11/goo...</a><br /><br />"SEC Charges 4 Companies Over Misleading SolarWinds Cyber Attack Disclosures" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa0NNSXZVb0c5TnpIXzZ6SWN1c3VZVmY2LUItZ3xBQ3Jtc0ttY2NuaHRlNTdRNFM5QVdJZWE1cUtzR3h5V2lLMWlLTlNKa1hVLVZFa1ZwaUNLTTk4T3lKRVJQRXVVeGcyMWwxTkJmMDYwRUp1TWUzd1JSX2wxRXZJYkx4Y3ZLMjFCd0YzMDM1ZWtUeWZrVjA4bmk1bw&amp;q=https%3A%2F%2Fthehackernews.com%2F2024%2F10%2Fsec-charges-4-companies-over-misleading.html%3Fm%3D1&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2024/10/sec...</a><br /><br />"OWASP Releases AI Security Guidance" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa3ZoV1oxN2x3RWs2a1Z2eFBYaTNjTkFkblhRZ3xBQ3Jtc0tteVBBQ3dEX1RZTFlHdlNwcVlibTBVaHlmcS1LSV96SzN2LUIyUTRFaDlIT3F0TmxmanlmdXVQa096OHB5Q01URERwSjRSNHBHS0FYZmZtR2hJVVJFMld0YXJkcXRJVEZRMkFrVnh0SXlRZWpQalEwZw&amp;q=https%3A%2F%2Fwww.darkreading.com%2Fapplication-security%2Fowasp-releases-ai-security-guidance&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/applicati...</a><br /><br />"Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems" <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa1hWQl9SdGdoejJGU2pWUVk2VXN5QXR0QnE0UXxBQ3Jtc0tsOGtNN2FwREhEaEpmdUdIZVB5MnNrcktuMGNJbnhJcTZ2SXlZdG5WYzdMS3VvUWJIcGd1blVadExIcGtyR21fcWEyWkFHMHJ5eEVFVzJfLTRvZEhZSVVuM1g4WW54UWVLT0hYZ3NCTmgwTUdVTnpURQ&amp;q=https%3A%2F%2Fthehackernews.com%2F2024%2F11%2Fcisco-releases-patch-for-critical-urwb.html&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2024/11/cis...</a><br /><br />Please like, subscribe, and follow us on social! <br />Facebook: <a href="https://www.facebook.com/frsecure/events/?_rdr" target="_blank" rel="noreferrer noopener">FRSecure LLC</a><br />Twitter: <a href="https://x.com/FRSecure?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor" target="_blank" rel="noreferrer noopener">@FRSecure</a><br /><a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFJKQ1BnY1gxWkpuUDAzTDZLWmVvbDFUZ25ad3xBQ3Jtc0ttSVNZa2RTUmVCdGFWZzREV2xmbW53aVlCRWI2dEFXRjQ5ck1sOW5BZEdWMUd5eGhwRmZma3g3c1dSU29DMHNKS21CbzVVRjBpOFVSVTVyUlVXZUhManh3ck50OXpKYjE2NGVGcnRMU2NaRFJvMkdDcw&amp;q=https%3A%2F%2Ftwitter.com%2Ffrsecure%2F%C2%A0&amp;v=CMpMdSqN2qg" target="_blank" rel="noreferrer noopener"></a>Instagram: <a href="https://www.instagram.com/frsecureofficial/" target="_blank" rel="noreferrer noopener">@FRSecureofficial</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure" target="_blank" rel="noreferrer noopener">FRSecure</a><br /><br /><br />About FRSecure: <a...]]></itunes:summary><itunes:duration>3437</itunes:duration><itunes:keywords>breach,cisa,consulting,cyber,cybersecurity,ethical,frsecure,hacking,hacklebox,incident,information,infosec,intelligence,minks,network,response,sec,security,threat,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episode>36</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Internet Archive Hacked, New CISA Warnings, Zero Day Alert</title><link>https://www.spreaker.com/episode/internet-archive-hacked-new-cisa-warnings-zero-day-alert--62507218</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  <br /><br />This month, the hosts talk about personal preparation for emergency events like natural disasters, the DDOS attacks of Internet Archive, newest CISA warnings, and Zero Day Alert for Ivanti exploitation. They also open up to the live audience for questions! <br /><br />Links: "Internet Archive Hacked, Data Breach Impacts 31 Million Users" https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ <br /><br />"CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches" https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html <br /><br />"Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited" https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html <br /><br />"N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware" https://thehackernews.com/2024/10/n-korean-hackers-use-fake-interviews-to.html <br /><br />Please like, subscribe, and follow us on social!  <br />Facebook: https://www.facebook.com/frsecure/  <br />Twitter: https://twitter.com/frsecure/  <br />Instagram: https://www.instagram.com/frsecureofficial/   <br />LinkedIn: https://www.linkedin.com/company/frsecure/  <br /><br />About FRSecure: https://frsecure.com/  <br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/62507218</guid><pubDate>Mon, 28 Oct 2024 21:01:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62507218/the_hackle_box_october_24.mp3" length="84612216" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  

This month, the hosts talk about personal preparation for emergency events like natural...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  <br /><br />This month, the hosts talk about personal preparation for emergency events like natural disasters, the DDOS attacks of Internet Archive, newest CISA warnings, and Zero Day Alert for Ivanti exploitation. They also open up to the live audience for questions! <br /><br />Links: "Internet Archive Hacked, Data Breach Impacts 31 Million Users" https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ <br /><br />"CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches" https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html <br /><br />"Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited" https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html <br /><br />"N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware" https://thehackernews.com/2024/10/n-korean-hackers-use-fake-interviews-to.html <br /><br />Please like, subscribe, and follow us on social!  <br />Facebook: https://www.facebook.com/frsecure/  <br />Twitter: https://twitter.com/frsecure/  <br />Instagram: https://www.instagram.com/frsecureofficial/   <br />LinkedIn: https://www.linkedin.com/company/frsecure/  <br /><br />About FRSecure: https://frsecure.com/  <br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3523</itunes:duration><itunes:keywords>box,cisa,cyber,cybersecurity,ethical,frsecure,hacking,hackle,incident,information,infosec,intelligence,minks,oscar,pinky,response,security,thompson,threat,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Worm-Driven USB Attacks, Microsoft Zero-Days, Scattered Spider Vishing &amp; Smishing</title><link>https://www.spreaker.com/episode/worm-driven-usb-attacks-microsoft-zero-days-scattered-spider-vishing-smishing--61869949</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />With Oscar out traveling, Pinky and Eric lead the discussion this month. Together, they discuss: A worm-driven USB attack strategy, Microsoft's disclosure of four zero-days in their September update, and the Scattered Spider ransomware group's sophisticated smishing and vishing campaigns on cloud services. They also open up to the live audience for questions!<br /><br />Links: <br />Mustang Panda Feeds Worm-Driven USB Attack Strategy<br />https://www.darkreading.com/cyberattacks-data-breaches/mustang-panda-worm-driven-usb-attack<br /><br />Microsoft Discloses 4 Zero-Days in September Update<br />https://www.darkreading.com/application-security/microsoft-discloses-4-zero-days-in-september-update<br /><br />Socially Savvy Scattered Spider Traps Cloud Admins in Web<br />https://www.darkreading.com/cloud-security/socially-savvy-scattered-spider-traps-cloud-admins-in-web<br /><br /><br />Please like, subscribe, and follow us on social!<br /><br />About FRSecure<br /><a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa1hmeGY2UnRZb1hmdUl5YTdjMmRybm1YbzhOQXxBQ3Jtc0trR3JlbEZvR1B0R2IyRmFBYzJvVUl0Sk1jMUxWLTZ3ellOREIyTHJDaGJ2UkhaZzZ1c3hEdzlvUFRkRnlEemd6Qld1dWhEVV9BSUFrMTJkM2hGR0FoLVkzellJa0F6M3hvZ0UxeXNDbHhjc3VCOEJFQQ&amp;q=https%3A%2F%2Ffrsecure.com%2F%C2%A0&amp;v=dbmw0R2dQZQ" target="_blank" rel="noreferrer noopener">https://frsecure.com/ </a><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/61869949</guid><pubDate>Mon, 16 Sep 2024 21:54:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61869949/the_hacklebox_sept_2024.mp3" length="85955884" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

With Oscar out traveling, Pinky and Eric lead the discussion this month. Together, they discuss: A...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />With Oscar out traveling, Pinky and Eric lead the discussion this month. Together, they discuss: A worm-driven USB attack strategy, Microsoft's disclosure of four zero-days in their September update, and the Scattered Spider ransomware group's sophisticated smishing and vishing campaigns on cloud services. They also open up to the live audience for questions!<br /><br />Links: <br />Mustang Panda Feeds Worm-Driven USB Attack Strategy<br />https://www.darkreading.com/cyberattacks-data-breaches/mustang-panda-worm-driven-usb-attack<br /><br />Microsoft Discloses 4 Zero-Days in September Update<br />https://www.darkreading.com/application-security/microsoft-discloses-4-zero-days-in-september-update<br /><br />Socially Savvy Scattered Spider Traps Cloud Admins in Web<br />https://www.darkreading.com/cloud-security/socially-savvy-scattered-spider-traps-cloud-admins-in-web<br /><br /><br />Please like, subscribe, and follow us on social!<br /><br />About FRSecure<br /><a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqa1hmeGY2UnRZb1hmdUl5YTdjMmRybm1YbzhOQXxBQ3Jtc0trR3JlbEZvR1B0R2IyRmFBYzJvVUl0Sk1jMUxWLTZ3ellOREIyTHJDaGJ2UkhaZzZ1c3hEdzlvUFRkRnlEemd6Qld1dWhEVV9BSUFrMTJkM2hGR0FoLVkzellJa0F6M3hvZ0UxeXNDbHhjc3VCOEJFQQ&amp;q=https%3A%2F%2Ffrsecure.com%2F%C2%A0&amp;v=dbmw0R2dQZQ" target="_blank" rel="noreferrer noopener">https://frsecure.com/ </a><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3579</itunes:duration><itunes:keywords>attacks,breaches,cloud,cyber,cybersecurity,exploits,frsecure,hacking,hacklebox,infosec,microsoft,minks,netsec,phishing,servers,smishing,usb,vishing,vulnerabilities,zero-day</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episode>34</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>TeamViewer APT29 Attack, Zero-Click Outlook RCE Vulnerability, CISA Takedown of Ivanti Systems</title><link>https://www.spreaker.com/episode/teamviewer-apt29-attack-zero-click-outlook-rce-vulnerability-cisa-takedown-of-ivanti-systems--60699694</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss Midnight Blizzard, a zero-click Outlook vulnerability, and CISA's takedown of Ivanti Systems.<br /><br />Links: <br />Network Segmentation Saved TeamViewer From APT29 Attack https://www.darkreading.com/cyberattacks-data-breaches/teamviewer-network-segmentation-apt29-attack<br /><br />Zero-Click Outlook RCE Vulnerability - Project Hyphae<br />https://projecthyphae.com/threat/zero-click-outlook-rce-vulnerability/ <br /><br />CISA Takedown of Ivanti Systems Is a Wake-up Call<br />https://www.darkreading.com/vulnerabilities-threats/cisa-takedown-ivanti-systems-is-wake-up-call<br /><br />Please like, subscribe, and follow us on social! <br />Facebook: https://www.facebook.com/frsecure/ <br />Twitter: https://twitter.com/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure<br />https://frsecure.com/ <br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/60699694</guid><pubDate>Tue, 16 Jul 2024 14:49:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60699694/hackle_box_july_15_prod.mp3" length="83477732" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time, they discuss Midnight Blizzard, a zero-click Outlook vulnerability, and CISA's takedown...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss Midnight Blizzard, a zero-click Outlook vulnerability, and CISA's takedown of Ivanti Systems.<br /><br />Links: <br />Network Segmentation Saved TeamViewer From APT29 Attack https://www.darkreading.com/cyberattacks-data-breaches/teamviewer-network-segmentation-apt29-attack<br /><br />Zero-Click Outlook RCE Vulnerability - Project Hyphae<br />https://projecthyphae.com/threat/zero-click-outlook-rce-vulnerability/ <br /><br />CISA Takedown of Ivanti Systems Is a Wake-up Call<br />https://www.darkreading.com/vulnerabilities-threats/cisa-takedown-ivanti-systems-is-wake-up-call<br /><br />Please like, subscribe, and follow us on social! <br />Facebook: https://www.facebook.com/frsecure/ <br />Twitter: https://twitter.com/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure<br />https://frsecure.com/ <br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3476</itunes:duration><itunes:keywords>apt29,blue-team,cisa,cyber,cybersecurity,data-security,frsecure,hacking,hackle-box,incident-response,infosec,ivanti,midnight-blizzard,minks,netsec,network-segmentation,outlook,rce,red-team,teamviewer</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Police Troll LockBit, Microsoft Holds Execs Accountable for Security</title><link>https://www.spreaker.com/episode/police-troll-lockbit-microsoft-holds-execs-accountable-for-security--60011305</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss critical Citrix flaws, fake journalists stealing data, Microsoft holding execs accountable for security, police trolling a ransomware gang, and more.<br /><br />Links: <br /><br />Citrix Addresses High-Severity Flaw in NetScaler ADC and Gateway<br />https://thehackernews.com/2023/10/critical-citrix-netscaler-flaw.html<br /><br />Apt42 Pose As Journalists, Harvest Credentials, Access Cloud Data<br />https://attackfeed.com/apt42-hackers-pose-as-journalists-to-harvest-credentials-and-access-cloud-data-infothehackernews-com-the-hacker-news/<br /><br />Microsoft Will Hold Execs Accountable for Cybersecurity<br />https://www.darkreading.com/cloud-security/feds-microsoft-clean-up-cloud-security-act<br /><br />Burnout Is Pushing Workers to Use AI—Even If Their Boss Doesn’t Know<br />https://www.wired.com/story/ai-workers-burnout-microsoft-linkedin/<br /><br />Police Resurrect LockBit's Site and Troll the Ransomware Gang | TechCrunch<br />https://techcrunch.com/2024/05/06/police-resurrect-lockbits-site-and-troll-the-ransomware-gang/<br /><br />US Indicts LockBit Ransomware Ringleader, Offers $10 Million Reward<br />https://www.theverge.com/2024/5/7/24151493/us-lockbit-ransomware-ringleader-indictment-reward<br /><br />Please like, subscribe, and follow us on social! <br /><br />Facebook: https://www.facebook.com/frsecure/ <br />Twitter: https://twitter.com/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/60011305</guid><pubDate>Mon, 13 May 2024 21:22:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60011305/may_2024.mp3" length="79543118" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time, they discuss critical Citrix flaws, fake journalists stealing data, Microsoft holding...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss critical Citrix flaws, fake journalists stealing data, Microsoft holding execs accountable for security, police trolling a ransomware gang, and more.<br /><br />Links: <br /><br />Citrix Addresses High-Severity Flaw in NetScaler ADC and Gateway<br />https://thehackernews.com/2023/10/critical-citrix-netscaler-flaw.html<br /><br />Apt42 Pose As Journalists, Harvest Credentials, Access Cloud Data<br />https://attackfeed.com/apt42-hackers-pose-as-journalists-to-harvest-credentials-and-access-cloud-data-infothehackernews-com-the-hacker-news/<br /><br />Microsoft Will Hold Execs Accountable for Cybersecurity<br />https://www.darkreading.com/cloud-security/feds-microsoft-clean-up-cloud-security-act<br /><br />Burnout Is Pushing Workers to Use AI—Even If Their Boss Doesn’t Know<br />https://www.wired.com/story/ai-workers-burnout-microsoft-linkedin/<br /><br />Police Resurrect LockBit's Site and Troll the Ransomware Gang | TechCrunch<br />https://techcrunch.com/2024/05/06/police-resurrect-lockbits-site-and-troll-the-ransomware-gang/<br /><br />US Indicts LockBit Ransomware Ringleader, Offers $10 Million Reward<br />https://www.theverge.com/2024/5/7/24151493/us-lockbit-ransomware-ringleader-indictment-reward<br /><br />Please like, subscribe, and follow us on social! <br /><br />Facebook: https://www.facebook.com/frsecure/ <br />Twitter: https://twitter.com/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></itunes:summary><itunes:duration>3312</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>AI-Written Malware, XZ Utils, Attackers Target Hospital Help Desks</title><link>https://www.spreaker.com/episode/ai-written-malware-xz-utils-attackers-target-hospital-help-desks--59495269</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time, they discuss AI-written malware, XZ Utils, and attackers targeting hospital IT help desks.<br /><br />Links:<br /><br />XZ Utils scare <br />https://www.darkreading.com/application-security/xz-utils-scare-exposes-hard-truths-in-software-security<br /><br />Change Healthcare hit with cyber extortion (again)<br />https://www.infosecurity-magazine.com/news/change-healthcare-double-cyber/<br /><br />Health Department warns attackers targeting IT help desks https://www.bleepingcomputer.com/news/security/us-health-dept-warns-hospitals-of-hackers-targeting-it-help-desks/<br /><br />Malicious PowerShell script appears to be AI-written <br />https://www.bleepingcomputer.com/news/security/malicious-powershell-script-pushing-malware-looks-ai-written/<br /><br />Please follow us on social!<br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.<br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/59495269</guid><pubDate>Tue, 16 Apr 2024 22:32:30 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59495269/hackle_box_april_2024.mp3" length="76898690" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss AI-written malware, XZ Utils, and attackers targeting hospital IT help...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time, they discuss AI-written malware, XZ Utils, and attackers targeting hospital IT help desks.<br /><br />Links:<br /><br />XZ Utils scare <br />https://www.darkreading.com/application-security/xz-utils-scare-exposes-hard-truths-in-software-security<br /><br />Change Healthcare hit with cyber extortion (again)<br />https://www.infosecurity-magazine.com/news/change-healthcare-double-cyber/<br /><br />Health Department warns attackers targeting IT help desks https://www.bleepingcomputer.com/news/security/us-health-dept-warns-hospitals-of-hackers-targeting-it-help-desks/<br /><br />Malicious PowerShell script appears to be AI-written <br />https://www.bleepingcomputer.com/news/security/malicious-powershell-script-pushing-malware-looks-ai-written/<br /><br />Please follow us on social!<br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.<br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3201</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Gemini AI Vulnerability, ChatGPT Plugins, Typosquatting, Vishing</title><link>https://www.spreaker.com/episode/gemini-ai-vulnerability-chatgpt-plugins-typosquatting-vishing--59104316</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time, they discuss security risks in ChatGPT plugins, a major flaw in Google's Gemini AI, typosquatting, and a worldwide vishing epidemic.<br /><br />Links:<br /><br />ChatGPT Plugin Security<br />https://www.infosecurity-magazine.com/news/security-risks-chatgpt-plugins/<br /><br />Gemini AI Vulnerability<br />https://www.darkreading.com/cyber-risk/google-gemini-vulnerable-to-content-manipulation-researchers-say<br /><br />Worldwide Vishing Epidemic<br />https://www.darkreading.com/endpoint-security/sophisticated-vishing-campaigns-take-world-by-storm<br /><br />Typosquatting<br />https://www.darkreading.com/threat-intelligence/typosquatting-wave-shows-no-signs-of-abating<br /><br />Please like, subscribe, and follow us on social!<br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br />About FRSecure https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.<br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/59104316</guid><pubDate>Tue, 19 Mar 2024 19:13:19 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59104316/march_2024.mp3" length="79246713" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss security risks in ChatGPT plugins, a major flaw in Google's Gemini AI,...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time, they discuss security risks in ChatGPT plugins, a major flaw in Google's Gemini AI, typosquatting, and a worldwide vishing epidemic.<br /><br />Links:<br /><br />ChatGPT Plugin Security<br />https://www.infosecurity-magazine.com/news/security-risks-chatgpt-plugins/<br /><br />Gemini AI Vulnerability<br />https://www.darkreading.com/cyber-risk/google-gemini-vulnerable-to-content-manipulation-researchers-say<br /><br />Worldwide Vishing Epidemic<br />https://www.darkreading.com/endpoint-security/sophisticated-vishing-campaigns-take-world-by-storm<br /><br />Typosquatting<br />https://www.darkreading.com/threat-intelligence/typosquatting-wave-shows-no-signs-of-abating<br /><br />Please like, subscribe, and follow us on social!<br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br />About FRSecure https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.<br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3299</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>AnyDesk, Resumes Stolen From Compromised Job Boards, Industry News</title><link>https://www.spreaker.com/episode/anydesk-resumes-stolen-from-compromised-job-boards-industry-news--58664310</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time, they discuss compromised job boards where millions of resumes were stolen, AnyDesk's actions post-hack, an exploited SSRF flaw in Ivanti, and more.<br /><br />Links:<br />Millions of resumes stolen via exploited job boards https://thehackernews.com/2024/02/hackers-exploit-job-boards-in-apac.html<br /><br />AnyDesk resets passwords/revokes certificates after hack https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/<br /><br />SSRF flaw in Ivanti exploited https://thehackernews.com/2024/02/recently-disclosed-ssrf-flaw-in-ivanti.html<br /><br />Fortinet reissues critical FortiSIEM vulnerabilities https://www.theregister.com/2024/02/06/fortinet_fortisiem_vulns/<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br />About FRSecure https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.<br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/58664310</guid><pubDate>Mon, 12 Feb 2024 21:54:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58664310/hackle_box_february_2024.mp3" length="77636734" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss compromised job boards where millions of resumes were stolen, AnyDesk's...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time, they discuss compromised job boards where millions of resumes were stolen, AnyDesk's actions post-hack, an exploited SSRF flaw in Ivanti, and more.<br /><br />Links:<br />Millions of resumes stolen via exploited job boards https://thehackernews.com/2024/02/hackers-exploit-job-boards-in-apac.html<br /><br />AnyDesk resets passwords/revokes certificates after hack https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/<br /><br />SSRF flaw in Ivanti exploited https://thehackernews.com/2024/02/recently-disclosed-ssrf-flaw-in-ivanti.html<br /><br />Fortinet reissues critical FortiSIEM vulnerabilities https://www.theregister.com/2024/02/06/fortinet_fortisiem_vulns/<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/<br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br />About FRSecure https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.<br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>3232</itunes:duration><itunes:keywords>ai,cyber,cybersecurity,ethical,fr,frsecure,hacking,hacklebox,hunting,information,infosec,minks,news,oscar,podcast,secure,security,threat,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Cybersecurity Funding Reduced 40% in 2023, Vulnerability/Patch News</title><link>https://www.spreaker.com/episode/cybersecurity-funding-reduced-40-in-2023-vulnerability-patch-news--58357414</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss the reduced cybersecurity funding observed in 2023 as well as new vulnerabilities, patches, and more.<br /><br />Links: <br /><br />Cybersecurity Funding Reduced <br />https://www.securityweek.com/cybersecurity-funding-dropped-40-in-2023-analysis/ <br /><br />Critical Flaws in Windows Kerberos and Hyper-V <br />https://securityweek.com/microsoft-ships-urgent-fixes-for-critical-flaws-in-windows-kerberos-hyper-v/ <br /><br />Pikabot Malware <br />https://www.darkreading.com/cyberattacks-data-breaches/pikabot-malware-qakbot-replacement-black-basta-attacks <br /><br />Decryptor for Black Basta and Babuk's Tortilla Ransomware https://thehackernews.com/2024/01/free-decryptor-released-for-black-basta.html <br /><br />Please like, subscribe, and follow us on social! <br /><br />Facebook: https://www.facebook.com/frsecure/ <br />Twitter: https://twitter.com/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/58357414</guid><pubDate>Fri, 19 Jan 2024 20:52:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58357414/hackle_box_january_2024.mp3" length="76883781" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time, they discuss the reduced cybersecurity funding observed in 2023 as well as new...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss the reduced cybersecurity funding observed in 2023 as well as new vulnerabilities, patches, and more.<br /><br />Links: <br /><br />Cybersecurity Funding Reduced <br />https://www.securityweek.com/cybersecurity-funding-dropped-40-in-2023-analysis/ <br /><br />Critical Flaws in Windows Kerberos and Hyper-V <br />https://securityweek.com/microsoft-ships-urgent-fixes-for-critical-flaws-in-windows-kerberos-hyper-v/ <br /><br />Pikabot Malware <br />https://www.darkreading.com/cyberattacks-data-breaches/pikabot-malware-qakbot-replacement-black-basta-attacks <br /><br />Decryptor for Black Basta and Babuk's Tortilla Ransomware https://thehackernews.com/2024/01/free-decryptor-released-for-black-basta.html <br /><br />Please like, subscribe, and follow us on social! <br /><br />Facebook: https://www.facebook.com/frsecure/ <br />Twitter: https://twitter.com/frsecure/ <br />Instagram: https://www.instagram.com/frsecureofficial/  <br />LinkedIn: https://www.linkedin.com/company/frsecure/ <br /><br />About FRSecure https://frsecure.com/ <br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></itunes:summary><itunes:duration>3201</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Breachmas &amp; Common Social Engineering Attacks</title><link>https://www.spreaker.com/episode/breachmas-common-social-engineering-attacks--57989105</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss common social engineering attacks carried out around the holidays when key team members are out of the office or organizations are shut down for seasonal breaks. <br /><br /><b>Links</b><br /><i>Social Engineering</i><br />https://thehackernews.com/2023/12/hacking-human-mind-exploiting.html<br /><br /><i>Cisco IOS XE Vuln Exploitation</i><br />https://www.securityweek.com/exploitation-of-recent-cisco-ios-xe-vulnerabilities-spikes/<br /><br /><i>Sierra:21 Attacks</i><br />https://thehackernews.com/2023/12/sierra21-flaws-in-sierra-wireless.html<br /><br /><i>Atlassian</i><br />https://www.darkreading.com/application-security/patch-now-critical-atlassian-bugs-endanger-enterprise-apps<br /><br />Please follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br /><b>About FRSecure</b><br />https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/57989105</guid><pubDate>Tue, 12 Dec 2023 21:21:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57989105/hackle_box_december_2023.mp3" length="67735490" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time, they discuss common social engineering attacks carried out around the holidays when key...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time, they discuss common social engineering attacks carried out around the holidays when key team members are out of the office or organizations are shut down for seasonal breaks. <br /><br /><b>Links</b><br /><i>Social Engineering</i><br />https://thehackernews.com/2023/12/hacking-human-mind-exploiting.html<br /><br /><i>Cisco IOS XE Vuln Exploitation</i><br />https://www.securityweek.com/exploitation-of-recent-cisco-ios-xe-vulnerabilities-spikes/<br /><br /><i>Sierra:21 Attacks</i><br />https://thehackernews.com/2023/12/sierra21-flaws-in-sierra-wireless.html<br /><br /><i>Atlassian</i><br />https://www.darkreading.com/application-security/patch-now-critical-atlassian-bugs-endanger-enterprise-apps<br /><br />Please follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br /><b>About FRSecure</b><br />https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.<br />]]></itunes:summary><itunes:duration>2820</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Recent Vulnerabilities in Confluence and Apache ActiveMQ</title><link>https://www.spreaker.com/episode/recent-vulnerabilities-in-confluence-and-apache-activemq--57651786</link><description><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time around, they discuss recent vulnerabilities in Confluence and Apache ActiveMQ.<br /><br /><b>Follow us on social!</b><br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br /><b>About FRSecure</b> - https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/57651786</guid><pubDate>Wed, 15 Nov 2023 18:29:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57651786/hacklebox_november_2023.mp3" length="60921293" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time around, they discuss recent vulnerabilities in Confluence and Apache ActiveMQ.

Follow us...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.<br /><br />This time around, they discuss recent vulnerabilities in Confluence and Apache ActiveMQ.<br /><br /><b>Follow us on social!</b><br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br /><br /><b>About FRSecure</b> - https://frsecure.com/<br /><br />FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. <br /><br />These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.]]></itunes:summary><itunes:duration>2536</itunes:duration><itunes:keywords>ai,cyber,cybersecurity,ethical,fr,frsecure,hacking,hacklebox,hunting,information,infosec,minks,news,oscar,podcast,secure,security,threat,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Incident Response Horror Stories</title><link>https://www.spreaker.com/episode/incident-response-horror-stories--57261359</link><description><![CDATA[The guys are back for a special, Friday the 13th episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time around, we're getting in the spooky spirit and telling scary stories from real-life IR cases. 🎃<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/57261359</guid><pubDate>Mon, 16 Oct 2023 21:31:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57261359/hacklebox_october_2023.mp3" length="78658644" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The guys are back for a special, Friday the 13th episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time around, we're getting in the spooky spirit and telling scary stories...</itunes:subtitle><itunes:summary><![CDATA[The guys are back for a special, Friday the 13th episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. <br /><br />This time around, we're getting in the spooky spirit and telling scary stories from real-life IR cases. 🎃<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />]]></itunes:summary><itunes:duration>3275</itunes:duration><itunes:keywords>ai,cyber,cybersecurity,ethical,fr,frsecure,hacking,hacklebox,hunting,information,infosec,minks,news,oscar,podcast,secure,security,threat,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Scattered Spider - The MGM Hackers, InfoSec News</title><link>https://www.spreaker.com/episode/scattered-spider-the-mgm-hackers-infosec-news--56843385</link><description><![CDATA[Oscar and Pinky are back for this month's session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><b></b><br /><b>DISCUSSED THIS MONTH:</b><br />Scattered Spider (MGM attack)<br />https://hackdojo.io/articles/E59P05LKQ/-scattered-spider-behind-mgm-cyberattack-targets-casinos<br /><br />Caesers confirms ransomware<br />https://hackdojo.io/articles/73WL5VP9N/caesars-confirms-ransomware-hack-stolen-loyalty-program-database<br /><br />MGM hackers branching out<br />https://hackdojo.io/articles/AEWED5DK7/mgm-hackers-broadening-targets-monetization-strategies<br /><br />UNC3944 Smishing Ransomware<br />https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware<br /><br />LastPass iOS vulnerability (BLASTPASS)<br />https://hackdojo.io/articles/AEWEDLDK7/blastpass-government-agencies-told-to-secure-iphones-against-spyware-attacks<br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/56843385</guid><pubDate>Mon, 18 Sep 2023 16:14:16 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56843385/hackle_box_9_2023.mp3" length="84990726" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar and Pinky are back for this month's session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

DISCUSSED THIS MONTH:
Scattered Spider (MGM attack)...</itunes:subtitle><itunes:summary><![CDATA[Oscar and Pinky are back for this month's session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><b></b><br /><b>DISCUSSED THIS MONTH:</b><br />Scattered Spider (MGM attack)<br />https://hackdojo.io/articles/E59P05LKQ/-scattered-spider-behind-mgm-cyberattack-targets-casinos<br /><br />Caesers confirms ransomware<br />https://hackdojo.io/articles/73WL5VP9N/caesars-confirms-ransomware-hack-stolen-loyalty-program-database<br /><br />MGM hackers branching out<br />https://hackdojo.io/articles/AEWED5DK7/mgm-hackers-broadening-targets-monetization-strategies<br /><br />UNC3944 Smishing Ransomware<br />https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware<br /><br />LastPass iOS vulnerability (BLASTPASS)<br />https://hackdojo.io/articles/AEWEDLDK7/blastpass-government-agencies-told-to-secure-iphones-against-spyware-attacks<br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3539</itunes:duration><itunes:keywords>2022,ai,cyber,cybersecurity,ethical,fr,frsecure,hacking,hacklebox,hunting,information,infosec,minks,news,oscar,podcast,secure,security,threat,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>DEFCON 31, EvilProxy, QR Code Credential Theft, AI Stealing Passwords</title><link>https://www.spreaker.com/episode/defcon-31-evilproxy-qr-code-credential-theft-ai-stealing-passwords--56555914</link><description><![CDATA[Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br /><b>Discussed this month</b><br /><ul><li>DEFCON Recap</li></ul><br /><ul><li>EvilProxy campaign<ul><li>https://www.techrepublic.com/article/evilproxy-phishing-attack/</li></ul></li></ul><br /><ul><li>QR Codes used for credential theft<ul><li>https://www.darkreading.com/attacks-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company</li></ul></li></ul><br /><ul><li>AI stealing passwords, listening to keystrokes<ul><li>https://www.darkreading.com/attacks-breaches/ai-model-can-replicate-password-listening-to-keystrokes</li></ul></li></ul><br /><b>Follow us on social!</b><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/56555914</guid><pubDate>Tue, 22 Aug 2023 15:26:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56555914/hacklebox_august_2023.mp3" length="85136313" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

Discussed this month

- DEFCON Recap


- EvilProxy campaign
    -...</itunes:subtitle><itunes:summary><![CDATA[Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br /><b>Discussed this month</b><br /><ul><li>DEFCON Recap</li></ul><br /><ul><li>EvilProxy campaign<ul><li>https://www.techrepublic.com/article/evilproxy-phishing-attack/</li></ul></li></ul><br /><ul><li>QR Codes used for credential theft<ul><li>https://www.darkreading.com/attacks-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company</li></ul></li></ul><br /><ul><li>AI stealing passwords, listening to keystrokes<ul><li>https://www.darkreading.com/attacks-breaches/ai-model-can-replicate-password-listening-to-keystrokes</li></ul></li></ul><br /><b>Follow us on social!</b><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3545</itunes:duration><itunes:keywords>2022,beginners,cyber,cybersecurity,ethical,for,fr,frsecure,hacking,hunting,information,infosec,minks,news,oscar,podcast,security,threat,tldr,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Hacklebox/Unsecurity Crossover: MOVEit, Microsoft Patch Tuesday, and Fortinet Infinity</title><link>https://www.spreaker.com/episode/hacklebox-unsecurity-crossover-moveit-microsoft-patch-tuesday-and-fortinet-infinity--56141830</link><description><![CDATA[This month, we're doing a crossover episode with the Unsecurity Podcast!<br /><br />For those who are not yet aware, Unsecurity is another FRSecure podcast focused on the business impact of current events and happenings within the security industry. It's hosted several times a month by Oscar and Brad Nigh, FRSecure's Principal Information Security Consultant.<br /><br /><b>Discussed this month: </b><br /><ul><li>MOVEit Attacks</li><li>Microsoft Patch Tuesday: Six 0-Days</li><li>Fortinet Infinity</li></ul><b>Please like, subscribe, and follow us on social! </b><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/56141830</guid><pubDate>Tue, 18 Jul 2023 19:54:41 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56141830/hacklebox_unsecurity_crossover.mp3" length="77109616" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>This month, we're doing a crossover episode with the Unsecurity Podcast!

For those who are not yet aware, Unsecurity is another FRSecure podcast focused on the business impact of current events and happenings within the security industry. It's hosted...</itunes:subtitle><itunes:summary><![CDATA[This month, we're doing a crossover episode with the Unsecurity Podcast!<br /><br />For those who are not yet aware, Unsecurity is another FRSecure podcast focused on the business impact of current events and happenings within the security industry. It's hosted several times a month by Oscar and Brad Nigh, FRSecure's Principal Information Security Consultant.<br /><br /><b>Discussed this month: </b><br /><ul><li>MOVEit Attacks</li><li>Microsoft Patch Tuesday: Six 0-Days</li><li>Fortinet Infinity</li></ul><b>Please like, subscribe, and follow us on social! </b><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/<br />]]></itunes:summary><itunes:duration>3210</itunes:duration><itunes:keywords>2022,beginners,cyber,cybersecurity,ethical,for,fr,frsecure,hacking,hunting,information,infosec,minks,news,oscar,podcast,security,threat,tldr,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Dragos Incident, Do's and Don'ts of SIEM Implementation</title><link>https://www.spreaker.com/episode/dragos-incident-do-s-and-don-ts-of-siem-implementation--53878398</link><description><![CDATA[Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br /><b>Discussed this month</b><br />Do's and don'ts of SIEM implementation<br /><br />The recent Dragos incident<br />https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/<br /><br /><br /><br /><b>Please follow us on social! </b><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/53878398</guid><pubDate>Mon, 15 May 2023 21:21:25 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53878398/may_2023.mp3" length="82592195" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

Discussed this month
Do's and don'ts of SIEM implementation

The recent Dragos...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br /><b>Discussed this month</b><br />Do's and don'ts of SIEM implementation<br /><br />The recent Dragos incident<br />https://www.bleepingcomputer.com/news/security/cybersecurity-firm-dragos-discloses-cybersecurity-incident-extortion-attempt/<br /><br /><br /><br /><b>Please follow us on social! </b><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3439</itunes:duration><itunes:keywords>2022,beginners,cyber,cybersecurity,ethical,for,fr,frsecure,hacking,hunting,information,infosec,minks,news,oscar,podcast,security,threat,tldr,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>3CX Supply Chain Attack, Windows 0-Day, Yum! Brands</title><link>https://www.spreaker.com/episode/3cx-supply-chain-attack-windows-0-day-yum-brands--53564882</link><description><![CDATA[Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br />Discussed this month:<br /><br />Windows zero-day exploited in the wild https://projecthyphae.com/threat/windows-zero-day-being-exploited-in-ransomware-attacks/<br /><br />3CX Supply Chain Attack https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html<br /><br />No evidence of…oh wait, your data was stolen (Yum! Brands breach) https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/<br /><br />Patch quick hits<br /><br />Adobe: https://www.cisa.gov/news-events/alerts/2023/04/11/adobe-releases-security-updates-multiple-products <br /><br />Apple: https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-update-iphones-macs-by-may-1st/<br /><br />Cisco: https://www.cisa.gov/news-events/alerts/2023/03/23/cisco-releases-security-advisories-multiple-products <br /><br />Fortinet: https://www.cisa.gov/news-events/alerts/2023/04/11/fortinet-releases-april-2023-vulnerability-advisories <br /><br />Microsoft: https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/<br /><br />SAP: https://www.bleepingcomputer.com/news/security/sap-releases-security-updates-for-two-critical-severity-flaws/ <br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/53564882</guid><pubDate>Mon, 17 Apr 2023 22:42:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53564882/hacklebox_april_2023.mp3" length="68336861" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

Discussed this month:

Windows zero-day exploited in the wild...</itunes:subtitle><itunes:summary><![CDATA[Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br />Discussed this month:<br /><br />Windows zero-day exploited in the wild https://projecthyphae.com/threat/windows-zero-day-being-exploited-in-ransomware-attacks/<br /><br />3CX Supply Chain Attack https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html<br /><br />No evidence of…oh wait, your data was stolen (Yum! Brands breach) https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/<br /><br />Patch quick hits<br /><br />Adobe: https://www.cisa.gov/news-events/alerts/2023/04/11/adobe-releases-security-updates-multiple-products <br /><br />Apple: https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-update-iphones-macs-by-may-1st/<br /><br />Cisco: https://www.cisa.gov/news-events/alerts/2023/03/23/cisco-releases-security-advisories-multiple-products <br /><br />Fortinet: https://www.cisa.gov/news-events/alerts/2023/04/11/fortinet-releases-april-2023-vulnerability-advisories <br /><br />Microsoft: https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/<br /><br />SAP: https://www.bleepingcomputer.com/news/security/sap-releases-security-updates-for-two-critical-severity-flaws/ <br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>2845</itunes:duration><itunes:keywords>2022,beginners,cyber,cybersecurity,ethical,for,fr,frsecure,hacking,hunting,information,infosec,minks,news,oscar,podcast,security,threat,tldr,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Security News Roundup</title><link>https://www.spreaker.com/episode/security-news-roundup--53474515</link><description><![CDATA[This week, Oscar and Brad sit down to catch up on all the latest in security news. <br /><br />Links:<br /><br />The Sound of Silence Critical Microsoft Outlook Vulnerability https://projecthyphae.com/threat/the-sound-of-silence-critical-microsoft-outlook-vulnerability/<br /><br />Fastest Ransomware Encryption in History<br />https://gbhackers.com/rorschach/<br /><br />'Operation Cookie Monster': International police action seizes dark web market https://www.reuters.com/world/uk/operation-cookie-monster-international-police-action-seizes-dark-web-market-2023-04-05/<br /><br />Check your hack<br />https://www.politie.nl/en/information/checkyourhack.html<br /><br />Send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/53474515</guid><pubDate>Fri, 07 Apr 2023 21:42:31 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53474515/episode_200.mp3" length="49073909" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>This week, Oscar and Brad sit down to catch up on all the latest in security news. 

Links:

The Sound of Silence Critical Microsoft Outlook Vulnerability https://projecthyphae.com/threat/the-sound-of-silence-critical-microsoft-outlook-vulnerability/...</itunes:subtitle><itunes:summary><![CDATA[This week, Oscar and Brad sit down to catch up on all the latest in security news. <br /><br />Links:<br /><br />The Sound of Silence Critical Microsoft Outlook Vulnerability https://projecthyphae.com/threat/the-sound-of-silence-critical-microsoft-outlook-vulnerability/<br /><br />Fastest Ransomware Encryption in History<br />https://gbhackers.com/rorschach/<br /><br />'Operation Cookie Monster': International police action seizes dark web market https://www.reuters.com/world/uk/operation-cookie-monster-international-police-action-seizes-dark-web-market-2023-04-05/<br /><br />Check your hack<br />https://www.politie.nl/en/information/checkyourhack.html<br /><br />Send any questions, comments, or feedback to unsecurity@protonmail.com. Don't forget to like and subscribe!]]></itunes:summary><itunes:duration>2042</itunes:duration><itunes:keywords>brad,ciso,cissp,cyber,cybersecurity,data,evan,francen,frsecure,information,minks,network,nigh,oscar,podcast,privacy,project,security,securitystudio,unsecurity</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Rise of Exfil-Only Ransom Attacks, &amp; New Threats</title><link>https://www.spreaker.com/episode/the-rise-of-exfil-only-ransom-attacks-new-threats--53186937</link><description><![CDATA[Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br />Discussed this month:<br /><br />Microsoft Word vulnerability goes public<br />https://projecthyphae.com/threat/microsoft-word-vulnerability-goes-public-users-wondering-if-a-rtf-means-risky-text-file/<br /><br />Emotet is back (again) after another hiatus<br />https://www.darkreading.com/threat-intelligence/emotet-resurfaces-yet-again-after-three-month-hiatus<br /><br />Security concerns over employees feeding ChatGPT sensitive data<br />https://www.darkreading.com/risk/employees-feeding-sensitive-business-data-chatgpt-raising-security-fears<br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/53186937</guid><pubDate>Mon, 13 Mar 2023 19:27:44 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/53186937/hacklebox_march_2023.mp3" length="85462948" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

Discussed this month:

Microsoft Word vulnerability goes public...</itunes:subtitle><itunes:summary><![CDATA[Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br />Discussed this month:<br /><br />Microsoft Word vulnerability goes public<br />https://projecthyphae.com/threat/microsoft-word-vulnerability-goes-public-users-wondering-if-a-rtf-means-risky-text-file/<br /><br />Emotet is back (again) after another hiatus<br />https://www.darkreading.com/threat-intelligence/emotet-resurfaces-yet-again-after-three-month-hiatus<br /><br />Security concerns over employees feeding ChatGPT sensitive data<br />https://www.darkreading.com/risk/employees-feeding-sensitive-business-data-chatgpt-raising-security-fears<br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3558</itunes:duration><itunes:keywords>2022,beginners,cyber,cybersecurity,ethical,for,fr,frsecure,hacking,hunting,information,infosec,minks,news,oscar,podcast,security,threat,tldr,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Developer Pleads Guilty to Hacking His Own Company</title><link>https://www.spreaker.com/episode/developer-pleads-guilty-to-hacking-his-own-company--52721266</link><description><![CDATA[Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br />Discussed this month:<br /><br />Developer pleads guilty to hacking his own company https://www.theverge.com/2023/2/3/23584414/ubiquiti-developer-guilty-extortion-hack-security-breach-bitcoin-ransom<br /><br />Google plagued with 'malvertisers' in January 2023 https://arstechnica.com/information-technology/2023/02/until-further-notice-think-twice-before-using-google-to-download-software/<br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/52721266</guid><pubDate>Mon, 13 Feb 2023 22:23:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52721266/hacklebox_february_2023.mp3" length="83318817" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

Discussed this month:

Developer pleads guilty to hacking his own company...</itunes:subtitle><itunes:summary><![CDATA[Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.<br /><br />Discussed this month:<br /><br />Developer pleads guilty to hacking his own company https://www.theverge.com/2023/2/3/23584414/ubiquiti-developer-guilty-extortion-hack-security-breach-bitcoin-ransom<br /><br />Google plagued with 'malvertisers' in January 2023 https://arstechnica.com/information-technology/2023/02/until-further-notice-think-twice-before-using-google-to-download-software/<br /><br />Follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3469</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Rackspace Ransomware, 98 Microsoft Patches, &amp; More</title><link>https://www.spreaker.com/episode/rackspace-ransomware-98-microsoft-patches-more--52465792</link><description><![CDATA[Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, security breaches, and exploits.<br /><br />Discussed this month:<br />Rackspace Ransomware Incident Highlights Risks of Relying on Mitigation Alone https://www.darkreading.com/vulnerabilities-threats/rackspace-ransomware-incident-highlights-risks-mitigation-alone<br /><br />Attackers Are Already Exploiting ChatGPT to Write Malicious Code https://www.darkreading.com/attacks-breaches/attackers-are-already-exploiting-chatgpt-to-write-malicious-code<br /><br />98 Patches: Microsoft Greets New Year With Zero-Day Security Fixes https://www.darkreading.com/vulnerabilities-threats/microsoft-new-year-patches-98-security-fixes<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/52465792</guid><pubDate>Tue, 17 Jan 2023 18:05:53 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52465792/january_2023.mp3" length="77419950" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, security breaches, and exploits.

Discussed this month:
Rackspace...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, security breaches, and exploits.<br /><br />Discussed this month:<br />Rackspace Ransomware Incident Highlights Risks of Relying on Mitigation Alone https://www.darkreading.com/vulnerabilities-threats/rackspace-ransomware-incident-highlights-risks-mitigation-alone<br /><br />Attackers Are Already Exploiting ChatGPT to Write Malicious Code https://www.darkreading.com/attacks-breaches/attackers-are-already-exploiting-chatgpt-to-write-malicious-code<br /><br />98 Patches: Microsoft Greets New Year With Zero-Day Security Fixes https://www.darkreading.com/vulnerabilities-threats/microsoft-new-year-patches-98-security-fixes<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecureofficial/ <br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3223</itunes:duration><itunes:keywords>2022,beginners,cyber,cybersecurity,ethical,for,fr,frsecure,hacking,hunting,information,infosec,minks,news,oscar,podcast,security,threat,tldr,today</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>New CISA Reporting Rule, Russian Attacks on Ukrainian Orgs, &amp; More.</title><link>https://frsecure.com/cyber-threat-intel-series/</link><description><![CDATA[Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Discussed this month: <br /><br />Russian Actors Use Compromised Healthcare Networks Against Ukrainian Orgs<br />https://www.darkreading.com/threat-intelligence/russian-actors-compromised-healthcare-networks-ukrainian-orgs<br /><br />Malware Authors Inadvertently Take Down Own Botnet<br />https://www.darkreading.com/attacks-breaches/malware-authors-inadvertently-takdown-own-botnet<br /><br />All You Need to Know About Emotet in 2022<br />https://thehackernews.com/2022/11/all-you-need-to-know-about-emotet-in.html<br /><br />What the CISA Reporting Rule Means for Your IT Security Protocol<br />https://thehackernews.com/2022/12/what-cisa-reporting-rule-means-for-your.html<br /><br />Rackspace Ransomware Attack Outage<br />https://www.bleepingcomputer.com/news/security/rackspace-confirms-outage-was-caused-by-ransomware-attack/<br /><br />Report: Air-Gapped Networks Vulnerable to DNS Attacks<br />https://www.darkreading.com/attacks-breaches/report-air-gapped-networks-vulnerable-dns-attacks<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/52167379</guid><pubDate>Mon, 12 Dec 2022 20:52:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/52167379/hackle_box_december_2022.mp3" length="79905136" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

Discussed this month:...</itunes:subtitle><itunes:summary><![CDATA[Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Discussed this month: <br /><br />Russian Actors Use Compromised Healthcare Networks Against Ukrainian Orgs<br />https://www.darkreading.com/threat-intelligence/russian-actors-compromised-healthcare-networks-ukrainian-orgs<br /><br />Malware Authors Inadvertently Take Down Own Botnet<br />https://www.darkreading.com/attacks-breaches/malware-authors-inadvertently-takdown-own-botnet<br /><br />All You Need to Know About Emotet in 2022<br />https://thehackernews.com/2022/11/all-you-need-to-know-about-emotet-in.html<br /><br />What the CISA Reporting Rule Means for Your IT Security Protocol<br />https://thehackernews.com/2022/12/what-cisa-reporting-rule-means-for-your.html<br /><br />Rackspace Ransomware Attack Outage<br />https://www.bleepingcomputer.com/news/security/rackspace-confirms-outage-was-caused-by-ransomware-attack/<br /><br />Report: Air-Gapped Networks Vulnerable to DNS Attacks<br />https://www.darkreading.com/attacks-breaches/report-air-gapped-networks-vulnerable-dns-attacks<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3327</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>VMware Bugs &amp; Remote Workspaces, Long Island Midterms Delayed, &amp; More.</title><link>https://www.spreaker.com/episode/vmware-bugs-remote-workspaces-long-island-midterms-delayed-more--51902927</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Discussed this month: <br /><br />Critical Citrix, VMware Bugs threaten remote workspaces<br />https://www.darkreading.com/vulnerabilities-threats/patch-asap-critical-citrix-vmware-bugs-remote-workspaces-takeover<br /><br />Long Island midterm votes delayed due to cyberattack<br />https://www.darkreading.com/attacks-breaches/long-island-midterm-votes-delayed-due-to-cyberattack-after-effects<br /><br />Microsoft Exchange vulnerability update<br /><br />Healthcare sector: Security threat landscape update<br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/51902927</guid><pubDate>Wed, 16 Nov 2022 16:55:25 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/51902927/november_2022.mp3" length="86827167" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

Discussed this...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Discussed this month: <br /><br />Critical Citrix, VMware Bugs threaten remote workspaces<br />https://www.darkreading.com/vulnerabilities-threats/patch-asap-critical-citrix-vmware-bugs-remote-workspaces-takeover<br /><br />Long Island midterm votes delayed due to cyberattack<br />https://www.darkreading.com/attacks-breaches/long-island-midterm-votes-delayed-due-to-cyberattack-after-effects<br /><br />Microsoft Exchange vulnerability update<br /><br />Healthcare sector: Security threat landscape update<br /><br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3615</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Fortinet Authentication Bypass, ProxyShell 2 (or 3?), and More!</title><link>https://www.spreaker.com/episode/fortinet-authentication-bypass-proxyshell-2-or-3-and-more--51601666</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Discussed this month: <br /><br />Fortinet Authentication Bypass<br />ZeroDay: ProxyShell 2 (or 3?)<br />Microsoft Addresses Zero-Days, Exchange Server Exploit Chain Remains Unpatched<br />Phishing Attacks Improving Dramatically<br />Emotet is Back<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/51601666</guid><pubDate>Mon, 17 Oct 2022 19:53:25 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/51601666/october_2022.mp3" length="86882964" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

Discussed this...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Discussed this month: <br /><br />Fortinet Authentication Bypass<br />ZeroDay: ProxyShell 2 (or 3?)<br />Microsoft Addresses Zero-Days, Exchange Server Exploit Chain Remains Unpatched<br />Phishing Attacks Improving Dramatically<br />Emotet is Back<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3617</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Defcon Recap, EvilProxy, TeslaGun, Broken Ice Cream Machines</title><link>https://www.spreaker.com/episode/defcon-recap-evilproxy-teslagun-broken-ice-cream-machines--51247001</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br />Defcon Recap<br />EvilProxy<br />TeslaGun<br />Broken Ice Cream Machines and McDonalds<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/51247001</guid><pubDate>Tue, 13 Sep 2022 19:51:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/51247001/sep_2022_final.mp3" length="76445061" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

This month's...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br />Defcon Recap<br />EvilProxy<br />TeslaGun<br />Broken Ice Cream Machines and McDonalds<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: https://www.facebook.com/frsecure/<br />Twitter: https://twitter.com/frsecure/<br />Instagram: https://www.instagram.com/frsecure/<br />LinkedIn: https://www.linkedin.com/company/frsecure/]]></itunes:summary><itunes:duration>3183</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box July 2022: NPM All Over the News, APT Targeting Healthcare Sector, and More</title><link>https://www.spreaker.com/episode/the-hackle-box-july-2022-npm-all-over-the-news-apt-targeting-healthcare-sector-and-more--50540055</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />NPM supply chain attack impacts hundreds of websites and apps<br /><a href="https://www.bleepingcomputer.com/news/security/npm-supply-chain-attack-impacts-hundreds-of-websites-and-apps/" rel="noopener">https://www.bleepingcomputer.com/news/security/npm-supply-chain-attack-impacts-hundreds-of-websites-and-apps/</a><br /><br />PyPi sending stolen AWS keys to unsecured sites<br /><a href="https://www.bleepingcomputer.com/news/security/pypi-python-packages-caught-sending-stolen-aws-keys-to-unsecured-sites/" rel="noopener">https://www.bleepingcomputer.com/news/security/pypi-python-packages-caught-sending-stolen-aws-keys-to-unsecured-sites/</a><br /><br />NPM packages involved in crypto mining<br /><a href="https://thehackernews.com/2022/07/over-1200-npm-packages-found-involved.html" rel="noopener">https://thehackernews.com/2022/07/over-1200-npm-packages-found-involved.html</a><br /><br />CISA alert for North Korean APT targeting the healthcare sector<br /><a href="https://www.cisa.gov/uscert/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware" rel="noopener">https://www.cisa.gov/uscert/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware</a><br /><br /><a href="https://thehackernews.com/2022/07/north-korean-maui-ransomware-actively.html" rel="noopener">https://thehackernews.com/2022/07/north-korean-maui-ransomware-actively.html</a><br /><br />Microsoft Edge WebView2 manipulated for cookie theft<br /><a href="https://projecthyphae.com/threat/microsoft-edge-webview2-manipulated-for-theft-of-cookies/" rel="noopener">https://projecthyphae.com/threat/microsoft-edge-webview2-manipulated-for-theft-of-cookies/</a><br /><br />Criminals are filling job applicant pools with deepfakes<br /><a href="https://projecthyphae.com/threat/criminals-are-filling-tech-job-applicant-pools-with-deepfakes/" rel="noopener">https://projecthyphae.com/threat/criminals-are-filling-tech-job-applicant-pools-with-deepfakes/</a><br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50540055</guid><pubDate>Mon, 11 Jul 2022 20:40:57 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50540055/hacklebox_july_2022.mp3" length="78525870" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
This month's...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />NPM supply chain attack impacts hundreds of websites and apps<br /><a href="https://www.bleepingcomputer.com/news/security/npm-supply-chain-attack-impacts-hundreds-of-websites-and-apps/" rel="noopener">https://www.bleepingcomputer.com/news/security/npm-supply-chain-attack-impacts-hundreds-of-websites-and-apps/</a><br /><br />PyPi sending stolen AWS keys to unsecured sites<br /><a href="https://www.bleepingcomputer.com/news/security/pypi-python-packages-caught-sending-stolen-aws-keys-to-unsecured-sites/" rel="noopener">https://www.bleepingcomputer.com/news/security/pypi-python-packages-caught-sending-stolen-aws-keys-to-unsecured-sites/</a><br /><br />NPM packages involved in crypto mining<br /><a href="https://thehackernews.com/2022/07/over-1200-npm-packages-found-involved.html" rel="noopener">https://thehackernews.com/2022/07/over-1200-npm-packages-found-involved.html</a><br /><br />CISA alert for North Korean APT targeting the healthcare sector<br /><a href="https://www.cisa.gov/uscert/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware" rel="noopener">https://www.cisa.gov/uscert/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware</a><br /><br /><a href="https://thehackernews.com/2022/07/north-korean-maui-ransomware-actively.html" rel="noopener">https://thehackernews.com/2022/07/north-korean-maui-ransomware-actively.html</a><br /><br />Microsoft Edge WebView2 manipulated for cookie theft<br /><a href="https://projecthyphae.com/threat/microsoft-edge-webview2-manipulated-for-theft-of-cookies/" rel="noopener">https://projecthyphae.com/threat/microsoft-edge-webview2-manipulated-for-theft-of-cookies/</a><br /><br />Criminals are filling job applicant pools with deepfakes<br /><a href="https://projecthyphae.com/threat/criminals-are-filling-tech-job-applicant-pools-with-deepfakes/" rel="noopener">https://projecthyphae.com/threat/criminals-are-filling-tech-job-applicant-pools-with-deepfakes/</a><br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3269</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box June 2022: Atlassian Confluence, Follina, Chinese Attackers Breach Telcos, and More</title><link>https://www.spreaker.com/episode/the-hackle-box-june-2022-atlassian-confluence-follina-chinese-attackers-breach-telcos-and-more--50188972</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />02:14 Atlassian Confluence – CVE-2022-26134<br /><a href="https://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html" rel="noopener">https://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html</a><br /><br />13:25 Follina<br /><a href="https://threatpost.com/follina-exploited-by-state-sponsored-hackers/179890/" rel="noopener">https://threatpost.com/follina-exploited-by-state-sponsored-hackers/179890/</a><br /><br />32:40 Paid a ransom? Now you’re a target.<br /><a href="https://threatpost.com/paying-ransomware-bullseye-back/179915/" rel="noopener">https://threatpost.com/paying-ransomware-bullseye-back/179915/</a><br /><br />47:30 Chinese State Attackers Breached Telcos<br /><a href="https://www.bleepingcomputer.com/news/security/us-chinese-govt-hackers-breached-telcos-to-snoop-on-network-traffic/" rel="noopener">https://www.bleepingcomputer.com/news/security/us-chinese-govt-hackers-breached-telcos-to-snoop-on-network-traffic/</a><br /><br />52:50 Kali team offering free penetration testing course on Twitch!<br /><a href="https://www.bleepingcomputer.com/news/security/kali-linux-team-to-stream-free-penetration-testing-course-on-twitch/" rel="noopener">https://www.bleepingcomputer.com/news/security/kali-linux-team-to-stream-free-penetration-testing-course-on-twitch/</a><br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50188972</guid><pubDate>Mon, 13 Jun 2022 19:08:22 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50188972/hacklebox_june_2022.mp3" length="80947108" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
This month's...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />02:14 Atlassian Confluence – CVE-2022-26134<br /><a href="https://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html" rel="noopener">https://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html</a><br /><br />13:25 Follina<br /><a href="https://threatpost.com/follina-exploited-by-state-sponsored-hackers/179890/" rel="noopener">https://threatpost.com/follina-exploited-by-state-sponsored-hackers/179890/</a><br /><br />32:40 Paid a ransom? Now you’re a target.<br /><a href="https://threatpost.com/paying-ransomware-bullseye-back/179915/" rel="noopener">https://threatpost.com/paying-ransomware-bullseye-back/179915/</a><br /><br />47:30 Chinese State Attackers Breached Telcos<br /><a href="https://www.bleepingcomputer.com/news/security/us-chinese-govt-hackers-breached-telcos-to-snoop-on-network-traffic/" rel="noopener">https://www.bleepingcomputer.com/news/security/us-chinese-govt-hackers-breached-telcos-to-snoop-on-network-traffic/</a><br /><br />52:50 Kali team offering free penetration testing course on Twitch!<br /><a href="https://www.bleepingcomputer.com/news/security/kali-linux-team-to-stream-free-penetration-testing-course-on-twitch/" rel="noopener">https://www.bleepingcomputer.com/news/security/kali-linux-team-to-stream-free-penetration-testing-course-on-twitch/</a><br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3370</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box May 2022: F5-Big IP, Fileless Malware Hides Shellcode in Windows Event Logs, and More</title><link>https://www.spreaker.com/episode/the-hackle-box-may-2022-f5-big-ip-fileless-malware-hides-shellcode-in-windows-event-logs-and-more--49821730</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/49821730</guid><pubDate>Mon, 16 May 2022 20:35:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/49821730/hacklebox_may_2022.mp3" length="79498879" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
Please like,...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3310</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box April 2022: Fake Emergency Data Requests, Critical Spring4Shell Vulnerability, &amp; More</title><link>https://www.spreaker.com/episode/the-hackle-box-april-2022-fake-emergency-data-requests-critical-spring4shell-vulnerability-more--49401896</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />- Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests”<br />- Forged Signatures: Not Just For Troubled Youths Anymore. #Nvidia<br />- Sophos firewalls require an URGENT new flame shield<br />- CISA Warns of Active Exploitation of Critical Spring4Shell Vulnerability<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/49401896</guid><pubDate>Mon, 11 Apr 2022 21:00:47 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/49401896/hacklebox_april_2022.mp3" length="76940269" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
This month's...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />- Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests”<br />- Forged Signatures: Not Just For Troubled Youths Anymore. #Nvidia<br />- Sophos firewalls require an URGENT new flame shield<br />- CISA Warns of Active Exploitation of Critical Spring4Shell Vulnerability<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3203</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box March 2022: AutoWarp Vulnerability, APC Burning Down, Dirty Pipe Exploit</title><link>https://www.spreaker.com/episode/the-hackle-box-march-2022-autowarp-vulnerability-apc-burning-down-dirty-pipe-exploit--49060798</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />- AutoWarp vulnerability in Microsoft Azure<br />- APC's Burning Down<br />- Dirty Pipe<br />- Russian Attack on Ukraine<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/49060798</guid><pubDate>Mon, 14 Mar 2022 19:53:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/49060798/hacklebox_march_2022.mp3" length="86379558" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
This month's...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />- AutoWarp vulnerability in Microsoft Azure<br />- APC's Burning Down<br />- Dirty Pipe<br />- Russian Attack on Ukraine<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3597</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box February 2022: EyeMed Breach, Data Exfil Using PowerAutomate, Google MFA.</title><link>https://www.spreaker.com/episode/the-hackle-box-february-2022-eyemed-breach-data-exfil-using-powerautomate-google-mfa--48745501</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />- EyeMed fined $600k in data breach<br />- Attackers reviving a 20-year-old tactic in Microsoft 365 phishing campaigns<br />- Google auto-enables two-step verification for more than 150 Million users<br />- A new tactic for data exfil using Power Automate in Microsoft 365<br /><br />Please like, subscribe, and follow us on social!<br /><br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/48745501</guid><pubDate>Wed, 16 Feb 2022 17:27:44 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/48745501/hacklebox_02112022_final.mp3" length="84288072" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
This month's...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month's episode includes:<br /><br />- EyeMed fined $600k in data breach<br />- Attackers reviving a 20-year-old tactic in Microsoft 365 phishing campaigns<br />- Google auto-enables two-step verification for more than 150 Million users<br />- A new tactic for data exfil using Power Automate in Microsoft 365<br /><br />Please like, subscribe, and follow us on social!<br /><br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3509</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box January 2022: Log4j, Russian Cyber Threat, AV Cryptominers, Patch Tuesday</title><link>https://www.spreaker.com/episode/the-hackle-box-january-2022-log4j-russian-cyber-threat-av-cryptominers-patch-tuesday--48351090</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month,  the trio dives into:<br /><br />• Log4j Overview and updates <br />• CSA advisory on Russian Cyber Threat to US Critical Infrastructure.<br />• Norton and Cryptominers in your AV <br />• Patch Tuesday: 96 patches to start 2022<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/48351090</guid><pubDate>Tue, 18 Jan 2022 19:10:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/48351090/final_audio.mp3" length="81793483" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.&#13;
&#13;
This month,  the...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month,  the trio dives into:<br /><br />• Log4j Overview and updates <br />• CSA advisory on Russian Cyber Threat to US Critical Infrastructure.<br />• Norton and Cryptominers in your AV <br />• Patch Tuesday: 96 patches to start 2022<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure/" rel="noopener">https://www.facebook.com/frsecure/</a><br />Twitter: <a href="https://twitter.com/frsecure/" rel="noopener">https://twitter.com/frsecure/</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure/" rel="noopener">https://www.linkedin.com/company/frsecure/</a>]]></itunes:summary><itunes:duration>3405</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box December 2021: Microsoft Exchange Exploit, FBI Website Hack, QuakNightmare</title><link>https://www.spreaker.com/episode/the-hackle-box-december-2021-microsoft-exchange-exploit-fbi-website-hack-quaknightmare--47921737</link><description><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month,  the trio dives into:<br /><br />• Cyber Actors Exploiting Microsoft Exchange in Furtherance of Malicious Activities<br />• FBI Website exploited resulting in hoax email blast<br />• Quakbot strikes again with QuakNightmare Exploitation<br /><br />In addition to the newsworthy topics, they also have a couple of recurring segments:<br /><br />Phishing Report - ACH Fraud in Proxylogon attack chain<br />Hacker Tip of the Month<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure" rel="noopener">https://www.facebook.com/frsecure</a><br />Twitter: <a href="https://twitter.com/FRSecure" rel="noopener">https://twitter.com/FRSecure</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frse.." rel="noopener">https://www.linkedin.com/company/frse..</a>.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47921737</guid><pubDate>Tue, 14 Dec 2021 19:32:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47921737/hacklebox_december_2021.mp3" length="85360138" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.

This month,  the...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them.<br /><br />This month,  the trio dives into:<br /><br />• Cyber Actors Exploiting Microsoft Exchange in Furtherance of Malicious Activities<br />• FBI Website exploited resulting in hoax email blast<br />• Quakbot strikes again with QuakNightmare Exploitation<br /><br />In addition to the newsworthy topics, they also have a couple of recurring segments:<br /><br />Phishing Report - ACH Fraud in Proxylogon attack chain<br />Hacker Tip of the Month<br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure" rel="noopener">https://www.facebook.com/frsecure</a><br />Twitter: <a href="https://twitter.com/FRSecure" rel="noopener">https://twitter.com/FRSecure</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frse.." rel="noopener">https://www.linkedin.com/company/frse..</a>.]]></itunes:summary><itunes:duration>3554</itunes:duration><itunes:keywords>ambush,box,breaches,data,day,email,frsecure,hacking,hackle,information,infosec,minks,oscar,phishing,ransomware,security,servers,team,vulnerabilities,zero</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box November 2021: Holiday Phishing Scams, SolarWinds Fallout, Microsoft Exchange, Ryuk</title><link>https://www.spreaker.com/episode/the-hackle-box-november-2021-holiday-phishing-scams-solarwinds-fallout-microsoft-exchange-ryuk--47525288</link><description><![CDATA[Oscar, Eric, and Pinky are back with another session of the Hackle Box, a series where they break down current cybersecurity threats, breaches, vulnerabilities, and more. This month, the trio discusses:<br /><br />Phishing Report – Holiday Phishing Trends <br />Hacker Tip of the Month<br /><br />News Topics: <br /><br />‘Trojan Source’ Bug Threatens the Security of All Code <br /><a href="https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/" rel="noopener">https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/</a> <br /><br />FBI Raids Chinese Point-of-Sale Giant PAX Technology <br /><a href="https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/" rel="noopener">https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/</a> <br /><br />Microsoft Fixes Exchange Server Zero-Day <br /><a href="https://www.darkreading.com/vulnerabilities-threats/microsoft-s-nov-security-update-contains-fix-for-exchange-server-0-day" rel="noopener">https://www.darkreading.com/vulnerabilities-threats/microsoft-s-nov-security-update-contains-fix-for-exchange-server-0-day</a> <br /><br />SolarWinds Vulnerability Exploited in First Stage of Clop Ransomware Attacks <br /><a href="https://www.darkreading.com/attacks-breaches/rise-in-clop-ransomware-attacks-tied-to" rel="noopener">https://www.darkreading.com/attacks-breaches/rise-in-clop-ransomware-attacks-tied-to</a> <br /><br />Researcher Details Vulnerabilities Found in AWS API Gateway <br /><a href="https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway" rel="noopener">https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway</a> <br /><br />RYUK is back! <br /><a href="https://thedfirreport.com/2020/10/08/ryuks-return/" rel="noopener">https://thedfirreport.com/2020/10/08/ryuks-return/</a> <br /><a href="https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/" rel="noopener">https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/</a> <br /><br />QR Codes Help Attackers Sneak Emails Past Security Controls <br /><a href="https://www.darkreading.com/attacks-breaches/qr-codes-help-attackers-sneak-emails-past-security-controls" rel="noopener">https://www.darkreading.com/attacks-breaches/qr-codes-help-attackers-sneak-emails-past-security-controls</a> <br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure" rel="noopener">https://www.facebook.com/frsecure</a><br />Twitter: <a href="https://twitter.com/FRSecure" rel="noopener">https://twitter.com/FRSecure</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure" rel="noopener">https://www.linkedin.com/company/frsecure</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47525288</guid><pubDate>Wed, 17 Nov 2021 19:57:39 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47525288/hacklebox_november_2021_podcast.mp3" length="81654929" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Oscar, Eric, and Pinky are back with another session of the Hackle Box, a series where they break down current cybersecurity threats, breaches, vulnerabilities, and more. This month, the trio discusses:

Phishing Report – Holiday Phishing Trends...</itunes:subtitle><itunes:summary><![CDATA[Oscar, Eric, and Pinky are back with another session of the Hackle Box, a series where they break down current cybersecurity threats, breaches, vulnerabilities, and more. This month, the trio discusses:<br /><br />Phishing Report – Holiday Phishing Trends <br />Hacker Tip of the Month<br /><br />News Topics: <br /><br />‘Trojan Source’ Bug Threatens the Security of All Code <br /><a href="https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/" rel="noopener">https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/</a> <br /><br />FBI Raids Chinese Point-of-Sale Giant PAX Technology <br /><a href="https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/" rel="noopener">https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/</a> <br /><br />Microsoft Fixes Exchange Server Zero-Day <br /><a href="https://www.darkreading.com/vulnerabilities-threats/microsoft-s-nov-security-update-contains-fix-for-exchange-server-0-day" rel="noopener">https://www.darkreading.com/vulnerabilities-threats/microsoft-s-nov-security-update-contains-fix-for-exchange-server-0-day</a> <br /><br />SolarWinds Vulnerability Exploited in First Stage of Clop Ransomware Attacks <br /><a href="https://www.darkreading.com/attacks-breaches/rise-in-clop-ransomware-attacks-tied-to" rel="noopener">https://www.darkreading.com/attacks-breaches/rise-in-clop-ransomware-attacks-tied-to</a> <br /><br />Researcher Details Vulnerabilities Found in AWS API Gateway <br /><a href="https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway" rel="noopener">https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway</a> <br /><br />RYUK is back! <br /><a href="https://thedfirreport.com/2020/10/08/ryuks-return/" rel="noopener">https://thedfirreport.com/2020/10/08/ryuks-return/</a> <br /><a href="https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/" rel="noopener">https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/</a> <br /><br />QR Codes Help Attackers Sneak Emails Past Security Controls <br /><a href="https://www.darkreading.com/attacks-breaches/qr-codes-help-attackers-sneak-emails-past-security-controls" rel="noopener">https://www.darkreading.com/attacks-breaches/qr-codes-help-attackers-sneak-emails-past-security-controls</a> <br /><br />Please like, subscribe, and follow us on social!<br />Facebook: <a href="https://www.facebook.com/frsecure" rel="noopener">https://www.facebook.com/frsecure</a><br />Twitter: <a href="https://twitter.com/FRSecure" rel="noopener">https://twitter.com/FRSecure</a><br />Instagram: <a href="https://www.instagram.com/frsecure/" rel="noopener">https://www.instagram.com/frsecure/</a><br />LinkedIn: <a href="https://www.linkedin.com/company/frsecure" rel="noopener">https://www.linkedin.com/company/frsecure</a>]]></itunes:summary><itunes:duration>3400</itunes:duration><itunes:keywords>ambush,box,breaches,bug,data,frsecure,hacking,hackle,information,infosec,microsoft,minks,oscar,pax,phishing,security,team,technology,trojan,vulnerabilities</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box October 2021: REBOL Yell, Microsoft Going Password-less, OMIGOD, Microsoft Azure</title><link>https://www.spreaker.com/episode/the-hackle-box-october-2021-rebol-yell-microsoft-going-password-less-omigod-microsoft-azure--46928521</link><description><![CDATA[Team Ambush members Oscar, Eric, and Pinky are back with another session of the Hackle Box—a series where they break down new and noteworthy breaches, vulnerabilities, exploits, and more over the last month.<br /><br />This month's topics:<br /><br />Microsoft going “passwordless”<br /><a href="https://arstechnica.com/gadgets/2021/09/starting-today-you-can-remove-your-password-from-your-microsoft-account/" rel="noopener">https://arstechnica.com/gadgets/2021/09/starting-today-you-can-remove-your-password-from-your-microsoft-account/</a><br /><br />OMIGOD—an exploitable hole in Microsoft open-source code<br /><a href="https://nakedsecurity.sophos.com/2021/09/16/omigod-an-exploitable-hole-in-microsoft-open-source-code/" rel="noopener">https://nakedsecurity.sophos.com/2021/09/16/omigod-an-exploitable-hole-in-microsoft-open-source-code/</a><br /><br />New Azure Active Directory password brute-forcing flaw has no fix<br /><a href="https://arstechnica.com/information-technology/2021/09/new-azure-active-directory-password-brute-forcing-flaw-has-no-fix/?amp=1" rel="noopener">https://arstechnica.com/information-technology/2021/09/new-azure-active-directory-password-brute-forcing-flaw-has-no-fix/?amp=1</a><br /><br />Does your organization have a Security.txt file?<br /><a href="https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/" rel="noopener">https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/</a><br /><br />CISA releases tool to help orgs fend off insider threat risks<br /><a href="https://www.bleepingcomputer.com/news/security/cisa-releases-tool-to-help-orgs-fend-off-insider-threat-risks/?utm_content=182136940&utm_medium=social&utm_source=twitter&hss_channel=tw-71605818" rel="noopener">https://www.bleepingcomputer.com/news/security/cisa-releases-tool-to-help-orgs-fend-off-insider-threat-risks/?utm_content=182136940&utm_medium=social&utm_source=twitter&hss_channel=tw-71605818</a><br /><br />The REBOL Yell—novel exploit using REBOL for command-and-control<br /><a href="https://frsecure.com/blog/the-rebol-yell-new-rebol-exploit/" rel="noopener">https://frsecure.com/blog/the-rebol-yell-new-rebol-exploit/</a><br /><br />Teasing Project Hyphae<br /><br />As always, the session ends with the Hacker Tip of the Month from Eric and the Phishing Report with Pinky.<br /><br />Give this session a watch or listen, and feel free to send any comments, questions, or topic suggestions to <a href="mailto:hacklebox@frsecure.com">hacklebox@frsecure.com</a>.<br /><br />And please like and subscribe!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/46928521</guid><pubDate>Mon, 11 Oct 2021 22:28:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/46928521/10082021_episode.mp3" length="88875516" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Team Ambush members Oscar, Eric, and Pinky are back with another session of the Hackle Box—a series where they break down new and noteworthy breaches, vulnerabilities, exploits, and more over the last month.

This month's topics:

Microsoft going...</itunes:subtitle><itunes:summary><![CDATA[Team Ambush members Oscar, Eric, and Pinky are back with another session of the Hackle Box—a series where they break down new and noteworthy breaches, vulnerabilities, exploits, and more over the last month.<br /><br />This month's topics:<br /><br />Microsoft going “passwordless”<br /><a href="https://arstechnica.com/gadgets/2021/09/starting-today-you-can-remove-your-password-from-your-microsoft-account/" rel="noopener">https://arstechnica.com/gadgets/2021/09/starting-today-you-can-remove-your-password-from-your-microsoft-account/</a><br /><br />OMIGOD—an exploitable hole in Microsoft open-source code<br /><a href="https://nakedsecurity.sophos.com/2021/09/16/omigod-an-exploitable-hole-in-microsoft-open-source-code/" rel="noopener">https://nakedsecurity.sophos.com/2021/09/16/omigod-an-exploitable-hole-in-microsoft-open-source-code/</a><br /><br />New Azure Active Directory password brute-forcing flaw has no fix<br /><a href="https://arstechnica.com/information-technology/2021/09/new-azure-active-directory-password-brute-forcing-flaw-has-no-fix/?amp=1" rel="noopener">https://arstechnica.com/information-technology/2021/09/new-azure-active-directory-password-brute-forcing-flaw-has-no-fix/?amp=1</a><br /><br />Does your organization have a Security.txt file?<br /><a href="https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/" rel="noopener">https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/</a><br /><br />CISA releases tool to help orgs fend off insider threat risks<br /><a href="https://www.bleepingcomputer.com/news/security/cisa-releases-tool-to-help-orgs-fend-off-insider-threat-risks/?utm_content=182136940&utm_medium=social&utm_source=twitter&hss_channel=tw-71605818" rel="noopener">https://www.bleepingcomputer.com/news/security/cisa-releases-tool-to-help-orgs-fend-off-insider-threat-risks/?utm_content=182136940&utm_medium=social&utm_source=twitter&hss_channel=tw-71605818</a><br /><br />The REBOL Yell—novel exploit using REBOL for command-and-control<br /><a href="https://frsecure.com/blog/the-rebol-yell-new-rebol-exploit/" rel="noopener">https://frsecure.com/blog/the-rebol-yell-new-rebol-exploit/</a><br /><br />Teasing Project Hyphae<br /><br />As always, the session ends with the Hacker Tip of the Month from Eric and the Phishing Report with Pinky.<br /><br />Give this session a watch or listen, and feel free to send any comments, questions, or topic suggestions to <a href="mailto:hacklebox@frsecure.com">hacklebox@frsecure.com</a>.<br /><br />And please like and subscribe!]]></itunes:summary><itunes:duration>3701</itunes:duration><itunes:keywords>active,ambush,azure,box,brute,cyber,cybersecurity,data,directory,force,hacking,hackle,microsoft,omigod,passwords,privacy,security,team,the,threats</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hackle Box September 2021: IDN Phishing, Razer Mouse, T-Mobile, Cobalt Strike, and OAuth 2.0</title><link>https://www.spreaker.com/episode/the-hackle-box-september-2021-idn-phishing-razer-mouse-t-mobile-cobalt-strike-and-oauth-2-0--46502172</link><description><![CDATA[The boys are back with another session of the Hackle Box. This month features in-depth discussion on four vulnerabilities/exploits that have gained the attention of Oscar, Pinky, and Eric over the last month or so.<br /><br />IDN Phishing — Outlook emails showing legitimate contact cards from lookalike domains<br /><a href="https://arstechnica.com/information-technology/2021/09/microsoft-outlook-shows-real-persons-contact-info-for-idn-phishing-emails/" rel="noopener">https://arstechnica.com/information-technology/2021/09/microsoft-outlook-shows-real-persons-contact-info-for-idn-phishing-emails/</a><br /><br />Razer Mouse Bug — The bug allows admin privileges in Windows 10<br /><a href="https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/" rel="noopener">https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/</a><br /><br />T-Mobile Breach — 48 million social security numbers accessed from a pool of 50 million affected customers<br /><a href="https://www.zdnet.com/article/t-mobile-hack-everything-you-need-to-know/" rel="noopener">https://www.zdnet.com/article/t-mobile-hack-everything-you-need-to-know/</a><br /><br />Hacking the Hackers — New exploit available for download lets hackers crash Cobalt Strike team servers<br /><a href="https://arstechnica.com/gadgets/2021/08/critical-cobalt-strike-bug-leaves-botnet-servers-vulnerable-to-takedown/" rel="noopener">https://arstechnica.com/gadgets/2021/08/critical-cobalt-strike-bug-leaves-botnet-servers-vulnerable-to-takedown/</a><br /><br />As always, the session ends with the Hacker Tip of the Month from Eric and the Phishing Report with Pinky.<br /><br />Give this session a watch or listen, and feel free to send any comments, questions, or topic suggestions to <a href="mailto:hacklebox@frsecure.com">hacklebox@frsecure.com</a>.<br /><br />And please like and subscribe!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/46502172</guid><pubDate>Mon, 13 Sep 2021 18:19:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/46502172/the_hacklebox_episode_1.mp3" length="84673187" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The boys are back with another session of the Hackle Box. This month features in-depth discussion on four vulnerabilities/exploits that have gained the attention of Oscar, Pinky, and Eric over the last month or so.

IDN Phishing — Outlook emails...</itunes:subtitle><itunes:summary><![CDATA[The boys are back with another session of the Hackle Box. This month features in-depth discussion on four vulnerabilities/exploits that have gained the attention of Oscar, Pinky, and Eric over the last month or so.<br /><br />IDN Phishing — Outlook emails showing legitimate contact cards from lookalike domains<br /><a href="https://arstechnica.com/information-technology/2021/09/microsoft-outlook-shows-real-persons-contact-info-for-idn-phishing-emails/" rel="noopener">https://arstechnica.com/information-technology/2021/09/microsoft-outlook-shows-real-persons-contact-info-for-idn-phishing-emails/</a><br /><br />Razer Mouse Bug — The bug allows admin privileges in Windows 10<br /><a href="https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/" rel="noopener">https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/</a><br /><br />T-Mobile Breach — 48 million social security numbers accessed from a pool of 50 million affected customers<br /><a href="https://www.zdnet.com/article/t-mobile-hack-everything-you-need-to-know/" rel="noopener">https://www.zdnet.com/article/t-mobile-hack-everything-you-need-to-know/</a><br /><br />Hacking the Hackers — New exploit available for download lets hackers crash Cobalt Strike team servers<br /><a href="https://arstechnica.com/gadgets/2021/08/critical-cobalt-strike-bug-leaves-botnet-servers-vulnerable-to-takedown/" rel="noopener">https://arstechnica.com/gadgets/2021/08/critical-cobalt-strike-bug-leaves-botnet-servers-vulnerable-to-takedown/</a><br /><br />As always, the session ends with the Hacker Tip of the Month from Eric and the Phishing Report with Pinky.<br /><br />Give this session a watch or listen, and feel free to send any comments, questions, or topic suggestions to <a href="mailto:hacklebox@frsecure.com">hacklebox@frsecure.com</a>.<br /><br />And please like and subscribe!]]></itunes:summary><itunes:duration>3526</itunes:duration><itunes:keywords>ambush,box,cobalt,cyber,cybersecurity,exploits,frsecure,hacking,hackle,hanson,information,intel,minks,oauth,owasp,security,thompson,threat,tmobile,vulnerabilities</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a21dd90560fa74363f1561192aa07d37.jpg"/><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
