Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
History
Music
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts125/v4/66/b8/45/66b8456d-b7eb-0c29-7d6b-a176ff890ec8/mza_638857556430010998.jpg/600x600bb.jpg
The Hackle Box
The InfoSec Mission
42 episodes
5 months ago
The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques, vulnerabilities, exploits, and more.
Show more...
Technology
RSS
All content for The Hackle Box is the property of The InfoSec Mission and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques, vulnerabilities, exploits, and more.
Show more...
Technology
Episodes (20/42)
The Hackle Box
June 2025: Q&A Session, CISA Updates
In this quarterly live Q&A session, the gang dives into the recent CISA budget cuts and hands it over to the audience for discussion. Tune in to get your updates, hear what folks are talking about, and a little on boats!

To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/

Please like, subscribe, and follow us on social! 
LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure: https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
5 months ago
48 minutes

The Hackle Box
Vibe Coding, Malicious AI Models, & More
Join us for our May Hackle Box session! The crew explores the emerging concept of "vibe coding", also known as vulnerability as a service, and unpacks its implications for cybersecurity. The team discusses how large language models (LLMs) may unknowingly import malicious code, raising critical concerns about training data integrity and AI trustworthiness.

Links:
"AI-Hallucinated Code Dependencies Become New Supply Chain Risk" 

"Vehicles Face 45% More Attacks, 4 Times More Hackers" https://www.darkreading.com/vulnerabilities-threats/vehicles-45-more-attacks-4-times-more-hackers

"'Venom Spider' Targets Hiring Managers in Phishing Scheme"
https://www.darkreading.com/cyber-risk/venom-spider-phishing-scheme

"CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation" https://www.darkreading.com/threat-intelligence/two-sonicwall-vulnerabilities-under-exploitation

"Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach" https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html

Be sure to submit your questions for our quarterly Q&A Episodes!
Ask Our Security Experts Anything!

To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/

Please like, subscribe, and follow us on social!

LinkedIn: frsecure
Instagram: @frsecureofficial
Facebook: frsecureBlueSky: @frsecure

About FRSecure:
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
5 months ago
1 hour

The Hackle Box
AI-Driven Attack Platforms, Record-Breaking Ransoms, Neptune RAT, & More!
In this month's edition of the Hackle Box, the guys are joined by Kevin Gunter, a penetration tester at FRSecure, to discuss "Xanthorox AI," a record-breaking $75M ransomware demand, a US Treasury breach going back to 2023, and Neptune RAT.

Links:
  • "Autonomous, GenAI-Driven Attacker Platform Enters the Chat"
    • https://www.darkreading.com/threat-intelligence/autonomous-genai-attacker-platform-chat 
  • "Fortune 50 Co. Pays Record-Breaking $75M Ransomware Demand"
    • https://www.darkreading.com/threat-intelligence/fortune-50-company-pays-record-breaking-75m-ransomware-demand
  • "Hackers lurked in Treasury OCC’s systems since June 2023 breach"
    • https://www.bleepingcomputer.com/news/security/hackers-lurked-in-treasury-occs-systems-since-june-2023-breach/
  • "NEPTUNE RAT : An advanced Windows RAT with System Destruction Capabilities and Password Exfiltration from 270+ Applications"
    • https://www.cyfirma.com/research/neptune-rat-an-advanced-windows-rat-with-system-destruction-capabilities-and-password-exfiltration-from-270-applications/
To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/

Please like, subscribe, and follow us on social!
LinkedIn: https://www.linkedin.com/company/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
6 months ago
57 minutes

The Hackle Box
March 2025: Q & A Open Call
Approaching the end of Q1, this special-edition episode answers questions from the audience including the U.S. Cyber Command's suspended operations against Russia and some essential beard maintenance. Security Analyst Tim Boyer sits in for Pinky to fill the blue team perspective.

Now happening quarterly, listeners can ask all things security to our expert crew! The next Q & A Session will be held June 13th. Submit questions to our survey here: https://www.surveymonkey.com/r/thehacklebox

To stay updated on all things The Hackle Box, sign up to receive our newsletters: https://frsecure.com/cyber-threat-intel-series/

Please like, subscribe, and follow us on social! 

LinkedIn: https://www.facebook.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
Facebook: https://www.facebook.com/frsecure/
BlueSky: https://bsky.app/profile/frsecure.bsky.social

About FRSecure:
https://frsecure.com/ 

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
7 months ago
54 minutes

The Hackle Box
DeepSeek, Ransomware Decline, New Exploited Vulnerabilities, & More
Oscar, Pinky, and Eric dive into DeepSeek, the downward trend of Ransomware extortions, and new, actively exploited vulnerabilities.

Links:
"DeepSeek App Transmits Sensitive User and Device Data Without Encryption" https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html

"DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked" https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html

"Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023" https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html

"CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25" https://thehackernews.com/2025/02/cisa-adds-four-actively-exploited.html

"Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software" https://thehackernews.com/2025/02/palo-alto-networks-patches.html

Please like, subscribe, and follow us on social! 
  • Facebook: https://www.facebook.com/frsecure/
  • Twitter: https://twitter.com/frsecure/ 
  • Instagram: https://www.instagram.com/frsecureofficial/ 
  • LinkedIn: https://www.linkedin.com/company/frsecure/ 


About FRSecure:
https://frsecure.com/ 

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
8 months ago
54 minutes

The Hackle Box
RCS, AuthQuake, & "The Night before Breachmas"
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.  This special holiday episode, Pinky shares a reading of "The Night Before Breachmas", the gang talks encrypted texting, Microsoft's MFA flaw - aka "AuthQuake", and hackers bypassing AntiVirus protections with BYOVD.

Links:
"FBI Warns iPhone And Android Users—Stop Sending Texts" https://www.forbes.com/sites/zakdoffman/2024/12/06/fbi-warns-iphone-and-android-users-stop-sending-texts/ 

"Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts" https://thehackernews.com/2024/12/microsoft-mfa-authquake-flaw-enabled.html?m=1

"Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections" https://thehackernews.com/2024/11/researchers-uncover-malware-using-byovd.html?m=1

Please like, subscribe, and follow us on social! 

Facebook: https://www.facebook.com/frsecure/ 
Twitter: https://twitter.com/frsecure/ 
Instagram: https://www.instagram.com/frsecureofficial/  
LinkedIn: https://www.linkedin.com/company/frsecure/ 

About FRSecure:
https://frsecure.com/ 

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. 

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
10 months ago
59 minutes

The Hackle Box
SolarWinds Attack Disclosures, OWASP's AI Security Guidance, & More
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This month, Oscar and the crew focus on SolarWinds cyber attack and the resulting charges from the SEC, guidance from OWASP on AI Security, and CISCO's security patch.

Links: "Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users" https://thehackernews.com/2024/11/goo...

"SEC Charges 4 Companies Over Misleading SolarWinds Cyber Attack Disclosures" https://thehackernews.com/2024/10/sec...

"OWASP Releases AI Security Guidance" https://www.darkreading.com/applicati...

"Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems" https://thehackernews.com/2024/11/cis...

Please like, subscribe, and follow us on social! 
Facebook: FRSecure LLC
Twitter: @FRSecure
Instagram: @FRSecureofficial
LinkedIn: FRSecure


About FRSecure: Show more...
12 months ago
57 minutes

The Hackle Box
Internet Archive Hacked, New CISA Warnings, Zero Day Alert
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This month, the hosts talk about personal preparation for emergency events like natural disasters, the DDOS attacks of Internet Archive, newest CISA warnings, and Zero Day Alert for Ivanti exploitation. They also open up to the live audience for questions!

Links: "Internet Archive Hacked, Data Breach Impacts 31 Million Users" https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/

"CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches" https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html

"Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited" https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html

"N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware" https://thehackernews.com/2024/10/n-korean-hackers-use-fake-interviews-to.html

Please like, subscribe, and follow us on social! 
Facebook: https://www.facebook.com/frsecure/ 
Twitter: https://twitter.com/frsecure/ 
Instagram: https://www.instagram.com/frsecureofficial/  
LinkedIn: https://www.linkedin.com/company/frsecure/ 

About FRSecure: https://frsecure.com/ 
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
58 minutes

The Hackle Box
Worm-Driven USB Attacks, Microsoft Zero-Days, Scattered Spider Vishing & Smishing
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

With Oscar out traveling, Pinky and Eric lead the discussion this month. Together, they discuss: A worm-driven USB attack strategy, Microsoft's disclosure of four zero-days in their September update, and the Scattered Spider ransomware group's sophisticated smishing and vishing campaigns on cloud services. They also open up to the live audience for questions!

Links: 
Mustang Panda Feeds Worm-Driven USB Attack Strategy
https://www.darkreading.com/cyberattacks-data-breaches/mustang-panda-worm-driven-usb-attack

Microsoft Discloses 4 Zero-Days in September Update
https://www.darkreading.com/application-security/microsoft-discloses-4-zero-days-in-september-update

Socially Savvy Scattered Spider Traps Cloud Admins in Web
https://www.darkreading.com/cloud-security/socially-savvy-scattered-spider-traps-cloud-admins-in-web


Please like, subscribe, and follow us on social!

About FRSecure
https://frsecure.com/ 
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
59 minutes

The Hackle Box
TeamViewer APT29 Attack, Zero-Click Outlook RCE Vulnerability, CISA Takedown of Ivanti Systems
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time, they discuss Midnight Blizzard, a zero-click Outlook vulnerability, and CISA's takedown of Ivanti Systems.

Links: 
Network Segmentation Saved TeamViewer From APT29 Attack https://www.darkreading.com/cyberattacks-data-breaches/teamviewer-network-segmentation-apt29-attack

Zero-Click Outlook RCE Vulnerability - Project Hyphae
https://projecthyphae.com/threat/zero-click-outlook-rce-vulnerability/ 

CISA Takedown of Ivanti Systems Is a Wake-up Call
https://www.darkreading.com/vulnerabilities-threats/cisa-takedown-ivanti-systems-is-wake-up-call

Please like, subscribe, and follow us on social! 
Facebook: https://www.facebook.com/frsecure/ 
Twitter: https://twitter.com/frsecure/ 
Instagram: https://www.instagram.com/frsecureofficial/  
LinkedIn: https://www.linkedin.com/company/frsecure/ 

About FRSecure
https://frsecure.com/ 
FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.  These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
57 minutes

The Hackle Box
Police Troll LockBit, Microsoft Holds Execs Accountable for Security
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits. 

This time, they discuss critical Citrix flaws, fake journalists stealing data, Microsoft holding execs accountable for security, police trolling a ransomware gang, and more.

Links: 

Citrix Addresses High-Severity Flaw in NetScaler ADC and Gateway
https://thehackernews.com/2023/10/critical-citrix-netscaler-flaw.html

Apt42 Pose As Journalists, Harvest Credentials, Access Cloud Data
https://attackfeed.com/apt42-hackers-pose-as-journalists-to-harvest-credentials-and-access-cloud-data-infothehackernews-com-the-hacker-news/

Microsoft Will Hold Execs Accountable for Cybersecurity
https://www.darkreading.com/cloud-security/feds-microsoft-clean-up-cloud-security-act

Burnout Is Pushing Workers to Use AI—Even If Their Boss Doesn’t Know
https://www.wired.com/story/ai-workers-burnout-microsoft-linkedin/

Police Resurrect LockBit's Site and Troll the Ransomware Gang | TechCrunch
https://techcrunch.com/2024/05/06/police-resurrect-lockbits-site-and-troll-the-ransomware-gang/

US Indicts LockBit Ransomware Ringleader, Offers $10 Million Reward
https://www.theverge.com/2024/5/7/24151493/us-lockbit-ransomware-ringleader-indictment-reward

Please like, subscribe, and follow us on social! 

Facebook: https://www.facebook.com/frsecure/ 
Twitter: https://twitter.com/frsecure/ 
Instagram: https://www.instagram.com/frsecureofficial/  
LinkedIn: https://www.linkedin.com/company/frsecure/ 

About FRSecure https://frsecure.com/ 

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. 

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
55 minutes

The Hackle Box
AI-Written Malware, XZ Utils, Attackers Target Hospital Help Desks
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss AI-written malware, XZ Utils, and attackers targeting hospital IT help desks.

Links:

XZ Utils scare 
https://www.darkreading.com/application-security/xz-utils-scare-exposes-hard-truths-in-software-security

Change Healthcare hit with cyber extortion (again)
https://www.infosecurity-magazine.com/news/change-healthcare-double-cyber/

Health Department warns attackers targeting IT help desks https://www.bleepingcomputer.com/news/security/us-health-dept-warns-hospitals-of-hackers-targeting-it-help-desks/

Malicious PowerShell script appears to be AI-written 
https://www.bleepingcomputer.com/news/security/malicious-powershell-script-pushing-malware-looks-ai-written/

Please follow us on social!

Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/ 

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
53 minutes

The Hackle Box
Gemini AI Vulnerability, ChatGPT Plugins, Typosquatting, Vishing
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss security risks in ChatGPT plugins, a major flaw in Google's Gemini AI, typosquatting, and a worldwide vishing epidemic.

Links:

ChatGPT Plugin Security
https://www.infosecurity-magazine.com/news/security-risks-chatgpt-plugins/

Gemini AI Vulnerability
https://www.darkreading.com/cyber-risk/google-gemini-vulnerable-to-content-manipulation-researchers-say

Worldwide Vishing Epidemic
https://www.darkreading.com/endpoint-security/sophisticated-vishing-campaigns-take-world-by-storm

Typosquatting
https://www.darkreading.com/threat-intelligence/typosquatting-wave-shows-no-signs-of-abating

Please like, subscribe, and follow us on social!

Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
54 minutes

The Hackle Box
AnyDesk, Resumes Stolen From Compromised Job Boards, Industry News
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss compromised job boards where millions of resumes were stolen, AnyDesk's actions post-hack, an exploited SSRF flaw in Ivanti, and more.

Links:
Millions of resumes stolen via exploited job boards https://thehackernews.com/2024/02/hackers-exploit-job-boards-in-apac.html

AnyDesk resets passwords/revokes certificates after hack https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/

SSRF flaw in Ivanti exploited https://thehackernews.com/2024/02/recently-disclosed-ssrf-flaw-in-ivanti.html

Fortinet reissues critical FortiSIEM vulnerabilities https://www.theregister.com/2024/02/06/fortinet_fortisiem_vulns/

Please like, subscribe, and follow us on social!
Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
53 minutes

The Hackle Box
Cybersecurity Funding Reduced 40% in 2023, Vulnerability/Patch News
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss the reduced cybersecurity funding observed in 2023 as well as new vulnerabilities, patches, and more.

Links:

Cybersecurity Funding Reduced
https://www.securityweek.com/cybersecurity-funding-dropped-40-in-2023-analysis/

Critical Flaws in Windows Kerberos and Hyper-V
https://securityweek.com/microsoft-ships-urgent-fixes-for-critical-flaws-in-windows-kerberos-hyper-v/

Pikabot Malware
https://www.darkreading.com/cyberattacks-data-breaches/pikabot-malware-qakbot-replacement-black-basta-attacks

Decryptor for Black Basta and Babuk's Tortilla Ransomware https://thehackernews.com/2024/01/free-decryptor-released-for-black-basta.html

Please like, subscribe, and follow us on social!

Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/

About FRSecure https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
53 minutes

The Hackle Box
Breachmas & Common Social Engineering Attacks
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time, they discuss common social engineering attacks carried out around the holidays when key team members are out of the office or organizations are shut down for seasonal breaks.

Links
Social Engineering
https://thehackernews.com/2023/12/hacking-human-mind-exploiting.html

Cisco IOS XE Vuln Exploitation
https://www.securityweek.com/exploitation-of-recent-cisco-ios-xe-vulnerabilities-spikes/

Sierra:21 Attacks
https://thehackernews.com/2023/12/sierra21-flaws-in-sierra-wireless.html

Atlassian
https://www.darkreading.com/application-security/patch-now-critical-atlassian-bugs-endanger-enterprise-apps

Please follow us on social!
Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/

About FRSecure
https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
47 minutes

The Hackle Box
Recent Vulnerabilities in Confluence and Apache ActiveMQ
The guys are back for another episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time around, they discuss recent vulnerabilities in Confluence and Apache ActiveMQ.

Follow us on social!

Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/

About FRSecure - https://frsecure.com/

FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs.

These fundamentals are lacking in our industry, and while progress is being made, we can’t do it alone. Whether you’re wondering where to start, or looking for a team of experts to collaborate with you, we are ready to serve.
Show more...
1 year ago
42 minutes

The Hackle Box
Incident Response Horror Stories
The guys are back for a special, Friday the 13th episode of the Hackle Box—a monthly conversation between information security experts about new and noteworthy exploits.

This time around, we're getting in the spooky spirit and telling scary stories from real-life IR cases. 🎃

Please like, subscribe, and follow us on social!
Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/
Show more...
2 years ago
54 minutes

The Hackle Box
Scattered Spider - The MGM Hackers, InfoSec News
Oscar and Pinky are back for this month's session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

DISCUSSED THIS MONTH:
Scattered Spider (MGM attack)
https://hackdojo.io/articles/E59P05LKQ/-scattered-spider-behind-mgm-cyberattack-targets-casinos

Caesers confirms ransomware
https://hackdojo.io/articles/73WL5VP9N/caesars-confirms-ransomware-hack-stolen-loyalty-program-database

MGM hackers branching out
https://hackdojo.io/articles/AEWED5DK7/mgm-hackers-broadening-targets-monetization-strategies

UNC3944 Smishing Ransomware
https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware

LastPass iOS vulnerability (BLASTPASS)
https://hackdojo.io/articles/AEWEDLDK7/blastpass-government-agencies-told-to-secure-iphones-against-spyware-attacks

Follow us on social!
Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/
Show more...
2 years ago
58 minutes

The Hackle Box
DEFCON 31, EvilProxy, QR Code Credential Theft, AI Stealing Passwords
Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits.

Discussed this month
  • DEFCON Recap

  • EvilProxy campaign
    • https://www.techrepublic.com/article/evilproxy-phishing-attack/

  • QR Codes used for credential theft
    • https://www.darkreading.com/attacks-breaches/qr-code-phishing-campaign-targets-top-u-s-energy-company

  • AI stealing passwords, listening to keystrokes
    • https://www.darkreading.com/attacks-breaches/ai-model-can-replicate-password-listening-to-keystrokes

Follow us on social!
Facebook: https://www.facebook.com/frsecure/
Twitter: https://twitter.com/frsecure/
Instagram: https://www.instagram.com/frsecureofficial/
LinkedIn: https://www.linkedin.com/company/frsecure/
Show more...
2 years ago
59 minutes

The Hackle Box
The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques, vulnerabilities, exploits, and more.