SecurIT360
The Cyber Threat Perspective
Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics. brad@securit360.com
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
9-2-22 Week in Review: Okta Phishing, BEC Analysis, LNK Attacks 02.09.2022 27:17
In this week's review Roasting 0ktapus: The phishing campaign going after Okta identity credentials Advanced BEC Scam Campaign Targeting Executives on O365 The Rise of LNK Files (T1547.009) and Ways To Detect Them Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: h...
Episode 5: Common High Risk Findings on Internal Penetration Tests & How to Mitigate Them 31.08.2022 30:51
It's an unfortunate truth that we see these common high risk findings time and time again on internal pentests. We find these issues on super-maximum secured environments as well in less hardened environments. The end result though is the same. Tune in to learn more about these common high risk findings and most importantly, how to mitigate them for free! Blog: https://offsec.blog/ Youtube: h...
8-26-22 Week in Review: LastPass Breach, Office 365 Abuse, DevSecOps 26.08.2022 31:50
In this week's review Hackers Breach LastPass Developer System to Steal Source Code You Can’t Audit Me: APT29 Continues Targeting Microsoft 365 | Mandiant The GitLab 2022 Global DevSecOps Survey Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: https://offsec.blog/...
Episode 4: 7 Awesome Ways to Show Off Your Skills as a Pentester 24.08.2022 32:20
In order to stay relevant and up-to-date with new techniques and tools, it requires a certain amount of focus day after day, week after week, year after year. That focus being constant improvement. If we, as pentesters, don’t get better, we can’t help businesses defend better. So that’s what this podcast is about. Constant improvement and showing that off to the world. We are going to talk about W...
8-19-22 Week in Review: Password Snooping, Supply Chain, Cl0p Ransomware 19.08.2022 22:32
In this week's review Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY Realtek SDK Vulnerability Exposes Routers InfoSec Handlers Diary Blog - SANS Internet Storm Center CVE-2022-27255 - Realtek eCos SDK SIP ALG buffer overflow Clop Ransomware Gang Breaches Water Utility, Just Not the Right One https://twitter.com/malwrhunterteam/status/1559244860636413952?s=20&t=i...
Episode 3: It's a Trap! Avoid These 4 Common Pentesting Mistakes 17.08.2022 32:09
This podcast is a discussion about 4 Common Pentesting Mistakes that we oursleves have made and have seen other pentesters make. Hopefully, the dialog around these mistakes and how we go about solving them, helps you not make them yourself or to realize them and recover from them quickly. Read the associated blog post here: https://offsec.blog/its-a-trap-avoid-these-4-common-pentesting-mistakes/ B...
8-12-22 Week in Review: BumbleBee Malware & High Profile Phishing Attacks 12.08.2022 23:31
In this week's review BumbleBee Roasts Its Way to Domain Admin SMS & Voice Phishing Attacks https://www.twilio.com/blog/august-2022-social-engineering-attack https://blog.cloudflare.com/2022-07-sms-phishing-attacks/ https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https...
Episode 2: How to Find Passwords on Network Shares Before Attackers Do 10.08.2022 16:37
Brad and Spencer discuss a common finding on internal penetration tests. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer&apos...
8-5-22 Week in Review: Evasive Phishing, Tricky Malware and Initial Access Brokers 05.08.2022 24:56
In this week's review Large-Scale AiTM Attack targeting enterprise users of Microsoft email services Deception at a scale Initial Access Brokers Are Key to Rise in Ransomware Attacks Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: ht...
Episode 1: Takeaways from the 2022 Verizon Data Breach Investigations Report 03.08.2022 33:53
This podcast is a discussion about the 2022 Verizon Data Breach Investigations Report and some of our key takeaways. From the Executive Summary of the DBIR: As introduced in the 2018 report, the DBIR provides “a place for security practitioners to look for data-driven, real-world views on what commonly befalls companies with regard to cybercrime.” For this, our 15th anniversary installment, we co...
July 29th Week in Review: Intergalactic Planetary Phishing, ISOs & LNKs, Ransomware & Extortion 29.07.2022 31:45
In this week's review IPFS The New Hotbed of Phishing How Threat Actors Are Adapting to a Post-Macro World Palo Alto 2022 Incident Response Threat Report Fewer Ransomware Victims Pay As Medium Ransom Falls in Q2 2022 Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog...
July 22nd 2022 CTP Week in Review: RIP Macros, Bad Luck BlackCat, Mr. Eagle 22.07.2022 24:53
In this week's review: Microsoft resumes default blocking of Office macros after updating docs https://docs.microsoft.com/en-us/deployoffice/security/internet-macros-blocked A potentially dangerous macro has been blocked BlackCat ransomware attacks not merely a byproduct of bad luck 'AIG' Threat Group Launches With Unique Business Model Blog: https://offsec.blog/ Youtube: https://w...
July 15th 2022 CTP Week in Review: Macros, Coin Miners, Rustomware, Cookie Phishing 15.07.2022 28:35
In this week's review: Microsoft DOES plan to work on blocking internet macros by default in Office , their pause is apparently temporary The DFIR Report - SELECT XMRig FROM SQLServer Hive ransomware gets upgrades in Rust From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCC...
July 8th 2022 CTP Week in Review: Office Macros - BRC4 - QNAPWorm - Leaky S3 Buckets - Prevention Over Response 08.07.2022 26:53
In this week's review Microsoft Rolls Back Decision to Block Office Macros By Default 😢 Possible APT29/Ransomware Groups Use of Brute Ratel C4 When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors Reversing Malware Also How is APT 29 Successful with This Phishing Technique Raspberry Robin/QNAPWorm Raspberry Robin gets the worm early Microsoft finds Raspberry Robin w...
July 1st 2022 CTP Week in Review: LNK Malware - LockBit 3.0 Bug Bounty - PwnKit Exploitation In The Wild 01.07.2022 12:34
In this week's review Rise of LNK (Shortcut files) Malware LockBit 3.0 Released Now With Bug Bounty Program CISA Says PwnKit Exploited in the Wild Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpo...
June 24th 2022 CTP Week In Review: DFSCoerce, Ransomware in OneDrive & PowerShell Forever 28.06.2022 15:30
In this week's review: New NTLM Relaying Attack via DFSCoerce Ransomware Potential for OneDrive & SharePoint Files Keeping PowerShell: Security Measures to Use and Embrace Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://w...
June 17th 2022 CTP Week In Review: BlackCat - LockBit 2.0 - Saitama DNS Tunneling - Exposed Travis CI Logs 17.06.2022 28:39
In this week's review: The rise of BlackCat (ALPHV) ransomware Microsoft Analysis of BlackCat AdvIntel Analysis of BlackCat Ransomware Group Debuts Searchable Victim Data LockBit 2.0: How This RaaS Operates and How to Protect Against It Translating Saitama's DNS tunneling messages - SANS Internet Storm Center Public Travis CI Logs (Still) Expose Users to Cyber Attacks Blog: https://offse...
June 10th 2022 CTP Week in Review: Dogwalk - Qakbot - Follina - ESXi Ransomware 10.06.2022 23:15
In this week's review: A DFIR Report with no Ransomware and no Cobalt Strike Path Traversal & MOTW Bypass - DIAGCAB Windows Zero-day aka "Dogwalk" Linux version of Black Basta ransomware targets VMware ESXi servers TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt) Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twit...
June 3rd 2022 – Cyber Threat Perspective – Week in Review 03.06.2022 28:27
In this week's review: Microsoft Diagnostics Tool Remote Code Execution Zero Day New Windows Search zero-day added to Microsoft protocol nightmare Vendor Refuses to Remove Backdoor Account That Can... Over 3.6 million exposed MySQL servers on IPv4 and IPv6 |... APTs Overwhelmingly Share Known Vulnerabilities Rather Than Attack O-Days Blog: https://offsec.blog/ Youtube: https://www.youtube.com...
Threat Intel Flash Briefing May 31st 2022 - Follina - CVE-2022-30190 31.05.2022 17:02
The sky IS NOT falling with this one. Is it important? Yes. Does it highlight an area that's under-researched and likely contains additional attack vectors and techniques? Absolutely. Resources https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190 https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e https://www.huntress.com/blog/microsof...
May 27th 2022 – Cyber Threat Perspective – Week in Review 27.05.2022 33:02
In This Weeks Review PDF Malware Is Not Dead Yet Detecting & Preventing Rogue Azure Subscriptions Python and PHP Library Updated with 'Extra' Features by a "Security Researcher" 2022 Verizon Data Breach Investigations Report Zoom: Remote Code Execution with XMPP Exploit released for critical VMware auth bypass bug Blog: https://offsec.blog/ Youtube: https://www.youtube.com/...
May 20th, 2022 - Cyber Threat Perspective - Week in Review 20.05.2022 21:34
In This Weeks Review Gootloader & Gootkit Analysis by DFIR Report and Red Canary Authenticated PetitPotam Lives On (CVE-2022-26925) The Hunter Becomes the Hunted: Evicting the Adversary Spoofing SaaS Vanity URLS for Social Engineering Attacks Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: ht...
May 13th, 2022 - Cyber Threat Perspective - Week in Review 13.05.2022 18:19
In This Weeks Review Threat Actor using Windows Event Logs for "fileless" Malware CVE-2022-1388 - F5 BIG-IP PoC Released CVE-2021-22600 - Privilege Escalation Bug In The Linux Kernel CVE-2022-26925 - A Windows LSA Spoofing Vulnerability (PetitPotam) CVE-2022–26923 - Another ADCS Domain Privilege Escalation Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAF...
May 6th, 2022 - Cyber Threat Perspective - Week in Review 06.05.2022 27:17
In this week's review: Detecting SharpHound using Decoys UNC3524: Eye Spy on Your Email | Mandiant The New Initial Access Trend: ZIPs, ISOs & LNKs Unauthenticated RCE in F5 BIG-IP CVE-2022-1388 Blog: https://offsec.blog/ Youtube: https://www.youtube.com/channel/UCCWmudG_CTNAFBaV48vIcfw Twitter: https://twitter.com/cyberthreatpov Work with Us: https://securit360.com Blog: https://offsec.bl...
Threat Intel Flash Briefing - Kerberos Relaying to Local SYSTEM 27.04.2022 23:59
There exists a universal no-fix local privilege escalation in Windows domain environments where LDAP signing is not enforced (the default settings). Thanks to the research and open source tools of several researchers, it's now trivial to elevate to SYSTEM on most Windows Operating Systems. Resources: https://github.com/Dec0ne/KrbRelayUp https://googleprojectzero.blogspot.com/2021/10/using-ker...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.