The InfoSec Mission

The Hackle Box

The Hackle Box is a monthly cyber threat intel discussion where Oscar Minks and members of FRSecure's technical services team (Team Ambush) break down the latest trends in the information security industry involving hacking techniques, vulnerabilities, exploits, and more.

Author

The InfoSec Mission

Category

Technology

Podcast website

frsecure.com

Latest episode

May 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

3CX Supply Chain Attack, Windows 0-Day, Yum! Brands 17.04.2023

Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits. Discussed this month: Windows zero-day exploited in the wild https://projecthyphae.com/threat/windows-zero-day-being-exploited-in-ransomware-attacks/ 3CX Supply Chain Attack https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-...

Security News Roundup 07.04.2023

This week, Oscar and Brad sit down to catch up on all the latest in security news. Links: The Sound of Silence Critical Microsoft Outlook Vulnerability https://projecthyphae.com/threat/the-sound-of-silence-critical-microsoft-outlook-vulnerability/ Fastest Ransomware Encryption in History https://gbhackers.com/rorschach/ 'Operation Cookie Monster': International police action seizes dark web market...

The Rise of Exfil-Only Ransom Attacks, & New Threats 13.03.2023

Eric and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits. Discussed this month: Microsoft Word vulnerability goes public https://projecthyphae.com/threat/microsoft-word-vulnerability-goes-public-users-wondering-if-a-rtf-means-risky-text-file/ Emotet is back (again) after another hiatus https://w...

Developer Pleads Guilty to Hacking His Own Company 13.02.2023

Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the information security experts about new and noteworthy exploits. Discussed this month: Developer pleads guilty to hacking his own company https://www.theverge.com/2023/2/3/23584414/ubiquiti-developer-guilty-extortion-hack-security-breach-bitcoin-ransom Google plagued with 'malvertisers' in January 202...

Rackspace Ransomware, 98 Microsoft Patches, & More 17.01.2023

Oscar, Eric, and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, security breaches, and exploits. Discussed this month: Rackspace Ransomware Incident Highlights Risks of Relying on Mitigation Alone https://www.darkreading.com/vulnerabilities-threats/rackspace-ransomware-incident-highligh...

New CISA Reporting Rule, Russian Attacks on Ukrainian Orgs, & More. 12.12.2022

Oscar and Pinky are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. Discussed this month: Russian Actors Use Compromised Healthcare Networks Against Ukrainian Orgs https://www.darkreading.com/threat-intelligence/russian-actors-compromised-heal...

VMware Bugs & Remote Workspaces, Long Island Midterms Delayed, & More. 16.11.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. Discussed this month: Critical Citrix, VMware Bugs threaten remote workspaces https://www.darkreading.com/vulnerabilities-threats/patch-asap-critical-citrix-vmware-bugs...

Fortinet Authentication Bypass, ProxyShell 2 (or 3?), and More! 17.10.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. Discussed this month: Fortinet Authentication Bypass ZeroDay: ProxyShell 2 (or 3?) Microsoft Addresses Zero-Days, Exchange Server Exploit Chain Remains Unpatched Phishi...

Defcon Recap, EvilProxy, TeslaGun, Broken Ice Cream Machines 13.09.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month's episode includes: Defcon Recap EvilProxy TeslaGun Broken Ice Cream Machines and McDonalds Please like, subscribe, and follow us on social! Facebook: https:...

The Hackle Box July 2022: NPM All Over the News, APT Targeting Healthcare Sector, and More 11.07.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month's episode includes: NPM supply chain attack impacts hundreds of websites and apps https://www.bleepingcomputer.com/news/security/npm-supply-chain-attack-impa...

The Hackle Box June 2022: Atlassian Confluence, Follina, Chinese Attackers Breach Telcos, and More 13.06.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month's episode includes: 02:14 Atlassian Confluence – CVE-2022-26134 https://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution....

The Hackle Box May 2022: F5-Big IP, Fileless Malware Hides Shellcode in Windows Event Logs, and More 16.05.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. Please like, subscribe, and follow us on social! Facebook: https://www.facebook.com/frsecure/ Twitter: https://twitter.com/frsecure/ Instagram: https://www.instagram.co...

The Hackle Box April 2022: Fake Emergency Data Requests, Critical Spring4Shell Vulnerability, & More 11.04.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month's episode includes: - Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests” - Forged Signatures: Not Just For Troubled Youths Anymore. #Nvidia...

The Hackle Box March 2022: AutoWarp Vulnerability, APC Burning Down, Dirty Pipe Exploit 14.03.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month's episode includes: - AutoWarp vulnerability in Microsoft Azure - APC's Burning Down - Dirty Pipe - Russian Attack on Ukraine Please like, subscribe, and fol...

The Hackle Box February 2022: EyeMed Breach, Data Exfil Using PowerAutomate, Google MFA. 16.02.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month's episode includes: - EyeMed fined $600k in data breach - Attackers reviving a 20-year-old tactic in Microsoft 365 phishing campaigns - Google auto-enables t...

The Hackle Box January 2022: Log4j, Russian Cyber Threat, AV Cryptominers, Patch Tuesday 18.01.2022

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month, the trio dives into: • Log4j Overview and updates • CSA advisory on Russian Cyber Threat to US Critical Infrastructure. • Norton and Cryptominers in your AV...

The Hackle Box December 2021: Microsoft Exchange Exploit, FBI Website Hack, QuakNightmare 14.12.2021

Oscar, Pinky, and Eric are back with another session of the Hackle Box—a monthly conversation between the three cybersecurity experts about new and noteworthy threats, attacks, breaches, exploits, and (of course) how to avoid them. This month, the trio dives into: • Cyber Actors Exploiting Microsoft Exchange in Furtherance of Malicious Activities • FBI Website exploited resulting in hoax email bla...

The Hackle Box November 2021: Holiday Phishing Scams, SolarWinds Fallout, Microsoft Exchange, Ryuk 17.11.2021

Oscar, Eric, and Pinky are back with another session of the Hackle Box, a series where they break down current cybersecurity threats, breaches, vulnerabilities, and more. This month, the trio discusses: Phishing Report – Holiday Phishing Trends Hacker Tip of the Month News Topics: ‘Trojan Source’ Bug Threatens the Security of All Code https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens...

The Hackle Box October 2021: REBOL Yell, Microsoft Going Password-less, OMIGOD, Microsoft Azure 11.10.2021

Team Ambush members Oscar, Eric, and Pinky are back with another session of the Hackle Box—a series where they break down new and noteworthy breaches, vulnerabilities, exploits, and more over the last month. This month's topics: Microsoft going “passwordless” https://arstechnica.com/gadgets/2021/09/starting-today-you-can-remove-your-password-from-your-microsoft-account/ OMIGOD—an exploitable hole...

The Hackle Box September 2021: IDN Phishing, Razer Mouse, T-Mobile, Cobalt Strike, and OAuth 2.0 13.09.2021

The boys are back with another session of the Hackle Box. This month features in-depth discussion on four vulnerabilities/exploits that have gained the attention of Oscar, Pinky, and Eric over the last month or so. IDN Phishing — Outlook emails showing legitimate contact cards from lookalike domains https://arstechnica.com/information-technology/2021/09/microsoft-outlook-shows-real-persons-contact...

Listen to the The Hackle Box podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.