Triskele Labs

TL Blue

News EN ↓ 16 episodes

Recognising that sharing cyber insights is in high demand, we created a new fortnightly audio-only format that will feature findings straight from our Security Operations Centre (SOC) and Digital Forensics and Incident Response (DFIR) teams.

Be sure to visit the podcast's website and support the creator: www.triskelelabs.com

Author

Triskele Labs

Category

News

Podcast website

www.triskelelabs.com

Latest episode

Apr 24, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

Episode 16 | April 2025 | TL Blue 24.04.2025

Introduction Credential stuffing attacks breach Australian superannuation funds CVE program faces uncertain future amid funding lapse RansomHub implodes – DragonForce moves in Fortinet FortiGate firewalls exploited – persistent access via symlink technique Ivanti CVE-2025-22457 – Remote Code Execution (RCE) vulnerability

Episode 15 | March 2025 | TL Blue 31.03.2025

ASIC and FIIG: The AFS Licensee was accused of insufficient planning, technical safeguards, and training. Medusa slams Critical Infrastructure: the ransomware gang has targeted over 300 healthcare, manufacturing, and technology organisations. RansomHub uses a novel backdoor function: unlike typical ransomware campaigns that rely on public tools, Betruger is a multi-function backdoor built specific...

Episode 14 | March 2025 | TL Blue 05.03.2025

➡️ Further Sanctions in Response to Medibank Cyberattack ➡️ Will Law Enforcement success against ransomware continue in 2025? ➡️ OneDrive Offline Mode ➡️ Fake Captcha ➡️ Lynx Ransomware-as-a-Service ➡️ Black Basta Chat Logs Leaked ➡️ Concerns Raised of Musk's Department of Government Efficiency ➡️ Vulnerability of the fortnight - SimpleHelp ➡️ SOC and DFIR activity

Episode 13 | Feb 2025 | TL Blue 04.02.2025

FortiGate data posting / Microsoft bug allowed users to update their user principal names / Court orders company to pay invoice after paying a fraudulent invoice / Ross Ulbricht pardoned by Donald Trump / Ransomware campaigns using email bombing / Critical Vulnerability in FortiOS and FortiProxy (CVE-2024-55591)

Episode 12 | Jan 2025 | TL Blue 18.01.2025

LockBit 4.0 Teaser Coveware’s insights: Australia ransomware payment statistics Cyberattack on Japan Airlines during Holiday Season Mailbox Synchronisation and Malicious OAuth Applications ( https://www.triskelelabs.com/business-email-compromise-mailbox-synchronisation-malicious-oauth-applications ) Vulnerability of the fortnight - CVE-2025-0282, CVE-2025-0283: Active Exploitation of Ivanti Vulner...

Episode 11 | 12 Dec 2024 | TL Blue 15.12.2024

ACSC Annual Report Texas teen arrested for Scattered Spider telecom hacks Commonwealth Director of Public Prosecutions (CDPP) secured 32 convictions for cyber offences in last six years Vulnerability of the fortnight: Critical security vulnerabilities affecting Mitel MiCollab

Episode 10 | 14 Nov 2024 | TL Blue 14.11.2024

Sydney hospital loses $2m to alleged BEC fraud RedLine and META infostealers disrupted by global operation ASD releases guidance on Detecting and mitigating Active Directory compromises Bengal cat lovers targeted in GootLoader campaign Vulnerability of the month - CVE-2024-47575 affecting FortiManager and FortiManager Cloud

Episode 9 | 15 Aug 2024 | TL Blue 15.08.2024

- Intro - New Australian Cybersecurity Bill Mandating Ransomware Reporting - Rising Cost of Data Breaches in Australia - IBM and Rubrik Reports - Australian SMBs’ Willingness to Pay Ransomware Criminals - Cyber Extortion Up 61% in Australia - Phishing Attacks Adapting to Current Events - 2024 Midyear Threat Landscape Review

Episode 8 | 20 June 2024 | TL Blue 19.06.2024

00:00 Intro 02:15 Microsoft delays release of Recall 05:14 ASD releases their Blueprint for secure cloud 10:47 Australian Information Commissioner v Medibank 25:03 Vulnerability of the week - Trio of Vcenter RCE 28:16 News from our SOC and DFIR teams Resources: https://www.itnews.com.au/news/microsoft-to-delay-release-of-recall-ai-feature-608832 https://blueprint.asd.gov.au/ https://www.bleepingco...

Episode 7 | 6 June 2024 | TL Blue 06.06.2024

Intro Leaking Clouds Optus Forensic report is not protected by legal privilege Australian bank account details Guardian childcare hack Microsoft Recall Topic Vulnerability of the fortnight Check Point Security Breaking News MediSecure SOC and DFIR updates https://www.linkedin.com/feed/update/urn:li:activity:7202881429796466688/ https://www.bleepingcomputer.com/news/security/snowflake-account-hacks...

Episode 6 | 23 May 2024 | TL Blue 22.05.2024

Intro LockBit founder unmasked DFAT warns of DPRK IT workers New government app set to fight credential misuse Microsoft Secure Future Initiative CVE-2024-30040 - Windows MSHTML Platform Security Feature Bypass Vulnerability Updates from our SOC & DFIR teams

Episode 5 | 9 May 2024 | TL Blue 09.05.2024

Intro Qantas app debacle - exposes other customer details Millions of records leaked in NSW clubs data breach Australian losses to scams decline, but we're still losing billions Vulnerability of the fortnight Fortnightly SOC and DFIR updates

Episode 4 | 25 April 2024 | TL Blue 02.05.2024

Introduction Global Cybercrime Sting MITRE Network Breach via Ivanti Zero-Days Vulnerability of the fortnight CVE-2024-3400 Palo Alto PAN-OS What is happening in the SOC/DFIR this fortnight British Library cyber incident review

Episode 3 | 11 April 2024 | TL Blue 10.04.2024

Intro New Ivanti Vulnerability Threat Actor claims to have stolen data belonging to the Five Eyes intelligence group after breaching a US national security technology contractor. Winnti's new UNAPIMON malware Possible data breach at Australian immigration consultancy Vulnerability of the fortnight: CVE-2024-3094 (aka xz Utils backdoor) What is happening in the SOC/DFIR this fortnight

Episode 2 | 28 March 2024 | TL Blue 28.03.2024

ACSC Publications Australians being notified about data breaches impacting them IT contractor sentenced for cybercrime and fraud offences after swindling more than $60k Vulnerability of the week - CVE-2023-48788 What we're seeing in the SOC and DFIR Resources for charities and not-for-profits : Educational pack for small businesses , including the Essential Eight and Exercise in a Box resources. T...

Episode 1 | 14 March 2024 | TL Blue 15.03.2024

Tune in this first episode to hear news from Brad Morgan and Richard Grainger , who will provide updates about ransomware group activities, the US government's Cybersecurity and Infrastructure Security Agency (CISA) being impacted by a breach, 14m Australian emails and addresses for sale on clear web hacking forum,  vulnerability of the fortnight,  and what we're seeing in the SOC and DF...

Listen to the TL Blue podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.