TL Blue

TL Blue

by Triskele Labs
Season 1

Episode 11 | 12 Dec 2024 | TL Blue

ACSC Annual Report Texas teen arrested for Scattered Spider telecom hacks Commonwealth Director of Public Prosecutions (CDPP) secured 32 convictions for cyber offences in last six years Vulnerability of the fortnight: Critical security vulnerabilities affecting Mitel MiCollab
Season 2

Episode 12 | Jan 2025 | TL Blue

LockBit 4.0 Teaser Coveware’s insights: Australia ransomware payment statistics Cyberattack on Japan Airlines during Holiday Season Mailbox Synchronisation and Malicious OAuth Applications (https://www.triskelelabs.com/business-email-compromise-mailbox-synchronisation-malicious-oauth-applications) Vulnerability of the fortnight - CVE-2025-0282, CVE-2025-0283: Active Exploitation of Ivanti Vulnerabilities (https://www.triskelelabs.com/blog/cve-2025-0282-cve-2025-0283-active-exploitation-of-ivanti-vulnerabilities) SOC and DFIR updates

Episode 13 | Feb 2025 | TL Blue

FortiGate data posting / Microsoft bug allowed users to update their user principal names / Court orders company to pay invoice after paying a fraudulent invoice / Ross Ulbricht pardoned by Donald Trump / Ransomware campaigns using email bombing / Critical Vulnerability in FortiOS and FortiProxy (CVE-2024-55591)

Episode 14 | March 2025 | TL Blue

➡️ Further Sanctions in Response to Medibank Cyberattack ➡️ Will Law Enforcement success against ransomware continue in 2025? ➡️ OneDrive Offline Mode ➡️ Fake Captcha ➡️ Lynx Ransomware-as-a-Service ➡️ Black Basta Chat Logs Leaked ➡️ Concerns Raised of Musk's Department of Government Efficiency ➡️ Vulnerability of the fortnight - SimpleHelp ➡️ SOC and DFIR activity

Episode 15 | March 2025 | TL Blue

ASIC and FIIG: The AFS Licensee was accused of insufficient planning, technical safeguards, and training. Medusa slams Critical Infrastructure: the ransomware gang has targeted over 300 healthcare, manufacturing, and technology organisations. RansomHub uses a novel backdoor function: unlike typical ransomware campaigns that rely on public tools, Betruger is a multi-function backdoor built specifically for pre-ransomware activity. 23andMe bankruptcy and the genetic data of 15 million users. CISA released 13 new Industrial Control Systems (ICS) advisories Vulnerability of the fortnight - Apple, CVE-2025-24201. Findings from our SOC and DFIR teams: Click Fix: Fake CAPTCHA, but make it Email. Endpoint Detection and Response (EDR) and Monitoring: Backdoor & Brute Ratel.

Episode 16 | April 2025 | TL Blue

Introduction Credential stuffing attacks breach Australian superannuation funds CVE program faces uncertain future amid funding lapse RansomHub implodes – DragonForce moves in Fortinet FortiGate firewalls exploited – persistent access via symlink technique Ivanti CVE-2025-22457 – Remote Code Execution (RCE) vulnerability
2 of 2