Recent uploads from trusted cybersecurity YouTube channels, covering threat hunting, malware analysis, and security research.
The Threat Hunting Course I Wish I Had
13Cubed·2.4K views · 2 weeks ago
Introducing Architecting the Hunt. Great threat hunting starts with the right questions. This entry-level mini course teaches you a repeatable framework that turns guesswork into a disciplined cycle. You'll learn how to form a hypothesis, acquire the right data, apply core hunting techniques, counter the biases that derail investigations, and communicate your findings. Then practice what you learned in a hands-on lab. No prior experience needed!
DEF CON 34 - Video Team - Voting Machine Hacking Village
DEFCONConference·10K views · 2 weeks ago
Voting Village returns to DEF CON 34 to consider the state of election security.
DEF CON 34 - VideoTeam - Cliff Stoll AfterHours
DEFCONConference·8.6K views · 2 weeks ago
An interview with the delightful Cliff Stolll. So very worth your time
DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking
DEFCONConference·5.5K views · 2 weeks ago
We get an EV charger hacking breakdown from the legend MajorMalfunction.
DEF CON 34 - Video Team - AI Hacking Village - Pokemon
DEFCONConference·5.1K views · 2 weeks ago
From the AI Hacking Village - an AI that plays Pokemon for you, without costing you 20 grand in tokens.
HackTheBox - Helix
IppSec·7.3K views · 2 weeks ago
00:00 - Introduction
00:45 - Start of nmap
03:20 - Using FFUF to VHOST Bruteforce and finding flow.helix.htb
05:30 - Looking into H2 Database RCE's, finding the Alias Command allows us the ability to run Java
07:10 - RCE #1: Using H2 Syntax to create an alias to run a shell command
15:10 - RCE #2: Adding a Processor to run Groovy
18:00 - RCE #3: Adding a Command Processor to run a bash command
19:40 - RCE #4: Is it easier to just use Metasploit?
26:00 - Shell on the box, using Find to show the types of all the files in our CWD and finding an SSH Key
30:15 - Shell as Operator, cracking a PDF
38:00 - Running OPCUA-Client-GUI and editing the registers to put the device in maintenance mode
Augmented Cloud Hacking with AI Workflows | BHIS Webcast
Black Hills Information Security·0 views · 2 weeks ago
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
GRC vs. Red Teaming: Better Together for Cyber Risk Analysis
Black Hills Information Security·1K views · 2 weeks ago
What happens when a GRC Assessor and a Red Team Operator evaluate the same organization?
🔗 Register for this FREE Infosec Webcast and other Anti-casts & Summits:
Your Workforce Is Using AI. Now What?
SANS Institute·315 views · 2 weeks ago
AI is already in your workplace. From generative tools that create content in seconds to emerging agentic systems that can plan and take action, your workforce is experimenting, often without fully understanding the risks or responsibilities.
This session gives security awareness and culture leaders a clear, accessible primer on generative and agentic AI, followed by practical guidance on what to teach your people. Through live demonstrations and real-world examples, we’ll focus on enablement over restriction, equipping your workforce to use AI confidently, productively, and securely.
Who Should Attend
- Security awareness and Culture Officers
- Governance, Risk and Compliance Officers
- AI and Business Leaders
- Risk and Compliance Officers
- Education and Training
Learning Objectives
- Define generative AI and agentic AI in practical, non-technical terms
- Identify the key human-centered risks associated with generative and agentic AI
- Define the key behaviors that manage those risks
- Design an enablement-driven AI awareness strategy.
Why Modern Malware keeps getting through Windows Defender
PC Security Channel·128K views · 2 weeks ago
Modern Malware use multi-stage payloads, LOLBINS that make it undetectable for Microsoft Defender to detect before it is too late.
SANS Share Your Story: How a CISO Stays Sharp with Jason Loomis
SANS Institute·157 views · 2 weeks ago
Jason Loomis is a sitting CISO who relies on SANS training to stay sharp across both deep technical work and strategic conversations with his board and executive team. In this video, Jason covers how SANS training helps him:
Move confidently between technical strategy and board-level strategy
Stay ahead of the threats and technologies shaping his decisions
Grow his own skills while raising the bar for his security practitioners
Iranian Cyberattacks on U.S. Water Systems – BHIS - Talkin' Bout [infosec] News 2026-08-03
Black Hills Information Security·1.9K views · 2 weeks ago
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
HackTheBox - Kobold
IppSec·8.8K views · 3 weeks ago
00:00 - Introduciton
01:00 - Start of nmap
02:30 - Finding the bin and mcp subdomain with ffuf
06:00 - Searching for PrivateBin exploits within version 2.0.2, finding an LFI but having trouble getting Code Execution from it
10:28 - Looking at the MCP Subdomain, finding MCPJam 1.4.2, which has an easy RCE Exploit
16:00 - SSH into the box as ben after dropping ssh key. Looking at processes and ports
18:37 - Looking at Arcane, another website discovering the default user of "arcane" still exists based upon timing on login
21:20 - Using find to see what files we have access to because we are in operator, discovering we can edit privateBin which allows us to weaponize the LFI to switch to its user (www-data)
26:30 - Inside of the PrivateBin Docker, looking for sensitive files, getting a password this lets us into Arcane.
30:03 - Logged into Arcane, a docker management website. Starting a container mounting / of the host to /mnt of the container, then accessing the host disk for privesc
33:30 - Showing a really cool unintended vector, which is the gshadow file. Using newgrp to add ourself to the docker group
JHT Course Launch! Home Labs with Proxmox
John Hammond·4.9K views · 3 weeks ago
Just Hacking Training livestream for Joram Stith's new course launch: Home Labs with Proxmox! Friday, July 31 at 1pm ET
Steam Malware situation so bad the FBI has a page for it!
PC Security Channel·111K views · 3 weeks ago
Payload Podcast 010 - Olaf Hartong
John Hammond·3K views · 3 weeks ago
Payload Podcast with Olaf Hartong! Live Tuesday, July 28 at 3pm ET.
The Sandbox Let It Out. The Guardrails Locked Us Out.
SANS Institute·3.7K views · 3 weeks ago
This month, an OpenAI model, running inside a sealed evaluation with its safety limits turned down, found a previously unknown flaw, broke out on its own, and took control of Hugging Face's live systems over a weekend. No human directed it. For years, industry leaders across the field warned this day would come. The disclosures suggest it has arrived.
The harder story is what happened next. When Hugging Face's responders went to investigate, the frontier models they reached for refused to run the analysis, so they pivoted to a self-hosted, open-weight model instead. Offensive research ran unrestricted while the defensive response hit a compliance blocker.
This is a policy story as much as a technical one. SANS faculty and staff, joined by voices from public policy and industry governance, will work through what it changes: AI testing standards, lab resilience, how we model attacker intent, who gets trusted access and who decides, and what defenders should build now, while nothing is on fire.
OpenAI Models Hacked Hugging Face | BHIS In Focus
Black Hills Information Security·2.6K views · 3 weeks ago
How an internal AI security test became one of the biggest cybersecurity stories of the year.
Join John Strand and guests for a special live episode of BHIS In Focus as they analyze the reported OpenAI security incident involving Hugging Face. We'll cover what happened, what we know so far, and what security professionals should be watching next.
Join us and fellow attendees for Live Chat in the Black Hills Infosec Discord server:
Join the Black Hills Infosec Discord Server!
in the #🔴live-chat channel.
Black Hills Information Security·1.6K views · 3 weeks ago
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.