DecryptedTech Feed (3874)
Tuesday, 12 September 2023 17:05
NetSPI’s Offensive Security Offering Leverages Subject Matter Experts to Enhance Pen Testing
Written by Sean Kalinich
Black Hat 2023 Las Vegas. The term offensive security has always been an interesting one for me. On the surface is brings to mind reaching out and touching the bad guys. However, due to many laws that is not really…
Read 1244 times
Published in
Security Talk
Tuesday, 12 September 2023 14:56
Black Kite Looks to Offer a Better View of Risk in a Rapidly Changing Threat Landscape
Written by Sean Kalinich
Black Hat 2023 – Las Vegas. Risk is an interesting subject and has many different meanings to many different people. For the most part Risk breaks down into a few categories, depending on who you are talking to cyber risk,…
Read 752 times
Published in
Security Talk
Thursday, 07 September 2023 14:40
Microsoft Finally Reveals how they Believe a Consumer Signing Key was Stollen
Written by Sean Kalinich
In May of 2023 a few sensitive accounts reported to Microsoft that their environments appeared to be compromised. Due to the nature of these accounts, Microsoft dove in and discovered that an expired Consumer Microsoft Account Singing Key had been…
Read 1131 times
Published in
Security Talk
Wednesday, 30 August 2023 16:09
Mandiant Releases a Detailed Look at the Campaign Targeting Barracuda Email Security Gateways, I Take a Look at What this all Might Mean
Written by Sean Kalinich
The recent attack that leveraged a 0-Day vulnerability to compromise a number of Barracuda Email Security Gateway appliances (physical and virtual, but not cloud) was a very sophisticated one. Even in the beginning when news of this first broke it…
Read 920 times
Published in
Security Talk
Wednesday, 30 August 2023 13:29
Threat Groups Return to Targeting Developers in Recent Software Supply Chain Attacks
Written by Sean Kalinich
There is a topic of conversation that really needs to be talked about in the open. It is the danger of developer systems (personal and company owned) being targets of threat groups. It is a fact; it is not going…
Read 992 times
Published in
Security Talk
Tuesday, 29 August 2023 19:12
Leaked Data from Duolingo incident Shows US is most Impacted
Written by Sean Kalinich
Duolingo, is a language learning site (not to be confused with an LLM) and has a very large base of users. The site is a good target for attackers that might want to take advantage of that user base. This…
Read 1404 times
Published in
Security Talk
Tuesday, 29 August 2023 18:26
We talk about the Ransomware Threat Landscape with SecureWorks at Black Hat 2023
Written by Sean Kalinich
Black Hat 2023 – Las Vegas, NV – One of my personal focuses is understanding the “Why” behind changes in the threat landscape. In simple terms understanding the Why of something gives you a good understanding of potential pivots and…
Read 1001 times
Published in
Security Talk
Monday, 28 August 2023 15:39
Now Patched Flaw Leverages Abandoned Reply URL found in Entra ID allows for Privilege Escalation
Written by Sean Kalinich
Microsoft has not been having the greatest of months. First it was identified that a stollen MSA signing key was used by a Nation State to access personal and low-side US government tenants (Low-Side it the unclassified side of Government…
Read 1627 times
Published in
Security Talk
Monday, 28 August 2023 12:53
Qrypt Looking to Attack the Inefficiencies in Quantum Encryption to make Quantum Secure Communication a Reality Today
Written by Sean Kalinich
Black Hat 2023, Las Vegas – At Black Hat one of my favorite things to do is see what the latest buzzword(s)/phrases are. One of my favorites from this year was “code to cloud” while others focused on the big…
Read 1117 times
Published in
Security Talk
Wednesday, 23 August 2023 16:10
ZeroFox Talks about the Value of Proper Attack Surface Management in Security
Written by Sean Kalinich
Black Hat 2023 Las Vegas – One of the areas I wanted to focus on this year while at both Black Hat and Def Con was to get an understanding of the threat landscape from both an industry and attacker…
Read 1038 times
Published in
Security Talk
Monday, 21 August 2023 14:02
Another Day Another Active Exploit in a Enterprise Tool as Ivanti warns of Exploited MobileIron 0-Day
Written by Sean Kalinich
It used to be a common phrase that the only certain things are Death and Taxes. These days it seems the list has been extended to Death, Taxes, and 0-days in enterprise tools sets. We have seen a number of…
Read 2275 times
Published in
Security Talk
Friday, 18 August 2023 17:36
Qwiet AI Looks to Bring a Smooth and Clean Sound to Development Security
Written by Sean Kalinich
Black Hat 2023 – Las Vegas. Sitting in one of my favorite bars in the Mandalay Bay Shoppes, 1923 Prohibition Bar, I had an opportunity to sit down and talk with Stuart McClure. For those that do not know, I…
Read 851 times
Published in
Security Talk
Wednesday, 16 August 2023 14:38
Hacker Summer Camp 2023 Recap and My Thoughts
Written by Sean Kalinich
Las Vegas – So Black Hat 2023 and Def Con 31 have come and gone, and while the exhaustion that comes from this epic combined event might not be completely gone, I am ready to give my thoughts on the…
Read 1079 times
Published in
Security Talk
Thursday, 03 August 2023 18:45
The Odd Duality of AI and its Unexpected Negative Impact on Cybersecurity
Written by Sean Kalinich
As we head into Hacker Summer Camp in Las Vegas, the emails are already flowing freely into my inbox. Some of them are the regular players that I see every year and others are new. Still more are people that…
Read 1052 times
Published in
Security Talk
Monday, 31 July 2023 13:31
June NPM Attack Attributed to North Korea in Recent Phylum Report
Written by Sean Kalinich
Hey, remember that supply chain attack on NPM that happened recently? Which one? Yeah, that is sort of the problem with recent supply chain attacks. In particular the ones that are targeting the development pipeline. This is because they are…
Read 668 times
Published in
Security Talk
Monday, 31 July 2023 11:48
Browser and App Pivots are part of the Problem, Seraphic looks to Address this with one Agent to Rule them All
Written by Sean Kalinich
If you look at common attack vectors and especially Initial Access Broker attacks, there are a few parts of the attack chain which stand out. These are the pivot through some form of communication/collaboration app to the phishing landing page.…
Read 814 times
Published in
Security Talk