DecryptedTech Feed (3739)
First provable SHA-1 Collision Happened Five Years Ago Yet SHA-1 is Still an Option.
Posted on Friday, 04 February 2022
in
Security Talk
Written by
Sean Kalinich
On February 23rd, 2017, Google published a paper on their security blog that showed how a SHA-1 collision was possible. It proved that the aging cryptographic and hashing standard was no longer a safe or secure method. Google showed that…
Read 596 times
New Vulnerability Found that Exposes a Large Number Routers to UPnProxy Attack
Posted on Friday, 04 February 2022
in
Security Talk
Written by
Sean Kalinich
Universal Plug and Play UPnP) is one of those technology decisions that make you wonder what people were thinking. The concept is fairly clear, find a way to make things easy for someone to just connect a device to a…
Read 870 times
Apple iOS Privacy Changes take a $10 Billion Chunk Out of Facebook’s Ad Plans.
Posted on Friday, 04 February 2022
in
Security Talk
Written by
Sean Kalinich
Facebook makes their money off their users. That is no shock to anyone considering the number of investigations currently ongoing over Facebook’s data collection practices. Of course, Facebook is not the only group collecting this type of information, they just…
Read 553 times
Microsoft Shows Their Lack of Focus as HoloLens 3 is Scrapped
Posted on Thursday, 03 February 2022
in
In Other News
Written by
Sean Kalinich
Microsoft has a history of making solid products that go nowhere. If you look at their history this is very clear from Windows Phone to Zune and more. They build it, fail to focus on penetrating the market and then…
Read 689 times
Microsoft Identifies New and Improved UpdateAgent macOS Malware
Posted on Thursday, 03 February 2022
in
Security Talk
Written by
Sean Kalinich
Microsoft’s Threat Intelligence team has recently disclosed their discovery and analysis of a new malware family. The malware in question is being tracked as a Trojan named UpdateAgent. The team has been watching as it progressed from a simple information…
Read 640 times
SolarWinds Supply Chain Attack is the Gift that Keeps on Giving for Security Research
Posted on Wednesday, 02 February 2022
in
Security Talk
Written by
Sean Kalinich
The SolarWinds supply chain attack was and still is one of the most complex and ingenious attacks that has come to light. How it was discovered is also an interesting topic for another conversation. The attack group in question is…
Read 1273 times
Microsoft’s Activision Blizzard Deal to be Reviewed by the FTC
Posted on Wednesday, 02 February 2022
in
In Other News
Written by
Sean Kalinich
Yesterday we talked about Microsoft’s plans to buy Activision Blizard as well as Sony’ plans to buy Bungie. We covered what these could mean in terms of content control and splitting console ownership into what titles people like. Although both…
Read 621 times
23 vulnerabilities found in UEFI firmware used across multiple vendors
Posted on Wednesday, 02 February 2022
in
Security Talk
Written by
Sean Kalinich
We first talked about the using the UEFI firmware as an attack vector (At Def Con 22 in 2014). Since that time there have been three identified and disclosed versions of malware that directly targeted this critical subsystem. That would…
Read 492 times
Device Fingerprinting Takes a Step Forward as the GPU Becomes the Focus
Posted on Tuesday, 01 February 2022
in
Security Talk
Written by
Sean Kalinich
Tracking users and devices as they browse the web is a common thing these days and has been for many years. The technology has evolved from the original tracking cookie to some of the more advanced methods in use now,…
Read 387 times
Just When You Thought It Was Safe to Samba Again, New Vulnerability Allows Remote Code Execution
Posted on Tuesday, 01 February 2022
in
Security Talk
Written by
Sean Kalinich
Samba has released several updates that patch critical flaws in their popular Sever Message Block (SMB) freeware implementation. SMB is a protocol that allows for simple sharing of network resources and has had its share of critical vulnerabilities in the…
Read 584 times
Microsoft Buys Activision, Sony Buys Bungie the Console Wars Heat Up
Posted on Tuesday, 01 February 2022
in
In Other News
Written by
Sean Kalinich
The war between Microsoft’s Xbox and Sony’s PlayStation has been going on for a while. As the two companies fight it out the consumer, for the most part, has been the winner. Each new generation of console has brought with…
Read 670 times
New Apps Allow Retrieval of Deleted Message for Users of WhatsApp on Android
Posted on Monday, 31 January 2022
in
Security Talk
Written by
Sean Kalinich
WhatsApp is one of a group of relatively secure messaging services available to both iPhone and Android users. WhatsApp states that it supports full end-to-end encryption, secure deletion of messages (by the sender and receiver) as well as the option…
Read 409 times
Direct Carrier Billing Scam Apps Nab 105 Million Users on Mobile Devices
Posted on Monday, 31 January 2022
in
Security Talk
Written by
Sean Kalinich
Scammers and threat groups are nothing if not creative. They have time and quite a bit of talent on their hands to figure out ways around security features and gateways to get what they want. Take the recent discovery of…
Read 500 times
MFA App on Google Play Store Used to Install Banking Malware
Posted on Monday, 31 January 2022
in
Security Talk
Written by
Sean Kalinich
Mobile device security is not where is should be. There is just no way around this fact. The vas majority of people simple download and install an app on their phone or tablet thinking that they are not going to…
Read 532 times
Security Awareness Training Versus Security Culture Building
Posted on Friday, 28 January 2022
in
Security Talk
Written by
Sean Kalinich
We have all opened our emails and seen the message “you have annual security awareness training assigned”. This message is one that usually elicits eye-rolls and groans of frustration. Who wouldn’t be annoyed? After all, these trainings are simplistic, boring…
Read 437 times
Apple Patches Safari WebKit Bug and a 0-Day
Posted on Friday, 28 January 2022
in
Security Talk
Written by
Sean Kalinich
Yesterday Apple released several patches for their different operating systems. One that we have talked about before is a core bug in Apple’s WebKit based Safari. This bug could potentially leak personal information regardless of the privacy settings you had…
Read 842 times