Decryptedtech Decryptedtech Decryptedtech Decryptedtech
  • Home
  • Articles
    • News
    • Security Talk
    • Game Thoughts
    • Editorials
    • Shows and Events
    • Leaks and Rumors
    • My Ramblings
    • In Other News
    • Bits, Bytes, and Bourbon
  • Consulting
    • Security Consulting
    • Why Us
    • Services
  • Privacy Policy
  • Archived Items
    • Reviews
      • Enthusiast Gear
        • Motherboards
        • CPUs
        • GPUs
        • Audio
        • Storage and Networking
        • Entusiast Peripherals
      • Pro Gear
        • Motherboards
        • Memory
        • Storage and Networking
      • Consumer Gear
        • Motherboards
        • Audio
        • Storage and Networking
        • Consumer Peripherals
      • Home Theater
      • Mobile Computing
      • Tech Unplugged
      • Gadgets
      • Systems
        • Pro Systems
      • Software and Games
        • Consumer Software
        • Games
      • Peripherals
      • Power and Cooling
  • Bits, Bytes, and Bourbon Store
Security Talk

IRS backs off Collecting Biometric Data as part of ID.me Account Creation

ID.me, the private identification verification company, has become a popular go-to when it comes to governmental services. We have seen it put in play at the local, state, and federal level. The idea is to have a source of truth for someone’s identity that can be used across multiple platforms. The reality is very different as it seems you need to have a different ID.me account for different services depending on the email address used. It also seems to be going well beyond normal methods of verification as we have seen multiple state and federal agencies begin collecting biometric data through the service.

Details
By Sean Kalinich
Sean Kalinich
Feb 24
Hits: 1079
  • Data Collection
  • Personal Data
  • irs
  • idme
  • biometric
  • identitfy theft

Read more: IRS backs off Collecting Biometric Data as part...

No comments on “IRS backs off Collecting Biometric Data as part of ID.me Account Creation”
Security Talk

Vulnerabilities, Phishing, and More allow Attackers to Compromise web3 services including OpenSea and Steal $1.7 Million in virtual assets

We have another Web3 article today. This one covers a new NFT marketplace compromise though the use of phishing emails that tricked users into singing over their digital assets to an, as of yet, unknown attacker.

Details
By Sean Kalinich
Sean Kalinich
Feb 23
Hits: 1017
  • Security
  • Phishing
  • web3
  • nfts
  • opensea
  • discord

Read more: Vulnerabilities, Phishing, and More allow...

No comments on “Vulnerabilities, Phishing, and More allow Attackers to Compromise web3 services including OpenSea and Steal $1.7 Million in virtual assets”
Security Talk

Unpatched and Unprotected Microsoft SQL Servers Targeted for Cobalt Strike Injection

It seems that there are still some MS SQL servers that are not only exposed to the open internet but are also still using weak passwords. When this is combined with vulnerabilities and the lack of other security controls and monitoring, it allows threat actors to compromise them. This is the case in a recently observed campaign where the attackers are targeting exposed MS SQL servers and injecting Cobalt Strike.

Details
By Sean Kalinich
Sean Kalinich
Feb 23
Hits: 1459
  • Security
  • Malware
  • Vulnerability
  • cobalt strike
  • ms sql

Read more: Unpatched and Unprotected Microsoft SQL Servers...

No comments on “Unpatched and Unprotected Microsoft SQL Servers Targeted for Cobalt Strike Injection”
Security Talk

noVNC Used by Clever Pentester to get Around MFA During Spearphishing Attack

Most attacks, be they real or from a penetration test, begin with an attempt to compromise a single system, or user. The compromise of a device or user account gives the attacker a small foothold in an environment that they can use to pivot to other areas and begin their complete takeover of the targeted organization. Defenders use many techniques to try to prevent this including complex passwords, complex usernames and, of course multi-factor authentication (MFA). MFA, when done properly, reduces the risk of credential compromise from phishing and spearphshing significantly.

Details
By Sean Kalinich
Sean Kalinich
Feb 23
Hits: 1322
  • Security
  • Phishing
  • spearphishing
  • mfa
  • credential compromise

Read more: noVNC Used by Clever Pentester to get Around MFA...

No comments on “noVNC Used by Clever Pentester to get Around MFA During Spearphishing Attack”
Security Talk

Another Banking Trojan for Android is making the Rounds Through Google’s Play Store

Google has a bit of an issue with malware present in their Play Store as there are reports of another banking trojan targeting users of European banks. Currently, the malware called Xenomorph may have infected as many as 50,000 devices across 56 Banks, all though a malicious app located in the Google Play Store.

Details
By Sean Kalinich
Sean Kalinich
Feb 22
Hits: 1397
  • Android
  • Mobile
  • Security
  • Malware
  • Google Play Store
  • xenomorph
  • android acessibiity service

Read more: Another Banking Trojan for Android is making the...

No comments on “Another Banking Trojan for Android is making the Rounds Through Google’s Play Store”

More Articles …

  1. Flaws, they’re not Just for Attackers Anymore as Researchers Find a way to Recover the Master Key for Hive Ransomware
  2. The Risks, the Crime, and the Illusions of Blockchain or Decentralized Networks.
  3. Concerned about Android Tracking? You Can Remove your Ad ID in Android 12 and Up to Help with This
  4. Linux has a New Local Privilege Escalation Bug in Snap-Confine
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25

Page 21 of 33

Follow Us

Follow DecryptedTech on Social Media

facebook twitter linkedin
Decryptedtech