Decryptedtech Decryptedtech Decryptedtech Decryptedtech
  • Home
  • Articles
    • News
    • Security Talk
    • Game Thoughts
    • Editorials
    • Shows and Events
    • Leaks and Rumors
    • My Ramblings
    • In Other News
    • Bits, Bytes, and Bourbon
  • Consulting
    • Security Consulting
    • Why Us
    • Services
  • Privacy Policy
  • Archived Items
    • Reviews
      • Enthusiast Gear
        • Motherboards
        • CPUs
        • GPUs
        • Audio
        • Storage and Networking
        • Entusiast Peripherals
      • Pro Gear
        • Motherboards
        • Memory
        • Storage and Networking
      • Consumer Gear
        • Motherboards
        • Audio
        • Storage and Networking
        • Consumer Peripherals
      • Home Theater
      • Mobile Computing
      • Tech Unplugged
      • Gadgets
      • Systems
        • Pro Systems
      • Software and Games
        • Consumer Software
        • Games
      • Peripherals
      • Power and Cooling
  • Bits, Bytes, and Bourbon Store
Security Talk

Leaked Data from Duolingo incident Shows US is most Impacted

Duolingo, is a language learning site (not to be confused with an LLM) and has a very large base of users. The site is a good target for attackers that might want to take advantage of that user base. This is something that apparently happened sometime before January 2023 with a cache of user data showed up on the now defunct Breached hacking forum. According to Duolingo, the information was listed as scraped as opposed to being part of a regular breach and Duolingo claimed the information was scraped from publicly available information.

Details
By Sean Kalinich
Sean Kalinich
Aug 29
Hits: 2380
  • Hacking
  • Cybersecurity
  • Data Theft
  • Breach
  • api abuse
  • duolingo
  • scraped data

Read more: Leaked Data from Duolingo incident Shows US is...

No comments on “Leaked Data from Duolingo incident Shows US is most Impacted”
Security Talk

We talk about the Ransomware Threat Landscape with SecureWorks at Black Hat 2023

Black Hat 2023 – Las Vegas, NV – One of my personal focuses is understanding the “Why” behind changes in the threat landscape. In simple terms understanding the Why of something gives you a good understanding of potential pivots and changes. After all a personal Why is what motivates and moves you, it stands to reason that identifying the Why behind threat groups gives you an insight into their motivations and drivers (besides money). With this in mind I sat down with Don Smith, VP of Threat Intelligence, Counter Threat Unit. The same team that identified the abandoned reply URL flaw in Power Platform.

Details
By Sean Kalinich
Sean Kalinich
Aug 29
Hits: 1952
  • Hacking
  • Cybersecurity
  • Data Theft
  • Ransomware
  • threat landscape
  • secureworks

Read more: We talk about the Ransomware Threat Landscape...

No comments on “We talk about the Ransomware Threat Landscape with SecureWorks at Black Hat 2023”
Security Talk

Now Patched Flaw Leverages Abandoned Reply URL found in Entra ID allows for Privilege Escalation

Microsoft has not been having the greatest of months. First it was identified that a stollen MSA signing key was used by a Nation State to access personal and low-side US government tenants (Low-Side it the unclassified side of Government Cloud Computing). This disclosure seems to have focused all of the attention on Microsoft as more and more security researchers are diving into their cloud services. That being said, there are and have always been researchers that keep Microsoft on their Radar, just because there is always something going on there. That is the case of the latest news to hit the street about Entra ID (formerly Azure AD).

Details
By Sean Kalinich
Sean Kalinich
Aug 28
Hits: 2530
  • Hacking
  • Cybersecurity
  • API
  • Vulnerabilities
  • entra id
  • graph api
  • power platform
  • secureworks
  • privilege escallation

Read more: Now Patched Flaw Leverages Abandoned Reply URL...

No comments on “Now Patched Flaw Leverages Abandoned Reply URL found in Entra ID allows for Privilege Escalation”
Security Talk

Qrypt Looking to Attack the Inefficiencies in Quantum Encryption to make Quantum Secure Communication a Reality Today

Black Hat 2023, Las Vegas – At Black Hat one of my favorite things to do is see what the latest buzzword(s)/phrases are. One of my favorites from this year was “code to cloud” while others focused on the big shiny object that is AI. Fortunately for me, I usually am afforded a chance to talk with amazing technical resources to allow me to continue my mission to cut through the marketing and get to the meat of the technology or issue. This brings me to my conversation with Denis Mandich, co-founder, and CTO of Qrypt, a quantum security company that has an interesting improvement on current methods to generate and provide access to true quantum random numbers (QRN).

Details
By Sean Kalinich
Sean Kalinich
Aug 28
Hits: 1923
  • RSA
  • qrypt
  • quantum random numbers
  • quantum encryption
  • informationtheoretic encryption
  • boublyaffine extractors
  • bound storage model
  • sample and extract seed

Read more: Qrypt Looking to Attack the Inefficiencies in...

No comments on “Qrypt Looking to Attack the Inefficiencies in Quantum Encryption to make Quantum Secure Communication a Reality Today”
Security Talk

ZeroFox Talks about the Value of Proper Attack Surface Management in Security

Black Hat 2023 Las Vegas – One of the areas I wanted to focus on this year while at both Black Hat and Def Con was to get an understanding of the threat landscape from both an industry and attacker perspective. My conversations (I don’t really do interviews) all included parts that related to the general attack landscape. So, it only made sense that one of my conversations needed to be with ZeroFox For those of you that might not be aware, ZeroFox throws a great Black Hat party… no wait. ZeroFox is an external attack surface management company. If you only think of them in terms of social media intelligence, then you probably need to revisit them.

Details
By Sean Kalinich
Sean Kalinich
Aug 23
Hits: 1649
  • Hacking
  • Cybersecurity
  • Cyber Attacks
  • Incident Response
  • threat intelligence
  • zerofox
  • physical security

Read more: ZeroFox Talks about the Value of Proper Attack...

No comments on “ZeroFox Talks about the Value of Proper Attack Surface Management in Security”

More Articles …

  1. Another Day Another Active Exploit in a Enterprise Tool as Ivanti warns of Exploited MobileIron 0-Day
  2. Qwiet AI Looks to Bring a Smooth and Clean Sound to Development Security
  3. Hacker Summer Camp 2023 Recap and My Thoughts
  4. The Odd Duality of AI and its Unexpected Negative Impact on Cybersecurity
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10

Page 6 of 33

Follow Us

Follow DecryptedTech on Social Media

facebook twitter linkedin
Decryptedtech