DecryptedTech Feed (3874)

Black Hat 2023 Las Vegas. The term offensive security has always been an interesting one for me. On the surface is brings to mind reaching out and touching the bad guys. However, due to many laws that is not really…
Black Hat 2023 – Las Vegas. Risk is an interesting subject and has many different meanings to many different people. For the most part Risk breaks down into a few categories, depending on who you are talking to cyber risk,…
In May of 2023 a few sensitive accounts reported to Microsoft that their environments appeared to be compromised. Due to the nature of these accounts, Microsoft dove in and discovered that an expired Consumer Microsoft Account Singing Key had been…
The recent attack that leveraged a 0-Day vulnerability to compromise a number of Barracuda Email Security Gateway appliances (physical and virtual, but not cloud) was a very sophisticated one. Even in the beginning when news of this first broke it…
There is a topic of conversation that really needs to be talked about in the open. It is the danger of developer systems (personal and company owned) being targets of threat groups. It is a fact; it is not going…
Duolingo, is a language learning site (not to be confused with an LLM) and has a very large base of users. The site is a good target for attackers that might want to take advantage of that user base. This…
Black Hat 2023 – Las Vegas, NV – One of my personal focuses is understanding the “Why” behind changes in the threat landscape. In simple terms understanding the Why of something gives you a good understanding of potential pivots and…
Microsoft has not been having the greatest of months. First it was identified that a stollen MSA signing key was used by a Nation State to access personal and low-side US government tenants (Low-Side it the unclassified side of Government…
Black Hat 2023, Las Vegas – At Black Hat one of my favorite things to do is see what the latest buzzword(s)/phrases are. One of my favorites from this year was “code to cloud” while others focused on the big…
Black Hat 2023 Las Vegas – One of the areas I wanted to focus on this year while at both Black Hat and Def Con was to get an understanding of the threat landscape from both an industry and attacker…
It used to be a common phrase that the only certain things are Death and Taxes. These days it seems the list has been extended to Death, Taxes, and 0-days in enterprise tools sets. We have seen a number of…
Black Hat 2023 – Las Vegas. Sitting in one of my favorite bars in the Mandalay Bay Shoppes, 1923 Prohibition Bar, I had an opportunity to sit down and talk with Stuart McClure. For those that do not know, I…
Wednesday, 16 August 2023 14:38

Hacker Summer Camp 2023 Recap and My Thoughts

Written by
Las Vegas – So Black Hat 2023 and Def Con 31 have come and gone, and while the exhaustion that comes from this epic combined event might not be completely gone, I am ready to give my thoughts on the…
As we head into Hacker Summer Camp in Las Vegas, the emails are already flowing freely into my inbox. Some of them are the regular players that I see every year and others are new. Still more are people that…
Hey, remember that supply chain attack on NPM that happened recently? Which one? Yeah, that is sort of the problem with recent supply chain attacks. In particular the ones that are targeting the development pipeline. This is because they are…
If you look at common attack vectors and especially Initial Access Broker attacks, there are a few parts of the attack chain which stand out. These are the pivot through some form of communication/collaboration app to the phishing landing page.…