Decryptedtech Decryptedtech Decryptedtech Decryptedtech
  • Home
  • Articles
    • News
    • Security Talk
    • Game Thoughts
    • Editorials
    • Shows and Events
    • Leaks and Rumors
    • My Ramblings
    • In Other News
    • Bits, Bytes, and Bourbon
  • Consulting
    • Security Consulting
    • Why Us
    • Services
  • Privacy Policy
  • Archived Items
    • Reviews
      • Enthusiast Gear
        • Motherboards
        • CPUs
        • GPUs
        • Audio
        • Storage and Networking
        • Entusiast Peripherals
      • Pro Gear
        • Motherboards
        • Memory
        • Storage and Networking
      • Consumer Gear
        • Motherboards
        • Audio
        • Storage and Networking
        • Consumer Peripherals
      • Home Theater
      • Mobile Computing
      • Tech Unplugged
      • Gadgets
      • Systems
        • Pro Systems
      • Software and Games
        • Consumer Software
        • Games
      • Peripherals
      • Power and Cooling
  • Bits, Bytes, and Bourbon Store

News

News

Let’s Talk a Minute About Meta’s Threads and the Data it Wants

Yesterday (July 5, 2023) Social Networking Giant, Meta launched their competitor to Twitter. This new app is a companion app to Instagram called threads. Ironically, Twitter had a lot of buzz about the new app including from people that routinely talk about how terrible Twitter is under Elon Musk. These Twitter detractors have been posting count down timers, information on how to ensure you can be on threads as soon as it launches and more. It is interesting, if not a bit funny, to see the dialog there. However, there is a very dark cloud (heavy black and pendulous) over the green pastures of Meta’s Threads. This is the very serious concern about Privacy and Security.

Details
By Sean Kalinich
Sean Kalinich
Jul 06
Hits: 1790
  • Security
  • Privacy
  • Data Collection
  • Censorship
  • Twitter
  • Instagram
  • meta
  • threads

Read more: Let’s Talk a Minute About Meta’s Threads and the...

No comments on “Let’s Talk a Minute About Meta’s Threads and the Data it Wants”
News

NPM is back in the news as Node.js is found to be open to a Manifest Confusion Attack

It has been a few days since we talked about NPM and node.js. The popular repository has been taking a bit of a beating in recent months as attackers, hacktivists, and others seek to compromise their packages as part of a general supply chain attack. Supply chain attacks are in vouge right now and are part of the reason you might be seeing the acronym SBOM (Software Build of Materials) so much. Sure, SBOM is not a new term, but the push for it and the rise of an entire vertical in the cybersecurity industry is new and should be a bit of an indicator that there is a problem.

Details
By Sean Kalinich
Sean Kalinich
Jul 05
Hits: 1069
  • Hacking
  • Security
  • Malware
  • Cybersecurity
  • supply chain attack
  • npm
  • nodejs
  • manifest confusion attack

Read more: NPM is back in the news as Node.js is found to...

No comments on “NPM is back in the news as Node.js is found to be open to a Manifest Confusion Attack”
News

Microsoft Teams Flaw Leveraged by New Red Team Tool to Push Malware

There is nothing like an unresolved security flaw in a major product. Especially when the flaw is one that the developer knows about but does not consider important enough to fix in a timely manner. If the flaw is in a commonly used product, it is even better. In this case we are talking about a flaw we covered back on the 23rd of June. This is a bug that can allow an attacker to mimic an internal sender to get around file handling from external senders. In our opinion, it is significant, but Microsoft has no plans to remediate it any time soon. I guess they have other things on their plate like Privacy Investigations in the EU (Over Teams and Office) and the pending Activision/Blizzard deal in court in the US.

Details
By Sean Kalinich
Sean Kalinich
Jul 05
Hits: 1389
  • Security
  • Malware
  • Microsoft
  • Cybersecurity
  • Phishing
  • red team
  • teams

Read more: Microsoft Teams Flaw Leveraged by New Red Team...

No comments on “Microsoft Teams Flaw Leveraged by New Red Team Tool to Push Malware”
News

New Process Injection Method Found that can Potentially Avoid EDR Detection

EDR, XDR, and MDR are acronyms that are well known to most organizations. The operative letters here are DR which stands for Detection and Response. The E, X, and M stand for Endpoint, E(x)tended, and Managed respectively. Each one of these is designed to monitor a device for threats and respond according to the profile/configuration/policy enabled for the device. This is different than the traditional “anti-virus/anti-malware” application in many ways. The most common is that an EDR is intended to do more than check files against a signature list and quarantine them if identified. The modern EDR does look for malware, but it also monitors script execution, process starts/stops, file and registry reads and writes and, in many cases, network activity that can indicate potential compromise.

Details
By Sean Kalinich
Sean Kalinich
Jun 27
Hits: 873
  • Malware
  • xdr
  • mdr
  • edr
  • process injection
  • process mockingjay
  • security joes

Read more: New Process Injection Method Found that can...

No comments on “New Process Injection Method Found that can Potentially Avoid EDR Detection”
News

Flaws in Microsoft Teams External Tenant Handling Allow for Easy Malware Distribution

You have to love Microsoft Teams. Teams is the Frankenstein Monster of Microsoft’s Lync, which then became Skype for Business, and then morphed into the problematic service we now know as Teams. The journey from Lync to Teams has been a mishmash of features added in and removed while trying to maintain the semblance of feature parity with the products that came before it. One of the big pushes for teams was the integration of SharePoint for file storage and collection. SharePoint integration has been and continues to be a HUGE push from Microsoft in all of their MS365 products and it is not always for the better.

Details
By Sean Kalinich
Sean Kalinich
Jun 23
Hits: 1117
  • Security
  • Malware
  • Social Engineering
  • SharePoint
  • Phishing
  • smishing
  • jumpsec
  • teams

Read more: Flaws in Microsoft Teams External Tenant...

No comments on “Flaws in Microsoft Teams External Tenant Handling Allow for Easy Malware Distribution”

More Articles …

  1. Apple Patches Flaw that Allowed for Spyware Which Russia Blamed on the US
  2. Flaw in MS Azure AD OAuth Could Allow for Complete Account Take Over
  3. New Info Stealer Malware, Mystic Stealer, can Target an Impressive 40 Web Browsers
  4. Fragments of a New Sophisticated macOS Toolkit found in the Wild
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10

Page 3 of 570

Follow Us

Follow DecryptedTech on Social Media

facebook twitter linkedin
Decryptedtech