Decryptedtech Decryptedtech Decryptedtech Decryptedtech
  • Home
  • Articles
    • News
    • Security Talk
    • Game Thoughts
    • Editorials
    • Shows and Events
    • Leaks and Rumors
    • My Ramblings
    • In Other News
    • Bits, Bytes, and Bourbon
  • Consulting
    • Security Consulting
    • Why Us
    • Services
  • Privacy Policy
  • Archived Items
    • Reviews
      • Enthusiast Gear
        • Motherboards
        • CPUs
        • GPUs
        • Audio
        • Storage and Networking
        • Entusiast Peripherals
      • Pro Gear
        • Motherboards
        • Memory
        • Storage and Networking
      • Consumer Gear
        • Motherboards
        • Audio
        • Storage and Networking
        • Consumer Peripherals
      • Home Theater
      • Mobile Computing
      • Tech Unplugged
      • Gadgets
      • Systems
        • Pro Systems
      • Software and Games
        • Consumer Software
        • Games
      • Peripherals
      • Power and Cooling
  • Bits, Bytes, and Bourbon Store

News

News

Fortinet Pre-Authentication RCE flaw Found in SSL VPN Function

The last couple of months have been rather busy with the identification of critical vulnerabilities. Multiple Zero-Days were found in different pieces of software including Remote Code Execution, data modification and theft, and complete compromise of other devices that require replacement rather than patching. So, with that it is not surprising that another critical flaw has been identified (and patched) in another major vendor’s devices. Fortinet has announced the release of patches for a vulnerability tracked as CVE-2023-27997.

Details
By Sean Kalinich
Sean Kalinich
Jun 12
Hits: 1147
  • Hacking
  • Cybersecurity
  • Vulnerabilities
  • Patching
  • fortinet
  • ssl vpn

Read more: Fortinet Pre-Authentication RCE flaw Found in...

No comments on “Fortinet Pre-Authentication RCE flaw Found in SSL VPN Function”
News

MOVIEit is having a Very Bad Week as more Flaw Found after Security Audit

MOVEit has been in the news quite a bit lately. First it was the disclosure of a Zero-Day that was actively being exploited since October 2022. Next up was the fact that the group exploiting the flaw was probably tinkering around the vulnerability since mice 2021. If that were not bad enough a new security audit performed on the MFT (managed file transfer) has found even more vulnerabilities in the service. The flaws are like the original zero-day flaws, in that they are SQL injection flaws that allow for theft of data from customer databases.

Details
By Sean Kalinich
Sean Kalinich
Jun 12
Hits: 1002
  • Hacking
  • Security
  • ZeroDay
  • Cybersecurity
  • moveit

Read more: MOVIEit is having a Very Bad Week as more Flaw...

No comments on “MOVIEit is having a Very Bad Week as more Flaw Found after Security Audit”
News

Just When you Thought it was Safe to go Back to the Bank, Microsoft Finds Banking Attacks Targeting Financial Institutions

Although Banking, Mortgage, and other financial institutions are always under attack, it is never a good thing to see a coordinated campaign targeting them. Microsoft has disclosed once such campaign using Attacker (Adversary, Man)-in -the-Middle tactics for phishing and BEC (Business Email Compromise) attacks. This style of attack is also not new and one that is often seen in the financial world. These campaigns typically start with one organization that gets popped.

Details
By Sean Kalinich
Sean Kalinich
Jun 09
Hits: 856
  • Hacking
  • Security
  • Phishing
  • bec
  • business email compromise
  • attacker in the middle
  • credential harvesting

Read more: Just When you Thought it was Safe to go Back to...

No comments on “Just When you Thought it was Safe to go Back to the Bank, Microsoft Finds Banking Attacks Targeting Financial Institutions”
News

MOVEit Zero-Day May Have Been Known by Threat Groups Since 2021

In today’s episode of why we need to change how we do things; it has come to light that the critical MOVEit zero-day that allowed complete control over targeted file transfer platforms may have been identified by the Cl0p ransomware group as far back as 2021. According to researchers at Kroll, the group appears to have been looking for the right way to properly exploit is as part of a data theft campaign against the Managed File Transfer Utility.

Details
By Sean Kalinich
Sean Kalinich
Jun 09
Hits: 1268
  • Hacking
  • Cybersecurity
  • Data Theft
  • Ransomware
  • zero day
  • moveit
  • cl0p

Read more: MOVEit Zero-Day May Have Been Known by Threat...

No comments on “MOVEit Zero-Day May Have Been Known by Threat Groups Since 2021”
News

Bring on the Ransomware Beta Test as Royal Begins Seems to be testing a New Encryptor called BlackSuit

The fine folks at the Royal ransomware group have begun testing a new flavor of encryptor that is being called BlackSuit (The hat was already taken). First identified in January of this year (2023), Royal is believed to be Conti returned to life. Royal is also a private group, meaning they are not selling their services to anyone else but looking to keep things internal and hoard all their revenue. Royal is who went after the City of Dallas recently and might have poked the bear on that one.

Details
By Sean Kalinich
Sean Kalinich
Jun 08
Hits: 1546
  • Hacking
  • Security
  • Cybersecurity
  • Ransomware
  • cybercrime
  • royal
  • blacksuit

Read more: Bring on the Ransomware Beta Test as Royal...

No comments on “Bring on the Ransomware Beta Test as Royal Begins Seems to be testing a New Encryptor called BlackSuit”

More Articles …

  1. Google and Microsoft Share a Zero Day as both Chrome and Edge get Patch Now Guidance.
  2. Barracuda Email Security Gateway Appliances that were Exploited due to Zero-Day Must Be Replaced, not Patched
  3. Minecraft Mods stuffed with Malware Used to Target Windows and Linux
  4. Sextortionists Get a Boost from AI and Publicly Available Images
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10

Page 6 of 570

Follow Us

Follow DecryptedTech on Social Media

facebook twitter linkedin
Decryptedtech