From The Blog
-
NetSPI’s Offensive Security Offering Leverages Subject Matter Experts to Enhance Pen Testing
Written by Sean KalinichBlack Hat 2023 Las Vegas. The term offensive security has always been an interesting one for me. On the surface is brings to mind reaching…Written on Tuesday, 12 September 2023 17:05 in Security Talk Read 1245 times Read more...
-
Black Kite Looks to Offer a Better View of Risk in a Rapidly Changing Threat Landscape
Written by Sean KalinichBlack Hat 2023 – Las Vegas. Risk is an interesting subject and has many different meanings to many different people. For the most part Risk…Written on Tuesday, 12 September 2023 14:56 in Security Talk Read 752 times Read more...
-
Microsoft Finally Reveals how they Believe a Consumer Signing Key was Stollen
Written by Sean KalinichIn May of 2023 a few sensitive accounts reported to Microsoft that their environments appeared to be compromised. Due to the nature of these accounts,…Written on Thursday, 07 September 2023 14:40 in Security Talk Read 1131 times Read more...
-
Mandiant Releases a Detailed Look at the Campaign Targeting Barracuda Email Security Gateways, I Take a Look at What this all Might Mean
Written by Sean KalinichThe recent attack that leveraged a 0-Day vulnerability to compromise a number of Barracuda Email Security Gateway appliances (physical and virtual, but not cloud) was…Written on Wednesday, 30 August 2023 16:09 in Security Talk Read 920 times Read more...
-
Threat Groups Return to Targeting Developers in Recent Software Supply Chain Attacks
Written by Sean KalinichThere is a topic of conversation that really needs to be talked about in the open. It is the danger of developer systems (personal and…Written on Wednesday, 30 August 2023 13:29 in Security Talk Read 992 times Read more...
-
Leaked Data from Duolingo incident Shows US is most Impacted
Written by Sean KalinichDuolingo, is a language learning site (not to be confused with an LLM) and has a very large base of users. The site is a…Written on Tuesday, 29 August 2023 19:12 in Security Talk Read 1404 times Read more...
-
We talk about the Ransomware Threat Landscape with SecureWorks at Black Hat 2023
Written by Sean KalinichBlack Hat 2023 – Las Vegas, NV – One of my personal focuses is understanding the “Why” behind changes in the threat landscape. In simple…Written on Tuesday, 29 August 2023 18:26 in Security Talk Read 1002 times Read more...
-
Now Patched Flaw Leverages Abandoned Reply URL found in Entra ID allows for Privilege Escalation
Written by Sean KalinichMicrosoft has not been having the greatest of months. First it was identified that a stollen MSA signing key was used by a Nation State…Written on Monday, 28 August 2023 15:39 in Security Talk Read 1627 times Read more...
-
Qrypt Looking to Attack the Inefficiencies in Quantum Encryption to make Quantum Secure Communication a Reality Today
Written by Sean KalinichBlack Hat 2023, Las Vegas – At Black Hat one of my favorite things to do is see what the latest buzzword(s)/phrases are. One of…Written on Monday, 28 August 2023 12:53 in Security Talk Read 1117 times Read more...
Recent Comments
- Sean, this is a fantastic review of a beautiful game. I do agree with you… Written by Jacob 2023-05-19 14:17:50 Jedi Survivor – The Quick, Dirty, and Limited Spoilers Review
- Great post. Very interesting read but is the reality we are currently facing. Written by JP 2023-05-03 02:33:53 The Dangers of AI; I Think I Have Seen this Movie Before
- I was wondering if you have tested the microphone audio frequency for the Asus HS-1000W? Written by Maciej 2020-12-18 14:09:33 Asus HS-1000W wireless headset impresses us in the lab
- Thanks for review. I appreciate hearing from a real pro as opposed to the blogger… Written by Keith 2019-06-18 04:22:36 The Red Hydrogen One, Possibly One of the Most “misunderstood” Phones Out
- Have yet to see the real impact but in the consumer segment, ryzen series are… Written by sushant 2018-12-23 10:12:12 AMD’s 11-year journey to relevance gets an epic finish.
Most Read
- Microsoft Fail - Start Button Back in Windows 8.1 But No Start Menu Written on Thursday, 30 May 2013 15:33 in News Be the first to comment! Read 115694 times Read more...
- We take a look at the NETGEAR ProSafe WNDAP360 Dual-Band Wireless Access Point Written on Saturday, 07 April 2012 00:17 in Pro Storage and Networking Be the first to comment! Read 85956 times Read more...
- Synology DS1512+ Five-Bay NAS Performance Review Written on Tuesday, 12 June 2012 20:31 in Pro Storage and Networking Be the first to comment! Read 80336 times Read more...
- Gigabyte G1.Sniper M3 Design And Feature Review Written on Sunday, 19 August 2012 22:35 in Enthusiast Motherboards Be the first to comment! Read 79031 times Read more...
- The Asus P8Z77-M Pro Brings Exceptional Performance and Value to the Lab Written on Monday, 23 April 2012 13:02 in Consumer Motherboards Be the first to comment! Read 69185 times Read more...
Displaying items by tag: Spam
Mumblehard Spamming Malware Making the Rounds in Joomla and WordPress sites
There is a common belief that Linux and BSD operating systems are, by their nature, much more secure than anything Microsoft has ever released. The problem with this belief is that it is simply not true. Linux, BSD and Windows can all be made more secure than they are by default, but there is work involved and there is a tradeoff of ease of use when you start locking things down. Many web hosts running Linux or BSD do not really have the time or available man power to really lock their host systems down which leaves them vulnerable to a number of attacks.
AdBlock allows you to block unwanted Youtube content
Adblock Plus, a popular application for blocking various advertising content that lavishes users on the Internet, is launching a new option to block unwanted content on popular social networks. Through special additives that can be found on the website YouTube Customizer, it is possible to block YouTube features that are not desirable.
There’s gold in them thar exploits
In a career that has spanned over 20 years in IT I have met a lot of people from different industries. Many of these people I have not kept in contact with and some I have. Occasionally when talking to some of them something will be said that might not hit home until a little later. This was the case with something that was said to be by an acquaintance who just happens to work as a technical manager at a security consulting company. During our talk I mentioned that it seemed like systems were getting much more insecure, and he joked saying: why would any security company want to work themselves out of business?
Path abusing access to users address books… again
![]() |
Remember Path? You know them, the social community that was accused of abusing access to their members’ mobile address books? Well they are at it again. The problem popped up not that long after they got into trouble for collecting information illegally including personal information about minors. They were reprimanded and fined $800,000 (which to a large business is still not that much). You would think they would have learned their lesson about this. Sadly it still seems to be an issue and Path argues that it this is all about maintaining the user experience.
SMS spammers fined 440,000 pounds
![]() |
Two spammers from Great Britain have received a large penalty for sending spam to mobile phones, according to the BBC. They were given a penalty in the amount of 440,000 pounds. The duo was emitting around 840,000 texts daily through the company they founded to recipients who without a doubt did not want to receive those messages. They "wasted" about 70 SIM cards daily that were connected through the device to the computer and then they used them to spam the messages until they used all available limits.
Facebook Offers Used to Turn People Into Facebook Spambots
![]() |
No sooner has Facebook given pages the ability to make offers to people then we see one of the first cams using the new system. Now, we all know that Facebook has to do something to keep people interested and in particular they need to give businesses the ability to push their products on other Facebook users. This can help Facebook generate more revenue… blah, blah, blah. However Facebook really does need to do something about their anti-spam and scam detection tools they are pretty much non-existent.
Facebook Cracking Down On Fake Likes... For The Users
![]() |
Facebook is facing something of a crisis of identity. Back when the company was still privately held everything looked very solid for the social networking giant to build into a behemoth and then push into the public market raking in even more cash. The reality of the situation was not so bright and cheerful as multiple analysts have commented on. Simply put Facebook did not turn out to be a good initial development for multiple reasons. Still we have to give them credit, they are trying to turn things around and we may possibly see Facebook turn things around financially.
Digg Backonline If You Are Willing to Give Up All Of Your Facebook Info
![]() |
Digg is officially back online and already it is off to a bad start. The newly reinvented page has decided that instead of using their own login procedure they are going to require people to log in with Facebook. This is probably one of the worst things that Digg could have done. Almost anything would have been preferable to using Facebook for the login path. Digg’s excuse of doing this to limit spam is not going to fly with many people either as there are a number of methods to prevent spam and still allow people to setup their own accounts.
New Twitter Malware Tries to Exploit Our Own Curiosity and Desire To See Ourselves On The Internet
![]() |
Remember the Faceboook malware we warned you about? You remember the one that relied on the fact that people love to see pictures of themselves on the internet? Well it looks like either the same group that was behind that malware or another equally clever group has moved from Faceboook to Twitter. We have heard multiple reports of tweets showing up that claim to have a link to a picture of the user. Unfortunately due to the widespread use of shortened links it is hard to spot many malicious payloads. Fortunately in this case you can identify the bad link by the .ru at the end… for now.
A Microsoft Engineer Claims There is an Android Botnet; The Proof Is A Little Thin
Hearing about a flaw in one product from a competitor in a product is sort of like asking your dog what food he likes best. You know you are not going to get a good answer and, of course, the dog is only going to stare at you and eat pretty much anything (including a bug…). So when we heard that a Microsoft Anti-Spam Engineer was reporting a new Android based email spam botnet we took it with a grain of salt (remember Microsoft has a new Phone OS coming out soon).