Skip to main content

Scotchtown Technology

Check Out

Category: Security

Firmware-Level Android Malware Represents a Threat Category That Standard Security Tools Are Not Designed to Catch

Firmware-Level Android Malware Represents a Threat Category That Standard Security Tools Are Not Designed to Catch

The security assumption that a new, unopened device is a clean device has been a reasonable baseline for most organizations managing mobile fleets. Kaspersky research has identified a threat that undermines that assumption at its foundation. The Keenadu backdoor malware is being found preinstalled on Android devices, in some cases deployed at the firmware level […]

Continue Reading

Weak Passwords Remain One of the Most Preventable Security Failures in Business, and the Evidence Is Still Accumulating

Weak Passwords Remain One of the Most Preventable Security Failures in Business, and the Evidence Is Still Accumulating

McDonald’s recently drew attention to a data point that is simultaneously amusing and genuinely concerning: Have I Been Pwned, the breach monitoring service that tracks compromised credentials across known data breaches, shows that “big mac” appears in over 110,000 compromised accounts, “frenchfries” in more than 34,000, “happymeal” in over 17,000, and “mcnuggets” in more than […]

Continue Reading

Ransomware Infrastructure Has Industrialized, and the Defense Strategy Needs to Reflect That Reality

Ransomware Infrastructure Has Industrialized, and the Defense Strategy Needs to Reflect That Reality

Ransomware has been a significant enterprise security concern for long enough that most organizations have some awareness of the threat. What is less well understood is how substantially the infrastructure supporting ransomware operations has matured, and what that maturity means for the scale and persistence of attacks that organizations now face. Sophos researchers investigating multiple […]

Continue Reading

Malicious Chrome Extensions Are Exploiting AI Platform Trust, and the Attack Method Deserves Careful Attention

Malicious Chrome Extensions Are Exploiting AI Platform Trust, and the Attack Method Deserves Careful Attention

The assumption that a curated app store or extension marketplace is a safe source of software is one of the most consequential security misconceptions in the current enterprise environment. Google’s Chrome Web Store has a review process, and that review process provides some protection against obviously malicious submissions. It does not provide the comprehensive vetting […]

Continue Reading

Software Integrity Is the Cybersecurity Problem That Data Sovereignty Cannot Solve

Software Integrity Is the Cybersecurity Problem That Data Sovereignty Cannot Solve

The recent wave of high-profile software supply chain incidents has pushed a specific response to the top of the policy agenda in several countries: keep data within national borders, reduce dependence on foreign cloud providers, and assert greater sovereign control over digital infrastructure. The instinct behind this response is understandable. When major incidents like the […]

Continue Reading

Microsoft Teams Is Adding Protection Against Brand Impersonation Calls, and It Reflects a Broader Pattern Worth Understanding

Microsoft Teams Is Adding Protection Against Brand Impersonation Calls, and It Reflects a Broader Pattern Worth Understanding

The attack surface that matters to sophisticated threat actors is not the one that is hardest to breach technically. It is the one that is most trusted by the people who use it. Microsoft Teams occupies exactly that position for the organizations that rely on it as their primary collaboration platform: it is familiar, it […]

Continue Reading

AI Investment in Finance Is Producing Returns, but Only for Organizations That Have Approached It Correctly

AI Investment in Finance Is Producing Returns, but Only for Organizations That Have Approached It Correctly

The finance sector’s relationship with artificial intelligence has moved past the point where adoption itself is the story. Investment is widespread, leadership buy-in is nearly universal, and the integration work is actively underway across the majority of organizations. The more important question now is whether that investment is producing the financial value it is supposed […]

Continue Reading

The Human Factor in Cyber Resilience Is Both the Central Problem and the Most Underutilized Solution

The Human Factor in Cyber Resilience Is Both the Central Problem and the Most Underutilized Solution

The question of where an organization’s cyber resilience strategy is most vulnerable rarely points toward infrastructure or software when examined honestly. Outdated systems and unpatched vulnerabilities are real risks, but they are also visible ones that security teams are trained to identify and address. The more persistent vulnerability is the human layer: the employees who […]

Continue Reading

The Microsoft Copilot Vulnerability That Requires Only One Click to Expose Your Sensitive Data

The Microsoft Copilot Vulnerability That Requires Only One Click to Expose Your Sensitive Data

Security researchers at Varonis have documented an attack technique called Reprompt that allows attackers to extract sensitive information from Microsoft Copilot through a single user click, without requiring phishing emails, fake login pages, or malicious downloads that security awareness training teaches employees to avoid. The technique exploits a class of vulnerability called prompt injection, in […]

Continue Reading

FREE REPORT

Free IT Assessment Report

The Hudson Valley Business Owner's Guide To I.T. Support Services And Fees

"What You Should Expect to pay for I.T. Support For Your Hudson Valley Business"

[contact-form-7 id="afc3d58" title="Free Report Form"]