Author: Bethany Kozal

Tales From the Road: An Ongoing Hardware Assessment in a High-Risk Environment

Never underestimate the abilities of people with too much time on their hands and a pension for malicious activity. Hardware and software security assessments are a key component of maintaining the safety, security, and compliance of any device type, almost regardless of the environment in which they are used. But when the environment is a… Read more »

A person holding a Google Chromecast remote and pointing it to a TV screen.

We Uncovered a Chain of Chromecast Vulnerabilities – Here’s Why It Matters.

What We Did, and What You Should Know Before Installing a Custom OS A DirectDefense security researcher, Nolen Johnson, joined two other researchers to exploit three Chromecast vulnerabilities present in the Chromecast with Google TV (CCwGTV) 1080P.  The team developed a chain of three exploits that ultimately allowed an individual to run a custom OS/unsigned… Read more »

Tales From the Road: The Fortifying Abilities of an In-Depth Web Application Security Assessment

Internal app assessments, while helpful, won’t reveal all of the vulnerabilities weakening your security. Web applications, or web apps, are a common and useful way for companies to interact with both employees and customers. Without adequate assessment, however, security risks thrive, leaving the door open for bad actors to manipulate the systems and cause serious… Read more »

Tales From the Road: OT Security Assessment of Water Utility Illuminates the Path for Widespread Industry Improvement

Our recent OT security assessment at a private water utility illustrates how no industry is safe from security threats. Regardless of sector, all industries, from education, to finance, to water treatment, are susceptible to bad actors taking advantage of their internally-overlooked vulnerabilities. While water utilities have historically lagged behind other industries in OT security, the… Read more »

Tales From the Road: The Power of Physical Penetration Testing

Is Your Organization’s Physical Security Top-Notch? Having high-level security measures at any organization is a must, especially for large corporations that deal with specific clientele and hold confidential and sensitive information. We know attackers find ways to gain access to corporate networks remotely, but physical access poses even more risk, as attackers can potentially get… Read more »

Tales From the Road: Physical Penetration Testing Breaches Weak Boundaries

How Secure Are Your Organization’s Premises? When it comes to entry points into an organization, network security gaps and vulnerabilities aren’t the only concern. Bad actors can choose a more traditional way in – physically walking through the doors. You may have locks, ID badges, cameras, and employee protocols, but the best way to know… Read more »

Detecting Hardware Vulnerabilities with IoT Penetration Testing

Welcome to a new series of DirectDefense blog posts about hardware and IoT penetration testing! The goal of this 101 series is to shed light on common hardware I/O interfaces, associated protocols, and the multitude of vulnerabilities that can arise when they are left unprotected. While hardware reconnaissance will be briefly discussed, this particular article… Read more »

Tales From the Road: What An Enterprise Risk Assessment Looks Like

Has your corporation been keeping up-to-date on the latest security practices? An important one to bring into your security repertoire is an enterprise risk assessment. It’s crucial to regularly conduct enterprise assessments to ensure the effectiveness of your corporation’s security measures. An enterprise risk assessment helps your organization continuously update and measure all security protocols,… Read more »

Combat Ransomware: Try Halcyon’s Anti-Ransomware Platform Free for 60 Days

Armor Your Endpoints Free for 60 Days  If you’ve experienced the impact of a ransomware attack, you understand how severely it can disrupt business operations. That is why we’re partnering with Halcyon to offer a 60-day free trial of their anti-ransomware platform.  Halcyon’s next-generation anti-ransomware solution stops attackers at all phases of a breach using… Read more »

Tales From the Road: A Cybersecurity Breach is Only A Phone Call Away

How DirectDefense Compromised a Banking Institution’s Help Desk and Member Services Using a Phone Social Engineering Attack + 5 Common Vishing Pitfalls to Avoid Cyber criminals will stop at nothing to steal personal and confidential information from their target. In recent years, many high-profile attacks have leveraged targeted phone social engineering attacks, known as vishing.… Read more »