Kay Farr - SeraBrynn Cyber Security & Compliance

Kay Farr - SeraBrynn Cyber Security & Compliance Trusted Cybersecurity & Compliance Advisors | FedRAMP 3PAO & CMMC C3PAO

01/24/2026
12/23/2025
12/19/2025
12/08/2025

๐—–๐—ฟ๐—ผ๐˜€๐˜€-๐—ฆ๐—ถ๐˜๐—ฒ ๐—ฆ๐—ฐ๐—ฟ๐—ถ๐—ฝ๐˜๐—ถ๐—ป๐—ด ๐—ฎ๐—น๐—น๐—ผ๐˜„๐˜€ ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐˜๐—ผ ๐—ถ๐—ป๐—ท๐—ฒ๐—ฐ๐˜ ๐—บ๐—ฎ๐—น๐—ถ๐—ฐ๐—ถ๐—ผ๐˜‚๐˜€ ๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐—ถ๐—ป๐˜๐—ผ ๐˜๐—ฟ๐˜‚๐˜€๐˜๐—ฒ๐—ฑ ๐˜„๐—ฒ๐—ฏ๐˜€๐—ถ๐˜๐—ฒ๐˜€.
Visitors believe they are safe, but their data and trust are at risk.

๐—ช๐—ต๐˜† ๐—ถ๐˜ ๐—บ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐˜€: XSS exploits harm both users and your reputation.
๐—ช๐—ต๐—ฎ๐˜ ๐˜๐—ผ ๐—ฑ๐—ผ: Encode outputs, validate inputs, and deploy web application firewalls.
๐—–๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—ถ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜: CMMC and FedRAMP audits check for XSS vulnerabilities.

๐—ช๐—ผ๐˜‚๐—น๐—ฑ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜„๐—ฒ๐—ฏ๐˜€๐—ถ๐˜๐—ฒ ๐—ฝ๐—ฎ๐˜€๐˜€ ๐—ฎ๐—ป ๐—ซ๐—ฆ๐—ฆ ๐˜๐—ฒ๐˜€๐˜ ๐˜๐—ผ๐—ฑ๐—ฎ๐˜†?

12/08/2025

Raging spyware and social engineering attacks have prompted CISA to update its definitive guidance. More โคต๏ธ

10/27/2025

๐Ÿšจ Hackers Can Steal Microsoft Teams Chats & Emails Using โ€œAccess Tokensโ€

Security experts found a new trick hackers are using to break into Microsoft Teams accounts โ€” and from there, they can read your chats, emails, and even company files on SharePoint.

๐Ÿง  Whatโ€™s happening

Hackers donโ€™t need your password for this.
Instead, they grab something called an โ€œaccess token.โ€
Think of an access token like a digital key that tells Microsoft, โ€œHey, this person is already logged in โ€” let them through.โ€

If hackers get that token, they can pretend to be you inside Teams, Outlook, or SharePoint.

๐Ÿ’ป How they steal the tokens

When you use Teams, it saves login data (including tokens) on your computer.

That data is protected by Windows security features.

But researchers found that hackers can find the encryption key Microsoft Teams uses to protect those tokens.

With that key, hackers can unlock the tokens and use them as if they were you.

Researchers even built a proof-of-concept tool (in the Rust programming language) to show how easy it is to automate this.

๐Ÿ”“ What hackers can do with stolen tokens

Once they have them, hackers can:

Read and send Teams messages as you

Access your emails and shared files

Pretend to be you in chats to trick coworkers

Spread through the company network quietly

Since it looks like the real user doing these things, itโ€™s hard for security systems to notice.

๐Ÿ›ก๏ธ How companies can protect themselves

Use endpoint protection tools that can spot strange activity on devices

Watch for weird or unexpected use of the Teams API (the system that talks to Microsoft servers)

Teach employees to be careful with suspicious links or downloads

Keep Windows and Teams fully updated and run modern antivirus software

In short:
Hackers can hijack Microsoft Teams accounts by stealing hidden โ€œlogin tokensโ€ from a userโ€™s computer. Once they do, they can spy on chats and emails or impersonate people at work โ€” all without needing passwords.

Source: https://gbhackers.com/hackers-steal-microsoft-teams-chats-emails/

SeraBrynn team at CS5 in DC!  If you're there, stop by and say hi.
10/16/2025

SeraBrynn team at CS5 in DC! If you're there, stop by and say hi.

10/09/2025

๐— ๐—ผ๐˜€๐˜ ๐—ฐ๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—ถ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐˜€ ๐˜€๐˜๐—ฎ๐—ฟ๐˜ ๐˜„๐—ถ๐˜๐—ต ๐—ผ๐—ป๐—ฒ ๐˜„๐—ฒ๐—ฎ๐—ธ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ. ๐——๐—ผ๐—ปโ€™๐˜ ๐—น๐—ฒ๐˜ ๐—ถ๐˜ ๐—ฏ๐—ฒ ๐˜†๐—ผ๐˜‚๐—ฟ๐˜€.

Hereโ€™s what works:
โ€ข Use long passphrases
โ€ข Turn on multi factor authentication
โ€ข Rotate passwords often

๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐—บ๐—ผ๐—ฟ๐—ฒ ๐˜๐—ต๐—ฎ๐—ป ๐—ท๐˜‚๐˜€๐˜ ๐—ฑ๐—ฎ๐˜๐—ฎ. ๐—ง๐—ต๐—ฒ๐˜† ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ฎ๐—ฐ๐˜๐˜€, ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฟ๐—ฒ๐—ฝ๐˜‚๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป, ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฏ๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€.

If youโ€™re ready to build stronger identity security, talk with us today.

10/09/2025

๐—ข๐—ฐ๐˜๐—ผ๐—ฏ๐—ฒ๐—ฟ ๐—ถ๐˜€ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—”๐˜„๐—ฎ๐—ฟ๐—ฒ๐—ป๐—ฒ๐˜€๐˜€ ๐— ๐—ผ๐—ป๐˜๐—ต. Hereโ€™s your quick checklist:
โœ”๏ธ Strong passwords
โœ”๏ธ Train your staff
โœ”๏ธ Update your software
โœ”๏ธ Back up your files

๐—ฆ๐—บ๐—ฎ๐—น๐—น ๐˜€๐˜๐—ฒ๐—ฝ๐˜€ ๐˜๐—ผ๐—ฑ๐—ฎ๐˜† ๐˜€๐—ฎ๐˜ƒ๐—ฒ ๐—ฏ๐—ถ๐—ด ๐—ต๐—ฒ๐—ฎ๐—ฑ๐—ฎ๐—ฐ๐—ต๐—ฒ๐˜€ ๐˜๐—ผ๐—บ๐—ผ๐—ฟ๐—ฟ๐—ผ๐˜„.
Need help building a plan for your business? Send us a message.

10/08/2025

Most contractors are not ready for ๐—–๐— ๐— ๐—– ๐—Ÿ๐—ฒ๐˜ƒ๐—ฒ๐—น ๐Ÿฎ. That is exactly why our CEO Jeff Farr spoke at DattoCon 2025 today with other industry leaders, Max Pruger, Brian Hubbard, and Rob Edwards, to share the real lessons that make the difference between passing and failing.

๐—ง๐—ต๐—ฒ ๐—ฑ๐—ฒ๐—ฎ๐—ฑ๐—น๐—ถ๐—ป๐—ฒ๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ฐ๐—น๐—ผ๐˜€๐—ถ๐—ป๐—ด ๐—ถ๐—ป. ๐——๐—ผ ๐—ป๐—ผ๐˜ ๐˜„๐—ฎ๐—ถ๐˜ ๐˜‚๐—ป๐˜๐—ถ๐—น ๐—ถ๐˜ ๐—ถ๐˜€ ๐˜๐—ผ๐—ผ ๐—น๐—ฎ๐˜๐—ฒ. Book a call with Sera Brynn today and get the expert guidance you need to secure your compliance and your contracts.

10/08/2025

Google Unveils AI-Powered Ransomware Defense for Drive

On September 30, 2025, Google announced a new AI-powered ransomware detection feature for Google Drive for Desktop. This tool monitors file changes that resemble ransomware behaviorโ€”such as mass encryption or sudden extension changesโ€”and automatically pauses file syncing to prevent further damage.

The AI model is trained on millions of ransomware samples and works by identifying destructive file modifications, not necessarily confirming an active infection. Once suspicious changes are detected, syncing stops, and users receive alerts to restore safe versions of the files.

This "trap" acts in the middle phase of ransomware attacksโ€”after malware bypasses antivirus protections but before widespread damage occurs. It complements existing antivirus and backup solutions.

The feature is currently in beta and is expected to be generally available by the end of 2025 for Business Standard and higher-tier users, at no extra cost.

Additional Context:

Ransomware groups are shifting from encryption to extortion tactics, as companies improve backup/restoration capabilities.

Despite this, ransomware attacks remain on the rise, with a 67% increase in victims listed by ransomware gangs in H1 2025 compared to the same period in 2024.

Experts praise Googleโ€™s approach as a simple but effective way to protect common file types, though affected machines still need to be cleaned manually.

Source: https://www.itbrew.com/stories/2025/10/02/monitoring-file-changes-google-announces-ai-powered-ransomware-trap-for-drive

09/26/2025

๐Ÿšจ A Popular Call-Recording App Called Neon Just Had a Huge Security Fail

Whatโ€™s Neon?

It's a viral iPhone app that records your phone calls and pays you.

It sells your recorded calls to AI companies so they can train AI systems.

It became super popular really fast โ€” 75,000 downloads in one day.

What went wrong?

The app had a massive security flaw.

Anyone using the app could easily see and listen to other users' private calls, their phone numbers, and even the transcripts of what was said.

All of this data was just sitting on the internet, unprotected.

How was this found out?

Reporters at TechCrunch tested the app and discovered the issue.

They used a tool to look at how the app talks to its servers.

They found links to other peopleโ€™s recordings and transcripts just sitting there, ready to be clicked.

What kind of data was exposed?

User phone numbers.

Who they called.

When the call happened and how long it lasted.

Full recordings and transcripts of the calls.

Did Neon tell users?

Not really.

The founder, Alex Kiam, shut the app down after being told about the issue.

He emailed users saying they were pausing to "add more security" โ€” but didnโ€™t mention the leak.

What now?

The app is offline, and itโ€™s unclear if or when it will return.

It's also unclear whether Apple or Google will take any action.

The founder hasnโ€™t said if any data was stolen or who else mightโ€™ve found the flaw.

TL;DR:

Neon was a popular app that let you sell your phone calls to AI companies โ€” but it accidentally let any user spy on other usersโ€™ private calls. Itโ€™s been shut down, but they never warned users their data had leaked.

Source: https://techcrunch.com/2025/09/25/viral-call-recording-app-neon-goes-dark-after-exposing-users-phone-numbers-call-recordings-and-transcripts/

Address

4324 Mapleshade Lane Suite 330
Plano, TX
75093

Alerts

Be the first to know and let us send you an email when Kay Farr - SeraBrynn Cyber Security & Compliance posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share