Category Archives: Security

Windows hardening: Guidances and key dates 2023

[English]Small reminder for administrators in the Windows environment. In 2023, Microsoft will continue to implement various hardening measures for Windows systems (DCOM authentication, Kerberos, Netjoin/Domain Join, etc.). These hardening measures will be rolled out in stages through monthly updates. Even … Continue reading

Posted in Security, Update, Windows | Tagged , , | Leave a comment

iOS 16.4.1(a): Rapid Security Responses Updates

[German]Apple has released an unscheduled security update (Rapid Security Response Update) for iOS to version 16.4.1 (a) on May 1, 2023. However, there are reports that there are problems with this special update on iPhones.

Posted in ios, Security, Update | Tagged , , | Leave a comment

Google Authenticator: Backup of passcodes in Google Account; but end-to-end encryption is yet to come …

[German]It's a lesson in how things shouldn't really work. The Google Authenticator app enables two-factor authentication for online accounts. In order to be able to use a replacement device with the app if the phone is lost, Google has implemented … Continue reading

Posted in Security | Tagged | Leave a comment

Windows 11: Defender LSA bug fixed by "removing settings", and more Defender/FASR issues …

[German]Microsoft's unconventional solution for the so-called LSA bug caused by a Defender update in Windows 11. Users got to see the message "Local Security Authority protection is disabled …", but could no longer enable this feature. After several "repair" attempts, … Continue reading

Posted in Security, Windows | Tagged , , | Leave a comment

SolarWinds hack in 2020: US Department of Justice knew 6 months in advance

[German]Does anyone remember the supply chain attack on SolarWinds' Orion software in 2020? That sent shockwaves through the IT landscape as masses of IT systems were hacked. Now it comes out that the US Department of Justice noticed the incident … Continue reading

Posted in Security, Software | Tagged , , , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Microsoft receives the German Big Brother Award 2023 for its "life's work"

[German]Microsoft received the German Big Brother Award 2023 for its "life's work" yesterday, April 28, 2023, because it uses its market power to force people, companies and public authorities to constantly transmit data during their digital activities, thereby making themselves … Continue reading

Posted in Office, Security, Software, Windows | Tagged , , | Leave a comment

Zyxel: Security advisory for CVE-2023-28771 in firewalls

Blog reader Liam had alerted me about vulnerability CVE-2023-28771 in Zyxel firewalls via email just a few days ago (thanks for that). An April 25, 2023 post states that improper handling of error messages occurs in Zyxel ZyWALL/USG series firmware … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

SonicOS SSLVPN: CVE-2023-1101 at MFA – new firmware for Gen6 firewalls (6.5.4.12-101n)

[German]Reminder for administrators using Sonic Wall products. There is a critical vulnerability in SonicOS SSLVPN that allows an authenticated attacker to use excessive MFA codes. The vulnerability, CVE-2023-1101, received a CVSS v3 index of 4.3 from SonicWall on March 28, … Continue reading

Posted in Security, Software | Tagged | Leave a comment

Apache Superset: CVE-2023-27524 allows Remote Code Execution (RCE)

[German]Brief note for users who deploy Apache Superset in their environment. There is a problem in the default configuration that the software can be attacked via remote code execution vulnerability. This becomes a problem if the server is accessible via … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Microsoft Edge feature "Follow creators" sends nerly all visited website URLs to Bing API

[German]There are reports, that the Microsoft Edge browser is  transmit the URLs of all websites visited by the user to the API of Microsoft's search engine Bing. The "Follow creators" feature, which is now being rolled out more broadly for … Continue reading

Posted in browser, Security | Tagged , | Leave a comment