Critical FortiOS-Bug (Feb. 8., 2024)

Sicherheit (Pexels, allgemeine Nutzung)[German]A very brief note, which was also pointed out to me by a blog reader. Forti has re-released all FortiOS versions on February 8, 2024. The release notes do not say what has been fixed in these versions. The reader confirmed my suspicion off the record that there is another critical SSLVPN bug.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Progress Kemp LoadMaster (load balancer) Firmware update

Sicherheit (Pexels, allgemeine Nutzung)[German]Quick note for administrators who use the load balancer LoadMaster from Progress Kemp. The provider has provided various firmware updates for its LoadMaster as of February 7, 2024. These should be installed immediately. Addendum: Information about CVE-2024-1212 in Progress Kemp LoadMaster added.

Continue reading

Posted in Security, Software, Update | Tagged , , | Leave a comment

JetBrains TeamCity: Critical vulnerability CVE-2024-23917 (on-premises)

Sicherheit (Pexels, allgemeine Nutzung)[German]A small addendum from yesterday regarding security. There is a critical vulnerability in JetBrains TeamCity Server that endangers on-premises servers. There is probably a security update available, which should be installed as soon as possible. I don't know who among the readership uses the package, I didn't know the name. I will summarize the necessary information in this article.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

AnyDesk hack already noticed on December 20, 2023? – Part 9

Sicherheit (Pexels, allgemeine Nutzung)[German]The successful cyberattack on AnyDesk, a provider of remote maintenance software, is making quite a stir. Officially, the incident was confirmed by AnyDesk on February 2, 2024 (specifically Friday evening at 10:44 pm). Almost nothing is known – neither when, nor what exactly was hacked. I've been working on this topic since January 2024 and an overall picture is emerging from many bits and pieces of information. I now have various sources that indicate that the hack was noticed as early as December 20, 2023. Addendum: AnyDesk has confirmed my suspicions, see my text below.

Continue reading

Posted in Security | Tagged | 3 Comments

Bitlocker key determined via TPM within 42 seconds with Raspberry Pi Pico

Sicherheit (Pexels, allgemeine Nutzung)[German]A news for Windows users, encrypting their disks with Bitlocker. A YouTuber demonstrates how a vulnerability in "external" TPM chips can be exploited to determine a Bitlocker key within seconds. All you need is a Bitlocker key sniffer in the form of a Raspberry Pi Pico for around 10 US dollar.

Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Google Chrome 121.0.6167.160/161 / 120.0.6099.283 with security fixes

Chrome[German]Google has released updates to the Google Chrome browser in the Stable Channel for Mac, Linux and Windows on February 6, 2024. There were also updates for the Extended Stable Channel. The Chrome browser Android app has also been updated. The updates contain security fixes. Here is an overview of these updates. Continue reading

Posted in browser, Security, Software, Update | Tagged , , | Leave a comment

Firefox 122.0.1

Mozilla[German]On February 6, 2024, the Mozilla developers released the update of Firefox Firefox 122.0.1. It is a maintenance update that fixes some bugs.

Continue reading

Posted in browser | Tagged | 9 Comments

AnyDesk hack – more details (FAQ from Feb. 5, 2024) – Part 8

Sicherheit (Pexels, allgemeine Nutzung)[German]The successful cyberattack on the provider of remote maintenance software, AnyDesk GmbH, has caused quite a stir. One problem for users of AnyDesk – at least in my eyes – is that the provider is very tight-lipped about the details. We don't know what happened, we don't know when something happened. However, there are always bits and pieces of information from the readership that fall into place like pieces of a puzzle. Below I try to complete this picture, especially after AnyDesk published an FAQ hours ago.

Continue reading

Posted in Security | Tagged | 1 Comment

Office: Project Update KB5002530 (February 6, 2024)

[German]On February 6, 2023 (first Tuesday of the month), Microsoft released a non-security update for Microsoft Project 2016. It is the update KB5002530, which is intended to fix a startup problem of previous updates. Here is some information about this update.

Continue reading

Posted in Office, Update | Tagged , | Leave a comment

AnyDesk hack – Notes on exchanging certificates for Customs clients 7.x – Part 7

Sicherheit (Pexels, allgemeine Nutzung)[German]Following the cyberattack on the provider of remote maintenance software, AnyDesk GmbH, there is a notice that the certificate for binary signing of the clients will be exchanged and the old certificate "will be revoked soon". Users should switch to AnyDesk Client 8.0.8 or higher. The problem is the "Customs Clients" used by OEMs or companies, which are still based on the 7.x development branch. There are problems with the generation of these client versions. And I have a statement from support via a reader that these clients will only be equipped with a new certificate "in a few weeks".

Continue reading

Posted in Security | Tagged | Leave a comment