Microsoft's Storm-0558 cloud hack: MSA key comes from Windows crash dump of a PC

[German]The hack of Microsoft's Azure cloud by the suspected Chinese group Storm-0558 from May to June 2023 was possible due to a stolen private MSA key and bugs. At the time, accounts at Exchange Online via OWA and  Outlook.com had been hacked from 25 organizations. It was unclear how the attackers came into possession of a private MSA key. Now Microsoft has announced that the MSA key came from a so-called Windows crash dump, which was created on a Microsoft PC and then dumped via a compromised system.

Continue reading

Posted in Cloud, Security | Tagged , | Leave a comment

Microsoft revises downfall recommendations; MSI delivers BIOS update for UNSUPPORTED_PROCESSOR problem

Windows[German]In August, the so-called Downfall vulnerability in processors had become known, which allows information to be leaked. Now Microsoft has updated its support post with notes about the downfall vulnerability in Windows and removed information on how to disable the protections. Furthermore, after installing the August 2023 preview updates, there was an issue with Windows delivering individual users into an UNSUPPORTED_PROCESSOR Bluescreen. The motherboard manufacturer MSI has now delivered a BIOS update that is supposed to correct this problem. Here is an overview of these two issues.

Continue reading

Posted in issue, Windows | Tagged , , | 1 Comment

Google Chrome shows updated privacy policy for ads, what does it mean

Chrome[German]As of September 5, 2023, Google has updated the Chrome browser for its platforms (desktop, Android, iOS) (see Google Chrome 116.0.5845.179/.180 security update). In addition to security fixes and stability improvements, users will suddenly see a pop up with privacy notice. In the pop up, people will be informed about changes that the browser can make regarding displayed ads and they can accept or reject them. This change is related to the fact that Google wants to eliminate ad tracking via third-party cookies in Chrome and replace it with other forms.

Continue reading

Posted in browser, Security | Tagged , | Leave a comment

Google Chrome 116.0.5845.179/.180 security update

Chrome[German]Google has released updates to the Google Chrome browser 116 in the stable and extended channels for Mac, Linux and Windows as of September 5, 2023. These are security updates that are rolled out and are intended to eliminate vulnerabilities (classified as "high"). Furthermore, there is an update of the Chrome app for Android as well as for iOS.
Continue reading

Posted in browser, Security, Software, Update | Tagged , | Leave a comment

Group Policy Analytics tool now generally available

Windows[German]Tip for administrators of Windows systems who work with Group Policies or want to switch from GPOs to Microsoft Intune and take over the GPO settings. Microsoft has just announced the general availability of its "Group Policy Analytics tool". Group Policy Analytics helps import GPOs in use, analyze settings through shareable reports, and migrate GPO settings to Intune.

Continue reading

Posted in Software, Windows | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Attention: Transcription APIs from teams will be chargeable from Sept. 1, 2023 onwards

Stop - Pixabay[German]One more small warning, even if it's currently more likely to affect developers who use Microsoft's cloud stuff via API. There is a preview of the Teams transcription APIs, which can be used to create meeting transcripts and recordings using Graph APIs. Actually a fine thing, some people will interject, even if the topic of Teams recordings is its own building site and subject to co-determination if necessary. But another trap beckons, which I want to point out in this blog post. Microsoft has just announced that there will be a charge for using Teams' transcription APIs, even in the preview. That can then add up to quite a bit of money.

Continue reading

Posted in Cloud, General | Tagged , | Leave a comment

Security update to FRITZ!OS 7.57 (7.31) closes serious vulnerability

Sicherheit (Pexels, allgemeine Nutzung)[German]The Berlin-based German manufacturer of routers, AVM, has released its FRITZ.OS version 7.57 for eligible FRITZ!Box models on September 4, 2023. AVM only writes that this firmware update is a necessary stability and security update. It is therefore unclear which vulnerabilities has been fixed. The manufacturer intends to publish details at a later date, which might be related to the fact that not all FRITZ!Box models have been updated to the new firmware yet. Rumors in the internet says that a serious vulnerability has been deteced in FRITZ!Box 7590 models and attacks in the wild are observed. I have compiled what the Internet believes to know.

Continue reading

Posted in devices, Security, Update | Tagged , , | Leave a comment

Windows Defender Application Control (WDAC) becomes Application Control for Business

WindowsSmall note to administrators in the Windows environment. As far as I know, it hasn't been officially announced yet, but Microsoft is working on renaming its Windows Defender Application Control (WDAC). If not everything is wrong, the function will soon be called Application Control for Business. At least that's according to Group Policy designations distributed with Windows Insider Previews.

Continue reading

Posted in Security, Windows | Tagged , | 1 Comment

Windows: Microsoft reminds of coming TLS 1.0/1.1 deactivation

Windows[German]It's a topic that has been addressed several times here on the blog: The days of using the TLS 1.0 and TLS 1.1 protocols to communicate with servers are coming to an end. The protocols are no longer considered secure and should no longer be used. Microsoft has again taken the opportunity on September 1, 2023 to inform administrators that the two protocols will be disabled "in the near future" under Windows "in upcoming operating system versions".

Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Vulnerabilities (CVE-2023-40481, CVE-2023-31102) in 7-ZIP; fixed in version 23.00 (August 2023)

Sicherheit (Pexels, allgemeine Nutzung)[German]A short update from the end of August 2023. Security researchers have found two vulnerabilities in the 7-Zip program, which is used to pack and unpack ZIP archive files. The vulnerabilities CVE-2023-40481 and CVE-2023-31102 are classified as high-risk from a security perspective. Attackers could possibly elevate privileges.

Continue reading

Posted in Security, Software, Update | Tagged , , | Leave a comment