Critical RCE vulnerability CVE-2023-39143 in PaperCut before version 22.1.3

Sicherheit (Pexels, allgemeine Nutzung)[German]Anyone using the Papercut MF/NG print management solution under Windows should urgently patch the product. A critical RCE vulnerability CVE-2023-39143 that has just been disclosed allows PaperCut servers to be taken over. The vendor has already released a corresponding security patch to eliminate the vulnerability.

Continue reading

Posted in Security, Software | Tagged , , | Leave a comment

Allegedly malicious notifications from teams through Defender ZAP

Sicherheit (Pexels, allgemeine Nutzung)[German]I would like to ask the administrators among the readership if anyone else is experiencing the effect mentioned here. An administrator contacted me because he has been getting reports of supposedly corrupt notifications from Teams for days. In use is Exchange Online and also the ZAP feature of Defender from Microsoft Office 365.

Continue reading

Posted in Cloud, Security | Tagged , , , | Leave a comment

Bypass malware detection in Google Play Store with Dynamic Code Loading

[German]If anyone is wondering why malware is repeatedly found in Android apps that are quite officially available in the Google Play Store, there is an explanation. Google's security team has now confirmed that attackers are using dynamic code loading to bypass malware detection in the Play Store.

Continue reading

Posted in Android, Security | Tagged , , | Leave a comment

Windows 11 gets soon an "Inplace upgrade" repair via Windows update

Windows[German]Broken Windows installations can be repaired by "installing over" the operating system (known as "Inplace Upgrade"). Now there are reports that Microsoft is internally working on a feature that will enable such a repair by an "Inplace Upgrade" via Windows Update. At least in Windows 11 Insider Preview, this previously hidden function can be tested. Overall, however, the whole thing sheds light on Microsoft's quality and development status – Windows 11 is so broken that it needs an integrated function to make the system usable again via reinstallation.

Continue reading

Posted in Windows | Tagged | 1 Comment

Microsoft's warning: Teams users targeted by Russian attackers (Midnight Blizzard)

Teams[German]Microsoft has just issued a warning to Teams users because they have encountered phishing campaigns targeting this clientele. Behind these phishing campaigns are Russian attackers that Microsoft names Midnight Blizzard (or NOBELIUM. APT29, UNC2452 and Cozy Bear). The group's goal is to obtain credentials from victims, specifically in the government, non-governmental organization (NGO), IT services, technology, discrete manufacturing, and media sectors.

Continue reading

Posted in Security | Tagged | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Firefox 116.0.1

Mozilla[German]The days the Mozilla developers had released the versions 116.0.0 of the Firefox browser. Now version 116.0.1 has already been added. The release notes says that a bug has been fixed: Fixed an issue which caused chart elements to render incorrectly for Windows users. 

Posted in browser, Update | Tagged | Leave a comment

Microsoft accidentally releases Windows 11 "staging tool" to unlock features

Windows[German]Microsoft mistakenly released the so-called "staging tool" that is used internally to unlock features in Windows 11. The tool was of course immediately withdrawn, but the leak was noticed and a copy of the staging tool is now circulating. Now Microsoft is trying to block the use of the tool. Below, for interested readers, is a brief overview of what's going on.

Continue reading

Posted in Software, Windows | Tagged , | Leave a comment

Outlook: Microsoft releases workaround for "open window" startup bug

[German]Since the Office updates of late June 2023, users have been complaining about a new bug in Outlook. Outlook asks at every start if windows open in the previous session (which do not exist) should be opened again. I had reported in the blog – now Microsoft has published a workaround that looks very familiar to me. Continue reading

Posted in issue, Office | Tagged , | 1 Comment

Thunderbird 102.14 and 115.1 released

[German]The developers of Thunderbird have released another update of the email client to version 115.1.0 and to 102.14 on August 1-2, 2023. These are updates which fix bugs and vulnerabilities.

Continue reading

Posted in Security, Software, Update | Tagged | Leave a comment

Microsoft as a Security Risk? Azure vulnerability unpatched since March 2023, heavy criticism from Tenable – Part 2

[German]Security vendor Tenable has made serious accusations against Microsoft. A critical vulnerability in Azure Active Directory (AAD, recently EntraID) has been known since March 2023, but has not yet been patched. The CEO of security vendor Tenable, Amit Yoran, sharply criticizes Microsoft's handling of security issues. More than 40 percent of all particularly acute vulnerabilities in recent years are related to Microsoft products. This comes at an inopportune time for Redmond, as the hack of Microsoft Azure services by the suspected Chinese group Storm-0558 has already caused enough waves. Addendum: Microsoft has patched the vulnerability on August 7, 2023.

Continue reading

Posted in Cloud, Security | Tagged , , | 1 Comment