Microsoft observed attacks on Microsoft SQL Server via PowerShell

Sicherheit (Pexels, allgemeine Nutzung)[German]The Microsoft security team is currently warning about a campaign in which unknown attackers are targeting Microsoft SQL databases. Although a brute force approach is used to crack the database access. What is new is that the campaign uses the sqlps.exe tool in conjunction with PowerShell scripts.

Continue reading

Posted in Security, Software | Tagged , , | Leave a comment

Advertising

Windows 10 21H2: Does Update KB5014023 fixes profile issues caused by May 2022 patches?

Windows[German]Question for Windows 10 users: Is anyone experiencing issues with user profiles on Windows 10 21H2 after installing the May 10, 2022 security updates? Microsoft may already be working on a fix, which is being tested with Windows Insiders via update KB5014023. Here is, what a reader experienced so far.

Continue reading

Posted in issue, Update, Windows | Tagged , , | 1 Comment

Bluetooth Low Energy vulnerability and the Tesla car theft

Sicherheit (Pexels, allgemeine Nutzung)[German]There is a vulnerability in the Bluetooth Low Energy implementation that allows remote access to corresponding Bluetooth devices (door locks, electronic devices and cars). Among others, the US car manufacturer Tesla had to admit that its electric car models Tesla Model 3 and Tesla Y can be unlocked, started and thus stolen in this way.

Continue reading

Posted in Security | Tagged | Leave a comment

Advertising

0Patch fixes vulnerabilities (CVE-2022-26809 and CVE-2022-22019) in Windows

Windows[German]The ACROS Security team around founder Mitja Kolsek has released a micro patch to close the Remote Procedure Call Runtime Integer Overflows vulnerabilities CVE-2022-26809 and CVE-2022-22019). The patch is available for Windows 7 SP1, Windows Server 2008 R2, up to Windows 10 (v1803 to v2004). The micro-patch is available for all customers with the 0patch agent who own a Pro or Enterprise license of ACROS Security. Here is some information about it.

Continue reading

Posted in Security, Windows | Tagged , , | Leave a comment

Active Directory Admins: May 2022 updates may force DCs to a boot loop (AltSecID attribute set on krbtgt)

Windows[German]Today a short information for administrators of Active Directory Domain Controllers under Windows Server, who still have to apply the security updates for May 2022. I have come across the information that there is a bug that leads to nasty problems in Windows Server in certain configurations (which should not actually occur). Administrators should pay attention to the configuration of the AltSecID attribute on the krbtgt account before installing the update. If this attribute is set, a boot loop of the DC is imminent and the Active Directory is down. I'll post the information I picked up yesterday from a Windows Escalation Engineer and since on Twitter here.

Continue reading

Posted in issue, Update, Windows | Tagged , , , , , | Leave a comment

Advertising

Researchers: Malware can run on iPhones that are switched off

Sicherheit (Pexels, allgemeine Nutzung)[German]A smartphone that is switched off is not off – we know this from movies where batteries are removed from smartphones and the devices are placed in a refrigerator or tin cans. It is certainly possible to run malware on an iPhone that is switched off. Security researchers from Darmstadt have just proven this in an experiment. It's a bit tricky and requires Bluetooth, NFC chips etc. in an iPhone – but it works.

Continue reading

Posted in devices, Security | Tagged , | Leave a comment

Nvidia security updates for Kepler GTX 700/600 GPU WHQL driver (473.47) released

Update[German]Nvidia has released a security update for the graphics driver of the Kepler GeForce GPUs on May 16, 2022, as you can read on this website. The new GeForce WHQL driver has the version 473.47 and is available for Windows 10 (64 bit) as well as Windows 11. The manufacturer writes that the security update has been released for the desktop Kepler-series GeForce GPUs, which are no longer supported by Game Ready drivers. This update fixes issues that can lead to several security compromises. Details can be found on the linked website and in the release notes.  (via)

Posted in Software, Update, Windows | Tagged , , , | Leave a comment

CISA warns against installing May 2022 updates on Windows Domain Controllers

Windows[German]US CERT CISA (Cybersecurity & Infrastructure Security Agency) has temporarily removed vulnerability CVE-2022-26925 from its Known Exploited Vulnerabilities catalog and warns US organizations not to install the May 2022 updates for Windows on machines that act as domain controllers. This is in response to authentication issues related to the updates and DCs.

Continue reading

Posted in issue, Security, Update, Windows | Tagged , , , , | Leave a comment

Advertising

Windows 11 Update KB5013943 drops BSODs and causes issues with Sophos driver

Windows[German]Another May 2022 patchday issue on Windows 11. Users who have been running Sophos antivirus solutions may have been seeing BlueScreens on Windows 11. The cause is the May 10, 2022 update KB5013943, which causes problems with a Sophos driver. Sophos has meanwhile released a fix to resolve this issue.

Continue reading

Posted in issue, Update, Windows | Tagged , , , | Leave a comment

Firefox 100.0.1

Mozilla[German]Mozilla developers have released versions 100.0.1 of the Firefox browser on May 16, 2022. It is a maintenance update, which fixes bugs. Thanks to the reader for the tip.

Continue reading

Posted in browser, Software, Update | Tagged | Leave a comment