Some insights about the warning of German BSI against Kaspersky antivirus software

Sicherheit (Pexels, allgemeine Nutzung)[German]I am once again taking up a difficult topic in a review, which has triggered numerous discussions within my Germanblog. It is about the German , BSI's (Federal Office for Information Security) warning against the use of products of the Russian provider Kaspersky. In the meantime, the Higher Regional Court has clarified that the BSI was allowed to warn and that this also falls within its scope. It should be clear to everyone that at least parts of the decision was also politically motivated. Now, in an article for the German broadcasting service Tagesschau, and Bavarian TV service BR has traced how difficult it was for the BSI to make its assessment.

Continue reading

Posted in Security | Tagged | Leave a comment

Microsoft Edge 104.0.1293.47 (August 5, 2022) with security fixes

EdgeMicrosoft has updated the Edge browser in the stable channel to version 104.0.1293.47 as of August 5, 2022. It is a security update that also includes a fix for vulnerabilities while also initiating the 104 development branch.

Continue reading

Posted in browser, Security, Update, Windows | Tagged , | 1 Comment

Lockbit attackers abuse Windows Defender to load Cobalt Strike

Sicherheit (Pexels, allgemeine Nutzung)[German]Security researchers from Sentinel One have discovered an interesting attack path under Windows, which is used by the ransomware gang Lockbit. The group uses Windows Defender in its ransomware construction kit to load the Cobalt Strike test tool and then abuse it. The (unpatched) target system is attacked via the Log4j vulnerability.

Continue reading

Posted in Security, Windows | Tagged , | 1 Comment

Remote access Trojan "Woody Rat" uses Follina exploits to attack Russian organizations

Sicherheit (Pexels, allgemeine Nutzung)[German]Malwarebytes' threat intelligence team has identified a new, technically advanced remote access Trojan. Dubbed "Woody Rat," the Trojan has been in circulation for about a year and targets Russian organizations. Among others, Obyedinyonnaya Aviastroitelnaya Korporatsiya (OAK), an aerospace and defense company majority-owned by the Russian state, has already been targeted by Woody Rat. The Trojan exploits the so-called Follina exploit (CVE-2022-30190), a zero-day vulnerability that can be used to abuse the Microsoft Support Diagnostics utility to download malicious Microsoft Word or Excel documents from the Web.

Continue reading

Posted in Security | Tagged | Leave a comment

Critical RCE Vulnerability CVE-2022-32548 in DrayTek Vigor Routers

Sicherheit (Pexels, allgemeine Nutzung)[German]Brief note for administrators and users who may be deploying Vigor routers in their environment. Security researchers have come across a critical Remote Code Execution vulnerability (RCE) that allows attackers to take over the router. DrayTek has provided a corresponding firmware update to close the vulnerability.

Continue reading

Posted in devices, Security | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Microsoft blocks Tutanota users in Teams

Stop - Pixabay[German]Unpleasant story that is boiling up right now. The operators of the secure email provider Tutanota just announced that Microsoft is now actively prohibiting their users from registering accounts on its platforms (e.g. Microsoft Teams). They say, incident once again confirms how large corporations act as gatekeepers and how European politics is asleep – there should be immediate intervention from competition authorities. Addendum: But there are some things still in the dark.

Continue reading

Posted in Cloud, Security | Tagged , , , | 1 Comment

Microsoft finds AiTM phishing campaign that also leverages 2FA

Sicherheit (Pexels, allgemeine Nutzung)[German]A small follow-up on security for online accounts using two-factor authentication (2FA). Microsoft's security teams have encountered a large-scale AiTM phishing campaign that attempted to attack more than 10,000 organizations since September 2021. The campaign involved stealing passwords, hijacking the user's login session and skipping the authentication process. This was true even if the user had multifactor authentication (MFA) enabled. The attackers then used the stolen credentials and session cookies to access the affected users' mailboxes and conduct further business email compromise (BEC) campaigns against other targets.

Continue reading

Posted in Security | Tagged | Leave a comment

Security & cyber attacks: Semikron, MBDA, Peter Berghaus GmbH and more

Sicherheit (Pexels, allgemeine Nutzung)[German]The last few hours have seen another rash of cyber attacks on companies and government agencies. Semikron, a German manufacturer of power semiconductor components has fallen victim to a ransomware attack. Peter Berghaus GmbH, a manufacturer of traffic technology and signaling systems, may also have fallen victim to a cyber attack (fraud emails are sent in the company's name). Furthermore, the Spanish Ministry of Science has become a victim of a cyber attack and the European missile manufacturer MBDA as well. Here is a summary of various security incidents.

Continue reading

Posted in Security | Tagged | Leave a comment

Windows 10: Update KB5014666 causes issues with Input Indicator and Language Bar

Windows[German]With the preview update released at the end of June 2022 for Windows 10 20H2 to 21H2, there is an issue that the input indicator and language bar may no longer be displayed in the status area of the taskbar. Microsoft has confirmed the bug and is rolling back the fixes via Known Issues Rollback (KIR).

Continue reading

Posted in issue, Update, Windows | Tagged , , | 1 Comment

Azure AD Connect (AADConnect) Bug Fix Update (August 2, 2022)

Quick note for administrators who have Azure AD Connect in use. As of August 2, 2022, the developers have probably released version 2.1.16.0. The reason for this release was a bug where auto-upgrade fails if the service account is in "UPN" format.

Continue reading

Posted in Cloud, Software | Tagged , | Leave a comment