Administrative Templates (.admx) v2.0 up to Windows 10 November 2021 Update (21H2)

Windows[German]Brief addendum from last week. Microsoft has released version 2.0 of its administrative templates (.admx files) for Group Policy for Windows – from Windows 7 up to Windows 10 November 2021 Update (21H2) as of 22 March 2022. Windows 11/Windows Server 2022 are not supported. The templates allow administrators to manage registry-based policy settings.

Continue reading

Posted in Windows | Tagged | 2 Comments

Microsoft Security Update Revisions (March 25, 2022)

Microsoft has released several revisions for security updates on 25 March 2022. The revisions address changed vulnerability assessments. Here is an uncommented overview.

Continue reading

Posted in Security | Tagged | Leave a comment

Fix for vulnerability CVE-2022-104 in Sophos Firewall (v18.5 MR3)

Sicherheit (Pexels, allgemeine Nutzung)[German]A security researchers have found a vulnerability CVE-2022-104 (authentication bypass) in Sophos firewalls (v18.5 MR3 and older) that allows authentication bypass. Attackers could thus take over the firewall and execute malicious code remotely. However, Sophos has since released an update for the firewall products in question.

Continue reading

Posted in Security, Software, Update | Tagged , | Leave a comment

"Browser in the browser" Phishing

Sicherheit (Pexels, allgemeine Nutzung)[German]A security researcher has recently introduced a technique to make intercepting credentials via phishing even more efficient. He calls the technique BitB, short for "browser in the browser". A fake browser window is displayed within a real login page in order to fake an OAuth login page. This allows login data to be tapped without the user being aware of it.

Continue reading

Posted in Security | Tagged | Leave a comment

Windows 10/11: Backup and Restore from Win7 is broken since Jan. 2022

Amazon[English]Another short addendum from this week on a topic that should hardly concern anyone. Microsoft has admitted that the "Backup and Restore" function known from Windows 7 for saving and restoring backups is now simply broken in Windows 10 and Windows 11. This has been the case since January 2022, when an update broke the function.

Continue reading

Posted in issue, Update, Windows | Tagged , , , | 1 Comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Anonymous has hacked Central Bank of Russia, 2nd hack of state-owned VGTRK media group?

Sicherheit (Pexels, allgemeine Nutzung)[German]The hacker group Anonymous has claimed responsibility for a hack of the Central Bank of Russia in which a lot of data was captured. The group has now published 28 GB of this data. A second hacker group calling itself "Network Battalion 65" claims a hack of Russia's state-run VGTRK media group, which operates many TV and radio stations in Russia.

Continue reading

Posted in Security | Tagged | Leave a comment

Citrix Workspace App 2204: Windows offline installation fails because of WebView2 missing

Windows[German]On 24 March 2022, Citrix released the Workspace App 2204. This enables audio redirection, has support for an improved Single Sign-On (SSO) for web and SaaS applications, as one can read in this Citrix document. But there is also a problem: an offline installation fails when the installer does not find the MicrosoftEdge WebView2 component.

Continue reading

Posted in Software, Windows | Tagged , , | Leave a comment

Microsoft Edge 99.0.1150.55 fixes vulnerability CVE-2022-1096

Edge[German]Microsoft has updated the Chromium Edge browser to version Edge 99.0.1150.55 as of 26 March 2022. This is a maintenance update that closes a number of vulnerabilities, including the highly rated and exploited vulnerability CVE-2022-1096. Microsoft has sent out an update information by email. The entry in the release notes says only that the Edge-specific vulnerability CVE-2022-1096 has been closed. Microsoft lists the release notes for Microsoft Edge and the new features on this page. There it also only says that the vulnerability CVE-2022-1096 has been closed. The browser should be updated automatically, but can also be downloaded here. Thanks to Stefan A. for the tip.

Posted in browser, Security, Update, Windows | Tagged | 2 Comments

Preliminary agreement between EU and US on the Trans-Atlantic Data Privacy Framework

[German]The European Union (EU) and the USA seem to have reached a preliminary agreement on the exchange of user data (Trans-Atlantic Data Privacy Framework) between these regions. The successor agreement is necessary because the European Court of Justice overturned two previous agreements. While the US IT giants are rejoicing, data protectionists are critical of the whole thing.

Continue reading

Posted in Security | Tagged | Leave a comment

Kaspersky on US FCC list & banned from HackerOne's bug bounty

Sicherheit (Pexels, allgemeine Nutzung)[German]Neue Entwicklung in Sachen Umgang mit dem aus Russland stammenden Sicherheitsunternehmen Kaspersky. Nachdem dessen Produkte bereits in US-Behörden nicht mehr eingesetzt werden durften, hat jetzt die US-Behörde FCC die Firma auf den Index gesetzt. Und bei der Plattform HackerOne ist Kaspersky aus dem Bug-Bounty-Programm verbannt worden. Alles Folgen des Einmarschs Russlands in die Ukraine und der damit verbundenen Sanktionen.

Continue reading

Posted in Security | Tagged | Leave a comment