Amazon Kindle: Vulnerability allowed Amazon account takeover

Sicherheit (Pexels, allgemeine Nutzung)[German]Security researchers from Check Point have found a dangerous vulnerability in the eBook reader Amazon Kindle. Attackers could have used malicious code to take over the linked Amazon account of the device owner or read out his data. In the meantime, Amazon has closed this vulnerability with an update.

Continue reading →

Posted in devices, Security | Tagged , | Leave a comment

Edge 92.0.902.67

Edge[German]Microsoft has updated the Edge browser to version 92.0.902.67 as of August 5, 2021. The release notes state that security updates to the Chromium browser have been included. Microsoft emailed me the list of fixed vulnerabilities in Chromium.

Continue reading →

Posted in browser, Security, Update | Tagged , , | Leave a comment

0patch fix for new Windows PrintNightmare 0-day vulnerability (Aug. 5, 2021)

Windows[German]In the blog post PrintNightmare: Point-and-Print allows installation of arbitrary files I had reported about a new vulnerability in Windows. A remote print server, which can be reached by unauthorized persons, allows to install arbitrary malicious files on the clients via point-and-print. In the article I had also mentioned ways to mitigate it. Now ACROS Security has presented a free 0Patch solution for various Windows Server versions that prevents exploitation of the vulnerability.

Continue reading →

Posted in Security, Windows | Tagged , | Leave a comment

ConfigMgr: Deprecated features in 2022

Windows[German]Brief information for administrators in enterprise environments who manage Windows Updates via Configuration Manager (ConfigMgr). On January 31, 2022, the first features will be deprecated. For example, Desktop Analytics for Windows 7, Windows 8.x and older Windows 10 versions will no longer be supported. Later in 2022, more features will be dropped Here's some information on what to look out for.

Continue reading →

Posted in Update, Windows | Tagged , | Leave a comment

INFRA:HALT: Vulnerabilities in TCP/IP stack endanger Operational technology systems (OT)

Sicherheit (Pexels, allgemeine Nutzung)[German]Security researchers from Forescout and JFrog have just made public the vulnerabilities in the NicheStack TCP/IP library grouped under the term INFRA:HALT. They had come across it while analyzing the library. This NicheStack TCP/IP library is used in products (industrial controllers and IOT industrial devices) from more than 200 vendors. More than 6,400 vulnerable devices are currently accessible online.

Continue reading →

Posted in devices, Security | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Microsofts Cloud PC "failed provisioning" error during Windows 365 setup

Windows[German]A short information tidbit about Microsoft's Cloud PC and issues during setting up Windows 365. The cloud service is only available since a few days (see Windows 365 released) and Microsoft has already had to suspend the provisioning of the free trial versions because the demand exceeded the available resources. But there are already first experiences that setting up Windows 365 at the Cloud PC ends with the error "failed provisioning".

Continue reading →

Posted in Cloud, issue, Windows | Tagged , , | Leave a comment

Free Software Foundation considers Microsoft's GitHub Copilot unfair and not legal

Paragraph[German]Does Copilot, the AI solution launched by Microsoft on GitHub for embedding code snippets (e.g., in Visual Studio code), violate fair use and the rights of code developers? The nonprofit Free Software Foundation has just raised some questions about the fairness, legitimacy and legality of the AI-driven coding assistant CoPilot.

Continue reading →

Posted in General, Software | Tagged , | Leave a comment

ProtonMail and the user data transfer to the USA

[German]The Swiss-based ProtonMail e-mail service offers end-to-end encryption of mails before they are sent to ProtonMail's server. ProtonMail is operated by Proton Technologies AG, which is based in Plan-les-Ouates (Canton Geneva). Its servers are located in two locations in Switzerland, outside EU and US jurisdiction. As a result, ProtonMail is (supposedly) considered a "secure email service and haven of privacy." 

Continue reading →

Posted in Security | Tagged | 1 Comment

NSA and CISA: Kubernetes Hardening Guidance

Sicherheit (Pexels, allgemeine Nutzung)[German]The NSA (National Security Agency) and CISAgov have published Kubernetes configurations and recommendations for securing Kubernetes environments against cyber attacks. Understanding the options for building and maintaining a secure Kubernetes cluster is key to protecting your data and resources.

Continue reading →

Posted in Security | Tagged , | Leave a comment

Update 2107 for Microsoft Endpoint Configuration Manager CB

Windows[German]Brief information for administrators in corporate environments who use Microsoft Endpoint Manager for device management. Microsoft has released update 2107 for Microsoft Endpoint Configuration Manager (current branch) as of August 2, 2021. Update 2107 brings numerous minor new features such as an application deployment and uninstallation.

Continue reading →

Posted in Windows | Tagged | Leave a comment