SUNBURST malware was injected into SolarWind's source code base

[German]An analysis of the supply chain attack on the Orion product line of the US security vendor SolarWinds suggests that the attackers had access to the source code base. For months, they prepared the insertion of the Trojan, which acted as a backdoor, and injected it into the source code.

Continue reading

Posted in Security | Tagged | 1 Comment

Windows 10 2004/20H2: Thunderbolt NVMe BSOD bug fixed

[German]Another topic I like to cover. With the update KB4586853 for Windows 10 2004 and 20H2, Microsoft also addressed the bug that caused bluescreens on Thunderbolt NVMe SSD units. The upgrade block has therefore been lifted as of December 11, 2020.

Continue reading

Posted in Windows | Tagged , | Leave a comment

Microsoft revisions to various Office CVEs (December 15, 2020)

[German]Microsoft has published an overview of revisions of various CVEs as of December 15, 2020. I received the whole thing by mail last night, and I'm posting it here for your information.

Continue reading

Posted in Office, Security | Tagged , | Leave a comment

News in the fight against SUNBURST infection, domain seized

[German]The knowledge about the cyber attack against US authorities and companies via the SUNBURST backdoor is growing. The U.S. State Department and other government agencies may have been hacked as well. Meanwhile, Microsoft and other industry partners have seized the domain with the C&C server and hope to be able to track down infected systems.

Continue reading

Posted in Security | Tagged , | Leave a comment

Firefox 84.0.0 and 78.6.0 ESR released

Mozilla[German]Mozilla's developer have released version 84.0.0 and 78.6.0 ESR of the Firefox browser as of December 15, 2020. These are new development branches for the browser. Here is an overview of the new features.

Continue reading

Posted in browser, Software, Update | Tagged , , | 1 Comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Thunderbird 78.6.0 released

[German]The developers of the Thunderbird email client have released Thunderbird 78.6.0 on December 15, 2020. This is a maintenance update for the 78 main version of the email client, which fixes bugs and closes security holes.

Continue reading

Posted in Security, Software, Update | Tagged , | Leave a comment

Sloppiness at SolarWinds responsible for compromised software?

[German]Was sloppiness or at least a lax security culture at the US software manufacturer SolarWinds possibly responsible for their compromised updates of the Orion products, that has been shipped for months with the SUNBURST Trojan? This Trojan has been used to hack numerous US government agencies and the security vendor FireEye in recent months. Here is a look into a security abyss …

Continue reading

Posted in Security | Tagged | Leave a comment

Windows 10 Insider Preview Build 20279

Microsoft has released Windows 10 Insider Preview build 20279 for Windows Insiders in the Developer Channel as of December 14, 2020. This build is largely identical to build 20277, which was released on December 10, 2020. Microsoft wants to test upgrade options to other builds. Windows Insiders who upgraded to build 21277 (RS_PRERELEASE) will not be offered this build because they are on a newer build. The announcement was made on the Windows blog, where you can read about fixes and known issues, as well as other details.

Posted in Windows | Tagged , | 1 Comment

Windows 10 20H2: Update KB4592438 blocks VMware ThinApp

[German]Windows 10 20H2 administrators using VMware ThinApp should beware. I have received feedback from users that after installing update KB4592438, VMware ThinApps no longer starts. Here's an overview, what I know so far.

Continue reading

Posted in issue, Update, Windows | Tagged , , , , , | 3 Comments

UK Tax Relief Company Exposes Customers' Personal Information In Data Leak

Security Researchers from Website Planet found, that an UK Tax Relief Company Exposes Customers' Personal Information due to a misconfigured web server. Here are a few details about this Data Leak.

Continue reading

Posted in Security | Tagged | Leave a comment