0-day vulnerability in Sophos XG Firewall under attack

[German]After experiencing issues with Sophos XG Firewall v18 MR1, the software has been pulled. And now there are reports that the Sophos XG Firewall is being attacked via 0-day exploits. Sophos has released an emergency patch to close the vulnerability. Here is some information about this 'drama' and the attack.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Revised Firmware update Sophos UTM 9.703-3 released

[German]There have been problems with the firmware update for Sophos UTM 9.703, as well as with the update for Sophos XG Firewall v18 MR1. The patches were then withdrawn by Sophos. Now the revision Sophos UTM 9.703-3 has been released again.  

Continue reading

Posted in Security, Software, Update | Tagged , , , | Leave a comment

French Kinomap app and the data leak

[German]French provider Kinomap suffers a data leak, where an unprotected database contained about 42 million records (40 GB) of user data was reachable unprotected on the Internet.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Android: Secret network of 27 app developers

[German]Security researchers have uncovered a secret network of 27 developers who have posted a total of 103 'potentially malicious' apps with 69 million downloads on the Google Play Store. The apps have now been largely removed from the Play Store by Google.

Continue reading

Posted in Android, Security | Tagged , , | Leave a comment

Windows 10: Issues with Update KB4549951?

[German]Currently, there are a lot of reports from users about issues that occur in connection with update KB4549951 on Windows 10 version 1903 or version 1909. Here is a short overview.

Continue reading

Posted in issue, Update, Windows | Tagged , , , | 10 Comments

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Security: Chromium Edge 81.0.416.64 released

EdgeMicrosoft released a security update for the Chromium Edge browser on April 23, 2020 (see ADV200002). This update fixes the vulnerabilities CVE-2020-6458, CVE-2020-6459 und CVE-2020-6460. The new Chromium Edge can be downloaded from this website.

Posted in browser, Office, Software, Update | Tagged , , | 2 Comments

Apple denies accuracy of 0-day mail bug report

[German]Is the there anything wrong with the report about two 0-day vulnerabilities in iOS that allow iPhones and iPads to be 'taken over' by mail? At least Apple and Sophos have doubts about the report released this week by a security researcher.

Continue reading

Posted in devices, ios, Security | Tagged , | Leave a comment

Workaround for Surface Pro 7 shutdown bug?

[German]There may be a workaround for owners of a Surface Pro 7 that can prevent the Microsoft tablet from spontaneously shutting down. Here are some hints about the problem and suggested workarounds.

Continue reading

Posted in devices, issue | Tagged , | Leave a comment

Backdoor: NSA and ASD warn of vulnerabilities

[German]The US secret service NSA and the Australian secret service have issued a joint warning. Hackers are increasingly trying to exploit unpatched vulnerabilities in products to infiltrate systems via web shell malware.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

PoC for Windows 10 Vulnerability CVE-2020-0624

[German]On patchday, January 14, 2020, Microsoft has closed the vulnerability CVE-2020-0624 (Win32k Elevation of Privilege) with security updates. Now I have found a Proof of Concept (PoC).

Continue reading

Posted in Security, Windows | Tagged , , , | Leave a comment