Security: Data leaks, Malware, Vulnerabilities (04/24)

[German]Today again an overview of security issues in IT. It's about a data leak at a startup that does payment processing, about weaknesses in smart home and compromised apps up to a hacked ad server.

Continue reading

Posted in Security | Tagged | Leave a comment

Cisco AnyConnect Secure Mobility Client Vulnerability CVE-2020-3153

[German]The Windows version of Cisco AnyConnect Secure Mobility client has a vulnerability in it's auto update, that can be misused for privilege escalation. A patch is available.

Continue reading

Posted in Security, Software, Update, Windows | Tagged , , | Leave a comment

0-day Exploits in iOS Mail

[German]Security researchers have found two 0-day exploits in virtually all iOS versions (iOS 6 through 13) that allow remote code execution (RCE) via mail. The vulnerabilities are likely to be actively exploited.

Continue reading

Posted in Security | Tagged , | Leave a comment

Windows 10 V2004 (Build 19041.208 in Insider Slow Ring)

[German]As of April 22, 2020, Microsoft has released a cumulative update (KB4558244) for the Windows 10 version 2004 for insiders in the slow ring. This update raises the build to 19041.208. It fixes an issue that prevents NPLogonNotify API notifications from being sent from the Credential Provider Framework. The announcement was published in the Windows Blog.

Posted in Update, Windows | Tagged , | Leave a comment

0patch fixes CVE-2020-0687 in Windows 7/Server 2008 R2

win7 [German]ACROS Security has released a micropatch for the memory corruption vulnerability CVE-2020-0687 in TTF fonts for Windows 7 and Server 2008 R2 (without ESU).

Continue reading

Posted in Security, Windows | Tagged , , , , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Windows 10 Insider Preview Build 19613 (Fast Ring)

[English]On April 22, 2020, Microsoft released the Windows 10 Insider Preview Build 19613.1000 (20H2 development branch) for insiders in the Fast Ring. Microsoft describes in the Windows Blog the new features, bug fixes and known issues of this build.

Posted in Windows | Tagged , | Leave a comment

Four 0-day Exploits in IBM Data Risk Manager

[German]Security researchers have just revealed four unpatched vulnerabilities in IBM Data Risk Manager. The vulnerabilities were reported to IBM, but IBM rejected the report due to lack of formal requirements. Three vulnerabilities are considered critical.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Chrome 81.0.4044.122 with security fixes released

[German]Google released the update to Chrome 81.0.4044.122 on April 21, 2020. This is an unscheduled security update which closes several (critical) vulnerabilities.

Continue reading

Posted in browser, Security, Software, Update | Tagged , | Leave a comment

Microsoft Security Advisories April 14, and 21, 2020

[German]Microsoft has published Security Advisories for a critical RCE vulnerability (CVE-2020-0905) in Microsofts Dynamics Business Central. And there are security advisories for an update to the Autodesk FBX Library and for an OpenSSL Remote Denial of Service vulnerability.

Continue reading

Posted in Security, Software, Update | Tagged , , , , | Leave a comment

Sophos Firmware Sophos UTM 9.703 re-release this week?

Brief information for users of Sophos UTM. In mid-April 2020, in the article Stop: Don't install Sophos UTM 9.703 Firmware, I reported that the firmware update was pulled due to issues. Users should not install this update. Sophos has updated now it's advisory and acknowledged the errors. A revised firmware is now in tests – if that shows no problems, a revised version of the firmware will be available this week. I have added details in the linked article. Thanks to Thorsten for pointing this out.

Posted in Software, Update | Tagged | Leave a comment