Windows: 0patch for 0-day URL File NTLM Hash Disclosure Vulnerability

Windows[German]ACROS Security has discovered a vulnerability in Windows that has not yet been closed by an update and allows the disclosure of NTLM hash values via URL. ACROS Security has released an opatch micropatch to fix this vulnerability. Until Microsoft provides an update, the opatch micropatch is available free of charge.

Continue reading

Posted in ios, Security, Windows | Tagged , | Leave a comment

Windows 11 24H2 available on more devices; TPM 2.0 mandatory; installation on unsupported CPUs

Windows[German]Microsoft has begun rolling out Windows 11 24H2 (referred to as Windows 11 2024 Update), which will be generally released in October 2024, to more devices. Microsoft has also confirmed that TPM 2.0 is mandatory for Windows 11. On the other hand, there are people who experience that Windows 11 24H2 can be installed on hardware that is not compatible without any tricks. Here is a summary article with an overview of these topics.

Continue reading

Posted in Windows | Tagged | Leave a comment

Microsoft 365 SAS-URL import error 500 fixed

Mail[German]Since November 2024, the PST import into a Microsoft 365 tenant using a SAS URL was broken. The import process was aborted with an error 500. Microsoft seems to have fixed the problem as of December 3, 2024.

Continue reading

Posted in Cloud, issue | Tagged , , | Leave a comment

30 Million protected links exposed by 'safe' link-sharing provider

Sicherheit (Pexels, allgemeine Nutzung)Cybernews research found out, that a safe linking service accidentally leaked millions of links that were meant to be private and exposed who created them. Researchers discovered that Safelinking.net, a platform designed to protect and manage links, had publicly leaked a tremendous amount of user data that was supposed to be protected. Apart from making 30 million private links public, the platform also exposed the account data of over 156,000 users.

Continue reading

Posted in Security | Tagged | Leave a comment

Update KB4484305: Fix for Excel 2016 add-in loading bug

[German]Another addendum from November 2024: On November 19, 2024, Microsoft fixed a problem caused by the security update KB5002653 from November 12, 2024 in Microsoft Excel 2016 (MSI version). Add-ins could no longer be loaded there.

Continue reading

Posted in issue, Office, Update | Tagged , , , , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Retailer Medion victim of a cyber attack

Sicherheit (Pexels, allgemeine Nutzung)[German]It seems that Medion, a German Lenovo subsidary, who offers electronic devices – for discounter like Aldi -has becom victim of a cyber attack. There are customers complaining about "delivery problems" with orders. And I have found information from Medion, that they are victim of a cyber incident, that affects their IT systems and the Medion shop.

Continue reading

Posted in Security | Tagged | Leave a comment

STIGA data leak (garden and sport tools)

Sicherheit (Pexels, allgemeine Nutzung)[German]The company STIGA, active as a supplier in the field of robotic lawnmowers, gardening equipment and sporting goods, has suffered a data protection incident. A reader had made enquiries and received confirmation from the provider. Customer data has been leaked and is now being offered on the Darknet.
Continue reading

Posted in Security | Tagged | Leave a comment

New Outlook app: No GMail calendar entries possible – workaround and fix

Mail[German]A blog reader pointed me to an issue with the new Outlook app. The app could no longer create new calendar entries for his Gmail account. However, there is a workaround, and a new version with bug fixes should be available by now.

Continue reading

Posted in issue, Software | Tagged , , , | Leave a comment

Bootkitty: First Linux UEFI Bootkit

[German]ESET Research has discovered the first Linux UEFI boot kit and named it Bootkitty. This Linux UEFI boot kit was uploaded to Virustotal in early November 2024 and came to the attention of the security researchers.

Continue reading

Posted in Linux, Security | Tagged , | Leave a comment

Exchange 2016/2019: Nov. 2024 SU v2 also with bug

Exchange Logo[German]Microsoft is not really having a good run with its security updates for Exchange Server 2016 and Exchange Server 2019. The version of the security updates released on November 12, 2024 had to be withdrawn due to a bug. Version 2, released on November 27, 2024, contains a time zone bug that Microsoft has already acknowledged.

Continue reading

Posted in issue, Software | Tagged , | Leave a comment