Tag Archives: Security

Microsoft shows a "slim foot" with PrintNightmare

[German]PrintNightmare is the name given to a series of vulnerabilities in the Windows Print Spooler service. Attackers can use these vulnerabilities to extend rights and possibly take over domain controllers. Microsoft reacts half-heartedly with patches and recommendations, which in practice … Continue reading

Posted in Security, Windows | Tagged , , | Leave a comment

2nd 0patch fix for Windows PetitPotam 0-day vulnerability (Aug. 19, 2021)

[German]ecurity researchers had recently disclosed a new attack vector called PetitPotam. By means of an NTLM relay attack, any Windows domain controller can be taken over by attackers. ACROS Security has now presented the second free 0Patch solution for different … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Security Alert for Synology DiskStation Manager and UC SkyNAS

[German]Synology has issued a security warning for its DiskStation Manager (version <6.2.4-25556-2 ; 7.0). There are several security vulnerabilities in the firmware of the devices. UC SkyNAS units are also at risk. Synology has already issued the first firmware updates. … Continue reading

Posted in devices, Security | Tagged , | Leave a comment

Google Chrome 92.0.4515.159 with security fixes

[German]Google has released Google Chrome 92.0.4515.159 for Windows, Mac and Linux as of August 16, 2021. It is a maintenance update that fixes 9 vulnerabilities, many assigned a priority of High, in older browser versions. The Android version improves stability.

Posted in browser, Security, Update | Tagged , , | Leave a comment

Microsoft explains SMB signing configuration

[German]Another brief information for administrators in the enterprises. Microsoft enables SMB signing for the relevant network protocol. This is to ensure the security of the communication. However, the whole thing is probably a bit complex, if I interpret this correctly. … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


T-Mobile (USA) investigates possible data leak involving 100 million customer records

[German](US) mobile carrier T-Mobile is investigating whether there was a data leak or hack. This is because 100 million customer records, some of which reveal very detailed information, were offered in an underground forum, allegedly from this provider. The provider … Continue reading

Posted in Security | Tagged | Leave a comment

Windows 365: Logon data can be dumped in plain text

[German]Microsoft only introduced its Windows 365, which runs Windows 10 on Azure, at the beginning of August 2021 and also released it for customers. There is also a test version that interested parties can take a look at. Now, security … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Vice Society: 2. Ransomware gang uses Windows PrintNightmare vulnerability for attacks

[German]In my blog post Ransomware gang uses PrintNightmare to attack Windows servers, I had reported about the first case where the PrintNightmare vulnerability was used to attack Windows. Now Talos Security has already come across the second case, reporting that … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Kaseya: Decryption key revealed, backup update closes vulnerabilities

[German]Small article at the end of the week, concerning the US vendor Kaseya. After the supply chain attack on Kaseya RMI software and encryption of numerous customer systems, a decryption key has surfaced in an underground forum. In addition, a … Continue reading

Posted in Security, Software | Tagged , , | Leave a comment

Attacks on Exchange Server via ProxyShell vulnerability (8/13/2021)

[German]I'm bringing this up again before the weekend, even though the readership of this blog is probably well informed and keeps the Exchange servers up to date with the latest patches. It's Friday the 13th and we're about to hit … Continue reading

Posted in Security, Software, Windows | Tagged , | Leave a comment