Tag Archives: Security

Patchday: Windows 10-Updates (April 9, 2024)

[German]On April 9, 2024 (second Tuesday of the month, patch day at Microsoft), various cumulative updates were released for the supported Windows 10 builds (from the RTM version to the current version) as well as for the Windows Server counterparts. … Continue reading

Posted in Security, Update, Windows | Tagged , , , | Leave a comment

Advertising

Microsoft Security Update Summary (April 9, 2024)

[German]On April 9, 2024, Microsoft released security updates for Windows clients and servers, Office and other products. The security updates address 147 vulnerabilities (CVEs), including three critical vulnerabilities. Below is a compact overview of these updates that were released on … Continue reading

Posted in Office, Security, Software, Update, Windows | Tagged , , , , | Leave a comment

How to find weak passwords in Active Directory and eliminate them with PowerShell

[Sponsored Post]Weak or compromised passwords are a known gateway for attackers. If you are able to identify which users in Active Directory (AD) are threatened by this, then PowerShell can help to remedy it. However, PowerShell scripts cannot eliminate basic AD deficits, other tools are needed for this. More ...

Windows NTLM credentials vulnerability CVE-2024-21320: Fix from 0patch

[German]There is a vulnerability in Windows (CVE-2024-21320) that exposes NTLM credentials about Windows topics. Microsoft patched the vulnerability CVE-2024-21320 in January 2024. This patch provides a policy to prevent the exposure of NTLM credentials when theme files are located on … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Advertising

Microsoft slammed for a cascade of faults that leads to Storm-0558 cloud hack

[German]The US Cyber Safety Review Board has now published its report on the hack of Microsoft Online Exchange in the summer of 2023 by the suspected Chinese group Storm-0558. The board's conclusion: Microsoft can't do security! And certainly not in … Continue reading

Posted in Cloud, Security | Tagged , , | Leave a comment

Windows 10: Prices for Extended Security Updates announced

[English]Microsoft has already announced that there will be an ESU program (Extended Security Updates Program) for Windows 10, which will no longer be supported on 14 October 2025. Even private users will be able to purchase extended security updates for … Continue reading

Posted in Security, Update, Windows | Tagged , , , | Leave a comment

Advertising

Breaking news: Microsoft abandons ChatGPT in EU after AI recommendation

[German]Microsoft's plans to roll out its AI solution Copilot worldwide with its products do not seem to be working out very well at the end of the day. Following extreme headwinds  in US congress and in the EU, I understand … Continue reading

Posted in Security, Software | Tagged , , , , | Leave a comment

US Congress bans the use of Microsoft AI solution Copilot

[German]Microsoft is sticking to its plans to roll out Copilot to users in all kinds of products, from Windows to Office. However, the US House of Representatives has issued a strict ban on the use of Microsoft Copilot by its … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Linux: Backdoor in upstream xz/liblzma; compromise of SSH servers

[German]As of Friday, March 29, 2024, Red Hat has published a warning. The latest versions of the "xz" tools and libraries contain malicious code, a backdoor, which is apparently intended to allow unauthorized access. Affected by the backdoor (vulnerability CVE-2024-3094) … Continue reading

Posted in issue, Linux, Security, Software | Tagged , , | 1 Comment

Advertising

Microsoft Edge Bug CVE-2024-21388 allowed to install arbitrary extensions

[German]A now-patched vulnerability in the Microsoft Edge web browser could have been abused to install arbitrary extensions on users' systems and carry out malicious actions. This was revealed by a security researcher to The Hacker News. Advertising

Posted in browser, issue, Security | Tagged , | Leave a comment

Apple users target of "MFA bombing" attacks (2024)

[German]Users of Apple devices (iPhone, Apple Watch, Macs) are probably being targeted by a wave of attacks known as "MFA bombing". The aim of the attackers is to take over the victims' Apple accounts through a wave of password reset … Continue reading

Posted in devices, Security | Tagged , | Leave a comment