Security News > 2021 > September

Is Traffic Mirroring for NDR Worth the Trouble? We Argue It Isn't
2021-09-02 02:20

NDR systems go beyond signature-based detection and analyze all network traffic coming inside or exiting the network and create a baseline of normal network activity. Using these technologies allows NDR systems to convert information gathered from network traffic into actionable intelligence used to detect and stop unknown cyber threats.

Windows Terminal now lets you drag and drop folders to open tabs
2021-09-01 23:51

Microsoft released Windows Terminal Preview v1.11 yesterday, and comes numerous improvements and features, including the ability to open a Terminal window by dropping a folder on the new tab button. Windows Terminal is one of my favorite features to come to Windows 10 over the past few years as it provides a multi-tabbed console window that you can use for PowerShell, WSL, and Command Prompt consoles.

Fired credit union employee admits: I wiped 21GB of files from company's shared drive in retaliation
2021-09-01 23:34

On Tuesday, a woman from Brooklyn, New York, pleaded guilty to destroying computer data at an unidentified credit union from which she had recently been fired. Juliana Barile, 35, according to charges filed by the US Attorney's Office in the Eastern District of New York [PDF], was working remotely at the credit union on a part-time basis when she was terminated on May 19, 2021.

FTC Bans Stalkerware App SpyFone; Orders Company to Erase Secretly Stolen Data
2021-09-01 23:25

The U.S. Federal Trade Commission on Wednesday banned a stalkerware app company called SpyFone from the surveillance business over concerns that it stealthily harvested and shared data on people's physical movements, phone use, and online activities that were then used by stalkers and domestic abusers to monitor potential targets. Calling out the app developers for its lack of basic security practices, the agency has also ordered SpyFone to delete the illegally harvested information and notify device owners that the app had been secretly installed on their phones.

Windows 10 KB5005101 Cumulative Update released with 34 fixes
2021-09-01 22:07

Microsoft has released the optional KB5005101 Preview cumulative update for Windows 10 2004, Windows 10 20H2, and Windows 10 21H1 with fixes for thirty-four issues. This preview update is part of Microsoft's June 2021 monthly "C" update, allowing Windows 10 users to test the upcoming fixes and changes to be released on September 14th as part of Patch Tuesday.

Windows 10 KB5005101 Cumulative Update released with gaming fixes
2021-09-01 22:07

Microsoft has released the optional KB5005101 Preview cumulative update for Windows 10 2004, Windows 10 20H2, and Windows 10 21H1 with fixes for thirty-five issues. This preview update is part of Microsoft's June 2021 monthly "C" update, allowing Windows 10 users to test the upcoming fixes and changes to be released on September 14th as part of Patch Tuesday.

Microsoft: Windows Server 2022 is now generally available
2021-09-01 20:28

Microsoft has announced that Window Server 2022, a Long Term Servicing Channel release with ten years of support, is generally available starting today. While the general availability of Windows Server 2022 was just revealed, the new release was made available to customers via the Volume Licensing Service Center and began rolling out to mainstream users almost two weeks ago, as ZDNet reported.

How to block Windows Plug-and-Play auto-installing insecure apps
2021-09-01 19:29

A trick has been discovered that prevents your device from being taken over by vulnerable Windows applications when devices are plugged into your computer. Last month, researchers detailed how simply plugging in a device in Windows may also install a vendor's application that allows regular users to quickly gain SYSTEM privileges, the highest user privilege level in Windows.

FTC bans stalkerware maker Spyfone from surveillance business
2021-09-01 18:49

FTC has banned stalkerware maker Spyfone and CEO Scott Zuckerman from the surveillance business after failing to protect customers' devices from hackers and sharing info on their location and activity. "Today, the Federal Trade Commission banned SpyFone and its CEO Scott Zuckerman from the surveillance business over allegations that the stalkerware app company secretly harvested and shared data on people's physical movements, phone use, and online activities through a hidden device hack," the FTC said today.

NSA: We 'don't know when or even if' a quantum computer will ever be able to break today's public-key encryption
2021-09-01 18:21

America's National Security Agency has published an FAQ about quantum cryptography, saying it does not know "When or even if" a quantum computer will ever exist to "Exploit" public-key cryptography. In the document, titled Quantum Computing and Post-Quantum Cryptography FAQ, the NSA said it "Has to produce requirements today for systems that will be used for many decades in the future." With that in mind, the agency came up with some predictions [PDF] for the near future of quantum computing and their impact on encryption.