Security News

Microsoft Edge is getting 'Edge for Gamers' mode
2023-05-21 23:09

Microsoft is doubling its efforts to court the gaming community with a new feature, "Edge for Gamers" mode, which promises to elevate the user experience inside and outside gaming sessions. In the initial descriptions provided by Microsoft, the Edge for Gamers mode will enable a variety of enhancements.

Microsoft: Notorious FIN7 hackers return in Clop ransomware attacks
2023-05-19 17:06

A financially motivated cybercriminal group known as FIN7 resurfaced last month, with Microsoft threat analysts linking it to attacks where the end goal was the deployment of Clop ransomware payloads on victims' networks. "The group was observed deploying the Clop ransomware in opportunistic attacks in April 2023, its first ransomware campaign since late 2021.".

Microsoft shares more info on the end of Internet Explorer
2023-05-18 18:57

Microsoft has decided to allow customers to choose when the last bits of Internet Explorer 11 will be removed from their devices. "Over the coming months a small subset of exceptional scenarios where IE11 is still accessible will be redirected to Edge, ensuring users access a supported and more secure Microsoft browser," the company added.

Microsoft decides it will be the one to choose which secure login method you use
2023-05-18 17:32

Microsoft wants to take the decision of which multi-factor authentication method to use out of the users' hands and into its own. The software maker this week is rolling out what it calls system-preferred authentication for MFA, which will present individuals signing in with the most secure method and then alternatives if that method is unavailable.

Microsoft pulls Defender update fixing Windows LSA Protection bug
2023-05-17 18:12

Microsoft has pulled a recent Microsoft Defender update that was supposed to fix a known issue triggering persistent restart alerts and Windows Security warnings that Local Security Authority Protection is off. Microsoft acknowledged the issue on March 21, after widespread user reports regarding Windows 11 systems warning that LSA protection was off.

Malicious Microsoft VSCode extensions steal passwords, open remote shells
2023-05-17 16:37

Cybercriminals are starting to target Microsoft's VSCode Marketplace, uploading three malicious Visual Studio extensions that Windows developers downloaded 46,600 times. According to Check Point, whose analysts discovered the malicious extensions and reported them to Microsoft, the malware enabled the threat actors to steal credentials, system information, and establish a remote shell on the victim's machine.

Microsoft Secure Boot Bug
2023-05-17 11:01

Microsoft is currently patching a zero-day Secure-Boot bug. The BlackLotus bootkit is the first-known real-world malware that can bypass Secure Boot protections, allowing for the execution of malicious code before your PC begins loading Windows and its many security protections.

Microsoft investigates slow Windows VPN speeds after May updates
2023-05-16 22:14

Microsoft is investigating major speed issues affecting L2TP/IPsec VPN connections after installing recent Windows 11 updates. Based on reports seen by BleepinComputer since the updates have been available, both updates are triggering the L2TP/IPsec VPN speed issues after deployment.

Week in review: Microsoft fixes two actively exploited bugs, MSI private code signing keys leaked
2023-05-14 08:00

Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkitFor May 2023 Patch Tuesday, Microsoft has delivered fixes for 38 CVE-numbered vulnerabilities, including a patch for a Windows bug and a Secure Boot bypass flaw exploited by attackers in the wild. MSI's firmware, Intel Boot Guard private keys leakedThe cybercriminals who breached Taiwanese multinational MSI last month have apparently leaked the company's private code signing keys on their dark web site.

Why Microsoft just patched a patch that squashed an under-attack Outlook bug
2023-05-12 23:17

If a miscreant carefully crafted a mail with that sound path set to a remote SMB server, when Outlook fetched and processed the message, and automatically followed the path to the file server, it would hand over the user's Net-NTLMv2 hash in an attempt to log in. The patch from a couple of months ago made Outlook use the Windows function MapUrlToZone to inspect where a notification sound path was really pointing, and if it was out to the internet, it would be ignored and the default sound would play.