Security News

Adobe now shows alerts in Windows 10 to uninstall Flash Player
2020-12-30 17:35

With the Flash Player officially reaching the end of life tomorrow, Adobe has started to display alerts on Windows computers recommending that users uninstall Flash Player. To help secure your system, Adobe will block Flash content from running in Flash Player beginning January 12, 2021.

New worm turns Windows, Linux servers into Monero miners
2020-12-30 09:40

A newly discovered and self-spreading Golang-based malware has been actively dropping XMRig cryptocurrency miners on Windows and Linux servers since early December. The C2 server is used to host the bash or PowerShell dropper script, a Golang-based binary worm, and the XMRig miner deployed to surreptitiously mine for untraceable Monero cryptocurrency on infected devices.

Google: Microsoft Improperly Patched Exploited Windows Vulnerability
2020-12-28 13:15

Google Project Zero has disclosed a Windows zero-day vulnerability caused by the improper fix for CVE-2020-0986, a security flaw abused in a campaign dubbed Operation PowerFall. Tracked as CVE-2020-17008, the new vulnerability was reported to Microsoft on September 24.

Google Discloses Poorly-Patched, Now Unpatched, Windows 0-Day Bug
2020-12-27 22:17

Google's Project Zero team has made public details of an improperly patched zero-day security vulnerability in Windows print spooler API that could be leveraged by a bad actor to execute arbitrary code. Details of the unpatched flaw were revealed publicly after Microsoft failed to rectify it within 90 days of responsible disclosure on September 24.

Windows 10 Cloud PC: What is known about Microsoft's new service
2020-12-27 12:43

Microsoft is believed to be working on a new virtualized desktop experience called 'Cloud PC' to help administrators deploy and manage Windows 10 PCs in the cloud via web browser, mobile app or another PC. Cloud PC will also allow Microsoft to handle your organization's device configuration by applying updates security improvements regularly, and offer managed support. Cloud PC is based on Azure and Windows Virtual Desktop and it won't replace any version of Windows.

Windows Zero-Day Still Circulating After Faulty Fix
2020-12-24 16:31

A high-severity Windows zero-day that could lead to complete desktop takeover remains dangerous after a "Fix" from Microsoft failed to adequately patch it. The local privilege-escalation bug in Windows 8.1 and Windows 10 exists in the Print Spooler API. It could allow a local attacker to elevate privileges and execute code in the context of the current user, according to Microsoft's advisory issued in June.

Windows zero-day with bad patch gets new public exploit code
2020-12-23 14:57

Back in June, Microsoft released a fix for a vulnerability in the Windows operating system that enabled attackers to increase their permissions to kernel level on a compromised machine. Google Project Zero security researcher Maddie Stone discovered that Microsoft's patch in June did not fix the original vulnerability and it can still be leveraged with some adjustments.

Microsoft: Don't delete Windows 10 root certificate expiring this month
2020-12-22 13:29

A Microsoft root certificate is expiring at the end of this month, and Microsoft warns that removing it could cause problems with the operating system. Earlier this month, BornCity reported that the 'Microsoft Root Authority' certificate in Microsoft's Trusted Root Certification Authorities was expiring at the end of the month, on 12/31/20.

Microsoft fixes Windows 10 chkdsk bug causing boot failures
2020-12-21 08:43

Microsoft has acknowledged a new issue impacting Windows 10 customers that might cause booting to fail on devices where the chkdsk tool has been used to repair logical file system errors. Chkdsk is a command-line utility that can be used to check a Windows device's volumes for file system and file system metadata logical and physical errors.

Windows Hello is now being used by 84% of Windows 10 users
2020-12-20 11:28

Microsoft's Windows Hello biometric, PIN, and hardware authentication system is slowly growing in popularity, according to a new report from Microsoft. For those unaware, Windows Hello allows users to authenticate secure access to their devices, online accounts, web browsers, etc with a Windows Hello supported hardware such as FIDO keys, PINs, or biometric features such as iris scan support, fingerprint scanner, and facial recognition.