Security News

Microsoft fixes Windows vulnerable driver blocklist sync issue
2022-10-26 09:22

Microsoft says it addressed an issue preventing its vulnerable driver blocklist from being synced to systems running older Windows versions. This blocklist is designed to block threat actors from dropping legitimate but vulnerable drivers on targets' systems in Bring Your Own Vulnerable Driver attacks on HVCI-enabled Windows machines or those running Windows in S Mode.

If someone tries ransacking your Windows network, it's a bit easier now to grok in Microsoft 365 Defender
2022-10-26 04:27

Microsoft is bringing Azure Active Directory Identity Protection alerts to Microsoft 365 Defender to seemingly help IT folks thwart criminals infiltrating corporate networks via compromised users. For one thing, this means that if you want to find out the role an Azure AD identity played in an intrusion, you can now do so from one place, Microsoft 365 Defender, saving you from having to check your Azure portal, according to Microsoftie Idan Pelleg.

Researchers Detail Windows Event Log Vulnerabilities: LogCrusher and OverLog
2022-10-25 12:46

The exploits, dubbed LogCrusher and OverLog by Varonis, take aim at the EventLog Remoting Protocol, which enables remote access to event logs. While the former allows "Any domain user to remotely crash the Event Log application of any Windows machine," OverLog causes a DoS by "Filling the hard drive space of any Windows machine on the domain," Dolev Taler said in a report shared with The Hacker News.

Google Chrome to drop support for Windows 7 / 8.1 in Feb 2023
2022-10-24 20:31

Google announced today that the Google Chrome web browser will likely drop support for Windows 7 and 8.1 starting February 2023. After support is discontinued for these two Windows versions, the company says Chrome users must ensure that their devices are running at least Windows 10.

Microsoft fixes printing issue blocking Windows 11 22H2 upgrades
2022-10-24 16:26

Microsoft has fixed a known issue blocking the Windows 11 2022 Update from being offered on systems with printers using Universal Print Class or Microsoft IPP Class drivers because of compatibility issues. In late September, Redmond added a compatibility hold to block Windows 11 22H2 on affected systems because some installed printers might only allow customers to use the default settings with features like color, 2-sided printing, or higher resolutions.

Typosquat campaign mimics 27 brands to push Windows, Android malware
2022-10-23 14:17

A massive, malicious campaign is underway using over 200 typosquatting domains that impersonate twenty-seven brands to trick visitors into downloading various Windows and Android malware. Some of the malicious sites were discovered by cyber-intelligence firm Cyble, which published a report this week focusing on domains mimicking popular Android app stores like Google Play, APKCombo, and APKPure, as well as download portals for PayPal, VidMate, Snapchat, and TikTok.

Exploited Windows zero-day lets JavaScript files bypass security warnings
2022-10-22 14:06

A new Windows zero-day allows threat actors to use malicious stand-alone JavaScript files to bypass Mark-of-the-Web security warnings. Windows includes a security feature called Mark-of-the-Web that flags a file as having been downloaded from the Internet and should be treated with caution as it could be malicious.

Microsoft testing a Windows ‘PC Manager’ system optimizer app
2022-10-21 16:17

Microsoft is developing a Windows system optimization program called 'PC Manager' that combines existing Windows tools into one interface. If you are a Windows user, you have likely run into various Windows system cleaners or system optimization programs that promise to increase the speed of your computer by deleting unnecessary files and Registry keys.

Microsoft improves the Windows Update experience in Windows 11
2022-10-20 08:40

Microsoft says the latest Windows 11 preview build improves update management for IT administrators and fixes several issues leading to app crashes. The focus of this build's update improvements is to help admins make system restarts after Windows updates are installed more predictable.

Experts Warn of Stealthy PowerShell Backdoor Disguising as Windows Update
2022-10-19 10:09

Details have emerged about a previously undocumented and fully undetectable PowerShell backdoor that gains its stealth by disguising itself as part of a Windows update process. "The covert self-developed tool and the associated C2 commands seem to be the work of a sophisticated, unknown threat actor who has targeted approximately 100 victims," Tomer Bar, director of security research at SafeBreach, said in a new report.