Posts

Showing posts with the label Windows

CrowdStrike update crashes Windows systems, causes outages worldwide

Image
By Ionut Ilascu,  Bleeping Computer A faulty component in the latest CrowdStrike Falcon update is crashing Windows systems, impacting various organizations and services across the world, including airports, TV stations, and hospitals. The glitch is affecting Windows workstations and servers, with users reporting massive outages that took offline entire companies and fleets of hundreds of thousands of computers. According to some reports, emergency services in the U.S. and Canada have also been impacted. Worldwide outage By the time of the correction, though, many large organizations across multiple verticals had already been affected. Some reports say that CrowdStrike’s update impacted some 911 emergency service agencies in the state of New York (EMS, police, fire department), Alaska, and Arizona, as well as 911 services in parts of Canada. A 911 telecommunicator in Illinois said that they were “working off of paper until things come back.” There also reports that the health hotlin...

Why remote desktop tools are facing an onslaught of cyber threats

Image
By Solomon Klappholz, IT Pro Hackers are increasingly targeting remote desktop tools in their attacks, new research reveals, prompting warnings for enterprises globally In the era of hybrid work, remote desktop tools have become vital business enablers, but due to their pervasiveness on corporate networks they have become a popular entry point for cyber criminals. If successfully exploited, remote access tools can provide hackers with a direct pathway into a system or network, and once access is gained attackers can move laterally within the network, escalating privileges and maintaining persistence. In an investigation into which remote desktop tools are targeted the most, Jonathan Tanner, senior security researcher at Barracuda Networks, explained that remote desktop software poses a particular challenge to IT teams to secure. “Among the security challenges facing IT teams implementing remote desktop software is that there are many different tools available, each using different and ...

Windows 11 is getting a major Mac feature soon

Image
By Fionna Agomuoh,  Digital Trends Microsoft is testing a task overflow bar in Windows 11 that works much like the stacks feature in MacOS. The feature is now available in the Windows 11 Insider Preview Build 25163, which rolled out to the Dev Channel on Thursday. The overflow makes it so that when you have more apps open than can fit in the taskbar, they are stored in their own section, which can be accessed via an ellipses icon (…) on the bottom-right section of the screen. You can click the icon to view, access, or close the still-running apps that no longer fit on the crowded taskbar. The feature serves as an optimized version of an old Windows feature, which truncated overflow apps into a single icon and triggered the need to utilize keyboard shortcuts such as Alt-Tab to access the hidden apps, PCWorld noted. While this updated version of the task overflow bar is a lot easier to understand and use, it’s not a guaranteed feature for a public build, as it is currently still at t...

Recent Windows Server updates break VPN, RDP, RRAS connections

By Sergiu Gatlan,  Bleeping Computer This month's Windows Server updates are causing a wide range of issues, including VPN and RDP connectivity problems on servers with Routing and Remote Access Service (RRAS) enabled. RRAS is a Windows service that offers additional TCP connectivity and routing features, including remote access or site-to-site connectivity with the help of virtual private network (VPN) or dial-up connections. Last week, Microsoft released the Windows Server 2019 2012 R2 KB5014746, the Windows Server 2019 KB5014692, the Windows Server 20H2 KB5014699, and the Windows Server 2022 KB5014678 updates as part of the June 2022 Patch Tuesday. However, after deploying these recent updates, Windows admins have reported experiencing multiple issues that could only be resolved after completely uninstalling the updates. One of the more severe problems is the servers freezing for several minutes after a client connects to the RRAS server with SSTP.

Russian hackers start targeting Ukraine with Follina exploits

By Bill Toulas,  Bleeping Computer Ukraine's Computer Emergency Response Team (CERT) is warning that the Russian hacking group Sandworm may be exploiting Follina, a remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) currently tracked as CVE-2022-30190. The security issue can be triggered by either opening or selecting a specially crafted document and threat actors have been exploiting it in attacks since at least April 2022. It is worth noting that Ukraine's agency assesses with medium confidence that behind the malicious activity is the Sandworm hacker group.

Microsoft shares mitigation for Windows KrbRelayUp LPE attacks

By Sergiu Gatlan, Bleeping Computer Microsoft has shared guidance to help admins defend their Windows enterprise environments against KrbRelayUp attacks that enable attackers to gain SYSTEM privileges on Windows systems with default configurations. Attackers can launch this attack using the KrbRelayUp tool developed by security researcher Mor Davidovich as an open-source wrapper for Rubeus, KrbRelay, SCMUACBypass, PowerMad/SharpMad, Whisker, and ADCSPwn privilege escalation tools. Since late April 2022, when the tool was first shared on GitHub, threat actors could escalate their permissions to SYSTEM in Windows domain environments with default settings (where LDAP signing is not enforced). Davidovich released an updated version of KrbRelayUp on Monday that also works when LDAP signing is enforced and will provide attackers with SYSTEM privileges if Extended Protection for Authentication (EPA) for Active Directory Certificate Services (AD CS) is not enabled. Microsoft says that this pri...

New Windows Subsystem for Linux malware steals browser auth cookies

Image
By Ionut Ilascu, Bleeping Computer Hackers are showing an increased interest in the Windows Subsystem for Linux (WSL) as an attack surface as they build new malware, the more advanced samples being suitable for espionage and downloading additional malicious modules. As the name of the feature implies, WSL allows running native Linux binaries to run on Windows in an environment that emulates the Linux kernel. WSL-based malware samples discovered recently rely on open-source code that routes communication through the Telegram messaging service and gives the threat actor remote access to the compromised system. RATs and shells Malicious Linux binaries for WSL were first discovered over a year ago, with researchers at Lumen Technologies’ Black Lotus Labs publishing a report on this new type of threat in September 2021. Since then, their number has grown constantly, with all variants enjoying low detection rates, despite being based on publicly available code. Black Lotus Labs researchers ...

Microsoft Windows 11 Hacked Six Times In Three Days

By Davey Winder, Forbes PWN2OWN Vancouver 2022 has now come to an end with seven hackers picking up a total of $240,000 for successful Windows 11 zero-day exploits. The hacking competition saw Windows 11 successfully hacked six times in all, along with one attempt that failed to work within the allotted time. The six successful Windows 11 hacks were spread across all three days of the hacking competition, two on day one, one on day two, and three on the final day of the event. Marcin Wiazowski executed an out-of-bounds escalation of privilege exploit that earned a $40,000 reward. Phan Thanh Duy and Le Hu'u Quang Linh demonstrated another Windows 11 elevation of privilege attack but this with a use after-free-exploit, also winning a $40,000 cash prize. A hacker known as T0 used an improper access control bug, again resulting in elevation of privilege success and getting another $40,000 prize. Escalation of privilege hacks were the order of the day, well all three days to be precise,...

Windows 11 Update Is Crashing Apps And Freezing PCs With BSOD Errors

Image
By Lane Babuder, Hot Hardware On the 10th of May this year the patch Tuesday updates for Windows started rolling out. Unfortunately, as almost always seems to be the case, there are more and more problems piling up. Of course, the first issue people started reporting was related to servers who use Kerberos and Domain Controllers on server editions. That issue, of course, doesn't really affect most home users. However, users who did get the KB5013943 patch for personal use editions of Windows 11 have started reporting blue screen crashes. A blue screen for Windows is a "Stop Error," which is basically an operation that is triggered when the operating system tells the system to stop all action in order to prevent damage to the OS or data. They can definitely be a headache if you're trying to get some work done and just everything stops, as you can lose your work. But at least your system is "safe." If you want to know more detail on that, former Microsoft Engi...

Windows admins frustrated by Quick Assist moving to Microsoft Store

By Sergiu Gatlan,  Bleeping Computer Windows admins have been expressing their dismay at Microsoft 's decision to move the Quick Assist remote assistance tool to the Microsoft Store . Quick Assist allows Windows 10 and Windows 11 users to receive or give assistance to other Windows users by taking control of their computer remotely, as we reported four years ago. The app makes it much easier to assist friends, family, and co-workers fix their computer problems without having to go to their location or install a third-party application. While previously a built-in standalone tool that also has a system-wide hotkey (Ctrl+Win+Q), Microsoft announced on April 27 that Quick Assist is reaching the end of service and will be replaced by a Microsoft Store version on May 16. "The end of service is planned for 5/16, after which point the existing inbox app will no longer work," the official Twitter account for the Office Insider Program explained. "Users will see a prompt wh...

Microsoft fixes new PetitPotam Windows NTLM Relay attack vector

By Lawrence Abrams,  Bleeping Computer A recent security update for a Windows NTLM Relay Attack has been confirmed to be a previously unfixed vector for the PetitPotam attack. During the May 2022 Patch Tuesday, Microsoft released a security update for an actively exploited NTLM Relay Attack labeled as a 'Windows LSA Spoofing Vulnerability' and tracked as CVE-2022-26925 . "An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate to the attacker using NTLM. This security update detects anonymous connection attempts in LSARPC and disallows it." An NTLM Relay Attack allows threat actors to force devices, even domain controllers, to authenticate against malicious servers they control. Once a device authenticates, the malicious server can impersonate the device and gain all of its privileges. These attacks are significant problems as they could allow a threat actor to gain complete control over the domain. Whi...

CISA warns not to install May Windows updates on domain controllers

Image
By Sergiu Gatlan,  Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has removed a Windows security flaw from its catalog of known exploited vulnerabilities due to Active Directory (AD) authentication issues caused by the May 2022 updates that patch it. This security bug is an actively exploited Windows LSA spoofing zero-day tracked as CVE-2022-26925, confirmed as a new PetitPotam Windows NTLM Relay attack vector. Unauthenticated attackers abuse CVE-2022-26925 to force domain controllers to authenticate them remotely via the Windows NT LAN Manager (NTLM) security protocol and, likely, gain control over the entire Windows domain. Update:  Microsoft fixes new PetitPotam Windows NTLM Relay attack vector

Microsoft Windows Patch Tuesday Update Bug Is Causing Major Authentication Headaches

By Lane Babuder, Hot Hardware Many are aware by now, second Tuesday of every month is Patch Tuesday for Microsoft Windows. This is when Microsoft rolls out major and critical updates to its ubiquitous operating system, Windows. Much like many Patch Tuesdays before, there are problems with the latest one . Specifically, the patch has problems relating to authentication. Unfortunately, it looks like the issue exists on all versions of Windows, including Windows 11 and Server 2022. The knowledge of the issue seemed to have shown up in the r/sysadmin Subreddit, where some users pointed out they received the following error. "Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing account or the password was incorrect." Or something similar. There's some good news and some bad news related to this. The error seems to only affect versions of Windows that are being used as Domain Controllers and those that use Kerberos....

Microsoft Patch Tuesday, May 2022 Edition

By KrebsOnSecurity Microsoft today released updates to fix at least 74 separate security problems in its Windows operating systems and related software. This month’s patch batch includes fixes for seven “critical” flaws, as well as a zero-day vulnerability that affects all supported versions of Windows. By all accounts, the most urgent bug Microsoft addressed this month is CVE-2022-26925 , a weakness in a central component of Windows security (the “Local Security Authority” process within Windows). CVE-2022-26925 was publicly disclosed prior to today, and Microsoft says it is now actively being exploited in the wild. The flaw affects Windows 7 through 10 and Windows Server 2008 through 2022. Greg Wiseman, product manager for Rapid7, said Microsoft has rated this vulnerability as important and assigned it a CVSS (danger) score of 8.1 (10 being the worst), although Microsoft notes that the CVSS score can be as high as 9.8 in certain situations. “This allows attackers to perform a man-in-...

Microsoft PowerShell lets you track Windows Registry changes

Image
By Lawrence Abrams, Bleeping Computer ​​A handy tip was shared online this week, showing how you can use PowerShell to monitor changes to the Windows Registry over time. As Windows updates, application installs, setting changes, and malware constantly makes changes to the Windows registry, this mode would allow you to quickly spot what was changed, allowing you to diagnose issues, remove malicious entries, and see what settings have been changed. This week, popular security and technology Twitter account SwiftOnSecurity , tweeted how they would love to see a Windows Registry Editor mode that would display all registry entries that were not created by default. In response to Swift's tweet, Microsoft's Principal Security Architect in Azure Security, Lee Holmes, tweeted an example of how you could do something similar in PowerShell. Holmes' example shows how you can use PowerShell to list all existing Windows Registry keys and store them in a $snapshot variable. Then, at a lat...

Google Patches Dozens Of Vulnerabilities In Chrome, Update ASAP

Image
By Lane Babuder, Hot Hardware Another day another vulnerability. This one's a doozy, though. The Stable Channel for the desktop edition of Chrome had an update on April 26, 2022. That update includes no less than 30 security fixes, half a dozen of which are rated as "High" severity flaws. The release notes for Google's Chrome v101.0.4951.41 for Windows, Mac, and Linux has a long list of bug fixes; you can view it here . However, there's also an interesting statement in that page. "Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed." Effectively the the non-developer translation of the quote above is that these are serious enough to keep the details hidden from the public to avoid bad actors pouncing on them with exploits. We can tell you a good portion of the...

Fake Windows 10 updates infect you with Magniber ransomware

Image
By Lawrence Abrams, Bleeping Computer Fake Windows 10 updates are being used to distribute the Magniber ransomware in a massive campaign that started earlier this month. Over the past few days, BleepingComputer has received a surge of requests for help regarding a ransomware infection targeting users worldwide. While researching the campaign, BleepingComputer discovered a topic in our forums where readers report becoming infected by the Magniber ransomware after installing what is believed to be Windows 10 cumulative or security update. These updates are distributed under various names, with Win10.0_System_Upgrade_Software.msi [ VirusTotal ] and Security_Upgrade_Software_Win10.0.msi being the most common. Other downloads pretend to be Windows 10 cumulative updates, using fake knowledge base articles, as shown below. System.Upgrade.Win10.0-KB47287134.msi System.Upgrade.Win10.0-KB82260712.msi System.Upgrade.Win10.0-KB18062410.msi System.Upgrade.Win10.0-KB66846525.msi Based on the submis...

How to Downgrade From Windows 11 to Windows 10

Image
Not a fan of Microsoft's newest operating system? You can go back to Windows 10, but you only have a certain number of days to revert your OS. By Lance Whitney, PC Mag You’ve upgraded from Windows 10 to Windows 11 and now realize you’re not that crazy about Microsoft's newest operating system. Maybe you don’t like the new Start menu or taskbar. Perhaps you miss certain built-in apps or features. Or maybe you just miss the familiarity of Windows 10. Whatever the reason, you can jump back to the older OS. Microsoft gives you 10 days to revert from Windows 11 to 10. However, there is a way to extend that deadline. Here's how to return to the comfort of Windows 10. Downgrade Within 10 Days Let’s say you upgraded to Windows 11 fewer than 10 days ago and want to go back to Windows 10. That’s easy enough. Go to Settings > System > Recovery . In the Recovery options section, you should see Go back: If this version isn't working, try going back to Windows 10 . Before you m...

Microsoft: Windows Autopatch steals the 'fun' from Patch Tuesdays

Image
Microsoft announced that Windows Autopatch, a service designed to automatically keep Windows and Office software up to date, will be released in July 2022. Windows Autopatch is a new managed service offered for free to all Microsoft customers who already have a Windows 10/11 Enterprise E3 or above license. "This service will keep Windows and Office software on enrolled endpoints up-to-date automatically, at no additional cost. The second Tuesday of every month will be 'just another Tuesday'," promised Lior Bela, a Sr. Product Marketing Manager at Microsoft. "Windows Autopatch manages all aspects of deployment groups for Windows 10 and Windows 11 quality and feature updates, drivers, firmware, and Microsoft 365 Apps for enterprise updates." It moves the update orchestration from organizations to Microsoft, with the burden of planning the Update process (including rollout and sequencing) no longer on the orgs' IT teams. Windows Autopatch works with al...