Category

NSA

Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don’t work for older kit NSA

Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don’t work for older kit

Good news: There is none. Well, apart from you can at least fully patch the Microsoft blunder Vid Easy-to-use exploits have emerged online for two high-profile security vulnerabilities, namely the Windows certificate spoofing bug and the Citrix VPN gateway hole. If you haven't taken mitigation steps by now, you're about…
bubmag
January 17, 2020
Podcast: NSA Reports Major Crypto-Spoofing Bug to Microsoft NSA

Podcast: NSA Reports Major Crypto-Spoofing Bug to Microsoft

Threatpost talks to Venafi about the recently-disclosed Microsoft vulnerability and whether the hype around the flaw was warranted. A major Microsoft crypto-spoofing bug impacting Windows 10 made waves this Patch Tuesday, particularly as the flaw was found and reported by the U.S. National Security Agency (NSA). Microsoft’s January Patch Tuesday security bulletin…
bubmag
January 15, 2020
Chain of Fools: What We Know So Far on Windows CryptoAPI Spoofing Vulnerability NSA

Chain of Fools: What We Know So Far on Windows CryptoAPI Spoofing Vulnerability

15 Jan 2020 on security | windows | cryptography On Monday this week, Brian Krebs broke a story that the NSA had discovered a critical flaw in Microsoft Windows software responsible for core security functions including, among other responsibilities, verifying the identity of other computers on local networks and the…
bubmag
January 15, 2020
Welcome to the 2020s: Booby-trapped Office files, NSA tipping off Windows code-signing bugs, RDP flaws… NSA

Welcome to the 2020s: Booby-trapped Office files, NSA tipping off Windows code-signing bugs, RDP flaws…

Patch Tuesday In the first Patch Tuesday of the year, Microsoft finds itself joined by Adobe, Intel, VMware, and SAP in dropping scheduled security updates. This month's Microsoft security fixes include three more remote-code-execution vulnerabilities in Red…
bubmag
January 14, 2020