Tag: windows
-
Windows 10 Supportende: BSI rät zum Wechsel des Betriebssystems
Wer noch immer Windows 10 im Einsatz hat, sollte nach Einschätzung des BSI zeitnah tätig werden und sich mit einem anderen Betriebssystem anfreunden. First seen on golem.de Jump to article: www.golem.de/news/windows-10-supportende-bsi-raet-zum-wechsel-des-betriebssystems-2504-195360.html
-
Don’t delete that mystery empty folder. Windows put it there as a security fix
Tags: windowsCopilot vibe coding for OS development? Why not First seen on theregister.com Jump to article: www.theregister.com/2025/04/14/windows_update_inetpub/
-
BSI warnt Windows-10-Nutzer: Warum ihr schon jetzt auf ein anderes Betriebssystem umsteigen solltet
First seen on t3n.de Jump to article: t3n.de/news/bsi-warnt-windows-10-nutzer-schon-jetzt-anderes-betriebssystem-umsteigen-1682949/
-
Microsoft tells Windows users to ignore 0x80070643 WinRE errors
Microsoft says some users might see 0x80070643 installation failures when trying to deploy the April 2025 Windows Recovery Environment (WinRE) updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-tells-windows-users-to-ignore-winre-install-errors/
-
New Windows updates fix Active Directory policy issues
Microsoft has released emergency Windows updates to address a known issue affecting local audit logon policies in Active Directory Group Policy. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-new-emergency-windows-updates-fix-ad-policy-issues/
-
New emergency Windows updates fix AD policy issues
Microsoft has released emergency Windows updates to address a known issue affecting local audit logon policies in Active Directory Group Policy. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-new-emergency-windows-updates-fix-ad-policy-issues/
-
âš¡ Weekly Recap: Windows 0-Day, VPN Exploits, Weaponized AI, Hijacked Antivirus and More
Attackers aren’t waiting for patches anymore, they are breaking in before defenses are ready. Trusted security tools are being hijacked to deliver malware. Even after a breach is detected and patched, some attackers stay hidden.This week’s events show a hard truth: it’s not enough to react after an attack. You have to assume that any…
-
Windows Server 2025 restarts break connectivity on some DCs
Microsoft warned IT admins that some Windows Server 2025 domain controllers might become inaccessible after a restart, causing apps and services to fail or remain unreachable. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-restarts-break-services-on-domain-controllers/
-
0x80070643 ist zurück: Windows 10 wirft erneut Fehler für WinRE-Update
Im letzten Jahr wurden viele Windows-Nutzer monatelang vom Fehlercode 0x80070643 geplagt. Seit dem April-Patchday tritt der Fehler erneut auf. First seen on golem.de Jump to article: www.golem.de/news/0x80070643-ist-zurueck-windows-10-wirft-erneut-fehler-fuer-winre-update-2504-195321.html
-
Windows 10 und 11: Mysterium um inetpub-Ordner teilweise aufgelöst
Nach dem April-Patchday ist auf vielen Windows-Systemen unerwartet ein Ordner namens inetpub aufgetaucht. Microsoft warnt davor, diesen zu löschen. First seen on golem.de Jump to article: www.golem.de/news/windows-10-und-11-mysterium-um-inetpub-ordner-teilweise-aufgeloest-2504-195313.html
-
Windows 10: BSI empfiehlt Upgrade oder Wechsel des Betriebssystems nach Support-Ende
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/windows-10-bsi-empfehlung-upgrade-wechsel-betriebssystem-support-ende
-
HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments
Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty ransomware, signaling its resurgence with attacks targeting Windows, Linux, and ESXi environments. HelloKitty ransomware, initially appearing in October 2020 as a fork of DeathRansom, has evolved significantly in its encryption methods. The ransomware now embeds an RSA-2048 public key, which is…
-
Microsoft Enhances Exchange and SharePoint Security with AMSI Integration
Microsoft has announced enhanced security measures for its Exchange Server and SharePoint Server products, both of which are critical assets for many organizations. The core of this enhancement is the integration with the Windows Antimalware Scan Interface (AMSI). The blog post emphasizes that Exchange and SharePoint servers are prime targets for attackers due to the…
-
Russian Shuckworm APT is back with updated GammaSteel malware
files.lnk, launched from an external drive. This was recorded under the UserAssist key in the Registry, which stores a record of files, links, applications, and objects accessed by the current user through Windows Explorer.After that file was executed, it launched mshta.exe, a Windows binary that can be used to execute VBScript and JScript locally on…
-
SonicWall Patches Multiple Vulnerabilities in NetExtender Windows Client
SonicWall has issued a critical alert concerning multiple vulnerabilities discovered in its NetExtender Windows client. These vulnerabilities, identified via several Common Vulnerabilities and Exposures (CVEs), could allow malicious actors to exploit privilege management flaws, trigger local privilege escalation, or manipulate file paths. Users are urged to update their software immediately to mitigate potential risks. Overview…
-
Ransomware-Attacken stoßen in Windows-Lücke
Tags: access, backdoor, bug, cve, cvss, cyberattack, exploit, kaspersky, malware, microsoft, ransomware, update, vulnerability, windowsCyberkriminelle missbrauchen eine Sicherheitslücke in Windows, um eine Backdoor-Malware und Ransomware einzuschleusen.Sicherheitsforscher von Microsoft haben eine Schwachstelle im CLFS-Treiber (Common Log File System) von Windows entdeckt, die Angreifern Systemrechte verleiht. Sie wird als CVE-2025-29824 geführt, die mit einem CVSS-Wert von 7,8 über einen hohen Schweregrad verfügt.Laut einem Blogbeitrag der Forscher wurde die Lücke bereits für…
-
Cyberkriminelle setzen weiterhin auf ClickFix als bewährte Methode
Über ein gefälschtes Sicherheitsfenster wird der Nutzer dazu verleitet, eine bestimmte Tastenkombination auszuführen. Diese öffnet das Windows-Tool ‘Ausführen”, über das ein schädlicher Befehl eingeschleust und direkt ausgeführt wird. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cyberkriminelle-setzen-weiterhin-auf-clickfix-als-bewaehrte-methode/a40458/
-
Top 16 OffSec, pen-testing, and ethical hacking certifications
Tags: access, android, antivirus, application-security, attack, authentication, blockchain, bug-bounty, business, cisco, cloud, computing, credentials, crypto, cryptography, cyber, cybersecurity, data, defense, detection, encryption, exploit, guide, hacker, hacking, incident response, injection, iot, jobs, kali, linux, malware, microsoft, mitigation, mobile, network, penetration-testing, RedTeam, remote-code-execution, reverse-engineering, risk, risk-assessment, sap, skills, sql, technology, threat, tool, training, update, vulnerability, windowsExperiential learning Offensive security can’t be fully mastered through lectures alone. Candidates need hands-on training in lab environments to develop practical skills. Ideally, certification exams should include a practical assessment, such as developing an exploit to compromise a system.Because individuals learn OffSec techniques, such as penetration testing, in different ways, the most effective certifications offer…
-
Nach Patchday: Mysteriöser Ordner erscheint unerwartet unter Windows
Nach der Installation der jüngsten Updates taucht unter Windows 10 und 11 unerwartet ein neuer Ordner auf. Der Grund dafür ist noch unklar. First seen on golem.de Jump to article: www.golem.de/news/nach-patchday-mysterioeser-ordner-erscheint-unerwartet-unter-windows-2504-195207.html
-
Microsoft Patches 125 Flaws Including Actively Exploited Windows CLFS Vulnerability
Microsoft has released security fixes to address a massive set of 125 flaws affecting its software products, including one vulnerability that it said has been actively exploited in the wild.Of the 125 vulnerabilities, 11 are rated Critical, 112 are rated Important, and two are rated Low in severity. Forty-nine of these vulnerabilities are classified as…
-
Per Pin oder Gesicht: April-Update macht Log-in mit Windows Hello kaputt
Einige Nutzer, die sich unter Windows 11 oder Windows Server 2025 per Pin oder Gesichtsscan anmelden wollen, stoßen neuerdings auf Fehler. First seen on golem.de Jump to article: www.golem.de/news/per-pin-oder-gesicht-april-update-macht-log-in-mit-windows-hello-kaputt-2504-195205.html
-
Windows 10/11: Alle Updates für Windows vom April 2025-Patchday verfügbar
Zum Patchday im April 2025 (8. April 2025) waren nicht alle Windows-Sicherheitsupdates fertig gestellt. So fehlte das Update für Windows 10 (RTM-Version, Version 1507) komplett. Microsoft hat dieses Update nun nachgereicht und dazu auch gleich einen eigenen Supportbeitrag veröffentlicht. Windows … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/04/10/windows-10-11-alle-updates-fuer-windows-vom-april-2025-patchday-verfuegbar/
-
Windows 11 24H2/Server 2025: Hello-Login geht nach April 2025-Updates nicht mehr
Der Patchday zum 8. April 2025 hat einige Kollateralschäden bei Outlook, Excel und Word 2016 verursacht. Einige Windows-Nutzer klagen zudem, dass die Anmeldung über Windows Hello nicht mehr funktioniert, nachdem sie die Updates vom 8. April 2025 unter Windows 11 … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/04/10/windows-11-24h2-server-2025-hello-login-geht-nach-april-2025-updates-nicht-mehr/
-
April’s Patch Tuesday leaves unlucky Windows Hello users unable to login
Can’t Redmond ask its whizz-bang Copilot AI to fix it? First seen on theregister.com Jump to article: www.theregister.com/2025/04/09/microsoft_hello_patch/
-
Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day
One CVE was used against “a small number of targets.” Windows 10 users needed to wait a little bit for their patches. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-patch-tuesday-april-2025/
-
Windows 11 tests sharing apps screen and files with Copilot AI
Copilot on Windows 11 is testing OS-level integration that would allow you to share your favourite apps’ screen with Copilot. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-tests-sharing-apps-screen-and-files-with-copilot-ai/
-
Flaws in Google Quick Share for Windows addressed via patch
First seen on scworld.com Jump to article: www.scworld.com/brief/flaws-in-google-quick-share-for-windows-addressed-via-patch
-
New Russia-linked cyberespionage campaign abuses Windows RDP
First seen on scworld.com Jump to article: www.scworld.com/brief/new-russia-linked-cyberespionage-campaign-abuses-windows-rdp
-
Addressed Windows CLFS zero-day exploited in ransomware intrusions
First seen on scworld.com Jump to article: www.scworld.com/brief/addressed-windows-clfs-zero-day-exploited-in-ransomware-intrusions
-
Microsoft Warns Ransomware Actors Exploiting Windows Flaw
Tech Giant Says Threat Actors Are Exploiting a Flaw in Widely-Targeted Windows Tool. Ransomware threat actors are exploiting a zero-day vulnerability discovered in a highly targeted Windows logging system tool in a campaign in part targeting U.S. IT and real estate sectors, Microsoft confirmed in a Tuesday blog post urging customers to apply available patches.…

