Another Windows protocol vulnerability emerges; this time it is a Windows Search zero-day
Following on from the Follina security flaw, another Windows zero-day vulnerability has come to light. Dubbed SearchNightmare, the issue allows the search-ms URI protocol handler to be used to launch remotely hosted malware-ridden executables via a search window.
The protocol is normally used to perform local searches, but it can also be used to do the same with shared files on a remote host. An attacker could easily trick a victim into clicking a search-ms URI, and a method has been found to bypass the security warning that should be displayed by default.
0patch releases free fix for Follina vulnerability in Windows as Microsoft apparently can't be bothered
This week, we have written about the Follina zero-day vulnerability that allows for remote code execution on a victim's computer. Despite having been known about for a number of weeks, Microsoft is still yet to issue a patch for the actively exploited critical security flaw, instead simply offering details of a workaround.
As has been the case in the past, a third party has come to the rescue. Micro-patching firm 0patch has released a free fix for the vulnerability -- for Windows 11, Windows 10, Windows 7 and Windows Server 2008 R2 -- which is tracked as CVE-2022-30190 and relates to the Microsoft Windows Support Diagnostic Tool (MSDT) component of Windows.
Top 5 issues IT departments face in 2022 and how IT pros can face these challenges
Over the past two years, IT departments have faced numerous unprecedented challenges. The rapid shift to remote work is chief among them.
However, as we progress through 2022, employees are no longer working from just their homes; they are working from everywhere. Hybrid work is becoming the norm, and with that comes significant challenges for IT Managers and departments.
Microsoft's new Surface Laptop Go 2 is available to pre-order today from $599
Just yesterday, we reported that Microsoft was readying a new Surface Laptop Go, with many of the specs revealed early on a Korean website.
We said that Microsoft was planning to announce the new device "in the coming weeks", but it turns out we don't have to wait anywhere near that long as the software giant today introduces the new Surface Laptop Go 2, with a starting price of $599.
Poor alerts hamper effective automation of threat detection
According to a new report 85 percent of IT security professionals have experienced preventable business impacts resulting from insufficient response procedures, while 97 percent say that more accurate alerting would increase their confidence in automating threat response actions.
The State of the Modern SOC report from Deepwatch is based on a survey by Dimensional Research of over 300 security professionals, working at US organizations with 1,000 or more employees.
APIs and cloud apps are greatest threats to enterprise security readiness
A survey of over 400 CISOs finds they are are grappling with a wide range of risks and challenges, especially linked to accelerating utilization of technologies like cloud-based applications and the use of Application Programming Interfaces (APIs).
The study from CISOs Connect, an invitation-only community of cyber experts and part of Security Current, finds the IT components rated as most needing improvement are: APIs (42 percent), cloud applications (SaaS) (41 percent), and cloud infrastructure (IaaS) (38 percent).
Almost half of IT security leaders believe they won't be breached
A new study shows 47 percent of security leaders do not believe they will be breached despite the increasing sophistication and frequency of attacks.
The survey of 1,000 IT and security professionals across eight countries, conducted by The Enterprise Strategy Group for Illumio finds in the past two years alone 76 percent have been attacked by ransomware and 66 percent have experienced at least one software supply chain attack.
Plugable UD-3900C4 USB-C docking station can push four displays
USB-C docking stations are pretty common these days. In fact, websites like Amazon are littered with countless makes and models. Of course, not all of them are good, nor are they all the same. Features can vary from dock to dock, such as the number of USB ports or video outputs.
Speaking of video output, most USB-C docks have either one or two such ports. Today, however, Plugable launches a docking station with four HDMI ports, and yes, they can all be used simultaneously for a quad-monitor configuration. But despite having so many video outputs, it doesn't skimp on other useful ports, including an SD card reader!
Get 'Windows 10 All-in-One For Dummies, 4th Edition' ($39.99 value) FREE for a limited time
Computer users have been "doing Windows" since the 1980s. That long run doesn’t mean everyone knows the best-kept secrets of the globally ubiquitous operating system. Windows 10 All-in-One For Dummies, 4th Edition offers a deep guide for navigating the basics of Windows 10 and diving into more advanced features.
Authors and recognized Windows experts Ciprian Rusen and Woody Leonhard deliver a comprehensive and practical resource that provides the knowledge you need to operate Windows 10, along with a few shortcuts to make using a computer feel less like work.
Microsoft Entra is a new identity and access-focused family of products
Microsoft has launched a new family of products called Entra. Microsoft Entra encompasses a number of identity and access management solutions including the existing Azure AD. The launch comes after the acquisition of CloudKnox Security last year, and is Microsoft's attempt to help boost security across multicloud environments -- or "secure access for a connected world".
Bolstering the product family, the company has also launched cloud permission management tool Microsoft Entra Permissions Management, and Microsoft Entra Verified ID -- a system that allows for more secure interactions, based on decentralized identity standards. Microsoft has also announced public previews of Workload Identities and Lifecycle Workflows.
How artificial intelligence and machine learning are changing the development landscape [Q&A]
It's an increasingly rare application these days that doesn’t claim to incorporate some form of artificial intelligence or machine learning capability.
But while this may be great from a marketing standpoint it does pose a challenge for developers. We spoke to Luis Ceze, CEO and co-founder of OctoML, to find out more.
It may not be long before you can edit WhatsApp messages
The ability to edit sent messages is something that is common -- although far from universal -- in chat and social apps. The likes of Slack and Skype make it easy to make changes, such as correcting typos in messages, and it is an option that is said to be coming to Twitter at some point in the future.
But while the option to edit tweets may be some way off, users of WhatsApp may have this option sooner rather than later. The developers of WhatsApp are currently working on bringing a message-editing option to the mobile versions of the apps, as well as the desktop and web editions.
Why has Microsoft still not fixed a weeks-old, actively exploited vulnerability affecting Windows 11 and more?
Yesterday we wrote about a zero-day vulnerability called Follina which allows for remote code execution on a victim's computer. While the flow -- tracked as CVE-2022-30190 -- has been described as an Office vulnerability, it is really the result of a security issue with a component of Windows.
A problem exists in the Microsoft Windows Support Diagnostic Tool (MSDT) which is found in all supported versions of Windows, including Windows 11. The vulnerability has been billed as an Office vulnerability as using a malicious Word file is one of the easiest attack vectors to exploit the flaw. But what is worrying about the vulnerability, apart from the fact that Microsoft has not fixed it yet, is that the company was made aware of the fact that it was being actively exploited way back on April 12.
Logitech shows off newest Design Collection of wireless mice
Every year, often in June, Logitech launches its latest Design Collection of wireless mice. These are small portable mice that are intended for laptops, but they can be used with any computer that has a USB-A port. Yes, these use a USB dongle rather than Bluetooth. They also don't have any thumb buttons and they do not have rechargeable batteries.
If you think these mice sound pretty basic, you'd be correct. So what makes them exciting? Ah, good question. This mouse collection is notable for featuring funky designs. Basically, Logitech's Design Collection is intended to be fun and whimsical with unique patterns and wacky colors. This year, the Design Collection seems largely focused on plants and flowers (you can see them above).
Say goodbye to Microsoft Windows 11 and wave hello to Ubuntu-based Linux Lite 6.0
Is Windows 11 a good desktop operating system. Absolutely. Is it the best desktop operating system? Well, that is harder to answer. Ultimately, if you are 100 percent dependent on Windows software, then yes, Windows 11 is the best operating system... for you. If you can get by without using software designed for Microsoft's OS, however, a Linux-based operating system might be the better option -- especially if you have an older computer.
You see, Windows 11 is very polarizing. The operating system features radical changes to the user interface (such as a centered task bar) which some users do like, but many others do not. Not to mention, the system requirements will leave many still-capable computers unable to upgrade without using unofficial hacks. Even worse, computers deemed incompatible could eventually stop getting updates! Linux doesn't have these problems.
Most Commented Stories
© 1998-2024 BetaNews, Inc. All Rights Reserved. Privacy Policy - Cookie Policy.