Posts

Microsoft fixes issue with outdated driver blocklist for Windows 10

Microsoft has fixed the problem with the driver blocklist for Windows 10 after it was previously known that it had not been automatically updated on systems for three years . Several attacks have been observed in the past year where attackers install a vulnerable driver on the attacked system. The vulnerability in the driver allows attackers to further increase their rights and, for example, disable security software. The technique is called Bring Your Own Driver or Bring Your Own Vulnerable Driver. To protect Windows computers from vulnerable drivers, Windows 10, 11 and Server 2016 and newer have a blocklist that is updated via Windows Update. The list includes vulnerable drivers that Windows will not load. However, the automatic list update on Windows 10 hasn't happened for three years, security researcher Will Dormann discovered. More than a month since Dormann's Twitter call, Microsoft has now released an update that fixes the issue for Windows 10 machines with Hypervisor...

Microsoft detects USB worm on computers of about a thousand companies

Apple actively fixes attacked zero day leak also in older iPhones and iPads

Google actively resolves zero-day attacks in Chrome for seventh time this year

Tor Project releases emergency update for Tor Browser due to connectivity issue

October - Security Awareness month: USB-attacks

NAS Devices to Remotely Take Over Synology Through Critical Vulnerabilities

Tor Project demands end-to-end encryption for private messages on all platforms

FBI warns hospitals against ransomware attacks via VPN servers

October - Security Awareness month: Harddisk encryption

Microsoft claims ransomware uses Avast driver to disable antivirus

Microsoft leaks customer data via misconfigured server

Firefox for Android will support many more extensions