Tag Archive for: This

One of this year’s most severe Windows bugs is now under active exploit

Image of ones and zeros with the word

(credit: Pixabay)

One of the highest-impact Windows vulnerabilities patched this year is now under active exploitation by malicious hackers, Microsoft warned overnight, in a development that puts increasing pressure on laggards to update now.

CVE-2020-1472, as the vulnerability is tracked, allows hackers to instantly take control of the Active Directory, a Windows server resource that acts as an all-powerful gatekeeper for all machines connected to a network. Researchers have dubbed the vulnerability Zerologon, because it allows attackers with only minimal access to a vulnerable network to login to the Active Directory by sending a string of zeros in messages that use the Netlogon protocol.

Zerologon carries a critical severity rating from Microsoft as well as a maximum of 10 under the Common Vulnerability Scoring System. Despite the high rating, the escalation-of-privileges vulnerability received scant, if any, attention when Microsoft patched it in August, and Microsoft deemed the chances of actual exploitation “less likely.”

Read 9 remaining paragraphs | Comments

Biz & IT – Ars Technica

I’m not interested in this Nigerian restaurant’s emails…

I’m sure their food is lovely, but I don’t think they’re going to deliver to me in Oxford, England, are they? Or if they did I’d have to give the delivery driver a stonking tip.
Graham Cluley

This Week In Techdirt History: August 30th – September 5th

Five Years Ago

This week in 2015, the NSA was renewing its bulk records collection after a worrying and slightly suspicious court ruling. The FBI was somehow using Hurricane Katrina as an excuse to get more Stingray devices, just before the Wall Street Journal got a “win” (though the devil was in the details) in a lawsuit related to Stingray surveillance orders, and the DOJ told federal agents that they need warrants to use the devices. Meanwhile, the NYPD was volunteering to be copyright cops in Times Square, Sony was downplaying the damage done by the same hack it was hyping up before, and the entertainment industry was freaking out about Popcorn Time.

Ten Years Ago

This week in 2010, we were saddened to see the US Commerce Secretary siding with the RIAA and telling ISPs to become copyright cops, even as more ISPs were stepping up to fight subpoenas from the US Copyright Group (and in France, some ISPs were fighting back against Hadopi, which was also becoming a tool of scammers). One court refused to dismiss a Righthaven lawsuit involving a copyright that was bought after the alleged infringement happened, while another court was seeking ways to minimize a Righthaven win with minuscule damages — and the LVRJ was defending the Righthaven suits and mocking a competitor for criticizing them.

Fifteen Years Ago

This week in 2005, we were pleased to see that the judge in one of the first instances of someone fighting back against RIAA lawsuits seemed to recognize the issues, and less pleased to see another court give its assent to yet another form of DMCA abuse. It wasn’t as crazy as what was happening in India, though, where it appeared that their equivalent of the MPAA got an open search warrant for the entire city of New Delhi to look for pirated movies. And even that didn’t match the panic over mobile porn that was gripping parts of the world, leading to things like Malaysian police performing random porn spot-checks on people’s phones.

Techdirt.