Security researchers have publicly revealed a newly discovered critical vulnerability that affects all Windows Workstation and Server versions, from Windows 7 and Server 2008 R2 to the latest Windows 11 (v24H2) and Server 2022. The flaw allows attackers to obtain a user’s NTLM credentials simply by tricking them into viewing a malicious file in Windows Explorer. This action could be triggered by opening a shared folder or USB disk containing such a file, or by accessing the Downloads folder where the malicious file might have been automatically downloaded from an attacker’s webpage. After responsibly reporting the issue to Microsoft, the researchers have released micropatches to protect users until they provide an official fix. These micropatches are available free of charge during this interim period. #Microsoft #micropatching #security
Eric Stylemans’ Post
More Relevant Posts
-
The new Windows flaw affects Windows Servers 2008 to 2022 and Windows 10 and 11. Attack allows bad actors downgrading security measures to a weaker counterpart and by intercepting credentials they can forward it to another service and gain access there. More details in the article. #windows #vulnerability #security https://lnkd.in/eCP4i377
Exploit released for new Windows Server "WinReg" NTLM Relay attack
bleepingcomputer.com
To view or add a comment, sign in
-
#Microsoft Update Warning—70% Of All Windows Users Now At Risk!!! Not upgrading to Windows 11, unless you use a solution like IGEL Technology, puts your organization at a security risk. For example: If there was any doubt as to the real danger in leaving Windows unprotected, then Monday’s US government warning should quickly change minds. A 2018 Windows vulnerability has been added to its Exploited Vulnerability (KEV) catalog. “Microsoft COM for Windows,” CISA warns, “contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution.” Users have been given until August 26 to patch or cease using Windows systems. Clearly, this 2018 vulnerability does not impact Windows 11, nor any other Windows system updated in the last six years. The Windows 10 risk, though, is real. 👉Please contact me to discuss your options for Windows 11 upgrades or alternatives like #IGEL. XenTegra is your preferred IT partner. #XenTegraNC #XenTegra #Windows #Windows10 #Windows11 #ITSecurity https://lnkd.in/eCDVuYM9
Microsoft Update Warning—70% Of All Windows Users Now At Risk
social-www.forbes.com
To view or add a comment, sign in
-
🚨 New Windows Theme Zero-Day Vulnerability (No Patch Yet) 🚨 A new 0-day vulnerability has been identified, impacting all Windows clients from Windows 7 to Windows 11. Microsoft’s recent patch (CVE-2024-38030) aimed to resolve it, but researchers discovered it still leaves systems partially exposed. 🔒 In response, 0patch has released free micropatches to secure affected versions, covering even older Windows clients still widely used. 🔗 More information here: https://lnkd.in/eDqWNVKW #Cybersecurity #Windows #ZeroDay #Security #InfoSec #Vulnerability
New Windows Theme Zero-Day Vulnerability Let Attackers Steal Credentials
https://cybersecuritynews.com
To view or add a comment, sign in
-
"End of support for Windows 10 arrives on October 14, 2025" Linux users you can move on with your day, this post is not relevant to you ;) Microsoft has announced that it will end support for #Windows 10 on October 14, 2025. After this date, #Windows 10 will no longer receive security updates, bug fixes, or technical support from #Microsoft. This means that users and organizations will need to consider #upgrading to a newer version of Windows, such as Windows 11, to ensure they continue to receive updates and support. #OPSEC #CyberSecurity #cisco #Malware #update #innovation #linux https://lnkd.in/dMfyn2yx
Microsoft Update Warning—70% Of All Windows Users Now At Risk
social-www.forbes.com
To view or add a comment, sign in
-
Did you know your Windows 11 account already comes equipped with password protection? 🔐 So, when you log in, you're essentially locking down access to your profile and all the files within it. Microsoft makes the assumption that you, and you alone, are the only person accessing your Windows account. If you're using the BitLocker security feature, your data gets an added layer of encryption, making it even tougher for unauthorised people to sneak a peek at your files. But what if you share your PC with others, or you simply want that extra level of security? Enter the virtual hard disk and BitLocker combo. Basically, it’s a secure folder within your computer, accessible only to those with the password. There's always a workaround to beef up your file security. Of course there are better ways to increase security and protect files within a business - can our team help you with that? #Windows11 #FileSecurity #FolderPassword https://hubs.ly/Q02vk4H00
How to protect folder with password on Windows 11
windowscentral.com
To view or add a comment, sign in
-
Beware Fake Windows 11 Offers! [#CyberSecurity #TechNews] 🚨 Key Risks of Illegal Windows 11: - High risk of malware and data loss. - Violates Microsoft’s terms of service. - Lacks official Windows 11 features and updates. This imitation poses serious security hazards and misses out on critical enhancements. Always opt for legitimate software sources to ensure your digital safety and compliance! 🔒 Are you tempted by software that promises fewer pre-installs at the risk of security? #Microsoft #Windows11 #SoftwarePiracy #DataProtection #Malware Read the full article here: https://lnkd.in/gjwyn3Xh
Don't fall for the no-bloat 'government' version of Windows 11
pcworld.com
To view or add a comment, sign in
-
Microsoft is now using a Windows driver to prevent users from changing the configured Windows 10 and Windows 11 default browser through software or by manually modifying the Registry. https://lnkd.in/dp5aFjKr #cybersecurity #ciberseguridad
New Windows driver blocks software from changing default web browser
bleepingcomputer.com
To view or add a comment, sign in
-
https://lnkd.in/gJFtC5pi The list of deprecated features in Windows is quite extensive and worth a read, but the deprecation of NTLM isn't as straightforward as it may seem when it comes to security. My 2 cents: 1. NTLM is no longer under active feature development. This may mean it receives less attention from security updates if (when?) additional vulnerabilities are discovered. 2. NTLM is now disabled by default, which means applications that call directly into NTLM will fail (need to call into SPNEGO SSPI instead). 3. Despite being deprecated, NTLM is *still* in the product. 4. NTLM still serves as a fallback alongside SPNEGO which is the design of SPNEGO. This introduces the risk of attackers (potentially) forcing a downgrade to NTLM from SPNEGO, exploiting any existing NTLM vulnerabilities (which is not getting product development attention). ... reminiscing on the good ol' days in Windows Authentication.. #WindowsSecurity #NTLM #SPNEGO
Deprecated features in the Windows client - What's new in Windows
learn.microsoft.com
To view or add a comment, sign in
-
Windows 11 has lots of new security capabilities, from chip-based security to layers of application and data security. Read this @Microsoft article to learn why @Windows 11 is the most secure Windows ever.
New security features in Windows 11 protect users and empower IT
https://www.microsoft.com/en-us/security/blog
To view or add a comment, sign in