Microsoft Patches Windows XP Again As Part of June Patch Tuesday
http://blog.trendmicro.com/trendlabs-security-intelligence/microsoft-patches-windows-xp-again-june-patch-tuesday/

Microsoft should seriously consider retiring Windows XP , Vista, 8.1 for good. It’s costing Microsoft more money and more human resources to baby sit these old Windows OS. Business owners, educational institution and etc should consider going to Windows 10. The institute that I go to they have already implemented Windows 10 in all of the computers and I am our neighboring country Australia has followed us. Why can’t other country follow the same thing and move to Windows 10.

This was hit just yesterday https://www.theguardian.com/technology/2017/jun/15/university-college-london-hit-by-ransomware-attack-hospitals-email-phishing

Changing to Windows 10 still doesn’t prevent the user for infecting the system.

Considerable Brute Force Attacks on Word Press CMS:

-https://www.wordfence.com/blog/2017/06/home-router-botnet-resumes-attacks/

Broke that link because of unsollicited adware for paid audit and subscription, if anyone wonders why I broke it.

polonus

Yes I agree but they will be much more safer and getting security updates from Microsoft and also it’s the most up to date Windows OS. They just need to apply common sense.

Samsung Magician fails to update itself securely (SSD’s)
http://www.kb.cert.org/vuls/id/846320

Windows 10 without creator’s update & device guard stays vulnerable to EternalBlue & EternalRomance NSA exploits as adapted for Win 10 by Shadow-Brokers’ to exploit your regular Windows 10.

Re: https://blogs.technet.microsoft.com/mmpc/2017/06/16/analysis-of-the-shadow-brokers-release-and-mitigation-with-windows-10-virtualization-based-security/

Why not run Windows 10 under linux in virtual box, and then have the best of both worlds, as we now should know that Windows (influenced by NSA etc.) can never really be trusted to be fully secure to specific end-users.

Patch and upgrade and you are and maybe feel more secure, but never fully secure in the surveillance state that we find ourselves to reside in to-day.

Propriety software, well you never know, what you are up against/

Open software is open and the code can be checked, so irresponsible big gubberment forces won’t sit silently on Zero-days for five years at a strechtch, before proliferation takes place through leaks and/or exploits are found up, and the hacks fall into the hands of cybercriminals.

polonus

Erebus Resurfaces as Linux Ransomware
http://blog.trendmicro.com/trendlabs-security-intelligence/erebus-resurfaces-as-linux-ransomware/

Microsoft admits it disables anti-virus software in response to Kaspersky’s EU complaint
https://www.theverge.com/2017/6/20/15836208/microsoft-kaspersky-eu-anti-virus-complaint-response

IMHO, better to disable something not compatible than allow it to run and crash the system.

Another chapter in Drupalgeddon: https://www.drupal.org/PSA-2014-003
Serious hole to be patched via an update.

CMS it can be a constant pain in the neck, sometimes. Drupal, Word Press etc.

polonus

First things learned by toddlers is to keep their hands out of the cookie-jar.

Part of education learnt with your first visit to a big department candy store.
Never forget that for the rest of your life, part of your Kinderstube education.

Now these mechanisms often fail for spoiled young folk even when they grow older.
What you put in is being turned out. Hey, Sparta, do you hear me?

Now that society educates and you’re not taught such things evidently by your parents or grandparents or whatever,
you get such news as this:

https://www.buzzfeed.com/jasonleopold/cia-vending-thefts?utm_term=.gpVkpnXNV#.qkmEbm69d

Nice to be protected by those from gubberment you cannot even trust as far as a candybar’s long :o

polonus

Bad news and a sure cause of more Win10 insecurity coming: https://www.theregister.co.uk/2017/06/23/windows_10_leak/

General issues with Microsoft Software according to GNU’s: https://www.gnu.org/proprietary/malware-microsoft.html

These are insecure days for Windows end-users.

polonus

TheRegister is completely wrong.
It wasn’t 32 Tb but only 1,2 Gb and a lot of the code never made it into the final build.

This is where the code was uploaded :
https://www.betaarchive.com/forum/viewtopic.php?t=37283

Hi Eddy,

If that should be otherwise, would not you be the first to debunk it as quickly as possible?
Some use this with a VM to feel a bit more comfy , see: https://www.youtube.com/watch?v=v-CzBkbISLQ

According to this source we can conclude then they are telling lies in commision:
https://arstechnica.com/information-technology/2017/06/32tb-of-windows-10-beta-builds-driver-source-code-leaked/

Since WannaCry I do not trust M$ very much security-wise, also due to NSA holding M$ sort of hostage.

Do not look at propriety code, those that do are excluded from work in the IT sector for a couple of years, because of the risks.
With open source however you are free to skim over the source, that is why it is open.

polonus

Just waiting for backdoors for strong encryption. Debate ongoing: https://www.attorneygeneral.gov.au/Mediareleases/Pages/2017/SecondQuarter/Tackling-Encryption-and-Border-Security-key-Priorities-at-Five-Eyes-Meeting-in-Ottawah.asp

Just a bit more of the common "t"and “p” arguments will do the job, and these forces will achieve what they are after, despite of the fact that knowledge of backdoors will proliferate to cybercriminals and will make everyone’s life a bit less secure also business competition (commercial spies - what businessman is taking his smartphone to the States for instance as it comes backdoored by design from Galaxy 4 onwards).

But this mechanism does not hamper those without technical knowledge how such things work, while those to decide are often not the ones ,that could do real technical risk-management to keep us all safe(r).

polonus

Insecurity coming, how you gonna flush dns when you have no command prompt nor Power Shell.
Shouldn’t this version be taken on hold, because it is too restrictive, and has also the known macro vulnerabilities there.

Re: https://arstechnica.com/information-technology/2017/06/microsoft-should-shore-up-windows-10-ss-security-then-offer-it-to-everyone/

polonus

All of a sudden today, Avast is giving me a warning that my webmail account for CenturyTel is not safe - phishing, I think it said. It continues to give me the warning even though I set it in the exceptions. Even when I try to do a reply. Of course, I override it but how can I get it to STOP?

BTW, The verification really sucks - I have enough vision problems as it is and have a super hard time reading the letters and the sound option doesn’t work at all.

  1. Start a new topic: https://forum.avast.com/index.php?action=post;board=4
  2. Only needed for your first 3 posts. (Spam protection)

Again a Windows Defender emulator hole found up with a fuzzer after porting Windows Defender onto linux.

Read here: https://twitter.com/taviso/status/878314575149506561
https://bugs.chromium.org/p/project-zero/issues/detail?id=1282&desc=2

Will Kaspersky’s start to moan again, while Tavis Ormandy makes that Windows Defender gets more secure all the time?

polonus