Avast - 2022 Predictions

https://d1ka0itfguscri.cloudfront.net/Lh/2021/12/14/17/05/crl2bhV2aWJ/preview.jpg

[b]https://youtu.be/Z9XJjAbbFHQ[/b]
Avast’s prediction of what the 2022 Cyber security landscape will look like.
Thanks to Grace Macej for her excellent information on this topic.
https://blog.avast.com/author/grace-macej

In Case you’d like predictions and opinions on next years
cyber security landscape from a variety of experts in the field.
https://blog.emsisoft.com/en/39386/cyber-security-predictions-for-2022-what-the-experts-expect/

If you’re using Gmail and other online service,
be extremely careful.
The SPAM filter isn’t working as well as it used to
My inbox has seen way to many emails that are spam
Here’s just one sample I just received.

https://d1ka0itfguscri.cloudfront.net/Lh/2021/12/15/17/17/crlobbV2g4b/preview.jpg

Read the headers. If you aren’t exping an email, trash it.
Even better, put it in the spam folder where it belongs.

12-16-2021 GOOGLE DRIVE WILL BEGIN INFORMING ITS USERS
OF CONTENT VIOLATIONS VIA EMAIL

https://d1ka0itfguscri.cloudfront.net/Lh/2021/12/16/19/41/crlDqpV25Q2/preview.jpg

[b]https://youtu.be/QusvmKD0afY[/b]
Here is my take on Google’s newest information release about files stored on Google Drive.
Thanks to ChromeUnboxed for their excellent article on this topic.
https://chromeunboxed.com/google-drive-violation-notice/

Interesting - whilst I have never used Google Drive and have no intention of doing so.
In order for Google to identify content violations they must have analytic access to your files. So the question is do you trust Google not to somehow benefit from rummaging through your data ?

No more or less than any other online storage service.
To protect the corporation, they actually need to do this to weed out the stuff that can get Google (Alphabet into hot water.)

Which is just one reason why I don’t use any on-line storage medium, I also haven’t any social networking accounts.

Lenovo laptops vulnerable to bug allowing admin privileges
https://www.bleepingcomputer.com/news/security/lenovo-laptops-vulnerable-to-bug-allowing-admin-privileges/
https://research.nccgroup.com/2021/12/15/technical-advisory-lenovo-imcontroller-local-privilege-escalation-cve-2021-3922-cve-2021-3969/

Lenovo again, can anyone remember a long time again when Lenovo products had a chip that had been hacked, a bug in it that could deliver malware ?

Weekly Security News Roundup w/e 12-17-2021

https://d1ka0itfguscri.cloudfront.net/Lh/2021/12/17/20/02/crlbYnV2mcS/preview.jpg

[b]https://youtu.be/AKUHgwwPi3I[/b]
Security-related news thanks mostly to Avast Software. I’m just a messenger.
They do most of the challenging work and research. https://www.avast.com/en-us/index#pc

All Log4j, logback bugs we know so far and why you MUST ditch 2.15
https://www.bleepingcomputer.com/news/security/all-log4j-logback-bugs-we-know-so-far-and-why-you-must-ditch-215/

Upgraded to log4j 2.16? Surprise, there’s a 2.17 fixing DoS
https://www.bleepingcomputer.com/news/security/upgraded-to-log4j-216-surprise-theres-a-217-fixing-dos/

Tackling the real big Log4Shell insecurity.

Re: https://snyk.io/blog/log4shell-remediation-cheat-sheet/

polonus

Microsoft warns of easy Windows domain takeover via Active Directory bugs
https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/

New Dell BIOS updates cause laptops and desktops not to boot
https://www.bleepingcomputer.com/news/technology/new-dell-bios-updates-cause-laptops-and-desktops-not-to-boot/

In trouble again. AWS Amazon now down for the third time this month.
See: https://downdetector.com/status/amazon/ & https://istheservicedown.com/problems/amazon
Re: https://www.tellerreport.com/tech/2021-12-22-amazon-is-experiencing-outage-for-the-third-time-in-a-short-time.ryxq23loF.html

polonus

It’s that time of year.
Be careful even spam blockers are having problems.
I received this in my in-box this morning.

https://d1ka0itfguscri.cloudfront.net/Lh/2021/12/22/18/19/crl3FqV2NA3/preview.jpg

NVIDIA discloses applications impacted by Log4j vulnerability
https://www.bleepingcomputer.com/news/security/nvidia-discloses-applications-impacted-by-log4j-vulnerability/

Weekly Security News Roundup w/e 12-24-2021

https://d1ka0itfguscri.cloudfront.net/Lh/2021/12/26/16/08/crlODjV2RSy/preview.jpg

[b]https://youtu.be/Y1OiQQrQg_E[/b]
Security-related news thanks mostly to Avast Software. I’m just a messenger.
They do most of the challenging work and research. https://www.avast.com/en-us/index#pc

Log4j 2.17.1 out now, fixes new remote code execution bug
https://www.bleepingcomputer.com/news/security/log4j-2171-out-now-fixes-new-remote-code-execution-bug/
https://checkmarx.com/blog/cve-2021-44832-apache-log4j-2-17-0-arbitrary-code-execution-via-jdbcappender-datasource-element/