Security Leftovers
-
Ethical Hacking Insights from HackerOne Report
Today’s ethical hackers are motivated by the desire to learn, to earn money, and to protect and defend, according to HackerOne’s 2022 Hacker-Powered Security Report. In fact, 92 percent of hackers say they can find vulnerabilities that scanners can’t, the report says.
-
The trials and tribulations of Microsoft’s KB5012170 patch [Ed: 'Secure' boot is the opposite of security]
KB5012170 is many things to many Windows users. First, it’s a patch that either installs with no problems or leads to a blue screen of death (BSOD). It can also be an indicator we have a problem getting updated drivers on our systems. It can demonstrate how users don’t keep up with Bios updates. And it shows that some OEMs enable Bitlocker on the systems they sell (not necessarily in a good way).
In short, it’s a problematic patch that just keeps rearing its head.
Also known as “Security Update for Secure Boot DBX,” KB5012170 was released earlier this year and makes improvements to the Secure Boot Forbidden Signature Database (DBX). Windows devices that have Unified Extensible Firmware Interface (UEFI)-based firmware have Secure Boot enabled. It ensures only trusted software can be loaded and executed on during the boot process by using cryptographic signatures to verify the integrity of the process and the software being loaded.
-
Microsoft: KB5021233 causes blue screens with 0xc000021a errors
Microsoft is investigating a known issue leading to Blue Screen of Death (BSOD) crashes with 0xc000021a errors after installing the Windows 10 KB5021233 cumulative update released during this month's Patch Tuesday.
The company warned over the weekend that "after installing KB5021233, some Windows devices might start up to an error (0xc000021a) with a blue screen."
This known issue is likely caused by a mismatch between the file versions of hidparse.sys in system32 and system32/drivers in the Windows folder, "which might cause signature validation to fail when cleanup occurs."
The list of affected platforms includes only client Windows 10 versions, from Windows 10 20H2 to the latest release, Windows 10 22H2.