Microsoft Disasters and Abuses
-
29 years ago, Microsoft thought of bundling Internet Explorer with Windows
Although Internet Explorer is now dead and has been succeeded by Microsoft Edge — which is based on Chromium and doesn’t really command a huge marketshare...
-
Microsoft might be saving your Bing Chat conversations
Uh-oh — Microsoft might be storing information from your Bing chats.
-
PowerShell? More like PowerHell: Microsoft won't fix flaws in package gallery ripe for supply chain attacks
Yet despite the IT goliath apparently confirming the existence of the flaws - and telling the Aqua team twice that fixes were in place and the issues had been resolved - as of today the bugs are still reproducible, it's claimed. The Aqua trio say they've made a proof-of-concept exploit for two of the three security issues.
The Windows giant did not immediately respond to The Register's inquiries, and we will update this story if or when we hear back.
-
Microsoft fails to fix major PowerShell Gallery security flaws even after claiming it did
AquaSec explains in its report that there are three major flaws in PSGallery, centered around deception and forgery.
-
Windows TCO
-
Clorox cleans up IT security breach that soaked its biz ops
The intrusion continues to disrupt "parts of the company's business operations," and it is "working diligently to respond to and address this issue, and is also coordinating with law enforcement," according to the Form 8-K submission.
The manufacturer has also hired third-party cybersecurity firms to help probe the mess and aid in the IT scrubbing efforts.
-
Bank Accidentally Lets People Withdraw Money From ATMs Even If They Don’t Have Any
The bank also warned customers that any withdrawals made during the time of the glitch would later be posted to their accounts.
-
Free Cash in Ireland, at Least for a Moment, Thanks to a Bank Glitch
Aside from the withdrawal glitch, customers said that the outage was especially frustrating given that the bank charged monthly fees to maintain the account — €6 for a personal use account — and called for a reimbursement.
-
Rapid7 Says ROI for Ransomware Remains High; Zero-Day Usage Expands
The review is compiled from the observations of Rapid7’s researchers and its managed services teams. It finds there were more than 1500 ransomware victims worldwide in H1 2023. These included 526 LockBit victims, 212 Alphv/BlackCat victims, 178 ClOp victims, and 133 BianLian victims. The figures are compiled from leak site communications, public disclosures, and Rapid7 incident response data.
These figures should be seen as conservative. [...]
-
Cuba Ransomware Deploys New Tools: Targets Critical Infrastructure Sector in the U.S. and IT Integrator in Latin America
Cuba ransomware is currently into the fourth year of its operation and shows no sign of slowing down. In the first half of 2023 alone, the operators behind Cuba ransomware were the perpetrators of several high-profile attacks across disparate industries.
-