CISA is the US government’s Cybersecurity and Infrastructure Security Agency and a very good source cyber security and software patching information. Last week they posted several software patching updates and known vulnerabilities that are being exploited and mitigations for them. Samba Releases Security Updates for Multiple Versions of Samba | …
Snipping tool data leak fixed
Here is a follow-up to last week’s Microsoft Snipping Tool story about potential data leaks after an image was cropped – a patch! Microsoft pushes OOB security updates for Windows Snipping tool flaw (bleepingcomputer.com) The out-of-band (OOB) patch is available now – if you – or someone in your company …
When redacting does not work
This is not a repeat of the previous post – now the Microsoft Snipping Tool has been shown to have similar issues to Google Pixel’s image cropping tool – what you cut away is not lost and so secret, it can be recovered later. Windows 11 Snipping Tool privacy bug …
Why Zero-day attacks are a real issue
The gap between the vendor discovering a vulnerability and the patch getting to you will always be an issue – this is the zero-day threat. It escalates if the threat actors became aware of the vulnerability and exploits it before the vendor becomes aware. Now research by Mandiant shows that, …
When redacting does not work
We all see redacting n the TV shows and movies we watch – documents with big black lines through the secret information that must not be revealed – and I use similar techniques for screenshots I use here to conceal secret information. I am sure you do the same. I …