backups

Winsage
May 20, 2026
Microsoft is addressing a zero-day exploit known as YellowKey, identified as CVE-2026-45585, which allows attackers to bypass BitLocker security using a specially crafted USB device. Following the release of exploit code by a hacker named Chaotic Eclipse, Microsoft has issued urgent mitigation advice. Cybersecurity expert Neena Sharma recommends treating this as an active threat and suggests implementing compensating controls, such as restricting USB boot access, until a patch is available. Microsoft has provided guidance for users to protect their systems, including the recommendation to add a PIN to BitLocker protection to reduce the risk of exploitation. Detailed instructions for adding a PIN are included in the advisory. YellowKey has not yet been exploited in the wild but requires physical access to the device.
Tech Optimizer
May 19, 2026
Percona has become a sponsor of pgBackRest following the departure of its primary maintainer due to funding challenges. This sponsorship aims to revitalize pgBackRest, a critical backup and recovery tool for PostgreSQL, ensuring its continued development and support. Percona's CEO, Peter Farkas, highlighted the importance of pgBackRest and the decision to coordinate with other companies to maintain its health. The plan for pgBackRest's future includes dedicated time from David Steele for bug fixes and feature enhancements, assistance from Percona's engineering team in onboarding a new maintainer, and efforts to attract additional sponsorship to diversify support. Percona's investment aims to prevent future uncertainties associated with reliance on a single maintainer.
Winsage
May 17, 2026
The utility created simplifies Windows management by consolidating various settings and diagnostics into a single interface. It provides an overview of system metrics such as DNS latency, system uptime, and temporary file accumulation. The application includes dedicated pages for health checks, network insights, services, scheduled tasks, drives, drivers, power plans, gaming toggles, privacy settings, and taskbar configuration. Each diagnostic is executed through PowerShell scripts, with results displayed in a user-friendly format. The utility maintains transparency by creating .reg backups before modifying the registry and allows users to revert changes easily. It is open-source, lightweight, and designed for personal use rather than debloating. The program's structure enables users to inspect and modify scripts, ensuring clarity and control over system adjustments.
Winsage
May 16, 2026
The utility developed streamlines access to Windows diagnostics and tweaks, consolidating functionalities typically spread across various settings panels into a single interface. It features an overview page with key system metrics and organized sections for health checks, network details, services, scheduled tasks, drives, drivers, power plans, gaming settings, privacy options, and taskbar adjustments. Each diagnostic is executed via PowerShell scripts that output JSON data for display. The application ensures transparency in registry changes by creating .reg backups before modifications and allows users to revert changes easily. It focuses on practical tweaks rather than debloating, maintaining a lightweight design without extensive features. The tool is open source and available on GitHub.
Tech Optimizer
May 16, 2026
O’Brien Technologies has launched a program called “Educate and Protect” to improve cybersecurity for businesses by addressing the human factor in breaches. They highlight that many cyber threats arise from human errors, such as clicking phishing links or misunderstanding data storage protocols. The company points out that cloud services do not automatically protect files without robust backup systems and that small businesses are often more vulnerable due to a lack of comprehensive security measures. They stress the inadequacy of relying solely on outdated tools like firewalls and antivirus software and advocate for a multi-layered cybersecurity approach. O’Brien Technologies recommends regular employee training, staying informed about threats, and ongoing commitment to cybersecurity. They offer tailored guidance for businesses looking to enhance their cybersecurity. Interested parties can contact them at 661-432-1301 or visit obrienmsp.com.
AppWizard
May 12, 2026
Krafton CEO Changhan Kim faced a [openai_gpt model="gpt-4o-mini" prompt="Summarize the content and extract only the fact described in the text bellow. The summary shall NOT include a title, introduction and conclusion. Text: In a remarkable twist of corporate fate, Krafton CEO Changhan Kim found himself navigating the turbulent waters of a 0 million bonus promise to the heads of the game studio he acquired. With the highly anticipated Subnautica 2 now the most-wishlisted game on Steam, the pressure mounted to fulfill that commitment. Faced with this financial dilemma, Kim sought counsel from ChatGPT, leading to the controversial decision to terminate the studio heads without a solid justification—an act that ultimately backfired. The Unfolding Drama The saga began in July 2025 when Ted Gill, CEO of Unknown Worlds, along with founders Charlie Cleveland and Max McGuire, were abruptly dismissed. Krafton initially claimed their termination was due to concerns over the premature release of Subnautica 2, alleging that the game was flawed enough to jeopardize the entire franchise. However, this reasoning raised eyebrows, especially given that a feature story on the game was in the works at PC Gamer just prior to the firing. As the legal battle unfolded, it became clear that the 0 million bonus was a significant factor in the studio heads' dismissal. Reports indicated that part of this bonus would have been shared with the studio staff, raising questions about Krafton's motives. The ousted executives contended that the claims regarding the game's readiness were fabricated to avoid the hefty payout. In court, Krafton shifted its narrative, asserting that the studio heads had "abandoned" their roles and taken confidential data with them. However, the judge noted that the data backup occurred after their termination, which undermined Krafton's justification for the dismissals. A CEO's AI Consultation Adding an unusual twist to the proceedings, it was revealed that Kim had consulted ChatGPT for advice on navigating the bonus situation. Initially denying this, he later admitted to using the AI to seek "faster answers." The judge remarked on the irony of a CEO relying on artificial intelligence to devise a corporate strategy, ultimately ruling that Gill should be reinstated as CEO of Unknown Worlds and extending the bonus eligibility deadline. Despite disagreeing with the ruling, Krafton complied, albeit with some tension. The company announced a May early access release for Subnautica 2, much to Gill's chagrin, as he had not yet resumed control. Although Krafton remains the parent company, the Steam page for Subnautica 2 no longer lists it as the publisher, indicating a shift in branding. The Anticipation Builds As the early access launch approaches, the gaming community is left to ponder whether Krafton's assertions about the game's unreadiness will be validated. Subnautica has established itself as a beloved title, earning an 89% rating from PC Gamer in 2018, and expectations are high for its sequel. Cleveland has expressed confusion over the claims that the game required additional development time, asserting that it was ready for release. With the early access launch set for May 14, the team at Unknown Worlds aims to deliver a polished experience, promising updates that will enhance gameplay and introduce new content over the next two to three years. As they embark on this journey, they invite players to engage in the development process, ensuring that Subnautica 2 evolves into a rich and immersive experience." max_tokens="3500" temperature="0.3" top_p="1.0" best_of="1" presence_penalty="0.1" frequency_penalty="frequency_penalty"] million bonus promise to the heads of Unknown Worlds, leading to their abrupt dismissal in July 2025. The terminations were initially justified by concerns over the premature release of Subnautica 2, which was the most-wishlisted game on Steam. However, this reasoning was questioned as a feature story on the game was being prepared at PC Gamer prior to the firings. Legal proceedings revealed that the bonus was a significant factor in the dismissals, with claims that the game was not ready being disputed by the ousted executives. Krafton's narrative shifted in court, claiming the studio heads had "abandoned" their roles, but evidence showed data backups occurred after their termination. Kim admitted to consulting ChatGPT for advice on the situation. The judge ruled that Ted Gill should be reinstated as CEO, extending the bonus eligibility deadline. Krafton complied with the ruling and announced a May early access release for Subnautica 2, although the game is no longer listed under Krafton as the publisher on Steam. The early access launch is set for May 14, with Unknown Worlds promising updates and player engagement in the development process.
Winsage
May 10, 2026
Microsoft's April 2026 Windows security update, KB5083769, may disrupt image-mount operations for backup applications such as Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup due to the addition of the psmounterex.sys kernel driver to its Vulnerable Driver Blocklist. This action was taken to address a high-severity buffer overflow vulnerability, CVE-2023-43896. The inclusion of this driver in the blocklist has rendered several backup products inoperable, and Microsoft will not retract the block for security reasons. Administrators can use Event ID 3077 in the Code Integrity log to confirm that the blocklist is causing the failures. Microsoft advises updating backup applications to versions that include necessary driver protections instead of uninstalling or pausing the security patch. Additionally, the April updates have caused other issues, such as failures in Windows Server installations and devices booting into BitLocker recovery mode.
Winsage
May 8, 2026
A recent Windows update, KB5083769, released on April 14, 2026, blocks the psmounterex.sys driver, disrupting the functionality of third-party backup software like Acronis Cyber Protect Cloud, Macrium Reflect, and NinjaOne. This driver is essential for loading and mounting backup storage images. Users may encounter errors related to Microsoft VSS during backup attempts. The update is a security enhancement, not a bug, and users are advised to upgrade their backup software to versions that use a newer driver or temporarily uninstall the KB5083769 update. It is recommended to check for updates from the backup software provider and pause Windows Updates to prevent automatic reinstallation of the problematic update until a fix is available.
Winsage
May 5, 2026
Microsoft will include the psmounterex.sys driver in its Vulnerable Driver Blocklist in the April 2026 security update, affecting third-party backup applications that use this driver for image mounting and Volume Shadow Copy Service (VSS) snapshots. This decision addresses CVE-2023-43896, a critical buffer overflow vulnerability. Affected software includes Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup on Windows 11, Windows 10, and Windows Server platforms. Users may face issues during image-mount operations, receiving error messages related to VSS timeouts and Code Integrity errors in the Event Viewer. To check if a system is affected, users can look for Event ID 3077 in the Code Integrity Operational log. Microsoft recommends upgrading to newer versions of backup applications that do not use blocked drivers and advises against uninstalling or delaying the April update. Additionally, the update may cause certain Windows Server 2025 devices to boot into BitLocker recovery mode and has led to out-of-band updates for Windows Server update failures and restart loops on domain controllers.
AppWizard
May 5, 2026
Meta has enhanced the security and transparency of its end-to-end encrypted backup system for WhatsApp and Messenger. The improvements focus on refining the distribution and verification of encryption keys, and allow for independent audits of certain infrastructure components. The updates are based on Meta's Hardware Security Module (HSM)-based Backup Key Vault architecture, which securely stores recovery secrets in tamper-resistant hardware, ensuring that neither Meta nor cloud service providers can access users' message archives. For encrypted backups, users' devices generate a 256-bit encryption key locally, which encrypts all backup data before uploading it to cloud storage. The key remains on the device in an encrypted format, with the user's password not visible to Meta or third parties. An encrypted version of the backup key is stored in the HSM-based vault using the OPAQUE password-authenticated key exchange protocol, enhancing recovery security without revealing the password. The recent updates include an over-the-air (OTA) fleet key distribution mechanism, which avoids hardcoding trusted infrastructure keys into Messenger applications. Clients receive a “validation bundle” containing the HSM fleet's public keys during runtime, with signatures verified against Cloudflare’s Key Transparency system. The vault operates across at least seven data centers using majority-consensus replication to ensure availability and integrity. Meta plans to publish cryptographic proof of each new HSM fleet deployment, allowing advanced users and researchers to verify these deployments through the open-source “mbt” (Meta Binary Transparency) CLI tool, which conducts multiple checks to confirm that fleet keys are untampered.
Search