certificates

Winsage
September 10, 2026
Microsoft is continuing the rollout of Secure Boot certificate updates, with the next significant deadline on October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires. The September 2026 Patch Tuesday update has expanded eligibility for Secure Boot certificates to more PCs classified as “high confidence.” Users may need to reboot their PCs to install these updates, and some may require firmware updates beforehand. Microsoft has confirmed that the update process will persist beyond established deadlines, and older certificates are expiring in stages, with the first two deadlines having already passed. Users should ensure they have the latest updates installed and check their Secure Boot status in Windows Security. Microsoft has assured that PCs without the newer certificates will continue to boot normally and receive standard updates while the rollout continues.
Winsage
September 8, 2026
Microsoft released its September 2026 security updates, addressing two critical Windows elevation-of-privilege vulnerabilities: CVE-2026-85880 and CVE-2026-81963. Both vulnerabilities were exploited before their public disclosure on September 8. CVE-2026-85880 involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing low-privileged attackers to gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack due to improper link resolution and access controls, enabling similar privilege escalation. The September release also includes 974 Common Vulnerabilities and Exposures (CVEs) across various Microsoft products, with 723 affecting Windows. Users of Windows 11 24H2 and 25H2 receive updates via KB5124008, while Windows 11 26H1 receives KB5124012. Windows 11 24H2 Home or Pro editions will reach end of servicing on October 13, 2026. Users are advised to install the updates promptly and back up important data.
Winsage
September 7, 2026
Microsoft is facing significant security and reliability issues, particularly related to system startup, BitLocker recovery, and updating Secure Boot certificates. Users have expressed confusion over these complexities, especially regarding Microsoft Defender Antivirus errors. These problems stem from a tumultuous period before the launch of Windows 11, including changes to the TPM requirement and the extension of Windows 10's life. Despite increased security patches, underlying issues remain, leading to user skepticism about the reliability of Windows systems.
AppWizard
September 6, 2026
In 2026, hosting game servers has become more efficient, allowing multiple game servers to run on a single cloud VPS using Pterodactyl Panel, which utilizes Docker containers for isolation. Pterodactyl is a free, open-source game server management panel that gained popularity due to its user-friendly interface and robust architecture. The latest stable release, v1.12.0, was launched in January 2026, with newer deployment templates available as of August 2026. To set up Pterodactyl, prerequisites include a cloud VPS with specific CPU and RAM requirements, Ubuntu 24.04 LTS, PHP 8.3, MariaDB 11.8.8 or newer, Redis 8.10.0 or newer, Docker Engine, a registered domain for SSL, SteamCMD dependencies, and at least 80 GB SSD storage. The installation process involves provisioning the VPS, installing necessary software, configuring Pterodactyl, setting up Nginx with SSL, and deploying game servers. Common pitfalls include under-provisioning RAM for resource-intensive games, neglecting firewall settings, and allowing backup retention to grow uncontrollably. Troubleshooting may involve addressing PHP-FPM issues, connection problems, and ensuring proper resource allocation. Advanced scaling may require multiple VPS nodes, and security measures like two-factor authentication can help protect the server. Pterodactyl is free to use commercially and can run multiple game containers on a single node.
Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
AppWizard
August 29, 2026
Google has introduced several network security enhancements in Android 17 to improve user privacy. One key feature is Encrypted Client Hello (ECH), which encrypts domain names to prevent external observers from monitoring user activities. ECH is integrated with private DNS and is enabled by default for apps using compatible networking libraries. Google claims to be the first major mobile operating system to implement widespread ECH support. Testing conducted by Jigsaw showed stable connection success rates and minimal interference across various networks. Additional security features in Android 17 include: - Local Network Protection, requiring apps to request permission before accessing devices on a user's home network. - Certificate Transparency, mandating public logging of certificates to detect forged ones. - A 2G Network Shutdown option for mobile operators to disable 2G services, reducing exposure to phishing messages.
AppWizard
August 28, 2026
Developers are encouraged to upgrade to OkHttp 5.5.0 and enable Encrypted Client Hello (ECH) for modern networking practices. Android 17 introduces Local Network Protection, requiring apps to obtain user permission before scanning local networks. Android has implemented Certificate Transparency (CT) by default to log all certificates in a public registry, reducing the risk of fraudulent certificates. Scammers are using portable devices known as “SMS blasters” to target mobile users by forcing them onto less secure 2G networks, allowing phishing texts to bypass modern spam filters.
AppWizard
August 26, 2026
Samsung has alerted developers using the Galaxy Store about upcoming changes due to Google's new Android Developer Verification (ADV) rules, which will take effect on September 30, 2026. Developers in Brazil, Indonesia, Singapore, and Thailand must complete the verification process to avoid having their unverified apps removed from the Galaxy Store. The ADV process requires developers to authenticate their identities and register package names and signing certificates. Apps that are not verified will be hidden from search results and listings, affecting their visibility. Users may face difficulties reinstalling or updating existing apps until developers complete the verification, although previously installed apps will continue to function. Samsung is indicating the status of app binaries in the Seller Portal and will restrict new registrations and updates lacking ADV approval starting in September. Sideloading will still be possible for certain apps and through an advanced installation flow, while ADB installations will remain unchanged. The initial rollout is limited to specific countries, with a global expansion expected in 2027. Developers are encouraged to act quickly to maintain app visibility.
Winsage
August 24, 2026
Microsoft has issued an advisory to IT teams and software developers regarding significant changes in Windows code signing due to the expiration of the Windows Production PCA 2011 certificate in October 2026. The transition will involve stronger cryptographic algorithms, including RSA-3072 and SHA-384, which may cause compatibility issues for applications that rely on hardcoded certificate checks or outdated cryptographic standards. Microsoft plans to implement post-quantum cryptography by default for Windows code signing in 2027. IT administrators are encouraged to assess their software environments, confirm vendor compliance with supported trust-validation mechanisms, and ensure applications are tested against the new certificate hierarchy and signing algorithms. Organizations with private trust stores must establish processes for recognizing and deploying legitimate Microsoft certificate updates.
Search