reporting

Winsage
September 22, 2025
A new technique called EDR-Freeze allows evasion of security solutions through Microsoft's Windows Error Reporting (WER) system, enabling attackers to suspend endpoint detection and response (EDR) tools without relying on vulnerable drivers. Security researcher TwoSevenOneThree utilized the WER framework and the MiniDumpWriteDump API to indefinitely suspend EDR and antivirus processes by exploiting the WerFaultSecure component, which operates with Protected Process Light (PPL) privileges. The method involves spawning WerFaultSecure, invoking MiniDumpWriteDump on the target process, monitoring the target until it is suspended, and then freezing the dumper. A tool has been developed to automate this process, successfully tested on Windows 11 24H2, which froze the Windows Defender process. To mitigate this attack, monitoring WER for identifiers linked to sensitive processes is recommended, and security researcher Steven Lim has created a tool to map WerFaultSecure to Microsoft Defender Endpoint processes. Microsoft has the opportunity to enhance these components against misuse by implementing restrictions on suspicious invocations.
AppWizard
September 22, 2025
Waze's latest beta version, 5.9.90 and beyond, will require Android 10 as the minimum operating system, leaving users with Android 8 or 9 unable to access new features and updates. Users of older smartphones or tablets and aftermarket in-car infotainment systems operating on Android 8 or 9 will be affected. While Waze can still be used on older versions, users will not receive new features or updates, and the app's reliability may decline over time. Google Maps remains a viable alternative for those unable to upgrade. Users are advised to check their Android version, update their devices if possible, consider budget upgrades, and keep Google Maps as a backup.
Tech Optimizer
September 22, 2025
A security researcher has developed a tool called EDR-Freeze that allows for the temporary disabling of endpoint detection and response (EDR) systems and antivirus software without using vulnerable drivers. EDR-Freeze exploits the Windows Error Reporting functionality to execute a race condition attack that suspends security processes, specifically targeting the WerFaultSecure.exe process. The tool can successfully suspend the MsMpEng.exe process of Windows Defender on Windows 11 24H2. It operates entirely within user-mode and uses legitimate Windows components, making detection more difficult for security teams. The source code for EDR-Freeze is publicly available on GitHub, intended for legitimate security research, but poses risks of misuse by malicious actors. Security teams are advised to monitor for suspicious activity related to WerFaultSecure.exe and to enhance their process protection mechanisms.
AppWizard
September 21, 2025
Battlefield 2042 faced significant backlash due to its underwhelming multiplayer experience and lack of a campaign mode, resulting in a Metacritic score of 68 and a user rating of 2.3 out of 10. The developers at DICE are optimistic about Battlefield 6, which aims to return to the franchise's roots, drawing inspiration from Battlefield 3 and 4. The successful open beta has renewed confidence among the team, and they are addressing player concerns regarding map sizes. DICE has introduced Battlefield Labs to engage with the community and gather feedback, fostering a sense of shared ownership among fans. Anticipation for Battlefield 6 is building, with discussions about launch weapons and remastering classic maps. Players are encouraged to join the community Discord server to share their thoughts.
Tech Optimizer
September 21, 2025
EDR-Freeze is a proof-of-concept tool developed by Zero Salarium that can place Endpoint Detection and Response (EDR) and antivirus solutions into a suspended state. It utilizes the MiniDumpWriteDump function from the Windows DbgHelp library to achieve this by extending the suspension of target processes. The tool circumvents the Protected Process Light (PPL) security feature using WerFaultSecure.exe, which operates at a high privilege level. By launching WerFaultSecure.exe with specific parameters, EDR-Freeze can monitor and suspend it, preventing the target EDR or antivirus process from resuming. A test on Windows 11 24H2 successfully suspended the MsMpEng.exe process of Windows Defender. Detecting this technique involves monitoring for unusual executions of WerFaultSecure.exe targeting sensitive process IDs.
AppWizard
September 20, 2025
The second pre-release of Minecraft: Java Edition 1.21.9 was released on Friday, addressing various issues from previous snapshots and updating the Data Pack major version. Changes include: - Copper Golems will oxidize even with the doDaylightCycle game rule disabled. - The transformation behavior of Copper Golems into statues has been refined, allowing them to transition without needing to be centered in an empty block and potentially turning into a statue upon full oxidation. Technical changes include an update to the Data Pack version to 88.0, reflecting changes to /setworldspawn and /spawnpoint. Bugs fixed in this release include: - MC-300362: Copper Golems do not oxidize when doDaylightCycle is disabled. - MC-301566: Occasional sound crash during resource pack reloads. - MC-301706: Server Management Protocol does not support parameters as objects. - MC-301770: Below_name plate fails to display correctly for players named “deadmau5.” - MC-301963: Copper Golems create significant lag spikes when checking chests. - MC-302088: Oxidized Copper Golems take too long to transform into statues. - MC-302112: Posed mannequins do not use the correct hitbox. - MC-302117: Text display billboarding is malfunctioning. - MC-302120: Dimension-specific world spawn points hinder mob spawning. - MC-302148: Copper Golems fail to approach chests adequately. - MC-302164: A breaking change to /setworldspawn and /spawnpoint noted in the minor datapack version. The pre-release is available for installation via the Minecraft Launcher, with a warning about potential world corruption.
Winsage
September 19, 2025
Valve will discontinue support for 32-bit versions of Windows 10 on January 1, 2026, as only 0.01% of users operate on this system. Existing installations will remain functional but will not receive updates or technical support. Support for Windows 10 64-bit will continue, and 32-bit games will still be playable after the support deadline. Valve advises users to transition to a 64-bit version for optimal performance and security, as future iterations of Steam will only operate on 64-bit systems.
AppWizard
September 18, 2025
The development team at DICE is remastering the iconic map Operation Firestorm from Battlefield 3 for Battlefield 6. Product owner Shashank Uchil highlights the challenges of meeting player expectations and balancing nostalgia with modern gameplay mechanics. Producer Jeremy Chubb notes that the foundation from previous Battlefield titles allows for innovation, but emphasizes the importance of evolving the map while maintaining its essence to satisfy both old fans and new players. The team aims to incorporate advanced physics and extensive destruction mechanics into the remaster. A preview of Battlefield 6 is available, and further insights will be shared in the coming week.
AppWizard
September 18, 2025
The copper age update introduces enhancements focused on copper golems, adjustments to mannequins, and various bug fixes. Key changes include: - Copper golems can now only attempt to open adjacent chests when acting as passengers. - Notifications now use the format minecraft:notification/ instead of notification:. - The Data Pack version has been updated to 87.1. - Mannequin descriptions are now configurable, and they can accept the minecraft:profile component from spawner items. - New data fields for mannequins include pose (with valid entries such as standing, crouching, swimming, fall_flying, sleeping), immovable, description, and hidedescription. - The spawnpoint command now accepts a pitch argument, and the setworldspawn command is no longer restricted to the overworld. - The fetchprofile command provides clickable text to summon a mannequin with the resolved profile. - Modified entity data for players includes required fields for yaw, pitch, and dimension. - New context values for loot functions have been added. - Multiple bugs have been fixed, including issues with copper golems, mannequins, and game crashes. Pre-releases are available for Minecraft: Java Edition, and users are advised to back up their worlds before testing.
AppWizard
September 17, 2025
Spotify is currently facing significant issues, with over 3,000 users reporting problems with the app, 95% of which are related to app functionality. Additionally, 3% of complaints are about the website, and 2% concern search features. Users have expressed their frustrations on X (formerly Twitter), asking if Spotify is down. While Spotify has not officially acknowledged the outage, inquiries have been made for clarification.
Search