security threats

Winsage
June 18, 2025
Microsoft will cease support for Windows 10 on October 14, 2025, affecting an estimated 200 to 400 million devices that will no longer receive updates or patches, exposing them to security vulnerabilities. Transitioning to Windows 11 requires modern hardware specifications, which many older devices lack. Users must decide between investing in new hardware, opting for extended security updates, or switching to alternative operating systems like Linux. The Document Foundation advocates for Linux and LibreOffice as viable alternatives, emphasizing their ability to run on older hardware and providing robust security updates. Linux offers users greater control and transparency, addressing privacy concerns associated with proprietary systems. LibreOffice supports open document formats, ensuring long-term accessibility without vendor constraints. The end of Windows 10 support may prompt significant shifts in the tech industry, encouraging a move towards systems that prioritize sustainability and user rights.
Winsage
June 17, 2025
Microsoft will cease support for Windows 10 on October 14, 2025, leaving an estimated 200 to 400 million devices vulnerable to security risks due to a lack of updates. Users must choose between upgrading to Windows 11, which has strict hardware requirements, paying for extended security updates, or switching to alternative operating systems like Linux. The Document Foundation advocates for Linux and LibreOffice as viable options, emphasizing their ability to run on older hardware and provide robust security updates without vendor lock-in. Privacy concerns regarding data collection by major tech companies are highlighted, with Linux offering users greater control and transparency. The transition away from Windows 10 is seen as an opportunity to promote user empowerment and sustainability in technology choices.
Winsage
June 16, 2025
CVE-2025-33073 is a Windows authentication relay attack vulnerability with a CVSS score of 8.8, indicating high severity. It allows attackers to gain SYSTEM privileges on affected systems. Currently, there is no evidence of active exploitation, but the public disclosure raises concerns. Exploitation involves executing a malicious script that makes the victim's machine connect to the attacker's system using SMB. Security researchers have described it as an authenticated remote command execution on machines that do not enforce SMB signing. Microsoft has released a fix as part of the June Patch Tuesday security updates to address this vulnerability.
Tech Optimizer
June 10, 2025
Norton 360 Deluxe is a comprehensive antivirus solution that offers extensive security features, including protection against botnets, brute force attacks, and vulnerabilities related to file and print sharing. It provides webcam protection, secure application sandboxing, and a Safe Search feature for risky websites. Users can create a rescue disk for emergencies. Scanning capabilities include quick scans, full scans, targeted folder scans, and a pre-boot deep scan, with the full scan completing in about four minutes. Parental controls allow management of screen time and website access across devices, while the included VPN can disable internet access if a compromised site is visited. Performance testing showed that Norton 360 Deluxe efficiently processed 927,000 files in about four minutes on various devices, significantly outperforming competitors like Bitdefender and McAfee. The Startup Scan feature is thorough but takes longer. The VPN maintained download speeds without noticeable degradation. Additional features include privacy monitoring tools, performance checks for outdated software, junk file removal, and limited cloud backup support for Windows devices. The user-friendly interface highlights key features and includes a search function for easy navigation. Norton provides 24/7 support through online chat and phone, with no email support available. The initial interaction with the virtual agent was efficient, followed by prompt human support.
Winsage
June 6, 2025
Users may face a significant vulnerability related to a Windows update from April 2025, particularly concerning the "inetpub" folder, which is essential for the security of Windows 11 systems. Microsoft clarified that this folder, linked to Internet Information Services (IIS) and necessary for hosting capabilities, should not be deleted. If users have removed the folder, they must restore it to address the security patch for CVE-2025-21204, as its absence can lead to risks such as privilege escalation and unauthorized access. Microsoft has provided a PowerShell script to restore the folder without enabling IIS, and users are advised to follow specific commands to execute the fix. However, many users may not take action, leaving their systems vulnerable.
Winsage
June 4, 2025
Microsoft will cease support for Windows 10 on October 14, leaving users vulnerable to bugs and security threats. Users have options to upgrade to Windows 11, invest in new hardware, or switch to alternative operating systems like Linux. The KDE group is promoting Linux, particularly Linux Mint, as a solution for those feeling abandoned by Microsoft, warning that users may face issues such as data breaches and inability to run new applications without updates. They also highlight the environmental impact of forced upgrades, labeling it "tech extortion." KDE advocates for the adoption of Linux to revitalize older hardware and regain control over computing experiences.
Winsage
June 2, 2025
A recent advisory warns Windows users about vulnerabilities, emphasizing the need to upgrade from Windows 10 to Windows 11 due to the impending cessation of support for Windows 10 in October. Asus has highlighted that users of Windows 10 or older systems will soon lose regular updates and support. Currently, around 750 million users are on Windows 10, with 500 million potentially eligible for a free upgrade to Windows 11. Recent market data shows Windows 10's user share has increased from 41% in April to over 43% in May, while Windows 11 has declined by 3.5%. The urgency for upgrades is heightened as the deadline for Windows 10 support approaches, raising concerns about a potential cybersecurity crisis.
Winsage
May 26, 2025
Microsoft encourages users to adopt the latest version of Windows or a version eligible for monthly security updates to protect against security threats. Older Windows ISOs are vulnerable due to outdated security updates and antimalware software. Microsoft has released an update for Microsoft Defender to enhance the security of these older Windows images. This update includes the latest Microsoft Defender binaries, which must be applied offline to WIM and VHD files for Windows 11, Windows 10 (Enterprise, Pro, Home), Windows Server 2022, 2019, and 2016. The update improves both the anti-malware client and engine, with package sizes of 78.2 MB for ARM64, 128 MB for x86, and 132 MB for x64 systems. Users need a 64-bit version of Windows 10 or later, PowerShell 5.1 or later, and specific modules to implement the update. Regular updates every three months are recommended for optimal security.
Tech Optimizer
May 19, 2025
The OpenEoX Technical Committee, part of OASIS, has introduced a draft framework to standardize end-of-life security notices for software and hardware, involving companies like Microsoft, Cisco, Oracle, IBM, Dell, and RedHat. The framework aims to provide clear communication about the security status of technology, helping organizations manage risks associated with legacy systems. It outlines a structured approach for notifying users about end-of-life status, enabling informed decisions on upgrades or replacements to improve security.
Winsage
May 1, 2025
Security researcher Daniel Wade has revealed that Microsoft’s Remote Desktop Protocol (RDP) allows users to log into systems using previously revoked passwords, raising concerns about user security. Wade highlights that this feature undermines the trust users place in password management, as changing passwords is expected to prevent unauthorized access. This issue affects a wide range of users, from individuals to employees in small businesses and hybrid work environments. Despite the increasing sophistication of cyberattacks on password managers, Microsoft has stated it will not change this RDP functionality.
Search