Security

Winsage
August 14, 2026
Researchers from the University of Birmingham and Durham University discovered a vulnerability in consumer DDR4 and DDR5 memory chips, termed "Download more RAM," which allows attackers to misreport memory configuration, potentially doubling the perceived RAM. This manipulation enables unauthorized access to memory allocations, bypassing Windows' Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI), and disabling antivirus software. The vulnerability affects major manufacturers like Corsair, G.Skill, and ADATA, which collectively hold over 55% of the high-performance memory market. Microsoft has patched the vulnerability, cataloged as CVE-2026-23670, with a medium severity score of 5.7/10, in the April 2026 Patch Tuesday update. Corsair has introduced a feature to enable write protection on their memory modules, and other tools are available for additional protection.
Winsage
August 14, 2026
Jonathan Blow expressed frustration on social media about delays in opening MP3 files in VLC Media Player, which he claimed could take over 30 seconds. A community note suggested that Microsoft Defender might be contributing to the delay. VideoLAN, the organization behind VLC, responded to the discussion, while Blow maintained that VLC should address the issue, despite acknowledging a faulty AMD graphics driver as a factor. Users on Reddit indicated that adding VLC's folder as an exception in Microsoft Defender resolved the delay. Steps to create this exception include navigating to Windows Security, selecting Virus & threat protection, managing settings, and adding an exclusion for the VLC folder. After creating the exclusion, the time to open an MP3 file decreased from approximately five seconds to under one second.
AppWizard
August 14, 2026
Threema experienced significant disruptions due to large-scale DDoS attacks, rendering the service inaccessible for several hours on Tuesday and causing intermittent outages on Wednesday morning. The attacks targeted both Threema and its Swiss colocation partner, Nine, with service being unavailable from 7:30 p.m. to 11:30 p.m. CEST on Tuesday. By 12:23 p.m. on Wednesday, normal operations were restored. The security of Threema's systems and user data remained intact despite the service availability issues. The nature of the attacks made mitigation challenging, as attackers modified their methods rapidly. Threema's status page faced issues during the outage, and communication was conducted via email and social media. In response, Threema is implementing specialized upstream DDoS protection and plans to enhance its status page to provide monitoring for future disruptions.
AppWizard
August 14, 2026
A recent court session involving Epic Games and Google highlighted issues with the Play Store's app search functionality. Judge Donato expressed dissatisfaction with the current search process and instructed Google to improve it, specifically by removing the third-party app store-specific page under the "Are you looking?" banner. Aptoide has returned to the Play Store due to Google's Play Catalogue Access Program, which allows qualifying third-party stores to publish their apps. Epic Games continues to challenge Google’s practices, arguing that the Play Store complicates the installation process for rival app stores. Judge Donato noted the unnecessary friction caused by the "Are you looking for?" banner, questioning its utility and instructing Google to eliminate it. The ongoing legal battle has also led to the Epic Games Store being allowed on the Play Store in 2025.
Tech Optimizer
August 14, 2026
Researchers have identified a significant vulnerability in consumer DDR4 and DDR5 memory modules, known as the “Download more RAM” flaw, which allows attackers to bypass advanced Windows security features, including Virtualization-Based Security (VBS) and Hypervisor Code Integrity (HVCI). This vulnerability enables the manipulation of configuration reports from RAM, misleading the system about its actual memory capacity, which can disable antivirus protections and allow the reintroduction of outdated drivers. The exploit can be executed via a single-click script, leading to security failures. Microsoft has released a patch for CVE‑2026‑23670 to enhance memory write protection against such exploits.
AppWizard
August 14, 2026
U.S. District Judge James Donato has ordered Google to simplify the installation process for rival Android app stores to eliminate barriers that discourage users from exploring alternative marketplaces. The judge criticized Google's practices as "anticompetitive friction" and mandated changes to ensure users can install alternative app stores as easily as any other Android application, giving Google one week to implement these changes. The ruling follows a previous antitrust victory for Epic Games, which found that Google maintained an illegal monopoly over Android app distribution and in-app billing services.
Search