system administrators

Winsage
March 7, 2025
The Akira ransomware group has demonstrated its ability to bypass Endpoint Detection and Response (EDR) tools by exploiting an unsecured webcam. In 2024, Akira was responsible for 15% of ransomware incidents addressed by the S-RM team. The group typically gains access through remote access solutions and uses tools like AnyDesk.exe. In a recent attempt to deploy ransomware on a Windows server, their initial effort was thwarted by EDR detection. Subsequently, they conducted an internal network scan and targeted a vulnerable webcam, which lacked EDR protection. By compromising the webcam, Akira deployed Linux-based ransomware to encrypt files across the victim’s network. This incident highlights the need for organizations to patch and manage IoT devices, audit networks for vulnerabilities, implement network segmentation, and monitor IoT traffic for anomalies.
Winsage
February 28, 2025
Windows 11 24H2 has a bug that causes mixed language displays in menus when users switch languages, often favoring the original language. This issue has been present since the update's rollout in October 2024 and affects some devices inconsistently. A recent optional update may resolve the problem for some users, with a full cumulative update expected next month.
Winsage
February 20, 2025
SysInternals is a suite of 74 utilities from Microsoft designed to enhance the performance and reliability of Windows PCs. Users can download the entire suite or select individual tools from the Microsoft SysInternals Learn page. 1. AutoRuns: Identifies unnecessary background processes and obsolete registry entries, providing detailed information about each entry. It allows users to review installed drivers and spot potentially harmful entries. Launched via Start menu or by typing Autoruns.exe in the Run dialog. 2. TCPView: Monitors all TCP and UDP connections in real-time, categorizing them by version and displaying ports and connection timestamps. It helps identify bandwidth-hogging processes. Launched via Start menu or by typing tcpview.exe in the Run dialog. 3. RamMap: Provides an in-depth analysis of memory consumption across processes, helping identify memory-hogging applications and diagnose memory leaks. It offers options to clear memory, including emptying working sets, standby lists, and modified lists. Launched via Start menu or by typing rammap.exe in the Run dialog. 4. DiskView: Offers detailed insights into hard drive usage with a color-coded map of disk sectors, helping users identify fragmentation and unused space. Launched via Start menu or by typing diskview.exe in the Run dialog. 5. CacheSet: Optimizes the Windows file system cache by allowing users to adjust cached data management settings and clear the cache with a single click. Launched by typing cacheset.exe in the Run dialog. The SysInternals Suite is cost-free, effective, and compatible with Windows Recovery mode, making it a practical choice for users looking to enhance their PC's performance.
Winsage
February 7, 2025
Starting in mid-2025, Microsoft will allow organizations to manage how fresh installations of Windows 11 handle cumulative updates from the outset, responding to system administrators' concerns about previous control limitations. This new policy will be available for devices running Windows 11 version 22H2 or newer during the Out-of-the-Box Experience (OOBE). Initially, Microsoft planned to require the installation of the latest updates upon first boot, but this raised concerns about potential issues with fixes and critical features. The new configuration can be enabled through Windows Autopilot, synchronizing existing quality update settings. This change applies only to cumulative or quality updates, not optional monthly updates. Organizations without Autopilot can disable quality updates during OOBE via Group Policy. The update process typically takes around 20 minutes, depending on various factors.
Search