The 1st MS Security Patch In 2015

image

Well, hell, it is about time. Why did we have to wait so long? To tell the absolute truth, we do not have a clue. Yet, for what is worth, Microsoft has closed the security door opened by Google. To be quite honest, Google has not done anything wrong, it just warned about the serious security flaw in Windows 8.

On the other hand, Microsoft was obviously hit straight into its most serious nerve. Microsoft replied that Google worries too much about its competitors, rather and more than its own customers. Then, we had to wait for more than four months to get this security patch in order to have careless dreams.

At the same Google has troubles of its own with the Android 5.0, or better known as the Lollipop. However, it is obviously easier to deal with other people’s problems, than your own, isn’t it? In addition, Microsoft just could not have issued a security patch for a single issue, regardless of its seriousness.

So, what is going to happen now? Are we to expect that Microsoft is to strike back? How? Well, it can find some vulnerability in Google’s system in return. In the meantime, while these two IT giants play their vanity games, we the users, still have to tremble. Does it really have to be this way? For real?

PoC Schock

image

We have already written about the extremely problematic security flaw with the Windows 8.1, which allows a hacker to gain administrative privileges in an almost undetectable way. To make things even worse for Microsoft the busy little bee, who has discovered this trouble, published the PoC, as well.

The PoC is actually the Proof of Concept, which gives you a step-by-step guide how to do it yourself. In the meantime, Microsoft has come up with a patch to fix this annoying problem. However, this meantime actually took three months to happen. Why? Is it a really complicated problem? What could it be?

For what is worth, Microsoft has to offer a solution for more than platform. That is why you cannot build a Rome in a day. On the other hand, some comments have pointed out that it was not an advisable thing to publish this vulnerability with the PoC. Microsoft would have reacted either way. Right?

This one comes without saying, that is for sure. We should be also aware what is happening in our brave new IT world. It seems that we are not as safe as we thought we are. We should not discourage the future cyber whistleblowers under any circumstances. Otherwise, we will end up living in the dark of harmful cyber ignorance.

Skype + Android + Bug = ?

image

Do you know the solution to this question? A spy trouble. This is what you get as a result, when you combine these three elements. Why? Well, there is this annoying and potentially dangerous bug, which allows the unwanted guests to spy on your conversations and messages. Only on Android devices.

For the time being there is only one efficient solution available. You have to log out as soon as you are done with your Skupe communication. Unfortunately, this is not an extremely practical thing to do, is it? If Skype cannot be on all the time on your smartphone, then what is the use, in the first place?

For what is worth, Microsoft is fully aware of this problem. While we are writing this, its development teams are already on it, fixing it. The trouble with the curve in this story is actually a simple one. You cannot never be safe, enough. Which brings us to one of our most used sayings in the field of cyber security.

If you have nothing to hide, then you have nothing to worry about. Right? At least this is what the NSA has to say to you. Nothing more. Nothing less. However, this is a weak comfort for the millions of Skype users, who are sharing their most intimate thoughts through it. You have a Skype call? Are you going to answer it, or what?

Forshaw’s Patch

image

There is a busy little cyber bee, who works in Google. One day, we are not quite sure if he was curious or bored, this bee has discovered a serious security flaw in Windows 8.1. This guy works and publish under a nickname Forshaw. So, are you eager to know what went wrong with Windows 8.1?

Apparently, there is a way for you to gain administrator’s privileges, and all of that completely undetected. What can you do with them? Well, it comes without saying that in this case sky is the limit. Literally. Forshaw has done both necessary things in this unfortunate and embarrassing situation.

On the side, he has informed Microsoft directly about his findings. On the other side, he has published his conclusions supported with the proper evidence. So far, Microsoft has been silent on this one. Nevertheless, it is only a matter of time before the new patch hits our cyber shores with a solution.

For what is worth, Microsoft itself has some other troubles on its mind. What is going to happen with the new Windows 10 and how successful it is going to be? This is undoubtedly the mother of all questions for Microsoft at this moment. We sure hope that this bug will not wish to move to the new OS version.

Sony Is Going To Make It Up For You

image

Great news, cyber boys and girls. Sony is going to make it up to you for the Christmas trouble. You will get extra five days on your account. We have already written about it. The hacker’s group called the Lizard Squad was responsible for the attacks on both PSN ans Xbox One network. No network. No game.

Do you have any idea, who has saved the day? One of the least likely guys you could have possibly expected. No more and no less, than Kim Dotcom himself had to intervene here. He has reached some kind of a deal with the Lizard Squad members. They will spare the PSN and Xbox One from future attacks.

Is this a complete surprise or what? What happened to a rule that a friend of my enemy is supposed to be my enemy by default? Kim Dotcom is a hero of this story. Maybe, this is the way how Sony should solve its problems with the Interview movie and the North Korean bad boy Kim Jong Un.

One more accidental hero for Sony can be the extremely controversial and influential Dennis Rodman. Perhaps he can change the color of his hair and the mind of his friend Kim Jong Un. Right now, Sony needs all the help it can get right now. No matter how the helping hand is covered in tattoos.

Google vs Russia

image

Relax, for the time being, there is no conflict between Google and Russia. However, some more or less malicious comments pointed out some obvious facts and comparisons. Does it really matter, if it is because of the politics, or only economic and business related purposes? So, let us see what is happening here.

The estimated value of the entire Russian stock market is around $325 billions. On the other hand, the estimated worth of Google is more than $340 billions. It is worth mentioning that both Apple and Microsoft are already in this big boys club with the estimated worth of more than $350 billions.

So, what is that supposed to mean? Something, anything and everything. All of that at the same time. Maybe, someone wants to make a point that the USA has more than one company, which is worth more than an entire Russian stock market. This sounds and looks a little bit childish, isn’t it?

What is the next move? The Russians can brag around with their oil, gas and gold reserves. It is ridiculous, but for some people obviously necessary to cheer up the tense situation over the Ukraine crisis. Oh dear, has it really come down to this? This is so disappointing on so many levels, isn’t it?

The Virus Of Impatience

image

It seems that there are quite a few Microsoft users, who are the same time huge Kaspersky fans, with some proper patience problems. Windows 10 Technical Preview is such an irresistible thing that they cannot wait to install Kaspersky. Yet, the trouble in this case is the lack of adequate compatibility.

Windows 10 Technical Preview build 9879 is an obvious example. Kaspersky 2015 refuses to make friends with the latest Windows version. Why? Well, it is supposed to be simple. The busy little bees in Microsoft are still working on the fully compatible version for the Windows 10. What about other options?

Here is something you have not heard it from us. You can try this one at home, but do not blame us for the troubles. For example, you have a file kav15.0.1.415en_6868.exe. As expected, it does not work on Windows 10 Technical Preview. Yet, there is something you can do. What exactly?

You can change the last four numbers 6868 with the new ones 9879. Now try it again. It actually may work. This is definitely not a recommended thing to do, but if your impatience is your biggest problem even more serious compared to the security itself, then go for it. For what is worth, you have been warned.

You Have An Additional Right To Be Forgotten

image

Great news for all of you privacy addicts. Yahoo and Bing have decided to process your right to forget requests. Unfortunately, we are still and only in Europe. That means the European Internet users have an additional option to protect their privacy. So far, only Google has accepted to play the oblivion game.

From now on, you can address Yahoo and Microsoft’s Bing with the same privacy related concerns. It is worth mentioning that the whole thing does not work simply and flawlessly. One may say, it is so cool, I can address all major search engines and my troubles will be over. As always, there is a catch.

The website Forget.me, which specializes in these specific issues and requests, has noticed something that limits our efforts. If your cyber oblivion request has something to do with the social networks, then you can kiss the closed door, which is very likely. It seems that this is more complex than it looks.

The right to forget is very close to your right to regret. We are so far away from the truly functional and fair solution. You cannot stop or delete the entire Internet, just because you feel hurt. On the other hand, our dearest search engines should do us a favor every once in a while. Isn’t that right?

Pwn2Own IE11

image

There are no true winners in hackers contests or bug bounty rewarding programs. Someone will take the sweet prize, while we will end up in tears. Why? Because we will become more aware about the fragile and insecure character of our system. Yet, we cannot allow ourselves a luxury of neglecting them.

Some of them actually work. This is how a successful prevention has achieved. Can this be a comfort for Microsoft? Two HP security experts were able to find a weakness in the Internet Explorer 11. As a result, we have a complete malicious control over the computer, which runs the Windows 8.1.

As expected, Microsoft will clean this situation with the next security patch. However, we still have this bitter taste in our mouth. Why? Well, it is actually quite simple, and that is why is so painful. Who knows how many bugs are out there flying and crawling all over our cyber space? Do not bother to ask.

Unfortunately, we do not have enough hackers competitions or bug bounty programs to find and eliminate them all. If you want to say keep on trying, then you are moving into the wrong direction. Maybe, we are truly blessed with our cyber ignorance. There is a difference, though. What we do not know can hurt us badly in this case.

Cyber Ladies Will Save The World

image

There is something that the National Protection and Programs Directorate (NPPD) and the Department of Homeland Security (DHS), including the Microsoft itself know about the next cyber super weapon. Who could have thought that the solution to our cyber troubles comes on high fashion heels?

For what is worth, the growing number of female IT security experts is supposed to save the day. We are more than likely to expect an unprecedented demand for the new cyber security experts, especially the ones who prefer both top fashion and security codes. We have one more proof of our claims.

Microsoft has launched one of the biggest new talent program in India, with the special focus on young IT women. As a result, in the upcoming years Microsoft expects to build an army of one million IT ladies. No wonder, both the NPPD and the DHS share this enthusiasm for the new IT lady wave.

On the other side, we just cannot help ourselves wondering what could be the motivation for these unorthodox plans? It seems that women have some kind of a special cyber power, we are not quite aware about. Do not forget, one beautiful woman gave birth to the very first Trojan in our history.