Mozilla issues final warning to websites using TLS 1.0

Credit to Author: John E Dunn| Date: Wed, 12 Feb 2020 16:13:57 +0000

From March, the Firefox, Chrome, Safari and Edge browsers will show warnings when users visit websites that only support TLS versions 1.0 or 1.1.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/3oMQ9dp5jKA” height=”1″ width=”1″ alt=””/>

Read more

Thought you already paid for Win7 Extended Security Updates? Think again.

Credit to Author: Woody Leonhard| Date: Wed, 12 Feb 2020 05:43:00 -0800

I’m hearing lots of complaints from people who spent good money to get Win7 Extended Security Updates, but don’t see this month’s patches. There’s a reason why. Microsoft didn’t bother to tell us that you need a new patch, released yesterday, in order to start receiving Win7 ESU updates. You have to download the new patch, KB 4538483, from the Microsoft Catalog, and install it manually before the updates even appear.

Folks who spent money to get the February and later patches are livid. 

Yesterday, after releasing the February updates, Microsoft modified its ESU Procedure page to add this step:

To read this article in full, please click here

Read more

February, 2020 Patch Tuesday brings a century of updates to Microsoft, Adobe products

Credit to Author: SophosLabs Offensive Security| Date: Tue, 11 Feb 2020 20:50:22 +0000

For this second Patch Tuesday of 2020, Microsoft has released a hundred patches to Windows and other Microsoft software, including 12 vulnerabilities flagged as Critical, and 87 flagged as Important. In addition, Adobe also published updates for its Flash Player, Acrobat, Framemaker, Experience Manager, and Digital Editions products in notifications timed to coincide with Microsoft&#8217;s [&#8230;]<img src=”http://feeds.feedburner.com/~r/sophos/dgdY/~4/zpsWY9HeJhU” height=”1″ width=”1″ alt=””/>

Read more

For Patch Tuesday, verify you have 'Pause Updates' enabled

Credit to Author: Woody Leonhard| Date: Mon, 10 Feb 2020 12:13:00 -0800

Read more

Patch Tuesday’s tomorrow. Verify you have 'Pause Updates' enabled

Credit to Author: Woody Leonhard| Date: Mon, 10 Feb 2020 12:13:00 -0800

Read more

It’s not too late to get an Extended Security Update license for Windows 7

Credit to Author: Woody Leonhard| Date: Wed, 05 Feb 2020 04:42:00 -0800

Worried about the future of your Win7 machine? Welcome to the family.

Right now, we have a promise that Microsoft will fix the “Stretch” wallpaper bug it rolled out last month, and there’s some hope that it will fix the Internet Explorer JScript engine security hole CVE-2020-0674 noted last month in Security Advisory ADV200001. We don’t know how/when the fix(es) will be distributed, or if Microsoft will soften its “no free Win7 patches after January 14” edict in some other way.

To read this article in full, please click here

Read more

Washington Privacy Act welcomed by corporate and nonprofit actors

Credit to Author: David Ruiz| Date: Tue, 04 Feb 2020 16:35:25 +0000

The Washington Privacy Act would extend new data rights of access, correction, and deletion to Washington residents, with new rules on facial recognition.

Categories:

Tags:

(Read more…)

The post Washington Privacy Act welcomed by corporate and nonprofit actors appeared first on Malwarebytes Labs.

Read more

Apple proposes simple security upgrade for SMS 2FA codes

Credit to Author: John E Dunn| Date: Mon, 03 Feb 2020 12:54:31 +0000

Apple thinks it’s come up with a simple way to make SMS two-factor authentication (2FA) one-time codes less susceptible to phishing attacks.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/EmuD8lIFjiU” height=”1″ width=”1″ alt=””/>

Read more

The perils of shouting 'fire' in a crowd of PC patchers

Credit to Author: Woody Leonhard| Date: Thu, 30 Jan 2020 10:14:00 -0800

Time and again we see the same drama play out. Microsoft releases a security patch and scary warnings appear from every corner. When your local news broadcast tells you that you better patch Windows right now…, more temperate advice should prevail.

A little over two weeks ago, on Patch Tuesday, Microsoft released a patch for a security hole known as  CVE-2020-0601 – the Crypt32.dll vulnerability also called ChainOfFools or CurveBall

To read this article in full, please click here

Read more