Category Archives: Security

Windows: Microsoft's Bing wallpaper app as "adware"?

[German]I'm going to compile an information, that I've just come across, into a post – a second post on a similar topic will follow. Microsoft is offering a new Bing wallpaper app in the App Store that is supposed to … Continue reading

Posted in Security, Windows | Tagged , , | Leave a comment

Vulnerabilities in Netwrix PingCastle Pro/Enterprise (Nov. 2024)

[German]Brief information for administrators and IT service providers who use PingCastle (now part of Netwrix) to analyze Active Directory security. Due to vulnerabilities in the code, older versions of the Enterprise and Pro editions of the tool should no longer … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Microsoft 365 MFA mandatory for admins from Feb. 3, 2025

[German]Quick note for administrators of Microsoft 365 tenants. As of February 3, 2025, Microsoft will begin enforcing multifactor authentication (MFA) for access to the Microsoft 365 Admin Center. The option to suspend this MFA for 14 days will then be … Continue reading

Posted in Cloud, Security | Leave a comment

CISA warns about attacks on 0 day vulnerability in Palo Alto Networks firewalls

[German]An unpatched vulnerability (0-day) exist in the firewalls of Palo Alto Networks. The management interface can be accessed via this vulnerability. This 0-day vulneability is already being exploited for attacks. Both the BSI and the US authority CISA have issued … Continue reading

Posted in devices, Security | Tagged , | Leave a comment

Exchange 2016/2019 now warns against exploiting the spoofing vulnerability CVE-2024-49040 in emails

[German]Microsoft's November 2024 security updates for Exchange, has added a new feature to its Exchange 2016 and Exchange 2019 servers. Microsoft Exchange now warns when receiving emails that exploit a spoofing vulnerability (Exchange Server non-RFC compliant P2 FROM header detection … Continue reading

Posted in Security, Software, Update | Tagged , , , | Leave a comment

Vulnerability in CrushFTP; update recommended

[German]Quick note to users who use CrushFTP. A blog reader has informed me that a serious vulnerability has been discovered ans has been made public on November 11, 2024. However, there are updates in which this vulnerability, for which no … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Exchange Server: November 2024 security updates pulled

[German]Disaster for administrators of Microsoft Exchange Server 2016 and 2019 systems who have installed the security updates from November 12, 2024. The transport rules no longer work after applying the November 2024 security update. Microsoft has now stopped the deployment … Continue reading

Posted in issue, Security, Software, Update | Tagged , , , | Leave a comment

Patchday: Microsoft Office Updates (November 12, 2024)

[German]On November 12, 2024 (second Tuesday of the month, Microsoft Patchday), Microsoft released several security-related updates for Microsoft Office 2016, as well as the C2R variants (Office 2016-2021 and 365) and other products. Below you will find an overview of … Continue reading

Posted in Office, Security, Update | Tagged , , , , | Leave a comment

Microsoft Exchange Server Updates November 12, 2024

[German]Microsoft has released security updates (SU) for Exchange Server 2016 and 2019 on November 12, 2024. These updates close vulnerabilities found by Microsoft or security partners in Exchange Server. Below is an overview of which updates are available for Exchange … Continue reading

Posted in Security, Software, Update | Tagged , , | Leave a comment

Patchday: Windows Server 2012 / R2 and Windows 7 (November 12, 2024)

[German]Various security updates for Windows Server 2012/R2 (1st ESU year) were published on November 12. Support for Windows Server 2008 R2 expired in January 2024. Here is an overview of these updates for Windows Server 2012 and Windows Server 2012 … Continue reading

Posted in Security, Update, Windows | Tagged , , , | 1 Comment