• Landing Page
  • Shop
  • Contact
  • Privacy Policy
  • Login
  • Register
Upgrade
TrivDaily
">
  • WorldNew
    Pound

    Pound hits 37-year low against dollar

    Palm Trees - WIND

    Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

    Prince of Wales - TrivDaily

    Princess Diana’s title has been passed on to the Duchess of Cambridge

    TrivDaily - King Charles Speech

    3 main points to be gleaned from King Charles first public speech

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

    Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    Lionel Messi, Argentina win Copa America over Brazil

    Lionel Messi, Argentina win Copa America over Brazil

    Trending Tags

    • Lifestyle
      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      Crystal Palace into Champions League places as Guehi scores late winner at Fulham

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      Trending Tags

      • Pandemic
    • Business
      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Trending Tags

      • Vaccine
      • Pandemic
    • Entertainment
      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Sophia Thakur’s Lexicon Is Love

      Sophia Thakur’s Lexicon Is Love

      President Trump awards medals to Sly Stallone, George Strait and more

      President Trump awards medals to Sly Stallone, George Strait and more

      Supplier Supplement: fraudsters, storytelling and technology

      Supplier Supplement: fraudsters, storytelling and technology

      Fred again.. And Blanco Combine On ‘Solo’

      Fred again.. And Blanco Combine On ‘Solo’

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      The six Latin American markets the betting industry should keep an eye on

      The six Latin American markets the betting industry should keep an eye on

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Peru escalates dispute of Dina’s tax encroachment 

      Peru escalates dispute of Dina’s tax encroachment 

      Trending Tags

      • Sports
        Ed Sheeran, Bruno Mars & Others Mega Concerts at NFL Stadiums Likely Causing NFL Schedule Release Delay

        Ed Sheeran, Bruno Mars & Others Mega Concerts at NFL Stadiums Likely Causing NFL Schedule Release Delay

        “Should Join Iowa Coaching Staff”: WNBA Community Shares Thoughts After Valkyries Waive Kate Martin

        “Should Join Iowa Coaching Staff”: WNBA Community Shares Thoughts After Valkyries Waive Kate Martin

        Paul George Confronted by Teammate After Last-Minute Mistake Costs 76ers’ Chance to Tie Series vs. Knicks

        Paul George Confronted by Teammate After Last-Minute Mistake Costs 76ers’ Chance to Tie Series vs. Knicks

        “You’re an Idiot”: Urban Meyer Gets Brutally Honest on Brendan Sorsby Situation Amid Uncertain Future

        “You’re an Idiot”: Urban Meyer Gets Brutally Honest on Brendan Sorsby Situation Amid Uncertain Future

        Worapon headlines ONE Friday Fights 153 on May 8 against Tom Casse

        Worapon headlines ONE Friday Fights 153 on May 8 against Tom Casse

        The biggest mistake Mike McCarthy and every first-year NFL coach made this offseason

        The biggest mistake Mike McCarthy and every first-year NFL coach made this offseason

        Victor Wembanyama has 12-block triple-double in Spurs’ loss

        Victor Wembanyama has 12-block triple-double in Spurs’ loss

        Inside the Met Gala, an Olympic champion learns just how famous she’s become

        Inside the Met Gala, an Olympic champion learns just how famous she’s become

        Breaking: Charles Leclerc slapped with massive time penalty after Miami GP

        Breaking: Charles Leclerc slapped with massive time penalty after Miami GP

        Trending Tags

        • Travel

          Trending Tags

          • Technology

            Trending Tags

            • Real Estate

              Trending Tags

              No Result
              View All Result
              • WorldNew
                Pound

                Pound hits 37-year low against dollar

                Palm Trees - WIND

                Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

                Prince of Wales - TrivDaily

                Princess Diana’s title has been passed on to the Duchess of Cambridge

                TrivDaily - King Charles Speech

                3 main points to be gleaned from King Charles first public speech

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

                Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                Lionel Messi, Argentina win Copa America over Brazil

                Lionel Messi, Argentina win Copa America over Brazil

                Trending Tags

                • Lifestyle
                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  Crystal Palace into Champions League places as Guehi scores late winner at Fulham

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  Trending Tags

                  • Pandemic
                • Business
                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Trending Tags

                  • Vaccine
                  • Pandemic
                • Entertainment
                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Sophia Thakur’s Lexicon Is Love

                  Sophia Thakur’s Lexicon Is Love

                  President Trump awards medals to Sly Stallone, George Strait and more

                  President Trump awards medals to Sly Stallone, George Strait and more

                  Supplier Supplement: fraudsters, storytelling and technology

                  Supplier Supplement: fraudsters, storytelling and technology

                  Fred again.. And Blanco Combine On ‘Solo’

                  Fred again.. And Blanco Combine On ‘Solo’

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  The six Latin American markets the betting industry should keep an eye on

                  The six Latin American markets the betting industry should keep an eye on

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Peru escalates dispute of Dina’s tax encroachment 

                  Peru escalates dispute of Dina’s tax encroachment 

                  Trending Tags

                  • Sports
                    Ed Sheeran, Bruno Mars & Others Mega Concerts at NFL Stadiums Likely Causing NFL Schedule Release Delay

                    Ed Sheeran, Bruno Mars & Others Mega Concerts at NFL Stadiums Likely Causing NFL Schedule Release Delay

                    “Should Join Iowa Coaching Staff”: WNBA Community Shares Thoughts After Valkyries Waive Kate Martin

                    “Should Join Iowa Coaching Staff”: WNBA Community Shares Thoughts After Valkyries Waive Kate Martin

                    Paul George Confronted by Teammate After Last-Minute Mistake Costs 76ers’ Chance to Tie Series vs. Knicks

                    Paul George Confronted by Teammate After Last-Minute Mistake Costs 76ers’ Chance to Tie Series vs. Knicks

                    “You’re an Idiot”: Urban Meyer Gets Brutally Honest on Brendan Sorsby Situation Amid Uncertain Future

                    “You’re an Idiot”: Urban Meyer Gets Brutally Honest on Brendan Sorsby Situation Amid Uncertain Future

                    Worapon headlines ONE Friday Fights 153 on May 8 against Tom Casse

                    Worapon headlines ONE Friday Fights 153 on May 8 against Tom Casse

                    The biggest mistake Mike McCarthy and every first-year NFL coach made this offseason

                    The biggest mistake Mike McCarthy and every first-year NFL coach made this offseason

                    Victor Wembanyama has 12-block triple-double in Spurs’ loss

                    Victor Wembanyama has 12-block triple-double in Spurs’ loss

                    Inside the Met Gala, an Olympic champion learns just how famous she’s become

                    Inside the Met Gala, an Olympic champion learns just how famous she’s become

                    Breaking: Charles Leclerc slapped with massive time penalty after Miami GP

                    Breaking: Charles Leclerc slapped with massive time penalty after Miami GP

                    Trending Tags

                    • Travel

                      Trending Tags

                      • Technology

                        Trending Tags

                        • Real Estate

                          Trending Tags

                          No Result
                          View All Result
                          TrivDaily
                          No Result
                          View All Result
                          Home Technology

                          Microsoft forgot to renew the certificate for its Windows Insider subdomain

                          Ferhan Rana by Ferhan Rana
                          June 12, 2022
                          in Technology
                          Reading Time:7 mins read
                          30.8k 953
                          A A
                          0
                          Microsoft forgot to renew the certificate for its Windows Insider subdomain
                          29.7k
                          SHARES
                          33.8k
                          VIEWS
                          Share on FacebookShare on Twitter
                          ">

                          Visitors to insider.windows.com met with safety warning – how reassuring


                          Microsoft has forgotten to renew the certificate for the web page of its Windows Insider software testing program.

                          Attempting to visit the Windows Insider portal was returning the familiar “Your connection is not private” warning – as if webpages larded with scripts and trackers can truly be called “private.” The problem has now been fixed, and someone’s no doubt getting an earful.

                          Browsers like Chrome, Firefox, and Safari will attempt to deter visitors from accessing the webpage, but will provide a link for those who ignore the warnings and persist on clicking through to advanced options.

                          We did so and lived to tell about it.

                          The Insider web page certificate expired on Thursday, June 9, 2022 at 4: 59: 59 PM Pacific Daylight Time.

                          Expired Microsoft certificate

                          Click to enlarge

                          Microsoft did not immediately respond to a request for comment. But clicking through the warnings on Firefox initially took this reporter to Microsoft’s main Windows page with 302 and 307 redirect responses – Microsoft is redirecting requests to its expired page and so is aware of the issue.

                          • Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point
                          • Expired cert breaks Windows 11 snipping tool, emoji panel, S Mode features, other stuff
                          • Xero, Slack suffer outages just as Let’s Encrypt root cert expiry downs other websites, services
                          • Happy New Year: Jan 1, 2021 security cert expiration causes havoc for some Check Point VPN users

                          This sort of snafu happens occasionally. In November, 2021, an expired cert affected Windows 11 version 21H2 – it prevented Windows users from opening certain apps like the snipping tool.

                          And in 2020, an expired authentication certificate prevented customers from accessing Microsoft Teams.

                          Cert expirations tend to be worse when they affect root certificates and bork services for multiple vendors and customers. The expiration of Sectigo’s AddTrust legacy root certificate two years ago affected thousands of customers.

                          They’re also rather disruptive when they occur at telecom companies, the 2018 Ericsson cert expiration that hindered communications among tens of millions of UK customers.

                          Maybe Window’s scheduling systems aren’t all they are cracked up to be. ®


                          Other stories you might like

                          • Supply chain attacks will get worse: Microsoft Security Response Center boss

                            Do you know all of your software dependencies? Spoiler alert: hardly anybody is on top of it

                            RSA Conference Major supply-chain attacks of recent years – we’re talking about SolarWinds, Kaseya and Log4j to name a few – are “just the tip of the iceberg at this point,” according to Aanchal Gupta, who leads Microsoft’s Security Response Center.

                            “All of those have been big,” she said, in an interview with The Register at RSA Conference. “But I feel they will continue and there will be more. And there’s a reason I think that.”

                            As the head of MSRC, Gupta has a unique vantage point. Her view spans all of Microsoft’s products and services, as well as visibility across industry partners’ software and tools plus customers’ environments including government agencies. 

                            Continue reading

                          • Microsoft seizes 41 domains tied to ‘Iranian phishing ring’

                            Windows giant gets court order to take over dot-coms and more

                            Microsoft has obtained a court order to seize 41 domains used by what the Windows giant said was an Iranian cybercrime group that ran a spear-phishing operation targeting organizations in the US, Middle East, and India. 

                            The Microsoft Digital Crimes Unit said the gang, dubbed Bohrium, took a particular interest in those working in technology, transportation, government, and education sectors: its members would pretend to be job recruiters to lure marks into running malware on their PCs.

                            “Bohrium actors create fake social media profiles, often posing as recruiters,” said Amy Hogan-Burney, GM of Microsoft’s Digital Crimes Unit. “Once personal information was obtained from the victims, Bohrium sent malicious emails with links that ultimately infected their target’s computers with malware.”

                            Continue reading

                          • GitHub drops Atom bomb: Open-source text editor mothballed by end of year

                            Embrace, extend technology into other products … and extinguish

                            On December 15, Microsoft’s GitHub plans to turn out the lights on Atom, its open-source text editor that has inspired and influenced widely used commercial apps, such as Microsoft Visual Studio Code, Slack, and GitHub Desktop.

                            The social code biz said it’s doing so to focus on cloud-based software.

                            “While that goal of growing the software creator community remains, we’ve decided to retire Atom in order to further our commitment to bringing fast and reliable software development to the cloud via Microsoft Visual Studio Code and GitHub Codespaces,” GitHub explained on Wednesday.

                            Continue reading

                          • How to find NPM dependencies vulnerable to account hijacking

                            Security engineer outlines self-help strategy for keeping software supply chain safe

                            Following the recent disclosure of a technique for hijacking certain NPM packages, security engineer Danish Tariq has proposed a defensive strategy for those looking to assess whether their web apps include dependencies tied to subvertable email domains.

                            NPM, acquired by Microsoft’s GitHub in March 2020, operates the NPM Registry, an online repository of code libraries that web developers include in their applications. It currently hosts almost two million packages and serves more than 174 billion downloads per month.

                            The attack described earlier this month by security consultant Lance Vick involves identifying NPM packages managed by email accounts tied to expired domains. By registering the expired domain, the attacker then gains control of any email addresses associated with that domain.

                            Continue reading

                          • World Economic Forum wants a global map of online crime

                            Will cyber crimes shrug off Atlas Initiative? Objectively, yes

                            RSA Conference An ambitious project spearheaded by the World Economic Forum (WEF) is working to develop a map of the cybercrime ecosystem using open source information.

                            The Atlas initiative, whose contributors include Fortinet and Microsoft and other private-sector firms, involves mapping the relationships between criminal groups and their infrastructure with the end goal of helping both industry and the public sector — law enforcement and government agencies — disrupt these nefarious ecosystems.  

                            This kind of visibility into the connections between the gang members can help security researchers identify vulnerabilities in the criminals’ supply chain to develop better mitigation strategies and security controls for their customers. 

                            Continue reading

                          • Microsoft brings tabs to File Explorer

                            New Insider build adds a few toys, but leaves Pro X users reaching for the power button

                            Microsoft has treated some of the courageous Dev Channel crew of Windows Insiders to the long-awaited tabbed File Explorer.

                            “We are beginning to roll this feature out, so it isn’t available to all Insiders in the Dev Channel just yet,” the software giant said.

                            The Register was one of the lucky ones and we have to commend Microsoft on the implementation (overdue as it is). The purpose of the functionality is to allow users to work on more than one location at a time in File Explorer via tabs in the title bar.

                            Continue reading

                          • About half of popular websites tested found vulnerable to account pre-hijacking

                            In detail: Ocean’s Eleven-grade ruse in which victims’ profiles are rigged from the start

                            Two security researchers have identified five related techniques for hijacking internet accounts by preparing them to be commandeered in advance.

                            And they claim that when they analyzed 75 popular internet services, almost half were vulnerable to at least one of these techniques.

                            Avinash Sudhodanan, an independent security researcher, and Andrew Paverd, a senior researcher at Microsoft, describe their findings in a paper titled, “Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web.”

                            Continue reading

                          • Next major update of Windows 11 prepares for launch

                            Microsoft’s flagship OS still leagues behind predecessor in terms of adoption

                            The next major version of Windows 11 is drawing near with the code hitting the Insider Release Preview Channel.

                            Build 22621, which has been floating around the Beta Channel since May 11, arrived last night.

                            Back in May, Microsoft noted that the disappearance of the watermark from the desktop “doesn’t mean we’re done.” However, its arrival in the Release Preview Channel means that, fixes aside, it is pretty much feature-complete and ready to roll.

                            Continue reading

                          • DuckDuckGo tries to explain why its browsers won’t block some Microsoft web trackers

                            Meanwhile, Tails 5.0 users told to stop what they’re doing over Firefox flaw

                            DuckDuckGo promises privacy to users of its Android, iOS browsers, and macOS browsers – yet it allows certain data to flow from third-party websites to Microsoft-owned services.

                            Security researcher Zach Edwards recently conducted an audit of DuckDuckGo’s mobile browsers and found that, contrary to expectations, they do not block Meta’s Workplace domain, for example, from sending information to Microsoft’s Bing and LinkedIn domains.

                            Specifically, DuckDuckGo’s software didn’t stop Microsoft’s trackers on the Workplace page from blabbing information about the user to Bing and LinkedIn for tailored advertising purposes. Other trackers, such as Google’s, are blocked.

                            Continue reading

                          • Apple M1 chip contains hardware vulnerability that bypasses memory defense

                            MIT CSAIL boffins devise PACMAN attack to let existing exploits avoid pointer authentication

                            Apple’s M1 chip has been found to contain a hardware vulnerability that can be abused to disable one of its defense mechanisms against memory corruption exploits, giving such attacks a greater chance of success.

                            MIT CSAIL computer scientists on Friday said they have identified a way to bypass the M1 chip’s pointer authentication, a security mechanism that tries to prevent an attacker from modifying memory references without being detected.

                            In a paper titled “PACMAN: Attacking Arm Pointer Authentication with Speculative Execution,” Joseph Ravichandran, ​​Weon Taek Na, Jay Lang, and Mengjia Yan describe how they were able to use speculative execution – the way in which modern processors perform calculations before they may or may not be needed to accelerate execution – to discern the pointer authentication Code that allows pointer modification on a protected system.

                            Continue reading

                          ">

                          Visitors to insider.windows.com met with safety warning – how reassuring


                          Microsoft has forgotten to renew the certificate for the web page of its Windows Insider software testing program.

                          Attempting to visit the Windows Insider portal was returning the familiar “Your connection is not private” warning – as if webpages larded with scripts and trackers can truly be called “private.” The problem has now been fixed, and someone’s no doubt getting an earful.

                          Browsers like Chrome, Firefox, and Safari will attempt to deter visitors from accessing the webpage, but will provide a link for those who ignore the warnings and persist on clicking through to advanced options.

                          We did so and lived to tell about it.

                          The Insider web page certificate expired on Thursday, June 9, 2022 at 4: 59: 59 PM Pacific Daylight Time.

                          Expired Microsoft certificate

                          Click to enlarge

                          Microsoft did not immediately respond to a request for comment. But clicking through the warnings on Firefox initially took this reporter to Microsoft’s main Windows page with 302 and 307 redirect responses – Microsoft is redirecting requests to its expired page and so is aware of the issue.

                          • Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point
                          • Expired cert breaks Windows 11 snipping tool, emoji panel, S Mode features, other stuff
                          • Xero, Slack suffer outages just as Let’s Encrypt root cert expiry downs other websites, services
                          • Happy New Year: Jan 1, 2021 security cert expiration causes havoc for some Check Point VPN users

                          This sort of snafu happens occasionally. In November, 2021, an expired cert affected Windows 11 version 21H2 – it prevented Windows users from opening certain apps like the snipping tool.

                          And in 2020, an expired authentication certificate prevented customers from accessing Microsoft Teams.

                          Cert expirations tend to be worse when they affect root certificates and bork services for multiple vendors and customers. The expiration of Sectigo’s AddTrust legacy root certificate two years ago affected thousands of customers.

                          They’re also rather disruptive when they occur at telecom companies, the 2018 Ericsson cert expiration that hindered communications among tens of millions of UK customers.

                          Maybe Window’s scheduling systems aren’t all they are cracked up to be. ®


                          Other stories you might like

                          • Supply chain attacks will get worse: Microsoft Security Response Center boss

                            Do you know all of your software dependencies? Spoiler alert: hardly anybody is on top of it

                            RSA Conference Major supply-chain attacks of recent years – we’re talking about SolarWinds, Kaseya and Log4j to name a few – are “just the tip of the iceberg at this point,” according to Aanchal Gupta, who leads Microsoft’s Security Response Center.

                            “All of those have been big,” she said, in an interview with The Register at RSA Conference. “But I feel they will continue and there will be more. And there’s a reason I think that.”

                            As the head of MSRC, Gupta has a unique vantage point. Her view spans all of Microsoft’s products and services, as well as visibility across industry partners’ software and tools plus customers’ environments including government agencies. 

                            Continue reading

                          • Microsoft seizes 41 domains tied to ‘Iranian phishing ring’

                            Windows giant gets court order to take over dot-coms and more

                            Microsoft has obtained a court order to seize 41 domains used by what the Windows giant said was an Iranian cybercrime group that ran a spear-phishing operation targeting organizations in the US, Middle East, and India. 

                            The Microsoft Digital Crimes Unit said the gang, dubbed Bohrium, took a particular interest in those working in technology, transportation, government, and education sectors: its members would pretend to be job recruiters to lure marks into running malware on their PCs.

                            “Bohrium actors create fake social media profiles, often posing as recruiters,” said Amy Hogan-Burney, GM of Microsoft’s Digital Crimes Unit. “Once personal information was obtained from the victims, Bohrium sent malicious emails with links that ultimately infected their target’s computers with malware.”

                            Continue reading

                          • GitHub drops Atom bomb: Open-source text editor mothballed by end of year

                            Embrace, extend technology into other products … and extinguish

                            On December 15, Microsoft’s GitHub plans to turn out the lights on Atom, its open-source text editor that has inspired and influenced widely used commercial apps, such as Microsoft Visual Studio Code, Slack, and GitHub Desktop.

                            The social code biz said it’s doing so to focus on cloud-based software.

                            “While that goal of growing the software creator community remains, we’ve decided to retire Atom in order to further our commitment to bringing fast and reliable software development to the cloud via Microsoft Visual Studio Code and GitHub Codespaces,” GitHub explained on Wednesday.

                            Continue reading

                          • How to find NPM dependencies vulnerable to account hijacking

                            Security engineer outlines self-help strategy for keeping software supply chain safe

                            Following the recent disclosure of a technique for hijacking certain NPM packages, security engineer Danish Tariq has proposed a defensive strategy for those looking to assess whether their web apps include dependencies tied to subvertable email domains.

                            NPM, acquired by Microsoft’s GitHub in March 2020, operates the NPM Registry, an online repository of code libraries that web developers include in their applications. It currently hosts almost two million packages and serves more than 174 billion downloads per month.

                            The attack described earlier this month by security consultant Lance Vick involves identifying NPM packages managed by email accounts tied to expired domains. By registering the expired domain, the attacker then gains control of any email addresses associated with that domain.

                            Continue reading

                          • World Economic Forum wants a global map of online crime

                            Will cyber crimes shrug off Atlas Initiative? Objectively, yes

                            RSA Conference An ambitious project spearheaded by the World Economic Forum (WEF) is working to develop a map of the cybercrime ecosystem using open source information.

                            The Atlas initiative, whose contributors include Fortinet and Microsoft and other private-sector firms, involves mapping the relationships between criminal groups and their infrastructure with the end goal of helping both industry and the public sector — law enforcement and government agencies — disrupt these nefarious ecosystems.  

                            This kind of visibility into the connections between the gang members can help security researchers identify vulnerabilities in the criminals’ supply chain to develop better mitigation strategies and security controls for their customers. 

                            Continue reading

                          • Microsoft brings tabs to File Explorer

                            New Insider build adds a few toys, but leaves Pro X users reaching for the power button

                            Microsoft has treated some of the courageous Dev Channel crew of Windows Insiders to the long-awaited tabbed File Explorer.

                            “We are beginning to roll this feature out, so it isn’t available to all Insiders in the Dev Channel just yet,” the software giant said.

                            The Register was one of the lucky ones and we have to commend Microsoft on the implementation (overdue as it is). The purpose of the functionality is to allow users to work on more than one location at a time in File Explorer via tabs in the title bar.

                            Continue reading

                          • About half of popular websites tested found vulnerable to account pre-hijacking

                            In detail: Ocean’s Eleven-grade ruse in which victims’ profiles are rigged from the start

                            Two security researchers have identified five related techniques for hijacking internet accounts by preparing them to be commandeered in advance.

                            And they claim that when they analyzed 75 popular internet services, almost half were vulnerable to at least one of these techniques.

                            Avinash Sudhodanan, an independent security researcher, and Andrew Paverd, a senior researcher at Microsoft, describe their findings in a paper titled, “Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web.”

                            Continue reading

                          • Next major update of Windows 11 prepares for launch

                            Microsoft’s flagship OS still leagues behind predecessor in terms of adoption

                            The next major version of Windows 11 is drawing near with the code hitting the Insider Release Preview Channel.

                            Build 22621, which has been floating around the Beta Channel since May 11, arrived last night.

                            Back in May, Microsoft noted that the disappearance of the watermark from the desktop “doesn’t mean we’re done.” However, its arrival in the Release Preview Channel means that, fixes aside, it is pretty much feature-complete and ready to roll.

                            Continue reading

                          • DuckDuckGo tries to explain why its browsers won’t block some Microsoft web trackers

                            Meanwhile, Tails 5.0 users told to stop what they’re doing over Firefox flaw

                            DuckDuckGo promises privacy to users of its Android, iOS browsers, and macOS browsers – yet it allows certain data to flow from third-party websites to Microsoft-owned services.

                            Security researcher Zach Edwards recently conducted an audit of DuckDuckGo’s mobile browsers and found that, contrary to expectations, they do not block Meta’s Workplace domain, for example, from sending information to Microsoft’s Bing and LinkedIn domains.

                            Specifically, DuckDuckGo’s software didn’t stop Microsoft’s trackers on the Workplace page from blabbing information about the user to Bing and LinkedIn for tailored advertising purposes. Other trackers, such as Google’s, are blocked.

                            Continue reading

                          • Apple M1 chip contains hardware vulnerability that bypasses memory defense

                            MIT CSAIL boffins devise PACMAN attack to let existing exploits avoid pointer authentication

                            Apple’s M1 chip has been found to contain a hardware vulnerability that can be abused to disable one of its defense mechanisms against memory corruption exploits, giving such attacks a greater chance of success.

                            MIT CSAIL computer scientists on Friday said they have identified a way to bypass the M1 chip’s pointer authentication, a security mechanism that tries to prevent an attacker from modifying memory references without being detected.

                            In a paper titled “PACMAN: Attacking Arm Pointer Authentication with Speculative Execution,” Joseph Ravichandran, ​​Weon Taek Na, Jay Lang, and Mengjia Yan describe how they were able to use speculative execution – the way in which modern processors perform calculations before they may or may not be needed to accelerate execution – to discern the pointer authentication Code that allows pointer modification on a protected system.

                            Continue reading

                          ">

                          Visitors to insider.windows.com met with safety warning – how reassuring


                          Microsoft has forgotten to renew the certificate for the web page of its Windows Insider software testing program.

                          Attempting to visit the Windows Insider portal was returning the familiar “Your connection is not private” warning – as if webpages larded with scripts and trackers can truly be called “private.” The problem has now been fixed, and someone’s no doubt getting an earful.

                          Browsers like Chrome, Firefox, and Safari will attempt to deter visitors from accessing the webpage, but will provide a link for those who ignore the warnings and persist on clicking through to advanced options.

                          We did so and lived to tell about it.

                          The Insider web page certificate expired on Thursday, June 9, 2022 at 4: 59: 59 PM Pacific Daylight Time.

                          Expired Microsoft certificate

                          Click to enlarge

                          Microsoft did not immediately respond to a request for comment. But clicking through the warnings on Firefox initially took this reporter to Microsoft’s main Windows page with 302 and 307 redirect responses – Microsoft is redirecting requests to its expired page and so is aware of the issue.

                          • Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point
                          • Expired cert breaks Windows 11 snipping tool, emoji panel, S Mode features, other stuff
                          • Xero, Slack suffer outages just as Let’s Encrypt root cert expiry downs other websites, services
                          • Happy New Year: Jan 1, 2021 security cert expiration causes havoc for some Check Point VPN users

                          This sort of snafu happens occasionally. In November, 2021, an expired cert affected Windows 11 version 21H2 – it prevented Windows users from opening certain apps like the snipping tool.

                          And in 2020, an expired authentication certificate prevented customers from accessing Microsoft Teams.

                          Cert expirations tend to be worse when they affect root certificates and bork services for multiple vendors and customers. The expiration of Sectigo’s AddTrust legacy root certificate two years ago affected thousands of customers.

                          They’re also rather disruptive when they occur at telecom companies, the 2018 Ericsson cert expiration that hindered communications among tens of millions of UK customers.

                          Maybe Window’s scheduling systems aren’t all they are cracked up to be. ®


                          Other stories you might like

                          • Supply chain attacks will get worse: Microsoft Security Response Center boss

                            Do you know all of your software dependencies? Spoiler alert: hardly anybody is on top of it

                            RSA Conference Major supply-chain attacks of recent years – we’re talking about SolarWinds, Kaseya and Log4j to name a few – are “just the tip of the iceberg at this point,” according to Aanchal Gupta, who leads Microsoft’s Security Response Center.

                            “All of those have been big,” she said, in an interview with The Register at RSA Conference. “But I feel they will continue and there will be more. And there’s a reason I think that.”

                            As the head of MSRC, Gupta has a unique vantage point. Her view spans all of Microsoft’s products and services, as well as visibility across industry partners’ software and tools plus customers’ environments including government agencies. 

                            Continue reading

                          • Microsoft seizes 41 domains tied to ‘Iranian phishing ring’

                            Windows giant gets court order to take over dot-coms and more

                            Microsoft has obtained a court order to seize 41 domains used by what the Windows giant said was an Iranian cybercrime group that ran a spear-phishing operation targeting organizations in the US, Middle East, and India. 

                            The Microsoft Digital Crimes Unit said the gang, dubbed Bohrium, took a particular interest in those working in technology, transportation, government, and education sectors: its members would pretend to be job recruiters to lure marks into running malware on their PCs.

                            “Bohrium actors create fake social media profiles, often posing as recruiters,” said Amy Hogan-Burney, GM of Microsoft’s Digital Crimes Unit. “Once personal information was obtained from the victims, Bohrium sent malicious emails with links that ultimately infected their target’s computers with malware.”

                            Continue reading

                          • GitHub drops Atom bomb: Open-source text editor mothballed by end of year

                            Embrace, extend technology into other products … and extinguish

                            On December 15, Microsoft’s GitHub plans to turn out the lights on Atom, its open-source text editor that has inspired and influenced widely used commercial apps, such as Microsoft Visual Studio Code, Slack, and GitHub Desktop.

                            The social code biz said it’s doing so to focus on cloud-based software.

                            “While that goal of growing the software creator community remains, we’ve decided to retire Atom in order to further our commitment to bringing fast and reliable software development to the cloud via Microsoft Visual Studio Code and GitHub Codespaces,” GitHub explained on Wednesday.

                            Continue reading

                          • How to find NPM dependencies vulnerable to account hijacking

                            Security engineer outlines self-help strategy for keeping software supply chain safe

                            Following the recent disclosure of a technique for hijacking certain NPM packages, security engineer Danish Tariq has proposed a defensive strategy for those looking to assess whether their web apps include dependencies tied to subvertable email domains.

                            NPM, acquired by Microsoft’s GitHub in March 2020, operates the NPM Registry, an online repository of code libraries that web developers include in their applications. It currently hosts almost two million packages and serves more than 174 billion downloads per month.

                            The attack described earlier this month by security consultant Lance Vick involves identifying NPM packages managed by email accounts tied to expired domains. By registering the expired domain, the attacker then gains control of any email addresses associated with that domain.

                            Continue reading

                          • World Economic Forum wants a global map of online crime

                            Will cyber crimes shrug off Atlas Initiative? Objectively, yes

                            RSA Conference An ambitious project spearheaded by the World Economic Forum (WEF) is working to develop a map of the cybercrime ecosystem using open source information.

                            The Atlas initiative, whose contributors include Fortinet and Microsoft and other private-sector firms, involves mapping the relationships between criminal groups and their infrastructure with the end goal of helping both industry and the public sector — law enforcement and government agencies — disrupt these nefarious ecosystems.  

                            This kind of visibility into the connections between the gang members can help security researchers identify vulnerabilities in the criminals’ supply chain to develop better mitigation strategies and security controls for their customers. 

                            Continue reading

                          • Microsoft brings tabs to File Explorer

                            New Insider build adds a few toys, but leaves Pro X users reaching for the power button

                            Microsoft has treated some of the courageous Dev Channel crew of Windows Insiders to the long-awaited tabbed File Explorer.

                            “We are beginning to roll this feature out, so it isn’t available to all Insiders in the Dev Channel just yet,” the software giant said.

                            The Register was one of the lucky ones and we have to commend Microsoft on the implementation (overdue as it is). The purpose of the functionality is to allow users to work on more than one location at a time in File Explorer via tabs in the title bar.

                            Continue reading

                          • About half of popular websites tested found vulnerable to account pre-hijacking

                            In detail: Ocean’s Eleven-grade ruse in which victims’ profiles are rigged from the start

                            Two security researchers have identified five related techniques for hijacking internet accounts by preparing them to be commandeered in advance.

                            And they claim that when they analyzed 75 popular internet services, almost half were vulnerable to at least one of these techniques.

                            Avinash Sudhodanan, an independent security researcher, and Andrew Paverd, a senior researcher at Microsoft, describe their findings in a paper titled, “Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web.”

                            Continue reading

                          • Next major update of Windows 11 prepares for launch

                            Microsoft’s flagship OS still leagues behind predecessor in terms of adoption

                            The next major version of Windows 11 is drawing near with the code hitting the Insider Release Preview Channel.

                            Build 22621, which has been floating around the Beta Channel since May 11, arrived last night.

                            Back in May, Microsoft noted that the disappearance of the watermark from the desktop “doesn’t mean we’re done.” However, its arrival in the Release Preview Channel means that, fixes aside, it is pretty much feature-complete and ready to roll.

                            Continue reading

                          • DuckDuckGo tries to explain why its browsers won’t block some Microsoft web trackers

                            Meanwhile, Tails 5.0 users told to stop what they’re doing over Firefox flaw

                            DuckDuckGo promises privacy to users of its Android, iOS browsers, and macOS browsers – yet it allows certain data to flow from third-party websites to Microsoft-owned services.

                            Security researcher Zach Edwards recently conducted an audit of DuckDuckGo’s mobile browsers and found that, contrary to expectations, they do not block Meta’s Workplace domain, for example, from sending information to Microsoft’s Bing and LinkedIn domains.

                            Specifically, DuckDuckGo’s software didn’t stop Microsoft’s trackers on the Workplace page from blabbing information about the user to Bing and LinkedIn for tailored advertising purposes. Other trackers, such as Google’s, are blocked.

                            Continue reading

                          • Apple M1 chip contains hardware vulnerability that bypasses memory defense

                            MIT CSAIL boffins devise PACMAN attack to let existing exploits avoid pointer authentication

                            Apple’s M1 chip has been found to contain a hardware vulnerability that can be abused to disable one of its defense mechanisms against memory corruption exploits, giving such attacks a greater chance of success.

                            MIT CSAIL computer scientists on Friday said they have identified a way to bypass the M1 chip’s pointer authentication, a security mechanism that tries to prevent an attacker from modifying memory references without being detected.

                            In a paper titled “PACMAN: Attacking Arm Pointer Authentication with Speculative Execution,” Joseph Ravichandran, ​​Weon Taek Na, Jay Lang, and Mengjia Yan describe how they were able to use speculative execution – the way in which modern processors perform calculations before they may or may not be needed to accelerate execution – to discern the pointer authentication Code that allows pointer modification on a protected system.

                            Continue reading

                          ">

                          Visitors to insider.windows.com met with safety warning – how reassuring


                          Microsoft has forgotten to renew the certificate for the web page of its Windows Insider software testing program.

                          Attempting to visit the Windows Insider portal was returning the familiar “Your connection is not private” warning – as if webpages larded with scripts and trackers can truly be called “private.” The problem has now been fixed, and someone’s no doubt getting an earful.

                          Browsers like Chrome, Firefox, and Safari will attempt to deter visitors from accessing the webpage, but will provide a link for those who ignore the warnings and persist on clicking through to advanced options.

                          We did so and lived to tell about it.

                          The Insider web page certificate expired on Thursday, June 9, 2022 at 4: 59: 59 PM Pacific Daylight Time.

                          Expired Microsoft certificate

                          Click to enlarge

                          Microsoft did not immediately respond to a request for comment. But clicking through the warnings on Firefox initially took this reporter to Microsoft’s main Windows page with 302 and 307 redirect responses – Microsoft is redirecting requests to its expired page and so is aware of the issue.

                          • Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point
                          • Expired cert breaks Windows 11 snipping tool, emoji panel, S Mode features, other stuff
                          • Xero, Slack suffer outages just as Let’s Encrypt root cert expiry downs other websites, services
                          • Happy New Year: Jan 1, 2021 security cert expiration causes havoc for some Check Point VPN users

                          This sort of snafu happens occasionally. In November, 2021, an expired cert affected Windows 11 version 21H2 – it prevented Windows users from opening certain apps like the snipping tool.

                          And in 2020, an expired authentication certificate prevented customers from accessing Microsoft Teams.

                          Cert expirations tend to be worse when they affect root certificates and bork services for multiple vendors and customers. The expiration of Sectigo’s AddTrust legacy root certificate two years ago affected thousands of customers.

                          They’re also rather disruptive when they occur at telecom companies, the 2018 Ericsson cert expiration that hindered communications among tens of millions of UK customers.

                          Maybe Window’s scheduling systems aren’t all they are cracked up to be. ®


                          Other stories you might like

                          • Supply chain attacks will get worse: Microsoft Security Response Center boss

                            Do you know all of your software dependencies? Spoiler alert: hardly anybody is on top of it

                            RSA Conference Major supply-chain attacks of recent years – we’re talking about SolarWinds, Kaseya and Log4j to name a few – are “just the tip of the iceberg at this point,” according to Aanchal Gupta, who leads Microsoft’s Security Response Center.

                            “All of those have been big,” she said, in an interview with The Register at RSA Conference. “But I feel they will continue and there will be more. And there’s a reason I think that.”

                            As the head of MSRC, Gupta has a unique vantage point. Her view spans all of Microsoft’s products and services, as well as visibility across industry partners’ software and tools plus customers’ environments including government agencies. 

                            Continue reading

                          • Microsoft seizes 41 domains tied to ‘Iranian phishing ring’

                            Windows giant gets court order to take over dot-coms and more

                            Microsoft has obtained a court order to seize 41 domains used by what the Windows giant said was an Iranian cybercrime group that ran a spear-phishing operation targeting organizations in the US, Middle East, and India. 

                            The Microsoft Digital Crimes Unit said the gang, dubbed Bohrium, took a particular interest in those working in technology, transportation, government, and education sectors: its members would pretend to be job recruiters to lure marks into running malware on their PCs.

                            “Bohrium actors create fake social media profiles, often posing as recruiters,” said Amy Hogan-Burney, GM of Microsoft’s Digital Crimes Unit. “Once personal information was obtained from the victims, Bohrium sent malicious emails with links that ultimately infected their target’s computers with malware.”

                            Continue reading

                          • GitHub drops Atom bomb: Open-source text editor mothballed by end of year

                            Embrace, extend technology into other products … and extinguish

                            On December 15, Microsoft’s GitHub plans to turn out the lights on Atom, its open-source text editor that has inspired and influenced widely used commercial apps, such as Microsoft Visual Studio Code, Slack, and GitHub Desktop.

                            The social code biz said it’s doing so to focus on cloud-based software.

                            “While that goal of growing the software creator community remains, we’ve decided to retire Atom in order to further our commitment to bringing fast and reliable software development to the cloud via Microsoft Visual Studio Code and GitHub Codespaces,” GitHub explained on Wednesday.

                            Continue reading

                          • How to find NPM dependencies vulnerable to account hijacking

                            Security engineer outlines self-help strategy for keeping software supply chain safe

                            Following the recent disclosure of a technique for hijacking certain NPM packages, security engineer Danish Tariq has proposed a defensive strategy for those looking to assess whether their web apps include dependencies tied to subvertable email domains.

                            NPM, acquired by Microsoft’s GitHub in March 2020, operates the NPM Registry, an online repository of code libraries that web developers include in their applications. It currently hosts almost two million packages and serves more than 174 billion downloads per month.

                            The attack described earlier this month by security consultant Lance Vick involves identifying NPM packages managed by email accounts tied to expired domains. By registering the expired domain, the attacker then gains control of any email addresses associated with that domain.

                            Continue reading

                          • World Economic Forum wants a global map of online crime

                            Will cyber crimes shrug off Atlas Initiative? Objectively, yes

                            RSA Conference An ambitious project spearheaded by the World Economic Forum (WEF) is working to develop a map of the cybercrime ecosystem using open source information.

                            The Atlas initiative, whose contributors include Fortinet and Microsoft and other private-sector firms, involves mapping the relationships between criminal groups and their infrastructure with the end goal of helping both industry and the public sector — law enforcement and government agencies — disrupt these nefarious ecosystems.  

                            This kind of visibility into the connections between the gang members can help security researchers identify vulnerabilities in the criminals’ supply chain to develop better mitigation strategies and security controls for their customers. 

                            Continue reading

                          • Microsoft brings tabs to File Explorer

                            New Insider build adds a few toys, but leaves Pro X users reaching for the power button

                            Microsoft has treated some of the courageous Dev Channel crew of Windows Insiders to the long-awaited tabbed File Explorer.

                            “We are beginning to roll this feature out, so it isn’t available to all Insiders in the Dev Channel just yet,” the software giant said.

                            The Register was one of the lucky ones and we have to commend Microsoft on the implementation (overdue as it is). The purpose of the functionality is to allow users to work on more than one location at a time in File Explorer via tabs in the title bar.

                            Continue reading

                          • About half of popular websites tested found vulnerable to account pre-hijacking

                            In detail: Ocean’s Eleven-grade ruse in which victims’ profiles are rigged from the start

                            Two security researchers have identified five related techniques for hijacking internet accounts by preparing them to be commandeered in advance.

                            And they claim that when they analyzed 75 popular internet services, almost half were vulnerable to at least one of these techniques.

                            Avinash Sudhodanan, an independent security researcher, and Andrew Paverd, a senior researcher at Microsoft, describe their findings in a paper titled, “Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web.”

                            Continue reading

                          • Next major update of Windows 11 prepares for launch

                            Microsoft’s flagship OS still leagues behind predecessor in terms of adoption

                            The next major version of Windows 11 is drawing near with the code hitting the Insider Release Preview Channel.

                            Build 22621, which has been floating around the Beta Channel since May 11, arrived last night.

                            Back in May, Microsoft noted that the disappearance of the watermark from the desktop “doesn’t mean we’re done.” However, its arrival in the Release Preview Channel means that, fixes aside, it is pretty much feature-complete and ready to roll.

                            Continue reading

                          • DuckDuckGo tries to explain why its browsers won’t block some Microsoft web trackers

                            Meanwhile, Tails 5.0 users told to stop what they’re doing over Firefox flaw

                            DuckDuckGo promises privacy to users of its Android, iOS browsers, and macOS browsers – yet it allows certain data to flow from third-party websites to Microsoft-owned services.

                            Security researcher Zach Edwards recently conducted an audit of DuckDuckGo’s mobile browsers and found that, contrary to expectations, they do not block Meta’s Workplace domain, for example, from sending information to Microsoft’s Bing and LinkedIn domains.

                            Specifically, DuckDuckGo’s software didn’t stop Microsoft’s trackers on the Workplace page from blabbing information about the user to Bing and LinkedIn for tailored advertising purposes. Other trackers, such as Google’s, are blocked.

                            Continue reading

                          • Apple M1 chip contains hardware vulnerability that bypasses memory defense

                            MIT CSAIL boffins devise PACMAN attack to let existing exploits avoid pointer authentication

                            Apple’s M1 chip has been found to contain a hardware vulnerability that can be abused to disable one of its defense mechanisms against memory corruption exploits, giving such attacks a greater chance of success.

                            MIT CSAIL computer scientists on Friday said they have identified a way to bypass the M1 chip’s pointer authentication, a security mechanism that tries to prevent an attacker from modifying memory references without being detected.

                            In a paper titled “PACMAN: Attacking Arm Pointer Authentication with Speculative Execution,” Joseph Ravichandran, ​​Weon Taek Na, Jay Lang, and Mengjia Yan describe how they were able to use speculative execution – the way in which modern processors perform calculations before they may or may not be needed to accelerate execution – to discern the pointer authentication Code that allows pointer modification on a protected system.

                            Continue reading

                          Tags: forgotMicrosoft
                          ">
                          Ferhan Rana

                          Ferhan Rana

                          Related Posts

                          Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
                          Technology

                          Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’

                          by Ferhan Rana
                          May 18, 2026
                          Surprise AI bills leave AWS and Google Cloud users aghast
                          Technology

                          Surprise AI bills leave AWS and Google Cloud users aghast

                          by Ferhan Rana
                          May 18, 2026
                          New ‘Gundam Wing’ ‘Visual Project’ in the Works
                          Technology

                          New ‘Gundam Wing’ ‘Visual Project’ in the Works

                          by Ferhan Rana
                          May 16, 2026
                          Dave Filoni Teases His Plan for the Future of ‘Star Wars’
                          Technology

                          Dave Filoni Teases His Plan for the Future of ‘Star Wars’

                          by Ferhan Rana
                          May 16, 2026
                          Possible Samsung strike puts even more pressure on memory pricing
                          Technology

                          Possible Samsung strike puts even more pressure on memory pricing

                          by Ferhan Rana
                          May 15, 2026

                          Premium Content

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          September 29, 2024
                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          July 25, 2024
                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          May 21, 2025

                          Browse by Category

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tags

                          announces Apple Beckham Charles Elizabeth Europe Exclusive family First George Google Harry health Inside Intel James Jennifer Kelly Lewis makes Manchester Markle Meghan Michael Microsoft Middleton people Prince Princess Queen REPORT reveals Review Royal Samsung Sarah Shares Taylor Trump Twitter wants WATCH William World Years
                          TrivDaily

                          Get the latest World news and analysis, breaking news, features and special reports from World. Also watch videos from across the Europian continent.

                          Learn more

                          Categories

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tag

                          Business (1613) Crypto (1705) Entertainment (2041) Fashion (3) Health (1961) Lifestyle (1932) Real Estate (40) Sports (3226) Technology (3144) Travel (1530) Uncategorized (11) World (23)

                          Recent Posts

                          • Jason Momoa Says He ‘Would Never’ Play Snake Plissken in an ‘Escape from New York’ Remake
                          • Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet
                          • ‘Nuns Are Awesome’: High Rents Push New Yorkers to Live With Nuns as Convent Rooms Cost Less

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Welcome Back!

                          Login to your account below

                          Forgotten Password? Sign Up

                          Create New Account!

                          Fill the forms bellow to register

                          All fields are required. Log In

                          Retrieve your password

                          Please enter your username or email address to reset your password.

                          Log In

                          Add New Playlist

                          • Login
                          • Sign Up
                          • Cart
                          No Result
                          View All Result
                          • Home
                          • Business News
                          • Entertainment News
                          • Lifestyle News
                          • Health News
                          • Tech News
                          • Real Estate News
                          • World News

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Are you sure want to unlock this post?
                          Unlock left : 0
                          Are you sure want to cancel subscription?