No Image

Announcing Windows 10 Insider Preview Build 19042.685 (20H2)

2020-12-09 KENNETH 0

Announcing Windows 10 Insider Preview Build 19042.685 (20H2) Hello Windows Insiders, today we’re releasing 20H2 Build 19042.685 (KB4592438) to the Beta and Release Preview Channels for those Insiders who are on 20H2 (Windows 10 October 2020 Update). This security update includes quality improvements. Key changes include: We fixed a security vulnerability by preventing applications that run as a SYSTEM account from printing to “FILE:” ports. To address this issue in the future, make sure your applications or services run as a specific user or service account. Security updates to Microsoft Edge Legacy, the Microsoft Graphics Component, Windows Media, Windows Fundamentals, and Windows Virtualization. For more information about the resolved security vulnerabilities, please refer to the new Security Update Guide website. Announcing a new way to deploy Servicing Stack Updates via WSUS In the past, organizations using WSUS have been able [ more… ]

No Image

Minecraft kicks off Community Celebration with free content

2020-12-09 KENNETH 0

Minecraft kicks off Community Celebration with free content Mojang Studios is ending the year by celebrating the Minecraft community in weekly free giveaways. Minecraft Starter Collection for Windows 10 players can look for free content made by community creators for both Bedrock and Java editions of the game, with new character creator items and maps over the course of four weeks, released each Monday. You could also get a free week of Java Realms between Dec. 8 and Jan. 13. Find out more at Minecraft.net. Source: Minecraft kicks off Community Celebration with free content

No Image

USN-4664-1: Aptdaemon vulnerabilities

2020-12-09 KENNETH 0

USN-4664-1: Aptdaemon vulnerabilities Kevin Backhouse discovered that Aptdaemon incorrectly handled certain properties. A local attacker could use this issue to test for the presence of local files. (CVE-2020-16128) Kevin Backhouse discovered that Aptdaemon incorrectly handled permission checks. A local attacker could possibly use this issue to cause a denial of service. (CVE-2020-27349) Source: USN-4664-1: Aptdaemon vulnerabilities

No Image

Announcing NGINX Plus R23

2020-12-09 KENNETH 0

Announcing NGINX Plus R23 We’re happy to announce the availability of NGINX Plus Release 23 (R23). Based on NGINX Open Source, NGINX Plus is the only <span style="white-space: nowrap;"all-in-one software load balancer, reverse proxy, and API gateway. New features in NGINX Plus R23 include: gRPC health checks – Actively testing that a gRPC service can handle requests before sending them significantly boosts reliability. Unprivileged installation support – NGINX Plus can now be installed by, and upgraded as, an unprivileged (non‑root) user. This fully supported solution aligns with the growing trend toward zero‑trust security models. OpenID Connect PKCE support – NGINX Plus R23 implements the Proof Key for Code Exchange (PKCE) extension to the OpenID Connect Authorization Code flow. PKCE prevents several types of attack and enables secure OAuth exchanges with public clients. Rounding out this release are finer‑grained control over SSL/TLS, a native method [ more… ]

No Image

USN-4663-1: GDK-PixBuf vulnerability

2020-12-09 KENNETH 0

USN-4663-1: GDK-PixBuf vulnerability Melvin Kool discovered that the GDK-PixBuf library did not properly handle certain GIF images. If an user or automated system were tricked into opening a specially crafted GIF file, a remote attacker could use this flaw to cause GDK-PixBuf to hang, resulting in a denial of service. Source: USN-4663-1: GDK-PixBuf vulnerability