❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 25 September 2026AskWoody

When was the start of the security industry?

24 September 2026 at 04:00
What do you think was the official start of the security industry? Some will say it was when the Morris Worm hit in November 1988.Β  It started people thinking more about firewalls and a vulnerability disclosure process. The official start of the AI security industry?Β  Hugging Face and the resulting fallout. We’re still coming to […]
Before yesterdayAskWoody

The hits for September just keep on coming

23 September 2026 at 04:00
Although the fix for the File History bug has been fixed in a preview update for Windows 11, there is no such advanced fix for those of you on Windows 10. Your choice is to uninstall the September updates if you happened to inadvertently install them, or to just wait out the month with a […]

Not all passkeys are created equally

21 September 2026 at 03:42
ON SECURITY By Susan Bradley Not a day goes by without a prompt to set up a passkey. As with everything in security, there are trade-offs. These mostly have to do with balancing security and convenience. This will manifest itself in the decisions you must make when setting up passkeys. Some decisions are made for […]

Master Patch List for September 2026

11 September 2026 at 04:00
I’ve updated the master patch list here.Β Β Please note I am not recommending installing updates at this time, we are just testing and reporting. I’ll be updating that page and monitoring for issues. So far the trending issues are: RDS servers having issues after the September updates. If you run an RDS farm, hold back. I […]

September 2026 Windows updates are released

8 September 2026 at 13:53
Once again it’s time to pause, ensure we have our backups and review what has been released. Even if you no longer use Windows, use a time of the month to review your browser updates, your operating system updates. All platforms need maintenance. Windows is releasing it’s normal monthly security updates. KB5124008 for Windows 11 […]

Can passkeys be shared?

4 September 2026 at 04:00
Well, sort of β€” with a password manager that can do so. While the rest of the world looks at the US Labor Day weekend as a time to relax, I look to it for a time to test. And what am I testing? If I enable passkeys on my personal PayPal account, can my […]

Keeping the threats at the edge

24 August 2026 at 03:45
ISSUE 23.34 β€’ 2026-08-24 ON SECURITY By Susan Bradley It all started when I was assisting someone who was trying to determine whether their Wi-Fi mesh routers were operating at the best possible speed. I tried to log in to the Web-based interface to the mesh system, which indicated that browser access was disabled. Uh-oh. […]

Will Iranian hackers shut off your city’s water supply?

24 August 2026 at 03:44
PUBLIC DEFENDER By Brian Livingston Public water utilities in several US states were hit with coordinated hacker attacks on July 26–27, 2026. The intrusions temporarily knocked Internet-connected control devices offline, forcing some agencies to warn customers to boil tap water. No permanent poisonings occurred, but the exploits may be a hacker group’s test run or […]

Your device is severely damaged

20 August 2026 at 04:00
Was searching on a topic on my phone today and hit this. There is a reason that Apple has moved to a twice a month patching schedule. The Microsoft Threat Intelligence team indicates that it is β€œmonitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry […]

Have you been flocked?

19 August 2026 at 04:00
You’ve heard of the Pwned site, now there is a site where you can see whether you’ve been in Flocked videos. Except there is one catch:Β  For the site to list your automobile, you would have had to been included in a Freedom of Information Act search. β€œThis website only displays searches from audit logs […]

Cyber pirates in our future

14 August 2026 at 04:00
The White House announced a change in policy wanting private companies to help in hacking our adversaries.Β  I’ve seen a few comments on it, such as Robert Graham’s take posted on Substack I’ve seen others indicate that it might make it harder to determine who is hacking whom, such as this author. I’m not so […]

Master patch list for August 2026

13 August 2026 at 04:00
I’ve updated the master patch list here.Β Β Please note I am not recommending installing updates at this time, we are just testing and reporting. I’ll be updating that page and monitoring for issues. Right now I’ve seen .NET want to install, reboot and then offer up the operating system update. This month we’ve had a smaller […]

Should I reboot?

12 August 2026 at 23:28
Reminder – we are still in pause mode.Β  But for those that are in test mode I’ve noticed one thing.Β  Some of you might get the .NET patch, it get installed and then the operating system is still downloading the main security patch. I’ve also seen a machine only see the .NET update and then […]

August 2026 Security updates

11 August 2026 at 13:47
Once again it’s time to pause, ensure we have our backups and review what has been released. Even if you no longer use Windows use a time of the month to review your browser updates, your operating system updates. All platforms need maintenance. Windows is releasing it’s normal monthly security updates. For Windows 10 KB5120249 […]

Vulnerabilities in our utilities

5 August 2026 at 04:00
I’m sure you’ve seen the news that there have been recent cyber-attacks from external attackers on various water systems in the United States.Β  Just the other day, PG&E changed out the gas smart meter at my home. All these smart devices provide a ton of benefit but also the potential for risk. Does your local […]

Separating that network

3 August 2026 at 03:42
ON SECURITY By Susan Bradley OpenAI’s recent attack on another company’s cloud instances reminds me that sometimes we forget the basics. As we understand the situation at the moment, OpenAI’s test platform was meant to be isolated and not connected to the Internet. But because it needed to download certain items, it was given read-only […]

AI and the Hugging Face breach

31 July 2026 at 04:00
If you missed it the other day, SANS has a recording of its recent live-panel discussion of the OpenAI/Hugging Face breach. It points to nine questions to ask your security teams. But what about us as users of all of these systems where we don’t have a lot of control? For me, it gets back […]

Anyone may be able to access your camera with a simple step

27 July 2026 at 03:44
PUBLIC DEFENDER By Brian Livingston Millions of people around the world have installed Internet-connected β€œsecurity cameras” to monitor foot traffic around their homes and offices. Unfortunately, many of these video devices make it easy for unwanted persons to see your live feed and record whatever comes into view. It’s convenient to know who’s at your […]

Tracking the attacker

27 July 2026 at 03:22
ON SECURITY Tracking the attacker By Susan Bradley Recently, Apple, Adobe, Microsoft, and others released updates illustrating how much we are being impacted by AI. The three major vendors either sped up releases or released updates with a massive number of vulnerabilities. But does that make us more unsecure? Before I discuss some side effects […]

Some Dell devices with a specific Intel driver might experience poor performance

18 July 2026 at 19:44
Some Dell devices with a specific Intel driver might experience poor performance Affected platforms Client Versions Message ID Originating KB Resolved KB Windows 11, version 25H2 WI1427598 KB5095093 KB5121767 Windows 11, version 24H2 WI1427599 KB5095093 KB5121767 After installing the June 23, 2026, Windows non-security preview update (the Originating KBs listed above), a limited number of […]
❌
❌