NSA Reports Major Windows 10 Flaw to Microsoft, Patch Coming Today

NSA Reports Major Windows 10 Flaw to Microsoft, Patch Coming Today

It’s “Patch Tuesday” for Microsoft, and this is an important one. Not only is this the end of the road for Windows 7, but Microsoft is releasing a major fix for Windows 10 thanks to the National Security Agency (NSA). The NSA reportedly uncovered a serious flaw in Windows 10, and it took the unusual but welcome step of telling Microsoft about it.

Despite its name, the NSA is not aimed at improving security for the general public. Its goal of gathering intelligence and monitoring national communication networks is not served by patching vulnerabilities when it can weaponize them instead. That’s why, traditionally, the NSA keeps these security holes a secret so it can use them against targets.

The vulnerability affects the way Windows 10 verifies digital signatures. That could allow a malicious software package to masquerade as a legitimate installer without tripping any alarms. Thus, someone could leverage the bug to remotely install malware and give it access to the entire system. From the NSA’s perspective, that’s a useful tool for cyberespionage, provided your target is using Windows 10. There’s a reasonable chance they will be, considering Windows 10 is the most popular desktop operating system in the world.

The new Windows 10 flaw is similar to EternalBlue, which fueled the WannaCry ransomware.
The new Windows 10 flaw is similar to EternalBlue, which fueled the WannaCry ransomware.

People briefed on the matter liken this vulnerability to EternalBlue, a flaw that affected most versions of Windows until 2017. The NSA used EternalBlue to break into computers for five years, but then the tool found its way into the hands of other organizations. As a result, EternalBlue fueled major malware campaigns like the WannaCry and NotPetya ransomware outbreaks. While the new vulnerability isn’t as severe as EternalBlue (it only affects Windows 10), it could allow for similar attacks if it ever got out. Perhaps that’s why the NSA opted to alert Microsoft instead of trying to weaponize the flaw.

Microsoft should release the patch today for all Windows 10 users. We also expect a statement on the vulnerability, urging everyone to update as soon as possible. While it’s better than the NSA disclosed the flaw to Microsoft, it could still serve as the basis for online attacks if users don’t update their systems. The NSA claims there are no currently active exploits online that use this vulnerability, but that could change in an instant.

Continue reading

New Intel Rocket Lake Details: Backwards Compatible, Xe Graphics, Cypress Cove
New Intel Rocket Lake Details: Backwards Compatible, Xe Graphics, Cypress Cove

Intel has released a bit more information about Rocket Lake and its 10nm CPU that's been back-ported to 14nm.

Time to Update: Google Patches 2 Severe Zero-Day Chrome Vulnerabilities
Time to Update: Google Patches 2 Severe Zero-Day Chrome Vulnerabilities

Unlike the last few zero-days, Google didn't find these security holes itself. Instead, it was tipped by anonymous third-parties, and the problems are severe enough that it hasn't released full details. Suffice it to say, you should stop putting off that update.

Early Adopters of Apple M1 Macs Should Be Cautious About Compatibility
Early Adopters of Apple M1 Macs Should Be Cautious About Compatibility

Apple's new MacBooks and Mac mini have made waves, partly thanks to the new silicon inside of them. Apple's new ARM ecosystem, however, is not without its growing pains.

Android 12 Could Include Major App Compatibility Improvements
Android 12 Could Include Major App Compatibility Improvements

Google has attempted to centralize chunks of Android over the years, and a major component called ART is set to get this treatment in Android 12. The result could be vastly improved app compatibility, which is sure to make everyone happy.