Big Patch Tuesday - updating the cryptographic functions in Windows
-
https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-of-first-2020-patch-tuesday/
Krebs has the scoop on the rumors, as usual.
-
Hmmm...... Makes me contemplate whether Windows 7 security updates end at 12:00am on Jan 14 or at 11:59pm on Jan 14th.
This could immediately place Windows 7 OSes at more risk, than people may have thought, this soon after the end of security updates.
-
@JasGot good question.
-
Sounds like convenient timing IMO.
Win7 support ends, no more security updates. New big security issue in all Windows versions, not patched in unsupported versions.
-
-
@Nic said in Big Patch Tuesday - updating the cryptographic functions in Windows:
Here's the full story:
https://www.washingtonpost.com/national-security/nsa-found-a-dangerous-microsoft-software-flaw-and-alerted-the-firm--rather-than-weaponize-it/2020/01/14/f024c926-3679-11ea-bb7b-265f4554af6d_story.htmlProbably because the NSA is using windows...
-
@Obsolesce said in Big Patch Tuesday - updating the cryptographic functions in Windows:
@Nic said in Big Patch Tuesday - updating the cryptographic functions in Windows:
Here's the full story:
https://www.washingtonpost.com/national-security/nsa-found-a-dangerous-microsoft-software-flaw-and-alerted-the-firm--rather-than-weaponize-it/2020/01/14/f024c926-3679-11ea-bb7b-265f4554af6d_story.htmlProbably because the NSA is using windows...
Or this is already in the wild.
-
@coliver said in Big Patch Tuesday - updating the cryptographic functions in Windows:
@Obsolesce said in Big Patch Tuesday - updating the cryptographic functions in Windows:
@Nic said in Big Patch Tuesday - updating the cryptographic functions in Windows:
Here's the full story:
https://www.washingtonpost.com/national-security/nsa-found-a-dangerous-microsoft-software-flaw-and-alerted-the-firm--rather-than-weaponize-it/2020/01/14/f024c926-3679-11ea-bb7b-265f4554af6d_story.htmlProbably because the NSA is using windows...
Or this is already in the wild.
More likely the reason.
-
@JaredBusch my bet is the NSA was using it, but now some other nation state has found it and is using it. Which is why NSA now wants us all to patch it.
-
@Nic said in Big Patch Tuesday - updating the cryptographic functions in Windows:
@JaredBusch my bet is the NSA was using it, but now some other nation state has found it and is using it. Which is why NSA now wants us all to patch it.
That is definitely a better clarification of the likely reason now that you mention it
-
@Nic said in Big Patch Tuesday - updating the cryptographic functions in Windows:
@JaredBusch my bet is the NSA was using it, but now some other nation state has found it and is using it. Which is why NSA now wants us all to patch it.
Yeah this was my point earlier. This tracks with their behavior with EternalBlue.