<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/bugs" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Bugs ]]></title>
                <link>https://www.itpro.com/tag/bugs</link>
        <description><![CDATA[ All the latest bugs content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 17 Dec 2025 10:03:45 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ The Microsoft bug bounty program just got a big update — and even applies to third-party code ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-microsoft-bug-bounty-program-just-got-a-big-update-and-even-applies-to-third-party-code</link>
                                                                            <description>
                            <![CDATA[ Microsoft is expanding its bug bounty program to cover all of its products, even those that haven't previously been covered by a bounty before and even third-party code. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">F65SM8RxEKtqoJWYz533YM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T2Nao4kWZWfYEHB3h7bLdQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Dec 2025 10:03:45 +0000</pubDate>                                                                                                                                <updated>Wed, 17 Dec 2025 10:04:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T2Nao4kWZWfYEHB3h7bLdQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo pictured above the entrance to the company&#039;s office in New York City, USA.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo pictured above the entrance to the company&#039;s office in New York City, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo pictured above the entrance to the company&#039;s office in New York City, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T2Nao4kWZWfYEHB3h7bLdQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft is expanding its bug bounty program to cover all of its products, even those that haven't previously been covered by a bounty before and even third-party code. </p><p>Security flaws continue to plague the digital world: Microsoft recently patched its Edge browser after Google spotted a zero-day being used by attackers in Chrome. </p><p>Last year, Microsoft paid out more than $17 million via its bug bounty program, versus <a href="https://www.mediapost.com/publications/article/404028/"><u>$11.8 million by Google</u></a> via its Vulnerability Reward Program, with payouts in the hundreds of thousands of dollars. </p><p>Microsoft has recently expanded its researcher reward programme to <a href="https://www.itpro.com/security/microsoft-copilot-bug-bounty-program-expansion"><u>increase payouts for Copilot bugs</u></a>.</p><p>But cloud and AI have changed the landscape, so Microsoft is widening the bounty program to include payments for critical vulnerabilities in online services, even if it didn't write the code. </p><p>"In an AI and cloud-first world, threat actors don’t limit themselves to specific products or services. They don’t care who owns the code they try to exploit," wrote Tom Gallagher, VP Engineering for Microsoft Security Response Center, in a <a href="https://www.microsoft.com/en-us/msrc/blog/2025/12/in-scope-by-default" target="_blank"><u>blog post</u></a>.</p><p> "The same approach should apply to the security community who continue to partner with us to provide critical insights that help protect our customers. Security vulnerabilities often emerge at the seams where components interact or where dependencies are involved."</p><p>Microsoft is calling the new scheme "<em>In Scope by Default</em>," noting that the aim is to widen coverage of its products and automatically include new services as soon as they are released. </p><p>"Our goal is to incentivize research on the highest risk areas, especially the areas that threat actors are most likely to exploit," Gallagher added. </p><h2 id="how-in-scope-by-default-works">How In Scope by Default works</h2><p>Microsoft said it will now pay a bounty award for any critical flaw impacting its services, whether the code is "owned and managed" by Microsoft, a third party, or is open source – assuming no other bounty award exists. </p><p>"If Microsoft’s online services are impacted by vulnerabilities in third-party code – including open source, we want to know," added Gallagher. "If no bounty award formerly exists to reward this vital work, we will offer one. This closes the gap for security research and raises the security bar for everyone who relies on this code."</p><p>Beyond the bounty, Microsoft said it will "do whatever it takes" to fix the flaw. </p><p>Microsoft said it hopes that expanding the program to include online domains and cloud services means those outside its existing systems will spend time studying its products. </p><p>"Security researchers don’t have our insider perspective and are uniquely placed to think like an attacker," Gallagher said. </p><p>The tech giant added that it expects researchers to protect privacy and customer data, and understand its guidelines for responsible security research. Payouts will depend on the severity of the vulnerability. </p><p>All the big companies – from Microsoft to OpenAI – offer bug bounties, and <a href="https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program"><u>some smaller companies are starting</u></a> to find value too, with awards less costly than regulatory fines and reputational damage. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program">Should your business start a bug bounty program?</a></li><li><a href="https://www.itpro.com/security/hacking/two-thirds-of-ethical-hackers-using-generative-ai-in-bug-hunting">Two-thirds of ethical hackers using generative AI in bug hunting</a></li><li><a href="https://www.itpro.com/security/openai-bug-bounty-program-payout">OpenAI announces five-fold increase in bug bounty reward</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Should your business start a bug bounty program? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program</link>
                                                                            <description>
                            <![CDATA[ Big tech firms including Google, Apple and Microsoft offer bug bounty programs, but can they benefit smaller businesses too? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RjaUR92rEaTSPeLR8Da2kc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y8abhoQWdvEHQQfbBgpqEn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Jul 2023 11:54:02 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Jul 2023 12:29:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y8abhoQWdvEHQQfbBgpqEn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker&#039;s hand hovering over an illuminated MacBook keyboard - an image denoting hacking]]></media:description>                                                            <media:text><![CDATA[Hacker&#039;s hand hovering over an illuminated MacBook keyboard - an image denoting hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker&#039;s hand hovering over an illuminated MacBook keyboard - an image denoting hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y8abhoQWdvEHQQfbBgpqEn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies of all sizes are starting to see the benefits of bug bounty programs. Big tech firms including Facebook, Google, Microsoft, and Apple have such a program in place, while <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> owner OpenAI recently <a href="https://www.itpro.com/security/openai-to-pay-up-to-dollar20k-in-rewards-through-new-bug-bounty-program"><u>unveiled</u></a> such a scheme. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">Patch management vs vulnerability management</a></p></div></div><p>At a time when breaches are hitting businesses of all sizes, adversaries are constantly probing for security weaknesses through which to attack. Bug bounties help to address this issue at the source, with researchers finding vulnerabilities before they can be used in real-life attack scenarios.</p><p>Bug bounty prizes can be huge, with firms such as Google <a href="https://security.googleblog.com/2023/02/vulnerability-reward-program-2022-year.html"><u>paying out</u></a> as much as $600,000 to those who find serious holes in its products. While it might seem like a big outlay, advocates point out that the expense is still smaller than regulatory fines and reputational damage caused by a data breach.</p><h2 class="article-body__section" id="section-what-different-types-of-bug-bounty-program-are-there"><span>What different types of bug bounty program are there?</span></h2><p>Bug bounty programs are typically either public or private. “A public bug bounty is usually listed on sites such as <a href="https://www.hackerone.com/"><u>HackerOne</u></a> and <a href="https://www.bugcrowd.com/"><u>Bugcrowd,</u></a> or in some cases on the company’s own website,” Joshua Hickling, managing consultant at Pentest People, explains.</p><p>A private bug bounty is only joinable via invitation, usually based on the researcher’s reputation. For example, those able to find pertinent, exploitable bugs consistently will be invited to private programs, Hickling says.</p><p>An organization sets the rules of engagement for its bug bounty program, including assets in and out of scope, types of vulnerabilities, permitted testing methodologies, and reward structure. “Hackers can test for vulnerabilities that elude security teams and cannot be discovered by automated scanning tools,” says Kayla Underkoffler, lead security technologist at HackerOne. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bBCW7mSoZuzjDPGyRGZQVg" name="The Threat Prevention Buyer’s Guide_listing.jfif.jpg" caption="" alt="Whitepaper cover with title and logo over image of female worker wearing glasses with digital screens reflected in them and workstations in the background" src="https://cdn.mos.cms.futurecdn.net/bBCW7mSoZuzjDPGyRGZQVg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The threat prevention buyer&apos;s guide</strong></p><p class="fancy-box__body-text"><em>Find the best advanced and file-based threat protection solution for you</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management/the-threat-prevention-buyers-guide"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Among the advantages, programs can be effective very quickly. According to Underkoffler, over 75% of new bug bounty programs on the HackerOne platform receive their first valid vulnerability report within 24 hours.</p><p>They can benefit firms of any size, but larger organizations that operate complex networks or handle large amounts of sensitive data are more likely to get value out of a program, says Cezary Cerekwicki, head of product security at browser maker Opera. “The larger an organization and a network, the greater the danger that vulnerabilities might go undetected.”</p><p>Large firms are a bigger target for adversaries, so a bug bounty offer might even persuade “unethical hackers” to probe for weaknesses with permission, says Leon Teale, a senior penetration tester at IT Governance. “In exchange, they could receive gifts, cash, notoriety, or honorable mentions,” he suggests.</p><p>Michael Adams, CISO at Zoom says the company’s bug bounty program hosted on the HackerOne platform helps the firm “proactively mitigate risk and create a safer environment for our customers”. </p><p>It can be challenging for companies to identify edge-case vulnerabilities or anomalies that only occur in certain circumstances, says Adams. “That’s where the <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hacker</a> community can perform a vital function in the continuous testing and probing of technologies. In many cases, they can help organizations save time and money by identifying certain security issues before they become a bigger problem.”</p><h2 class="article-body__section" id="section-are-bug-bounty-programs-worth-the-cost"><span> Are bug bounty programs worth the cost?</span></h2><p>The cost of running a bug bounty program can vary, but experts say the outlay is worth it. There are two components to the cost: the first is the platform fee, if you use one, with firms such as Bugcrowd or HackerOne offering the service a SaaS subscription model.</p><p>“This is what we charge for connecting organizations that want to run a program with ethical hackers, triaging the results and verifying they are legitimate vulnerabilities – as well as handling payments to the hacker community,” says Dave Gerry, CEO of bug bounty platform Bugcrowd. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022">The scariest cyber security horror stories of 2022</a></p></div></div><p>The second cost is the bounties themselves – which according to Gerry, is set by the market. “If a company’s bounty rates are too low, it will struggle to attract ethical hackers to work on the program.”</p><p>You do not have to pay, with some companies purely offering an honorable mention or some “swag” in return, says Teale. “Offering a ‘kudos’ can still be helpful to those who would like to gain recognition through this exposure – although paid bounties will always attract more testers,” he says.</p><p>The value of the bounty is usually paid based upon the seriousness of the issue, with low severity flaws seeing bounties of anywhere from $0 to $50 and critical issues in some cases exceeding $100,000, says Hickling. “If a vulnerability is identified which could result in the leak of personally identifiable information, paying a $100,000 bounty far outweighs the potential <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid"><u>GDPR fines</u></a> a business could be hit with.”</p><h2 class="article-body__section" id="section-how-to-implement-a-program-in-your-business"><span>How to implement a program in your business</span></h2><p>The benefits of having a bug country program are clear, but there can be challenges when implementing one. </p><p>Scoping is important, says Gerry. “To make them manageable, projects are usually targeted at a specific online asset that has already been tested internally. This prevents organizations from exposing themselves to unexpectedly high levels of cost and stops them from being over-run with reports of vulnerabilities.”</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=52201813&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>It’s also important that firms are ready and able to take remedial action when flaws are discovered, he adds. At the same time, it’s key to match the skills of ethical hackers with the type of assets to be tested, he says. </p><p>But it can be difficult to identify the true impact of vulnerabilities. While an outside researcher might believe they’ve identified a major flaw, companies often have many defenses and mitigations already in place that are not shared externally, says Adams. </p><p>With this in mind, Zoom is rolling out a “Vulnerability Impact Scoring System” to measure the impact of flaws, and pay researchers for the best bugs. </p><p>Before introducing a bug bounty program, it’s important to consider the business objectives, says Adams. “These will help determine the scope of the program, whether it runs as private or public, and the rewards system. It may attract a range of participants from beginner bug bounty hunters to full-time professionals.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI to pay up to $20k in rewards through new bug bounty program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/openai-to-pay-up-to-dollar20k-in-rewards-through-new-bug-bounty-program</link>
                                                                            <description>
                            <![CDATA[ The move follows a period of unrest over data security concerns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZzZXTsDY4Nzg33Gh3Do3kK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 12:06:44 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 09:03:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:description>                                                            <media:text><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:text>
                                <media:title type="plain"><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a new bug bounty program offering rewards for security researchers if they can uncover vulnerabilities in its products. </p><p>In an announcement on Tuesday, the California-based AI firm said the bug bounty scheme is “essential to our commitment to develop safe and advanced AI” and deliver services that are secure, reliable, and trustworthy. </p><p>As part of the initiative, OpenAI said it will offer a tiered reward system based on the severity of bugs uncovered by researchers. </p><p>Rewards can range from as little as $200 for low-severity flaws with a maximum reward of $20,000 for “exceptional discoveries”. </p><p>“The OpenAI Bug Bounty Program is a way for us to recognize and reward the valuable insights of security researchers who contribute to keeping our technology and company secure,” the firm said in a statement. </p><p>“We invite you to report vulnerabilities, bugs, or security flaws you discover in our systems. By sharing your findings, you will play a crucial role in making our technology safer for everyone.”</p><p>Researchers participating in the new initiative will be able to disclose vulnerabilities or flaws through a partner organisation, Bugcrowd.</p><p>Bugcrowd will manage the submission and reward process, which OpenAI said is designed to “ensure a streamlined experience for all participants”. </p><h2 id="chatgpt-vulnerability-concerns">ChatGPT vulnerability concerns</h2><p>The move from OpenAI follows a period of unrest over security-related issues at the generative AI firm, which has close ties with Microsoft. </p><p>Last month, the company revealed that a bug in <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> led to a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370315/chatgpt-privacy-flaw-exposes-users-chatbot-interactions"><u>leak of users&apos; data</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aWdFz5f4uyXMEphjuW8u2e" name="SOC modernisation and and the role of XDR_thumb.png" caption="" alt="Whitepaper cover with image of male colleague at workstation" src="https://cdn.mos.cms.futurecdn.net/aWdFz5f4uyXMEphjuW8u2e.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>SOC modernisation and the role of XDR</strong></p><p class="fancy-box__body-text"><em>How to cope with increasing threats and IT sprawl</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>This flaw meant that <a href="https://www.itpro.com/business/business-strategy/369989/openai-launches-chatgpt-plus-greater-revenue"><u>ChatGPT Plus</u></a> users began seeing user email addresses, subscriber names, payment addresses, and limited credit card information. </p><p>The issue prompted the company to temporarily take the <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369979/chatgpt-vs-chatbots-whats-the-difference"><u>chatbot</u></a> offline to work on a fix. </p><p>“The bug was discovered in the Redis client open-source library, redis-py,” OpenAI explained in a post at the time. </p><p>“As soon as we identified the bug, we reached out to the Redis maintainers with a patch to resolve the issue.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 users locked out of devices by unskippable Microsoft 365 advert ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/370000/windows-10-users-locked-out-of-devices-microsoft-365-advert</link>
                                                                            <description>
                            <![CDATA[ Entering payment information was the only way for some to enter their own PCs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">77MpCP2BHxSzzDhYtKMU4b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MMaRMY5XXarKmgh6dkj9xk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Feb 2023 13:02:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft Office]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MMaRMY5XXarKmgh6dkj9xk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Courtesy of Reddit user u/whatsurissuebro]]></media:description>                                                            <media:text><![CDATA[Windows 10 desktop on an open laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 desktop on an open laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MMaRMY5XXarKmgh6dkj9xk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Windows 10 users have reported a broken Microsoft 365 trial offer which prevents access to the desktop until credit card details are entered.</p><p>On booting up, some Windows 10 devices have shown a full-screen offer for a trial version of Microsoft 365, the tech giant’s suite of productivity apps.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/369757/windows-10-blue-screen-of-death-patch-tuesday-updates" data-original-url="/operating-systems/microsoft-windows/369757/windows-10-blue-screen-of-death-patch-tuesday-updates">Windows 10 users encounter ‘blue screen of death’ after latest Patch Tuesday update</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/368936/how-to-downgrade-from-windows-11-to-windows-10" data-original-url="/software/368936/how-to-downgrade-from-windows-11-to-windows-10">How to downgrade from Windows 11 to Windows 10</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business" data-original-url="/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business">Windows 10 vs Windows 11: Is Windows 10 or 11 better for your business?</a></p></div></div><p>Buttons at the bottom of the screen read ‘Use for free’ and ‘No thanks’, but each leads to a screen prompting users to enter credit card details.</p><p>One Reddit user <a href="https://www.reddit.com/r/Windows10/comments/10r6i6g/windows_10_preventing_me_from_booting_into">posted</a> an example of the issue on the platform's <a href="https://www.itpro.com/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business" data-original-url="https://www.itpro.com/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business">Windows 10</a> community, noting that they had to put in their credit card details to gain access to their desktop and cancel afterwards to prevent being charged recurring payments.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ENQ5wNfoxnDTMpfQ6j2iE7" name="" alt="Microsoft 365 advert in windows 10 that cannot be exited" src="https://cdn.mos.cms.futurecdn.net/ENQ5wNfoxnDTMpfQ6j2iE7.jpg" mos="https://cdn.mos.cms.futurecdn.net/ENQ5wNfoxnDTMpfQ6j2iE7.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Courtesy of Reddit user u/whatsurissuebro </span><span class="credit" itemprop="copyrightHolder">(Image credit: Reddit user u/whatsurissuebro)</span></figcaption></figure><p>No other buttons on the window enabled the user to skip entering payment details.</p><p>Microsoft 365 costs between £4.50 and £16.60 per month for businesses. It is unclear whether the nature of this bug enables it to appear on devices that are already subscribed to a plan with the suite, which could decide the likelihood of it being recreated on <a href="https://www.itpro.com/laptops/23742/best-laptops" data-original-url="https://www.itpro.com/laptops/23742/best-laptops">business laptops</a>.</p><p>Another user <a href="https://www.reddit.com/r/assholedesign/comments/10r2eto/windows_tried_to_pull_a_fast_one_on_me_by">posted</a> a similar bug on a subreddit designed to highlight bad user interface (UI) design. Their full-screen offer advertised 50% off Microsoft 365 Family, and identically to the other post pressing ‘No thanks’ took them to the payment details screen.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Vt8hwZ4SNDyWDjAGgbkGzF" name="Vt8hwZ4SNDyWDjAGgbkGzF.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Vt8hwZ4SNDyWDjAGgbkGzF.png" mos="https://cdn.mos.cms.futurecdn.net/Vt8hwZ4SNDyWDjAGgbkGzF.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Accelerate full-stack web and mobile app development</strong></p><p class="fancy-box__body-text">Three tips proven to help teams build modern apps faster</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/enterprise-applications/369949/accelerate-full-stack-web-and-mobile-app-development" data-original-url="/software/enterprise-applications/369949/accelerate-full-stack-web-and-mobile-app-development">FREE DOWNLOAD</a></p></div></div><p>The offer is meant to be shown in the Windows out of box experience (OOBE), which users see when a device is first turned on after purchase or immediately following a <a href="https://www.itpro.com/operating-systems/28288/how-to-factory-reset-windows-10" data-original-url="https://www.itpro.com/operating-systems/28288/how-to-factory-reset-windows-10">Windows 10 factory reset</a>.</p><p>As the bug has not been addressed by Microsoft, it is not clear if it is the result of an erroneous update or a flaw with the individual users' machines. </p><p>One Reddit user asked for the name of the device's original equipment manufacturer (OEM).</p><p>"Looks like a bug in their OOBE - e.g. strings got swapped in their translations," wrote one individual.</p><p>"Not a [Microsoft] problem - though I'm sure if it gets into the right channels could mean a big fine for the OEM."</p><p><em>IT Pro</em> has approached Microsoft for more information.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 11 System Restore bug preventing users from accessing apps ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/369893/windows-11-system-restore-bug-preventing-accessing-apps</link>
                                                                            <description>
                            <![CDATA[ Microsoft has issued a series of workarounds for the issue which is affecting a range of apps including Office and Terminal ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pZSaBpN9Lr5eA74WNTpZTu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w2xT8M3KemFbrRB7ognD9V-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Jan 2023 10:31:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w2xT8M3KemFbrRB7ognD9V-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 11 splash screen]]></media:description>                                                            <media:text><![CDATA[Windows 11 splash screen]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 11 splash screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w2xT8M3KemFbrRB7ognD9V-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has warned that some Windows 11 users may encounter a bug which prevents access to applications after running the System Restore program. </p><p>An advisory published by the tech giant confirmed that devices using the latest versions of Windows 11 have been impacted by the bug, which affects some applications using the MSIX Windows app package format. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/369661/how-to-install-windows-11-on-a-mac" data-original-url="/operating-systems/microsoft-windows/369661/how-to-install-windows-11-on-a-mac">How to install Windows 11 on a Mac</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/369564/windows-11-tips-and-tricks-for-working-professionals" data-original-url="/operating-systems/microsoft-windows/369564/windows-11-tips-and-tricks-for-working-professionals">Windows 11 tips and tricks for IT professionals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/369867/windows-defender-update-deletes-start-menu-taskbar-desktop-shortcuts" data-original-url="/operating-systems/microsoft-windows/369867/windows-defender-update-deletes-start-menu-taskbar-desktop-shortcuts">Windows Defender update deletes Start Menu, Taskbar, Desktop shortcuts</a></p></div></div><p>Users have reported problems running a number of applications, Microsoft said, including <a href="https://www.itpro.com/software/business-software/369078/canva-launches-new-suite-of-productivity-tools-that-will-rival-g-suite-microsoft-office" data-original-url="https://www.itpro.com/software/business-software/369078/canva-launches-new-suite-of-productivity-tools-that-will-rival-g-suite-microsoft-office">Office</a>, Notepad, Paint, Cortana, and Terminal. </p><p>In its <a href="https://support.microsoft.com/en-us/topic/kb5023152-this-app-can-t-open-error-message-when-starting-a-windows-app-in-windows-11-version-22h2-52d63063-a912-4b2b-b0b8-a934d18625bf">advisory</a>, the company warned that this is not a comprehensive list and could include a range of other apps run via the MSIX app package. </p><p>“This list of apps is not a complete list,” the tech giant said. “Any Windows applications that use the MSIX Windows app package format may experience this issue.” </p><p>Users affected by the bug have reportedly been met with an error message stating “this app can’t open” instead of the app launching, while some apps have multiple entries on the Start Menu. </p><p>In some instances, apps have simply failed to respond upon launch, Microsoft said. In addition, users have encountered an I/O error which is followed by the app crashing.</p><p>The complete list of operating systems affected includes <a href="https://www.itpro.com/operating-systems/microsoft-windows/369237/should-your-business-upgrade-to-windows-11" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/369237/should-your-business-upgrade-to-windows-11">Windows 11</a> version 22H2, Windows 11 SE, Windows 11 Home and Pro, Windows 11 IoT Enterprise, Windows 11 Enterprise and Education, and Windows 11 Enterprise Multi-Session. </p><h2 id="windows-11-system-restore-bug-potential-workarounds">Windows 11 System Restore bug – potential workarounds </h2><p>Microsoft has outlined a number of potential workarounds for users affected by the bug. </p><p>This includes restarting the app or attempting to reinstall the app from the <a href="https://www.itpro.com/operating-systems/microsoft-windows/361051/windows-store-opens-third-party-app-stores" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/361051/windows-store-opens-third-party-app-stores">Windows Store</a>. </p><p>Additionally, users have been advised to try running Windows update or reinstalling the app “from the original source from which it was first installed”. </p><h2 id="windows-11-issues-snowballing">Windows 11 issues snowballing </h2><p>Issues for <a href="https://www.itpro.com/operating-systems/microsoft-windows/369564/windows-11-tips-and-tricks-for-working-professionals" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/369564/windows-11-tips-and-tricks-for-working-professionals">Windows 11</a> users also appear to have been compounded over the last 48 hours amidst claims that IT admins have encountered unresponsive Windows taskbar and Start Menus. </p><p>Microsoft said it is currently investigating the issue, which reportedly hampers users’ ability to log into Outlook and Teams. </p><p>Reports suggest that users have been repeatedly unable to access the <a href="https://www.itpro.com/operating-systems/34614/how-to-fix-the-windows-10-start-menu-if-its-frozen" data-original-url="https://www.itpro.com/operating-systems/34614/how-to-fix-the-windows-10-start-menu-if-its-frozen">Windows Start Menu</a> while other users have revealed the Windows Search feature is unavailable. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KoCPGWaMFabR4Q4NgSnY4D" name="KoCPGWaMFabR4Q4NgSnY4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" mos="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Threat hunting for MSPs</strong></p><p class="fancy-box__body-text">Are you ready to take your Managed Security Service to the next level?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps" data-original-url="/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps">FREE DOWNLOAD</a></p></div></div><p>The Windows bugs follow a recent <a href="https://www.itpro.com/operating-systems/microsoft-windows/369867/windows-defender-update-deletes-start-menu-taskbar-desktop-shortcuts" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/369867/windows-defender-update-deletes-start-menu-taskbar-desktop-shortcuts">high-profile issue</a> affecting Windows Defender which caused significant issues for IT admins globally. </p><p>An update for Windows Defender caused users to experience a “series of false positive detections” for the Attack Surface Reduction (ASR) rule, Microsoft confirmed. </p><p>Users who encountered the issue reported that their device's Start Menu, Taskbar, and desktop shortcuts were deleted. </p><p>On Saturday 14 January, Microsoft published <a href="https://www.itpro.com/operating-systems/microsoft-windows/369873/microsoft-releases-scripts-to-restore-shortcuts-windows-defender-faulty-update" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/369873/microsoft-releases-scripts-to-restore-shortcuts-windows-defender-faulty-update">instructions</a> detailing ways that users could rectify the issue. This included updating to build 1.381.2164.0 or later.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 users encounter ‘blue screen of death’ after latest Patch Tuesday update ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/369757/windows-10-blue-screen-of-death-patch-tuesday-updates</link>
                                                                            <description>
                            <![CDATA[ Microsoft said it is working on a fix for the issue and has offered users a temporary workaround ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3RSxZEAmy7ZDkFH9t7UDac</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MLga8ibx8D8AQHWUtnhYUi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Dec 2022 12:27:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MLga8ibx8D8AQHWUtnhYUi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 10 operating system logo displayed on a laptop screen ]]></media:description>                                                            <media:text><![CDATA[Windows 10 operating system logo displayed on a laptop screen ]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 operating system logo displayed on a laptop screen ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MLga8ibx8D8AQHWUtnhYUi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has warned that some Windows 10 users may encounter the infamous ‘blue screen of death’ (BSOD) after installing its latest 'Patch Tuesday' security updates. </p><p>In an update on the Windows Health Dashboard, the company revealed that the blue screen issue could affect selected users who downloaded the KB5021233 update in this month’s recent raft of security fixes. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369717/microsoft-patches-zero-day-vulnerabilities-in-latest-patch-tuesday-update" data-original-url="/security/369717/microsoft-patches-zero-day-vulnerabilities-in-latest-patch-tuesday-update">Microsoft patches two zero-day vulnerabilities in last Patch Tuesday of 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business" data-original-url="/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business">Windows 10 vs Windows 11: Is Windows 10 or 11 better for your business?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/358097/how-to-fix-a-blue-screen-of-death-error-in-windows-10" data-original-url="/operating-systems/microsoft-windows/358097/how-to-fix-a-blue-screen-of-death-error-in-windows-10">How to fix a blue screen of death error in Windows 10</a></p></div></div><p><a href="https://support.microsoft.com/en-us/topic/december-13-2022-kb5021233-os-builds-19042-2364-19043-2364-19044-2364-and-19045-2364-44e774aa-60c4-4e38-b7e7-c886d210db3b">KB5021233</a> was initially intended to resolve an issue affecting the Camera app after users reported that the app stops responding when memory is low. </p><p>The issue has so far affected users operating several different versions of Windows 10, the firm revealed, including 22H2, 21H2, 21H1, and 20H2. </p><p>Impacted users have been met with the <a href="https://www.itpro.com/operating-systems/microsoft-windows/358097/how-to-fix-a-blue-screen-of-death-error-in-windows-10" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/358097/how-to-fix-a-blue-screen-of-death-error-in-windows-10">BSOD</a> and error code 0xc000021a upon startup, and have been unable to access devices. </p><p>“After installing KB5021233, there might be a mismatch between the file versions of hidparse.sys in c:/windows/system32 and c:/windows/system32/drivers (assuming Windows is installed to your C: drive), which might cause signature validation to fail when cleanup occurs,” Microsoft confirmed in its <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc">update</a> over the weekend. </p><h2 id="how-to-fix-the-issue">How to fix the issue</h2><p>Microsoft revealed it is currently “working on a resolution” for the issue and said it will provide an update in an upcoming release. </p><p>However, for users currently affected by the problem, the firm offered a temporary workaround using the <a href="https://www.itpro.com/operating-systems/microsoft-windows/358036/how-to-reinstall-windows-10-without-losing-data" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/358036/how-to-reinstall-windows-10-without-losing-data">Windows Recovery Environment</a> (WinRE). </p><p>“To mitigate this issue on devices already experiencing it, you will need to use Windows Recovery Environment (WinRE),” Microsoft said. </p><p>The firm outlined the following steps for affected users: </p><ol><li>Enter Windows Recovery Environment. If your device has not automatically started up into WinRE, please see Entry points into WinRE.</li><li>Select 'Troubleshoot'</li><li>Select the 'Start recovery, troubleshooting, and diagnostic tools button</li><li>Select 'Advanced Options'</li><li>Select 'Command Prompt' and wait for your device to restart, if needed.</li><li>Your device should restart to a <a href="https://www.itpro.com/microsoft-windows/30414/command-prompt-windows-10" data-original-url="https://www.itpro.com/microsoft-windows/30414/command-prompt-windows-10">Command Prompt</a> window. You might need to sign into your device with your password before getting to the Command Prompt window</li><li>Run the following command (Important: If Windows is not installed to C:\windows you will need to modify the command to your environment): xcopy C:\windows\system32\drivers\hidparse.sys C:\windows\\system32\hidparse.sys</li><li>Once the previous command completes, type: exit</li><li>Select 'Continue'</li></ol><p>After following these steps, Microsoft said <a href="https://www.itpro.com/operating-systems/26138/how-to-speed-up-windows-10" data-original-url="https://www.itpro.com/operating-systems/26138/how-to-speed-up-windows-10">Windows</a> should now startup “as expected” for users. The firm also warned users against finding alternative workarounds. </p><p>“It is not recommended to follow any other workaround than those recommended above. We do not recommend deleting the hidparse.sys from your Windows\System32 folder,” the company said. </p><h2 id="patch-tuesday">Patch Tuesday </h2><p>This particular issue comes as a result of Microsoft’s recent <a href="https://www.itpro.com/security/369717/microsoft-patches-zero-day-vulnerabilities-in-latest-patch-tuesday-update" data-original-url="https://www.itpro.com/security/369717/microsoft-patches-zero-day-vulnerabilities-in-latest-patch-tuesday-update">Patch Tuesday</a> update, issued on 13 December. </p><p>As part of the update, Microsoft patched a number of critical vulnerabilities along with fixes for two critical <a href="https://www.itpro.com/security/369713/apple-issues-fix-for-actively-exploited-webkit-zero-day-vulnerability" data-original-url="https://www.itpro.com/security/369713/apple-issues-fix-for-actively-exploited-webkit-zero-day-vulnerability">zero-day vulnerabilities</a>. </p><p>49 vulnerabilities were disclosed in the bulletin last week. Six were rated as ‘critical’ while another was identified as having been actively exploited in the wild. </p><p>The exploited bug, tracked as CVE-2022-44698, was found to affect <a href="https://www.itpro.com/operating-systems/microsoft-windows/369111/windows-11-update-2022" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/369111/windows-11-update-2022">Windows SmartScreen</a> and enabled threat actors to bypass Mark of the Web (MOTW) protocols.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SpaceX bug bounty offers up to $25,000 per Starlink exploit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368818/spacex-bug-bounty-offers-up-to-25000-per-starlink-exploit</link>
                                                                            <description>
                            <![CDATA[ The spacecraft manufacturer has offered white hats immunity to exploit a wide range of Starlink systems, with a dedicated report page ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kcZcBG9HRWB1E3RwPokuqX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7GkXcP3EpizVUKqUkMfu4b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Aug 2022 15:52:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7GkXcP3EpizVUKqUkMfu4b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up of the Starlink logo, a stylised black &amp;#039;X&amp;#039; with the word starlink beneath on a white background, with other such logos in the background but blurry]]></media:description>                                                            <media:text><![CDATA[Close up of the Starlink logo, a stylised black &amp;#039;X&amp;#039; with the word starlink beneath on a white background, with other such logos in the background but blurry]]></media:text>
                                <media:title type="plain"><![CDATA[Close up of the Starlink logo, a stylised black &amp;#039;X&amp;#039; with the word starlink beneath on a white background, with other such logos in the background but blurry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7GkXcP3EpizVUKqUkMfu4b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SpaceX is offering between $100 and $25,000 in bounties to hackers who report exploits to the company through their website.</p><p>The spacecraft manufacturer has set up a <a href="https://bugcrowd.com/spacex">dedicated page</a> on crowdsourced <a href="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits" data-original-url="https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits">bug bounty</a> platform Bugcrowd, giving would-be <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hats</a> a centralised method for reporting un-patched SpaceX and Starlink exploits.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R2jbpb4nBynt6hb5iyJKaD" name="R2jbpb4nBynt6hb5iyJKaD.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" mos="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing IBM Security QRadar XDR</strong></p><p class="fancy-box__body-text">A comprehensive open solution in a crowded and confusing space</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368459/introducing-ibm-security-qradar-xdr" data-original-url="/security/cyber-security/368459/introducing-ibm-security-qradar-xdr">FREE DOWNLOAD</a></p></div></div><p>Hackers who submit reports on network vulnerabilities can expect up to $10,000, while on a “case-by-case” basis those who discover and report vulnerabilities with Starlink dishes, satellites or other such hardware can receive up to $25,000.</p><p>According to its <a href="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program" data-original-url="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program">Bugcrowd</a> page, SpaceX has so far rewarded 41 vulnerability reports, at an average of $972 each. A more comprehensive list of prices per type of vulnerability discovered can be found on the page, but SpaceX specifically forbids physical tampering with its infrastructure or that of Starlink’s, as well as testing that could directly impact its services.</p><p>In a <a href="https://api.starlink.com/public-files/StarlinkWelcomesSecurityResearchersBringOnTheBugs.pdf">document</a> shared by SpaceX titled ‘Starlink welcomes security researchers (bring on the bugs), the company outlines its position on bug bounties.</p><p>“We allow responsible security researchers to do their own testing, and we provide monetary rewards when they find and report vulnerabilities,” states the document.</p><p>“We recognize and appreciate the support of the broader security community in making Starlink better and more secure. We encourage researchers to test Starlink for security issues in a non-destructive way and to report their findings through our bug bounty program.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime" data-original-url="/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime">Ethical hackers handed lifeline in controversial US cyber crime review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network" data-original-url="/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network">DARPA recruits SpaceX, Intel and Amazon for major satellite network project</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/368813/zoom-patches-privilege-escalation-flaw-for-macos-users" data-original-url="/security/368813/zoom-patches-privilege-escalation-flaw-for-macos-users">Zoom patches privilege escalation flaw for macOS users</a></p></div></div><p>SpaceX further states that it considers vulnerability research within its bug bounty policies to be exempt from Digital Millennium Copyright Act (DMCA) claims, legal action as a result of <a href="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime" data-original-url="https://www.itpro.com/security/ethical-hacking/367753/ethical-hackers-handed-lifeline-in-controversial-us-cyber-crime">Computer Fraud and Abuse Act (CFAA)</a> violation, and SpaceX terms and conditions that would interfere with research.</p><p>Bug bounties are a popular form of publicly-sourced testing for companies, that offer white hat hackers <a href="https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services" data-original-url="https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services">lucrative rewards</a> and permission to attempt to hack some of the most challenging commercial security systems, in return for information on any vulnerabilities that they discover.</p><p>In June, an employee working for the vulnerability coordination platform HackerOne was <a href="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties" data-original-url="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties">found to have been stealing and re-submitting bug bounties</a> for personal profit and was subsequently fired.</p><p>The Starlink constellation, which aims to provide satellite broadband access to customers worldwide, is rapidly growing. With over 2,500 satellites currently in orbit and an end goal of 12,000 having been approved by the FCC, it is a frontrunner in the growing race for satellite internet dominance, which has already <a href="https://www.itpro.com/infrastructure/network-internet/368492/dish-refutes-spacex-claims-sharing-12ghz-kill-starlink" data-original-url="https://www.itpro.com/infrastructure/network-internet/368492/dish-refutes-spacex-claims-sharing-12ghz-kill-starlink">spawned disagreements</a> as well as interest from agencies such as <a href="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network" data-original-url="https://www.itpro.com/infrastructure/network-internet/368793/darpa-recruits-spacex-intel-amazon-satellite-network">DARPA</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft announces lucrative new bug bounty awards for M365 products and services ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367436/microsoft-announces-lucrative-new-bug-bounty-awards-for-m365-products-and-services</link>
                                                                            <description>
                            <![CDATA[ The new awards will focus on scenario-based weaknesses and offer bonuses of up to 30% for the most severe bugs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tDHt4cgZ8fWU12qRAtzziG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/j6R2EGh2rKSsbwP9XrD4K4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Apr 2022 09:36:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/j6R2EGh2rKSsbwP9XrD4K4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bug surrounding by computer code and jargon]]></media:description>                                                            <media:text><![CDATA[Bug surrounding by computer code and jargon]]></media:text>
                                <media:title type="plain"><![CDATA[Bug surrounding by computer code and jargon]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/j6R2EGh2rKSsbwP9XrD4K4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has announced two brand-new awards for its Microsoft 365 bug bounty programmes, offering the highest potential payouts for eligible submissions.</p><p>The two new awards focus on scenario-based bugs, Microsoft said and will be available to the Dynamics 365 and Power Platform Bounty Program and the M365 Bounty Program.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367413/microsofts-massive-145-vulnerability-patch-tuesday-fixes-ten-critical-exploits" data-original-url="/security/367413/microsofts-massive-145-vulnerability-patch-tuesday-fixes-ten-critical-exploits">Microsoft's massive 145-vulnerability Patch Tuesday fixes ten critical exploits</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">Microsoft awarded $13.6 million in bug bounties over the last 12 months</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams" data-original-url="/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams">Microsoft launches bug bounty programme for Teams</a></p></div></div><p>The most severe bugs that could be used in high-impact scenarios will be awarded the biggest payouts with the potential for a 30% bonus on top of the vulnerability itself.</p><p>Microsoft lists several examples of high-impact scenarios in which it’s looking for reported bugs. Remote code execution (RCE) flaws attract the most lucrative payouts and the full 30% bonus, in some cases, while others such as privilege escalation issues, information disclosure, spoofing, tampering, and denial of service (DoS) bugs also lead to awards.</p><p>In Microsoft’s most recent ‘Patch Tuesday’, <a href="https://www.itpro.com/security/367413/microsofts-massive-145-vulnerability-patch-tuesday-fixes-ten-critical-exploits" data-original-url="https://www.itpro.com/security/367413/microsofts-massive-145-vulnerability-patch-tuesday-fixes-ten-critical-exploits">issued last week</a>, a total of 145 vulnerabilities were addressed and the majority of these were privilege escalation and RCE issues.</p><p>RCE vulnerabilities accounted for close to a third of all the bugs that were patched, three of which were rated 9.8/10 for severity and two were wormable.</p><p>The severity of the reported bug, combined with the quality of the report itself and whether it can be executed in a high-impact scenario all impact the overall payout.</p><p>There are <a href="https://msrc-blog.microsoft.com/2022/04/14/expanding-high-impact-scenario-awards-for-microsoft-bug-bounty-programs">six total scenarios Microsoft earmarked for bonuses</a>, five of which are exclusive to the M365 Bounty Program. Each one has a unique common weakness enumeration (CWE) code with additional bonuses ranging between 15-30% of the initial bug’s reward.</p><p>The Dynamics 365 and Power Platform Bounty Program has just the one high-impact scenario which is ‘cross-tenant information disclosure’ - a condition that warrants a maximum reward of $20,000 if met.</p><p>Microsoft added scenario-based rewards to its cloud security bug bounty programs in <a href="https://msrc-blog.microsoft.com/2021/10/18/new-high-impact-scenarios-and-awards-for-the-azure-bounty-program">October last year</a>, offering larger bonuses of up to 50% and a total value of $60,000 for the most severe flaws affecting Azure services.</p><p>Cross-tenant data leakage in Azure Synapse Analytics, and compromise logging or auditing keys in Key Vault, were both made eligible for the maximum bonuses at the time.</p><p>The company <a href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">announced</a> in July last year that it awarded a total of $13.6 million in bug bounty payouts in the previous one-year period, a figure <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">three times greater than what it awarded in 2019</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Adobe forced to patch its own failed security update ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/362307/adobe-forced-to-patch-its-own-failed-security-update</link>
                                                                            <description>
                            <![CDATA[ Company issues new fix for e-commerce vulnerability after researchers bypass the original update ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">61n9ubHckj4AoKfasEwxHe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/33TheFjneZs7vjGMSmsg7m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Feb 2022 17:07:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/33TheFjneZs7vjGMSmsg7m-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a building with the Adobe sign on the side, shot from below]]></media:description>                                                            <media:text><![CDATA[An image of a building with the Adobe sign on the side, shot from below]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a building with the Adobe sign on the side, shot from below]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/33TheFjneZs7vjGMSmsg7m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Adobe has had to issue another software update after an out-of-band patch failed to fix a vulnerability in its e-commerce software.</p><p>Last weekend, the company <a href="https://www.itpro.com/security/vulnerability/362241/adobe-patches-critcal-bug-in-e-commerce-software" data-original-url="https://www.itpro.com/security/vulnerability/362241/adobe-patches-critcal-bug-in-e-commerce-software">released</a> an out-of-band patch to fix a vulnerability in its Adobe Commerce and Magento Open Source e-commerce products.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/362241/adobe-patches-critcal-bug-in-e-commerce-software" data-original-url="/security/vulnerability/362241/adobe-patches-critcal-bug-in-e-commerce-software">Adobe patches critcal bug in e-commerce software</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/361611/hackers-use-linux-backdoor-on-compromised-e-commerce-sites-with-software" data-original-url="/security/malware/361611/hackers-use-linux-backdoor-on-compromised-e-commerce-sites-with-software">Hackers use Linux backdoor on compromised e-commerce sites with software skimmer</a></p></div></div><p>The CVE-2022-24086 input validation bug allowed attackers to run their own code on e-commerce sites, making them vulnerable to <a href="https://www.itpro.com/security/hacking/357101/largest-ever-magecart-hack-compromises-2000-online-magento-1-sites" data-original-url="https://www.itpro.com/security/hacking/357101/largest-ever-magecart-hack-compromises-2000-online-magento-1-sites">cart skimmers</a>. The company said that the attack had been exploited in the wild.</p><p>Adobe credited the new discovery to one of the bug researchers that found the original vulnerability. The researcher from security company Bugscale, who uses the Twitter handle @Blaklis, <a href="https://twitter.com/Blaklis_/status/1494363202074914822">warned</a> about Adobe's first patch on Twitter. "THIS IS NOT SUFFICIENT to be safe," they said, adding a comment that hinted at the cause of the problem: "take care of json/url encoded values".</p><p>Researchers at security company Positive Technologies also <a href="https://twitter.com/ptswarm/status/1494593464683610115">warned</a> that they had bypassed the initial patch to exploit the vulnerability again. "We weren't the first," they added.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1494363202074914822"></a></p></blockquote><div class="see-more__filter"></div></div><p>The additional research created a new vulnerability ID, CVE-2022-24087. It mirrors the first bug's 9.8 (critical) rating. Adobe released a fix for the bug, which customers must apply on top of the first patch.</p><p>This isn't the first critical vulnerability that Adobe has had to patch lately. Earlier this month it <a href="https://helpx.adobe.com/security/products/creative-cloud/apsb22-11.html">issued a patch</a> for a critical bug, CVE-2022-23202, that enabled attackers to execute their own code in its Creative Cloud Desktop application.</p><p>It also <a href="https://helpx.adobe.com/security/products/after_effects/apsb22-09.html">patched</a> an arbitrary code execution bug in Adobe After Effects, and <a href="https://helpx.adobe.com/security/products/photoshop/apsb22-08.html">another</a> in Photoshop.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google doubles bug bounty rewards for Linux, Kubernetes exploits ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/zero-day-exploit/362258/google-doubles-bug-bounty-linux-kubernetes-exploits</link>
                                                                            <description>
                            <![CDATA[ The increased rewards are said to align better with the community's expectations of a bug bounty programme of this kind ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eLFqyZs2JHmnrop3oU2cS7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sAqLobsdzrPCJjwoWDsoqM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Feb 2022 10:51:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sAqLobsdzrPCJjwoWDsoqM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mockup of a stethoscope treating a keyboard, symbolising a computer bug patch]]></media:description>                                                            <media:text><![CDATA[Mockup of a stethoscope treating a keyboard, symbolising a computer bug patch]]></media:text>
                                <media:title type="plain"><![CDATA[Mockup of a stethoscope treating a keyboard, symbolising a computer bug patch]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sAqLobsdzrPCJjwoWDsoqM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced it will be doubling the rewards it offers to bug hunters who can demonstrate working exploits for a range of zero-day and one-day vulnerabilities across a variety of platforms. </p><p>The reward increases will be applied to exploits discovered in the Linux Kernel, <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes" data-original-url="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes</a>, Google Kubernetes Engine (GKE), or kCTF (Kubernetes-based infrastructure for capture the flag exercises), with the next review coming at the start of 2023.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="/security/27713/the-importance-and-benefits-of-effective-patch-management">Patch management vs vulnerability management</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform" data-original-url="/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform">Google launches new bug bounty platform</a></p></div></div><p>Rewards offered for valid one-day security exploits increase by more than double to a maximum of $71,337, up from $31,337 previously. Sometimes known as 'n-days', one-days are publicly known vulnerabilities that have patches for them, but Google will offer rewards for novel exploits in this case.</p><p>Bug hunters seeking rewards for valid one-day exploits will have to provide a link to the existing <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patch</a> in their report. Google also said it will be limiting the number of rewards for one-day vulnerabilities to only one version or build.</p><p>"There are 12-18 GKE releases per year on each channel, and we have two clusters on different channels, so we will pay the $31,337 base rewards up to 36 times (no limit for the bonuses)," said Eduardo Vela, Product Security Response TL/M at Google. "While we don't expect every upgrade to have a valid 1day submission, we would love to learn otherwise."</p><p>Valid exploits for previously unknown <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day vulnerabilities</a> will nearly double to a maximum reward of $91,337, up from $50,337 previously. Zero-day vulnerabilities typically attract greater rewards because any given vendor would always want to secure the weakness before news of it ever reached cyber criminals.</p><p>"We launched an expansion of kCTF VRP on 1 November 2021 in which we paid $31,337 to $50,337 to those that are able to compromise our kCTF cluster and obtain a flag," said Vela. "We increased our rewards because we recognised that in order to attract the attention of the community we needed to match our rewards to their expectations. We consider the expansion to have been a success, and because of that, we would like to extend it even further to at least until the end of the year (2022)."</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1ojGcpJHLKOEausXT9cuVa"></iframe><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="f35o2EnwwnfZvkHHe5RZSd" name="f35o2EnwwnfZvkHHe5RZSd.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/f35o2EnwwnfZvkHHe5RZSd.png" mos="https://cdn.mos.cms.futurecdn.net/f35o2EnwwnfZvkHHe5RZSd.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Vulnerability and patch management</strong></p><p class="fancy-box__body-text">Keep known vulnerabilities out of your IT infrastructure</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/362135/vulnerability-and-patch-management" data-original-url="/security/vulnerability/362135/vulnerability-and-patch-management">FREE DOWNLOAD</a></p></div></div><p>An increasing amount of recent research has highlighted cyber criminals' shift in focus towards Linux environments, both in and outside of the cloud. </p><p>Qualys published findings earlier this year regarding a Linux root privilege flaw that went unnoticed for 12 years while "<a href="https://www.itpro.com/software/linux/362069/pwnkit-12-year-old-linux-root-privilege-flaw-hiding-plain-sight" data-original-url="https://www.itpro.com/software/linux/362069/pwnkit-12-year-old-linux-root-privilege-flaw-hiding-plain-sight">hiding in plain sight</a>", while VMware observed an increasing number of ransomware attacks targeting Linux-based multi-cloud environments <a href="https://www.itpro.com/software/linux/362197/linux-multi-cloud-ransomware-on-the-rise" data-original-url="https://www.itpro.com/software/linux/362197/linux-multi-cloud-ransomware-on-the-rise">last week</a>.</p><p>Full details on the reporting process can be found in the <a href="http://security.googleblog.com/2022/02/roses-are-red-violets-are-blue-giving.html">Google blog post</a>.</p><h3 class="article-body__section" id="section-reward-structure"><span>Reward structure</span></h3><p>Google will offer a base reward of $31,337 for the first valid exploit for a given vulnerability, zero-day or one-day. This will only be paid once per vulnerability and once per cluster version or build. Duplicate exploits will not be awarded unless it presents a novel exploit chain, Google said.</p><p>From there, a total of three bonuses of $20,000 are available depending on the nature of the exploit disclosed. </p><ul><li>$20,000 will be awarded if the exploit is a zero-day</li><li>A further $20,000 will be awarded for exploits that do not require unprivileged user namespaces</li><li>Another $20,000 is on offer to those who can demonstrate novel exploit techniques. This also applies to duplicate exploits and Google requires a full write-up to qualify as a valid submission</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Intel expands its bug bounty program with Project Circuit Breaker ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/362150/intel-expands-its-bug-bounty-program-with-project-circuit-breaker</link>
                                                                            <description>
                            <![CDATA[ The initiative aims to address vulnerabilities in Intel’s firmware, GPUs, hypervisors, and chipsets ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uTQdLCR37RM3d86LpYZJbW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uz76KuT7TmRMk4CJy8BpEM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Feb 2022 13:07:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uz76KuT7TmRMk4CJy8BpEM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Intel logo displayed on a smartphone in front of a screen of computer code]]></media:description>                                                            <media:text><![CDATA[The Intel logo displayed on a smartphone in front of a screen of computer code]]></media:text>
                                <media:title type="plain"><![CDATA[The Intel logo displayed on a smartphone in front of a screen of computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uz76KuT7TmRMk4CJy8BpEM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Intel has expanded its $100,000 bug bounty program in an effort to entice “elite hackers” to report vulnerabilities in the company's firmware, hypervisors, graphics processing units (GPUs), and chipsets.</p><p>Of the 113 external vulnerabilities detected in 2021, 97 were reported to <a href="https://www.itpro.com/tag/intel" data-original-url="https://www.itpro.com/search/intel">Intel</a> through its public bug bounty program.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/362141/cloudflare-opens-3000-bug-bounty-program-to-the-public" data-original-url="/security/bugs/362141/cloudflare-opens-3000-bug-bounty-program-to-the-public">Cloudflare opens $3,000 bug bounty program to the public</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a></p></div></div><p>Dubbed Project Circuit Breaker, the expansion to Intel's existing program will see the creation of an integrated community that will offer targeted training, <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">hacking challenges</a>, and opportunities to explore new and pre-release products, in addition to enhanced collaborations with hardware and software engineering teams at Intel.</p><p>"Project Circuit Breaker broadens and deepens Intel's existing open Bug Bounty program by hosting targeted time-boxed events on specific new platforms and technologies, providing training and creating opportunities for more hands-on collaboration with Intel engineers," explained Intel.</p><p>"Project Circuit Breaker's first event, Camping with Tigers, is already underway with a group of 20 researchers who received systems with Intel Core i7 processors (formerly Tiger Lake)."</p><p>In the exclusive Camping with Tigers event, researchers will look for security vulnerabilities in Intel’s Tiger Lake platform. The program began in December 2021 and will be in effect until May 2022. At three milestones, eligible vulnerabilities will earn bounty multipliers.</p><p>Potential findings may include, among others, micro-architectural and firmware vulnerabilities. This covers flaws related to BIOS, IP firmware components, embedded controller, sensor, trusted platform module, and flash storage.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=48283579&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>“We invest in and host bug bounty programs because they attract new perspectives on how to challenge emerging security threats – and Project Circuit Breaker is the next step in collaborating with researchers to strengthen the industry’s security assurance practices, especially when it comes to hardware, said Katie Noble, director of Intel’s product security incident response team (PSIRT) and bug bounty.</p><p>“We look forward to seeing how the program will evolve and to introducing new voices to the meaningful work that we do,” added Noble.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloudflare opens $3,000 bug bounty program to the public ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/362141/cloudflare-opens-3000-bug-bounty-program-to-the-public</link>
                                                                            <description>
                            <![CDATA[ The company's previous program paid out around $212,000 over its lifetime ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bv7Y2T8Tr24zxbJFrDpykg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ebV9KGC3t4y2ZW2aHZksuQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Feb 2022 09:00:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ebV9KGC3t4y2ZW2aHZksuQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Binary code]]></media:description>                                                            <media:text><![CDATA[Binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ebV9KGC3t4y2ZW2aHZksuQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloudflare, a provider of web infrastructure and security services, has announced the launch of its public bug bounty program.</p><p>Bug hunters and security researchers can now report vulnerabilities found in <a href="https://www.itpro.com/cloud/cloud-hosting" data-original-url="https://www.itpro.com/search/cloudlfare">Cloudflare</a> products as part of the company's latest program, which is hosted on HackerOne.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/361049/cloudflare-enters-the-email-security-business" data-original-url="/security/phishing/361049/cloudflare-enters-the-email-security-business">Cloudflare enters the email security business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a></p></div></div><p>A private bounty program was previously launched in 2018, following a vulnerability disclosure program in 2014. The company paid $211,512 in bounties during the lifetime of this program, with 292 out of the 430 reports receiving a reward.</p><p>Rewards for Cloudflare's latest program vary with the severity of the vulnerability. Each security flaw is assigned a severity rating based on the Common Vulnerability Scoring Standard (CVSS) version 3.</p><p>There is a $3,000 payment for a critical vulnerability report, while high, medium, and low vulnerabilities are worth $1,000, $500, and $250, respectively. However, rewards vary for secondary and other targets.</p><p>As a way to make vulnerability research easier, Cloudflare also developed a sandbox called CumulusFire, which provides a standardized playground for researchers to test their exploits. The sandbox will also assist Cloudflare’s security teams in reproducing <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">potential exploits for analysis</a>.</p><p>“CumulusFire has already helped us address the constant trickle of reports in which researchers would configure their origin server in an obviously insecure way, beyond default or expected settings, and then report that Cloudflare’s WAF does not block an attack. By policy, we will now only consider WAF bypasses a vulnerability if it is reproducible on CumulusFire,” explained Cloudflare.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/361847/log4shell-zero-day-vulnerability-numbers-revealed" data-original-url="/security/zero-day-exploit/361847/log4shell-zero-day-vulnerability-numbers-revealed">Log4Shell: New numbers reveal the scale of the critical software exploit</a></p></div></div><p>A good place to start is to refer to the documentation on Cloudflare's developer and <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a> portals, the Learning Center, and its support forums.</p><p>The firm also aims to add additional documentation, testing platforms, and a way for researchers to interact with its security teams to ensure submissions are valid.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft issues out-of-band patch for Windows Server sign-in bug ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/server-storage/microsoft-windows-server/361918/patch-issued-for-windows-server-sign-in-bug</link>
                                                                            <description>
                            <![CDATA[ The flaw, which causes a slow down in the user verification process, needs to be installed manually by IT admins ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uqB1agzEtZHFMo9RRAiXJ1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WCgJoHLYwD3rMoqZWYNaER-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jan 2022 14:53:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WCgJoHLYwD3rMoqZWYNaER-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo suspended above a conference floor]]></media:description>                                                            <media:text><![CDATA[Microsoft logo suspended above a conference floor]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo suspended above a conference floor]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WCgJoHLYwD3rMoqZWYNaER-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/microsoft" data-original-url="https://www.itpro.com/search/microsoft">Microsoft</a> has issued an out-of-band patch for Windows Server to fix a problem that could potentially stop remote desktop users logging into the system.</p><p>The flaw causes performance issues with Windows Server, which would result either in a slow sign-in process, general slowness, or at worst a black screen, Microsoft said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361781/microsoft-launches-secured-core-servers-to-combat-ransomware" data-original-url="/security/cyber-security/361781/microsoft-launches-secured-core-servers-to-combat-ransomware">Microsoft launches Secured-core servers to combat ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/357168/windows-server-flaw-sparks-us-gov-warning" data-original-url="/security/vulnerability/357168/windows-server-flaw-sparks-us-gov-warning">Windows Server flaw sparks emergency US gov warning</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/exploits/357248/microsoft-warns-of-hackers-exploiting-zerologon-windows-server-bug" data-original-url="/security/exploits/357248/microsoft-warns-of-hackers-exploiting-zerologon-windows-server-bug">Microsoft warns 'Zerologon' Windows Server bug being exploited by hackers</a></p></div></div><p>Windows Server 2019 is at risk, and Microsoft has <a href="https://support.microsoft.com/en-us/topic/january-4-2022-kb5010196-os-build-17763-2369-out-of-band-1a7a9a37-b154-4e73-92dc-1a2f65a4c0d1">published KB5010196</a> to address this edition. The bug also affects Windows Server 2012 Release 2, which the company has addressed with <a href="https://support.microsoft.com/en-us/topic/kb5010215-windows-server-2012-r2-stops-responding-after-installing-the-december-14-2021-update-b7c5219f-d865-489f-a02a-6652095439b5">KB5010215</a>.</p><p>Also affected are Window Server 2022 and 2016, which the company said it would address in the coming days.</p><p>The bug stemmed from the KB5008218 update that Microsoft released during a regular Patch Tuesday update on December 14. This update introduced some security changes for Windows.</p><p>The out-of-band updates will not install automatically as part of the Windows Update service, meaning that administrators must install them manually by importing it into the Windows Server Update Service (WSUS). They can get the Windows Server 2019 patch by visiting the <a href="https://www.catalog.update.microsoft.com/Search.aspx?q=KB5010196">Microsoft Update Catalog website</a>. Windows Server 2012 Release 2 users can go <a href="https://www.catalog.update.microsoft.com/Search.aspx?q=KB5010215">here</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eWsAVmqb7koagsygWZB7LE" name="eWsAVmqb7koagsygWZB7LE.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eWsAVmqb7koagsygWZB7LE.jpg" mos="https://cdn.mos.cms.futurecdn.net/eWsAVmqb7koagsygWZB7LE.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The care and feeding of cloud</strong></p><p class="fancy-box__body-text">How to support cloud infrastructure post-migration</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/358701/the-care-and-feeding-of-cloud" data-original-url="/cloud/cloud-management/358701/the-care-and-feeding-of-cloud">FREE DOWNLOAD</a></p></div></div><p>The latest updates are cumulative, and the Windows Server 2019 update inherits three other less urgent Windows issues identified by Microsoft. This includes errors for devices using Asian language packs, and a temporary problem starting the Windows Cluster Service that disappears when rebooting after approximately 20 minutes. There is also an issue with versions of Windows Server used as Key Management Services hosts that might prevent some client <a href="https://www.itpro.com/tag/windows-10" data-original-url="https://www.itpro.com/search/windows%2010">Windows 10</a> operating systems from activating. The company will fix these in future releases, it said.</p><p>Out-of-band patches for Windows Server are rare. Microsoft issued one in November last year, addressing a bug in Windows Server when used as a domain controller. The flaw prevented servers from authenticating legitimate users who tried to access resources using a <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" data-original-url="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on token</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta expands bug bounty programme to cover data scraping  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/361857/meta-expands-bug-bounty-programme-to-cover-data-scraping</link>
                                                                            <description>
                            <![CDATA[ The move comes two years after a massive scraping incident on Facebook that resulted in data leaking online ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uF24jezCdhHY2PBTHtwJgX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y9D7nRU5SSP6x2cyxj6kba-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Dec 2021 12:34:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y9D7nRU5SSP6x2cyxj6kba-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A smartphone lying on a laptop displaying the Meta company logo]]></media:description>                                                            <media:text><![CDATA[A smartphone lying on a laptop displaying the Meta company logo]]></media:text>
                                <media:title type="plain"><![CDATA[A smartphone lying on a laptop displaying the Meta company logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y9D7nRU5SSP6x2cyxj6kba-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has expanded its bug bounty programme to include flaws that lead to data scraping in a move it's describing as an industry-first.</p><p>The programme will now cover database scraping and also offer rewards for researchers who can simply show novel methods of scraping on its products - the latter of which is a first-of-its-kind programme, according to the <a href="https://www.itpro.com/business/business-strategy/361396/meta-industry-reacts-to-the-facebook-companys-rebrand" data-original-url="https://www.itpro.com/business/business-strategy/361396/meta-industry-reacts-to-the-facebook-companys-rebrand">newly rebranded</a> parent company of Facebook.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Ten ways to protect your company from the next big data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-controller/360053/linkedin-data-breach-denial" data-original-url="/business-strategy/data-controller/360053/linkedin-data-breach-denial">LinkedIn denies data breach that reportedly exposed 700 million user records</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/361396/meta-industry-reacts-to-the-facebook-companys-rebrand" data-original-url="/business/business-strategy/361396/meta-industry-reacts-to-the-facebook-companys-rebrand">'Changing name to Meat': Industry reacts to Facebook's Meta rebrand</a></p></div></div><p>It will begin as a private programme only available to Meta's Gold+ HackerPlus security researchers - a title for researchers who have reported at least five valid bugs to the company - and will offer rewards to those who show how data scraping can be achieved, regardless of the degree of impact on the product.</p><p>Researchers can submit methods even if the data is public and Meta said it's particularly looking for reports regarding logic bypass issues - flaws that permit access to data via unintended mechanisms.</p><p>Data scraping can be achieved using specially crafted scripts, often using the Python programming language, which are designed to lift the data from any given web page. These scripts can be designed to grab specific information, depending on the target and the purpose of the activity.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDddJPsRCmdrr35SdPri7g" name="TDddJPsRCmdrr35SdPri7g.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TDddJPsRCmdrr35SdPri7g.jpg" mos="https://cdn.mos.cms.futurecdn.net/TDddJPsRCmdrr35SdPri7g.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to reduce the risk of phishing and ransomware</strong></p><p class="fancy-box__body-text">Top security concerns and tips for mitigation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware" data-original-url="/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware">FREE DOWNLOAD</a></p></div></div><p>"We know that automated activity designed to scrape people’s public and private data targets every website or service," said Meta in an <a href="https://about.fb.com/news/2021/12/expanding-bug-bounty-program-to-address-scraping">announcement</a>.</p><p>"We also know that it is a highly adversarial space where scrapers - be it malicious apps, websites or scripts - constantly adapt their tactics to evade detection in response to the defences we build and improve. As part of our larger security strategy to make scraping harder and more costly for the attackers, today we are beginning to reward valid reports of scraping bugs in our platform."</p><p>The move comes more than two years after the company formerly known as Facebook first identified an issue that allowed users to scrape data of 533 million of its users. The data was <a href="https://www.itpro.com/policy-legislation/data-protection/359114/facebook-data-breach-533-million-hacking-forum" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359114/facebook-data-breach-533-million-hacking-forum">leaked online</a>, in full, by a hacker earlier this year after they ran an underground business that saw people pay small sums to access and retrieve information such as users' phone numbers.</p><p>Meta has said it will also reward researchers who can demonstrate they can scrape datasets containing at least 100,000 Facebook user records, starting today.</p><p>To be eligible for a reward, the dataset must be unique and unknown to Meta, and contain personally identifiable information (PII) such as email addresses, phone numbers, physical addresses, or religious or political affiliations.</p><p>"If we confirm that user PII was scraped and is now available online on a non-Meta site, we will work to take appropriate measures, which may include working with the relevant entity to remove the dataset or seeking legal means to help ensure the issue is addressed," the company said.</p><p>The maximum reward for the programme is not disclosed by Meta, but it said each successful, eligible disclosure will be rewarded with the bare minimum of $500 (£376).</p><p>Database scraping is often confused with a <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">data breach</a> and it represents an interesting differentiation of the two terms, despite the outcome largely being the same - user data falling into the hands of those with whom the user did not explicitly share.</p><p>Unlike data breaches, which fall under the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act" data-original-url="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act</a>, there is no specific law against data scraping in the UK. However, sites can take action against individuals if the data scraping results in an infringement of intellectual property or breaches the site's terms of service.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to fix the blue screen of death error in Windows 11 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/361713/how-to-fix-blue-screen-error-bsod-windows-11</link>
                                                                            <description>
                            <![CDATA[ The blue screen of death in Windows 11 can be frustrating but it's relatively easy to fix ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j4q93pFLX3MASeUV1W9CSc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PJyEybKyQhGBpM4QXw7ccH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Dec 2021 16:20:16 +0000</pubDate>                                                                                                                                <updated>Thu, 19 Jun 2025 16:04:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Chris Merriman) ]]></author>                    <dc:creator><![CDATA[ Chris Merriman ]]></dc:creator>                                                                                                                            <dc:contributor><![CDATA[ Rene Millman ]]></dc:contributor>
                                                                                                                                                                                    <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PJyEybKyQhGBpM4QXw7ccH-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue screen of death Windows 11 - a screenshot taken of the error screen from a Microsoft Windows PC]]></media:description>                                                            <media:text><![CDATA[Blue screen of death Windows 11 - a screenshot taken of the error screen from a Microsoft Windows PC]]></media:text>
                                <media:title type="plain"><![CDATA[Blue screen of death Windows 11 - a screenshot taken of the error screen from a Microsoft Windows PC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PJyEybKyQhGBpM4QXw7ccH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Encountering a Blue Screen of Death (BSOD) on a Windows 11 system can be alarming for any user, from IT professionals managing critical infrastructure to individuals relying on their PCs for daily tasks. This critical stop error, often displaying a cryptic message, signals a serious system issue that has forced Windows to halt to prevent potential data corruption or hardware damage. While a BSOD can stem from a multitude of causes, including hardware malfunctions, driver incompatibilities, or corrupted system files, many instances are resolvable. This guide provides a structured approach to diagnosing and fixing common Blue Screen of Death errors in Windows 11, helping you restore system stability.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/361662/how-to-boot-windows-11-in-safe-mode" data-original-url="/operating-systems/microsoft-windows/361662/how-to-boot-windows-11-in-safe-mode">How to boot Windows 11 in Safe Mode</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/361645/how-to-move-windows-11-from-a-hard-drive-to-an-ssd" data-original-url="/operating-systems/microsoft-windows/361645/how-to-move-windows-11-from-a-hard-drive-to-an-ssd">How to move Microsoft's Windows 11 from a hard drive to an SSD</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/361465/windows-11-problems-and-how-to-fix-them" data-original-url="/operating-systems/microsoft-windows/361465/windows-11-problems-and-how-to-fix-them">Most common Windows 11 problems and how to fix them</a></p></div></div><p>Experiencing a blue screen of death (BSOD) on Windows 11 can be a frustrating encounter, but it’s a relatively common issue that doesn’t always indicate a catastrophic problem. Many Windows users have encountered a BSOD, which signals a system crash. Fortunately, it often can be resolved with systematic troubleshooting.</p><p>The causes of a BSOD can vary widely, ranging from hardware issues (like faulty RAM or overheating components) and driver conflicts to software bugs and corrupted system files. In some cases, a simple restart may temporarily resolve the issue. However, for persistent problems, more comprehensive methods are needed to address and fix the underlying causes to ensure your system runs smoothly.</p><p>The BSOD on Windows 11 helpfully provides an error code (often called a Stop Code) and sometimes a QR code to give users an initial idea of what caused the crash. These codes are the starting point for diagnosis.</p><p>The BSOD is also known as a ‘STOP error,’ indicating a fatal system error. IT professionals have referred to it by its foreboding name for years due to its disruptive nature.</p><p>A brief historical note: When <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review"><u>Windows 11</u></a> first launched, some early builds displayed this error screen with a black background. However, Microsoft <a href="https://blogs.windows.com/windows-insider/2021/11/12/releasing-windows-11-build-22000-346-to-beta-and-release-preview-channels/#:~:text=We%20changed%20the%20screen%20color%20to%20blue%20when%20a%20device%20stops%20working%20or%20a%20stop%20error%20occurs%20as%20in%20previous%20versions%20of%20Windows."><u>quickly reinstated</u></a> the classic blue background in subsequent updates. If you encounter a black screen error, it indicates you are running a significantly outdated build of Windows 11, and you should prioritize updating Windows 11 immediately to benefit from the latest security patches, features, and stability improvements.</p><h2 class="article-body__section" id="section-how-to-fix-the-blue-screen-of-death-in-windows-11"><span>How to fix the blue screen of death in Windows 11</span></h2><p>The BSOD in Windows 11 is designed to be more user-friendly than in older Windows versions, but its sudden appearance can still be daunting. When a BSOD occurs, your system typically attempts to gather diagnostic information and may automatically restart.</p><p>To avoid any potential loss of unsaved work if the system is configured to collect a memory dump, it’s best to let the process complete if it shows a percentage counter.</p><p>Here are effective steps to diagnose and resolve a BSOD:</p><section class="howto-block">                    <h3>Check error and QR codes </h3>                                        <p><p>When the BSOD appears, users will be shown an error code. This will be a mixture of numbers and letters, usually starting with "0x".</p></p><p><p><br></p></p><p><p>This number corresponds with the exact error that your machine is having, so it’s important to keep a record of it.</p></p><p><p><br></p></p><p><p>It’s normal for the error code to be shown alongside its Stop Code, which is the part that tells the user the cause of the problem. The stop code is always a series of words in block capitals, shown in square brackets.</p></p><p><p><br></p></p><p><p>For example, the error code <strong>0x00000001</strong> may show as '<strong>APC_INDEX_MISMATCH</strong>' which tells the user that there is a mismatch in the APC state index.</p></p><p><p><br></p></p><p><p>In contrast, <strong>[CRITCAL_PROCESS_DIED]</strong> informs the user that something is wrong with an aspect of the operating system that your device runs. Don't worry if it is just the Error Code that comes up, because that will still be useful to any technicians you might have to call in for help.</p></p><p><p>Windows 8 included the useful introduction of QR codes to the BSOD. Scan this code with your smartphone’s camera and you will be taken to the support page in your <a href="https://www.itpro.com/web-browsers/24796/best-browser-chrome-vs-edge-vs-firefox"><u>web browser</u></a>.</p></p>                </section><section class="howto-block">                    <h3>Query BSOD error codes</h3>                                        <p><p>Identifying the error codes is just the first part of the process. Next, you must figure out what they mean. In most cases, the code will relate to an issue, or simply point you in the right direction, rather than give you the precise cause.</p></p><p><p><br></p></p><p><p><br></p></p>                </section><p>Some errors are harder to diagnose, however. The error code <strong>IRQL_not_less_or_equal</strong>, for example, usually relates to a hardware fault, such as a corrupted<a href="https://www.itpro.com/laptops/29190/how-to-find-ram-speed-size-and-type"> <u>RAM</u></a> module.</p><p>It can also be triggered by faulty drivers, or even faulty<a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"> <u>antivirus software</u></a></p><p>Aside from using the QR code, the quickest way to check the error is to type the code into a search engine. It’s best to find the Microsoft Support page for that code first and foremost, before looking at third-party sites that will either try and sell you a quick fix, or get you to try every fix possible</p><p>The<a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=46128&u1=itprous-gb-2277674889039954318&murl=https%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fsbs%2Fwindows%2Ftroubleshoot-blue-screen-errors-5c62726c-6489-52da-a372-3f73142c14ad%3Fui%3Den-US%26rs%3Den-GB%26ad%3DGB"> <u>Microsoft support page</u></a> will be able to explain the error, the circumstances that triggered it, and if there is a fix or workaround to resolve it. The support page should give you step-by-step instructions to follow and guide you on your way to resolving the issue.</p><p>If there are no fixes, or if the page only offers vague information like &apos;driver issue&apos;, it’s time to think back to any recent installations or changes you made to your machine, and if need be, uninstall them.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=45431401&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><section class="howto-block">                    <h3>Check the Windows 11 memory dump</h3>                                        <p><p>If the Support Page doesn’t answer your question, you can find a lot more information by looking through the Memory Dump, an error log that’s automatically created whenever Windows encounters an error from which it’s unable to recover.</p></p><p><p><br></p></p><p><p>You’ll find it on the same drive that holds your Windows 11 installation, in a folder called <strong>%SystemRoot%\MEMORY. DMP</strong> or <strong>%SystemRoot%\Minidump</strong>.</p></p><p><p><br></p></p><p><p>To open the file, you’ll need an app called <strong>WinDbg</strong> from the Microsoft Store. We won’t go into detail on how to decipher a memory dump in this article, but if you need to, call in a technical support person or system administrator.</p></p><p><p>Unfortunately, Windows can only diagnose so far and if it’s still not clear at this stage what the issue is, you might need to ask for outside help. Microsoft has forums for this sort of issue, staffed by the community and Microsoft engineers.</p></p><p><p><br></p></p><p><p>To get the best support, you should try to be as detailed as possible when describing what you were doing when the error occurred and don’t forget to include both the Error Code and Stop Code.</p></p><p><p><br></p></p><p><p>We have a guide on <a href="https://www.itpro.com/operating-systems/26581/how-to-get-help-in-windows-10">how to access help in Windows</a>, which will give you plenty of pointers.</p></p><p><p><br></p></p><p><p>While it is recommended you follow support options outlined by Microsoft or technicians, options may help you resolve the situation.</p></p>                </section><section class="howto-block">                    <h3>Boot Windows in Safe Mode</h3>                    <figure>                            <p class="bordeaux-image-check">                                <img    src="https://cdn.mos.cms.futurecdn.net/skKgez9QNLeGpjLgWsJtoX.png"                                        alt="Image showing the safe mode notification on Windows 11"                                        onerror="this.parentNode.replaceChild(window.missingImage(),this)"                                        data-pin-media="https://cdn.mos.cms.futurecdn.net/skKgez9QNLeGpjLgWsJtoX.png"                                        class="expandable van-old-layout-image">                            </p><div class="credit">(Image: © Future)</div></figure>                    <p><p>If the BSOD prevents Windows from starting normally, or if you suspect a driver or software conflict, booting into Safe Mode is essential. Safe Mode starts Windows with a minimal set of drivers and startup programs.</p></p>                </section><p>You can follow our detailed guide on how to <a href="https://www.itpro.com/operating-systems/microsoft-windows/361662/how-to-boot-windows-11-in-safe-mode"><u>boot Windows 11 in Safe Mode</u></a>. If the BSOD does not occur in Safe Mode, a third-party driver or software is likely the culprit. This is similar to <a href="https://www.itpro.com/software/29158/how-to-boot-windows-10-in-safe-mode"><u>booting Windows 10 in safe mode</u></a>.</p><section class="howto-block">                    <h3>Use System Restore</h3>                                        <p><p>System Restore offers another way out of a stubborn error, though it comes at a cost: the rollback returns Windows to an earlier snapshot and erases any edits or additions you have made to files and folders since that snapshot was created.</p></p><p><p>To roll back with System Restore:</p></p><p><ul></p><p><li>Open <strong>Settings</strong> and choose <strong>System</strong>.</li></p><p><li>Head to <strong>Recovery</strong> and click <strong>Go back</strong> (greyed-out means no restore points exist).</li></p><p><li>In the <em>Restore system files and settings</em> window, hit <strong>Next</strong>.</li></p><p><li>Pick the restore point you want and follow the prompts to start the rollback.</li></p><p></ul></p>                </section><section class="howto-block">                    <h3>Reset your PC</h3>                    <figure>                            <p class="bordeaux-image-check">                                <img    src="https://cdn.mos.cms.futurecdn.net/HdxW2y4YzU6tMXjodWiYQZ.png"                                        alt="A screenshot of the Windows 11 Settings menu showing options for resetting a PC"                                        onerror="this.parentNode.replaceChild(window.missingImage(),this)"                                        data-pin-media="https://cdn.mos.cms.futurecdn.net/HdxW2y4YzU6tMXjodWiYQZ.png"                                        class="expandable van-old-layout-image">                            </p><div class="credit">(Image: © ITPro)</div></figure>                    <p><p>If you’ve tried all the above steps and are still unable to fix the error, you may want to consider <a href="https://www.itpro.com/software/windows/how-to-factory-reset-windows-11"><u>factory resetting your Windows 11</u></a> PC. </p></p><p><p><br></p></p><p><p>To do this, go to:</p></p><p><ol></p><p><li>Start Menu</li></p><p><li>Settings</li></p><p><li>System</li></p><p><li>Recovery</li></p><p><li>Once you’ve reached this menu, you can select the ‘Reset PC’ option</li></p><p></ol></p><p><p>Choosing to reset your PC will delete the C: drive, as well as all files and folders saved to Desktop, Documents, and Downloads.</p></p>                </section><section class="howto-block">                    <h3>Run System File Checker (SFC) and DISM</h3>                                        <p><p>Corrupted system files can lead to BSODs.</p></p><p><ul></p><p><li>Open <strong>Command Prompt as Administrator</strong> or <strong>Windows PowerShell (Admin)</strong>.</li></p><p><li>Type sfc /scannow and press Enter. This will scan and attempt to repair corrupted Windows system files.</li></p><p><li>If SFC finds issues but cannot fix them, or if you suspect deeper image corruption, run DISM:</p><p><ul></p><p><li>DISM /Online /Cleanup-Image /CheckHealth</li></p><p><li>DISM /Online /Cleanup-Image /ScanHealth</li></p><p><li>DISM /Online /Cleanup-Image /RestoreHealth</li></p><p></ul></p><p></li></p><p></ul></p>                </section><h2 class="article-body__section" id="section-what-is-the-green-screen-of-death-in-windows-11"><span>What is the green screen of death in Windows 11?</span></h2><p>If you’re a Windows Insider running preview builds of Windows 11, you might encounter a Green Screen of Death (GSOD) instead of blue. The GSOD serves the same purpose but is green to distinguish crashes in Insider builds from those in stable releases. It often contains more detailed debugging information. If you encounter a GSOD, the issue may be specific to the unstable preview build, and fixes that are perhaps not yet available. Check the <a href="https://techcommunity.microsoft.com/t5/windows-insider-program/bd-p/WindowsInsiderProgram"><u>Windows Insider Program hub</u></a> and forums for support.</p><h2 id="managing-software-conflicts">Managing software conflicts</h2><p>Managing software conflicts in Windows 11 starts with the simplest remedy: keep everything current. Refresh the operating system, device drivers and every application you have installed, because most updates slip in quiet compatibility tweaks and bug fixes that stop potential clashes before they can knock the whole machine over. If crashes continue after you patch, cast an eye over any programs you have added or upgraded in the past few days; it is not unusual for a brand-new utility — or even a well-meant update — to spark the infamous blue screen. Removing the newcomer through “Apps & Features” in Settings will tell you quickly whether it was the culprit.</p><p>Sometimes the friction hides in the background, so pare back what loads at start-up. Open Task Manager with Ctrl + Shift + Esc, switch to the “Startup” tab and turn off anything that is not essential to daily work. A leaner launch makes it easier to spot a rogue process that was tripping Windows during boot.</p><p>When stubborn conflicts refuse to show themselves, boot the system with just the bare minimum of services and drivers. This so-called clean boot isolates the offender by process of elimination, letting you restore normal operations with confidence that the disruptive code has been identified — and that the dreaded BSOD will stay away.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to boot into Windows 11 Safe Mode ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/361662/how-to-boot-windows-11-in-safe-mode</link>
                                                                            <description>
                            <![CDATA[ Long-time Windows users will already be familiar with Windows 11 Safe Mode, but what exactly is it for and how do you boot your system into it? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gcEX2CeRxFo5nypxnfzaed</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kHL69Bux4BrtcZrT3yrzC9-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Dec 2021 16:01:06 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Nov 2025 19:46:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/kHL69Bux4BrtcZrT3yrzC9-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Screenshot of the Windows recovery settings menu that allows users to open Windows 11 Safe Mode]]></media:description>                                                            <media:text><![CDATA[Screenshot of the Windows recovery settings menu that allows users to open Windows 11 Safe Mode]]></media:text>
                                <media:title type="plain"><![CDATA[Screenshot of the Windows recovery settings menu that allows users to open Windows 11 Safe Mode]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kHL69Bux4BrtcZrT3yrzC9-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Windows 11 Safe Mode is a vital diagnostic utility that enables users to<a href="https://www.itpro.com/operating-systems/microsoft-windows/361465/windows-11-problems-and-how-to-fix-them"><u> troubleshoot complex system issues</u></a> by booting the operating system in a minimal state. By loading only the most essential drivers and services, Safe Mode effectively isolates the root causes of problems, whether they are software glitches, driver conflicts, or performance bottlenecks.</p><p>This stripped-back environment is particularly useful for tackling persistent crashes, system instability, or malware infections. Disabling non-essential components allows IT professionals and users to identify and resolve underlying issues without interference from third-party applications or background processes.</p><p>Windows 11 provides three distinct Safe Mode environments to suit different troubleshooting needs: Standard Safe Mode, Safe Mode with Networking, and Safe Mode with <a href="https://www.itpro.com/operating-systems/34493/take-command-of-your-computer-with-a-command-line-interface"><u>Command Prompt</u></a>.</p><p>Understanding how to use these configurations effectively is crucial for diagnosing and resolving system issues without compromising security or functionality.</p><h2 class="article-body__section" id="section-why-boot-into-windows-11-safe-mode"><span>Why boot into Windows 11 Safe Mode?</span></h2><p>Booting into Windows 11 Safe Mode is a crucial step when addressing significant system issues, such as frequent crashes, system instability, or failure to boot correctly. By initiating the operating system with only essential drivers and services, Safe Mode creates a controlled environment that simplifies the process of isolating and resolving underlying problems. ​</p><p>One prevalent issue that Safe Mode can help mitigate is the <a href="https://www.itpro.com/operating-systems/microsoft-windows/361713/how-to-fix-blue-screen-error-bsod-windows-11"><u>Blue Screen of Death (BSOD)</u></a>, often resulting from faulty or outdated drivers. If you've recently installed new hardware or software leading to system instability, booting into Safe Mode allows you to uninstall the problematic components or revert to a stable configuration. ​</p><p>Additionally, running the Check Disk (CHKDSK) utility in Safe Mode is advisable for diagnosing and repairing hard drive errors. This tool scans the file system and metadata of a volume for logical and physical errors, ensuring the integrity of your data. </p><p>Executing CHKDSK in Safe Mode minimizes the chance of interference from third-party processes, leading to a more effective repair process. <a href="https://www.itpro.com/technology/34385/how-to-run-chkdsk"><u><em>ITPro’s</em></u><u> guide on running the Chkdsk tool</u></a> is a great resource for addressing potential hard drive errors while in Safe Mode. </p><h2 id="important-warning-check-for-bitlocker">Important warning: Check for BitLocker</h2><p>Before attempting to boot into Safe Mode, ensure you have your <strong>BitLocker Recovery Key</strong> handy. If your device is encrypted (which is standard on most modern Windows 11 laptops), the system may interpret the change in boot mode as a security risk and lock the drive.</p><p>You can find your 48-digit recovery key by logging into your Microsoft account on another device (account.microsoft.com/devices/recoverykey). Without this key, you may find yourself locked out of the system once the recovery menu loads.</p><h2 class="article-body__section" id="section-how-do-i-know-if-windows-11-is-in-safe-mode"><span>How do I know if Windows 11 is in Safe Mode?</span></h2><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="skKgez9QNLeGpjLgWsJtoX" name="" alt="Image showing the safe mode notification on Windows 11" src="https://cdn.mos.cms.futurecdn.net/skKgez9QNLeGpjLgWsJtoX.png" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>​When your system boots into Windows 11 Safe Mode, several indicators confirm this status. The desktop will appear with a basic black background, devoid of personalized elements such as custom wallpapers or themes. </p><p>Additionally, the text "Safe Mode" will be displayed in the corners of the screen, including just above the clock in the bottom-right corner. </p><h2 class="article-body__section" id="section-how-to-boot-into-safe-mode-in-windows-11"><span>How to boot into Safe Mode in Windows 11</span></h2><p>​Accessing Safe Mode in Windows 11 is similar to previous versions, offering multiple methods to accommodate different scenarios. Whether you're logged into your system or unable to boot into Windows, you can initiate Safe Mode through various approaches. ​</p><p>Here’s a breakdown of the four most common methods:</p><ul><li>Method One - The Start Menu method</li><li>Method Two - The Advanced Start method</li><li>Method Three - The Function Key method</li><li>Method Four - The ‘When all else fails’ method</li></ul><p>Read on to see detailed instructions for each step.</p><section class="howto-block">                    <h3>Method One - The Start Menu method</h3>                                        <p><p>The first, and easiest way is using the Start Menu inside Windows 11's desktop.</p><p><br></p><p>1. Click the Start Menu.</p><p>2. Select the Power button.</p><p>3. Hold down the Shift key and click Restart.</p><p>4. Wait for the system to reboot and display the Recovery Menu.</p></p>                </section><section class="howto-block">                    <h3>Method Two - The Advanced Start Method</h3>                    <figure>                            <p class="bordeaux-image-check">                                <img    src="https://cdn.mos.cms.futurecdn.net/tdUmUbV5EHvg6RRVgFjrWn.png"                                        alt="Screenshot of Windows 11's advanced settings menu"                                        onerror="this.parentNode.replaceChild(window.missingImage(),this)"                                        data-pin-media="https://cdn.mos.cms.futurecdn.net/tdUmUbV5EHvg6RRVgFjrWn.png"                                        class="expandable van-old-layout-image">                            </p><div class="credit">(Image: © ITPro)</div></figure>                    <p><p>1. Press the <strong>Windows key + i</strong> to open Settings.</p><p>2. Navigate to the System menu.</p><p>3. Select Recovery from the options on the right.</p><p>4. Under Advanced Startup, click Restart Now.</p></p>                </section><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pnKL8BfeGt4mJeBLgMW72e" name="pnKL8BfeGt4mJeBLgMW72e.png" alt="A screenshot showing Windows 11's advanced startup option" src="https://cdn.mos.cms.futurecdn.net/pnKL8BfeGt4mJeBLgMW72e.png" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: ITPro)</span></figcaption></figure><section class="howto-block">                    <h3>Method Three - The Function Key method</h3>                                        <p><p>This method is useful if you cannot boot into Windows 11 at all. However, note that on modern PCs with fast SSDs, the window to press these keys is extremely short, and the traditional "F8" key is disabled by default in Windows 11.</p></p>                </section><ol start="1"><li>Completely shut down your computer.</li><li>Turn the computer on and <strong>immediately</strong> start tapping the appropriate recovery key repeatedly.</li><li>The key varies by manufacturer: try <strong>F11</strong> (HP, Lenovo), <strong>F12</strong> (Dell), <strong>F9</strong> (Asus), or <strong>Esc</strong>.</li><li>If successful, you will see the "Choose an option" or "Recovery" screen.</li></ol><p><em>Note: On most modern Windows 11 PCs, the traditional F8 menu is disabled by default to speed up boot times. If F11 or Esc does not work, you will likely need to use Method Four (interrupting the boot process) instead.</em></p><section class="howto-block">                    <h3>Method Four - The ‘When all else fails’ method</h3>                                        <p><p>If you’ve tried everything else and still can’t trigger safe mode, there’s a workaround.</p></p>                </section><ol start="1"><li>Turn on the computer, then hold down the power button to interrupt the boot.</li><li>Repeat this process two more times.</li><li>On the third reboot, you’ll see the Startup Repair option.</li><li>Choose Advanced Options from here to enter Safe Mode.</li></ol><h2 class="article-body__section" id="section-navigating-the-recovery-menu"><span>Navigating the recovery menu</span></h2><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="K9hHXZLhBmqVpRScruPvf9" name="" alt="Screenshot showing Windows 11's recovery menu" src="https://cdn.mos.cms.futurecdn.net/K9hHXZLhBmqVpRScruPvf9.png" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>After following the steps outlined in any of the methods listed above, your PC will reboot into a recovery menu. At this stage, you will need to complete these steps:</p><ol start="1"><li>Click on ‘Troubleshoot’</li><li>Click on ‘Advanced Options’</li><li>Click on ‘Start Up Settings’</li><li>Click on ‘Restart’</li></ol><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kHL69Bux4BrtcZrT3yrzC9" name="" alt="Screenshot of Windows 11's recovery settings menu" src="https://cdn.mos.cms.futurecdn.net/kHL69Bux4BrtcZrT3yrzC9.png" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>After clicking Restart, your PC will reboot and display a numbered list of startup options. You cannot use your mouse on this screen; you must use the physical keyboard.</p><p>Press the number or Function key corresponding to your desired mode:</p><ul><li><strong>Press 4 (or F4)</strong> for Standard Safe Mode.</li><li><strong>Press 5 (or F5)</strong> for Safe Mode with Networking (drivers for Wi-Fi/Ethernet).</li><li><strong>Press 6 (or F6)</strong> for Safe Mode with Command Prompt.</li></ul><p>Whichever option you choose, your machine will immediately load into the Safe Mode environment.</p><h2 class="article-body__section" id="section-leaving-safe-mode"><span>Leaving Safe Mode</span></h2><p>A straightforward restart is typically sufficient to exit Safe Mode in Windows 11. You can do this by clicking the Start button, selecting the Power icon, and then choosing Restart. This action should reboot your system into its standard operating mode, restoring all personalized settings and functionalities.</p><p>However, there are instances where the system may persist in Safe Mode despite a restart. In such cases, manual intervention is required to reset the boot configuration:</p><p>1. Open the Run dialog box by pressing the Windows key + R. </p><p>2. Type msconfig and press Enter to launch the System Configuration utility. </p><p>3. Navigate to the 'Boot' tab.</p><p>4. Uncheck the 'Safe boot' option under Boot options. </p><p>5. Click 'Apply', then 'OK'. </p><p>6. Restart your computer. </p><p>This process modifies the boot settings to ensure that Windows 11 starts in its normal mode. </p><h2 class="article-body__section" id="section-safe-mode-for-system-restore-in-windows-11"><span>Safe Mode for System Restore in Windows 11</span></h2><p>Integrating System Restore with Windows 11's Safe Mode offers a method for addressing system issues, such as crashes or irregular behaviour following software installations. </p><p>Using Safe Mode, which runs with minimal drivers and services, allows you to perform a System Restore without interference from third-party applications or problematic drivers, facilitating a smoother recovery process.</p><h2 id="benefits-of-using-system-restore-in-safe-mode">Benefits of Using System Restore in Safe Mode</h2><p>Using System Restore in Safe Mode is useful for resolving issues caused by recent updates or drivers. It allows you to revert to a stable state with minimal risk, as only essential system files and services operate during restoration.</p><h2 id="steps-to-perform-system-restore-in-safe-mode">Steps to Perform System Restore in Safe Mode</h2><p>Performing a System Restore in Safe Mode is a reliable method to resolve software-induced problems, potentially saving time that might otherwise be spent on manual troubleshooting.​</p><p>After clicking Restart, your PC will reboot and display a numbered list of startup options. You cannot use your mouse on this screen; you must use the physical keyboard.</p><p>Press the number or Function key corresponding to your desired mode:</p><ul><li><strong>Press 4 (or F4)</strong> for Standard Safe Mode.</li><li><strong>Press 5 (or F5)</strong> for Safe Mode with Networking (drivers for Wi-Fi/Ethernet).</li><li><strong>Press 6 (or F6)</strong> for Safe Mode with Command Prompt.</li></ul><p>Whichever option you choose, your machine will immediately load into the Safe Mode environment.</p><h2 id="considerations">Considerations</h2><p>System Restore is a useful tool, but it is important to understand its limitations. It may not resolve issues caused by hardware malfunctions or severe malware infections. </p><p>While System Restore does not affect personal files, it can remove recently installed applications and drivers. Therefore, it is wise to regularly back up important data and ensure that System Restore is properly enabled and configured on your system.</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=45431401&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Singapore government expands bug bounty programme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/360723/singapore-expands-bug-bounty-programme</link>
                                                                            <description>
                            <![CDATA[ White hat hackers could earn up to $5,000 for any vulnerabilities they report through HackerOne ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uV1pCWzVRN294dVGg6P9vj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WMEar7ZBE87ojcXBdnVcuA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 31 Aug 2021 09:40:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WMEar7ZBE87ojcXBdnVcuA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A depiction of a bug on a blue binary background]]></media:description>                                                            <media:text><![CDATA[A depiction of a bug on a blue binary background]]></media:text>
                                <media:title type="plain"><![CDATA[A depiction of a bug on a blue binary background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WMEar7ZBE87ojcXBdnVcuA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Singapore government is expanding its bug bounty programme to enable which white hat hackers to earn up to $5,000 for vulnerabilities they report through <a href="https://www.itpro.com/security/hacking" target="_blank" data-original-url="https://www.itpro.com/search/hackerone">HackerOne</a>.</p><p>The Government Technology Agency (GovTech) has launched a new Vulnerability Rewards Programme (VRP) as part of its Government Bug Bounty Programme (GBBP) and Vulnerability Disclosure Programme (VDP) which it says will supplement its suite of <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/search/cyber%20security">cyber security</a> capabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/360584/linkedin-pilot-skills-programme-singapore" data-original-url="/business-strategy/careers-training/360584/linkedin-pilot-skills-programme-singapore">LinkedIn launches pilot skills programme in Singapore</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform" data-original-url="/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform">Google launches new bug bounty platform</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program" data-original-url="/security/bugs/359827/cisa-launches-security-bug-reporting-program">CISA launches security bug reporting program</a></p></div></div><p>The VRP aims to continuously test a wider range of critical ICT systems necessary for the continuous delivery of essential services in the country’s <a href="https://www.itpro.com/business/digital-transformation" target="_blank" data-original-url="https://www.itpro.com/search/digital%20economy">digital economy</a>, the government stated.</p><p>The programme offers monetary rewards ranging from $250 to $5,000 to white hat hackers depending on the severity of vulnerabilities discovered. It is also offering a special bounty of $150,000 for the discovery of vulnerabilities that could cause “exceptional impact on selected systems and data”, which is benchmarked against other bounty programmes conducted by global tech firms like <a href="https://www.itpro.com/software/google" target="_blank" data-original-url="https://www.itpro.com/search/google">Google</a> and <a href="https://www.itpro.com/software/microsoft" target="_blank" data-original-url="https://www.itpro.com/search/microsoft">Microsoft</a>.</p><p>“Since the launch of our first crowdsourced vulnerability discovery programme in 2018, we have partnered with over 1,000 highly skilled white hat hackers to discover about 500 valid vulnerabilities,” said Lim Bee Kwan, assistant chief executive for governance and cybersecurity at GovTech.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PGoruQcVQLZaD3tFfbynhC" name="PGoruQcVQLZaD3tFfbynhC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PGoruQcVQLZaD3tFfbynhC.png" mos="https://cdn.mos.cms.futurecdn.net/PGoruQcVQLZaD3tFfbynhC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of Mimecast</strong></p><p class="fancy-box__body-text">Cost savings and business benefits enabled by using Mimecast with Microsoft 365</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/359472/the-total-economic-impacttm-of-mimecast" data-original-url="/security/cyber-crime/359472/the-total-economic-impacttm-of-mimecast">FREE DOWNLOAD</a></p></div></div><p>“The new Vulnerability Rewards Programme will allow the Government to further tap the global pool of cybersecurity talents to put our critical systems to the test, keeping citizens’ data secured to build a safe and secure Smart Nation.”</p><p>Currently, the programme will cover three systems, Singpass and Corppass (GovTech), Member e-services (Ministry of Manpower), and Workpass Integrated System 2 (Ministry of Manpower), with more critical ICT systems set to be added to the programme in the future.</p><p>The government said that only white hat hackers who have met strict criteria will be allowed to participate, as “these are systems that are critical to the delivery of essential government services”. The checks will be carried out by HackerOne and registered participants will carry out security testing through a <a href="https://www.itpro.com/software/vpn" target="_blank" data-original-url="https://www.itpro.com/search/vpn">VPN</a>, which will also be provided by the bug bounty company.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google launches new bug bounty platform ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ethical-hacking/360394/google-launches-new-bug-bounty-platform</link>
                                                                            <description>
                            <![CDATA[ Vulnerability hunters will be able to improve their skills through the newly launched Bug Hunter University ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qHzmz8RHKtVbAHk9g2n5KG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rzbbePFwKtpa9HpTeo4kz9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Jul 2021 11:25:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rzbbePFwKtpa9HpTeo4kz9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up Google logo with the security lock icon isolated on black background]]></media:description>                                                            <media:text><![CDATA[Close up Google logo with the security lock icon isolated on black background]]></media:text>
                                <media:title type="plain"><![CDATA[Close up Google logo with the security lock icon isolated on black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rzbbePFwKtpa9HpTeo4kz9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced the launch of a new bug bounty platform that will make it easier for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">vulnerability hunters</a> to submit issues.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months" data-original-url="/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months">Microsoft awarded $13.6 million in bug bounties over the last 12 months</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/360310/google-cloud-rolls-out-new-security-capabilities-following-surge-in" data-original-url="/cloud/cloud-security/360310/google-cloud-rolls-out-new-security-capabilities-following-surge-in">Google Cloud beefs up security following surge in ransomware attacks</a></p></div></div><p>Available under bughunters.google.com, the platform brings together all of the tech giant’s vulnerability reward programmes (VRP) – Google, Android, Abuse, <a href="https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices" data-original-url="https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices">Chrome</a>, and Play – with hunters able to submit issues using a single intake form.</p><p>Moreover, the new platform will provide more opportunities for interaction with other hunters through gamification, including awards and badges for certain bug-reporting achievements. </p><p>Google has also improved its VRP leaderboards, which will now be “more functional and aesthetically pleasing”, as well as show the best hunters per country, making it easier to use the results to boost a CV when applying for a job in tech.</p><p>The new platform also provides greater emphasis on research and education, making it easier for hunters to publish their bug reports in order to share their knowledge. Hunters will also be able to improve their skills through the newly-launched <a href="http://goo.gle/bhu">Bug Hunter University</a>, which includes courses on how to submit a successful vulnerability report.</p><p>Research papers on the security of open source will be <a href="https://bughunters.google.com/about/rules/5122527111938048">eligible for a reward</a>, just like open source software <a href="http://goo.gle/patchz">patch submissions</a>, while hunters improving security in open source programmes will be eligible to <a href="http://goo.gle/subsidiz">apply for a grant</a> to better secure their own projects.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gGRwbS6T2JYCbdQmJ8xJri" name="gGRwbS6T2JYCbdQmJ8xJri.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" mos="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to increase cyber resilience within your organisation</strong></p><p class="fancy-box__body-text">Cyber resilience for dummies</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation" data-original-url="/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation">FREE DOWNLOAD</a></p></div></div><p>Commenting on the announcement, Google VRP technical programme manager, Jan Keller, <a href="https://security.googleblog.com/2021/07/a-new-chapter-for-googles-vulnerability.html">said</a> that when Google launched its “very first VRP” over a decade ago, no one knew “how many valid vulnerabilities – if any – would be submitted on the first day”.</p><p>“Everyone on the team put in their estimate, with predictions ranging from zero to 20. In the end, we actually received more than 25 reports, taking all of us by surprise,” he added.</p><p>Three years later, the programme was expanded to include <a href="https://www.itpro.com/security/software-vulnerability/20766/google-launches-open-source-bug-bounty-programme" data-original-url="https://www.itpro.com/security/software-vulnerability/20766/google-launches-open-source-bug-bounty-programme">open source</a> as well as <a href="https://www.itpro.com/security/21057/google-extends-open-source-bug-bounty-programme-android-and-apache" data-original-url="https://www.itpro.com/security/21057/google-extends-open-source-bug-bounty-programme-android-and-apache">Google Android and Apache</a>.</p><p>“Since its inception, the VRP programme has not only grown significantly in terms of report volume, but the team of security engineers behind it has also expanded – including almost 20 bug hunters who reported vulnerabilities to us and ended up joining the Google VRP team. That is why we are thrilled to bring you this new platform, continue to grow our community of bug hunters and support the skill development of up-and-coming vulnerability researchers,” said Keller.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Faulty Windows 10 update breaks printing with smart cards ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/360355/fault-windows-update-breaks-printing-with-smart-cards</link>
                                                                            <description>
                            <![CDATA[ Microsoft’s 2021 printing woes continue after several vulnerabilities were found in the Print Spooler component ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jmZCVa3XhfJoZY5dfXWBko</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6KkdCPUDoaPNLRQmrgeRvd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Jul 2021 11:24:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6KkdCPUDoaPNLRQmrgeRvd-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A broken window pane]]></media:description>                                                            <media:text><![CDATA[A broken window pane]]></media:text>
                                <media:title type="plain"><![CDATA[A broken window pane]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6KkdCPUDoaPNLRQmrgeRvd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has <a href="https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-21h1#1663msgdesc" target="_blank">confirmed</a> that its recent Patch Tuesday round of fixes for Windows 10 has introduced a bug that’s causing issues when users try to print or scan using smart cards for authentication.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/354585/whatever-happened-to-the-3d-printing-revolution" data-original-url="/technology/354585/whatever-happened-to-the-3d-printing-revolution">Whatever happened to the 3D printing revolution?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/exploits/360091/hackers-are-abusing-the-leaked-printnightmare-windows-exploit" data-original-url="/security/exploits/360091/hackers-are-abusing-the-leaked-printnightmare-windows-exploit">Instructions on how to exploit Windows Print Spooler accidentally leaked after research blunder</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/356077/microsofts-may-update-is-wreaking-havoc-on-all-types-of" data-original-url="/operating-systems/microsoft-windows/356077/microsofts-may-update-is-wreaking-havoc-on-all-types-of">Microsoft’s latest Windows 10 update is wreaking havoc on printers</a></p></div></div><p>As part of the wave of updates <a href="https://www.itpro.com/security/vulnerability/360072/weekly-threat-roundup-cisco-windows-google-cloud-vms" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/360072/weekly-threat-roundup-cisco-windows-google-cloud-vms">released on 13 July</a>, Microsoft attempted to fix an issue affecting printers that were connected to machines through USB connections. However, after installing the updates on domain controllers (DCs), administrators might find that some multifunctional printers will fail to print when using <a href="https://www.itpro.com/security/encryption/356207/company-launches-end-to-end-encryption-service-for-feds" target="_blank" data-original-url="https://www.itpro.com/security/encryption/356207/company-launches-end-to-end-encryption-service-for-feds">smart card (PIV) authentication</a>. </p><p>These ID cards are often used in secure environments and workplaces with contactless card readers for gaining entry to certain areas and are also attached to devices such as printers to authenticate identities prior to their usage. The affected machines are printers and scanners that aren’t compliant with section 3.2.1 of <a href="https://www.ietf.org/rfc/rfc4556.txt">RFC 4556 spec</a>, according to Microsoft. </p><p>“If you encounter this issue with your printing or scanning devices, verify that you are using the latest firmware and drivers available for your device,” a Microsoft advisory said. “If your firmware and drivers are up-to-date and you still encounter this issue, we recommend that you contact the device manufacturer. </p><p>“Ask if a setting or configuration change is required to bring the device into compliance with the hardening change or if a compliant update will be available.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bcLWVstWjYdjhPzEY5EUG3" name="bcLWVstWjYdjhPzEY5EUG3.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bcLWVstWjYdjhPzEY5EUG3.png" mos="https://cdn.mos.cms.futurecdn.net/bcLWVstWjYdjhPzEY5EUG3.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Nine traits you need to succeed as a cyber security leader</strong></p><p class="fancy-box__body-text">What characteristics and certifications make a successful cyber security leader?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360350/nine-traits-you-need-to-succeed-as-a-cyber-security-leader" data-original-url="/security/cyber-security/360350/nine-traits-you-need-to-succeed-as-a-cyber-security-leader">FREE DOWNLOAD</a></p></div></div><p>The firm confirmed it’s working on a temporary mitigation, but this isn’t yet available to share. This should allow printing and scanning on affected devices, allowing time for manufacturers to release compliant firmware and drivers for their devices. </p><p>This issue might cause a nightmare for workers in certain office environments that rely on smart card-compatible printers. It follows a string of issues in Windows deployments this year, including a <a href="https://www.itpro.com/security/vulnerability/360275/alarm-sounded-over-further-printspooler-vulnerabilities" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/360275/alarm-sounded-over-further-printspooler-vulnerabilities">string of vulnerabilities detected in the Print Spooler component</a>.</p><p>For example, users encountered several printer-related problems in the Patch Tuesday round of fixes released on 9 March this year, <a href="https://www.neowin.net/news/microsoft-releases-additional-updates-to-resolve-some-more-printer-problems" target="_blank">according to <em>Neowin</em></a>. Some instances even resulted in users encountered a blue screen of death when trying to print as a result of driver conflicts. These were subsequently fixed on 15 March in an emergency fix. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google coding typo effectively bricks Chrome OS devices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/operating-systems/360341/google-coding-typo-effectively-bricks-chrome-os-devices</link>
                                                                            <description>
                            <![CDATA[ A hastily released update prevented users from logging into their machines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kQBrRSaWoKooJcyLfk3UVS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dz2CcDDnKu7hsW4QTuNEED-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Jul 2021 11:11:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dz2CcDDnKu7hsW4QTuNEED-1280-80.jpg">
                                                            <media:credit><![CDATA[Keumars Afifi-Sabet/IT Pro]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chromebook logo of the HP Pro c640 Chromebook]]></media:description>                                                            <media:text><![CDATA[Chromebook logo of the HP Pro c640 Chromebook]]></media:text>
                                <media:title type="plain"><![CDATA[Chromebook logo of the HP Pro c640 Chromebook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dz2CcDDnKu7hsW4QTuNEED-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has fixed a serious bug in a <a href="https://www.itpro.com/tag/google-chrome" data-original-url="https://www.itpro.com/search/chrome%20os">Chrome OS</a> stable channel update released earlier this week that locked Chromebook users out of their machines.</p><p>The verification error, present in version 91.1.4472.165, came as a result of a single character typo in a string of code in Chrome OS’s Cryptohome VaultKeyset, which is the portion of the operating system that holds user encryption keys.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/video-conferencing/358643/google-introduces-new-video-tools-for-meet-chrome-os" data-original-url="/software/video-conferencing/358643/google-introduces-new-video-tools-for-meet-chrome-os">Google introduces new video tools for Meet, Chrome OS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/laptops/360016/acer-chromebook-spin-713-review-a-high-end-package-with-a-budget-price" data-original-url="/hardware/laptops/360016/acer-chromebook-spin-713-review-a-high-end-package-with-a-budget-price">Acer Chromebook Spin 713 review: A high-end package with a budget price</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/laptops/358322/hp-pro-c640-chromebook-review-nailing-the-basics" data-original-url="/hardware/laptops/358322/hp-pro-c640-chromebook-review-nailing-the-basics">HP Pro c640 Chromebook review: Nailing the basics</a></p></div></div><p>The string in question was a conditional statement that included a single ampersand, ‘&’, <a href="https://chromium-review.googlesource.com/c/chromiumos/platform2/+/3039560/2/cryptohome/vault_keyset.cc#471">instead of two ampersands, ‘&&’</a>, which is the AND operator in C++. As a result, the conditional statement was broken and meant that Chrome OS was unable to check user passwords against those stored.</p><p>This meant, in practice, that all users who had updated to 91.1.4472.165 were met with error messages, even if they had entered the correct password to access their user account. For some users, their devices were even stuck in a boot loop that meant they couldn’t even reach the login screen.</p><p>Google rolled out the buggy update through its stable channel last weekend, which bypassed several of its testing channels including the ‘canary’, ‘dev’, and ‘beta’ channels.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CZNNbjT89BEPQ8cC5AnjQV" name="CZNNbjT89BEPQ8cC5AnjQV.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/CZNNbjT89BEPQ8cC5AnjQV.jpg" mos="https://cdn.mos.cms.futurecdn.net/CZNNbjT89BEPQ8cC5AnjQV.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>DevOps: A view from the enterprise</strong></p><p class="fancy-box__body-text">What's driving DevOps, the impact of value stream management, and more</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/devops/360223/devops-a-view-from-the-enterprise" data-original-url="/development/devops/360223/devops-a-view-from-the-enterprise">FREE DOWNLOAD</a></p></div></div><p>It was then almost immediately met with widespread complaints on social media platforms such as Reddit. There were <a href="https://www.reddit.com/r/chromeos/comments/onlcus/update_it_seems_google_has_pulled_the_165_stable">several threads</a> and hundreds of posts on the <a href="https://www.reddit.com/r/chromeos" target="_blank">r/chromeos page</a> from users reporting they were unable to access their machines properly, alongside messages warning others not to update to the latest version of Chrome OS.</p><p>Google’s <a href="https://www.reddit.com/r/chromeos/comments/onlcus/update_it_seems_google_has_pulled_the_165_stable/h5wj8qd/?utm_source=share&utm_medium=web2x&context=3">engineering team quickly identified the bug</a> and halted the rollout of the Chrome OS update on Tuesday, promising a new version the following day. In the meantime, the team <a href="https://support.cloud.google.com/portal/system-status?start_time=1626753600000">recommended</a> either factory resetting the device or rolling back the Chrome OS device to a previous version via USB. The firm released version 91.1.4472.167 the next day.</p><p>This is the second major bug that’s slipped into the stable channel for Chrome OS updates this month. Another bug that slipped into a final release caused extremely high CPU usage spikes, <a href="https://www.androidpolice.com/2021/07/15/you-might-not-want-to-update-your-chromebook-to-the-latest-chrome-os-release-just-yet">according to <em>Android Police</em></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft awarded $13.6 million in bug bounties over the last 12 months ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/360167/microsoft-awarded-136-million-in-bug-bounties-over-the-last-12-months</link>
                                                                            <description>
                            <![CDATA[ Over 340 security researchers from 58 countries reported a total of 1,261 valid vulnerabilities between 2020-2021 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5dq9gR2Z2HngSWVZ57RdHy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/a6UYCVj2xe9xHmoYCjcSBe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jul 2021 10:54:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/a6UYCVj2xe9xHmoYCjcSBe-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft sign-in page on screen]]></media:description>                                                            <media:text><![CDATA[Microsoft sign-in page on screen]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft sign-in page on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/a6UYCVj2xe9xHmoYCjcSBe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has said it awarded over $13.6 million (£9.87 million) in rewards to <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researchers participating in its public bug bounty programmes over the last 12 months.</p><p>Between 1 July 2020 and 30 June 2021, over 340 security researchers from across 58 countries participated in the tech giant’s 17 software bug hunts, reporting a total of 1,261 valid vulnerabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/360028/48-of-enterprise-5g-operators-lack-the-tools-or-knowledge-to-fix-security-bugs" data-original-url="/mobile/5g/360028/48-of-enterprise-5g-operators-lack-the-tools-or-knowledge-to-fix-security-bugs">Half of enterprise 5G operators lack the tools to fix security bugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/360027/microsoft-fixes-windows-11-upgrade-bug" data-original-url="/operating-systems/microsoft-windows/360027/microsoft-fixes-windows-11-upgrade-bug">Microsoft fixes Windows 11 upgrade bug</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year" data-original-url="/software/development/360020/github-bug-bounties-pay-out-over-500000-in-last-year">GitHub bug bounty payouts surpass $1.5 million</a></p></div></div><p>The number of participating researchers grew by at least a dozen since the same period last year, when Microsoft awarded <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">$13.7 million to 327 security researchers</a>. Since then, the tech giant has added two more bug bounty programmes, including <a href="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams" data-original-url="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams">one for its Teams desktop client</a> with potential rewards of up to $30,000, and saw the number of vulnerability reports increase by 35.</p><p>However, despite the reward amount tripling between 2019 and 2020, 2021 saw a slight decrease, of around $100,000.</p><p>Over the last 12 months, the highest number of bug reports were submitted from security researchers based in China, the US, Israel, and India. Although the average reward was over $10,000 (£7,260), the largest payout – $200,000 (£145,000) – was awarded for a vulnerability reported in Microsoft’s OS virtualisation technology, Hyper-V, under the <a href="https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1">Hyper-V Bounty Programme</a>.</p><p>Microsoft Security Response Center members Jarek Stanley, Lynn Miyashita, and Madeline Eckert thanked “everyone who shared their research with Microsoft this year and for their partnership in securing millions of customers”, in a statement on the company’s <a href="https://msrc-blog.microsoft.com/2021/07/08/microsoft-bug-bounty-programs-year-in-review-13-6m-in-rewards">blog</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ffna7TmpqYrgTZpXMRi9u6" name="ffna7TmpqYrgTZpXMRi9u6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" mos="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave: Top security analytics platforms</strong></p><p class="fancy-box__body-text">The 11 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms" data-original-url="/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms">FREE DOWNLOAD</a></p></div></div><p>“We’re constantly evaluating the threat landscape to evolve our programmes and listening to feedback from researchers to help make it easier to share their research. This year, we introduced new challenges and scenarios to award research focused on the highest impact to customer security.</p><p>"These focus areas helped us not only discover and fix risks to customer privacy and security, but also offer researchers top awards for their high-impact work,” they said, adding that the Microsoft Security Response Center will share “more bounty programme updates and improvements in the coming year”.</p><p>The title of the Most Valuable Security Researcher 2021 is to be announced in August.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Atlassian patches One-Click flaw that allowed hackers to steal user sessions ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/360006/atlassian-patches-one-click-flaw-that-allowed-hackers-to-steal-user</link>
                                                                            <description>
                            <![CDATA[ With the stolen session, the hacker could steal sensitive information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dBFWAn7yF2c3jnc4D1xZqW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/akQN9ftBBPYFhHPQxSGBmb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Jun 2021 13:27:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/akQN9ftBBPYFhHPQxSGBmb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Atlassian logo on a computer screen]]></media:description>                                                            <media:text><![CDATA[Atlassian logo on a computer screen]]></media:text>
                                <media:title type="plain"><![CDATA[Atlassian logo on a computer screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/akQN9ftBBPYFhHPQxSGBmb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have warned of a critical flaw in the Atlassian project and software development platform that hackers can use to take over an account and control some of the apps connected through its single sign-on (SSO) capability.</p><p><a href="https://research.checkpoint.com/2021/a-supply-chain-breach-taking-over-an-atlassian-account">According to Check Point Research (CPR)</a>, hackers could exploit the flaw to access Atlassian’s Jira, a bug-tracking and agile project-management tool used by over 65,000 customers, including Cisco, Pfizer, and Visa.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/358650/atlassians-new-cloud-offering-addresses-enterprises-core-needs" data-original-url="/cloud/cloud-management/358650/atlassians-new-cloud-offering-addresses-enterprises-core-needs">Atlassian’s new cloud offering addresses enterprises’ core needs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/357467/atlassian-to-end-on-prem-support-by-2024-in-major-cloud-pivot" data-original-url="/cloud/357467/atlassian-to-end-on-prem-support-by-2024-in-major-cloud-pivot">Atlassian to end on-prem server support by 2024 in major cloud pivot</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/32152/atlassians-jira-software-cloud-is-now-generally-available" data-original-url="/cloud/32152/atlassians-jira-software-cloud-is-now-generally-available">Atlassian's Jira software cloud is now generally available</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/359961/nvidia-jetson-chips-make-iot-devices-vulnerable-to-attack" data-original-url="/security/vulnerability/359961/nvidia-jetson-chips-make-iot-devices-vulnerable-to-attack">Nvidia Jetson chips make IoT devices vulnerable to attack</a></p></div></div><p>The flaw focuses on Atlassian’s use of SSO to ensure continuous navigation between subdomains for related products, such as Jira (jira.atlassian.com) and Confluence (confluence.atlassian.com). This creates a potential attack scenario involving injecting malicious code into the platform, then leveraging a session fixation flaw to hijack a valid user session and take control of an account.</p><p>Researchers proved that account takeover was possible on Atlassian accounts accessible by subdomains under atlassian.com. </p><p>To exploit the flaw, hackers would have to lure a victim into clicking on a crafted link coming from the “Atlassian” domain via <a href="https://www.itpro.com/technology/social-media" data-original-url="https://www.itpro.com/tags/social-media">social media</a>, a fake email, or a messaging app, etc. By clicking on the link, the payload would send a request on the victim’s behalf to the Atlassian platform, which would perform the attack and steal the user session. Then the hacker logs onto the victim's Atlassian apps associated with the account, gaining all the sensitive information stored there.</p><p>“What makes a supply chain attack such as this one so significant is the fact that once the attacker leverages these vulnerabilities and takes over an account, he can plant backdoors that he can use in the future for his attack. This can create severe damage which will be identified and controlled only much after the damage is done,” said researchers.</p><p>Lewis Jones, threat intelligence analyst at Talion, told <em>ITPro</em> that successfully exploiting these flaws could result in a supply-chain attack whereby an attacker can take over an account, use it to perform unauthorized actions, such as edit Confluence pages, access Jira tickets, and even inject malicious implants to stage further attacks down the line. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bRgjxZYos5Bjth4n8XKXvf" name="bRgjxZYos5Bjth4n8XKXvf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" mos="https://cdn.mos.cms.futurecdn.net/bRgjxZYos5Bjth4n8XKXvf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The definitive guide to IT security</strong></p><p class="fancy-box__body-text">Protecting your MSP and your customers</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security" data-original-url="/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security">FREE DOWNLOAD</a></p></div></div><p>“Furthermore, if an attacker gains access to a Jira account, the attacker can proceed to gain control of a Bitbucket account which could lead to an attacker being able to pilfer credentials. This could grant them permissions to access or alter source code, make the repository public, or even insert backdoors,” he said.</p><p>“Whilst details have recently emerged, a fix for the flaw was released in May. Users are advised to ensure that updates are implemented as soon as possible, and to continue monitoring for any further developments."</p><p>CPR disclosed its research findings to Atlassian on January 8, and Atlassian deployed a fix on May 18.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA launches security bug reporting program  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/359827/cisa-launches-security-bug-reporting-program</link>
                                                                            <description>
                            <![CDATA[ Now white hat hackers have a way to tell the government about bugs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m9MEVoBJQYTug6k53dqBx5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/j6R2EGh2rKSsbwP9XrD4K4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Jun 2021 17:09:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/j6R2EGh2rKSsbwP9XrD4K4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bug surrounding by computer code and jargon]]></media:description>                                                            <media:text><![CDATA[Bug surrounding by computer code and jargon]]></media:text>
                                <media:title type="plain"><![CDATA[Bug surrounding by computer code and jargon]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/j6R2EGh2rKSsbwP9XrD4K4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Cybersecurity and Infrastructure Security Agency (CISA) plans to launch a crowdsourced bug reporting site serving a range of federal government agencies. The Department of Homeland Security's cyber arm will work with Bugcrowd, a crowdsourced bug reporting site, to launch the project. </p><p>CISA will offer the bug reporting platform to federal government <a href="https://cyber.dhs.gov/agencies">agencies</a>. While it won't be a paid bug bounty program, it'll give security researchers a way to report bugs to government organizations through a system that guarantees a response and ensures officials note all bugs. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams" data-original-url="/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams">Microsoft launches bug bounty programme for Teams</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/358867/sovryn-announces-125-million-bug-bounty-program" data-original-url="/security/bugs/358867/sovryn-announces-125-million-bug-bounty-program">Sovryn announces $1.25 million bug bounty program</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme" data-original-url="/security/358083/mod-launches-bug-bounty-programme">MoD launches bug bounty programme</a></p></div></div><p>The deal follows the announcement of <a href="https://cyber.dhs.gov/bod/20-01">Binding Operational Directive 20-01</a> last September, in which CISA laid out plans to create a vulnerability disclosure policy (VDP). It directed agencies to publish a VDP policy on their websites within 180 days, describing what systems it covers and how security researchers can report bugs. It also mandates timelines for acknowledging and dealing with each bug. </p><p>Government technology contractor Endyna will support the reporting platform under a one-year software as a service (SaaS) contract. The arrangement includes an optional extension of up to four years. </p><p>The VDP effort has been brewing for a while. CISA originally published the draft of BDO 20-01 in November 2019, <a href="https://www.cisa.gov/blog/2019/11/27/improving-vulnerability-disclosure-together">inviting</a> public comment on the issue. The final BDO — and the forthcoming program — will carry forward some of CISA's original suggestions, including the mandatory inclusion of all new computing systems in the scope of an agency's VDP. </p><p>The directive also set out a two-year deadline for including all internet-accessible systems in agency VDPs. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HuVkXKYxS9nVFkEwoBk7MR" name="HuVkXKYxS9nVFkEwoBk7MR.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" mos="https://cdn.mos.cms.futurecdn.net/HuVkXKYxS9nVFkEwoBk7MR.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Don’t just educate: Create cyber-safe behaviour</strong></p><p class="fancy-box__body-text">Designing effective security awareness and training programmes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour" data-original-url="/business-strategy/training/356984/dont-just-educate-create-cybersafe-behaviour">FREE DOWNLOAD</a></p></div></div><p>If nothing else, this should reduce the danger of legal threats against white hat hackers trying to report bugs to federal agencies. It mandates that agencies not issue threatening language as part of their VDP or pursue legal action against researchers trying to report bugs in good faith. </p><p>The directive also states CISA won't send any bugs it collects to the Vulnerabilities Equities Process (VEP). VEP is a government initiative that gives intelligence officials the option to store bugs secretly as potential weapons rather than releasing them to the public. </p><p>The Pentagon has taken its own approach to vulnerability reporting by offering paid bug bounty programs, including a new one launched this week.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple patches exploited iOS and macOS WebKit flaws ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/zero-day-exploit/359407/apple-patches-ios-macos-webkit-flaws</link>
                                                                            <description>
                            <![CDATA[ iPhone, iPad, Apple Watch users may have been subject to arbitrary code execution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bRsc5fkYwfuPxQrXA2DcWt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 May 2021 10:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:description>                                                            <media:text><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:text>
                                <media:title type="plain"><![CDATA[An anonymous mobile phone user using their device in a darkened room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dunZGYN9Pny39MvC8xZM3h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has released security updates addressing zero-day vulnerabilities in its WebKit browser engine, which is primarily used in Safari and any other web browsers available on iOS, as well as Apple Mail and the App Store.</p><p>The two vulnerabilities, known as CVE-2021-30665 and CVE-2021-30663, allowed hackers to execute arbitrary remote code execution (RCE) on any device that had visited a malicious website.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/358041/microsoft-teams-wormable-rce-flaw" data-original-url="/security/358041/microsoft-teams-wormable-rce-flaw">Zero-click 'wormable' RCE flaw uncovered in Microsoft Teams</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359394/apple-charged-over-breach-of-eu-anti-competition-rules" data-original-url="/business/policy-legislation/359394/apple-charged-over-breach-of-eu-anti-competition-rules">Apple charged over breach of EU anti-competition rules</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359405/apple-hires-google-ai-veteran-samy-bengio" data-original-url="/technology/artificial-intelligence-ai/359405/apple-hires-google-ai-veteran-samy-bengio">Apple hires Google AI veteran Samy Bengio amid ethics controversy</a></p></div></div><p>CVE-2021-30665 had been reported by Beijing-based <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researcher <a href="https://twitter.com/dnpushme">Yang Kang</a> and Bian Liang, who is reportedly a researcher for antivirus provider Qihoo 360 ATA. The researcher who had discovered CVE-2021-30663 opted to remain anonymous.</p><p>Devices that may have been exploited by the two bugs include iPhone 6s and later, all models of iPad Pro, iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, the 7th generation iPod touch, as well as the Apple Watch Series 3 and later.</p><p>The security updates iOS 14.5.1 and iPadOS 14.5.1 were released on Monday to remedy the issues, which Apple described as “a memory corruption issue” and “an integer overflow”, which were “addressed with improved state management”.</p><p>The latest security update is also a fix for issues with Apple’s new <a href="https://www.itpro.com/security/privacy/359341/apples-ios-145-released-tracking-update" data-original-url="https://www.itpro.com/security/privacy/359341/apples-ios-145-released-tracking-update">App Tracking Transparency (ATT)</a>, which was released with iOS 14.5.</p><p>"This update fixes an issue with App Tracking Transparency where some users who previously disabled Allow Apps to Request to Track in Settings may not receive prompts from apps after re-enabling it," Apple stated in its <a href="https://support.apple.com/en-us/HT211808">iOS 14.5.1 release notes</a>.</p><p>Apple also released an update for macOS Big Sur, labelled 11.3.1.</p><p>All three security updates were described as remedies to CVE-2021-30663 and CVE-2021-30665, with the tech giant stating that it “is aware of a report that this issue may have been actively exploited”.</p><p>However, the scope of the issue, as well as the number of affected users was not made publicly available. <em>IT Pro</em> has contacted Apple for comment and will update this story when more information becomes available.</p><p>The new security updates come just days after iOS 14.5, released on 27 April, which removed default data tracking and made it a requirement for <a href="https://www.itpro.com/development/34728/learn-to-code-for-free-the-best-uk-coding-and-app-development-courses" data-original-url="https://www.itpro.com/development/34728/learn-to-code-for-free-the-best-uk-coding-and-app-development-courses">app developers</a> to present users with a pop-up notification asking them to consent to be tracked.</p><p>In the months coming up to the release of iOS 14.5, <a href="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war" data-original-url="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war">Facebook publicly campaigned against</a> this decision, arguing that it would severely harm the revenues of its advertising partners, many of which are smaller companies.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft launches bug bounty programme for Teams ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/359024/microsoft-launches-bug-bounty-programme-for-teams</link>
                                                                            <description>
                            <![CDATA[ The programme will award bug hunters up to $30,000 for the most severe exploits ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pDmbDZTdrpkeEDZ3tDTjfh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g4JXbcJ2DfcDZthpVKj4o4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Mar 2021 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft Office]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g4JXbcJ2DfcDZthpVKj4o4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Microsoft Teams app logo displayed on a smartphone]]></media:description>                                                            <media:text><![CDATA[The Microsoft Teams app logo displayed on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[The Microsoft Teams app logo displayed on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g4JXbcJ2DfcDZthpVKj4o4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has launched a bug bounty reward programme for its Teams desktop client with potential rewards of up to $30,000.</p><p>The reward scheme falls under the new Microsoft Applications Bounty Programme, which so far only covers Microsoft Teams but will be expanded to include others in the near future.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft tripled bug bounty payouts to $13.7m last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358083/mod-launches-bug-bounty-programme" data-original-url="/security/358083/mod-launches-bug-bounty-programme">MoD launches bug bounty programme</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/358867/sovryn-announces-125-million-bug-bounty-program" data-original-url="/security/bugs/358867/sovryn-announces-125-million-bug-bounty-program">Sovryn announces $1.25 million bug bounty program</a></p></div></div><p>Lynn Miyashita, programme manager at Microsoft Security Response Centre (MSRC), <a href="http://msrc-blog.microsoft.com/2021/03/24/introducing-bounty-awards-for-teams-desktop-client-security-research">said</a>: “Partnering with the security research community is an important part of Microsoft’s holistic approach to defending against security threats. As much of the world has shifted to working from home in the last year, <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/358985/microsoft-in-talks-to-buy-discord-for-10bn" target="_blank" data-original-url="https://www.itpro.com/business-strategy/mergers-and-acquisitions/358985/microsoft-in-talks-to-buy-discord-for-10bn">Microsoft</a> Teams has enabled people to stay connected, organized, and collaborate remotely.</p><p>“Microsoft and security researchers across the planet continue to partner to help secure customers and the technologies we use for remote collaboration.”</p><p>The programme includes scenario-based bounty awards for vulnerabilities that have the highest potential impact on customer privacy and security. The <a href="https://www.itpro.com/cloud/microsoft-azure/355567/microsoft-offers-hackers-100k-to-break-azure-sphere" target="_blank" data-original-url="https://www.itpro.com/cloud/microsoft-azure/355567/microsoft-offers-hackers-100k-to-break-azure-sphere">rewards</a> for this range between $6,000 to $30,000.</p><p>There are also general bounty rewards for other valid vulnerability reports for the Teams desktop client, with the rewards ranging from $500 to $15,000. Microsoft will also accept submissions for Teams online services, but those will be rewarded under the <a href="https://www.microsoft.com/en-us/msrc/bounty-online-services?rtc=1" target="_blank">Online Services Bounty Program</a>, where rewards are between $500 to $20,000.</p><p>Valid reports for Microsoft Teams research are also eligible for a 2x bonus multiplier under the <a href="https://www.microsoft.com/en-us/msrc/researcher-recognition-program" target="_blank">Research Recognition Programme</a>, the company has confirmed. These points contribute to a researcher’s eligibility for the annual MSRC Most Valuable Security Researcher list.</p><p>In August 2020, it emerged that <a href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft paid out $13.7m (£10.5m)</a> across 15 bounty programmes during the last 12 months, over three times the amount paid to researchers in the same period during 2018/2019. The biggest single reward was $200,000, with 1,226 eligible vulnerability reports being filed during the period.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sovryn announces $1.25 million bug bounty program  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/358867/sovryn-announces-125-million-bug-bounty-program</link>
                                                                            <description>
                            <![CDATA[ Bonus payouts are available for smart-contract- and blockchain-related bugs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6pnP6CDToYwEUUFS181FMJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Mar 2021 16:17:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cryptocurrencies]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fake ladybug on a circuit board]]></media:description>                                                            <media:text><![CDATA[Fake ladybug on a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Fake ladybug on a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bitcoin trading and lending platform Sovryn has announced its biggest bug bounty program. The announcement comes after the company raised an equivalent of $10 million in bitcoin through its governance token presale.</p><p>The bounty, launched in partnership with Immunefi, will offer white-hat <a href="https://www.itpro.com/security/hacking/354310/inside-the-mind-of-a-hacker" data-original-url="https://www.itpro.com/security/hacking/354310/inside-the-mind-of-a-hacker">hackers</a> a whopping $1.25 million to unearth security <a href="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now" data-original-url="https://www.itpro.com/security/vulnerability/356709/why-vulnerability-management-is-crucial-right-now">vulnerabilities</a> in the Sovryn smart contract.</p><p>“Throughout the proposal drafting process for SIP-8, the Sovryn team and community have provided valuable feedback and sharing ideas on how to improve the program, said Immunefi co-founder Travin Keith.</p><p>Keith continued, “the program will incentivize white hats to look through the code as well as incentivizing black hats to disclose bugs, instead of exploiting them."</p><p>According to the bounty’s <a href="https://gitcoin.co/issue/TravinImmunefi/Sovryn-SIP0008/1/100024978">official page</a>, payouts will adhere to Immunefi’s vulnerability severity classification system. </p><p>For smart contract and blockchain vulnerabilities, the bounties range from $2,200 for low-risk issues to as much as $1 million for critical flaws. Sovryn will cap the $1 million bounties at 10% of the funds at risk. </p><p>Sovryn will also pay a bonus for smart-contract- and blockchain-related bugs reported within the first three weeks of the bounty program. The special reward starts at 25% and is split into seven-day rounds. The bonus reduces by five percentage points at the end of each round until it reaches 10% in the final bonus round.</p><p>Website and app vulnerabilities have lower payouts that range from $2,200 for medium-severity vulnerabilities to $22,140 for critical issues.There’s no bonus for finding these vulnerabilities in the first three weeks. </p><p>Rewards are payable in bitcoin, but the Sovryn team may decide to have “up to 50% of the reward payable in schedule of values (SOV) tokens according to a vesting schedule dependent on the amount paid out.”</p><p>Casting light on the most rewarding vulnerabilities, Sovryn said the company is especially interested in receiving news about missing access controls, consensus failures, logic errors, susceptibility to block timestamp manipulation, <a href="https://www.itpro.com/security/32215/remote-code-execution-flaw-found-in-cisco-webex" data-original-url="https://www.itpro.com/security/32215/remote-code-execution-flaw-found-in-cisco-webex">remote code execution</a>, clickjacking, and cryptography problems. </p><p>Sovryn also clarified that in case two or more reports suggest the same vulnerability, only the first complete bug report will receive the reward. “The final reward amount is capped at 10% of the funds at risk based on the vulnerability reported," the company said.</p><p>“The Sovryn developer team/community takes security seriously and this successful presale has allowed us to take that to the next level, encouraging thousands of hackers to try to penetrate our decentralized protocol. Forged in the white-hot fire of this testing, the armor of our security will emerge all the strong,” added Sovryn co-founder Edan Yago.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple fixes macOS Big Sur bug that caused irretrievable data loss ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/358625/apple-fixes-macos-big-sur-data-loss-bug</link>
                                                                            <description>
                            <![CDATA[ The macOS upgrade installer failed to check if you had enough free space available, causing major issues if you didn’t ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r2Dr2ok4RraK1VrmRoHbef</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nq2sD3vpwdQ2DrVddNyM2E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Feb 2021 10:14:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nq2sD3vpwdQ2DrVddNyM2E-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[macOS on an iMac desktop computer]]></media:description>                                                            <media:text><![CDATA[macOS on an iMac desktop computer]]></media:text>
                                <media:title type="plain"><![CDATA[macOS on an iMac desktop computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nq2sD3vpwdQ2DrVddNyM2E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has patched a non-exploitable programming bug in its flagship macOS Big Sur operating system (OS) that could lead to irretrievable data loss.</p><p>Usually, before the OS undergoes a major upgrade, it performs a check for how much free space is available. In versions 11.2 and 11.3 of Big Sur, however, this check doesn't work as intended, <a href="https://mrmacintosh.com/big-sur-upgrade-not-enough-hd-space-serious-issue-possible-data-loss">according to Mr Macintosh</a>, meaning the upgrade will start even if you have 1% of space left. </p><p>This means that the upgrade will start anyway and will saturate users’ hard disk space at 100%, with the installer stuck in a boot loop in an attempt to finish the install.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/357690/apple-will-require-developers-to-add-privacy-nutrition-labels-to-apps" data-original-url="/security/privacy/357690/apple-will-require-developers-to-add-privacy-nutrition-labels-to-apps">Apple will require developers to add privacy nutrition labels to apps</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/operating-systems/357775/mac-big-sur-bricking-macbooks" data-original-url="/software/operating-systems/357775/mac-big-sur-bricking-macbooks">macOS Big Sur is bricking some older MacBooks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/356179/wwdc-2020-macos-big-sur-and-apple-designed-chips-headline-a-busy-event" data-original-url="/hardware/356179/wwdc-2020-macos-big-sur-and-apple-designed-chips-headline-a-busy-event">WWDC 2020: Apple unveils macOS Big Sur, iOS 14 and more</a></p></div></div><p>The problem is exacerbated for Mac devices <a href="https://www.itpro.com/security/357338/apple-t2-unpatchable-flaw-jailbreak" target="_blank" data-original-url="https://www.itpro.com/security/357338/apple-t2-unpatchable-flaw-jailbreak">with the T2 security chip</a> and FileVault 2 encryption enabled. For those with a T2 Mac, they will be unable to get into macOS recovery because their password will not work. </p><p>Enabling the <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">hard disk encryption</a> software FileVault locks people out due to a failure to accept their passwords in the normal recovery prompts, the Mac researcher showed. </p><p>If FileVault is enabled, users will be prompted to enter their admin password before accessing recover, but it won’t be accepted. If users then try to reset their password with a personal recovery key or AppleID, the reset process will fail. Even Target Disk Mode, which turns the macOS device into an external hard drive for another Mac, will fail. </p><p>If upgrading from macOS Sierra or later, macOS Big Sur requires 35.5GB of available storage to upgrade. If upgrading from an even earlier release, macOS Big Sur requires up to 44.5GB of available storage. </p><p>The range of available hard drive space where the bug would kick users into a boot loop was between 13GB and 35.5GB of free space. This is according to a <a href="https://www.youtube.com/watch?v=Qcu9o4qz2Ls" target="_blank">deep-dive video compiled by Mr Machintosh</a> breaking down the issue and how it manifests. </p><p>Thankfully, Apple has released a fresh installer, macOS Big Sur 11.2.1, which now checks for free space properly before applying any major upgrade to the system.</p><p>The issue isn’t a new one, with users reporting problems installing Big Sur <a href="https://discussions.apple.com/thread/252038616?answerId=253922337022">as far back as November</a>, losing their data in the process. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft releases emergency fix for Patch Tuesday Wi-Fi glitch ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/358594/microsoft-releases-emergency-fix-for-patch-tuesday-wi-fi-glitch</link>
                                                                            <description>
                            <![CDATA[ Users report BSOD system crashes when trying to connect to Wi-Fi through WPA3 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">raBwswXbP3zVU99jJHSL2z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f5sWNzKUAiaXnaKkByq63c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Feb 2021 10:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f5sWNzKUAiaXnaKkByq63c-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Blue Screen of Death (BSOD) error screen as shown on a Samsung monitor in an office]]></media:description>                                                            <media:text><![CDATA[The Blue Screen of Death (BSOD) error screen as shown on a Samsung monitor in an office]]></media:text>
                                <media:title type="plain"><![CDATA[The Blue Screen of Death (BSOD) error screen as shown on a Samsung monitor in an office]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f5sWNzKUAiaXnaKkByq63c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has issued an out-of-band patch for a <a href="https://www.itpro.com/operating-systems/microsoft-windows/358097/how-to-fix-a-blue-screen-of-death-error-in-windows-10" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/358097/how-to-fix-a-blue-screen-of-death-error-in-windows-10">blue screen of death (BSOD)</a>-causing glitch introduced with the release of this week’s round of Patch Tuesday security fixes.</p><p>Some users have reported their devices crashing following the latest update, according to <a href="https://www.windowslatest.com/2021/02/12/windows-10-emergency-update-is-rolling-out-to-fix-bsod-crashes"><em>Windows Latest</em></a>. Dubbed KB4601315, this round of fixes rectified 56 security flaws in Windows 10, including a <a href="https://www.itpro.com/security/vulnerability/358577/microsft-patches-actively-exploited-windows-zero-day-flaw" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/358577/microsft-patches-actively-exploited-windows-zero-day-flaw">critical zero-day vulnerability affecting the win32k component</a>, being actively exploited by hackers in China.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/358586/weekly-threat-roundup-zero-days-in-windows-adobe-google-chrome" data-original-url="/security/vulnerability/358586/weekly-threat-roundup-zero-days-in-windows-adobe-google-chrome">Weekly threat roundup: Zero-days in Windows, Adobe, Google Chrome</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/two-factor-authentication-2fa/358323/cyber-criminals-bypassing-mfa-to-access-cloud-service" data-original-url="/security/two-factor-authentication-2fa/358323/cyber-criminals-bypassing-mfa-to-access-cloud-service">Cyber criminals bypassing MFA to access cloud service accounts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a></p></div></div><p>Microsoft acknowledged the rollout of KB4601315 caused the BSOD to appear for a handful of users, revealing that devices stopped working when users attempted to connect to a Wi-Fi network through the <a href="https://www.itpro.com/security/30848/why-wpa3-may-be-no-safer-from-attack-than-wpa2" target="_blank" data-original-url="https://www.itpro.com/security/30848/why-wpa3-may-be-no-safer-from-attack-than-wpa2">Wi-Fi Protected Access 3 (WPA3) protocol</a>.</p><p>Users will encounter “stop error 0x7E in nwifi.sys” when they attempt to use a WPA3 connection, the company confirmed. The emergency update, <a href="https://support.microsoft.com/en-us/topic/february-11-2021-kb5001028-os-build-18363-1379-out-of-band-42c34ace-7ae8-4b66-bdf9-94a5a5589659" target="_blank">dubbed KB5001028</a>, has now been released and should address the issue.</p><p>WPA3 is the most recent version of the security standard for wireless networks, <a href="https://www.itpro.com/network-internet/31391/wi-fi-alliance-rolls-out-wpa3-to-boost-wireless-security" target="_blank" data-original-url="https://www.itpro.com/network-internet/31391/wi-fi-alliance-rolls-out-wpa3-to-boost-wireless-security">introduced in January 2018</a>. This added a number of improvements to security over WPA2, including stronger encryption and <a href="https://www.itpro.com/security/32073/weak-default-passwords-to-be-made-illegal-in-california" target="_blank" data-original-url="https://www.itpro.com/security/32073/weak-default-passwords-to-be-made-illegal-in-california">mitigations against weak passwords</a>.</p><p>The Windows 10 bug caused by this week’s Patch Tuesday update should not affect too many devices considering WPA3 has yet to be adopted in the mainstream. Many devices with WPA3 support have been manufactured, but organisations and individuals across the world haven’t yet necessarily changed their WPA2 networking equipment.</p><p>Although the WPA3 standard isn’t as widely used as it one day will be, Microsoft still deemed this bug severe enough to release an out-of-band fix, something the company only does in emergency situations.</p><p>Previous out-of-band updates have normally been issued to fix critical flaws that render Windows devices vulnerable to exploitation by hackers.</p><p>Microsoft released emergency patches for high-risk <a href="https://www.itpro.com/security/vulnerability/356295/microsoft-patches-high-risk-flaws-that-can-be-exploited-with-a" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/356295/microsoft-patches-high-risk-flaws-that-can-be-exploited-with-a">Windows 10 and Windows Server 2019 remote code execution flaws</a> affecting Windows Codecs Library in July 2020, for example. The firm also issued out-of-band updates to fix two further remote code execution bugs affecting <a href="https://www.itpro.com/security/357463/microsoft-launches-two-emergency-windows-patches" target="_blank" data-original-url="https://www.itpro.com/security/357463/microsoft-launches-two-emergency-windows-patches">Windows Codecs Library again as well as Visual Studio Code</a> in October.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google fixes actively exploited Chrome zero-day ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/network-internet/web-browser/358535/google-fixes-exploited-chrome-zero-day</link>
                                                                            <description>
                            <![CDATA[ The flaw may be related to a recent hacking campaign against the cyber security community ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cRN4mTzKwkQXNn7nqqXxZa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qrFsNYa8SrgR3gS9nzwE5d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Feb 2021 10:34:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Web Browsers]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qrFsNYa8SrgR3gS9nzwE5d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome logo in browser displayed on desktop screen]]></media:description>                                                            <media:text><![CDATA[Chrome logo in browser displayed on desktop screen]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome logo in browser displayed on desktop screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qrFsNYa8SrgR3gS9nzwE5d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has released an updated version of its Chrome web browser following reports of a zero-day vulnerability being exploited in the wild.</p><p>Version 88.0.4324.150 for Windows, Mac and Linux contains only one patch which is aimed at a memory corruption bug in Chrome’s V8 JavaScript engine, known as CVE-2021-21148.</p><p>The vulnerability, marked as high risk, was reported on 24 January by <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researcher Mattias Buelens, who is also a lead <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> architect on THEOplayer. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities" data-original-url="/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities">Apple pays ethical hackers $288k for finding 55 vulnerabilities</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/web-browser/358385/google-chrome-makes-it-easier-to-fix-weak-passwords" data-original-url="/network-internet/web-browser/358385/google-chrome-makes-it-easier-to-fix-weak-passwords">Google Chrome makes it easier to fix weak passwords</a></p></div></div><p>Google Chrome technical program manager Srinivas Sista said that the tech giant is “aware of reports that an exploit for CVE-2021-21148 exists in the wild”. He didn’t provide any additional details about the zero-day vulnerability due to risk of further exploitation, noting that the majority of users hadn’t yet been updated with a fix.</p><p>However, <em><a href="https://www.zdnet.com/article/google-patches-an-actively-exploited-chrome-zero-day">ZDNet</a></em> notes that the date on which Google says the bug was reported, January 24, is just two days after Google's Threat Analysis Group <a href="https://www.itpro.com/security/hacking/358425/security-researchers-targeted-by-north-korean-hackers" target="_blank" data-original-url="https://www.itpro.com/security/hacking/358425/security-researchers-targeted-by-north-korean-hackers">reported</a> a hacking campaign carried out by North Korean hackers against the cyber security community. It's believed this campaign may have relied on zero-day exploits in Chrome and Internet Explorer.</p><p>Chrome version 88.0.4324.150 has begun to roll out to users across Windows, Mac and Linux systems. Users can check if their Chrome browser is up to date by following these steps: </p><ol><li>Open your Chrome browser and look the three vertical dots on the top right corner</li><li>Green means the update it less than two days old</li><li>Orange means the update is about four days old</li><li>Red means the update is a least a week old</li><li>If the dots are coloured, click them to open the menu</li><li>Click “Update Google Chrome”</li><li>Exit your Chrome browser and reopen it to complete the update.</li></ol><p>Google was forced to deal with another Chrome zero-day vulnerability in <a href="https://www.itpro.com/security/bugs/357534/latest-chrome-and-chrome-os-updates-fix-zero-day-flaw" data-original-url="https://www.itpro.com/security/bugs/357534/latest-chrome-and-chrome-os-updates-fix-zero-day-flaw">October of last year</a>, when its <a href="https://www.itpro.com/security/vulnerability/354481/googles-project-zero-rolls-out-automatic-90-day-disclosures" data-original-url="https://www.itpro.com/security/vulnerability/354481/googles-project-zero-rolls-out-automatic-90-day-disclosures">Project Zero</a> security team discovered that hackers were exploiting the bug to attack Chrome users’ systems. </p><p>The vulnerability, a memory corruption bug in the FreeType font-rendering library, prompted the tech giant to release the Chrome OS 86.0.4240.112 update, which addressed the detected zero-day security flaw on Google <a href="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech" data-original-url="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech">Chromebooks</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft fixes actively exploited Defender zero-day flaw ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/358304/microsoft-fixes-zero-day-defender-exploit-with-patch-tuesday</link>
                                                                            <description>
                            <![CDATA[ The firm's latest Patch Tuesday release includes fixes for a total of 83 vulnerabilities across Windows, Azure and more ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xoU2sPHD6agBCrX4buTYTq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FxpgapgufsGPJrodato7an-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Jan 2021 11:54:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FxpgapgufsGPJrodato7an-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Windows update ready to be installed on a laptop]]></media:description>                                                            <media:text><![CDATA[A Windows update ready to be installed on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[A Windows update ready to be installed on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FxpgapgufsGPJrodato7an-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has released a fix for the zero-day remote access exploit recently uncovered in its Defender <a href="https://www.itpro.com/antivirus/28144/best-antivirus" target="_blank" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> service.</p><p>The fix arrives in the company's monthly set of security patches, known as 'Patch Tuesday', which included patches for a total of 83 vulnerabilities across a wide range of products, including Windows, Azure and other Microsoft services. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/358041/microsoft-teams-wormable-rce-flaw" data-original-url="/security/358041/microsoft-teams-wormable-rce-flaw">Zero-click 'wormable' RCE flaw uncovered in Microsoft Teams</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358171/weekly-threat-roundup-solarwinds-hpe-and-postgresql" data-original-url="/security/358171/weekly-threat-roundup-solarwinds-hpe-and-postgresql">Weekly threat roundup: Solarwinds, HPE, and PostgreSQL</a></p></div></div><p>The <a href="https://www.itpro.com/mobile/remote-access/357972/apple-patches-iphone-vulnerability-found-by-project-zero-researcher" target="_blank" data-original-url="https://www.itpro.com/mobile/remote-access/357972/apple-patches-iphone-vulnerability-found-by-project-zero-researcher">zero-day</a> exploit is tracked as <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1647" target="_blank">CVE-2021-1647</a> and is described as a remote code execution (<a href="https://www.itpro.com/security/358041/microsoft-teams-wormable-rce-flaw" target="_blank" data-original-url="https://www.itpro.com/security/358041/microsoft-teams-wormable-rce-flaw">RCE</a>) bug that allows threat actors to embed code on vulnerable devices by tricking users into opening a loaded document on a system with <a href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender" target="_blank" data-original-url="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender">Microsoft Defender</a> installed. </p><p>Microsoft said that despite exploitation being detected in the wild, the technique was not functional in all situations, suggesting that it is still at a 'proof-of-concept' stage. However, the company warned that the code could evolve into more reliable attacks. </p><p>To protect against any future attacks, Microsoft has released patches for the Microsoft Malware Protection Engine, which will be installed automatically unless blocked by system administrators.</p><p>Alongside the Defender zero-day bug, the tech giant has also released a patch for a flaw in the Windows splwow64 service. This was tracked as CVE-2021-1648 and could be used to elevate the privileges of attack codes. This hasn't been exploited in the wild, according to Microsoft, but system admins have been advised to apply the patches to avoid any future problems. </p><p>Microsoft is not the only firm starting 2021 with patches, as Adobe has released its first major batch of security fixes. On Tuesday, the software firm released a number of security advisories for vulnerabilities in seven different products: Photoshop, Illustrator, Animate, Bridge, InCopy, Captivate and Campaign Classic.</p><p>The first of these fixes have already been applied to the Photoshop image creation software on Windows and macOS-based machines. It is tracked as CVE-2021-21006 and can be used to trigger arbitrary code execution.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS COVID-19 app failed to ask users to self-isolate due to 'software glitch' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/357612/nhs-test-and-trace-app-software-glitch-self-isolate-notifications</link>
                                                                            <description>
                            <![CDATA[ The bug is the latest in a long line of errors and glitches to plague the government's contact-tracing app ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9HCoweTmg46vdnFq2VuFAY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5hXo5hxPsxTKcqDJwjbkUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Nov 2020 10:25:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5hXo5hxPsxTKcqDJwjbkUL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NHS app on a smartphone]]></media:description>                                                            <media:text><![CDATA[NHS app on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[NHS app on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5hXo5hxPsxTKcqDJwjbkUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government’s COVID-19 contact-tracing app was patched last week to fix a bug that meant the system failed to send notifications to thousands of users who should have been warned to self-isolate.</p><p>The Test and Trace app, which is supposed to be a core part of the government’s national coronavirus response, hasn’t been working properly since its <a href="https://www.itpro.com/software/development/357081/england-and-wales-contact-tracing-app-to-launch-later-this-month" target="_blank" data-original-url="https://www.itpro.com/software/development/357081/england-and-wales-contact-tracing-app-to-launch-later-this-month">late September launch</a> because it was set to the wrong sensitivity.</p><p>Users whose “risk score” should have triggered an alert, due to possible exposure among their contacts, were not alerted to either get a test or self-isolate due to the error, according to <a href="https://www.thetimes.co.uk/article/software-bungle-meant-nhs-covid-app-failed-to-warn-users-to-self-isolate-6tzstqnr9"><em>the Times</em></a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/356027/coronavirus-contact-tracing-app-delayed-due-to-bluetooth-issues" data-original-url="/security/privacy/356027/coronavirus-contact-tracing-app-delayed-due-to-bluetooth-issues">UK's coronavirus contact-tracing app faces delay over complications with Bluetooth</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/357273/police-officers-advised-not-to-download-covid-19-contact" data-original-url="/data-insights/data-management/357273/police-officers-advised-not-to-download-covid-19-contact">Police officers told not to download NHS contact-tracing app</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/357096/data-breach-wales-covid-19-positive-tests" data-original-url="/security/data-breaches/357096/data-breach-wales-covid-19-positive-tests">Data breach exposes details of 18,000 people who tested positive for COVID-19</a></p></div></div><p>As a result, “shockingly low” numbers of users had been sent warnings since the app was released, according to a government source, with Android users among those more likely not to have been sent a notification when they were supposed to.</p><p>An update to the app, released last week, fixed both this error, as well as another bug in which users were notified about a “potential exposure” only for the <a href="https://www.itpro.com/security/357603/weekly-threat-roundup-nhs-covid-19-app-nvidia-and-oracle" target="_blank" data-original-url="https://www.itpro.com/security/357603/weekly-threat-roundup-nhs-covid-19-app-nvidia-and-oracle">message to disappear without a trace</a>, and without any further details. </p><p>The risk threshold is calculated for each user and for each possible COVID-19 exposure using various factors including distance, as well as the infectiousness of the person who has tested positive. The system then works out the overall risk to each applicable individual, and sends out a notification if it exceeds the threshold.</p><p>This threshold was due to be lowered when the app launched from 900 to 180, although this didn’t happen until the patch was launched last week. This is <a href="https://healthtech.blog.gov.uk/2020/10/29/how-the-nhs-covid-19-app-is-making-the-most-of-cutting-edge-global-technology" target="_blank">according to a blog</a> written by the head of product for the NHS COVID-19 app Randeep Sidhu and the director of product for Test and Trace, Gaby Appleton. Due to a new statistical algorithm in use by the app, the risk threshold is being lowered to 120.</p><p>Although 19 million people now use the app, officials have refused to reveal how many people have been told to self-isolate, <em>the Times</em> report added.</p><p>The NHS app has suffered a disastrous and long-drawn-out launch, having first been promised in April 2020 and <a href="https://www.itpro.com/security/privacy/356027/coronavirus-contact-tracing-app-delayed-due-to-bluetooth-issues" target="_blank" data-original-url="https://www.itpro.com/security/privacy/356027/coronavirus-contact-tracing-app-delayed-due-to-bluetooth-issues">delayed several times</a> due to various concerns, including potential security risks as well as compatibility issues. </p><p>The original idea was to <a href="https://www.itpro.com/security/privacy/355304/nhs-working-with-apple-google-coronavirus-tracking-app" target="_blank" data-original-url="https://www.itpro.com/security/privacy/355304/nhs-working-with-apple-google-coronavirus-tracking-app">pursue the decentralised Google and Apple API</a>, which the majority of national COVID-19 contact tracing apps are powered by. The government then <a href="https://www.itpro.com/business-strategy/public-sector/356139/the-governments-contact-tracing-app-was-always-going-to-be" target="_blank" data-original-url="https://www.itpro.com/business-strategy/public-sector/356139/the-governments-contact-tracing-app-was-always-going-to-be">ditched this in favour of developing its own centralised app</a>, although ran into issues when it was trialled on the Isle of Wight and was eventually abandoned in favour of a manual national contact tracing scheme. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SJad7r56DDot9wiEMPTvjK" name="SJad7r56DDot9wiEMPTvjK.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/SJad7r56DDot9wiEMPTvjK.jpg" mos="https://cdn.mos.cms.futurecdn.net/SJad7r56DDot9wiEMPTvjK.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 state of IT asset management report</strong></p><p class="fancy-box__body-text">The role of IT asset management for maximising technology investments</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/asset-management/357457/2021-state-of-it-asset-management-report" data-original-url="/business-operations/asset-management/357457/2021-state-of-it-asset-management-report">FREE DOWNLOAD</a></p></div></div><p>The government then <a href="https://www.itpro.com/security/privacy/356128/uk-government-switches-to-apple-google-model-for-coronavirus-tracing-app" target="_blank" data-original-url="https://www.itpro.com/security/privacy/356128/uk-government-switches-to-apple-google-model-for-coronavirus-tracing-app">pivoted back to using the Google and Apple API</a> to power its contact-tracing smartphone app, which eventually launched on 24 September. Its release was far from the smoothest, however, with fears initially that it would not be compatible with a large swathe of iOS devices.</p><p>A fix was also needed two days after launch when it was revealed that tens of thousands of NHS tests were not compatible with the app’s current build version,</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google fixes zero-day flaw in Chrome and Chrome OS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/357534/latest-chrome-and-chrome-os-updates-fix-zero-day-flaw</link>
                                                                            <description>
                            <![CDATA[ Flaw created by memory corruption bug in FreeType font-rendering library ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uGJSnrPkBT2soNxnx2Qic9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/i625piRDMo8T7VfRfiL8vN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Oct 2020 14:44:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Gargaro ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/i625piRDMo8T7VfRfiL8vN-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome logo on black background]]></media:description>                                                            <media:text><![CDATA[Chrome logo on black background]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome logo on black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/i625piRDMo8T7VfRfiL8vN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has discovered htat the latest versions of Chrome and <a href="https://www.itpro.com/618193/google-chrome-os-review-first-look" data-original-url="https://www.itpro.com/618193/google-chrome-os-review-first-look">Chrome OS</a> contained a zero-day security flaw.</p><p><a href="https://www.itpro.com/security/vulnerability/354481/googles-project-zero-rolls-out-automatic-90-day-disclosures" data-original-url="https://www.itpro.com/security/vulnerability/354481/googles-project-zero-rolls-out-automatic-90-day-disclosures">Project Zero</a>, Google’s security team responsible for finding these vulnerabilities, discovered hackers were using the bug to attack Chrome users’ systems. Google patched Chrome’s flaw a few days ago, and has now rolled out a fix for Chrome OS. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/613846/chrome-os--lost-in-the-cloud" data-original-url="/613846/chrome-os--lost-in-the-cloud">Chrome OS – Lost in the cloud?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/628336/new-zero-day-flaw-hits-microsofts-internet-explorer" data-original-url="/628336/new-zero-day-flaw-hits-microsofts-internet-explorer">New zero day flaw hits Microsoft’s Internet Explorer</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/637753/another-adobe-zero-day-strikes" data-original-url="/637753/another-adobe-zero-day-strikes">Another Adobe zero day strikes</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/zero-day-exploit/31962/zero-day-initiative-disclosed-unpatched-microsoft-jet-database-flaw" data-original-url="/zero-day-exploit/31962/zero-day-initiative-disclosed-unpatched-microsoft-jet-database-flaw">Zero Day Initiative disclosed unpatched Microsoft Jet database flaw</a></p></div></div><p>Today’s Chrome OS 86.0.4240.112 update addresses the detected zero-day security flaw on Google <a href="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech" data-original-url="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech">Chromebooks</a>. The vulnerability was a memory corruption bug in the FreeType font-rendering library. </p><p>Other functional changes in the Chrome OS update include fixes for the 'Clear all' button and 'Pairing lost' notification, and flags for modifying the protection level against <a href="https://www.itpro.com/security/33031/spectre-vulnerabilities-cannot-be-mitigated-by-software-alone" data-original-url="https://www.itpro.com/security/33031/spectre-vulnerabilities-cannot-be-mitigated-by-software-alone">Spectre</a>.</p><p>If you’re uncertain whether your Chrome OS is up to date or not, here’s how to find out if there’s a Chrome OS update:</p><ol><li>Click the “Settings” gear icon on the lower right corner of your screen</li><li>Click “About Chrome OS” on the bottom of the left panel</li><li>Find your Chrome OS version under “Google Chrome OS”</li><li>Click “Check for updates”</li><li>Your Chromebook will automatically download an update if one’s available</li><li>Restart your Chromebook to complete the update</li></ol><p>Two days ago, Google also launched Chrome version 86.0.4240.111, which included a patch for Chrome’s zero-day security vulnerability. </p><p>Users should have the Chrome patch by now, but you can check if your Chrome browser is up to date with these steps: </p><ol><li>Open your Chrome browser and look the three vertical dots on the top right corner</li><li>Green means the update it less than two days old</li><li>Orange means the update is about four days old</li><li>Red means the update is a least a week old</li><li>If the dots are colored, click them to open the menu</li><li>Click “Update Google Chrome”</li><li>Exit your Chrome browser and reopen it to complete the update</li></ol><p>A zero-day security vulnerability is a previously unknown software flaw that would be of interest to the software developer or vendor. Cybercriminals and hackers can exploit this flaw to attack users, computer programs, data, other computers or a network.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 update sparks driver compatibility fears ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/357431/windows-10-update-sparks-driver-compatibility-fears</link>
                                                                            <description>
                            <![CDATA[ Over-zealous verification checks designed to tighten security may block some older drivers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x9hPvb4bWfxZZ9tBch9dnb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8xrGyxrECZFcFQK45xXhd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Oct 2020 09:01:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8xrGyxrECZFcFQK45xXhd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two options shown on the Windows 10 start menu, reading &amp;quot;Update and shut down&amp;quot;, or &amp;quot;Update and restart&amp;quot;]]></media:description>                                                            <media:text><![CDATA[Two options shown on the Windows 10 start menu, reading &amp;quot;Update and shut down&amp;quot;, or &amp;quot;Update and restart&amp;quot;]]></media:text>
                                <media:title type="plain"><![CDATA[Two options shown on the Windows 10 start menu, reading &amp;quot;Update and shut down&amp;quot;, or &amp;quot;Update and restart&amp;quot;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8xrGyxrECZFcFQK45xXhd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A cumulative Windows 10 update released as part of <a href="https://www.itpro.com/security/357423/microsoft-fixes-critical-wormable-remote-code-flaw" target="_blank" data-original-url="https://www.itpro.com/security/357423/microsoft-fixes-critical-wormable-remote-code-flaw">this week’s Patch Tuesday</a> round of fixes may be causing incompatibility issues with certain versions of legitimate drivers.</p><p>The change Microsoft has implemented, as part of the update tagged KB4579311, aims to tighten up the verification standard in Windows 10 for driver software. This has been rolled out to minimise the chances of <a href="https://www.itpro.com/security/357420/the-truth-about-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/357420/the-truth-about-ransomware">malware</a> exploiting vulnerable or out-of-date drivers, and fully compromising systems.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/356837/20-new-features-in-windows-10" data-original-url="/operating-systems/microsoft-windows/356837/20-new-features-in-windows-10">20 new features in Windows 10</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357383/weekly-threat-roundup-apple-amd-and-google" data-original-url="/security/357383/weekly-threat-roundup-apple-amd-and-google">Weekly threat roundup: Apple, AMD, and Google</a></p></div></div><p>Windows 10 will prevent users from applying driver updates if the operating system cannot verify the software publisher, displaying two error messages when this happens. Users will first be informed that Windows 10 cannot verify the driver software, and secondly that no signature was present in the subject. These errors suggest that Windows did not recognise the formatted catalogue file in the driver validation, <a href="https://support.microsoft.com/en-au/help/4579311/windows-10-update-kb4579311" target="_blank">Microsoft has disclosed</a>, and that installation therefore won’t be successful.</p><p>While this measure has been introduced to prevent potentially vulnerable drivers from being installed on machines, and therefore heightening the risk of exploitation by malware, the tighter standards could hit legitimate software. Older versions of existing drivers, for example, may not pass the new checks.</p><p>Should users encounter these errors when attempting to <a href="https://www.itpro.com/microsoft-windows/30420/how-to-update-windows-drivers" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/30420/how-to-update-windows-drivers">update their drivers</a> to legitimate software that cannot be verified, Microsoft has recommended that they contact the driver manufacturer. The only way around the glitch is for the device manufacturer to re-upload the driver, or provide a more up-to-date version of the software, in which the catalogue file is formatted correctly.</p><p>Microsoft released up to 87 security fixes as part of its <a href="https://www.itpro.com/security/357044/microsoft-patches-129-flaws-as-big-updates-becomes-new-normal" target="_blank" data-original-url="https://www.itpro.com/security/357044/microsoft-patches-129-flaws-as-big-updates-becomes-new-normal">routine Patch Tuesday</a> updates yesterday, including fixes for 11 critical vulnerabilities. Among these was a ‘wormable’ remote code execution flaw affecting the TCP/IP component of Windows 10 and Windows Server 2019, rated 9.8 on the CVSS scale.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple pays ethical hackers $288k for finding 55 vulnerabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ethical-hacking/357380/apple-pays-ethical-hackers-288k-for-finding-55-vulnerabilities</link>
                                                                            <description>
                            <![CDATA[ If exploited the bugs would have provided access to Apple's infrastructure and sensitive user data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wncpZeTzjvY2uJG4rm6uEN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gg9aXpt82myN8kj48ADaBV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Oct 2020 10:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gg9aXpt82myN8kj48ADaBV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple logo stuck onto a glass building]]></media:description>                                                            <media:text><![CDATA[The Apple logo stuck onto a glass building]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple logo stuck onto a glass building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gg9aXpt82myN8kj48ADaBV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has paid a group of <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a> $288,500 (£222,813) for finding and disclosing critical vulnerabilities in its network, some of which could have provided access to company infrastructure and iCloud data.</p><p>Since 6 July of this year, Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes have worked together as a part of Apple’s bug bounty programme. The team managed to discover a total of 55 vulnerabilities, 11 of which were of critical severity, 29 of high severity, 13 of medium severity, and two of low severity.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business" data-original-url="/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year" data-original-url="/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year">Microsoft tripled bug bounty payouts to $13.7m last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/34663/cloud-storage-how-secure-are-dropbox-onedrive-google-drive-and-icloud" data-original-url="/cloud-security/34663/cloud-storage-how-secure-are-dropbox-onedrive-google-drive-and-icloud">Cloud storage: How secure are Dropbox, OneDrive, Google Drive, and iCloud?</a></p></div></div><p>The 11 most critical bugs made it possible for the group to access Apple’s <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and use it to potentially steal confidential information such as private emails and <a href="https://www.itpro.com/tag/icloud" data-original-url="https://www.itpro.com/search/icloud">iCloud</a> data.</p><p>Sam Curry said that the team “found a variety of vulnerabilities in core portions of [Apple’s] infrastructure that would've allowed an attacker to fully compromise both customer and employee applications, launch a worm capable of automatically taking over a victim's iCloud account" and "fully compromise an industrial control warehouse <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> used by Apple", as detailed in a blog covering three months of research.</p><p>He added that exploits may have also allowed hackers to "take over the sessions of Apple employees with the capability of accessing management tools and sensitive resources".</p><p>The 11 vulnerabilities found to be critical were as follows:</p><ul><li>Remote Code Execution via Authorization and Authentication Bypass</li><li>Authentication Bypass via Misconfigured Permissions allows Global Administrator Access</li><li>Command Injection via Unsanitized Filename Argument</li><li>Remote Code Execution via Leaked Secret and Exposed Administrator Tool</li><li>Memory Leak leads to Employee and User Account Compromise allowing access to various internal applications</li><li>Vertica SQL Injection via Unsanitized Input Parameter</li><li>Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account</li><li>Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account</li><li>Full Response SSRF allows Attacker to Read Internal Source Code and Access Protected Resources</li><li>Blind XSS allows Attacker to Access Internal Support Portal for Customer and Employee Issue Tracking</li><li>Server-Side PhantomJS Execution allows attacker to Access Internal Resources and Retrieve AWS IAM Keys</li></ul><p>According to Curry, the “vast majority” of the 55 vulnerabilities have already been fixed.</p><p>“They were typically remediated within 1-2 business days (with some being fixed in as little as 4-6 hours),” he added.</p><p>Apple has so far paid the team a total of $288,500 for discovering the vulnerabilities, yet they could be awarded another quarter of a million dollars when the tech giant processes the entirety of their report.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft open-sources fuzzing tool used for bug-ridden Windows 10 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/development/software-development/357121/microsoft-open-sources-fuzzing-tool-used-for-bug-ridden</link>
                                                                            <description>
                            <![CDATA[ Developers can access the vulnerability detection tool through Github as Microsoft shifts away from its legacy scheme ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2f4PWLqBJtTFUXayeLS5oL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/n7476M5kq5SyG6ewCWvoog-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2020 11:01:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/n7476M5kq5SyG6ewCWvoog-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[magnifying glass showing bug on binary code]]></media:description>                                                            <media:text><![CDATA[magnifying glass showing bug on binary code]]></media:text>
                                <media:title type="plain"><![CDATA[magnifying glass showing bug on binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/n7476M5kq5SyG6ewCWvoog-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has publicly released the vulnerability testing tool it uses to detect bugs in its flagship products including the Windows 10 operating system, which has been blighted with glitches in recent months.</p><p>After previously revealing it would replace its existing software testing programme, known as Microsoft Security and Risk Detection, Microsoft has made its automated and open source tool available through <a href="https://www.itpro.com/open-source/31833/what-is-github" target="_blank" data-original-url="https://www.itpro.com/open-source/31833/what-is-github">Github</a> for developers around the world. </p><p>This transition to fuzzing, dubbed Project OneFuzz, sits in line with the wider industry’s movement to this method of vulnerability detection. Google, for example, has deployed fuzzing for some time, and even <a href="https://opensource.googleblog.com/2020/03/fuzzbench-fuzzer-benchmarking-as-service.html">launched a Fuzzing benchmarking tool in March this year</a> for developers to compare the viability of different services.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357044/microsoft-patches-129-flaws-as-big-updates-becomes-new-normal" data-original-url="/security/357044/microsoft-patches-129-flaws-as-big-updates-becomes-new-normal">Microsoft patches 129 flaws as big updates become new normal</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw" data-original-url="/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw">Microsoft to patch ‘extraordinarily serious’ cryptographic flaw</a></p></div></div><p>The technique is known to be a highly effective method for raising the level of security and reliability of native code, and involves developers feeding random excerpts of programming into a bug detection engine.</p><p>Project OneFuzz is an extensive fuzz testing framework that can be deployed through the Azure public cloud, and is the same testing framework used to detect bugs in various Microsoft products including Windows, Edge and other projects.</p><p>“Microsoft’s goal of enabling developers to easily and continuously fuzz test their code prior to release is core to our mission of empowerment,” said Microsoft Security’s principal security software engineer lead Justin Campbell and senior director for special projects management Mike Walker.</p><p>“The global release of Project OneFuzz is intended to help harden the platforms and tools that power our daily work and personal lives to make an attacker’s job more difficult.</p><p>Recent advancements have transformed the security engineering tasks involved in fuzz testing native code, with several useful functionalities including crash detection, coverage tracking and input harnessing now baked into fuzzing.</p><p>Project OneFuzz has already allowed developers to continuously scan Windows operating system builds for errors and harden updates prior to launch, Microsoft claims. Windows 10, however, has suffered from recent waves of glitches and bugs, particularly as a result of both major and minor updates. </p><p>Windows 10’s May 2020 Update, for example, has produced a litany of issues for users of all varieties over the last few months, ranging from <a href="https://www.itpro.com/operating-systems/microsoft-windows/356504/windows-10-may-2020-bug-causing-internet-connection" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356504/windows-10-may-2020-bug-causing-internet-connection">strange networking and connectivity issues</a> to <a href="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues">problems affecting Lenovo devices specifically</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="G6SJzwtKh9cWg8GQCKX6iX" name="G6SJzwtKh9cWg8GQCKX6iX.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/G6SJzwtKh9cWg8GQCKX6iX.jpg" mos="https://cdn.mos.cms.futurecdn.net/G6SJzwtKh9cWg8GQCKX6iX.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why containerisation needs context</strong></p><p class="fancy-box__body-text">The problems with infrastructure monitoring in the age of Kubernetes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/containers/357038/why-containerisation-needs-context" data-original-url="/development/containers/357038/why-containerisation-needs-context">FREE DOWNLOAD</a></p></div></div><p>The latest Patch Tuesday, too, saw Microsoft release 129 fixes across its various products including 23 patches for critical flaws, <a href="https://www.itpro.com/security/357044/microsoft-patches-129-flaws-as-big-updates-becomes-new-normal" target="_blank" data-original-url="https://www.itpro.com/security/357044/microsoft-patches-129-flaws-as-big-updates-becomes-new-normal">signalling that big updates have become the new normal</a> for the Windows developer.</p><p>Microsoft would hope that the continued deployment of Project OneFuzz would eventually begin to iron out errors and bugs prior to patches and updates being released. </p><p>Project OneFuzz gives developers the capability to launch fuzz jobs running from a few virtual machines to thousands of cores. Features include composable fuzzing workloads, built-in ensemble fuzzing, on-demand live-debugging of crashes, and crash reporting notification callbacks, among many others.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 users complain of performance loss and hardware errors after latest update ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/356862/windows-10-updates-causing-performance-issues-and-bsod-errors</link>
                                                                            <description>
                            <![CDATA[ Dozens of complaints are flooding online forums, many of which are from Lenovo device owners ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">55qEbczfkyq8JAk2UarF8b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Wh46bS2Gw8vUC6iQh2wEd6-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2020 09:37:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Wh46bS2Gw8vUC6iQh2wEd6-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 10 blue screen of death]]></media:description>                                                            <media:text><![CDATA[Windows 10 blue screen of death]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 blue screen of death]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Wh46bS2Gw8vUC6iQh2wEd6-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The latest round of Windows 10 updates are causing major issues for enterprise users, ranging from performance and networking problems to frequent blue screen of death (BSOD) error messages.</p><p>The Windows 10 <a href="https://support.microsoft.com/en-gb/help/4549951/windows-10-update-kb4549951" target="_blank">KB4549951</a> and <a href="https://support.microsoft.com/en-us/help/4566782/windows-10-update-kb4566782" target="_blank">KB4566782</a> updates, lanched on 11 August, have resulted in a range of performance issues and, in some cases, hardware errors, according to a host of user complaints on the official Windows support forum.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020" data-original-url="/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020">Microsoft warns users not to install Windows 10's May update</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues" data-original-url="/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues">Lenovo devices hit by Windows 10 May 2020 Update issues</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/354584/windows-10-pro-and-the-tools-for-agile-working" data-original-url="/hardware/354584/windows-10-pro-and-the-tools-for-agile-working">Windows 10 Pro and the tools for agile working</a></p></div></div><p>The updates were designed to provide a fix for the way Windows 10 stores and manages files, as well as security improvements for how the operating system uses external devices, such as a mouse or keyboard.</p><p>However, many users have reported frequent BSOD errors in a variety of contexts since updating, on top of a handful of users experiencing the rarer green screen of death (GSOD) message that only Windows Insiders with preview editions of Windows 10 can see.</p><p>Complaints also include slow Wi-Fi and sluggish download speeds, an inability to connect Bluetooth devices, external devices connected via USB not being recognised, as well as data transfer speeds crashing.</p><p>BSOD errors appear in ‘Unexpected Store Exception’ contexts, most often caused by hardware component failures, with some users even reporting repeated or looped blue-screen errors.</p><p>Although the errors are affecting users with devices from several manufacturers, including Dell and Acer, one seemingly common thread running through the errors is the use of the Hyper-V virtualisation engine. It’s also used by <a href="https://www.itpro.com/microsoft-windows/33249/microsoft-to-roll-out-windows-10-sandbox-extension-for-chrome-and-firefox" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/33249/microsoft-to-roll-out-windows-10-sandbox-extension-for-chrome-and-firefox">Windows Sandbox</a>, a Microsoft-developed feature that allows for potentially harmful software to be run in an isolated environment without affecting the rest of your system.</p><p>It also appears that a disproportionate number of Lenovo device users are experiencing this Hyper-V error, although this has not been confirmed by either Lenovo or Microsoft. A handful of the Windows 10 May 2020 Update bugs reported earlier this year <a href="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues">had affected Lenovo hardware exclusively</a>.</p><p>“I installed KB4566782 a few days ago. My system is Windows 10 2004, 64 bit, installed on Thinkpad T470,” <a href="https://answers.microsoft.com/en-us/windows/forum/all/cumulative-updates-august-11th-2020/6a8f94e3-aae0-446e-862c-db55c43721a4?LastReply=true#LastReply&page=9" target="_blank">one user on Microsoft Answers commented</a>.</p><p>“As a consequence, I suffered from slow Wi-Fi surfing and very slow (practically zero) downloading speed. After I tried every solution (update drivers, etc) and checked that other devices in my home work fine, today I uninstalled KB4566782. The solution worked and now everything is fine again.”</p><p>“19041.450 and 19041.423 (last month's preview) both break my Thinkpad X390 pretty badly when Hyper-V is installed,” <a href="https://www.reddit.com/r/Windows10/comments/i7vojm/cumulative_updates_august_11th_2020/g14m3b5/?utm_source=reddit&utm_medium=web2x&context=3" target="_blank">another user said on Reddit</a>.</p><p>“The Windows Hello camera stops working, and the machine BSODs when going to sleep or when trying to run Lenovo Vantage. The Intel management engine interface device stops working as well. If I uninstall Hyper-V it's fine. If I roll back to prior to 19041.423 it's also fine with Hyper-V still installed.”</p><p>These updates initially caused installation issues when they were launched earlier in the month, according to <a href="https://www.windowslatest.com/2020/08/14/windows-10-kb4565351-kb4566782-installation-issues"><em>Windows Latest</em></a>, although these fresh complaints appear to suggest the problems are far worse than initially thought.</p><p><em>IT Pro</em> asked Microsoft whether it was aware of the latest reports.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft tripled bug bounty payouts to $13.7m last year ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/356657/microsoft-tripled-bug-bounty-payouts-to-137m-last-year</link>
                                                                            <description>
                            <![CDATA[ The figure is more than double Google’s payout for 2019 and was divided among 327 security researchers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r1TXjjw2sRYoH1cDAVpQTD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/skux38sXJtXTUfNvahVEg7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2020 09:37:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/skux38sXJtXTUfNvahVEg7-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A magnifying glass focussing on the Microsoft logo on a web browser]]></media:description>                                                            <media:text><![CDATA[A magnifying glass focussing on the Microsoft logo on a web browser]]></media:text>
                                <media:title type="plain"><![CDATA[A magnifying glass focussing on the Microsoft logo on a web browser]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/skux38sXJtXTUfNvahVEg7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft paid out $13.7 million (roughly £10.5 million) across 15 bounty programmes during the last 12 months, more than three times the amount paid out to researchers in the same period during 2018/19.</p><p>The company rewarded 327 researchers for identifying bugs and flaws in Microsoft software during the last year, with 1,226 eligible vulnerability reports being filed during the period. The biggest single reward was $200,000.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" data-original-url="/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">Microsoft joins forces with HackerOne to boost bug bounties</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" data-original-url="/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">Teenage hacker makes $1m from bug bounty rewards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical" data-original-url="/security/ethical-hacking/355860/developer-scores-100000-bounty-from-apple-for-exposing-a-critical">Developer scores $100,000 bounty from Apple for exposing a critical vulnerability</a></p></div></div><p>The overall payout is greater than the $4.4 million (approximately £3.4 million) Microsoft distributed during the same 12-month period across 2018 and 2019, and <a href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" target="_blank" data-original-url="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">significantly higher than the $2 million (around £1.5 million) rewarded during 2018</a>. </p><p>This is due to a number of significant changes to the bug bounty programme made over the last two years, <a href="https://www.itpro.com/business-strategy/digital-transformation/355152/it-pro-panel-coping-with-covid-19" target="_blank" data-original-url="https://www.itpro.com/business-strategy/digital-transformation/355152/it-pro-panel-coping-with-covid-19">as well as the COVID-19 pandemic</a>, which has led to a higher rate of engagement among the security community.</p><p>Programmes for Microsoft Dynamics 365, Azure Security Lab, <a href="https://www.itpro.com/bugs/34243/microsoft-launches-bug-bounty-programme-for-chromium-based-edge" target="_blank" data-original-url="https://www.itpro.com/bugs/34243/microsoft-launches-bug-bounty-programme-for-chromium-based-edge">Edge on Chromium</a>, and Election Guard were all launched between July and October 2019, while the Xbox bounty and <a href="https://www.itpro.com/cloud/microsoft-azure/355567/microsoft-offers-hackers-100k-to-break-azure-sphere" target="_blank" data-original-url="https://www.itpro.com/cloud/microsoft-azure/355567/microsoft-offers-hackers-100k-to-break-azure-sphere">Azure Sphere Security Research Challenge</a> programmes were launched this year.</p><p>This is in addition to the Identity and Windows Insider Preview bounty programmes being updated in October 2019 and July 2020, respectively.</p><p>“We’re constantly evaluating the threat landscape to evolve our programs and listening to feedback from researchers to help make it easier to share their research,” said Microsoft’s senior program manager leading its Bug Bounty Program, Jarek Stanley.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Gs9jjBRysn7g62McSWyWZf" name="Gs9jjBRysn7g62McSWyWZf.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Gs9jjBRysn7g62McSWyWZf.png" mos="https://cdn.mos.cms.futurecdn.net/Gs9jjBRysn7g62McSWyWZf.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing VMDR: Vulnerability Management, Detection and Response</strong></p><p class="fancy-box__body-text">The all-in-one vulnerability management service</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/disaster-recovery-dr/355412/the-all-in-one-vulnerability-management-service" data-original-url="/business-strategy/disaster-recovery-dr/355412/the-all-in-one-vulnerability-management-service">FREE DOWNLOAD</a></p></div></div><p>“This year, we launched six new bounty programs and two new research grants, attracting over 1,000 eligible reports from over 300 researchers across 6 continents. In addition to the new bounty programs, COVID-19 social distancing appears to have had an impact on security researcher activity; across all 15 of our bounty programs we saw strong researcher engagement and higher report volume during the first several months of the pandemic.”</p><p>The final payout is more than double the $6.5 million Google paid through its bug bounty programme during the 2019 fiscal year, which was distributed among 461 researchers, with the biggest single reward standing at $201,000.</p><p>Microsoft didn’t disclose the number of vulnerabilities reported across the previous 12-month period, although the 1,226 flaws reported in the last year may well represent a major increase. This is not only due to the number of new and expanded programmes the company has introduced, but the frequency of flaws identified.</p><p>The Windows 10 operating system, for example, has been the source of many complaints over the previous 12 months, particularly with regards to major feature updates <a href="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft">such as the recent May 2020 upgrade</a>.</p><p>Microsoft <a href="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020">warned users against installing the Windows 10 update</a> after its initial two-week delay due to a number of serious issues it had identified, ranging from faulty Bluetooth connectivity to broken mouse input.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 bug is causing internet connection problems ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/356504/windows-10-may-2020-bug-causing-internet-connection</link>
                                                                            <description>
                            <![CDATA[ False network status reporting is causing some apps like Cortana and the Feedback Hub to fail to establish connections ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aD9uHwJWzjHJxUW2sgdwZ8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6RXzFusysdbZQrSWUqbJxh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2020 10:51:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6RXzFusysdbZQrSWUqbJxh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wifi sign with &amp;#039;X&amp;#039; symbol top right ]]></media:description>                                                            <media:text><![CDATA[Wifi sign with &amp;#039;X&amp;#039; symbol top right ]]></media:text>
                                <media:title type="plain"><![CDATA[Wifi sign with &amp;#039;X&amp;#039; symbol top right ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6RXzFusysdbZQrSWUqbJxh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft is investigating reports that Windows 10 is falsely suggesting users who have upgraded to the latest feature update aren’t connected to the internet, despite them experiencing a stable connection.</p><p>Bizarrely, this issue, which is being <a href="https://answers.microsoft.com/en-us/windows/forum/all/windows-10-version-2004-internet-access/faf0bab2-765d-41dc-b251-3e3301b9a3f0?page=1">widely reported online</a>, is also causing some desktop apps, such as Cortana and Feedback Hub, to break because these applications believe the device is not connected to the web, according to <a href="https://www.windowslatest.com/2020/07/18/windows-10-no-internet-connection-problem"><em>Windows Latest</em></a>.</p><p>“I am running on Windows 10 Enterprise, Version 2004, OS Build 19041.264,” <a href="https://answers.microsoft.com/en-us/windows/forum/all/windows-10-says-i-have-no-internet-connection-but/50153e5b-a008-443d-af0e-5ee3822c37a1?page=1">one user commented</a>. “I recently changed to the Windows Insider Program and updated Windows. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/356348/windows-10-needs-to-go-back-to-basics" data-original-url="/operating-systems/microsoft-windows/356348/windows-10-needs-to-go-back-to-basics">Windows 10 needs to go back to basics</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a> How to switch from Windows 10 to Linux</p></div></div><p>"In the taskbar, the Wi-Fi icon shows No Internet Access, but I have a stable internet connection wirelessly (Ex: I can browse the internet, ping IP Addresses, etc.). Another problem is when I try to open Cortana it also says that I have no internet connection (By the way, I can also open Microsoft's website).”</p><p>The bug manifests as the Wi-Fi icon to the bottom-right of the icon tray incorrectly displaying a ‘No Internet Access’ message. While users are still able to browse the internet, as normal, a host of apps seemingly rely on this status message in order to establish connections, with software such as Spotify and even the Microsoft Store failing to reach their servers. </p><p>Microsoft is aware of the Network Connectivity Status Indicator (NCSI) issue, <a href="https://social.technet.microsoft.com/Forums/en-US/4c8654be-d3da-4611-a649-110ca5a7c70a/ncsi-taskbar-icon-may-report-quotno-internetquot-on-windows-10-2004-devices-that-do-have?forum=win10itpronetworking" target="_blank">according to a contract worker</a> posting on a Microsoft forum, but the bug hasn’t yet been resolved. </p><p>Most users experiencing the issue have complained only after upgrading to version 2004, also known as the May 2020 Update. </p><p>This is simply the latest in a string of minor, and major, issues that have arisen after Microsoft first launched its major May 2020 Update. This update, in the first instance, was initially delayed <a href="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft">after the last-minute discovery of a zero-day flaw</a>.</p><p>Microsoft subsequently warned users against installing the May 2020 update <a href="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020">until a set of other issues were resolved</a>.</p><p>Several issues have since come to light including <a href="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues">incompatibility problems with certain Lenovo devices</a>, as well as a <a href="https://www.itpro.com/operating-systems/microsoft-windows/356063/users-report-chrome-bugs-after-upgrading-to-window-10" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356063/users-report-chrome-bugs-after-upgrading-to-window-10">Google Chrome flaw</a> whereby the web browser logs users out of their accounts and wipes stored information such as cookies and passwords.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 May 2020 Update is causing major Chrome issues ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/356063/users-report-chrome-bugs-after-upgrading-to-window-10</link>
                                                                            <description>
                            <![CDATA[ Microsoft's latest upgrade continues to cause problems, with users also complaining of incompatibility with USB printers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8c2Nn2zSTk3xcGw3AYfeEM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t4tREYvC8sETcHwFN5xyZK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Jun 2020 09:27:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t4tREYvC8sETcHwFN5xyZK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A finger about to push the windows button on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A finger about to push the windows button on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A finger about to push the windows button on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t4tREYvC8sETcHwFN5xyZK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Windows 10 users have reported issues with Google Chrome whereby the web browser logs them out of their accounts and removes stored information such as cookies and passwords.</p><p>The <a href="https://www.itpro.com/operating-systems/microsoft-windows/355631/windows-10-may-update-available-via-msdn" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355631/windows-10-may-update-available-via-msdn">Windows 10 May 2020 Update</a> seemingly undermines Google Chrome’s authentication and sign-in features and renders it unable to retain data as it should, according to issues widely noted on internet forums, as reported by <a href="https://www.windowslatest.com/2020/06/15/windows-10-may-2020-update-google-chrome-issue"><em>Windows Latest</em></a>. </p><p>One user, for example, has reported <a href="https://support.google.com/chrome/thread/49967636?hl=en">Chrome not saving cookies</a> and preventing synchronisation after rebooting their system. Others, meanwhile, have <a href="https://www.reddit.com/r/Windows10/comments/h8xawt/windows_10_issue_after_2004_update_forgets">complained about similar sign-in issues</a> with various applications such as Edge, OneDrive, and the Chromium-based Battle.Net app.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them" data-original-url="/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them">17 common Windows 10 problems and how to fix them</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft" data-original-url="/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft">Windows 10 May 2020 Update delayed after zero-day discovery</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/34691/windows-10s-buggy-updates-blamed-on-toxic-work-culture" data-original-url="/software/34691/windows-10s-buggy-updates-blamed-on-toxic-work-culture">Windows 10's buggy updates blamed on toxic work culture</a></p></div></div><p>“I'm dealing with a problem where each time I close chrome, it pauses sync and doesn't seem to use stored cookies (meaning it logs me out of all websites, regardless of if the password is stored in sync or not),” <a href="https://support.google.com/chrome/thread/49967636?hl=en">commented one user on a Google forum</a>. “This issue only began after I moved to a new computer (from windows 7 to windows 10) and used restore from an external hard drive to move over all my files.”</p><p>The user added they tried a number of workarounds, such as deleting all Chrome-related files, restoring the app as well as downloading the Chrome Beta, none of which seemed to fix the issues.</p><p>Two weeks after Microsoft launched the May 2020 Update, <a href="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020">which was released with ten major flaws</a>, users have continued to experience issues. Lenovo ThinkPad users, for example, may encounter bugs specific to their machines, including <a href="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues">incompatibility with BitLocker and an AMD video driver issue</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kKbZCv2ayrHik6L2FLwPnc" name="kKbZCv2ayrHik6L2FLwPnc.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/kKbZCv2ayrHik6L2FLwPnc.jpg" mos="https://cdn.mos.cms.futurecdn.net/kKbZCv2ayrHik6L2FLwPnc.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Join us for the inaugural IT Pro Live conference June 22-26</strong></p><p class="fancy-box__body-text">Stream it live from the safety of your own home or office</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/video-conferencing/355521/join-us-for-the-inaugural-it-pro-live-conference-june-22-26" data-original-url="/software/video-conferencing/355521/join-us-for-the-inaugural-it-pro-live-conference-june-22-26">FREE DOWNLOAD</a></p></div></div><p>The reported issues with Google Chrome’s syncing capabilities, which hasn’t yet been recognised by Microsoft, has emerged alongside incompatibility issues with certain printers. Microsoft confirmed over the weekend that it’s an investigating an issue involving the print spooler erroring or closing unexpectedly when attempting to print. This has come as a result of <a href="https://support.microsoft.com/help/4557957" target="_blank">the minor update KB4557957</a>.</p><p>There is some dispute over the root nature of the cause, however, with one user noting on a Microsoft Answer forum, for instance, that <a href="https://answers.microsoft.com/en-us/windows/forum/all/unable-to-print-after-installing-update-kb4560960/9c1ecffd-bbc8-44f7-a9d8-23854771c8e3" target="_blank">the problem was solved after they uninstalled the </a><a href="https://answers.microsoft.com/en-us/windows/forum/all/unable-to-print-after-installing-update-kb4560960/9c1ecffd-bbc8-44f7-a9d8-23854771c8e3" target="_blank">KB4560960 and KB4561608 updates.</a></p><p>The latest in a string of bug-ridden flagship upgrades, the May 2020 upgrade has seen a bumpy release so far, despite Microsoft giving it a much longer testing lead-time than normal. The update was being <a href="https://www.itpro.com/microsoft-windows/33011/windows-10-begins-early-testing-for-major-2020-upgrade" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/33011/windows-10-begins-early-testing-for-major-2020-upgrade">beta-tested as far back as February 2019</a>, in light of the botched April 2018 and October 2018 upgrade. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lenovo devices hit by Windows 10 May 2020 Update issues ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/356004/lenovo-devices-hit-by-windows-10-may-2020-issues</link>
                                                                            <description>
                            <![CDATA[ The manufacturer identifies five compatibility issues specifically affecting a string of ThinkPad machines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3ZLAhBg3ojLD9CYY5WYfy7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8mJZ77H4vsk8Hmk5zXoXa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Jun 2020 10:40:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8mJZ77H4vsk8Hmk5zXoXa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8mJZ77H4vsk8Hmk5zXoXa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Lenovo has identified five major errors that may occur when users upgrade their ThinkPad devices with the latest version of Windows 10 after testing the May 2020 Update for any compatibility issues.</p><p>The latest update to the Windows 10 operating system, dubbed version 2004, was <a href="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020">released with a number of significant flaws towards the end of May</a>, with Microsoft warning some users against updating their systems as a result. This was after the developer had to delay the update initially <a href="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft">due to the last-minute discovery of a zero-day vulnerability</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft" data-original-url="/operating-systems/microsoft-windows/355522/windows-10-may-2020-upgrade-delayed-after-microsoft">Windows 10 May 2020 Update delayed after zero-day discovery</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/355634/the-top-ten-most-commonly-exploited-vulnerabilities-revealed" data-original-url="/security/vulnerability/355634/the-top-ten-most-commonly-exploited-vulnerabilities-revealed">The top ten most-commonly exploited vulnerabilities revealed</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020" data-original-url="/operating-systems/microsoft-windows/355812/microsoft-warns-against-installing-windows-10-may-2020">Microsoft warns users not to install Windows 10's May update</a></p></div></div><p>Having tested version 2004 with dozens of Lenovo machines, five additional errors that users may encounter have been identified affecting ThinkPad devices. </p><p>These range in severity from limitations with video drivers causing obscurities to manifest in certain apps, to some drivers failing altogether. These errors are as follows.</p><h3 class="article-body__section" id="section-bios-failure-resulting-in-bsod"><span>BIOS failure resulting in BSOD </span></h3><p>Users with Lenovo ThinkPad P70 devices may inexplicably encounter the infamous blue screen of death (BSOD) after the system is resumed from sleep or hibernate modes. This is suspected to be related to an error in the system BIOS, although it’s still under investigation. </p><p>To avoid the BSOD, Lenovo has recommended that users roll back to the previous iteration of Windows 10, dubbed version 1909, until the issue is resolved and a fix is released. </p><h3 class="article-body__section" id="section-ultranav-driver-incompatibility-issue"><span>UltraNav driver incompatibility issue</span></h3><p>Affecting Lenovo ThinkPad E570p and ThinkPad L570 machines, users may encounter an error message due to a limitation with the UltraNav driver after recovering their machines from a system image. </p><p>The error message will be displayed as “Failed to load Apoint.DLL, Alps Pointing device application has stopped”, although ca be resolved by updating the UltraNav driver through Device Manager module.</p><h3 class="article-body__section" id="section-bitlocker-incompatibility"><span>BitLocker incompatibility</span></h3><p>After upgrading from the Windows 10 Autumn 2019 update to version 2004 on a string of ThinkPad devices including the <a href="https://www.itpro.com/laptops/32934/lenovo-thinkpad-x1-extreme-review-the-thinkpad-perfected" target="_blank" data-original-url="https://www.itpro.com/laptops/32934/lenovo-thinkpad-x1-extreme-review-the-thinkpad-perfected">ThinkPad X1 Extreme</a> Gen2, and the ThinkPad E15 Gen 2, users may encounter a yellow warning mark on the disk drive. </p><p>To resolve the problem, and to continue to use the BitLocker hard driver encryption feature, users will need to right-click on the disk drive with the warning mark, turn on BitLocker and then turn off BitLocker. </p><h3 class="article-body__section" id="section-amd-video-driver-issue"><span>AMD video driver issue</span></h3><p>Users with ThinkPad X395 devices may encounter a green border when attempting to resize the window of the Movies & TV application. This is due to a limitation with the AMD video driver fitted into the device, and cannot be resolved using a workaround, although an update for the driver should be available after 15 June 2020.</p><h3 class="article-body__section" id="section-failure-in-the-system-recovery-process"><span>Failure in the system recovery process</span></h3><p>During the system recovery process on the ThinkPad X1 Tablet Gen3, the F11 hotkey may not work normally. Although the target fix date won’t be until 29 June 2020, Lenovo has advised users to navigate to the Keyboard Manager settings in the Control Panel. </p><p>Users can navigate to the <a href="https://pcsupport.lenovo.com/in/en/solutions/ht510448" target="_blank">Lenovo support page for more information</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edison Mail flaw granted users access to other people's inboxes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/355679/edison-mail-flaw-granted-users-access-to-other-peoples-inboxes</link>
                                                                            <description>
                            <![CDATA[ The third-party email client has rolled back a faulty update after major privacy concerns were raised ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jmYA8aeH72zghKvoAFLXbV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SX45TD67aDdGYDZTiHFk89-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 May 2020 11:04:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SX45TD67aDdGYDZTiHFk89-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Email symbols with padlock against dark background]]></media:description>                                                            <media:text><![CDATA[Email symbols with padlock against dark background]]></media:text>
                                <media:title type="plain"><![CDATA[Email symbols with padlock against dark background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SX45TD67aDdGYDZTiHFk89-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Thousands using the popular third-party <a href="https://www.itpro.com/email-providers/24794/gmail-vs-outlookcom-which-one-is-better" target="_blank" data-original-url="https://www.itpro.com/email-providers/24794/gmail-vs-outlookcom-which-one-is-better">email client</a>, Edison Mail, accidentally gained full access to the email accounts of other users due to a software glitch.</p><p>The temporary issue, which occurred when iOS users enabled a new account syncing feature, was widely reported online following the release of an update last week. </p><p>This bug, which has now been resolved, inadvertently caused individuals’ inboxes to synchronise with other users’ accounts, leading to a significant violation of privacy.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/355415/two-severe-ios-mail-flaws-being-exploited-in-the-wild" data-original-url="/security/vulnerability/355415/two-severe-ios-mail-flaws-being-exploited-in-the-wild">Apple Mail on iOS has two severe "zero-click" flaws</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/355527/the-love-bug-creator-fesses-up-20-years-later" data-original-url="/security/hacking/355527/the-love-bug-creator-fesses-up-20-years-later">Creator of notorious 'Love Bug' virus comes clean after 20 years</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs" data-original-url="/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs">Safari bug let hackers access cameras on iPhones and Macs</a></p></div></div><p>Edison Mail allows users on hardware manufactured by Apple, including iPhones, iPads and Macs, as well as Android devices, to manage their email inboxes and synchronise them across their hardware. Edison Mail also boasts fast loading times, functionality to categorise messages, and claims to offer an ad-free experience. </p><p>An update rolled out on 15 May, however, caused a “technical malfunction” that allowed users to gain full access to inboxes belonging to others, in their entirety. This incident affected 6,480 Edison Mail <a href="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you" target="_blank" data-original-url="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you">iOS users</a>, according to the company.</p><p>“A security bug was introduced for a small fraction of our iOS users,” the company said. “We have rolled that update back. All impacted users are being logged out and will need to re-login.</p><p>“We have resolved the recent security issue in Edison mail for iOS and secured all potentially impacted accounts. We apologize to all and are fixing our processes so this does not happen again.”</p><p>The company added that although data from these individuals’ email accounts was exposed to other users, no passwords were compromised. A subsequent patch was issued on 16 May to eliminate this undue exposure.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Xc7EaCG9cbXstGjH8MnEFb" name="Xc7EaCG9cbXstGjH8MnEFb.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Xc7EaCG9cbXstGjH8MnEFb.jpg" mos="https://cdn.mos.cms.futurecdn.net/Xc7EaCG9cbXstGjH8MnEFb.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Don’t just collect data, innovate with it.</strong></p><p class="fancy-box__body-text">Removing the barriers to the experience economy</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/354045/dont-just-collect-data-innovate-with-it" data-original-url="/marketing-comms/customer-experience-cx/354045/dont-just-collect-data-innovate-with-it">FREE DOWNLOAD</a></p></div></div><p><a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">This patch</a>, as a precaution, prevented all potentially impacted users from being able to access any mail from the Edison app, effectively bricking their apps. This was before a new version of the application was made available on Sunday that restored full functionality for the thousands affected.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft AI can detect security flaws with 99% accuracy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/355368/microsoft-builds-ai-to-detect-security-flaws-with-99-accuracy</link>
                                                                            <description>
                            <![CDATA[ Developers can use the mechanism to establish whether bugs are security-related and assign a severity rating ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ogtXMDSBg8UsSMAtEZNyje</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M23LQ7ZzDBqQoDZiVUnUoR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Apr 2020 10:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M23LQ7ZzDBqQoDZiVUnUoR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M23LQ7ZzDBqQoDZiVUnUoR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has released an <a href="https://www.itpro.com/strategy/28181/what-is-ai" target="_blank" data-original-url="https://www.itpro.com/strategy/28181/what-is-ai">artificial intelligence (AI)</a>-powered tool to help developers categorise bugs and features that need to be addressed in forthcoming releases.</p><p>The software giant’s <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" target="_blank" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> system classifies bugs as security or non-security with a 99% accuracy, and also determines whether a bug is critical or non-critical with a 97% accuracy rating.</p><p>With ambitions to build a system with a level of accuracy as close as possible to a security expert, Microsoft fed its machine learning model with bugs labelled as <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">security and non-security</a>. Once this was trained, it could then label data that was not pre-classified. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32842/benefits-of-ai-and-machine-learning-for-cloud-security" data-original-url="/security/32842/benefits-of-ai-and-machine-learning-for-cloud-security">Benefits of AI and machine learning for cloud security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/354748/microsoft-unveils-largest-ever-ai-natural-language-model" data-original-url="/technology/machine-learning/354748/microsoft-unveils-largest-ever-ai-natural-language-model">Microsoft unveils 'largest ever' AI natural language model</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/30736/what-is-ethical-ai" data-original-url="/technology/30736/what-is-ethical-ai">What is ethical AI?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/354879/microsoft-and-ibm-back-popes-pledge-for-ethical-ai" data-original-url="/technology/artificial-intelligence-ai/354879/microsoft-and-ibm-back-popes-pledge-for-ethical-ai">Microsoft and IBM back Pope’s pledge for ethical AI</a></p></div></div><p>“Every day, software developers stare down a long list of features and bugs that need to be addressed,” said Microsoft’s senior security program manager Scott Christiansen, and data and applied scientist Mayana Pereira. </p><p>“Security professionals try to help by using automated tools to prioritize security bugs, but too often, engineers waste time on false positives or miss a critical security vulnerability that has been misclassified.</p><p>“At Microsoft, 47,000 developers generate nearly 30 thousand bugs a month. These items get stored across over 100 AzureDevOps and <a href="https://www.itpro.com/software/development/355317/github-now-free-for-all-dev-teams" target="_blank" data-original-url="https://www.itpro.com/software/development/355317/github-now-free-for-all-dev-teams">GitHub repositories</a>. To better label and prioritize bugs at that scale, we couldn’t just apply more people to the problem. However, large volumes of semi-curated data are perfect for machine learning.”</p><p>Because the system needs to be as accurate as a security expert, security professionals approved training data before this was fed into the machine learning model. Once the model was operational, they were brought back to evaluate the model in production.</p><p>The project began with data science and the collection of all data types and sources to evaluate quality. Security experts were then brought in to review the data and confirm the labels assigned were correct. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="poHpRUafXEx545ewBPBLXc" name="poHpRUafXEx545ewBPBLXc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/poHpRUafXEx545ewBPBLXc.png" mos="https://cdn.mos.cms.futurecdn.net/poHpRUafXEx545ewBPBLXc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Shifting toward Enterprise-grade AI</strong></p><p class="fancy-box__body-text">Resolving data and skills gaps to realise value</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/355280/shifting-toward-enterprise-grade-ai" data-original-url="/technology/artificial-intelligence-ai/355280/shifting-toward-enterprise-grade-ai">FREE DOWNLOAD</a></p></div></div><p>Data scientists then chose a modelling technique, trained the model, and evaluated performance. Finally, security experts evaluated the model in production by monitoring the average number of bugs and manually reviewing a random sample.</p><p>The mechanism uses a step-step machine learning model operation; first learning how to classify between security and non-security bugs and then to apply a severity rating.</p><p>As a result of the level of accuracy, Microsoft now believes it’s catching more security vulnerabilities before they are exploited in the wild.</p><p>Development teams can read details in a <a href="https://docs.microsoft.com/security/engineering/identifying-security-bug-reports">published academic paper</a>, with the machine learning methodology set to be open-sourced through GitHub in the coming months. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Businesses brace for second 'Fujiwhara effect' of 2020 as Patch Tuesday looms ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/355276/businesses-brace-for-second-fujiwhara-effect-of-2020-as-patch-tuesday</link>
                                                                            <description>
                            <![CDATA[ Organisations set for a day of chaos on 14 April as vendors plan to fix 500-plus software vulnerabilities at once ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A95QmqPGwfsD5vJ62RsFh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Uf9RHPHEBRC6WC57YiYu96-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Apr 2020 11:42:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Uf9RHPHEBRC6WC57YiYu96-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[weather]]></media:description>                                                            <media:text><![CDATA[weather]]></media:text>
                                <media:title type="plain"><![CDATA[weather]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Uf9RHPHEBRC6WC57YiYu96-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Software giants will release fixes for hundreds of bugs in unison for the second time this year, at a time when IT teams are already under pressure from mass adoption of remote working and surging cyber crime.</p><p>The forthcoming Patch Tuesday, on 14 April, will see as many as 500 vulnerabilities released by the likes of Microsoft and Oracle, causing a phenomenon dubbed the ‘Fujiwhara effect’. Such a security event is ordinarily rare, with the last one before 2020 occurring in 2014. </p><p>This year has been no stranger to coordinated bug fixes, with next Tuesday representing the second ‘Fujiwhara effect’ in 2020, according to <a href="https://www.riskbasedsecurity.com/2020/04/08/a-familiar-storm-approaches-april-14ths-vulnerability-fujiwhara-event">Risk Based Security</a>. This is in addition to a third event scheduled to hit on 14 July.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw" data-original-url="/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw">Microsoft to patch ‘extraordinarily serious’ cryptographic flaw</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed" data-original-url="/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Stories from the front line: The secrets of the Red Team revealed</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354440/the-scariest-security-horror-stories-of-2019" data-original-url="/security/cyber-security/354440/the-scariest-security-horror-stories-of-2019">The scariest security horror stories of 2019</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" data-original-url="/security/34257/it-pro-panel-why-is-patch-management-so-difficult">IT Pro Panel: Why is patch management so difficult?</a></p></div></div><p>Such coordination of bug fixes poses a challenge for security teams, who <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">must analyse and prioritise hundreds of disclosures</a> before remediation can even begin.</p><p>This coming Tuesday may see as many as 300 to 500-plus fixes released, according to forecasts. This is significantly higher than average, with roughly 60 flaws published per day, normally.</p><p>This latest onslaught will also come at a time when employees have begun working from home en masse, and cyber criminals have been empowered by <a href="https://www.itpro.com/business-strategy/flexible-working/355186/why-were-lucky-covid-19-has-come-now" target="_blank" data-original-url="https://www.itpro.com/business-strategy/flexible-working/355186/why-were-lucky-covid-19-has-come-now">the COVID-19 pandemic</a> to ramp up activity significantly.</p><p>“Even for large organizations, processing these new “Patch Tuesday” disclosures can take weeks, and that’s with a well-funded and coordinated team,” said Risk Based Security. “The hours required for IT security teams to collect, analyze, triage, and then address the coming vulnerabilities will be considerable.</p><p>“If there wasn’t enough going on already, organizations must somehow manage the coming Vulnerability Fujiwhara Effect despite the current business disruption and pressure on security budgets.”</p><p>The ‘Fujiwhara effect’ in meteorology is known as an extreme weather event in which two massive hurricanes collide or merge.</p><p>The last cyber security ‘Fujiwhara effect’ on 14 January, saw more than ten major software players participate, including Adobe, SAP, Schneider Electric, VMWare, Intel, as well as Oracle and Microsoft, among others.</p><p>The release of so many patches at once, numbering more than 300, saw IT and security teams across the world scramble to implement updates to their business-critical systems.</p><p>Among these fixes was a Microsoft-developed patch for <a href="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw" target="_blank" data-original-url="https://www.itpro.com/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw">an "extraordinarily serious" cryptographic flaw</a> anchored in the crypt32.dll Windows component, with organisations like the US military given advanced access to the fix.</p><p>Winding forward some months, <a href="https://www.itpro.com/business-strategy/digital-transformation/355152/it-pro-panel-coping-with-covid-19" target="_blank" data-original-url="https://www.itpro.com/business-strategy/digital-transformation/355152/it-pro-panel-coping-with-covid-19">organisations are facing greater challenges than arguably ever before</a>, in terms of the economy and the labour market, not to mention cyber security threats increasing significantly over the last few weeks. </p><p>The UK’s National Cyber Security Centre (NCSC) this week issued a joint-warning with US cyber security authorities warning businesses of a surge in cyber criminal activity, most of which was attempting to exploit the coronavirus pandemic.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HPE warns of 'critical' bug that destroys SSDs after 40,000 hours ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/server-storage/355118/hpe-warns-of-critical-bug-that-destroys-ssds-after-40000-hours</link>
                                                                            <description>
                            <![CDATA[ Firm urges customers to upgrade firmware as soon as possible ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i9f7T9m2qY5RUSNYLha5bu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ia7B426S8S39obSVe26bBd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Mar 2020 10:46:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Carly Page ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/haaytLZQLzJxCzMHFEeyiZ.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ia7B426S8S39obSVe26bBd-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hewlett Packard Enterprise (HPE) logo on a glass building]]></media:description>                                                            <media:text><![CDATA[Hewlett Packard Enterprise (HPE) logo on a glass building]]></media:text>
                                <media:title type="plain"><![CDATA[Hewlett Packard Enterprise (HPE) logo on a glass building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ia7B426S8S39obSVe26bBd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hewlett-Packard Enterprise (HPE) has warned that some of its SCSI solid-state drives will fail after 40,000 hours of operation.</p><p>The “critical” flaw affects drives in HPE server and storage products, including the <a href="https://www.itpro.com/server/29461/hpe-proliant-dl380-gen10-review" target="_blank" data-original-url="https://www.itpro.com/server/29461/hpe-proliant-dl380-gen10-review">HPE ProLiant</a>, Synergy, Apollo 4200, Synergy Storage Modules, D3000 Storage Enclosure, StoreEasy 1000 Storage, and causes the SSDs to brick after exactly 40,000 hours (4 years, 206 days and 16 hours) of use. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CPqieBrZwYSbafXamK3TUe" name="CPqieBrZwYSbafXamK3TUe.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/CPqieBrZwYSbafXamK3TUe.png" mos="https://cdn.mos.cms.futurecdn.net/CPqieBrZwYSbafXamK3TUe.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Enabling enterprise machine and deep learning with intelligent storage</strong></p><p class="fancy-box__body-text">The power of AI can only be realised through efficient and performant delivery of data</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/354886/enabling-enterprise-machine-and-deep-learning-with-intelligent" data-original-url="/technology/machine-learning/354886/enabling-enterprise-machine-and-deep-learning-with-intelligent">FREE DOWNLOAD</a></p></div></div><p>HPE said an SSD manufacturer alerted it to the firmware bug and added that, in a scenario where multiple SSDs are installed and put to work at the same time, it’s possible for all disks to break down simultaneously.</p><p>The company also warned that the bug is not unique to HPE drives and that other manufacturers SSDs could also be affected.</p><p>It’s likely Dell-EMC was also affected, as the company issued an urgent firmware update last month that also mentioned SSDs failing after 40,000 hours.</p><p>The catastrophic bug, which would cause data to become unrecoverable once a drive had failed, affects products running a firmware version older than HPD7, HPE says.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/1u-servers/25753/hpe-proliant-dl20-gen9-review" data-original-url="/1u-servers/25753/hpe-proliant-dl20-gen9-review">HPE ProLiant DL20 Gen9 review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/354979/hpe-reveals-text-book-sized-micro-server" data-original-url="/cloud/354979/hpe-reveals-text-book-sized-micro-server">HPE reveals text book-sized micro server</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/solid-state-storage-ssd/33908/best-ssds-the-top-nvme-and-sata-drives-around" data-original-url="/solid-state-storage-ssd/33908/best-ssds-the-top-nvme-and-sata-drives-around">Best SSDs 2023: The top NVMe and SATA drives around</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/354923/hpe-partners-with-amd-for-el-capitan-nuclear-weapons-supercomputer" data-original-url="/technology/354923/hpe-partners-with-amd-for-el-capitan-nuclear-weapons-supercomputer">HPE partners with AMD for El Capitan nuclear weapons supercomputer</a></p></div></div><p>The company recommends that users upgrade the firmware to version HPD7 as soon as possible. </p><p>“HPE recommends performing an online firmware update on HPE Gen9 servers during minimal I/O activity. This will not require a reboot in most circumstances,” <a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00097382en_us" target="_blank">HPE said in an advisory</a>. </p><p>“However, in instances where the online firmware update does not complete successfully, an offline update is required. After the flash update completes, the Smart Component will provide a message regarding whether the flash completed successfully.” </p><p>Fortunately, HPE said that no affected SSDs have yet to fail as a result of the firmware bug, but it estimates that SSDs that are left unpatched will begin to fail as early as October of this year.</p><p>This is not the first time HPE has warned about potentially disastrous flaws affecting its solid-state drives. Back in November of last year, the company sent out a similar message to its customers after a firmware defect in its SSDs caused them to fail after running for 32,768 hours.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google’s Project Zero rolls out automatic 90-day disclosures ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/354481/googles-project-zero-rolls-out-automatic-90-day-disclosures</link>
                                                                            <description>
                            <![CDATA[ A raft of policy tweaks are aimed at instigating more thorough patch development and better patch adoption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xqVVrC9RCayeAHfaKXNdU3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jan 2020 12:05:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fake ladybug on a circuit board]]></media:description>                                                            <media:text><![CDATA[Fake ladybug on a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Fake ladybug on a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v4j367nsp96PK3hjm8MxGk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Project Zero security team has expanded disclosure for all bugs to a full 90 days after first being flagged, even if the bug has been fixed early, as part of a number of changes to its policies and objectives.</p><p>Previously, its security researchers would disclose a bug that’s been flagged after 90 days have elapsed, or when the bug was fixed, at their discretion. </p><p>The Google-run team, however, is trialling 90-day disclosure by default, whether or not the bug has been fixed, unless a mutual agreement is reached between Project Zero and any vendor in concern.</p><p>Project Zero’s policy goals have also evolved beyond just ‘<a href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" target="_blank" data-original-url="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult">faster patch deployment</a>’, to also encompass ‘thorough patch development’ and, among customers, ‘improved patch adoption’.</p><p>Extending the disclosure window to 90 days for bugs that have been fixed, meanwhile, will lead to incomplete fixes reported back, and compiled into the original bug report, as opposed to being filed under a new vulnerability. This was also previously done at the discretion of any particular researcher.</p><p>“We're constantly considering whether our policies are in the interest of user security, and we believe this change is a further step in the right direction,” said Project Zero manager Tim Willis. “We also think it's simple, consistent and fair.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34116/google-discloses-slew-of-imessage-vulnerabilities" data-original-url="/security/34116/google-discloses-slew-of-imessage-vulnerabilities">Google discloses slew of iMessage vulnerabilities</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33863/mozilla-urges-firefox-users-to-patch-browsers-immediately" data-original-url="/security/33863/mozilla-urges-firefox-users-to-patch-browsers-immediately">Mozilla urges Firefox users to patch browsers immediately</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" data-original-url="/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">Teenage hacker makes $1m from bug bounty rewards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" data-original-url="/security/34257/it-pro-panel-why-is-patch-management-so-difficult">IT Pro Panel: Why is patch management so difficult?</a></p></div></div><p>“We want to make attacks using zero-day exploits more costly. We do this through the lens of offensive vulnerability research and evidence of how real attackers behave. </p><p>“This involves discovering and reporting a large number of security vulnerabilities, and through our experience with this work, we realised that faster patch development and patch deployment were very important and areas for industry improvement.”</p><p>The team has been at the heart of a string of significant bug disclosures of varying severity over the last few years, including, for example, <a href="https://www.itpro.com/zero-day-exploit/30582/google-s-project-zero-discloses-edge-browser-bug-after-microsoft-didn-t-fix" target="_blank" data-original-url="https://www.itpro.com/zero-day-exploit/30582/google-s-project-zero-discloses-edge-browser-bug-after-microsoft-didn-t-fix">the disclosure in 2018 of a significant Edge browser bug</a> that Microsoft didn't fix within the 90-day window.</p><p>Project Zero’s core principles also came under review, with the team prioritising simplicity, consistency and fairness to different vendors, where some don’t get preferential treatment over others.</p><p>Its two new core objectives, <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">thorough patch deployment</a> and improved adoption, meanwhile are being added in conjunction to the full extension of the 90-day window as there were concerns that some companies fixed bugs by simply “papering over the cracks”.</p><p>By extending the disclosure window to a full 90 days for all bugs, including fixed bugs, Project Zero is hoping that the aim of ‘faster patch deployment’ will no longer lead to compromise on quality if there’s no need to rush getting fixes out.</p><p>As a result of extending disclosure to 90 days, researchers are hoping to see more iterative and through patching practices from vendors, and also improve patch adoption since Project Zero is incentivising vendors to offer updates to a large population within 90 days.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HackerOne bug bounty platform breached by its own user ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/354287/hackerone-bug-bounty-platform-breached-by-its-own-user</link>
                                                                            <description>
                            <![CDATA[ The bug bounty specialist paid the hacker responsible a cool $20,000 for their efforts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eX5G43mZHbYhshH8tUFMi2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JcULBUeCjTeXK6wU56j3e4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Dec 2019 08:37:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JcULBUeCjTeXK6wU56j3e4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker wearing an anonymous mask with a golden halo above their head]]></media:description>                                                            <media:text><![CDATA[A hacker wearing an anonymous mask with a golden halo above their head]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker wearing an anonymous mask with a golden halo above their head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JcULBUeCjTeXK6wU56j3e4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Provider of bug bounty support to <a href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" target="_blank" data-original-url="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">major global organisations</a> HackerOne has paid one of its members for exposing an internal security breach. </p><p>A reward of $20,000 (£15,244) has been given to haxta4ok00, the bug hunter who exposed the mistake committed by a staffer at the company which helps the likes of <a href="https://www.itpro.com/business/policy-legislation/354196/uber-denied-licence-to-operate-in-london" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/354196/uber-denied-licence-to-operate-in-london">Uber</a>, <a href="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs" target="_blank" data-original-url="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs">Goldman Sachs</a> and the US Department of Defense offer bug bounties of their own.</p><p>The bug hunter was potentially able to view the records and private, undisclosed <a href="https://www.itpro.com/vulnerability/34184/what-s-the-difference-between-a-security-vulnerability-and-a-security-threat" target="_blank" data-original-url="https://www.itpro.com/vulnerability/34184/what-s-the-difference-between-a-security-vulnerability-and-a-security-threat">vulnerabilities</a> of HackerOne's biggest clients due to what the company is calling a "human error".</p><p>A HackerOne security analyst tasked with verifying disclosure reports from bug hunters sent a URL loaded with their session <a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" target="_blank" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">cookie information</a> which the hunter was able to use to view things on the site only logged-in staffers should be able to.</p><p>Sending URLs between analyst and hunter is a routine process, HackerOne said in a report. </p><p>"When a security analyst fails to reproduce a potentially valid security vulnerability, they go back and forth with the hacker to better understand the report," said HackerOne. "During this dialogue, security analysts may include steps they've taken in their response to the report, including HTTP requests that they made to reproduce. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties" data-original-url="/security/33412/microsoft-joins-forces-with-hackerone-to-boost-bug-bounties">Microsoft joins forces with HackerOne to boost bug bounties</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" data-original-url="/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">Teenage hacker makes $1m from bug bounty rewards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs" data-original-url="/security/34708/never-give-humans-the-keys-to-your-kingdom-say-goldman-sachs-security-chiefs">Never give humans the keys to your kingdom, say Goldman Sachs security chiefs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28649/why-can-t-software-firms-sort-their-own-security" data-original-url="/security/28649/why-can-t-software-firms-sort-their-own-security">Why can’t software firms sort their own security?</a></p></div></div><p>"In this particular case, parts of a cURL command, copied from a browser console, were not removed before posting it to the report, disclosing the session cookie," it added.</p><p>The company confirmed that the event lasted only a short time and was not carried out with malicious intent. No undisclosed vulnerabilities were stolen, exploited or published as a result of the incident. All copies of potentially sensitive information were deleted.</p><p>"Similar to previously disclosed incidents or weaknesses within BugZilla or Google Issue Tracker, exposure of non-public HackerOne reports presents an immediate danger to not only businesses with hosted programs but also effectively all Internet users," said Craig Young, senior security researcher at Tripwire.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mVM9DUbmvCJhNp5jYeasdf" name="mVM9DUbmvCJhNp5jYeasdf.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf.png" mos="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why UEM is the key to enterprise IT security</strong></p><p class="fancy-box__body-text">A guide to effective endpoint security</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security" data-original-url="/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security">FREE DOWNLOAD</a></p></div></div><p>"While I commend HackerOne for their response, this incident is yet another reminder of the distinct risk organisations take by using managed vulnerability reporting services like BugCrowd or HackerOne," he added. "The consolidation of valuable data by such vendors creates a hugely attractive attack target for intelligence agencies (or even criminal actors) to fill their arsenal."</p><p>Something that seemed to concern Jobert Abma, co-founder of HackerOne and the individual responsible for following-up with haxta4ok00, was the observation he made regarding the sheer number of pages the hunter opened while accessing a privileged account.</p><p>"We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account," said Abma. "Would you mind explaining why you did so to us?"</p><p>"I did it to show the impact," said haxta4ok00. "I didn't mean any harm by it. I reported it to you at once.</p><p>"I apologise if I did anything wrong, but it was just a <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hack</a>," the bug hunter added.</p><p>The issue was given a CVSS score of 8.3, which is considered "high", not as severe as the likes of <a href="https://www.itpro.com/security/34802/bluekeep-attack-discovery-has-done-nothing-to-motivate-businesses-into-patching" target="_blank" data-original-url="https://www.itpro.com/security/34802/bluekeep-attack-discovery-has-done-nothing-to-motivate-businesses-into-patching">BlueKeep</a>, for example.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google to offer $1.5m to anyone that can break a Pixel 4 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/bugs/354180/google-to-offer-15m-to-anyone-that-can-break-a-pixel-4</link>
                                                                            <description>
                            <![CDATA[ In a bid to make its Titan technology more secure, Google takes a page out of Apple's playbook ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hfUUbp1rHyKuiFVQAsAySL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oYR9j29t6uVrrfgXKAbNKD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Nov 2019 10:25:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oYR9j29t6uVrrfgXKAbNKD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oYR9j29t6uVrrfgXKAbNKD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has expanded its Android <a href="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards" target="_blank" data-original-url="https://www.itpro.com/bugs/33127/teenage-hacker-makes-1m-from-bug-bounty-rewards">bug bounty program</a> to match the $1.5 million (£1.17m) payout Apple offers for bugs found in its flagship smartphones.</p><p>The Titan M security layer, which features in Google's latest Pixel 4 smartphone, is now included as part of the company's bounty list, with the discovery of a working remote-code execution (RCE) bug being worth a potential $1 million (£776,900).</p><p>The bug hunter will be eligible for an additional 50% bonus if the Titan M vulnerability is detected and provided to Google in a developer preview version of Android, taking the maximum reward up to $1.5 million.</p><p>Aside from Titan M, Google’s <a href="https://www.google.com/about/appsecurity/android-rewards">Android Security Reward Program</a> will also continue to offer rewards to researchers who find vulnerabilities in other hardware.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34185/security-researchers-now-eligible-for-bug-hunting-iphones" data-original-url="/security/34185/security-researchers-now-eligible-for-bug-hunting-iphones">Security researchers now eligible for bug-hunting iPhones</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/bugs/34243/microsoft-launches-bug-bounty-programme-for-chromium-based-edge" data-original-url="/bugs/34243/microsoft-launches-bug-bounty-programme-for-chromium-based-edge">Microsoft launches bug bounty programme for Chromium-based Edge</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/two-factor-authentication-2fa/33833/google-turns-android-phones-into-2fa-keys-for-ios-login" data-original-url="/two-factor-authentication-2fa/33833/google-turns-android-phones-into-2fa-keys-for-ios-login">Google turns Android phones into 2FA keys for iOS login</a></p></div></div><p>Up to $500,000 (£388,365) will be awarded to those who can find bugs relating to issues such as unauthorised data exfiltration and bypassing of the Pixel’s lock screen. The 50% developer preview bonus also applies to these vulnerabilities.</p><p>Google has invested heavily in its proprietary Titan technology in recent years, adding its functionality to many of its products as a more secure method of account authentication compared to <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" target="_blank" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">2FA</a>.</p><p>It’s designed to offer Google hardware owners better security by assigning a physical security layer to an account, meaning remote attackers can’t intercept authenticator codes or mimic approval actions of the true owner.</p><p>Despite the faith that Google has placed in its Titan technology, it has been proven in the past to be less than iron-clad.</p><p>Earlier this year, <a href="https://www.itpro.com/two-factor-authentication-2fa/33654/security-flaw-found-in-googles-most-secure-account-authenticator" data-original-url="https://www.itpro.com/two-factor-authentication-2fa/33654/security-flaw-found-in-googles-most-secure-account-authenticator">a security flaw was found in a version of Google’s Titan Key</a>, a physical device outside of the Pixel line that authenticates account log-in. </p><p>It only affected the Bluetooth pairing protocol needed to pair the key with the device through which the account was being accessed and Google said it would offer free replacements for the faulty units worth $50.</p><p>The bounty rewards have been increased to match Apple’s own bug bounty program which itself expanded earlier this year.</p><p>Apple also offers a maximum reward of $1 million with a 50% bonus for bugs found during an iOS beta phase.</p><p>Apple announced the expansion at Black Hat 2019 along with the news that select researchers could apply for <a href="https://www.itpro.com/security/34185/security-researchers-now-eligible-for-bug-hunting-iphones" data-original-url="https://www.itpro.com/security/34185/security-researchers-now-eligible-for-bug-hunting-iphones">specially crafted iPhones</a> that would make it easier for them to detect vulnerabilities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tech giants band together to form the GitHub Security Lab ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/bugs/34827/tech-giants-band-together-to-form-the-github-security-lab</link>
                                                                            <description>
                            <![CDATA[ The likes of Mozilla, Intel and Oracle have joined with Microsoft for the open-source project ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">usmLzifomMBBoCi1rE54gR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/77vJGaSB5YgJ2D9sLQcnRR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Nov 2019 12:49:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/77vJGaSB5YgJ2D9sLQcnRR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GitHub office with GitHub logo over top]]></media:description>                                                            <media:text><![CDATA[GitHub office with GitHub logo over top]]></media:text>
                                <media:title type="plain"><![CDATA[GitHub office with GitHub logo over top]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/77vJGaSB5YgJ2D9sLQcnRR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Some of the biggest tech firms have joined forces to launch a community-led <a href="https://www.itpro.com/open-source/31833/what-is-github" target="_blank" data-original-url="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> scheme in which researchers will hunt down and fix bugs in <a href="https://www.itpro.com/software/28109/what-is-open-source" target="_blank" data-original-url="https://www.itpro.com/software/28109/what-is-open-source">open-source </a>projects.</p><p>The co-operative effort will see security researchers report new vulnerabilities in open source projects using GitHub's newly-developed CodeQL tool. This semantic code analysis engine will let users query code as if it were data, in order to find all variants of a discovered vulnerability, and then share findings with the wider community.</p><p>GitHub's <a href="https://securitylab.github.com" target="_blank">Security Lab</a> will also work to build tools to better secure code-bases, more effectively connect the wider security community, and bring developers together as well.</p><p>"GitHub's approach to security addresses the whole open source security lifecycle," said vice president for product management and security Jamie Cool.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/20567/what-does-microsoft-buying-nokia-mean-oem-community" data-original-url="/strategy/20567/what-does-microsoft-buying-nokia-mean-oem-community">What does Microsoft buying Nokia mean for the OEM community?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/web-development/34799/mozilla-fastly-intel-and-red-hat-launch-secure-development-alliance" data-original-url="/web-development/34799/mozilla-fastly-intel-and-red-hat-launch-secure-development-alliance">Mozilla, Fastly, Intel, and Red Hat launch secure development alliance</a></p></div></div><p>"GitHub Security Lab will help identify and report vulnerabilities in open source software, while maintainers and developers use GitHub to create fixes, coordinate disclosure, and update dependent projects to a fixed version."</p><p>The initiative has launched as a 14-strong collaboration between F5 Networks, GitHub, Google, HackerOne, Intel, IOActive, JP Morgan, Microsoft, Mozilla, NCC Group, Okta, Trail of Bits, Uber and VMware.</p><p>The team behind Security Lab will dedicate full-time resources into finding and reporting vulnerabilities, and has already found more than 100 issues deemed serious enough to be issued with CVE categorisations.</p><p>The CodeQL tool, developed by GitHub, is also being made open-source, with users able to explore reams of open source code to find vulnerabilities, especially different versions of the same vulnerability that can otherwise be difficult to trace.</p><p>Developers are also being incentivised to contribute through a bug bounty programme which offers an award of up to $2,500, depending on the severity of the flaw and the quality of the submitted query.</p><p>GitHub's initiative is similar in nature to a host of other organisations that have been created in recent years to combat the rising tide of cyber crime, and bolster <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> in general.</p><p>Microsoft, for example, is also a <a href="https://www.itpro.com/security/34511/tech-giants-form-cyber-security-supergroup" target="_blank" data-original-url="https://www.itpro.com/security/34511/tech-giants-form-cyber-security-supergroup">founding member of the CyberPeace Institute</a>, which was established alongside Mastercard and the Hewlett Foundation in September to combat global cyber crime.</p><p>Mozilla, Intel and Red Hat among others were also part of a just freshly-launched initiative to make the software development process more secure. <a href="https://www.itpro.com/web-development/34799/mozilla-fastly-intel-and-red-hat-launch-secure-development-alliance" target="_blank" data-original-url="https://www.itpro.com/web-development/34799/mozilla-fastly-intel-and-red-hat-launch-secure-development-alliance">The Bytecode Alliance will be an open source community</a> dedicated to creating secure software foundations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 17 common Windows 10 problems and how to fix them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them</link>
                                                                            <description>
                            <![CDATA[ Tips and tricks to help you solve the most common Windows 10 problems, whether that's freeing up storage or handling safe mode ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9xzx7fEMbYrX8TYy7xiU8a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hxGGjuU7JVdvrqVpUZc6Ag-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Nov 2019 12:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Nov 2024 12:32:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hxGGjuU7JVdvrqVpUZc6Ag-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Windows 10 blue screen error message displayed on a monitor]]></media:description>                                                            <media:text><![CDATA[A Windows 10 blue screen error message displayed on a monitor]]></media:text>
                                <media:title type="plain"><![CDATA[A Windows 10 blue screen error message displayed on a monitor]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hxGGjuU7JVdvrqVpUZc6Ag-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Windows 10 problems can be incredibly frustrating. From simple error alerts to the dreaded 'blue screen of death,' these issues can severely impact productivity and create major challenges for both individual users and businesses.</p><p>Despite its popularity, Windows 10 is not immune to bugs and issues. Problems with booting, upgrading, privacy protection, <a href="https://www.itpro.com/hardware/360050/hdd-vs-ssd-which-storage-solution-is-best-for-you"><u>storage management,</u></a> or a <a href="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update"><u>stuck Windows 10 update</u></a> can disrupt your workflow.</p><p>Regularly updating your system, following good cyber security practices, and monitoring system performance can significantly reduce the occurrence of many common problems.</p><p>However, when issues inevitably arise, having a trustworthy resource for troubleshooting is essential for quickly resolving them. To assist you in overcoming these challenges, we've compiled a comprehensive list of common Windows 10 problems along with detailed steps to fix them.</p><p>Whether you are facing a performance issue, software malfunction, or security concern, our guide offers practical, easy-to-follow solutions to ensure your operating system continues running smoothly, reliably, and efficiently.</p><p>Additionally, if your system has become sluggish, you might find solutions in our guide on ways to <a href="https://www.itpro.com/operating-systems/26138/windows-10-services-to-disable-how-to-speed-up-windows-10"><u>speed up Windows 10</u></a>, which can address many issues not listed here.</p><h2 class="article-body__section" id="section-1-can-t-upgrade-from-windows-7-or-windows-8"><span>1. Can't upgrade from Windows 7 or Windows 8</span></h2><p>A frequent issue many users have with Windows 10 occurs right at the start when they <a href="https://www.itpro.com/software/operating-systems/355083/how-to-upgrade-to-windows-10-for-free">upgrade from Windows 7 or Windows 8</a>. This tends to be a warning which notifies a user that the 'Get Windows 10' (also known as GWX) app is not compatible.</p><p>Alternatively, users could find that the application isn’t showing up at all. Rather annoyingly, this will cause the update to fail. But there’s no need to worry as there are a couple of ways to solve this problem:</p><ul><li>Open the Control Panel and then run Windows Update and ensure that the PC is fully up to date. If updates fail, run the Windows Update Troubleshooter (see below)</li><li>Head to Microsoft's <a href="http://www.microsoft.com/en-us/software-download/windows10">Media Creation Tool</a>. Click 'Download now', save the tool, and run it on the PC you want to upgrade. If this didn't work for you back when Windows 10 launched, try it again now - the tool has received a number of updates since.</li><li>Make sure that hardware Disable Execution Prevention (DEP) is switched on in the BIOS, referring to your motherboard manual for help if you need it. If you still have problems, use the Start Menu to search for 'performance', run Adjust the appearance and performance of Windows, click the Data Execution Prevention tab and turn DEP on for all programs and services, then reboot and try again.</li></ul><h2 class="article-body__section" id="section-2-can-t-upgrade-to-the-latest-windows-10-version"><span>2. Can't upgrade to the latest Windows 10 version</span></h2><p>Every now and then, Microsoft releases a new <a href="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update">update for Windows 10</a>. Updates tend to provide various bug fixes to help the operating system run smoother, but these can also introduce new and exciting features to Windows 10.</p><p>Even though Windows 10 is known as one of Microsoft’s more stable releases, sometimes users of the operating system find it troublesome to update to the latest Windows 10 update available.</p><p>Unfortunately, not all users will be able to see if this update is ready, meaning that you’ll have to investigate how the operating system update can be installed manually.</p><p>Ahead of carrying out the upgrade, you should see which version of the operating system you’re currently using. This can be found in the 'About Windows' tab in the Settings menu.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2hr5RKX35swY3xPkxZ4gdJ" name="" alt="Windows 10 "About Windows" screen" src="https://cdn.mos.cms.futurecdn.net/2hr5RKX35swY3xPkxZ4gdJ.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="caption-text">A screenshot of the Windows 10 "About Windows" screen </span></figcaption></figure><p>Once you're ready to upgrade to the latest Windows 10 version, you can use the Windows Update Tool. Some users see the Media Creation Tool alternative as a better and more reliable option. To access it, simply download and install it before using it to upgrade your device to the latest version.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mLccbqYSai3vKvkX6dQXye" name="" alt="A screenshot of the upgrade menu on Windows 10 Home" src="https://cdn.mos.cms.futurecdn.net/mLccbqYSai3vKvkX6dQXye.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>One thing to bear in mind is that if you run the Media Creation Tool, it may not immediately display any kind of reference that it's upgrading to the most recent version of Windows 10. The tool will ask you if you want the <a href="https://www.itpro.com/software/operating-systems/367779/windows-10-pro-vs-home-vs-enterprise-best-for-business">Home or Business version of Windows 10</a> and, if you have one of these already on your device, the newest build should hopefully be installed.</p><p>Also, make sure you've opted to keep the personal files and apps and click 'Install' to keep your data, apps, and most of your settings untouched. Now, when you hit 'Install', it should start installing the most up-to-date version of the operating system.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hcJdBp3BCdK8v9L2jVBcJJ" name="" alt="A screenshot showing the Windows Media creation tool" src="https://cdn.mos.cms.futurecdn.net/hcJdBp3BCdK8v9L2jVBcJJ.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><h2 class="article-body__section" id="section-3-you-have-a-lot-less-free-storage-after-upgrading"><span>3. You have a lot less free storage after upgrading</span></h2><p>Following a successful Windows 10 installation, the previous operating system may still be lingering and consuming hard disk space.</p><p>Unlike many other tech companies, Microsoft lets users <a href="https://www.itpro.com/hardware/357087/when-should-you-upgrade-your-hardware">upgrade their devices</a> and keep a backup of the important files that make up the previous version of your OS. This is embedded deep in the C:/ drive and acts as a safety net in case you run into issues with the newer OS, or if you simply dislike the new look.</p><p>However, if you're in need of the space, it is possible to remove this backup. To do this:</p><ul><li>Click the Windows Start button and type 'Disk Cleanup', which should produce the app in the results</li><li>Once the app opens, a drive selection option should appear next. All you need to do is select the drive your operating system is installed on. The C:/ drive should appear first, as it's more often than not the default drive.</li><li>Hit 'OK' if you're sure this is the drive your operating system was installed on. Windows 10 should then scan your system for a short period before another prompt appears.</li></ul><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JApQSFrCpKZwbyNfRtscbF" name="" alt="A screenshot showing the Disk Cleanup tool on Windows 10" src="https://cdn.mos.cms.futurecdn.net/JApQSFrCpKZwbyNfRtscbF.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><ul><li>You will now be faced with two choices, which look like a list of files to delete immediately. One option is 'Previous Windows Installation(s)' and the other will be 'Clean up system files' option on the bottom left if this first choice isn't available.</li><li>The operating system will then perform some more calculations and offers a similar-looking prompt window. This time, though, it will give you the option to delete previous Windows installation(s). You might have to scroll down to find it, but it should be taking up a sizeable bit of drive space (in our case 5GB). Tick this option and click 'OK'.</li><li>In the separate message box that appears asking if you're certain you want to send this, click 'Delete Files' and you're done.</li></ul><h2 class="article-body__section" id="section-4-windows-update-isn-t-working"><span>4. Windows Update isn't working</span></h2><p>Many people have reported issues with Windows Update, whether that's the <a href="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update">update getting stuck</a> or simply failing. Check first that you've upgraded to the Windows 10 Fall update (see above, number 2). If you're still encountering problems, download and run the Windows Update Troubleshooter, then reboot and try to update again.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MPkhMegXRccmyw39Dknhvi" name="" alt="A screenshot of the Windows Update Troubleshooter" src="https://cdn.mos.cms.futurecdn.net/MPkhMegXRccmyw39Dknhvi.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>If the problems remain, you might need to get a bit more stuck in. First, check that System Restore is configured (see below, number 7) and create a restore point. With this done, use Win+X and select Command Prompt (Admin), then type 'net stop wuauserv' (without the quotes) and hit Enter, followed by 'net stop bits' and Enter.</p><p>You should see confirmations that each service was either stopped or wasn't running. Next, open Explorer and navigate to:</p><p><strong>C:\Windows\SoftwareDistribution</strong></p><p>Delete its contents including any sub-folders. Now reboot, open Windows Update, and click Check for updates.</p><h2 class="article-body__section" id="section-5-windows-updates-when-i-don-t-want-it-to"><span>5. Windows updates when I don't want it to</span></h2><p>If you're anything like us, you set up previous Windows releases so that they wouldn't install updates automatically - one forced reboot is one too many.</p><p>There is a workaround for users running Windows 10 Pro: from the <a href="https://www.itpro.com/operating-systems/34614/how-to-fix-the-windows-10-start-menu-if-its-frozen">Start Menu</a>, search for 'gpedit' and run the Group Policy Editor. Expand Computer Configuration in the left-hand pane and navigate to Administrative Templates\Windows Components\Windows Update.</p><p>Double-click Configure Automatic Updates in the list, select the Enabled radio button, and in the left-hand box select 2 - Notify for download and notify for install. Now click OK, and you'll be notified whenever there are updates - unfortunately, they'll be a daily irritation if you're using <a href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender">Windows Defender</a>.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ajFLgYJE2d25tQdQbGCw7Z" name="" alt="Screenshot of a Windows 10 menu allowing users to turn off forced updates" src="https://cdn.mos.cms.futurecdn.net/ajFLgYJE2d25tQdQbGCw7Z.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>The Group Policy Editor isn't available on Windows 10 Home, but we'd recommend you at least open Windows Update, click 'Advanced options' and select 'Notify' to schedule restart from the 'Choose how updates are installed' list. </p><p>While you're here, all Windows 10 users might want to click 'Choose how updates are delivered' and ensure that 'Updates from more than one place' is either off or set to 'PCs on my local network'.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Qit9cov7rgwXhZph6gAo75" name="" alt="Screenshot of a Windows 10 menu showing how to notify to reschedule updates" src="https://cdn.mos.cms.futurecdn.net/Qit9cov7rgwXhZph6gAo75.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><h2 class="article-body__section" id="section-6-too-many-unnecessary-windows-10-notifications"><span>6. Too many unnecessary Windows 10 notifications</span></h2><p>Encountering too many notifications in Windows 10 can be overwhelming. The Action Center, located on the right-hand side of the taskbar, consolidates various notifications for easy management. </p><p>While this feature is helpful in principle, neglecting to manage it can lead to an overload of both important and trivial notifications. To handle this, open 'Settings' and navigate to 'Notifications & Actions' where you can customize which apps are allowed to send you alerts.</p><p>Additionally, Windows 10's default data-sharing settings are not ideal for privacy, so reviewing and adjusting these is crucial. </p><p>Access the Settings app via the Start Menu, then go to Privacy. Here, you’ll find multiple options to control which apps can access your camera, microphone, and other sensitive data. This ensures that no apps have access to information you aren’t aware of.</p><p>Windows Defender settings should also be checked. Navigate to Update & Security in Settings, then to Windows Defender. Review and adjust settings for cloud-based detection and automatic sample submission according to your preferences.</p><p>Wi-Fi Sense, a feature designed to connect your device to networks quickly, raises privacy concerns. To manage this, go to Network & Internet in the Settings menu, select Wi-Fi, then Manage Wi-Fi Settings. Turn off options like Connect to suggested open hotspots and Connect to networks shared by my contacts. This prevents your device from automatically connecting to potentially insecure networks.</p><p>Wi-Fi Sense might inadvertently share your network’s credentials with nearby devices, including those not under your control. To prevent this, rename your network’s SSID to end with "_optout." For better network hygiene, allow guests to use a separate guest network and configure all devices to avoid using Wi-Fi Sense. This practice helps maintain a secure and private network environment.</p><h2 class="article-body__section" id="section-7-windows-10-shares-too-much-data"><span>7. Windows 10 shares too much data</span></h2><p>Windows 10's default data-sharing settings are often too permissive, so it's important for users to review and adjust them to protect their privacy periodically. </p><p>To begin, open the Start Menu and search for the Settings app. Navigate to the Privacy section, where on the left-hand pane, you’ll find various options regarding how your device shares data.</p><p>Carefully examine all the categories to determine if you’re comfortable with your apps using services like the camera, microphone, and accessing your account information. This step is crucial to ensure you know which apps have access to your data.</p><p>By default, incidentally, the Feedback & diagnostics setting beams ‘enhanced data’ to Microsoft – so turn this off if you’d rather not.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cUviDmprz5LBrxsf8dDpnW" name="" alt="A screenshot of the Windows 10 privacy settings menu" src="https://cdn.mos.cms.futurecdn.net/cUviDmprz5LBrxsf8dDpnW.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>Next, go back to the main settings menu and select Update & Security, then navigate to Windows Defender. Review the default settings for cloud-based detection and automatic sample submission, and adjust them according to your preferences to ensure they align with your privacy needs.</p><p>Wi-Fi Sense, a feature designed to connect your Windows 10 device to networks more quickly, can raise privacy concerns. To manage this, enter the Settings menu, choose Network & Internet, then Wi-Fi, and select Manage Wi-Fi Settings. It is recommended to turn off "Connect to suggested open hotspots" and "Connect to networks shared by my contacts." Additionally, disable the option under Paid Wi-Fi services.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HBum8iTSpS7U8N8QhbPpiY" name="" alt="A screenshot of the Windows 10 Wi-Fi Sense setup menu" src="https://cdn.mos.cms.futurecdn.net/HBum8iTSpS7U8N8QhbPpiY.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>Wi-Fi Sense can also share your network’s credentials with nearby devices, including those not under your control, which poses a privacy risk. To mitigate this, rename your network's SSID to end with '_optout'. Providing guests with access to a separate guest network instead of the main one is a good practice. Ensure that all devices and staff disable Wi-Fi Sense before connecting to your primary network.</p><p>By regularly checking and adjusting these settings, you can maintain better control over your data and enhance your privacy on Windows 10.</p><h2 class="article-body__section" id="section-8-can-t-access-safe-mode-using-keyboard-function-keys"><span>8. Can't access safe mode using keyboard function keys</span></h2><p><a href="https://www.itpro.com/software/29158/how-to-boot-windows-10-in-safe-mode">Safe Mode</a> can be a life-saver in many system-critical problem situations, especially when your device is finding it difficult to start correctly. However, what if one day, you find out that you can no longer activate Safe Mode by pressing the F8 or Shift+F8 keys at boot?</p><p>Fortunately, there are a variety of ways to boot into Safe Mode. We've put together a guide on <a href="https://www.itpro.com/software/29158/how-to-boot-windows-10-in-safe-mode">how to boot Windows 10 Safe Mode</a>, which provides alternatives to using the F8 shortcut, or bypassing shortcuts entirely. These include access a boot option inside the Update & Security settings, or using the Left Shift button as part of a restart.</p><p>You should also consider setting a Safe Mode as an option in the boot menu, although your system will first need to be configured to support it. </p><p>To set this up, you can do the following:</p><section class="howto-block">                    <h3>Setting Safe Mode as a boot option</h3>                                        <p><p>Press the Windows button + X</p><p>Select Command Prompt (Admin) - (may be shown as Terminal (Admin)</p><p>type bcdedit /copy {current} /d 'Windows 10 Safe Mode'</p><p>Press Enter</p><p>Next, click the Windows button</p><p>Type msconfig, and then click on the System Configuration app in the results window</p><p>Navigate to the Boot tab</p><p>Find your newly created Windows 10 Safe Mode option</p><p>Highlight it and select 'Safe Boot' option below</p><p>Select 'Minimal' under Boot type choices</p><p>Select 'Make all boot settings permanent'</p><p>Click Ok</p></p>                </section><p>If you ever want to get rid of the Safe Mode entry, you can do it easily by returning here and deleting it.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PocMaaGLCqpj6VBqLCFwCf" name="" alt="A screenshot showing the various Windows 10 boot options" src="https://cdn.mos.cms.futurecdn.net/PocMaaGLCqpj6VBqLCFwCf.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>You can repeat these steps, substituting suitable names in quotes at the Command Prompt, to create shortcuts for Safe Mode with Networking (tick Network rather than Minimal in System Configuration) and Safe Mode with Command Prompt (Alternate shell).</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zdMxHWxoPCKACU34KVvMgP" name="" alt="A screenshot of the Windows 10 recovery screen and boot options" src="https://cdn.mos.cms.futurecdn.net/zdMxHWxoPCKACU34KVvMgP.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><h2 class="article-body__section" id="section-9-system-restore-isn-t-turned-on"><span>9. System Restore isn't turned on</span></h2><p>One of the most puzzling aspects of Windows 10 is that System Restore is not enabled by default, despite its crucial role in system recovery. To activate System Restore, you need to do this manually via the Control Panel.</p><ul><li>Start by searching for "<strong>Create a restore point</strong>" in the search bar and open the <strong>System Properties</strong> page from the top result.</li><li>In the <strong>Protection Settings</strong> section, select your main system drive (usually labeled as 'C:') and click <strong>Configure</strong>.</li><li>Next, choose the option labeled <strong>Turn on system protection</strong> and apply the changes.</li></ul><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="f2eALQ9WMVWoenkUc4ixRT" name="" alt="A screenshot showing a menu allowing users to turn on System Restore" src="https://cdn.mos.cms.futurecdn.net/f2eALQ9WMVWoenkUc4ixRT.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>Once enabled, Windows 10 will automatically create restore points during updates or other significant changes to your system. This feature acts as a valuable safety net, allowing you to revert your system to a previous state in case something goes wrong, thereby helping you recover quickly from unexpected issues.</p><h2 class="article-body__section" id="section-10-windows-10-default-app-settings-reset-after-update"><span>10. Windows 10 default app settings reset after update</span></h2><p>Major operating system updates can sometimes alter your settings, including which third-party apps are used to open specific file types. Instead of keeping your custom settings, the update may revert everything back to the Windows 10 default apps, which can be quite frustrating. Fortunately, it’s easy to restore your preferences without remapping all file types manually.</p><p>To resolve this, open the <strong>Settings</strong> app and click on the <strong>System</strong> tab. Navigate to <strong>Default apps</strong> to choose which applications should handle different file types. For instance, you might prefer using Groove Music for music files instead of the default Windows Media Player.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XhZA6uDAqSkTAwv3H2EHRW" name="" alt="A screenshot of the Windows 10 desktop showing a menu allowing users to set default apps" src="https://cdn.mos.cms.futurecdn.net/XhZA6uDAqSkTAwv3H2EHRW.png" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>In this section, you can also customize which apps open particular file extensions. For example, you could set VLC Media Player to open MP3 files while keeping Windows Media Player for M4A files or other audio formats. Making these small adjustments helps enhance your overall experience and ensures that your preferred tools are always used.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uFiLnAYbYtRViNRUtCXUaC" name="" alt="A screenshot of the Windows 10 desktop showing a menu allowing users to set default applications based on file type" src="https://cdn.mos.cms.futurecdn.net/uFiLnAYbYtRViNRUtCXUaC.png" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><h2 class="article-body__section" id="section-11-windows-10-is-using-4g-data"><span>11. Windows 10 is using 4G data</span></h2><p>If you have a <a href="https://www.itpro.com/hardware/laptops/368274/best-windows-laptops"><u>Windows tablet or laptop</u></a>  that can use a SIM card, you can access mobile internet on Windows 10 when Wi-Fi isn't available. However, this can lead to unexpected data usage if not properly configured, especially when <a href="https://www.itpro.com/network-internet/wifi-hotspots/356112/how-to-create-a-mobile-hotspot"><u>using a portable hotspot</u></a>.</p><p>To prevent this, go to ‘Settings’, then ‘Network & Internet’. Select ‘Wi-Fi’, followed by ‘Advanced Options’, and enable the ‘Set as metered connection’ option. This setting ensures the operating system minimizes background data usage, such as non-essential updates, protecting your monthly data allowance.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jCceDHzS92NcoUD3bCy6Jb" name="" alt="4g Data Metered Connections Setting" src="https://cdn.mos.cms.futurecdn.net/jCceDHzS92NcoUD3bCy6Jb.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><h2 class="article-body__section" id="section-12-bad-localisation-cortana-not-available"><span>12. Bad localisation, Cortana 'not available'</span></h2><p>Windows 10’s localisation options can sometimes be confusing and inconsistent. There have been instances where incorrect localisation settings are carried over from previous versions, such as Windows 7 or Windows 8, even after a proper upgrade. This can lead to issues like incorrect regional formats or Cortana being unavailable in regions where it should be supported.</p><p>One common cause of these problems is the system date format being set incorrectly. For example, the system may have defaulted to the standard US date format (MM/DD/YY), instead of a UK format. To correct this, go to the Start Menu and search for Region to access the Region & Language settings. Ensure that the Country or region is set correctly, such as 'United Kingdom', and verify that the language setting reflects your preferred language. Click on Options under your primary language, and if prompted, download the language pack and speech options.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GqYmoq2WXDru8AdwkaM8BU" name="" alt="A screenshot of the Windows 10 region settings" src="https://cdn.mos.cms.futurecdn.net/GqYmoq2WXDru8AdwkaM8BU.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>It’s also important to make sure that your keyboard input method matches your region. Incorrect input methods can cause further confusion, so select the correct one and remove any incorrect configurations.</p><p>Next, navigate to <strong>Additional date, time & regional settings</strong> by clicking the back arrow. From there, choose <strong>Change input methods</strong> under the <strong>Language section</strong>, select your preferred language, and make sure it is at the top of the list. Click on <strong>Options</strong> to verify further settings.</p><p>For the Windows display language, it may show as either ‘Enabled’ or ‘Available’. If it’s marked as ‘<strong>Available</strong>’, click <strong>Make this the primary language</strong>. If the option does not appear, download and install the necessary language pack first. Finally, go back to the language preferences, click on <strong>Change date, time, or number formats</strong> in the left pane, and ensure the correct language format is displayed.</p><p>To complete the setup, switch to the <strong>Location</strong> tab and confirm that your <strong>Home location</strong> is correct. Then, click on the <strong>Administrative tab</strong> and check your System locale. Use the Copy settings option if you want to apply these changes to new user accounts and the Welcome screen, ensuring consistency across the system.</p><h2 class="article-body__section" id="section-13-i-can-t-save-a-webpage-as-an-html-file-in-microsoft-edge"><span>13. I can't save a webpage as an HTML file in Microsoft Edge</span></h2><p>In Microsoft Edge, you currently cannot save web pages as HTML files. Previously, Internet Explorer 11 provided a workaround for this feature, but it has since been removed from most Windows 10 PCs. Instead, you'll need to use a browser like Chrome that supports this functionality.</p><p>To save a web page as an HTML file in Chrome, click the three dots in the top-right corner of the browser, navigate to ‘More tools’, and select ‘Save page as’. A Windows popup box will appear, allowing you to rename the file and choose to save it as an HTML file. Finally, press the save button to download the page to your computer. This method ensures you can keep a local copy of web pages for offline access or archival purposes.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="E4zzTp4HRJnqB9AGgFQd9d" name="" alt="The location of the 'Save page' button in Chrome" src="https://cdn.mos.cms.futurecdn.net/E4zzTp4HRJnqB9AGgFQd9d.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IT Pro)</span></figcaption></figure><h2 class="article-body__section" id="section-14-the-lock-screen-gets-in-the-way"><span>14. The lock screen gets in the way</span></h2><p>If you find the Windows lock screen to be an unnecessary barrier, you can disable it through the Registry Editor. This tweak allows you to bypass the lock screen and go straight to the login screen or desktop, saving time and reducing annoyance.</p><p>To start, open the Registry Editor by searching for regedit in the Start Menu. Once the Registry Editor is open, navigate to the following path:</p><p><strong>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows</strong></p><p>Look for a key named <strong>Personalization</strong>. If it doesn’t exist, you will need to create it: right-click the Windows key, select New > Key, and rename it to Personalization.</p><p>Next, right-click the new Personalization key, choose New > DWORD (32-bit) Value, and name it NoLockScreen. Double-click on this value and set the data to 1, then click OK to confirm. </p><p>After making these changes, restart your computer. The lock screen should now be disabled, allowing for a more streamlined login experience without the extra step of dismissing the lock screen.</p><h2 class="article-body__section" id="section-15-boot-times-are-too-slow"><span>15. Boot times are too slow</span></h2><p>In Windows 8, Microsoft introduced hybrid boot to shorten start-up times, and this feature was carried over to Windows 10. Normally, when you shut down your PC, all processes are terminated. However, with hybrid boot, the Windows kernel goes into hibernation to <a href="https://www.itpro.com/operating-systems/microsoft-windows/355247/make-windows-boot-faster"><u>speed up the next start-up</u></a>. While this is useful, it can sometimes be too slow for IT professionals.</p><p>To disable hybrid boot, search for ‘Power Options’ in the Start Menu. Open the Control Panel applet from the left pane, and click on ‘Choose what the power buttons do.’ Select ‘Change settings that are currently unavailable,’ then find and deselect ‘Turn on fast start-up.’ Save your changes, and your PC should turn on faster.</p><p>Interestingly, some users have found that toggling fast start-up off and then back on can resolve related issues. To do this, follow the previous steps to deselect the function, restart your system, and then re-enable it.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ag9LnFscXHPkcY3PUyvfM8" name="" alt="A screenshot of the Windows 10 fast startup settings" src="https://cdn.mos.cms.futurecdn.net/ag9LnFscXHPkcY3PUyvfM8.jpg" mos="" align="middle" fullscreen="" width="0" height="0" attribution="" endorsement="" class=""></p></div></div></figure><p>Additionally, if you dual-boot between Windows 7 and Windows 10, disabling fast start-up in Windows 10 can prevent Windows 7 from performing a disk check every time you boot. This happens because with fast start-up enabled, Windows 7 may not recognize that the disks were properly shut down in Windows 10. Disabling this feature ensures smoother transitions between the two operating systems.</p><h2 class="article-body__section" id="section-16-windows-10-sound-problems"><span>16. Windows 10 Sound Problems</span></h2><p>Sound issues can be quite common in Windows 10, especially after an update. Here’s how to fix sound problems:</p><ul><li><strong>Check audio output device</strong>: Make sure the correct output device is selected. Click on the speaker icon in the system tray and ensure the proper device is chosen from the dropdown list.</li><li><strong>Update audio drivers</strong>: Outdated or corrupted audio drivers are a common cause of sound issues. Open <strong>Device Manager</strong>, expand <strong>Sound, video and game controllers</strong>, right-click your audio device, and select <strong>Update driver</strong>.</li><li><strong>Run the audio troubleshooter</strong>: Windows has a built-in troubleshooter that can often resolve sound issues automatically. Go to <strong>Settings > Update & Security > Troubleshoot</strong> and select <strong>Playing Audio</strong>.</li></ul><h2 class="article-body__section" id="section-17-windows-10-startup-problems"><span>17. Windows 10 startup problems</span></h2><p>Startup issues are a frequent source of frustration for Windows 10 users. These problems can range from the system being stuck in a boot loop to errors preventing the computer from starting properly. To address startup issues:</p><ul><li><strong>Use startup repair</strong>: Restart your computer and boot into the Advanced Startup menu by holding the Shift key while selecting Restart. From here, select <strong>Troubleshoot > Advanced options > Startup Repair</strong>.</li><li><strong>Boot in safe mode</strong>: If the system is struggling to start normally, try booting into Safe Mode. Hold the Shift key while restarting, and select <strong>Troubleshoot > Advanced options > Startup Settings</strong>. In Safe Mode, you can uninstall problematic updates or drivers.</li><li><strong>Check boot order in BIOS</strong>: Sometimes incorrect BIOS settings can prevent Windows from starting. Enter the BIOS (usually by pressing <strong>F2</strong> or <strong>Del</strong> during startup) and verify that the correct drive is set as the primary boot device.</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to run Chkdsk on Windows ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/34385/how-to-run-chkdsk</link>
                                                                            <description>
                            <![CDATA[ A guide to the various ways of accessing and running the Chkdsk function on Windows ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jgMvD98UNV2rbFTzdQtB6a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ANSbotDHNFc3eG64Zj9uBR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Sep 2019 09:49:00 +0000</pubDate>                                                                                                                                <updated>Thu, 15 Jun 2023 13:06:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ANSbotDHNFc3eG64Zj9uBR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of the chkdsk process underway on a Windows machine]]></media:description>                                                            <media:text><![CDATA[Image of the chkdsk process underway on a Windows machine]]></media:text>
                                <media:title type="plain"><![CDATA[Image of the chkdsk process underway on a Windows machine]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ANSbotDHNFc3eG64Zj9uBR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Chkdsk function is a tool capable of seeking out and repairing hard drive issues on Windows operating systems. This powerful tool analyses the hard drive to prevent major issues from spiralling out of control and resulting in hardware corruption. The procedure is somewhat in-depth and can take some time to complete.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/33387/what-is-windows-10-ltsb" data-original-url="/microsoft-windows/33387/what-is-windows-10-ltsb">What is Windows 10 LTSB?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7" data-original-url="/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7">What to do if you're still running Windows 7</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/32538/time-is-up-for-windows-7-how-do-you-migrate-to-windows-10" data-original-url="/operating-systems/32538/time-is-up-for-windows-7-how-do-you-migrate-to-windows-10">Time is up for Windows 7: How do you migrate to Windows 10?</a></p></div></div><p>The Chkdsk function is handy for identifying potential problems with a storage device, and can perform a variety of functions, from fixing issues to assessing the integrity of a system file. Chkdsk is particularly efficient at fixing corrupted master file tables, weak security descriptors, and incorrectly entered timestamps.</p><p>The tool is also good for scanning sectors for signs of corruption that may be degrading overall performance. The tool checks specifically for so-called &apos;<strong>soft</strong>&apos; or &apos;<strong>hard</strong>&apos; bad sectors.</p><p>Soft bad sectors are those that have become corrupted during the write process, while hard bad sectors are the result of physical damage to the device. The Chkdsk function is useful for handling these bad sectors, as it&apos;s able to repair the soft ones, and isolate the hard ones so they&apos;re not used.</p><h2 id="how-to-run-chkdsk">How to run Chkdsk</h2><p>Most Windows systems have the means to use Chkdsk, from Windows 7 to the latest version of Windows 10. Users of legacy Windows systems, including Vista or XP, can also trigger Chkdsk to analyse their hard drives for any bad sectors or issues. The tool can normally be triggered for each hard drive, or even individual partitions, as you boot into windows.</p><p>There are a number of ways to run the Chkdsk function. One popular method is to use the <a href="https://www.itpro.com/microsoft-windows/30414/command-prompt-windows-10" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/30414/command-prompt-windows-10">Command Prompt</a>, which is handy if you&apos;re unable to access the desktop. You can either use Recovery Mode, or the original installation medium to boot and then run Command Prompt in order to run Chkdsk this way.</p><section class="howto-block">                    <h3>How to run Chkdsk using a Command Prompt</h3>                    <figure>                            <p class="bordeaux-image-check">                                <img    src="https://cdn.mos.cms.futurecdn.net/2xajTS8uzLkHoVqUg9Uion.png"                                        alt="A screenshot of the chkdsk command being run on Command Prompt in Windows 10"                                        onerror="this.parentNode.replaceChild(window.missingImage(),this)"                                        data-pin-media="https://cdn.mos.cms.futurecdn.net/2xajTS8uzLkHoVqUg9Uion.png"                                        class="expandable van-old-layout-image">                            </p><div class="credit">(Image: © ITPro)</div></figure>                    <p><ol></p><p><li>Open the Command Prompt either using Safe Mode or by typing 'cmd' into the Windows search box and running the Command Prompt application</li></p><p><li>Type 'chkdsk volume :/r' into the Command Prompt window, replacing 'volume' with the letter associated with the drive you would like to scan</li></p><p><li>Wait for the process to finish</li></p><p></ol></p>                </section><section class="howto-block">                    <h3>How to run the Chkdsk function without using Command Prompt</h3>                    <figure>                            <p class="bordeaux-image-check">                                <img    src="https://cdn.mos.cms.futurecdn.net/nw65CXWUgoaHceZRPRWHqe.png"                                        alt="A screenshot of a menu on Windows 11 showing the button for running the Check Disk function"                                        onerror="this.parentNode.replaceChild(window.missingImage(),this)"                                        data-pin-media="https://cdn.mos.cms.futurecdn.net/nw65CXWUgoaHceZRPRWHqe.png"                                        class="expandable van-old-layout-image">                            </p><div class="credit">(Image: © ITPro)</div></figure>                    <p><ol></p><p><li>Open 'This PC', which is found in your folder directory</li></p><p><li>Right click the hard drive you would like to scan</li></p><p><li>Click Properties</li></p><p><li>Click the Tools tab</li></p><p><li>Under Error Checking, click Check</li></p><p></ol></p>                </section><p>To repair errors without scanning for bad sectors, select the &apos;Automatically fix file system errors&apos; box and to repair errors and scan for bad sectors, select the &apos;Scan for and attempt recovery of bad sectors&apos; box. The utility will notify you if the scan finds any errors or not.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>